mirror of
https://github.com/sudo-project/sudo.git
synced 2025-09-01 06:45:10 +00:00
Fix for CVE-2017-1000367, parsing of /proc/pid/stat on Linux when
the process name contains spaces. Since the user has control over the command name this could be used by a user with sudo access to overwrite an arbitrary file. Thanks to Qualys for investigating and reporting this bug. Also stop performing a breadth-first traversal of /dev when looking for the device. Only the directories specified in search_devs[] are checked.
This commit is contained in:
141
src/ttyname.c
141
src/ttyname.c
@@ -1,5 +1,5 @@
|
|||||||
/*
|
/*
|
||||||
* Copyright (c) 2012-2016 Todd C. Miller <Todd.Miller@courtesan.com>
|
* Copyright (c) 2012-2017 Todd C. Miller <Todd.Miller@courtesan.com>
|
||||||
*
|
*
|
||||||
* Permission to use, copy, modify, and distribute this software for any
|
* Permission to use, copy, modify, and distribute this software for any
|
||||||
* purpose with or without fee is hereby granted, provided that the above
|
* purpose with or without fee is hereby granted, provided that the above
|
||||||
@@ -145,20 +145,22 @@ sudo_ttyname_dev(dev_t tdev, char *name, size_t namelen)
|
|||||||
}
|
}
|
||||||
#elif defined(HAVE_STRUCT_PSINFO_PR_TTYDEV) || defined(HAVE_PSTAT_GETPROC) || defined(__linux__)
|
#elif defined(HAVE_STRUCT_PSINFO_PR_TTYDEV) || defined(HAVE_PSTAT_GETPROC) || defined(__linux__)
|
||||||
/*
|
/*
|
||||||
* Devices to search before doing a breadth-first scan.
|
* Device nodes and directories to search before searching all of /dev
|
||||||
*/
|
*/
|
||||||
static char *search_devs[] = {
|
static char *search_devs[] = {
|
||||||
"/dev/console",
|
"/dev/console",
|
||||||
"/dev/wscons",
|
"/dev/pts/", /* POSIX pty */
|
||||||
"/dev/pts/",
|
"/dev/vt/", /* Solaris virtual console */
|
||||||
"/dev/vt/",
|
"/dev/term/", /* Solaris serial ports */
|
||||||
"/dev/term/",
|
"/dev/zcons/", /* Solaris zone console */
|
||||||
"/dev/zcons/",
|
"/dev/pty/", /* HP-UX old-style pty */
|
||||||
NULL
|
NULL
|
||||||
};
|
};
|
||||||
|
|
||||||
|
/*
|
||||||
|
* Device nodes to ignore when searching all of /dev
|
||||||
|
*/
|
||||||
static char *ignore_devs[] = {
|
static char *ignore_devs[] = {
|
||||||
"/dev/fd/",
|
|
||||||
"/dev/stdin",
|
"/dev/stdin",
|
||||||
"/dev/stdout",
|
"/dev/stdout",
|
||||||
"/dev/stderr",
|
"/dev/stderr",
|
||||||
@@ -166,16 +168,18 @@ static char *ignore_devs[] = {
|
|||||||
};
|
};
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* Do a breadth-first scan of dir looking for the specified device.
|
* Do a scan of a directory looking for the specified device.
|
||||||
|
* Does not descend into subdirectories.
|
||||||
* Returns name on success and NULL on failure, setting errno.
|
* Returns name on success and NULL on failure, setting errno.
