Skip to content

Conversation

@pali
Copy link

@pali pali commented Feb 12, 2018

Method Email::Address->parse is vulnerable to CVE-2015-7686 and also does
not parse list of email addresses correctly. This patch replaces it by a
new module Email::Address::XS.

Also do not use Email::Address->parse for parsing Message-Id, In-Reply-To
and References headers. They have different structure and for replying it
is not needed at all. Update also unit tests for Message-Id headers.

Method Email::Address->parse is vulnerable to CVE-2015-7686 and also does
not parse list of email addresses correctly. This patch replaces it by a
new module Email::Address::XS.

Also do not use Email::Address->parse for parsing Message-Id, In-Reply-To
and References headers. They have different structure and for replying it
is not needed at all. Update also unit tests for Message-Id headers.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant