aboutsummaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorDenys Vlasenko <vda.linux@googlemail.com>2017-07-24 17:20:13 +0200
committerDenys Vlasenko <vda.linux@googlemail.com>2017-07-24 17:20:13 +0200
commitb920a38dc0a87f5884444d4731a8b887b5e16018 (patch)
tree5d845976a9471e705183db9afbbe7885e9070b52
parentc810978552bc0133ba723ababaa178c8d53256e1 (diff)
downloadbusybox-w32-b920a38dc0a87f5884444d4731a8b887b5e16018.tar.gz
busybox-w32-b920a38dc0a87f5884444d4731a8b887b5e16018.tar.bz2
busybox-w32-b920a38dc0a87f5884444d4731a8b887b5e16018.zip
tar: postpone creation of symlinks with "suspicious" targets. Closes 8411
function old new delta data_extract_all 968 1038 +70 tar_main 952 986 +34 scan_tree 258 262 +4 ------------------------------------------------------------------------------ (add/remove: 0/0 grow/shrink: 3/0 up/down: 108/0) Total: 108 bytes Signed-off-by: Denys Vlasenko <vda.linux@googlemail.com>
-rw-r--r--archival/libarchive/data_extract_all.c42
-rw-r--r--archival/tar.c37
-rwxr-xr-xarchival/tar_symlink_attack16
-rw-r--r--coreutils/link.c2
-rw-r--r--include/bb_archive.h4
-rwxr-xr-xtestsuite/tar.tests65
6 files changed, 130 insertions, 36 deletions
diff --git a/archival/libarchive/data_extract_all.c b/archival/libarchive/data_extract_all.c
index 1830ffb8d..1ce927c2f 100644
--- a/archival/libarchive/data_extract_all.c
+++ b/archival/libarchive/data_extract_all.c
@@ -128,10 +128,11 @@ void FAST_FUNC data_extract_all(archive_handle_t *archive_handle)
128 res = link(hard_link, dst_name); 128 res = link(hard_link, dst_name);
129 if (res != 0 && !(archive_handle->ah_flags & ARCHIVE_EXTRACT_QUIET)) { 129 if (res != 0 && !(archive_handle->ah_flags & ARCHIVE_EXTRACT_QUIET)) {
130 /* shared message */ 130 /* shared message */
131 bb_perror_msg("can't create %slink " 131 bb_perror_msg("can't create %slink '%s' to '%s'",
132 "%s to %s", "hard", 132 "hard",
133 dst_name, 133 dst_name,
134 hard_link); 134 hard_link
135 );
135 } 136 }
136 /* Hardlinks have no separate mode/ownership, skip chown/chmod */ 137 /* Hardlinks have no separate mode/ownership, skip chown/chmod */
137 goto ret; 138 goto ret;
@@ -178,15 +179,44 @@ void FAST_FUNC data_extract_all(archive_handle_t *archive_handle)
178 case S_IFLNK: 179 case S_IFLNK:
179 /* Symlink */ 180 /* Symlink */
180//TODO: what if file_header->link_target == NULL (say, corrupted tarball?) 181//TODO: what if file_header->link_target == NULL (say, corrupted tarball?)
182
183 /* To avoid a directory traversal attack via symlinks,
184 * for certain link targets postpone creation of symlinks.
185 *
186 * For example, consider a .tar created via:
187 * $ tar cvf bug.tar anything.txt
188 * $ ln -s /tmp symlink
189 * $ tar --append -f bug.tar symlink
190 * $ rm symlink
191 * $ mkdir symlink
192 * $ tar --append -f bug.tar symlink/evil.py
193 *
194 * This will result in an archive that contains:
195 * $ tar --list -f bug.tar
196 * anything.txt
197 * symlink [-> /tmp]
198 * symlink/evil.py
199 *
200 * Untarring bug.tar would otherwise place evil.py in '/tmp'.
201 */
202 if (file_header->link_target[0] == '/'
203 || strstr(file_header->link_target, "..")