|
||||||
*/
|
*/
|
||||||
static char *
|
static char *
|
||||||
sudo_ttyname_scan(const char *dir, dev_t rdev, bool builtin, char *name, size_t namelen)
|
sudo_ttyname_scan(const char *dir, dev_t rdev, char *name, size_t namelen)
|
||||||
{
|
{
|
||||||
size_t sdlen, num_subdirs = 0, max_subdirs = 0;
|
size_t sdlen;
|
||||||
char pathbuf[PATH_MAX], **subdirs = NULL;
|
char pathbuf[PATH_MAX];
|
||||||
char *ret = NULL;
|
char *ret = NULL;
|
||||||
struct dirent *dp;
|
struct dirent *dp;
|
||||||
|
struct stat sb;
|
||||||
unsigned int i;
|
unsigned int i;
|
||||||
DIR *d = NULL;
|
DIR *d = NULL;
|
||||||
debug_decl(sudo_ttyname_scan, SUDO_DEBUG_UTIL)
|
debug_decl(sudo_ttyname_scan, SUDO_DEBUG_UTIL)
|
||||||
@@ -187,6 +191,18 @@ sudo_ttyname_scan(const char *dir, dev_t rdev, bool builtin, char *name, size_t
|
|||||||
if ((d = opendir(dir)) == NULL)
|
if ((d = opendir(dir)) == NULL)
|
||||||
goto done;
|
goto done;
|
||||||
|
|
||||||
|
if (fstat(dirfd(d), &sb) == -1) {
|
||||||
|
sudo_debug_printf(SUDO_DEBUG_ERROR|SUDO_DEBUG_LINENO,
|
||||||
|
"unable to fstat %s", dir);
|
||||||
|
goto done;
|
||||||
|
}
|
||||||
|
if ((sb.st_mode & S_IWOTH) != 0) {
|
||||||
|
sudo_debug_printf(SUDO_DEBUG_ERROR|SUDO_DEBUG_LINENO,
|
||||||
|
"ignoring world-writable directory %s", dir);
|
||||||
|
errno = ENOENT;
|
||||||
|
goto done;
|
||||||
|
}
|
||||||
|
|
||||||
sudo_debug_printf(SUDO_DEBUG_INFO|SUDO_DEBUG_LINENO,
|
sudo_debug_printf(SUDO_DEBUG_INFO|SUDO_DEBUG_LINENO,
|
||||||
"scanning for dev %u in %s", (unsigned int)rdev, dir);
|
"scanning for dev %u in %s", (unsigned int)rdev, dir);
|
||||||
|
|
||||||
@@ -224,18 +240,6 @@ sudo_ttyname_scan(const char *dir, dev_t rdev, bool builtin, char *name, size_t
|
|||||||
}
|
}
|
||||||
if (ignore_devs[i] != NULL)
|
if (ignore_devs[i] != NULL)
|
||||||
continue;
|
continue;
|
||||||
if (!builtin) {
|
|
||||||
/* Skip entries in search_devs; we already checked them. */
|
|
||||||
for (i = 0; search_devs[i] != NULL; i++) {
|
|
||||||
len = strlen(search_devs[i]);
|
|
||||||
if (search_devs[i][len - 1] == '/')
|
|
||||||
len--;
|
|
||||||
if (d_len == len && strncmp(pathbuf, search_devs[i], len) == 0)
|
|
||||||
break;
|
|
||||||
}
|
|
||||||
if (search_devs[i] != NULL)
|
|
||||||
continue;
|
|
||||||
}
|
|
||||||
# if defined(HAVE_STRUCT_DIRENT_D_TYPE) && defined(DTTOIF)
|
# if defined(HAVE_STRUCT_DIRENT_D_TYPE) && defined(DTTOIF)
|
||||||
/*
|
/*
|
||||||
* Avoid excessive stat() calls by checking dp->d_type.
|
* Avoid excessive stat() calls by checking dp->d_type.
