GHSA-88cv-mj24-8w3q

    Dashboard / Vulnerabilities / GHSA-88cv-mj24-8w3q

    GHSA-88cv-mj24-8w3q

    Published: 21 Sept 2022Last Modified: 8 Nov 2023

    Summary: arr-pm vulnerable to arbitrary shell execution when extracting or listing files contained in a malicious rpm.

    Details: ### Impact Arbitrary shell execution is possible when using RPM::File#files and RPM::File#extract if the RPM contains a malicious "payload compressor" field. This vulnerability impacts the `extract` and `files` methods of the `RPM::File` class in the affected versions of this library. ### Patches Version 0.0.12 is available with a fix for these issues. ### Workarounds When using an affected version of this library (arr-pm), ensure any RPMs being processed contain valid/known payload compressor values. Such values include: gzip, bzip2, xz, zstd, and lzma. You can check the payload compressor field in an rpm by using the rpm command line tool. For example: ``` % rpm -qp example-1.0-1.x86_64.rpm --qf "%{PAYLOADCOMPRESSOR}\n" gzip ``` ### Impact on known dependent projects This library is used by [fpm](https://github.com/jordansissel/fpm). The vulnerability may impact fpm only when using the flag `-s rpm` or `--input-type rpm` to convert a malicious rpm to another format. It does not impact creating rpms. ### References * https://github.com/jordansissel/ruby-arr-pm/pull/14 * https://github.com/jordansissel/ruby-arr-pm/pull/15 ### Credit Thanks to @joernchen for reporting this problem and contributing to the resolution :) ### For more information If you have any questions or comments about this advisory: * Open an issue in [the arr-pm issue tracker](https://github.com/jordansissel/ruby-arr-pm/)

    Affected packages

    Package

    Name: arr-pm

    Purl: pkg:gem/arr-pm

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -0.0.12

    Affected versions

    0.0.10
    0.0.11
    0.0.2
    0.0.3
    0.0.4
    0.0.5
    0.0.6
    0.0.7
    0.0.8
    0.0.9

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-88cv-mj24-8w3q | CVE-DB