68 lines
2.0 KiB
Diff
68 lines
2.0 KiB
Diff
diff --git a/runtime/autoload/tar.vim b/runtime/autoload/tar.vim
|
|
index a3abbc7..c8d5d03 100644
|
|
--- a/runtime/autoload/tar.vim
|
|
+++ b/runtime/autoload/tar.vim
|
|
@@ -780,9 +780,9 @@ fun! tar#Vimuntar(...)
|
|
" if necessary, decompress the tarball; then, extract it
|
|
if tartail =~ '\.tgz'
|
|
if executable("gunzip")
|
|
- silent exe "!gunzip ".shellescape(tartail)
|
|
+ silent exe "!gunzip ".shellescape(tartail, 1)
|
|
elseif executable("gzip")
|
|
- silent exe "!gzip -d ".shellescape(tartail)
|
|
+ silent exe "!gzip -d ".shellescape(tartail, 1)
|
|
else
|
|
echoerr "unable to decompress<".tartail."> on this system"
|
|
if simplify(curdir) != simplify(tarhome)
|
|
diff --git a/src/testdir/Make_all.mak b/src/testdir/Make_all.mak
|
|
index 8dd04e7..2b3d16d 100644
|
|
--- a/src/testdir/Make_all.mak
|
|
+++ b/src/testdir/Make_all.mak
|
|
@@ -227,6 +227,7 @@ NEW_TESTS = \
|
|
test_partial \
|
|
test_paste \
|
|
test_perl \
|
|
+ test_plugin_tar \
|
|
test_plus_arg_edit \
|
|
test_popup \
|
|
test_popupwin \
|
|
@@ -476,6 +477,7 @@ NEW_TESTS_RES = \
|
|
test_partial.res \
|
|
test_paste.res \
|
|
test_perl.res \
|
|
+ test_plugin_tar.res \
|
|
test_plus_arg_edit.res \
|
|
test_popup.res \
|
|
test_popupwin.res \
|
|
diff --git a/src/testdir/test_plugin_tar.vim b/src/testdir/test_plugin_tar.vim
|
|
new file mode 100644
|
|
index 0000000..5e712df
|
|
--- /dev/null
|
|
+++ b/src/testdir/test_plugin_tar.vim
|
|
@@ -0,0 +1,25 @@
|
|
+vim9script
|
|
+
|
|
+source check.vim
|
|
+CheckNotMSWindows
|
|
+
|
|
+runtime plugin/tarPlugin.vim
|
|
+
|
|
+def g:Test_extract_command_injection()
|
|
+ CheckExecutable gunzip
|
|
+ CheckExecutable touch
|
|
+ var tgz = eval('0z1F8B08087795056A000364756D6D792E74617200EDCE2B12C2300004D01C254' ..
|
|
+ '7480269CE534080A8495BD1DBF3996106C3A08A7ACFACD8157B59A7690BFB4A0FC3707C666E357D' ..
|
|
+ 'E65BC8B5A47CC8A5D61A522EA5B510D3CEBF5ED679197B8CE17CEDB7F9D4C76FBB5F3D000000000' ..
|
|
+ '000000000FCD11D32415E2C00280000')
|
|
+ var dirname = tempname()
|
|
+
|
|
+ mkdir(dirname, 'R')
|
|
+ var tar = dirname .. "/';%$(touch pwned)'.tgz"
|
|
+ writefile(tgz, tar)
|
|
+ new
|
|
+ exe "e " .. fnameescape(tar)
|
|
+ exe ":Vimuntar " .. dirname
|
|
+ assert_false(filereadable(dirname .. "/pwned"))
|
|
+ bw!
|
|
+enddef
|