git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH 3/3] verify_path: consider dos drive prefix

From
Erik Faye-Lund <kusmabite@gmail.com>
Date
May 27, 2011, 16:00 UTC
Message-ID
<1306512040-1468-4-git-send-email-kusmabite@gmail.com>
In-Reply-To
<1306512040-1468-1-git-send-email-kusmabite@gmail.com>

If someone manage to create a repo with a 'C:' entry in the root-tree, files can be written outside of the working-dir. This opens up a can-of-worms of exploits.

Fix it by explicitly checking for a dos drive prefix when verifying a paht. While we're at it, make sure that paths beginning with '\' is considered absolute as well.

Noticed-by: Theo Niessink <theo@taletn.com>
Signed-off-by: Erik Faye-Lund <kusmabite@gmail.com>
---
 read-cache.c |    5 ++++-
 1 files changed, 4 insertions(+), 1 deletions(-)
diff --git a/read-cache.c b/read-cache.c
index f38471c..68faa51 100644
--- a/read-cache.c
+++ b/read-cache.c
@@ -753,11 +753,14 @@ int verify_path(const char *path)
 {
 	char c;
 
+	if (has_dos_drive_prefix(path))
+		return 0;
+
 	goto inside;
 	for (;;) {
 		if (!c)
 			return 1;
-		if (c == '/') {
+		if (is_dir_sep(c)) {
 inside:
 			c = *path++;
 			switch (c) {
-- 
1.7.5.3.3.g435ff
Previous: Erik Faye-LundNext: Johannes Sixt
Message 4 of 20 in “do not write files outside of work-dir”
  1. 0/3 do not write files outside of work-dirErik Faye-Lund, May 27, 2011
  2. 1/3 A Windows path starting with a backslash is absoluteErik Faye-Lund, May 27, 2011
  3. 2/3 real_path: do not assume '/' is the path seperatorErik Faye-Lund, May 27, 2011
  4. 3/3 verify_path: consider dos drive prefixErik Faye-Lund, May 27, 2011
  5. Johannes SixtMay 27, 2011
  6. Erik Faye-LundMay 30, 2011
  7. Theo NiessinkMay 30, 2011
  8. Erik Faye-LundMay 30, 2011
  9. Junio C HamanoJun 7, 2011
  10. Erik Faye-LundJun 7, 2011
  11. Erik Faye-LundJun 7, 2011
  12. Junio C HamanoJun 7, 2011
  13. Erik Faye-LundJun 7, 2011
  14. Theo NiessinkJun 7, 2011
  15. Johannes SixtMay 30, 2011
  16. Junio C HamanoMay 27, 2011
  17. Johannes SchindelinMay 27, 2011
  18. Junio C HamanoMay 27, 2011
  19. TaitJun 1, 2011
  20. Johannes SixtJun 1, 2011

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.