diff options
| author | Danilo M. <danix@danix.xyz> | 2026-09-18 16:04:37 +0200 |
|---|---|---|
| committer | Danilo M. <danix@danix.xyz> | 2026-09-18 16:04:37 +0200 |
| commit | 7454096cae63d87c75a676751bb07f5650280cd0 (patch) | |
| tree | ff2d1b2c60f25bbdb5419c9a9259e7d4f160e2e5 /src/calendarstore.cpp | |
| parent | f7815097104ae6da9bb763d1b63df55217818445 (diff) | |
| download | qtmaildir-7454096cae63d87c75a676751bb07f5650280cd0.tar.gz qtmaildir-7454096cae63d87c75a676751bb07f5650280cd0.zip | |
fix: sanitise untrusted contact names on insertion
A vCard FN is untrusted and ContactStore faithfully decodes `\n` to a real
newline, so `Evil\nBcc: x` was inserted raw into a recipient field and flowed
through splitRecipients() to MessageBuilder. contactInsertionText() only quoted
a name carrying a comma or a double quote, so every other RFC 5322 special
(<, >, ;, @) and any control character reached the header unguarded.
The name now has control characters and whitespace runs replaced by single
spaces, and every non-empty name is quoted, with `\` escaped before `"`.
Quoting contains all the specials in one step. The parser is left faithful;
this is fixed at the consumer/trust boundary.
Tests: a name with a decoded newline inserts no control character and yields
one recipient; a name with <, >, ;, @ is quoted and yields one recipient. The
three tests that expected an unquoted plain name now expect the quoted form.
Diffstat (limited to 'src/calendarstore.cpp')
0 files changed, 0 insertions, 0 deletions
