Perl-Email-Project / Email-Reply

perl library for making replies to email
2 stars 3 forks source link

Do not depend on insecure module Email::Address #6

Open pali opened 6 years ago

pali commented 6 years ago

Method Email::Address->parse is vulnerable to CVE-2015-7686 and also does not parse list of email addresses correctly. This patch replaces it by a new module Email::Address::XS.

Also do not use Email::Address->parse for parsing Message-Id, In-Reply-To and References headers. They have different structure and for replying it is not needed at all. Update also unit tests for Message-Id headers.