[SECURITY] - An attacker can write files with exact names to arbitrary locations on the filesystem
Ninguém assumiu esta issue ainda.
Avaliação
- Dificuldade
- 2/5
- Tempo estimado
- 1-3 horas
- Facilidade para iniciantes
- 72/100
Direção de pesquisa
Leia shell/ev-window.c por volta das linhas 7374 e 7400 e acompanhe os caminhos de salvamento de anexos locais e remotos. Verifique como os nomes dos anexos são tratados em cada caminho; o trabalho estará concluído quando não for possível usar ../ ao salvar um anexo para sair do diretório escolhido, preservando o nome de arquivo pretendido.
Escrita pelo modelo de indexação a partir do texto da issue.
Descrição
Description
Xreader 4.6.3 (commit ef5a50d) passes the raw PDF attachment filename directly to g_file_get_child() when saving attachments via "Save Attachment As...". Since g_file_get_child() resolves ../ sequences, an attacker-controlled filename can escape the user-selected target directory and write files to arbitrary locations with the exact filename specified by the attacker — no random suffix.
This is the most critical of the attachment vulnerabilities, as it enables writing .desktop files (or any other file) with precise names to arbitrary locations, leading to arbitrary code execution.
Affected Code
shell/ev-window.c:7374:
save_to = g_file_get_child(target_file, ev_attachment_get_name(attachment));
shell/ev-window.c:7400:
dest_file = g_file_get_child(target_file, ev_attachment_get_name(attachment));
Both the local and remote save paths use the unsanitized attachment name.
Steps to Reproduce
- Generate a malicious PDF using the PoC script from the full report — the attachment is named
../Desktop/test.desktopand contains a valid.desktopentry that executes an arbitrary command - Open
poc.pdfin xreader - In the sidebar, right-click the attachment and select "Save Attachment As..."
- Select any directory (e.g.,
~/Documents/) test.desktopis written to~/Desktop/instead of the selected directory- Double-clicking the
.desktopfile executes the embedded command
Suggested Fix
Extract the basename before passing to g_file_get_child() in both code paths:
// line 7374
-save_to = g_file_get_child(target_file, ev_attachment_get_name(attachment));
+gchar *basename = g_path_get_basename(ev_attachment_get_name(attachment));
+save_to = g_file_get_child(target_file, basename);
+g_free(basename);
// line 7400
-dest_file = g_file_get_child(target_file, ev_attachment_get_name(attachment));
+gchar *basename = g_path_get_basename(ev_attachment_get_name(attachment));
+dest_file = g_file_get_child(target_file, basename);
+g_free(basename);
Impact
An attacker can write files with exact names to arbitrary locations on the filesystem. By writing a .desktop file to ~/Desktop/, arbitrary code execution is achieved when the user double-clicks it. The only user interaction required is opening the PDF, right-clicking the attachment, selecting "Save As", and choosing any directory.
References
- Linguagem predominante
- C
- Estrelas
- 285
- Forks
- 82
- Métricas de merge de PRs
- Nenhum PR com merge em 30d
Preparar o ambiente
Este projeto não oferece contêiner de desenvolvimento, Dockerfile nem guia de contribuição, então a configuração fica por sua conta: comece pelo README e veja nosso guia da primeira contribuição para os passos gerais.
Primeiros passos
- Leia a issue inteira e depois o guia de contribuição do projeto.
- Comente na issue dizendo que vai assumir — evita que duas pessoas façam o mesmo trabalho.
- Faça um fork do repositório e trabalhe em uma branch.
- Abra um pull request que referencie o número da issue.
Mais de linuxmint/xreader
-
Cyrillic homoglyph characters used in place of ASCII <p> tags in Kazakh AppData description stringAberta
Dificuldade 1/5 Menos de uma hora Facilidade para iniciantes 88/100
-
Dificuldade 4/5 3-5 dias Facilidade para iniciantes 38/100
-
Dificuldade 4/5 3-5 dias Facilidade para iniciantes 45/100
-
Dificuldade 3/5 1-2 dias Facilidade para iniciantes 55/100
-
Dificuldade 3/5 1-2 dias Facilidade para iniciantes 48/100
Todas as issues de linuxmint/xreader
Issues semelhantes
-
[P2] Workspace updates silently ignore forbidden assignments while staging the rowTalvez já em andamento Um pull request vinculado a esta issue está aberto ou já foi mesclado. Aberta
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 78/100
Mantenedores costumam responder em até 1 dia
-
Dificuldade 1/5 Menos de uma hora Facilidade para iniciantes 70/100
Mantenedores costumam responder em até 4 dias
-
sdl3-image update to 3.4.8Abertacategory:port-update
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 72/100
microsoft/vcpkg#54338 · 1 comentário ·
Mantenedores costumam responder em até 2 dias
-
area:http-gateway good first issue priority:low type:docs
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 88/100
crazy-goat/php-fpm-ng#828 ·
Mantenedores costumam responder em até 1 dia
-
enhancement
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 63/100
SunDevilRocketry/Flight-Computer-Firmware#347 ·
Mantenedores costumam responder em até 3 dias