Re: Symlink-Follow File Overwrite in aclocal --install (CWE-61)

MichaƂ Majchrowicz via Discussion list for automake <[email protected]> Wed, 3 Jun 2026 13:25:36 +0200
Newsgroups gmane.comp.sysutils.automake.general
Message-ID <[email protected]>
--Apple-Mail=_DBA972FB-EDAE-4A67-9F93-A739E82F6A40
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=utf-8

Hello Bruno,
To be honest I mostly agree with you. Both attack scenarios & suggest =
fix part
I have added because some maintainers asked me about it. Some parts of =
advisories
Thanks for the good words about the language. I prepare are mostly =
static text (credits, disclosure timeline, etc.)
and come from files on disk tough but after compiling the advisory I =
like to put it trough
I like running it trough AI to add some variation and hopefully fix some =
language issues.
I noticed that an AI has bigger =E2=80=9Econtext=E2=80=9D and often can =
find issues in text that are more
niuanse that simple spell check in text editor can miss. Regarding the =
4th issue I think
It won=E2=80=99t be much harder for me to compile a bug report =
(especially when excluding
some parts from advisory) using just static files that I have on disk. I =
considered it as potential
issue in specific CI pipeline context so I have decided to report it as =
a security issue.
Maybe that was a mistake but from my point of view at that time it was =
the right thing to do.
Also I think =E2=80=9Efast generation=E2=80=9D of such reports (or even =
bogus) ones could be automatised using
pure bash/python scrips. I know that there is a lot of such things =
nowadays but I don=E2=80=99t believe AI itself
made it so much easier. At least for people with little scripting =
knowledge. I think it simply became more
=E2=80=9Efashionable=E2=80=9D or it attracted people who only know how =
to type AI prompts=E2=80=A6

Anyways sorry for misunderstanding. I just wanted to let you know that =
before
I report anything I test it myself multiple times and as a human I might =
make
a mistake and report something that is not a security issue as one. =
Anyway
I just wanted to let you know that nothing I report is reported =
automatically but I try=20
to (hopefully) improve the quality of our reports using automated tools.
Regards,
=E2=80=94
Micha=C5=82 Majchrowicz / Offensive Security Engineer / PhD eWPTX
PGP: D52A 5289 8256 006D 5E05 BAC6 79EA 0072 F4E1 9D57

AFINE sp. z o.o.
Al. Jerozolimskie 146C, 02-305 Warszawa
https://www.afine.com <https://www.afine.com/>

> Wiadomo=C5=9B=C4=87 napisana przez Bruno Haible <[email protected]> w =
dniu 3 cze 2026, o godz. 12:53:
>=20
> Hello Micha=C5=82,
>=20
> Micha=C5=82 Majchrowicz wrote:
>> Sorry for being to automatic for you :) I like to put few words =
before each advisory tough=20
>> I have to admit I put my rambling through AI as often people have =
issues understanding me.=20
>> I am not a native English speaker and at the same time even in my =
native language I have
>> a tendency to write incoherent sentences and miss some stuff. Anyway =
to overcome my
>> problems I use an =E2=80=9EAI tool=E2=80=9D as a kind of advanced =
spellchecker. Sorry if it annoys but it helps=20
>> me keep things organised and overcome my limitations.
>=20
> Your English is quite good; no problem with that.
>=20
> I see two benefits with the approach of using AI tools for =
vulnerability
> reporting:
>  - It can find bugs that a human would have needed more effort to =
find.
>  - It can add an exploit scenario. In the case of your 3 reports, we =
would
>    not have needed it, but you never know the maintainer's thinking in
>    advance.
>=20
> And I see also one drawback:
>  - It is so easy to write reports that are not well founded (like your =
4th one),
>    that maintainers can get overwhelmed.
>=20
> So, in the end, it is still your task as a reporter to focus on the =
real problems
> and not send reports about things which are not vulnerabilities.
>=20
>> Regarding the symlink issue I was thinking in the context of recent =
history with how people=20
>> were using Gemini CLI in the pipeline or last Shai Halud (or whatever =
it was called) attack.
>> Where problems with GitHub CI process allowed attackers to leak =
authentication tokens
>> and as a result gain access to repo itself. I was thinking about a =
scenario where this issue
>> is used to overwrite such tokens.
>=20
> The major problem here is the possibility to leak authentications.
>=20
> When you have two issues that, together, allow a certain exploit, try =
to ask
> yourself whether the first or the second one can be replaced by a =
similar one.
> If the first issue can be combined with a multitude of second issues, =
the first
> issue is the major problem. And vice versa.
>=20
>> During my research I often encounter issues that=20
>> whether they are security bugs or not often depends on context. My =
approach
>> is to report them anyway and let the developer decide the impact as =
in most cases
>> I don=E2=80=99t have enough knowledge about project internals to =
decide myself.
>=20
> IMO, you should consider the context first. The Automake maintainers =
should
> not need to have knowledge about GitHub or CI or similar stuff.
>=20
> Bruno
>=20
>=20
>=20


--Apple-Mail=_DBA972FB-EDAE-4A67-9F93-A739E82F6A40
Content-Transfer-Encoding: 7bit
Content-Disposition: attachment;
	filename=signature.asc
Content-Type: application/pgp-signature;
	name=signature.asc
Content-Description: Message signed with OpenPGP

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEE1SpSiYJWAG1eBbrGeeoAcvThnVcFAmogDzAACgkQeeoAcvTh
nVd+Wg//bfRT6At+heFPsiDdWJ+NDr7DyVAa4T8Eyp8WDeubcnScUmb+ruj8CDaN
5IP+34Gi7uEKtCPaWvzx+e5yo/LKHAzdh6uQJIYKEffVHkjCJ7/q/f89uoQUaW0L
2fwecQqpEWBLuPsUDB5MHQ9ZHXUtb3QxJOq9EIRgZ5S39QQRLmIqZtSy1t/XWI1X
7Mnukmz1vFsjaP5nGDP50P4U645ESIvkCG1k/HGlxjmgyGY2glEpZH4mQHEoLg7B
7EngZi10RyABCW/TXTlHcgaMJSl3n7v3RNlhhoBJ3DId5RwRm3z7Vu7PUKrlh6Jh
Hh7NL/xrHLxpe9L4Ptc6c8iC12DfvGp4wcDzGKCW92TidX3VRBtQcF3b9KiYBVFe
7oTOj1rvMMQx5yKRcJVZclMNcRrc+fFpPw6CDS5bUgbchYGXM49klyHqb9Md4QWA
Cvymp7pp5Ida4NkrLpAGQLmtgR//3KnAmE0SkJsbpealHjM7B5NhNeCeFesDPcn9
OUx7wNkw8hRkK8lX1cSdVSf/b7adsoxtSKaqWgVh9gbgEtIWetCZnX2HCK1mqUo2
AQ1M/brDWR7FWTaHJNGw4y23pD4+vXzDEty6PrsdpYF6EdYbg6L8jQLycMIzpcmC
X1R59d8/5V20oi/V2EFIe+T25G9Gykw8XP7MwX7bEvX1zlxmmPk=
=MC/A
-----END PGP SIGNATURE-----

--Apple-Mail=_DBA972FB-EDAE-4A67-9F93-A739E82F6A40--