[SECURITY] - An attacker can write files with exact names to arbitrary locations on the filesystem
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 2/5
- Tiempo estimado
- 1-3 horas
- Aptitud para principiantes
- 72/100
Línea de trabajo
Lee shell/ev-window.c alrededor de las líneas 7374 y 7400, y sigue las rutas de guardado de adjuntos locales y remotos. Comprueba cómo se manejan los nombres de los adjuntos en cada ruta; el trabajo estará terminado cuando al guardar un adjunto no se pueda usar ../ para salir del directorio elegido, preservando el nombre de archivo previsto.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Description
Xreader 4.6.3 (commit ef5a50d) passes the raw PDF attachment filename directly to g_file_get_child() when saving attachments via "Save Attachment As...". Since g_file_get_child() resolves ../ sequences, an attacker-controlled filename can escape the user-selected target directory and write files to arbitrary locations with the exact filename specified by the attacker — no random suffix.
This is the most critical of the attachment vulnerabilities, as it enables writing .desktop files (or any other file) with precise names to arbitrary locations, leading to arbitrary code execution.
Affected Code
shell/ev-window.c:7374:
save_to = g_file_get_child(target_file, ev_attachment_get_name(attachment));
shell/ev-window.c:7400:
dest_file = g_file_get_child(target_file, ev_attachment_get_name(attachment));
Both the local and remote save paths use the unsanitized attachment name.
Steps to Reproduce
- Generate a malicious PDF using the PoC script from the full report — the attachment is named
../Desktop/test.desktopand contains a valid.desktopentry that executes an arbitrary command - Open
poc.pdfin xreader - In the sidebar, right-click the attachment and select "Save Attachment As..."
- Select any directory (e.g.,
~/Documents/) test.desktopis written to~/Desktop/instead of the selected directory- Double-clicking the
.desktopfile executes the embedded command
Suggested Fix
Extract the basename before passing to g_file_get_child() in both code paths:
// line 7374
-save_to = g_file_get_child(target_file, ev_attachment_get_name(attachment));
+gchar *basename = g_path_get_basename(ev_attachment_get_name(attachment));
+save_to = g_file_get_child(target_file, basename);
+g_free(basename);
// line 7400
-dest_file = g_file_get_child(target_file, ev_attachment_get_name(attachment));
+gchar *basename = g_path_get_basename(ev_attachment_get_name(attachment));
+dest_file = g_file_get_child(target_file, basename);
+g_free(basename);
Impact
An attacker can write files with exact names to arbitrary locations on the filesystem. By writing a .desktop file to ~/Desktop/, arbitrary code execution is achieved when the user double-clicks it. The only user interaction required is opening the PDF, right-clicking the attachment, selecting "Save As", and choosing any directory.
References
- Lenguaje dominante
- C
- Estrellas
- 285
- Forks
- 82
- Métricas de merge de PR
- Sin PR fusionados en 30 d
Preparar el entorno
Este proyecto no incluye contenedor de desarrollo, Dockerfile ni guía de contribución, así que la configuración corre por tu cuenta: empieza por su README y consulta nuestra guía para la primera contribución para los pasos generales.
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de linuxmint/xreader
-
Cyrillic homoglyph characters used in place of ASCII <p> tags in Kazakh AppData description stringAbierto
Dificultad 1/5 Menos de una hora Aptitud para principiantes 88/100
-
Dificultad 4/5 3-5 días Aptitud para principiantes 38/100
-
Dificultad 4/5 3-5 días Aptitud para principiantes 45/100
-
Dificultad 3/5 1-2 días Aptitud para principiantes 55/100
-
Dificultad 3/5 1-2 días Aptitud para principiantes 48/100
Todos los issues de linuxmint/xreader
Issues similares
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
mypaint/libmypaint#209 ·
-
[LOGO] Keenetic OSPosiblemente ocupada @Ivan-Alone la tomó hoy. Abiertologo request
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
fastfetch-cli/fastfetch#2646 ·
Los mantenedores suelen responder en 1 día
-
rc_runtime_activate_richpresence leaves a half-initialised entry when the buffer allocation failsAbierto
Dificultad 1/5 Menos de una hora Aptitud para principiantes 88/100
RetroAchievements/rcheevos#558 ·
-
good first issue priority:low type:docs
Dificultad 2/5 1-3 horas Aptitud para principiantes 82/100
crazy-goat/php-fpm-ng#920 ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 74/100