X-Git-Url: https://git.proxmox.com/?a=blobdiff_plain;f=src%2FPVE%2FTools.pm;h=039c9fb8dae5e2d10cb492b9f41ecf4f08397a91;hb=c9c6d9107387fd09d3b26206c81a66326f138de9;hp=58a20063a3380f53a23becc3fa1695eadbc07419;hpb=1a0c010327d130c5a7cfb1fe588602184df2cc38;p=pve-common.git diff --git a/src/PVE/Tools.pm b/src/PVE/Tools.pm index 58a2006..039c9fb 100644 --- a/src/PVE/Tools.pm +++ b/src/PVE/Tools.pm @@ -1224,19 +1224,24 @@ sub sync_mountpoint { # mailto may be a single email string or an array of receivers sub sendmail { my ($mailto, $subject, $text, $html, $mailfrom, $author) = @_; + my $mail_re = qr/[^-a-zA-Z0-9+._@]/; $mailto = [ $mailto ] if !ref($mailto); - my $rcvrarg = ''; - foreach my $r (@$mailto) { - $rcvrarg .= " '$r'"; + foreach (@$mailto) { + die "illegal character in mailto address\n" + if ($_ =~ $mail_re); } + my $rcvrtxt = join (', ', @$mailto); $mailfrom = $mailfrom || "root"; + die "illegal character in mailfrom address\n" + if $mailfrom =~ $mail_re; + $author = $author || 'Proxmox VE'; - open (MAIL,"|sendmail -B 8BITMIME -f $mailfrom $rcvrarg") || + open (MAIL, "|-", "sendmail", "-B", "8BITMIME", "-f", $mailfrom, @$mailto) || die "unable to open 'sendmail' - $!"; # multipart spec see https://www.ietf.org/rfc/rfc1521.txt