aboutsummaryrefslogtreecommitdiffstats
path: root/assets/qtmaildir.desktop
diff options
context:
space:
mode:
authorDanilo M. <danix@danix.xyz>2026-09-18 16:04:37 +0200
committerDanilo M. <danix@danix.xyz>2026-09-18 16:04:37 +0200
commit7454096cae63d87c75a676751bb07f5650280cd0 (patch)
treeff2d1b2c60f25bbdb5419c9a9259e7d4f160e2e5 /assets/qtmaildir.desktop
parentf7815097104ae6da9bb763d1b63df55217818445 (diff)
downloadqtmaildir-7454096cae63d87c75a676751bb07f5650280cd0.tar.gz
qtmaildir-7454096cae63d87c75a676751bb07f5650280cd0.zip
fix: sanitise untrusted contact names on insertion
A vCard FN is untrusted and ContactStore faithfully decodes `\n` to a real newline, so `Evil\nBcc: x` was inserted raw into a recipient field and flowed through splitRecipients() to MessageBuilder. contactInsertionText() only quoted a name carrying a comma or a double quote, so every other RFC 5322 special (<, >, ;, @) and any control character reached the header unguarded. The name now has control characters and whitespace runs replaced by single spaces, and every non-empty name is quoted, with `\` escaped before `"`. Quoting contains all the specials in one step. The parser is left faithful; this is fixed at the consumer/trust boundary. Tests: a name with a decoded newline inserts no control character and yields one recipient; a name with <, >, ;, @ is quoted and yields one recipient. The three tests that expected an unquoted plain name now expect the quoted form.
Diffstat (limited to 'assets/qtmaildir.desktop')
0 files changed, 0 insertions, 0 deletions