204 ) {
205 llist_add_to(&archive_handle->symlink_placeholders,
206 xasprintf("%s%c%s", file_header->name, '\0', file_header->link_target)
207 );
208 break;
209 }
181 res = symlink(file_header->link_target, dst_name); 210 res = symlink(file_header->link_target, dst_name);
182 if (res != 0 211 if (res != 0
183 && !(archive_handle->ah_flags & ARCHIVE_EXTRACT_QUIET) 212 && !(archive_handle->ah_flags & ARCHIVE_EXTRACT_QUIET)
184 ) { 213 ) {
185 /* shared message */ 214 /* shared message */
186 bb_perror_msg("can't create %slink " 215 bb_perror_msg("can't create %slink '%s' to '%s'",
187 "%s to %s", "sym", 216 "sym",
188 dst_name, 217 dst_name,
189 file_header->link_target); 218 file_header->link_target
219 );
190 } 220 }
191 break; 221 break;
192 case S_IFSOCK: 222 case S_IFSOCK:
diff --git a/archival/tar.c b/archival/tar.c
index 0fc574dfd..280ded4e1 100644
--- a/archival/tar.c
+++ b/archival/tar.c
@@ -22,24 +22,6 @@
22 * 22 *
23 * Licensed under GPLv2 or later, see file LICENSE in this source tree. 23 * Licensed under GPLv2 or later, see file LICENSE in this source tree.
24 */ 24 */
25/* TODO: security with -C DESTDIR option can be enhanced.
26 * Consider tar file created via:
27 * $ tar cvf bug.tar anything.txt
28 * $ ln -s /tmp symlink
29 * $ tar --append -f bug.tar symlink
30 * $ rm symlink
31 * $ mkdir symlink
32 * $ tar --append -f bug.tar symlink/evil.py
33 *
34 * This will result in an archive which contains:
35 * $ tar --list -f bug.tar
36 * anything.txt
37 * symlink
38 * symlink/evil.py
39 *
40 * Untarring it puts evil.py in '/tmp' even if the -C DESTDIR is given.
41 * This doesn't feel right, and IIRC GNU tar doesn't do that.
42 */
43 25
44//config:config TAR 26//config:config TAR
45//config: bool "tar (40 kb)" 27//config: bool "tar (40 kb)"
@@ -296,6 +278,23 @@ static void chksum_and_xwrite(int fd, struct tar_header_t* hp)
296 xwrite(fd, hp, sizeof(*hp)); 278 xwrite(fd, hp, sizeof(*hp));
297} 279}
298 280
281static void replace_symlink_placeholders(llist_t *list)
282{
283 while (list) {
284 char *target;
285
286 target = list->data + strlen(list->data) + 1;
287 if (symlink(target, list->data)) {
288 /* shared message */
289 bb_error_msg_and_die("can't create %slink '%s' to '%s'",
290 "sym",
291 list->data, target
292 );
293 }
294 list = list->link;
295 }
296}
297
299#if ENABLE_FEATURE_TAR_GNU_EXTENSIONS 298#if ENABLE_FEATURE_TAR_GNU_EXTENSIONS
300static void writeLongname(int fd, int type, const char *name, int dir) 299static void writeLongname(int fd, int type, const char *name, int dir)
301{ 300{
@@ -1252,6 +1251,8 @@ int tar_main(int argc UNUSED_PARAM, char **argv)
1252 while (get_header_tar(tar_handle) == EXIT_SUCCESS) 1251 while (get_header_tar(tar_handle) == EXIT_SUCCESS)
1253 bb_got_signal = EXIT_SUCCESS; /* saw at least one header, good */ 1252 bb_got_signal = EXIT_SUCCESS; /* saw at least one header, good */
1254 1253
1254 replace_symlink_placeholders(tar_handle->symlink_placeholders);
1255
1255 /* Check that every file that should have been extracted was */ 1256 /* Check that every file that should have been extracted was */
1256 while (tar_handle->accept) { 1257 while (tar_handle->accept) {
1257 if (!find_list_entry(tar_handle->reject, tar_handle->accept->data) 1258 if (!find_list_entry(tar_handle->reject, tar_handle->accept->data)
diff --git a/archival/tar_symlink_attack b/archival/tar_symlink_attack
