Fwd: Minor bug in freebsd-version(1), potential DoS vulnerability
Nami Arjmandi <[email protected]>
| Newsgroups | gmane.os.freebsd.devel.net |
|---|---|
| Message-ID | <CAAdZWasSuTRmCPZ14cC01P=VTSWp0E=UEZC=u7ivPAfxoRaeSw@mail.gmail.com> |
Hi, I discovered several bugs in `freebsd-version(1)`. Unfortunately, due to Iran’s extended internet blackout I was unable to report them earlier and now can only use a few whitelisted services (e.g., Gmail) to send this message. Bugs: 1. `-j` option handles arguments without quoting - The option expands variables without quotes, making it vulnerable to glob expansion when special characters such as `?`, `*`, or `/` are present. - Jails whose names contain spaces do not work because `freebsd-version` iterates over a space‑separated list. - I could not run a jail with a space in its name, but I could run jails containing `*` and `?`. 2. Information leakage and resource exhaustion - Carefully crafted input strings can reveal sensitive data or exhaust system resources. Examples: # freebsd-version -j "/root/*" jexec: jail "/root/Book" not found # freebsd-version -j "/root/*/*/*/*" jexec: jail "/root/Book/Jung/C.G." not found # freebsd-version -j "/*/*/*/*/*/*/*/*/*" # (excessive expansion leading to high resource usage) - When provided with an empty string, the command exits silently: # freebsd-version -j "" I have attached the patched script and a patchfile in this email. The changes include: - Adding quotation marks to the variable affected by the `-j` option. - Setting `-f` to disable glob expansion. - Minor styling improvements. - A check for an empty `-j` option. Please let me know what you think. Thank you, Nami Arj
patchfile
(application/octet-stream, 373 B) - not displayed
patched-freebsd-version
(application/octet-stream, 3.7 KB) - not displayed