pjfanning opened a new pull request, #1348:
URL: https://github.com/apache/poi/pull/1348
`Msg2txt.processAttachment` writes each attachment to a path built directly
from the message:
```java
String fileName = attachment.getAttachFileName().toString();
if (attachment.getAttachLongFileName() != null) {
fileName = attachment.getAttachLongFileName().toString();
}
File f = new File(dir, fileName);
try (OutputStream fileOut = new FileOutputStream(f)) {
fileOut.write(attachment.getAttachData().getValue());
}
```
`PR_ATTACH_LONG_FILENAME` / `PR_ATTACH_FILENAME` are attacker controlled and
never normalized, so a crafted `.msg` file can write outside the directory the
caller nominated.
Now routed through `IOUtils.newFile`, the project's designated traversal
guard — the same one `HMEFContentsExtractor` uses for TNEF attachments (since
#1066) and `VBAMacroExtractor` uses for extracted modules.
### Context
Found while checking a security report filed against
`HMEFContentsExtractor.extractAttachments`. That report is **already fixed on
trunk** by #1066, which added the `IOUtils.newFile` guard there. This is the
same defect class at a sink that fix did not cover.
I swept the other `new File(dir, name)` write sinks at the same time; the
rest are already safe:
| Site | Why it's safe |
|---|---|
| `VBAMacroExtractor` | uses `IOUtils.newFile` |
| `VsdxToPng`, `HierarchyPrinter` | `Util.sanitizeFilename` replaces every
path separator |
| `PPTX2PNG` | `new File(filename).getName()` drops any directory component |
| `HMEFContentsExtractor` (`message.rtf`) | constant name |
🤖 Generated with [Claude Code](https://claude.com/claude-code)
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]