new file mode 100755
index 000000000..35455f200
--- /dev/null
+++ b/archival/tar_symlink_attack
@@ -0,0 +1,16 @@
1#!/bin/sh
2# Makes "symlink attack" tarball (needs GNU tar for --append)
3
4true >anything.txt
5tar cvf tar_symlink_attack.tar anything.txt
6rm anything.txt
7
8ln -s /tmp symlink
9tar --append -f tar_symlink_attack.tar symlink
10rm symlink
11
12mkdir symlink
13echo BUG >symlink/bb_test_evilfile
14tar --append -f tar_symlink_attack.tar symlink/bb_test_evilfile
15rm symlink/bb_test_evilfile
16rmdir symlink
diff --git a/coreutils/link.c b/coreutils/link.c
index 56832fdf6..6e20dafe3 100644
--- a/coreutils/link.c
+++ b/coreutils/link.c
@@ -33,7 +33,7 @@ int link_main(int argc UNUSED_PARAM, char **argv)
33 if (link(argv[0], argv[1]) != 0) { 33 if (link(argv[0], argv[1]) != 0) {
34 /* shared message */ 34 /* shared message */
35 bb_perror_msg_and_die("can't create %slink " 35 bb_perror_msg_and_die("can't create %slink "
36 "%s to %s", "hard", 36 "'%s' to '%s'", "hard",
37 argv[1], argv[0] 37 argv[1], argv[0]
38 ); 38 );
39 } 39 }
diff --git a/include/bb_archive.h b/include/bb_archive.h
index 2b9c5f04c..d3762415f 100644
--- a/include/bb_archive.h
+++ b/include/bb_archive.h
@@ -64,6 +64,9 @@ typedef struct archive_handle_t {
64 /* Currently processed file's header */ 64 /* Currently processed file's header */
65 file_header_t *file_header; 65 file_header_t *file_header;
66 66
67 /* List of symlink placeholders */
68 llist_t *symlink_placeholders;
69
67 /* Process the header component, e.g. tar -t */ 70 /* Process the header component, e.g. tar -t */
68 void FAST_FUNC (*action_header)(const file_header_t *); 71 void FAST_FUNC (*action_header)(const file_header_t *);
69 72
@@ -188,6 +191,7 @@ char get_header_ar(archive_handle_t *archive_handle) FAST_FUNC;
188char get_header_cpio(archive_handle_t *archive_handle) FAST_FUNC; 191char get_header_cpio(archive_handle_t *archive_handle) FAST_FUNC;
189char get_header_tar(archive_handle_t *archive_handle) FAST_FUNC; 192char get_header_tar(archive_handle_t *archive_handle) FAST_FUNC;
190char get_header_tar_gz(archive_handle_t *archive_handle) FAST_FUNC; 193char get_header_tar_gz(archive_handle_t *archive_handle) FAST_FUNC;
194char get_header_tar_xz(archive_handle_t *archive_handle) FAST_FUNC;
191char get_header_tar_bz2(archive_handle_t *archive_handle) FAST_FUNC; 195char get_header_tar_bz2(archive_handle_t *archive_handle) FAST_FUNC;
192char get_header_tar_lzma(archive_handle_t *archive_handle) FAST_FUNC; 196char get_header_tar_lzma(archive_handle_t *archive_handle) FAST_FUNC;
193char get_header_tar_xz(archive_handle_t *archive_handle) FAST_FUNC; 197char get_header_tar_xz(archive_handle_t *archive_handle) FAST_FUNC;
diff --git a/testsuite/tar.tests b/testsuite/tar.tests
index 9f7ce1587..1675b07b1 100755
--- a/testsuite/tar.tests
+++ b/testsuite/tar.tests
@@ -10,9 +10,6 @@ unset LC_COLLATE
10unset LC_ALL 10unset LC_ALL
11umask 022 11umask 022
12 12
13rm -rf tar.tempdir 2>/dev/null
14mkdir tar.tempdir && cd tar.tempdir || exit 1
15
16# testing "test name" "script" "expected result" "file input" "stdin" 13# testing "test name" "script" "expected result" "file input" "stdin"
17 14
18testing "Empty file is not a tarball" '\ 15testing "Empty file is not a tarball" '\
@@ -53,6 +50,7 @@ dd if=/dev/zero bs=512 count=20 2>/dev/null | tar xvf - 2>&1; echo $?
