Skip to content

Reject unsafe paths while extracting add-on ZIPs - #5817

Open
acts-1631 wants to merge 1 commit into
supertuxkart:masterfrom
acts-1631:fix-addon-archive-paths
Open

Reject unsafe paths while extracting add-on ZIPs#5817
acts-1631 wants to merge 1 commit into
supertuxkart:masterfrom
acts-1631:fix-addon-archive-paths

Conversation

@acts-1631

Copy link
Copy Markdown

Add-on ZIP files are extracted recursively by extract_zip(). Archive member names were appended to the extraction directory without rejecting traversal components, allowing a ZIP entry with .. components to write outside the add-on tree.

Validate recursive member names before creating their parent directory or opening the output file. The check rejects absolute, drive-qualified, empty, dot, and dot-dot path components while preserving normal nested add-on files.

ZIP member names were appended directly to the add-on destination.

A member containing traversal components could write outside that directory.

Reject absolute, drive-qualified, empty, dot, and dot-dot path

components before creating any directories or files.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant