Re: Symlink-Follow File Overwrite in aclocal --install (CWE-61)
MichaĆ Majchrowicz via Discussion list for automake <[email protected]> Wed, 3 Jun 2026 13:25:36 +0200
| Newsgroups | gmane.comp.sysutils.automake.general |
|---|---|
| Message-ID | <[email protected]> |
--Apple-Mail=_DBA972FB-EDAE-4A67-9F93-A739E82F6A40 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset=utf-8 Hello Bruno, To be honest I mostly agree with you. Both attack scenarios & suggest = fix part I have added because some maintainers asked me about it. Some parts of = advisories Thanks for the good words about the language. I prepare are mostly = static text (credits, disclosure timeline, etc.) and come from files on disk tough but after compiling the advisory I = like to put it trough I like running it trough AI to add some variation and hopefully fix some = language issues. I noticed that an AI has bigger =E2=80=9Econtext=E2=80=9D and often can = find issues in text that are more niuanse that simple spell check in text editor can miss. Regarding the = 4th issue I think It won=E2=80=99t be much harder for me to compile a bug report = (especially when excluding some parts from advisory) using just static files that I have on disk. I = considered it as potential issue in specific CI pipeline context so I have decided to report it as = a security issue. Maybe that was a mistake but from my point of view at that time it was = the right thing to do. Also I think =E2=80=9Efast generation=E2=80=9D of such reports (or even = bogus) ones could be automatised using pure bash/python scrips. I know that there is a lot of such things = nowadays but I don=E2=80=99t believe AI itself made it so much easier. At least for people with little scripting = knowledge. I think it simply became more =E2=80=9Efashionable=E2=80=9D or it attracted people who only know how = to type AI prompts=E2=80=A6 Anyways sorry for misunderstanding. I just wanted to let you know that = before I report anything I test it myself multiple times and as a human I might = make a mistake and report something that is not a security issue as one. = Anyway I just wanted to let you know that nothing I report is reported = automatically but I try=20 to (hopefully) improve the quality of our reports using automated tools. Regards, =E2=80=94 Micha=C5=82 Majchrowicz / Offensive Security Engineer / PhD eWPTX PGP: D52A 5289 8256 006D 5E05 BAC6 79EA 0072 F4E1 9D57 AFINE sp. z o.o. Al. Jerozolimskie 146C, 02-305 Warszawa https://www.afine.com <https://www.afine.com/> > Wiadomo=C5=9B=C4=87 napisana przez Bruno Haible <[email protected]> w = dniu 3 cze 2026, o godz. 12:53: >=20 > Hello Micha=C5=82, >=20 > Micha=C5=82 Majchrowicz wrote: >> Sorry for being to automatic for you :) I like to put few words = before each advisory tough=20 >> I have to admit I put my rambling through AI as often people have = issues understanding me.=20 >> I am not a native English speaker and at the same time even in my = native language I have >> a tendency to write incoherent sentences and miss some stuff. Anyway = to overcome my >> problems I use an =E2=80=9EAI tool=E2=80=9D as a kind of advanced = spellchecker. Sorry if it annoys but it helps=20 >> me keep things organised and overcome my limitations. >=20 > Your English is quite good; no problem with that. >=20 > I see two benefits with the approach of using AI tools for = vulnerability > reporting: > - It can find bugs that a human would have needed more effort to = find. > - It can add an exploit scenario. In the case of your 3 reports, we = would > not have needed it, but you never know the maintainer's thinking in > advance. >=20 > And I see also one drawback: > - It is so easy to write reports that are not well founded (like your = 4th one), > that maintainers can get overwhelmed. >=20 > So, in the end, it is still your task as a reporter to focus on the = real problems > and not send reports about things which are not vulnerabilities. >=20 >> Regarding the symlink issue I was thinking in the context of recent = history with how people=20 >> were using Gemini CLI in the pipeline or last Shai Halud (or whatever = it was called) attack. >> Where problems with GitHub CI process allowed attackers to leak = authentication tokens >> and as a result gain access to repo itself. I was thinking about a = scenario where this issue >> is used to overwrite such tokens. >=20 > The major problem here is the possibility to leak authentications. >=20 > When you have two issues that, together, allow a certain exploit, try = to ask > yourself whether the first or the second one can be replaced by a = similar one. > If the first issue can be combined with a multitude of second issues, = the first > issue is the major problem. And vice versa. >=20 >> During my research I often encounter issues that=20 >> whether they are security bugs or not often depends on context. My = approach >> is to report them anyway and let the developer decide the impact as = in most cases >> I don=E2=80=99t have enough knowledge about project internals to = decide myself. >=20 > IMO, you should consider the context first. The Automake maintainers = should > not need to have knowledge about GitHub or CI or similar stuff. >=20 > Bruno >=20 >=20 >=20 --Apple-Mail=_DBA972FB-EDAE-4A67-9F93-A739E82F6A40 Content-Transfer-Encoding: 7bit Content-Disposition: attachment; filename=signature.asc Content-Type: application/pgp-signature; name=signature.asc Content-Description: Message signed with OpenPGP -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEE1SpSiYJWAG1eBbrGeeoAcvThnVcFAmogDzAACgkQeeoAcvTh nVd+Wg//bfRT6At+heFPsiDdWJ+NDr7DyVAa4T8Eyp8WDeubcnScUmb+ruj8CDaN 5IP+34Gi7uEKtCPaWvzx+e5yo/LKHAzdh6uQJIYKEffVHkjCJ7/q/f89uoQUaW0L 2fwecQqpEWBLuPsUDB5MHQ9ZHXUtb3QxJOq9EIRgZ5S39QQRLmIqZtSy1t/XWI1X 7Mnukmz1vFsjaP5nGDP50P4U645ESIvkCG1k/HGlxjmgyGY2glEpZH4mQHEoLg7B 7EngZi10RyABCW/TXTlHcgaMJSl3n7v3RNlhhoBJ3DId5RwRm3z7Vu7PUKrlh6Jh Hh7NL/xrHLxpe9L4Ptc6c8iC12DfvGp4wcDzGKCW92TidX3VRBtQcF3b9KiYBVFe 7oTOj1rvMMQx5yKRcJVZclMNcRrc+fFpPw6CDS5bUgbchYGXM49klyHqb9Md4QWA Cvymp7pp5Ida4NkrLpAGQLmtgR//3KnAmE0SkJsbpealHjM7B5NhNeCeFesDPcn9 OUx7wNkw8hRkK8lX1cSdVSf/b7adsoxtSKaqWgVh9gbgEtIWetCZnX2HCK1mqUo2 AQ1M/brDWR7FWTaHJNGw4y23pD4+vXzDEty6PrsdpYF6EdYbg6L8jQLycMIzpcmC X1R59d8/5V20oi/V2EFIe+T25G9Gykw8XP7MwX7bEvX1zlxmmPk= =MC/A -----END PGP SIGNATURE----- --Apple-Mail=_DBA972FB-EDAE-4A67-9F93-A739E82F6A40--