Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

[SECURITY] - An attacker can write files with exact names to arbitrary locations on the filesystem

未关闭 适合新手
#714 5 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

还没有人认领这个 Issue。

评估

难度
2/5
预计耗时
1-3 小时
新手友好度
72/100
Issue 类型
缺陷
描述清晰度
描述清楚
活跃度
活跃
技术栈
c
领域
desktop, security

调研方向

阅读 shell/ev-window.c 第 7374 行和第 7400 行附近的代码,并追踪本地和远程附件保存路径。检查每条路径如何处理附件名称;完成标准是保存附件时无法使用 ../ 逃出所选目录,同时保留预期的文件名。

由索引模型根据 Issue 内容生成。

描述

Description

Xreader 4.6.3 (commit ef5a50d) passes the raw PDF attachment filename directly to g_file_get_child() when saving attachments via "Save Attachment As...". Since g_file_get_child() resolves ../ sequences, an attacker-controlled filename can escape the user-selected target directory and write files to arbitrary locations with the exact filename specified by the attacker — no random suffix.

This is the most critical of the attachment vulnerabilities, as it enables writing .desktop files (or any other file) with precise names to arbitrary locations, leading to arbitrary code execution.

Affected Code

shell/ev-window.c:7374:

save_to = g_file_get_child(target_file, ev_attachment_get_name(attachment));

shell/ev-window.c:7400:

dest_file = g_file_get_child(target_file, ev_attachment_get_name(attachment));

Both the local and remote save paths use the unsanitized attachment name.

Steps to Reproduce

  1. Generate a malicious PDF using the PoC script from the full report — the attachment is named ../Desktop/test.desktop and contains a valid .desktop entry that executes an arbitrary command
  2. Open poc.pdf in xreader
  3. In the sidebar, right-click the attachment and select "Save Attachment As..."
  4. Select any directory (e.g., ~/Documents/)
  5. test.desktop is written to ~/Desktop/ instead of the selected directory
  6. Double-clicking the .desktop file executes the embedded command

Suggested Fix

Extract the basename before passing to g_file_get_child() in both code paths:

// line 7374
-save_to = g_file_get_child(target_file, ev_attachment_get_name(attachment));
+gchar *basename = g_path_get_basename(ev_attachment_get_name(attachment));
+save_to = g_file_get_child(target_file, basename);
+g_free(basename);

// line 7400
-dest_file = g_file_get_child(target_file, ev_attachment_get_name(attachment));
+gchar *basename = g_path_get_basename(ev_attachment_get_name(attachment));
+dest_file = g_file_get_child(target_file, basename);
+g_free(basename);

Impact

An attacker can write files with exact names to arbitrary locations on the filesystem. By writing a .desktop file to ~/Desktop/, arbitrary code execution is achieved when the user double-clicks it. The only user interaction required is opening the PDF, right-clicking the attachment, selecting "Save As", and choosing any directory.

References

主要语言
C
星标
285
派生
82
PR 合并指标
30 天内没有已合并 PR

环境准备

这个项目没有提供开发容器、Dockerfile 或贡献指南,环境需要你自己搭建:先看它的 README,通用步骤见我们的新手贡献指南。

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

linuxmint/xreader 的其他 Issue

查看 linuxmint/xreader 的全部 Issue

相似的 Issue

更多 C Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。