|
||||||
@@ -248,39 +252,14 @@ sudo_ttyname_scan(const char *dir, dev_t rdev, bool builtin, char *name, size_t
|
|||||||
if (stat(pathbuf, &sb) == -1)
|
if (stat(pathbuf, &sb) == -1)
|
||||||
continue;
|
continue;
|
||||||
break;
|
break;
|
||||||
case DT_DIR:
|
|
||||||
/* Directory, no need to stat() it. */
|
|
||||||
sb.st_mode = DTTOIF(dp->d_type);
|
|
||||||
sb.st_rdev = 0; /* quiet ccc-analyzer false positive */
|
|
||||||
break;
|
|
||||||
default:
|
default:
|
||||||
/* Not a character device, link or directory, skip it. */
|
/* Not a character device or link, skip it. */
|
||||||
continue;
|
continue;
|
||||||
}
|
}
|
||||||
# else
|
# else
|
||||||
if (stat(pathbuf, &sb) == -1)
|
if (stat(pathbuf, &sb) == -1)
|
||||||
continue;
|
continue;
|
||||||
# endif
|
# endif
|
||||||
if (S_ISDIR(sb.st_mode)) {
|
|
||||||
if (!builtin) {
|
|
||||||
/* Add to list of subdirs to search. */
|
|
||||||
if (num_subdirs + 1 > max_subdirs) {
|
|
||||||
char **new_subdirs;
|
|
||||||
|
|
||||||
new_subdirs = reallocarray(subdirs, max_subdirs + 64,
|
|
||||||
sizeof(char *));
|
|
||||||
if (new_subdirs == NULL)
|
|
||||||
goto done;
|
|
||||||
subdirs = new_subdirs;
|
|
||||||
max_subdirs += 64;
|
|
||||||
}
|
|
||||||
subdirs[num_subdirs] = strdup(pathbuf);
|
|
||||||
if (subdirs[num_subdirs] == NULL)
|
|
||||||
goto done;
|
|
||||||
num_subdirs++;
|
|
||||||
}
|
|
||||||
continue;
|
|
||||||
}
|
|
||||||
if (S_ISCHR(sb.st_mode) && sb.st_rdev == rdev) {
|
if (S_ISCHR(sb.st_mode) && sb.st_rdev == rdev) {
|
||||||
sudo_debug_printf(SUDO_DEBUG_INFO|SUDO_DEBUG_LINENO,
|
sudo_debug_printf(SUDO_DEBUG_INFO|SUDO_DEBUG_LINENO,
|
||||||
"resolved dev %u as %s", (unsigned int)rdev, pathbuf);
|
"resolved dev %u as %s", (unsigned int)rdev, pathbuf);
|
||||||
@@ -296,16 +275,9 @@ sudo_ttyname_scan(const char *dir, dev_t rdev, bool builtin, char *name, size_t
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
/* Search subdirs if we didn't find it in the root level. */
|
|
||||||
for (i = 0; ret == NULL && i < num_subdirs; i++)
|
|
||||||
ret = sudo_ttyname_scan(subdirs[i], rdev, false, name, namelen);
|
|
||||||
|
|
||||||
done:
|
done:
|
||||||
if (d != NULL)
|
if (d != NULL)
|
||||||
closedir(d);
|
closedir(d);
|
||||||
for (i = 0; i < num_subdirs; i++)
|
|
||||||
free(subdirs[i]);
|
|
||||||
free(subdirs);
|
|
||||||
debug_return_str(ret);
|
debug_return_str(ret);
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -324,7 +296,7 @@ sudo_ttyname_dev(dev_t rdev, char *name, size_t namelen)
|
|||||||
debug_decl(sudo_ttyname_dev, SUDO_DEBUG_UTIL)
|
debug_decl(sudo_ttyname_dev, SUDO_DEBUG_UTIL)
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* First check search_devs for common tty devices.
|
* First check search_devs[] for common tty devices.
