[SECURITY] - An attacker can write files with exact names to arbitrary locations on the filesystem
Personne n'a encore pris cette issue.
Évaluation
- Difficulté
- 2/5
- Temps estimé
- 1-3 heures
- Accessibilité débutants
- 72/100
Piste de recherche
Lisez shell/ev-window.c autour des lignes 7374 et 7400, et suivez les chemins d’enregistrement des pièces jointes locales et distantes. Vérifiez comment les noms des pièces jointes sont traités dans chaque chemin ; le travail est terminé lorsqu’il est impossible d’utiliser ../ lors de l’enregistrement d’une pièce jointe pour sortir du répertoire choisi, tout en préservant le nom de fichier prévu.
Rédigé par le modèle d'indexation à partir du texte de l'issue.
Description
Description
Xreader 4.6.3 (commit ef5a50d) passes the raw PDF attachment filename directly to g_file_get_child() when saving attachments via "Save Attachment As...". Since g_file_get_child() resolves ../ sequences, an attacker-controlled filename can escape the user-selected target directory and write files to arbitrary locations with the exact filename specified by the attacker — no random suffix.
This is the most critical of the attachment vulnerabilities, as it enables writing .desktop files (or any other file) with precise names to arbitrary locations, leading to arbitrary code execution.
Affected Code
shell/ev-window.c:7374:
save_to = g_file_get_child(target_file, ev_attachment_get_name(attachment));
shell/ev-window.c:7400:
dest_file = g_file_get_child(target_file, ev_attachment_get_name(attachment));
Both the local and remote save paths use the unsanitized attachment name.
Steps to Reproduce
- Generate a malicious PDF using the PoC script from the full report — the attachment is named
../Desktop/test.desktopand contains a valid.desktopentry that executes an arbitrary command - Open
poc.pdfin xreader - In the sidebar, right-click the attachment and select "Save Attachment As..."
- Select any directory (e.g.,
~/Documents/) test.desktopis written to~/Desktop/instead of the selected directory- Double-clicking the
.desktopfile executes the embedded command
Suggested Fix
Extract the basename before passing to g_file_get_child() in both code paths:
// line 7374
-save_to = g_file_get_child(target_file, ev_attachment_get_name(attachment));
+gchar *basename = g_path_get_basename(ev_attachment_get_name(attachment));
+save_to = g_file_get_child(target_file, basename);
+g_free(basename);
// line 7400
-dest_file = g_file_get_child(target_file, ev_attachment_get_name(attachment));
+gchar *basename = g_path_get_basename(ev_attachment_get_name(attachment));
+dest_file = g_file_get_child(target_file, basename);
+g_free(basename);
Impact
An attacker can write files with exact names to arbitrary locations on the filesystem. By writing a .desktop file to ~/Desktop/, arbitrary code execution is achieved when the user double-clicks it. The only user interaction required is opening the PDF, right-clicking the attachment, selecting "Save As", and choosing any directory.
References
- Langage dominant
- C
- Étoiles
- 285
- Forks
- 82
- Métriques de merge des PR
- Aucune PR mergée en 30 j
Préparer son environnement
Ce projet ne fournit ni conteneur de développement, ni Dockerfile, ni guide de contribution : l'installation est à votre charge. Commencez par son README, et consultez notre guide de la première contribution pour les étapes générales.
Par où commencer
- Lisez l'issue en entier, puis le guide de contribution du projet.
- Signalez en commentaire que vous la prenez — cela évite que deux personnes fassent le même travail.
- Forkez le dépôt et travaillez sur une branche.
- Ouvrez une pull request qui référence le numéro de l'issue.
Autres issues de linuxmint/xreader
-
Cyrillic homoglyph characters used in place of ASCII <p> tags in Kazakh AppData description stringOuverte
Difficulté 1/5 Moins d'une heure Accessibilité débutants 88/100
-
Difficulté 4/5 3-5 jours Accessibilité débutants 38/100
-
Difficulté 4/5 3-5 jours Accessibilité débutants 45/100
-
Difficulté 3/5 1-2 jours Accessibilité débutants 55/100
-
Difficulté 3/5 1-2 jours Accessibilité débutants 48/100
Toutes les issues de linuxmint/xreader
Issues similaires
-
Policy query leaks host primary block (BSL_PrimaryBlock_deinit skipped) on two early-exit pathsOuverte
Difficulté 2/5 1-3 heures Accessibilité débutants 72/100
NASA-AMMOS/BSL#355 ·
Les mainteneurs répondent en général sous 1 jour
-
#242 leftovers: dated narrative and shas in the social-features test planPeut-être pris Une pull request liée à cette issue est ouverte ou déjà fusionnée. Ouverte
Difficulté 2/5 1-3 heures Accessibilité débutants 72/100
EchoTools/nevr-runtime#264 ·
Les mainteneurs répondent en général sous 1 jour
-
area/docdb kind/bug priority/medium status/awaiting-triage
Difficulté 2/5 1-3 heures Accessibilité débutants 82/100
yugabyte/yugabyte-db#34873 ·
Les mainteneurs répondent en général sous 1 jour
-
Difficulté 1/5 Moins d'une heure Accessibilité débutants 70/100
Les mainteneurs répondent en général sous 1 jour
-
[sqlcipher] update to 4.19.0Ouvertecategory:port-update
Difficulté 2/5 1-3 heures Accessibilité débutants 72/100
Les mainteneurs répondent en général sous 2 jours