53"" "" 50"" ""
54SKIP= 51SKIP=
55 52
53mkdir tar.tempdir && cd tar.tempdir || exit 1
56# "tar cf test.tar input input_dir/ input_hard1 input_hard2 input_hard1 input_dir/ input": 54# "tar cf test.tar input input_dir/ input_hard1 input_hard2 input_hard1 input_dir/ input":
57# GNU tar 1.26 records as hardlinks: 55# GNU tar 1.26 records as hardlinks:
58# input_hard2 -> input_hard1 56# input_hard2 -> input_hard1
@@ -64,7 +62,6 @@ SKIP=
64# We also don't use "hrw-r--r--" notation for hardlinks in "tar tv" listing. 62# We also don't use "hrw-r--r--" notation for hardlinks in "tar tv" listing.
65optional FEATURE_TAR_CREATE FEATURE_LS_SORTFILES 63optional FEATURE_TAR_CREATE FEATURE_LS_SORTFILES
66testing "tar hardlinks and repeated files" '\ 64testing "tar hardlinks and repeated files" '\
67rm -rf input_* test.tar 2>/dev/null
68>input_hard1 65>input_hard1
69ln input_hard1 input_hard2 66ln input_hard1 input_hard2
70mkdir input_dir 67mkdir input_dir
@@ -95,10 +92,11 @@ drwxr-xr-x input_dir
95" \ 92" \
96"" "" 93"" ""
97SKIP= 94SKIP=
95cd .. || exit 1; rm -rf tar.tempdir 2>/dev/null
98 96
97mkdir tar.tempdir && cd tar.tempdir || exit 1
99optional FEATURE_TAR_CREATE FEATURE_LS_SORTFILES 98optional FEATURE_TAR_CREATE FEATURE_LS_SORTFILES
100testing "tar hardlinks mode" '\ 99testing "tar hardlinks mode" '\
101rm -rf input_* test.tar 2>/dev/null
102>input_hard1 100>input_hard1
103chmod 741 input_hard1 101chmod 741 input_hard1
104ln input_hard1 input_hard2 102ln input_hard1 input_hard2
@@ -128,10 +126,11 @@ Ok: 0
128" \ 126" \
129"" "" 127"" ""
130SKIP= 128SKIP=
129cd .. || exit 1; rm -rf tar.tempdir 2>/dev/null
131 130
131mkdir tar.tempdir && cd tar.tempdir || exit 1
132optional FEATURE_TAR_CREATE FEATURE_LS_SORTFILES 132optional FEATURE_TAR_CREATE FEATURE_LS_SORTFILES
133testing "tar symlinks mode" '\ 133testing "tar symlinks mode" '\
134rm -rf input_* test.tar 2>/dev/null
135>input_file 134>input_file
136chmod 741 input_file 135chmod 741 input_file
137ln -s input_file input_soft 136ln -s input_file input_soft
@@ -159,10 +158,11 @@ lrwxrwxrwx input_file
159" \ 158" \
160"" "" 159"" ""
161SKIP= 160SKIP=
161cd .. || exit 1; rm -rf tar.tempdir 2>/dev/null
162 162
163mkdir tar.tempdir && cd tar.tempdir || exit 1
163optional FEATURE_TAR_CREATE FEATURE_TAR_LONG_OPTIONS 164optional FEATURE_TAR_CREATE FEATURE_TAR_LONG_OPTIONS
164testing "tar --overwrite" "\ 165testing "tar --overwrite" "\
165rm -rf input_* test.tar 2>/dev/null
166ln input input_hard 166ln input input_hard
167tar cf test.tar input_hard 167tar cf test.tar input_hard
168echo WRONG >input 168echo WRONG >input
@@ -174,12 +174,13 @@ Ok
174" \ 174" \
175"Ok\n" "" 175"Ok\n" ""
176SKIP= 176SKIP=
177cd .. || exit 1; rm -rf tar.tempdir 2>/dev/null
177 178
179mkdir tar.tempdir && cd tar.tempdir || exit 1
178test x"$SKIP_KNOWN_BUGS" = x"" && { 180test x"$SKIP_KNOWN_BUGS" = x"" && {
