Movatterモバイル変換


[0]ホーム

URL:


Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

[3.7] bpo-45001: Make email date parsing more robust against malformed input (GH-27946)#27975

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to ourterms of service andprivacy statement. We’ll occasionally send you account related emails.

Already on GitHub?Sign in to your account

Merged
ned-deily merged 1 commit intopython:3.7frommiss-islington:backport-989f6a3-3.7
Aug 30, 2021

Conversation

@miss-islington
Copy link
Contributor

@miss-islingtonmiss-islington commentedAug 26, 2021
edited by bedevere-bot
Loading

Various date parsing utilities in the email module, such as
email.utils.parsedate(), are supposed to gracefully handle invalid
input, typically by raising an appropriate exception or by returning
None.

The internal email._parseaddr._parsedate_tz() helper used by some of
these date parsing routines tries to be robust against malformed input,
but unfortunately it can still crash ungracefully when a non-empty but
whitespace-only input is passed. This manifests as an unexpected
IndexError.

In practice, this can happen when parsing an email with only a newline
inside a ‘Date:’ header, which unfortunately happens occasionally in the
real world.

Here's a minimal example:

$ pythonPython 3.9.6 (default, Jun 30 2021, 10:22:16)[GCC 11.1.0] on linuxType "help", "copyright", "credits" or "license" for more information.>>> import email.utils>>> email.utils.parsedate('foo')>>> email.utils.parsedate(' ')Traceback (most recent call last):  File "<stdin>", line 1, in <module>  File "/usr/lib/python3.9/email/_parseaddr.py", line 176, in parsedate    t = parsedate_tz(data)  File "/usr/lib/python3.9/email/_parseaddr.py", line 50, in parsedate_tz    res = _parsedate_tz(data)  File "/usr/lib/python3.9/email/_parseaddr.py", line 72, in _parsedate_tz    if data[0].endswith(',') or data[0].lower() in _daynames:IndexError: list index out of range

The fix is rather straight-forward: guard against empty lists, after
splitting on whitespace, but before accessing the first element.
(cherry picked from commit989f6a3)

Co-authored-by: wouter bolsterleewouter@bolsterl.ee

https://bugs.python.org/issue45001

pythonGH-27946)Various date parsing utilities in the email module, such asemail.utils.parsedate(), are supposed to gracefully handle invalidinput, typically by raising an appropriate exception or by returningNone.The internal email._parseaddr._parsedate_tz() helper used by some ofthese date parsing routines tries to be robust against malformed input,but unfortunately it can still crash ungracefully when a non-empty butwhitespace-only input is passed. This manifests as an unexpectedIndexError.In practice, this can happen when parsing an email with only a newlineinside a ‘Date:’ header, which unfortunately happens occasionally in thereal world.Here's a minimal example:    $ python    Python 3.9.6 (default, Jun 30 2021, 10:22:16)    [GCC 11.1.0] on linux    Type "help", "copyright", "credits" or "license" for more information.    >>> import email.utils    >>> email.utils.parsedate('foo')    >>> email.utils.parsedate(' ')    Traceback (most recent call last):      File "<stdin>", line 1, in <module>      File "/usr/lib/python3.9/email/_parseaddr.py", line 176, in parsedate        t = parsedate_tz(data)      File "/usr/lib/python3.9/email/_parseaddr.py", line 50, in parsedate_tz        res = _parsedate_tz(data)      File "/usr/lib/python3.9/email/_parseaddr.py", line 72, in _parsedate_tz        if data[0].endswith(',') or data[0].lower() in _daynames:    IndexError: list index out of rangeThe fix is rather straight-forward: guard against empty lists, aftersplitting on whitespace, but before accessing the first element.(cherry picked from commit989f6a3)Co-authored-by: wouter bolsterlee <wouter@bolsterl.ee>
@miss-islington
Copy link
ContributorAuthor

@wbolster and@ambv: Status check is done, and it's a success ✅ .

@miss-islington
Copy link
ContributorAuthor

@wbolster and@ambv: Status check is done, and it's a success ✅ .

@miss-islington
Copy link
ContributorAuthor

@wbolster and@ambv: Status check is done, and it's a success ✅ .

@ambvambv requested a review fromned-deilyAugust 26, 2021 15:49
@ambv
Copy link
Contributor

@ned-deily, this is a bug fix with security-related connotations. I merged it to 3.8 so we might as well get it to 3.7 and 3.6.

@wbolster
Copy link
Contributor

@ned-deily fyi, this explains how this can lead to denial-of-service:#27946 (comment)

@miss-islington
Copy link
ContributorAuthor

Sorry, I can't merge this PR. Reason:You're not authorized to push to this branch. Visit https://docs.github.com/articles/about-protected-branches/ for more information..

@ned-deilyned-deily merged commite9b85af intopython:3.7Aug 30, 2021
@miss-islingtonmiss-islington deleted the backport-989f6a3-3.7 branchAugust 30, 2021 18:48
Sign up for freeto join this conversation on GitHub. Already have an account?Sign in to comment

Reviewers

@ned-deilyned-deilyned-deily approved these changes

Assignees

No one assigned

Labels

None yet

Projects

None yet

Milestone

No milestone

Development

Successfully merging this pull request may close these issues.

6 participants

@miss-islington@ambv@wbolster@ned-deily@the-knights-who-say-ni@bedevere-bot

[8]ページ先頭

©2009-2025 Movatter.jp