This is an automated email from the ASF dual-hosted git repository.
swebb2066 pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/logging-log4cxx.git
The following commit(s) were added to refs/heads/master by this push:
new 802dfb35 Prevent an embedded NUL character truncating a SMTP alert
email (#731)
802dfb35 is described below
commit 802dfb35dc38a33d580e5d9aa23b45fe1f394ebf
Author: Stephen Webb <[email protected]>
AuthorDate: Thu Aug 20 10:41:51 2026 +1000
Prevent an embedded NUL character truncating a SMTP alert email (#731)
---
src/main/cpp/smtpappender.cpp | 18 ++++++++++++------
src/main/include/log4cxx/net/smtpappender.h | 1 -
2 files changed, 12 insertions(+), 7 deletions(-)
diff --git a/src/main/cpp/smtpappender.cpp b/src/main/cpp/smtpappender.cpp
index 496c3d53..02b5a2e0 100644
--- a/src/main/cpp/smtpappender.cpp
+++ b/src/main/cpp/smtpappender.cpp
@@ -222,8 +222,7 @@ class SMTPMessage
const LogString msg, Pool& p)
{
message = smtp_add_message(session);
- current_len = msg.length();
- body = current = toMessage(msg, p);
+ body = current = toMessage(msg, p, current_len);
messagecbState = 0;
smtp_set_reverse_path(message, toAscii(from, p));
addRecipients(to, "To", p);
@@ -273,8 +272,9 @@ class SMTPMessage
/**
* Message bodies can only contain US-ASCII characters and
* CR and LFs can only occur together.
+ * On return \c lenOut holds the length of the converted body.
*/
- static const char* toMessage(const LogString& str, Pool& p)
+ static const char* toMessage(const LogString& str, Pool& p,
size_t& lenOut)
{
//
// count the number of carriage returns and line
feeds
@@ -301,9 +301,10 @@ class SMTPMessage
for (unsigned int c : str)
{
//
- // replace non-ASCII characters with '?'
+ // replace non-ASCII characters and embedded
NULs with '?'
+ // (a NUL octet must never act as a body
terminator)
//
- if (c > 0x7F)
+ if (c > 0x7F || c == 0)
{
*current++ = 0x3F; // '?'
}
@@ -335,6 +336,7 @@ class SMTPMessage
}
*current = 0;
+ lenOut = current - retval;
return retval;
}
@@ -362,7 +364,11 @@ class SMTPMessage
if (pThis->current)
{
- *len = strnlen_s(pThis->current,
pThis->current_len);
+ // Use the stored post-conversion
length: strnlen_s over the
+ // pre-conversion length truncates at
an embedded NUL and
+ // undercounts the CRLF-expanded body,
silently dropping the
+ // newest content from the alert email.
+ *len =
static_cast<int>(pThis->current_len);
}
retval = pThis->current;
diff --git a/src/main/include/log4cxx/net/smtpappender.h
b/src/main/include/log4cxx/net/smtpappender.h
index d7107697..55894982 100644
--- a/src/main/include/log4cxx/net/smtpappender.h
+++ b/src/main/include/log4cxx/net/smtpappender.h
@@ -119,7 +119,6 @@ class LOG4CXX_EXPORT SMTPAppender : public AppenderSkeleton
cc | (\ref asciiCheck "1") | - |
bcc | (\ref asciiCheck "1") | - |
subject | {any} | - |
- subject | {any} | - |
buffersize | {int} | 512 |
evaluatorClass | (\ref AppenderSkeleton "2") | - |