CVE-2018-1000802
CPython Command Injection in shutil module make_archive
- CVSS 9.8
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')
- Input Validation and Sanitization
- Local
Python Software Foundation Python (CPython) version 2.7 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in shutil module (make_archive function) that can result in Denial of service, Information gain via injection of arbitrary files on the system or entire drive. This attack appear to be exploitable via Passage of unfiltered user input to the function. This vulnerability appears to have been fixed in after commit add531a1e55b0a739b0f42582f1c9747e5649ace.
- CVSS base score
- 9.8
- Published
- 2018-09-18
- OWASP
- A03 Injection
- Orthogonal defect classification
- Function
- Code defect classification
- Incorrect Functionality
- Category
- Input Validation and Sanitization
- Subcategory
- Command Injection
- Accessibility scope
- Local
- Impact
- Denial of Service (DoS)
- Fixed by upgrading
- Yes
Solution
Update to Python 2.7.18 or a later.
Vulnerable code sample
import shutil
def make_archive(base_name, format, root_dir=None, base_dir=None):
return shutil.make_archive(base_name, format, root_dir, base_dir)
if __name__ == "__main__":
user_input_base_name = "../my_archive"
user_input_format = "zip"
try:
make_archive(user_input_base_name, user_input_format, root_dir="/path/to/directory")
print("Archive created successfully.")
except Exception as e:
print("Error creating archive:", e)Patched code sample
import os
import shutil
def make_archive(base_name, format, root_dir=None, base_dir=None):
if os.path.basename(base_name) != base_name:
raise ValueError("Invalid base_name: directory traversal detected.")
allowed_formats = ['zip', 'tar', 'gztar', 'bztar', 'xztar']
if format not in allowed_formats:
raise ValueError(f"Invalid format: {format}. Allowed formats are: {allowed_formats}")
return shutil.make_archive(base_name, format, root_dir, base_dir)
if __name__ == "__main__":
try:
make_archive("my_archive", "zip", root_dir="/path/to/directory")
print("Archive created successfully.")
except Exception as e:
print("Error creating archive:", e)Cite this entry
@misc{vaitp:cve20181000802,
title = {{CPython Command Injection in shutil module make_archive}},
author = {Bogaerts, Fr\'ed\'eric and Ivaki, Naghmeh and Fonseca, Jos\'e},
year = {2018},
note = {VAITP Python Vulnerability Dataset, entry CVE-2018-1000802},
howpublished = {\url{https://netpack.pt/vaitp/vulnerability/CVE-2018-1000802/}}
}
Introducing the "VAITP dataset": a specialized repository of Python vulnerabilities and patches, meticulously compiled for the use of the security research community. As Python's prominence grows, understanding and addressing potential security vulnerabilities become crucial. Crafted by and for the cybersecurity community, this dataset offers a valuable resource for researchers, analysts, and developers to analyze and mitigate the security risks associated with Python. Through the comprehensive exploration of vulnerabilities and corresponding patches, the VAITP dataset fosters a safer and more resilient Python ecosystem, encouraging collaborative advancements in programming security.
The supreme art of war is to subdue the enemy without fighting.
Sun Tzu – “The Art of War”
:: Shaping the future through research and ingenuity ::
