Skip to content
Snippets Groups Projects
Commit 69c22fa4 authored by Stephan Bosch's avatar Stephan Bosch
Browse files

lib-sieve: editheader extension: added runtime header field name verification.

parent 01b034aa
No related branches found
No related tags found
No related merge requests found
......@@ -238,6 +238,17 @@ static int cmd_addheader_operation_execute
(renv, address, "value", &value)) <= 0 )
return ret;
/*
* Verify arguments
*/
if ( !rfc2822_header_field_name_verify
(str_c(field_name), str_len(field_name)) ) {
sieve_runtime_error(renv, NULL, "specified field name `%s' is invalid",
str_sanitize(str_c(field_name), 80));
return SIEVE_EXEC_FAILURE;
}
/*
* Perform operation
*/
......
......@@ -425,6 +425,17 @@ static int cmd_deleteheader_operation_execute
(renv, &oprnd, address, "value-patterns", &vpattern_list)) <= 0 )
return ret;
/*
* Verify arguments
*/
if ( !rfc2822_header_field_name_verify
(str_c(field_name), str_len(field_name)) ) {
sieve_runtime_error(renv, NULL, "specified field name `%s' is invalid",
str_sanitize(str_c(field_name), 80));
return SIEVE_EXEC_FAILURE;
}
/*
* Execute command
*/
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment

Consent

On this website, we use the web analytics service Matomo to analyze and review the use of our website. Through the collected statistics, we can improve our offerings and make them more appealing for you. Here, you can decide whether to allow us to process your data and set corresponding cookies for these purposes, in addition to technically necessary cookies. Further information on data protection—especially regarding "cookies" and "Matomo"—can be found in our privacy policy. You can withdraw your consent at any time.