[SECURITY] - An attacker can write files with exact names to arbitrary locations on the filesystem
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 2/5
- Tempo stimato
- 1-3 ore
- Idoneità per principianti
- 72/100
Direzione di ricerca
Leggi shell/ev-window.c intorno alle righe 7374 e 7400 e segui i percorsi di salvataggio degli allegati locali e remoti. Controlla come vengono gestiti i nomi degli allegati in ciascun percorso; il lavoro è completato quando, salvando un allegato, non è possibile usare ../ per uscire dalla directory scelta, preservando il nome del file previsto.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Description
Xreader 4.6.3 (commit ef5a50d) passes the raw PDF attachment filename directly to g_file_get_child() when saving attachments via "Save Attachment As...". Since g_file_get_child() resolves ../ sequences, an attacker-controlled filename can escape the user-selected target directory and write files to arbitrary locations with the exact filename specified by the attacker — no random suffix.
This is the most critical of the attachment vulnerabilities, as it enables writing .desktop files (or any other file) with precise names to arbitrary locations, leading to arbitrary code execution.
Affected Code
shell/ev-window.c:7374:
save_to = g_file_get_child(target_file, ev_attachment_get_name(attachment));
shell/ev-window.c:7400:
dest_file = g_file_get_child(target_file, ev_attachment_get_name(attachment));
Both the local and remote save paths use the unsanitized attachment name.
Steps to Reproduce
- Generate a malicious PDF using the PoC script from the full report — the attachment is named
../Desktop/test.desktopand contains a valid.desktopentry that executes an arbitrary command - Open
poc.pdfin xreader - In the sidebar, right-click the attachment and select "Save Attachment As..."
- Select any directory (e.g.,
~/Documents/) test.desktopis written to~/Desktop/instead of the selected directory- Double-clicking the
.desktopfile executes the embedded command
Suggested Fix
Extract the basename before passing to g_file_get_child() in both code paths:
// line 7374
-save_to = g_file_get_child(target_file, ev_attachment_get_name(attachment));
+gchar *basename = g_path_get_basename(ev_attachment_get_name(attachment));
+save_to = g_file_get_child(target_file, basename);
+g_free(basename);
// line 7400
-dest_file = g_file_get_child(target_file, ev_attachment_get_name(attachment));
+gchar *basename = g_path_get_basename(ev_attachment_get_name(attachment));
+dest_file = g_file_get_child(target_file, basename);
+g_free(basename);
Impact
An attacker can write files with exact names to arbitrary locations on the filesystem. By writing a .desktop file to ~/Desktop/, arbitrary code execution is achieved when the user double-clicks it. The only user interaction required is opening the PDF, right-clicking the attachment, selecting "Save As", and choosing any directory.
References
- Lingua principale
- C
- Stelle
- 285
- Fork
- 82
- Metriche di merge delle PR
- Nessuna PR unita negli ultimi 30g
Preparare l'ambiente
Questo progetto non fornisce container di sviluppo, Dockerfile né guida per i contributori, quindi l'ambiente è a tuo carico: parti dal suo README e consulta la nostra guida al primo contributo per i passaggi generali.
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di linuxmint/xreader
-
Cyrillic homoglyph characters used in place of ASCII <p> tags in Kazakh AppData description stringAperta
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 88/100
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 38/100
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 45/100
-
Difficoltà 3/5 1-2 giorni Idoneità per principianti 55/100
-
Difficoltà 3/5 1-2 giorni Idoneità per principianti 48/100
Tutte le issue di linuxmint/xreader
Issue simili
-
area:http-gateway good first issue priority:low type:docs
Difficoltà 2/5 1-3 ore Idoneità per principianti 88/100
crazy-goat/php-fpm-ng#828 ·
I maintainer di solito rispondono entro 1 giorno
-
area:docs good first issue type:docs
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 92/100
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
-
CVE-2026-18839 popt: size_t underflow in `singleOptionHelp`Forse già presa @pmatilai l’ha presa 34 giorni fa. Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 70/100
rpm-software-management/popt#143 ·
-
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 85/100