Debian Bug report logs - #556459
php5-common: PHP Bug #50158 FILTER_VALIDATE_EMAIL fails with valid addresses containing = or ?

version graph

Package: php5-common; Maintainer for php5-common is (unknown);

Reported by: Andrew Robert Nicols <andrew.nicols@luns.net.uk>

Date: Mon, 16 Nov 2009 10:36:02 UTC

Severity: normal

Tags: patch

Found in version php5/5.2.6.dfsg.1-1+lenny3

Fixed in version 5.3.3-7

Done: Ondřej Surý <ondrej@sury.org>

Bug is archived. No further changes may be made.

Forwarded to http://bugs.php.net/bug.php?id=50158

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, andrew.nicols@luns.net.uk, Debian PHP Maintainers <pkg-php-maint@lists.alioth.debian.org>:
Bug#556459; Package php5-common. (Mon, 16 Nov 2009 10:36:05 GMT) (full text, mbox, link).


Acknowledgement sent to Andrew Robert Nicols <andrew.nicols@luns.net.uk>:
New Bug report received and forwarded. Copy sent to andrew.nicols@luns.net.uk, Debian PHP Maintainers <pkg-php-maint@lists.alioth.debian.org>. (Mon, 16 Nov 2009 10:36:05 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Andrew Robert Nicols <andrew.nicols@luns.net.uk>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: php5-common: PHP Bug #50158 FILTER_VALIDATE_EMAIL fails with valid addresses containing = or ?
Date: Mon, 16 Nov 2009 10:11:48 +0000
Package: php5-common
Version: 5.2.6.dfsg.1-1+lenny3
Severity: normal
Tags: patch

As reported to bugs.php.net, the filter_var function, when used with the
FILTER_VALIDATE_EMAIL filter, does not correctly parse e-mail addresses
which contain either a ? or an =, both of which are valid according to the
relevant RFCs.

A patch has been provided by php and is attached to the bug
(http://bugs.php.net/bug.php?id=50158) and the php subversion revision
number is 290791.

-- System Information:
Debian Release: 5.0.3
  APT prefers stable
  APT policy: (500, 'stable')
Architecture: i386 (i686)

Kernel: Linux 2.6.26-2-vserver-686-bigmem (SMP w/2 CPU cores)
Locale: LANG=en_GB.UTF-8, LC_CTYPE=en_GB.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/bash

Versions of packages php5-common depends on:
ii  libc6                         2.7-18     GNU C Library: Shared libraries
ii  sed                           4.1.5-6    The GNU sed stream editor

php5-common recommends no packages.

php5-common suggests no packages.

-- no debconf information




Set Bug forwarded-to-address to 'http://bugs.php.net/bug.php?id=50158'. Request was from Raphael Geissert <geissert@debian.org> to control@bugs.debian.org. (Mon, 11 Jan 2010 19:09:10 GMT) (full text, mbox, link).


Information forwarded to debian-bugs-dist@lists.debian.org, Debian PHP Maintainers <pkg-php-maint@lists.alioth.debian.org>:
Bug#556459; Package php5-common. (Mon, 22 Feb 2010 22:30:07 GMT) (full text, mbox, link).


Acknowledgement sent to Raphael Geissert <geissert@debian.org>:
Extra info received and forwarded to list. Copy sent to Debian PHP Maintainers <pkg-php-maint@lists.alioth.debian.org>. (Mon, 22 Feb 2010 22:30:07 GMT) (full text, mbox, link).


Message #12 received at 556459@bugs.debian.org (full text, mbox, reply):

From: Raphael Geissert <geissert@debian.org>
To: 556459@bugs.debian.org
Cc: ,control@bugs.debian.org
Subject: [debian/debian-lenny] Recognise ? and = in email addresses as valid (Closes: #556459)
Date: Mon, 22 Feb 2010 22:27:14 +0000
tag 556459 pending
thanks

Date: Sun Jan 24 20:29:44 2010 -0600
Author: Raphael Geissert <geissert@debian.org>
Commit ID: b9facc50983b2361814f8c8c6a0354de4c5738be
Commit URL: http://git.debian.org/?p=pkg-php/php.git;a=commitdiff;h=b9facc50983b2361814f8c8c6a0354de4c5738be
Patch URL: http://git.debian.org/?p=pkg-php/php.git;a=commitdiff_plain;h=b9facc50983b2361814f8c8c6a0354de4c5738be

    Recognise ? and = in email addresses as valid (Closes: #556459)

      




Added tag(s) pending. Request was from Raphael Geissert <geissert@debian.org> to control@bugs.debian.org. (Mon, 22 Feb 2010 22:30:14 GMT) (full text, mbox, link).


Reply sent to Ondřej Surý <ondrej@sury.org>:
You have taken responsibility. (Wed, 27 Apr 2011 08:34:07 GMT) (full text, mbox, link).


Notification sent to Andrew Robert Nicols <andrew.nicols@luns.net.uk>:
Bug acknowledged by developer. (Wed, 27 Apr 2011 08:34:08 GMT) (full text, mbox, link).


Message #19 received at 556459-done@bugs.debian.org (full text, mbox, reply):

From: Ondřej Surý <ondrej@sury.org>
To: 465081-done@bugs.debian.org, 537794-done@bugs.debian.org, 553048-done@bugs.debian.org, 574610-done@bugs.debian.org, 584885-done@bugs.debian.org, 584957-done@bugs.debian.org, 594613-done@bugs.debian.org, 493045-done@bugs.debian.org, 549492-done@bugs.debian.org, 450581-done@bugs.debian.org, 502174-done@bugs.debian.org, 543177-done@bugs.debian.org, 547134-done@bugs.debian.org, 552089-done@bugs.debian.org, 556523-done@bugs.debian.org, 559273-done@bugs.debian.org, 576147-done@bugs.debian.org, 578754-done@bugs.debian.org, 601602-done@bugs.debian.org, 609355-done@bugs.debian.org, 419649-done@bugs.debian.org, 442063-done@bugs.debian.org, 500567-done@bugs.debian.org, 513429-done@bugs.debian.org, 528600-done@bugs.debian.org, 597650-done@bugs.debian.org, 603641-done@bugs.debian.org, 405067-done@bugs.debian.org, 430397-done@bugs.debian.org, 440775-done@bugs.debian.org, 591759-done@bugs.debian.org, 565387-done@bugs.debian.org, 507762-done@bugs.debian.org, 529278-done@bugs.debian.org, 556459-done@bugs.debian.org
Subject: Closing segfaults (and some other minor bugs) for version older than squeeze (5.3.3)
Date: Wed, 27 Apr 2011 10:28:24 +0200
Version: 5.3.3-7

Hi,

since lenny is oldstable it will not get any updates now (except
security)[1], I am closing all segfault bugs filled against php5 in
lenny. (This is kind of saying that we don't care much about php5 in
lenny anymore).

If you believe the bug is still there, please provide evidence[2] and
a (preferably complete) test case with up-to-date squeeze (and/or
testing or unstable) version of php5 and reopen the bug.

O.
1. http://wiki.debian.org/PHP#Notes_on_PHP_and_security
2. Install php5-dbg and provide backtrace:
http://bugs.php.net/bugs-generating-backtrace.php
-- 
Ondřej Surý <ondrej@sury.org>




Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Thu, 26 May 2011 07:37:41 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Sun Jul 2 01:14:49 2023; Machine Name: bembo

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.