Title: Directory traversal in uu module / uu.decode · Issue #99889 · python/cpython · GitHub
Open Graph Title: Directory traversal in uu module / uu.decode · Issue #99889 · python/cpython
X Title: Directory traversal in uu module / uu.decode · Issue #99889 · python/cpython
Description: Bug report The function uu.decode is vulnerable to trivial directory traversal if no output filename is given. An uu-encoded file with a path starting with a repetition of ../../ or a / allows writing a file to an arbitrary location on t...
Open Graph Description: Bug report The function uu.decode is vulnerable to trivial directory traversal if no output filename is given. An uu-encoded file with a path starting with a repetition of ../../ or a / allows writ...
X Description: Bug report The function uu.decode is vulnerable to trivial directory traversal if no output filename is given. An uu-encoded file with a path starting with a repetition of ../../ or a / allows writ...
Mail addresses
security@python.org
Opengraph URL: https://github.com/python/cpython/issues/99889
X: @github
Domain: github.com
{"@context":"https://schema.org","@type":"DiscussionForumPosting","headline":"Directory traversal in uu module / uu.decode","articleBody":"# Bug report\r\n\r\nThe function uu.decode is vulnerable to trivial directory traversal if no output filename is given. An uu-encoded file with a path starting with a repetition of ../../ or a / allows writing a file to an arbitrary location on the filesystem. \r\n\r\nI reported this to security@python.org and was asked to report it publicly as the function is rarely used and removal is planned anyway for Python 3.13.\r\n\r\n# Your environment\r\n\r\nCPython versions tested on: 3.10.8\r\nOperating system and architecture: Linux\r\n\r\n# example files\r\n\r\nCase 1:\r\n```\r\nbegin 644 ../../../../../../../../tmp/test1\r\n$86)C\"@``\r\n`\r\nend\r\n```\r\n\r\nCase 2:\r\n```\r\nbegin 644 /tmp/test2\r\n$86)C\"@``\r\n`\r\nend\r\n```\n\n\u003c!-- gh-linked-prs --\u003e\n### Linked PRs\n* gh-104096\n* gh-104329\n* gh-104330\n* gh-104331\n* gh-104332\n* gh-104333\n\u003c!-- /gh-linked-prs --\u003e\n","author":{"url":"https://github.com/hannob","@type":"Person","name":"hannob"},"datePublished":"2022-11-30T07:50:33.000Z","interactionStatistic":{"@type":"InteractionCounter","interactionType":"https://schema.org/CommentAction","userInteractionCount":2},"url":"https://github.com/99889/cpython/issues/99889"}
| route-pattern | /_view_fragments/issues/show/:user_id/:repository/:id/issue_layout(.:format) |
| route-controller | voltron_issues_fragments |
| route-action | issue_layout |
| fetch-nonce | v2:bf5ce253-a9e0-6570-a791-16ec087abdb4 |
| current-catalog-service-hash | 81bb79d38c15960b92d99bca9288a9108c7a47b18f2423d0f6438c5b7bcd2114 |
| request-id | C4F2:26204A:A0BFA0:D7F1F3:69699132 |
| html-safe-nonce | 4aee5ca1659dd87e7e7a140f913ec4c578f5412928359e4b2bd3912a97c1d891 |
| visitor-payload | eyJyZWZlcnJlciI6IiIsInJlcXVlc3RfaWQiOiJDNEYyOjI2MjA0QTpBMEJGQTA6RDdGMUYzOjY5Njk5MTMyIiwidmlzaXRvcl9pZCI6IjMwOTc3MTI1MDUwNzcyMDczNDYiLCJyZWdpb25fZWRnZSI6ImlhZCIsInJlZ2lvbl9yZW5kZXIiOiJpYWQifQ== |
| visitor-hmac | 216d7ee74c67d69db3bd925be30f13eb39b7c3d23d83723d470d4d63bc73dc44 |
| hovercard-subject-tag | issue:1469196184 |
| github-keyboard-shortcuts | repository,issues,copilot |
| google-site-verification | Apib7-x98H0j5cPqHWwSMm6dNU4GmODRoqxLiDzdx9I |
| octolytics-url | https://collector.github.com/github/collect |
| analytics-location | / |
| fb:app_id | 1401488693436528 |
| apple-itunes-app | app-id=1477376905, app-argument=https://github.com/_view_fragments/issues/show/python/cpython/99889/issue_layout |
| twitter:image | https://opengraph.githubassets.com/215f923279b8aae4dc55b74b942b7034260e8a08acb1139710f819cfa77ee342/python/cpython/issues/99889 |
| twitter:card | summary_large_image |
| og:image | https://opengraph.githubassets.com/215f923279b8aae4dc55b74b942b7034260e8a08acb1139710f819cfa77ee342/python/cpython/issues/99889 |
| og:image:alt | Bug report The function uu.decode is vulnerable to trivial directory traversal if no output filename is given. An uu-encoded file with a path starting with a repetition of ../../ or a / allows writ... |
| og:image:width | 1200 |
| og:image:height | 600 |
| og:site_name | GitHub |
| og:type | object |
| og:author:username | hannob |
| hostname | github.com |
| expected-hostname | github.com |
| None | 3542e147982176a7ebaa23dfb559c8af16f721c03ec560c68c56b64a0f35e751 |
| turbo-cache-control | no-preview |
| go-import | github.com/python/cpython git https://github.com/python/cpython.git |
| octolytics-dimension-user_id | 1525981 |
| octolytics-dimension-user_login | python |
| octolytics-dimension-repository_id | 81598961 |
| octolytics-dimension-repository_nwo | python/cpython |
| octolytics-dimension-repository_public | true |
| octolytics-dimension-repository_is_fork | false |
| octolytics-dimension-repository_network_root_id | 81598961 |
| octolytics-dimension-repository_network_root_nwo | python/cpython |
| turbo-body-classes | logged-out env-production page-responsive |
| disable-turbo | false |
| browser-stats-url | https://api.github.com/_private/browser/stats |
| browser-errors-url | https://api.github.com/_private/browser/errors |
| release | af80af7cc9e3de9c336f18b208a600950a3c187c |
| ui-target | full |
| theme-color | #1e2327 |
| color-scheme | light dark |
Links:
Viewport: width=device-width