void message_part_envelope_parse_from_header(pool_t pool,
struct message_part_envelope **data,
- struct message_part_data_limits *limits ATTR_UNUSED,
+ struct message_part_data_limits *limits,
struct message_header_line *hdr)
{
struct message_part_envelope *d;
if (addr_p != NULL) {
message_address_parse_full(pool, hdr->full_value,
hdr->full_value_len,
- UINT_MAX,
+ limits->remaining_addresses,
MESSAGE_ADDRESS_PARSE_FLAG_FILL_MISSING,
&new_addr);
+ i_assert(new_addr.count <= limits->remaining_addresses);
+ limits->remaining_addresses -= new_addr.count;
+
/* Merge multiple headers the same as if they were comma
separated in a single line. This is better from security
point of view, because attacker could intentionally write
struct message_header_line;
+#define MESSAGE_PART_DATA_MAX_TOTAL_ADDRESSES 100000
+
struct message_part_data_limits {
+ unsigned int remaining_addresses;
};
-#define MESSAGE_PART_DATA_LIMITS_INIT { }
+#define MESSAGE_PART_DATA_LIMITS_INIT \
+ { MESSAGE_PART_DATA_MAX_TOTAL_ADDRESSES }
struct message_part_param {
const char *name;