179# Needs to be run under non-root for meaningful test 181# Needs to be run under non-root for meaningful test
180optional FEATURE_TAR_CREATE 182optional FEATURE_TAR_CREATE
181testing "tar writing into read-only dir" '\ 183testing "tar writing into read-only dir" '\
182rm -rf input_* test.tar 2>/dev/null
183mkdir input_dir 184mkdir input_dir
184>input_dir/input_file 185>input_dir/input_file
185chmod 550 input_dir 186chmod 550 input_dir
@@ -201,7 +202,9 @@ dr-xr-x--- input_dir
201"" "" 202"" ""
202SKIP= 203SKIP=
203} 204}
205cd .. || exit 1; rm -rf tar.tempdir 2>/dev/null
204 206
207mkdir tar.tempdir && cd tar.tempdir || exit 1
205# Had a bug where on extract autodetect first "switched off" -z 208# Had a bug where on extract autodetect first "switched off" -z
206# and then failed to recognize .tgz extension 209# and then failed to recognize .tgz extension
207optional FEATURE_TAR_CREATE FEATURE_SEAMLESS_GZ GUNZIP 210optional FEATURE_TAR_CREATE FEATURE_SEAMLESS_GZ GUNZIP
@@ -217,7 +220,9 @@ Ok
217" \ 220" \
218"" "" 221"" ""
219SKIP= 222SKIP=
223cd .. || exit 1; rm -rf tar.tempdir 2>/dev/null
220 224
225mkdir tar.tempdir && cd tar.tempdir || exit 1
221# Do we detect XZ-compressed data (even w/o .tar.xz or txz extension)? 226# Do we detect XZ-compressed data (even w/o .tar.xz or txz extension)?
222# (the uuencoded hello_world.txz contains one empty file named "hello_world") 227# (the uuencoded hello_world.txz contains one empty file named "hello_world")
223optional UUDECODE FEATURE_TAR_AUTODETECT FEATURE_SEAMLESS_XZ 228optional UUDECODE FEATURE_TAR_AUTODETECT FEATURE_SEAMLESS_XZ
@@ -236,7 +241,9 @@ AAAEWVo=
236==== 241====
237" 242"
238SKIP= 243SKIP=
244cd .. || exit 1; rm -rf tar.tempdir 2>/dev/null
239 245
246mkdir tar.tempdir && cd tar.tempdir || exit 1
240# On extract, everything up to and including last ".." component is stripped 247# On extract, everything up to and including last ".." component is stripped
241optional FEATURE_TAR_CREATE 248optional FEATURE_TAR_CREATE
242testing "tar strips /../ on extract" "\ 249testing "tar strips /../ on extract" "\
@@ -255,7 +262,9 @@ Ok
255" \ 262" \
256"" "" 263"" ""
257SKIP= 264SKIP=
265cd .. || exit 1; rm -rf tar.tempdir 2>/dev/null
258 266
267mkdir tar.tempdir && cd tar.tempdir || exit 1
259# attack.tar.bz2 has symlink pointing to a system file 268# attack.tar.bz2 has symlink pointing to a system file
260# followed by a regular file with the same name 269# followed by a regular file with the same name
261# containing "root::0:0::/root:/bin/sh": 270# containing "root::0:0::/root:/bin/sh":
@@ -270,6 +279,7 @@ optional UUDECODE FEATURE_TAR_AUTODETECT FEATURE_SEAMLESS_BZ2
270testing "tar does not extract into symlinks" "\ 279testing "tar does not extract into symlinks" "\
271>>/tmp/passwd && uudecode -o input && tar xf input 2>&1 && rm passwd; cat /tmp/passwd; echo \$? 280>>/tmp/passwd && uudecode -o input && tar xf input 2>&1 && rm passwd; cat /tmp/passwd; echo \$?
