Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

[SECURITY] - An attacker can write files with exact names to arbitrary locations on the filesystem

Đang mở Phù hợp với người mới
#714 5 bình luận 0 reaction 0 người được giao Xem trên GitHub

Chưa có ai nhận issue này.

Đánh giá

Độ khó
2/5
Thời gian dự kiến
1-3 giờ
Mức phù hợp với người mới
72/100
Loại issue
Lỗi
Độ rõ ràng
Đặc tả rõ ràng
Mức độ hoạt động
Sôi nổi
Công nghệ
c
Lĩnh vực
desktop, security

Hướng nghiên cứu

Đọc shell/ev-window.c quanh dòng 7374 và 7400, rồi lần theo các đường dẫn lưu tệp đính kèm cục bộ và từ xa. Kiểm tra cách tên tệp đính kèm được xử lý trong từng đường dẫn; công việc hoàn tất khi không thể dùng ../ để thoát khỏi thư mục đã chọn trong lúc lưu tệp đính kèm, đồng thời vẫn giữ nguyên tên tệp dự định.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

Description

Xreader 4.6.3 (commit ef5a50d) passes the raw PDF attachment filename directly to g_file_get_child() when saving attachments via "Save Attachment As...". Since g_file_get_child() resolves ../ sequences, an attacker-controlled filename can escape the user-selected target directory and write files to arbitrary locations with the exact filename specified by the attacker — no random suffix.

This is the most critical of the attachment vulnerabilities, as it enables writing .desktop files (or any other file) with precise names to arbitrary locations, leading to arbitrary code execution.

Affected Code

shell/ev-window.c:7374:

save_to = g_file_get_child(target_file, ev_attachment_get_name(attachment));

shell/ev-window.c:7400:

dest_file = g_file_get_child(target_file, ev_attachment_get_name(attachment));

Both the local and remote save paths use the unsanitized attachment name.

Steps to Reproduce

  1. Generate a malicious PDF using the PoC script from the full report — the attachment is named ../Desktop/test.desktop and contains a valid .desktop entry that executes an arbitrary command
  2. Open poc.pdf in xreader
  3. In the sidebar, right-click the attachment and select "Save Attachment As..."
  4. Select any directory (e.g., ~/Documents/)
  5. test.desktop is written to ~/Desktop/ instead of the selected directory
  6. Double-clicking the .desktop file executes the embedded command

Suggested Fix

Extract the basename before passing to g_file_get_child() in both code paths:

// line 7374
-save_to = g_file_get_child(target_file, ev_attachment_get_name(attachment));
+gchar *basename = g_path_get_basename(ev_attachment_get_name(attachment));
+save_to = g_file_get_child(target_file, basename);
+g_free(basename);

// line 7400
-dest_file = g_file_get_child(target_file, ev_attachment_get_name(attachment));
+gchar *basename = g_path_get_basename(ev_attachment_get_name(attachment));
+dest_file = g_file_get_child(target_file, basename);
+g_free(basename);

Impact

An attacker can write files with exact names to arbitrary locations on the filesystem. By writing a .desktop file to ~/Desktop/, arbitrary code execution is achieved when the user double-clicks it. The only user interaction required is opening the PDF, right-clicking the attachment, selecting "Save As", and choosing any directory.

References

Ngôn ngữ chính
C
Star
285
Fork
82
Chỉ số merge pull request
Không có pull request nào được merge trong 30 ngày

Chuẩn bị môi trường

Dự án này không cung cấp dev container, Dockerfile hay hướng dẫn đóng góp, nên bạn cần tự thiết lập môi trường: hãy bắt đầu từ README và xem hướng dẫn đóng góp lần đầu của chúng tôi để biết các bước chung.

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của linuxmint/xreader

Tất cả issue của linuxmint/xreader

Issue tương tự

Thêm issue về C

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.