[issue32606] Email Header Injection Protection Bypass

2018-01-20 Thread Dalton Campbell
Change by Dalton Campbell : -- nosy: +barry ___ Python tracker <https://bugs.python.org/issue32606> ___ ___ Python-bugs-list mailing list Unsubscribe:

[issue32606] Email Header Injection Protection Bypass

2018-01-20 Thread Dalton Campbell
New submission from Dalton Campbell : The protection's implemented in https://github.com/python/cpython/blob/master/Lib/email/header.py to prevent Email Header injection can be bypassed by specifying an injected additional header in the following format: exam...@python.org\ncc :