|
||||||
*/
|
*/
|
||||||
for (sd = search_devs; (devname = *sd) != NULL; sd++) {
|
for (sd = search_devs; (devname = *sd) != NULL; sd++) {
|
||||||
len = strlen(devname);
|
len = strlen(devname);
|
||||||
@@ -349,7 +321,7 @@ sudo_ttyname_dev(dev_t rdev, char *name, size_t namelen)
|
|||||||
"comparing dev %u to %s: no", (unsigned int)rdev, buf);
|
"comparing dev %u to %s: no", (unsigned int)rdev, buf);
|
||||||
} else {
|
} else {
|
||||||
/* Traverse directory */
|
/* Traverse directory */
|
||||||
ret = sudo_ttyname_scan(devname, rdev, true, name, namelen);
|
ret = sudo_ttyname_scan(devname, rdev, name, namelen);
|
||||||
if (ret != NULL || errno == ENOMEM)
|
if (ret != NULL || errno == ENOMEM)
|
||||||
goto done;
|
goto done;
|
||||||
}
|
}
|
||||||
@@ -367,9 +339,9 @@ sudo_ttyname_dev(dev_t rdev, char *name, size_t namelen)
|
|||||||
}
|
}
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* Not found? Do a breadth-first traversal of /dev/.
|
* Not found? Check all device nodes in /dev.
|
||||||
*/
|
*/
|
||||||
ret = sudo_ttyname_scan(_PATH_DEV, rdev, false, name, namelen);
|
ret = sudo_ttyname_scan(_PATH_DEV, rdev, name, namelen);
|
||||||
|
|
||||||
done:
|
done:
|
||||||
debug_return_str(ret);
|
debug_return_str(ret);
|
||||||
@@ -493,28 +465,35 @@ get_process_ttyname(char *name, size_t namelen)
|
|||||||
len = getline(&line, &linesize, fp);
|
len = getline(&line, &linesize, fp);
|
||||||
fclose(fp);
|
fclose(fp);
|
||||||
if (len != -1) {
|
if (len != -1) {
|
||||||
/* Field 7 is the tty dev (0 if no tty) */
|
/*
|
||||||
char *cp = line;
|
* Field 7 is the tty dev (0 if no tty).
|
||||||
char *ep = line;
|
* Since the process name at field 2 "(comm)" may include spaces,
|
||||||
const char *errstr;
|
* start at the last ')' found.
|
||||||
int field = 0;
|
*/
|
||||||
while (*++ep != '\0') {
|
char *cp = strrchr(line, ')');
|
||||||
if (*ep == ' ') {
|
if (cp != NULL) {
|
||||||
*ep = '\0';
|
char *ep = cp;
|
||||||
if (++field == 7) {
|
const char *errstr;
|
||||||
dev_t tdev = strtonum(cp, INT_MIN, INT_MAX, &errstr);
|
int field = 1;
|
||||||
if (errstr) {
|
|
||||||
sudo_debug_printf(SUDO_DEBUG_ERROR|SUDO_DEBUG_LINENO,
|
while (*++ep != '\0') {
|
||||||
"%s: tty device %s: %s", path, cp, errstr);
|
if (*ep == ' ') {
|
||||||
|
*ep = '\0';
|
||||||
|
if (++field == 7) {
|
||||||
|
dev_t tdev = strtonum(cp, INT_MIN, INT_MAX, &errstr);
|
||||||
|
if (errstr) {
|
||||||
|
sudo_debug_printf(SUDO_DEBUG_ERROR|SUDO_DEBUG_LINENO,
|
||||||
|
"%s: tty device %s: %s", path, cp, errstr);
|
||||||
|
}
|
||||||
|
if (tdev > 0) {
|
||||||
|
errno = serrno;
|
||||||
|
ret = sudo_ttyname_dev(tdev, name, namelen);
|
||||||
|
goto done;
|
||||||
|
}
|
||||||
|
break;
|
||||||
}
|
}
|
||||||
if (tdev > 0) {
|
cp = ep + 1;
|
||||||
errno = serrno;
|
|
||||||
ret = sudo_ttyname_dev(tdev, name, namelen);
|
|
||||||
goto done;
|
|
||||||
}
|
|
||||||
break;
|
|
||||||
}
|
}
|
||||||
cp = ep + 1;
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
Reference in New Issue
Block a user