92 lines
2.9 KiB
Diff
92 lines
2.9 KiB
Diff
From a51ca3f97ec9362366c918d37905b3a083eff82e Mon Sep 17 00:00:00 2001
|
|
From: Christian Brabandt <cb@256bit.org>
|
|
Date: Thu, 14 May 2026 15:35:28 +0000
|
|
Subject: [PATCH] patch 9.2.0479: [security]: runtime(tar): command injection
|
|
in tar plugin
|
|
|
|
Problem: [security]: runtime(tar): command injection in tar plugin
|
|
(Christopher Lusk)
|
|
Solution: Use the correct shellescape(args, 1) form for a :! command
|
|
|
|
Github Advisory:
|
|
https://github.com/vim/vim/security/advisories/GHSA-2fpv-9ff7-xg5w
|
|
|
|
Signed-off-by: Christian Brabandt <cb@256bit.org>
|
|
---
|
|
runtime/autoload/tar.vim | 4 ++--
|
|
src/testdir/Make_all.mak | 2 ++
|
|
src/testdir/test_plugin_tar.vim | 24 ++++++++++++++++++++++++
|
|
3 files changed, 28 insertions(+), 2 deletions(-)
|
|
create mode 100644 src/testdir/test_plugin_tar.vim
|
|
|
|
diff --git a/runtime/autoload/tar.vim b/runtime/autoload/tar.vim
|
|
index 13df5790a..ef7b21499 100644
|
|
--- a/runtime/autoload/tar.vim
|
|
+++ b/runtime/autoload/tar.vim
|
|
@@ -774,9 +774,9 @@ fun! tar#Vimuntar(...)
|
|
" if necessary, decompress the tarball; then, extract it
|
|
if tartail =~ '\.tgz'
|
|
if executable("gunzip")
|
|
- silent exe "!gunzip ".shellescape(tartail)
|
|
+ silent exe "!gunzip ".shellescape(tartail, 1)
|
|
elseif executable("gzip")
|
|
- silent exe "!gzip -d ".shellescape(tartail)
|
|
+ silent exe "!gzip -d ".shellescape(tartail, 1)
|
|
else
|
|
echoerr "unable to decompress<".tartail."> on this sytem"
|
|
if simplify(curdir) != simplify(tarhome)
|
|
diff --git a/src/testdir/Make_all.mak b/src/testdir/Make_all.mak
|
|
index 111111111..222222222 100644
|
|
--- a/src/testdir/Make_all.mak
|
|
+++ b/src/testdir/Make_all.mak
|
|
@@ -209,6 +209,7 @@ NEW_TESTS = \
|
|
test_paste \
|
|
test_perl \
|
|
+ test_plugin_tar \
|
|
test_plus_arg_edit \
|
|
test_popup \
|
|
test_popupwin \
|
|
test_popupwin_textprop \
|
|
@@ -447,6 +448,7 @@ NEW_TESTS_RES = \
|
|
test_paste.res \
|
|
test_perl.res \
|
|
+ test_plugin_tar.res \
|
|
test_plus_arg_edit.res \
|
|
test_popup.res \
|
|
test_popupwin.res \
|
|
test_popupwin_textprop.res \
|
|
diff --git a/src/testdir/test_plugin_tar.vim b/src/testdir/test_plugin_tar.vim
|
|
new file mode 100644
|
|
index 000000000..000000001
|
|
--- /dev/null
|
|
+++ b/src/testdir/test_plugin_tar.vim
|
|
@@ -0,0 +1,25 @@
|
|
+vim9script
|
|
+
|
|
+source check.vim
|
|
+CheckNotMSWindows
|
|
+
|
|
+runtime plugin/tarPlugin.vim
|
|
+
|
|
+def g:Test_extract_command_injection()
|
|
+ CheckExecutable gunzip
|
|
+ CheckExecutable touch
|
|
+ var tgz = eval('0z1F8B08087795056A000364756D6D792E74617200EDCE2B12C2300004D01C254' ..
|
|
+ '7480269CE534080A8495BD1DBF3996106C3A08A7ACFACD8157B59A7690BFB4A0FC3707C666E357D' ..
|
|
+ 'E65BC8B5A47CC8A5D61A522EA5B510D3CEBF5ED679197B8CE17CEDB7F9D4C76FBB5F3D000000000' ..
|
|
+ '000000000FCD11D32415E2C00280000')
|
|
+ var dirname = tempname()
|
|
+
|
|
+ mkdir(dirname, 'R')
|
|
+ var tar = dirname .. "/';%$(touch pwned)'.tgz"
|
|
+ writefile(tgz, tar)
|
|
+ new
|
|
+ exe "e " .. fnameescape(tar)
|
|
+ exe ":Vimuntar " .. dirname
|
|
+ assert_false(filereadable(dirname .. "/pwned"))
|
|
+ bw!
|
|
+enddef
|
|
--
|
|
2.52.0
|
|
|