Skip to content

Don't let wheel pack write outside the destination directory - #704

Open
varun3257 wants to merge 1 commit into
pypa:mainfrom
varun3257:pack-dest-traversal
Open

varun3257 wants to merge 1 commit into
pypa:mainfrom
varun3257:pack-dest-traversal

Conversation

@varun3257

Copy link
Copy Markdown
Contributor

wheel pack builds the output file name from the dist-info directory name, the tags and the Build header of the WHEEL file in the directory being packed, and joins it onto the destination directory as is. #698 added validation for the --build-number option, but a build number that is already in WHEEL goes straight into the name, and that file comes verbatim from whatever wheel was unpacked. A value such as 1/../../outside/pwned-1.0 turns the name into a relative path whose last component is still a valid wheel file name, so WheelFile accepts it and the repacked wheel is written outside the destination. On POSIX the first component (test-1.0-1 in the test) has to exist under the destination for the open to succeed, which is what the regression test sets up; Windows collapses .. before the lookup, so I'd expect it to need nothing there, though I only ran this on macOS. I noticed it reading pack alongside the convert fix in #696, which closed the same hole for names and versions taken from an egg or installer. The check sits in pack where the name is assembled, so it also covers the tags from WHEEL and rejects any name containing a separator before anything is opened. The new test fails on main with the wheel landing in the outside directory and passes with this change.

The build number and tags read from .dist-info/WHEEL were spliced into the output file name unchecked, so a Build header containing path separators moved the repacked wheel out of the destination directory.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant