gufw-developers team mailing list archive
-
gufw-developers team
-
Mailing list archive
-
Message #01824
[Bug 1410839] Re: Shell Command injection in ufw_backend.py
Hi!
Your video was really clear! Thanks!!
About the change "Import/Export" > "Backup/Restore" is another
improvement. I'll think on it ;) But I'd prefer an import/export.
Bernd, Could you confirm me if the attachment patch is fixing the injection?
It's working for me in the python Shell and I'll try in a few hours with Gufw in my computer.
If it's fixed, I'll send to the repository maintainers.
Thanks a lot for report this vulnerability!!!
** Patch added: "path_1410839.patch"
https://bugs.launchpad.net/gui-ufw/+bug/1410839/+attachment/4300558/+files/path_1410839.patch
--
You received this bug notification because you are a member of Gufw
Developers, which is subscribed to Gufw.
https://bugs.launchpad.net/bugs/1410839
Title:
Shell Command injection in ufw_backend.py
Status in Gufw:
Fix Committed
Bug description:
Firewall Administrators can be tricked by someone to export a profile
with Gufw to an special crafted file or path name wich contains shell
code.
reason is this line in ufw_backend.py :
def export_profile(self, profile, file):
commands.getstatusoutput('cp /etc/gufw/' + profile + '.profile ' + file + ' ; chmod 777 ' + file)
The rename and delete funktions are also unsave if profile name
contains shell code, like semicolons.
To manage notifications about this bug go to:
https://bugs.launchpad.net/gui-ufw/+bug/1410839/+subscriptions
References