Kurt Seifried of Red Hat Product Security reports:
========================================
./lib/util/MiqSshUtilV1.rb
def shell_exec(cmd, doneStr=nil, shell=@shell)
if shell
# Writing to a temp remote script to handle cases where the cmd string is
# too long and is truncated.
temp_remote_script = "/var/tmp/miq-#{Time.now.to_i}.sh"
self.exec("echo \"#{cmd}\" > #{temp_remote_script}")
self.exec("chmod 700 #{temp_remote_script}")
out = shell.send_command(temp_remote_script)
self.exec("rm -f #{temp_remote_script}")
@status = out.status
msg = out.stdout
# Check if the first output return references the remote script and remove it.
msgs = msg.split("\n")
msg = msgs[1..-1].join("\n") if msgs[0].include?(temp_remote_script)
raise "#{msg}" unless doneStr.nil? || msg.include?(doneStr)
return msg
else
return self.exec(cmd, doneStr)
end
end
========================================
./lib/util/MiqSshUtilV2.rb
def temp_cmd_file(cmd)
temp_remote_script = "/var/tmp/miq-#{Time.now.to_i}.sh"
self.exec("echo \"#{cmd}\" > #{temp_remote_script}")
remote_cmd = "chmod 700 #{temp_remote_script}; #{temp_remote_script}; rm -f #{temp_remote_script}"
yield(remote_cmd)
end
========================================
Time.now.to_i = 1412123123
setup a file and a few hundred/thousand symlinks and you can cover an hour easily.
Between the
self.exec("echo \"#{cmd}\" > #{temp_remote_script}")
self.exec("chmod 700 #{temp_remote_script}")
an attacker can replace the file, which is then executed as root.
It should use Ruby Tempfile:
http://kurt.seifried.org/2012/03/14/creating-temporary-files-securely/
Kurt Seifried of Red Hat Product Security reports: ======================================== ./lib/util/MiqSshUtilV1.rb def shell_exec(cmd, doneStr=nil, shell=@shell) if shell # Writing to a temp remote script to handle cases where the cmd string is # too long and is truncated. temp_remote_script = "/var/tmp/miq-#{Time.now.to_i}.sh" self.exec("echo \"#{cmd}\" > #{temp_remote_script}") self.exec("chmod 700 #{temp_remote_script}") out = shell.send_command(temp_remote_script) self.exec("rm -f #{temp_remote_script}") @status = out.status msg = out.stdout # Check if the first output return references the remote script and remove it. msgs = msg.split("\n") msg = msgs[1..-1].join("\n") if msgs[0].include?(temp_remote_script) raise "#{msg}" unless doneStr.nil? || msg.include?(doneStr) return msg else return self.exec(cmd, doneStr) end end ======================================== ./lib/util/MiqSshUtilV2.rb def temp_cmd_file(cmd) temp_remote_script = "/var/tmp/miq-#{Time.now.to_i}.sh" self.exec("echo \"#{cmd}\" > #{temp_remote_script}") remote_cmd = "chmod 700 #{temp_remote_script}; #{temp_remote_script}; rm -f #{temp_remote_script}" yield(remote_cmd) end ======================================== Time.now.to_i = 1412123123 setup a file and a few hundred/thousand symlinks and you can cover an hour easily. Between the self.exec("echo \"#{cmd}\" > #{temp_remote_script}") self.exec("chmod 700 #{temp_remote_script}") an attacker can replace the file, which is then executed as root. It should use Ruby Tempfile: http://kurt.seifried.org/2012/03/14/creating-temporary-files-securely/