[SECURITY] - An attacker can write files with exact names to arbitrary locations on the filesystem
还没有人认领这个 Issue。
评估
调研方向
阅读 shell/ev-window.c 第 7374 行和第 7400 行附近的代码,并追踪本地和远程附件保存路径。检查每条路径如何处理附件名称;完成标准是保存附件时无法使用 ../ 逃出所选目录,同时保留预期的文件名。
由索引模型根据 Issue 内容生成。
描述
Description
Xreader 4.6.3 (commit ef5a50d) passes the raw PDF attachment filename directly to g_file_get_child() when saving attachments via "Save Attachment As...". Since g_file_get_child() resolves ../ sequences, an attacker-controlled filename can escape the user-selected target directory and write files to arbitrary locations with the exact filename specified by the attacker — no random suffix.
This is the most critical of the attachment vulnerabilities, as it enables writing .desktop files (or any other file) with precise names to arbitrary locations, leading to arbitrary code execution.
Affected Code
shell/ev-window.c:7374:
save_to = g_file_get_child(target_file, ev_attachment_get_name(attachment));
shell/ev-window.c:7400:
dest_file = g_file_get_child(target_file, ev_attachment_get_name(attachment));
Both the local and remote save paths use the unsanitized attachment name.
Steps to Reproduce
- Generate a malicious PDF using the PoC script from the full report — the attachment is named
../Desktop/test.desktopand contains a valid.desktopentry that executes an arbitrary command - Open
poc.pdfin xreader - In the sidebar, right-click the attachment and select "Save Attachment As..."
- Select any directory (e.g.,
~/Documents/) test.desktopis written to~/Desktop/instead of the selected directory- Double-clicking the
.desktopfile executes the embedded command
Suggested Fix
Extract the basename before passing to g_file_get_child() in both code paths:
// line 7374
-save_to = g_file_get_child(target_file, ev_attachment_get_name(attachment));
+gchar *basename = g_path_get_basename(ev_attachment_get_name(attachment));
+save_to = g_file_get_child(target_file, basename);
+g_free(basename);
// line 7400
-dest_file = g_file_get_child(target_file, ev_attachment_get_name(attachment));
+gchar *basename = g_path_get_basename(ev_attachment_get_name(attachment));
+dest_file = g_file_get_child(target_file, basename);
+g_free(basename);
Impact
An attacker can write files with exact names to arbitrary locations on the filesystem. By writing a .desktop file to ~/Desktop/, arbitrary code execution is achieved when the user double-clicks it. The only user interaction required is opening the PDF, right-clicking the attachment, selecting "Save As", and choosing any directory.
References
- 主要语言
- C
- 星标
- 285
- 派生
- 82
- PR 合并指标
- 30 天内没有已合并 PR
环境准备
这个项目没有提供开发容器、Dockerfile 或贡献指南,环境需要你自己搭建:先看它的 README,通用步骤见我们的新手贡献指南。
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
linuxmint/xreader 的其他 Issue
-
Cyrillic homoglyph characters used in place of ASCII <p> tags in Kazakh AppData description string未关闭
难度 1/5 1 小时以内 新手友好度 88/100
-
难度 4/5 3-5 天 新手友好度 38/100
-
难度 4/5 3-5 天 新手友好度 45/100
-
难度 3/5 1-2 天 新手友好度 55/100
-
难度 3/5 1-2 天 新手友好度 48/100
查看 linuxmint/xreader 的全部 Issue
相似的 Issue
-
难度 2/5 1-3 小时 新手友好度 82/100
openwrt/firmware-utils#82 ·
-
area:http-gateway good first issue priority:low type:bug
难度 2/5 1-3 小时 新手友好度 78/100
crazy-goat/php-fpm-ng#870 ·
维护者通常 1 天内回复
-
Discover carries headerEdges that nothing reads since #1914 moved E0507/E0517 to the compiler graph未关闭tech-debt
难度 2/5 1-3 小时 新手友好度 84/100
维护者通常 1 天内回复
-
2个显示的问题未关闭
难度 2/5 1-3 小时 新手友好度 62/100
coolsnowwolf/lede#14209 ·
-
难度 1/5 1 小时以内 新手友好度 75/100
polhenarejos/pico-hsm#147 ·