diff --git a/runtime/autoload/tar.vim b/runtime/autoload/tar.vim index a3abbc7..c8d5d03 100644 --- a/runtime/autoload/tar.vim +++ b/runtime/autoload/tar.vim @@ -780,9 +780,9 @@ fun! tar#Vimuntar(...) " if necessary, decompress the tarball; then, extract it if tartail =~ '\.tgz' if executable("gunzip") - silent exe "!gunzip ".shellescape(tartail) + silent exe "!gunzip ".shellescape(tartail, 1) elseif executable("gzip") - silent exe "!gzip -d ".shellescape(tartail) + silent exe "!gzip -d ".shellescape(tartail, 1) else echoerr "unable to decompress<".tartail."> on this system" if simplify(curdir) != simplify(tarhome) diff --git a/src/testdir/Make_all.mak b/src/testdir/Make_all.mak index 8dd04e7..2b3d16d 100644 --- a/src/testdir/Make_all.mak +++ b/src/testdir/Make_all.mak @@ -227,6 +227,7 @@ NEW_TESTS = \ test_partial \ test_paste \ test_perl \ + test_plugin_tar \ test_plus_arg_edit \ test_popup \ test_popupwin \ @@ -476,6 +477,7 @@ NEW_TESTS_RES = \ test_partial.res \ test_paste.res \ test_perl.res \ + test_plugin_tar.res \ test_plus_arg_edit.res \ test_popup.res \ test_popupwin.res \ diff --git a/src/testdir/test_plugin_tar.vim b/src/testdir/test_plugin_tar.vim new file mode 100644 index 0000000..5e712df --- /dev/null +++ b/src/testdir/test_plugin_tar.vim @@ -0,0 +1,25 @@ +vim9script + +source check.vim +CheckNotMSWindows + +runtime plugin/tarPlugin.vim + +def g:Test_extract_command_injection() + CheckExecutable gunzip + CheckExecutable touch + var tgz = eval('0z1F8B08087795056A000364756D6D792E74617200EDCE2B12C2300004D01C254' .. + '7480269CE534080A8495BD1DBF3996106C3A08A7ACFACD8157B59A7690BFB4A0FC3707C666E357D' .. + 'E65BC8B5A47CC8A5D61A522EA5B510D3CEBF5ED679197B8CE17CEDB7F9D4C76FBB5F3D000000000' .. + '000000000FCD11D32415E2C00280000') + var dirname = tempname() + + mkdir(dirname, 'R') + var tar = dirname .. "/';%$(touch pwned)'.tgz" + writefile(tgz, tar) + new + exe "e " .. fnameescape(tar) + exe ":Vimuntar " .. dirname + assert_false(filereadable(dirname .. "/pwned")) + bw! +enddef