272" "\ 281" "\
282tar: can't create symlink 'passwd' to '/tmp/passwd'
2730 2830
274" \ 284" \
275"" "\ 285"" "\
@@ -281,12 +291,15 @@ l4/V8LDoe90yiWJhOJvIypgEfxdyRThQkBVn/bI=
281==== 291====
282" 292"
283SKIP= 293SKIP=
294cd .. || exit 1; rm -rf tar.tempdir 2>/dev/null
295
296mkdir tar.tempdir && cd tar.tempdir || exit 1
284# And same with -k 297# And same with -k
285optional UUDECODE FEATURE_TAR_AUTODETECT FEATURE_SEAMLESS_BZ2 298optional UUDECODE FEATURE_TAR_AUTODETECT FEATURE_SEAMLESS_BZ2
286testing "tar -k does not extract into symlinks" "\ 299testing "tar -k does not extract into symlinks" "\
287>>/tmp/passwd && uudecode -o input && tar xf input -k 2>&1 && rm passwd; cat /tmp/passwd; echo \$? 300>>/tmp/passwd && uudecode -o input && tar xf input -k 2>&1 && rm passwd; cat /tmp/passwd; echo \$?
288" "\ 301" "\
289tar: can't open 'passwd': File exists 302tar: can't create symlink 'passwd' to '/tmp/passwd'
2900 3030
291" \ 304" \
292"" "\ 305"" "\
@@ -298,7 +311,9 @@ l4/V8LDoe90yiWJhOJvIypgEfxdyRThQkBVn/bI=
298==== 311====
299" 312"
300SKIP= 313SKIP=
314cd .. || exit 1; rm -rf tar.tempdir 2>/dev/null
301 315
316mkdir tar.tempdir && cd tar.tempdir || exit 1
302optional UNICODE_SUPPORT FEATURE_TAR_GNU_EXTENSIONS FEATURE_SEAMLESS_BZ2 FEATURE_TAR_AUTODETECT 317optional UNICODE_SUPPORT FEATURE_TAR_GNU_EXTENSIONS FEATURE_SEAMLESS_BZ2 FEATURE_TAR_AUTODETECT
303testing "Pax-encoded UTF8 names and symlinks" '\ 318testing "Pax-encoded UTF8 names and symlinks" '\
304tar xvf ../tar.utf8.tar.bz2 2>&1; echo $? 319tar xvf ../tar.utf8.tar.bz2 2>&1; echo $?
@@ -318,8 +333,36 @@ etc/ssl/certs/f80cc7f6.0 -> EBG_Elektronik_Sertifika_Hizmet_Sağlayıcısı.pem
318" \ 333" \
319"" "" 334"" ""
320SKIP= 335SKIP=
336cd .. || exit 1; rm -rf tar.tempdir 2>/dev/null
321 337
322 338mkdir tar.tempdir && cd tar.tempdir || exit 1
323cd .. && rm -rf tar.tempdir || exit 1 339optional FEATURE_SEAMLESS_BZ2 FEATURE_TAR_AUTODETECT
340testing "Symlink attack: create symlink and then write through it" '\
341exec 2>&1
342uudecode -o input && tar xvf input; echo $?
343ls /tmp/bb_test_evilfile
344ls bb_test_evilfile
345ls symlink/bb_test_evilfile
346' "\
347anything.txt
348symlink
349symlink/bb_test_evilfile
350tar: can't create symlink 'symlink' to '/tmp'
3511
352ls: /tmp/bb_test_evilfile: No such file or directory
353ls: bb_test_evilfile: No such file or directory
354symlink/bb_test_evilfile
355" \
356"" "\
357begin-base64 644 tar_symlink_attack.tar.bz2
358QlpoOTFBWSZTWZgs7bQAALT/hMmQAFBAAf+AEMAGJPPv32AAAIAIMAC5thlR
359omAjAmCMADQT1BqNE0AEwAAjAEwElTKeo9NTR6h6gaeoA0DQNLVdwZZ5iNTk
360AQwCAV6S00QFJYhrlfFkVCEDEGtgNVqYrI0uK3ggnt30gqk4e1TTQm5QIAKa
361SJqzRGSFLMmOloHSAcvLiFxxRiQtQZF+qPxbo173ZDISOAoNoPN4PQPhBhKS
362n8fYaKlioCTzL2oXYczyUUIP4u5IpwoSEwWdtoA=
363====
364"
365SKIP=
366cd .. || exit 1; rm -rf tar.tempdir 2>/dev/null
324 367
325exit $FAILCOUNT 368exit $FAILCOUNT