pjfanning opened a new pull request, #1348:
URL: https://github.com/apache/poi/pull/1348

   `Msg2txt.processAttachment` writes each attachment to a path built directly 
from the message:
   
   ```java
   String fileName = attachment.getAttachFileName().toString();
   if (attachment.getAttachLongFileName() != null) {
       fileName = attachment.getAttachLongFileName().toString();
   }
   
   File f = new File(dir, fileName);
   try (OutputStream fileOut = new FileOutputStream(f)) {
       fileOut.write(attachment.getAttachData().getValue());
   }
   ```
   
   `PR_ATTACH_LONG_FILENAME` / `PR_ATTACH_FILENAME` are attacker controlled and 
never normalized, so a crafted `.msg` file can write outside the directory the 
caller nominated.
   
   Now routed through `IOUtils.newFile`, the project's designated traversal 
guard — the same one `HMEFContentsExtractor` uses for TNEF attachments (since 
#1066) and `VBAMacroExtractor` uses for extracted modules.
   
   ### Context
   
   Found while checking a security report filed against 
`HMEFContentsExtractor.extractAttachments`. That report is **already fixed on 
trunk** by #1066, which added the `IOUtils.newFile` guard there. This is the 
same defect class at a sink that fix did not cover.
   
   I swept the other `new File(dir, name)` write sinks at the same time; the 
rest are already safe:
   
   | Site | Why it's safe |
   |---|---|
   | `VBAMacroExtractor` | uses `IOUtils.newFile` |
   | `VsdxToPng`, `HierarchyPrinter` | `Util.sanitizeFilename` replaces every 
path separator |
   | `PPTX2PNG` | `new File(filename).getName()` drops any directory component |
   | `HMEFContentsExtractor` (`message.rtf`) | constant name |
   
   🤖 Generated with [Claude Code](https://claude.com/claude-code)


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to