Skip to content

[SECURITY] - An attacker can write files with exact names to arbitrary locations on the filesystem #714

Description

@rodtvs

Description

Xreader 4.6.3 (commit ef5a50d) passes the raw PDF attachment filename directly to g_file_get_child() when saving attachments via "Save Attachment As...". Since g_file_get_child() resolves ../ sequences, an attacker-controlled filename can escape the user-selected target directory and write files to arbitrary locations with the exact filename specified by the attacker — no random suffix.

This is the most critical of the attachment vulnerabilities, as it enables writing .desktop files (or any other file) with precise names to arbitrary locations, leading to arbitrary code execution.

Affected Code

shell/ev-window.c:7374:

save_to = g_file_get_child(target_file, ev_attachment_get_name(attachment));

shell/ev-window.c:7400:

dest_file = g_file_get_child(target_file, ev_attachment_get_name(attachment));

Both the local and remote save paths use the unsanitized attachment name.

Steps to Reproduce

  1. Generate a malicious PDF using the PoC script from the full report — the attachment is named ../Desktop/test.desktop and contains a valid .desktop entry that executes an arbitrary command
  2. Open poc.pdf in xreader
  3. In the sidebar, right-click the attachment and select "Save Attachment As..."
  4. Select any directory (e.g., ~/Documents/)
  5. test.desktop is written to ~/Desktop/ instead of the selected directory
  6. Double-clicking the .desktop file executes the embedded command

Suggested Fix

Extract the basename before passing to g_file_get_child() in both code paths:

// line 7374
-save_to = g_file_get_child(target_file, ev_attachment_get_name(attachment));
+gchar *basename = g_path_get_basename(ev_attachment_get_name(attachment));
+save_to = g_file_get_child(target_file, basename);
+g_free(basename);

// line 7400
-dest_file = g_file_get_child(target_file, ev_attachment_get_name(attachment));
+gchar *basename = g_path_get_basename(ev_attachment_get_name(attachment));
+dest_file = g_file_get_child(target_file, basename);
+g_free(basename);

Impact

An attacker can write files with exact names to arbitrary locations on the filesystem. By writing a .desktop file to ~/Desktop/, arbitrary code execution is achieved when the user double-clicks it. The only user interaction required is opening the PDF, right-clicking the attachment, selecting "Save As", and choosing any directory.

References

Activity

  1. yochananmarqos commented on May 25, 2026

    @yochananmarqos

    Was this not already fixed with 4.6.4 with 50052ea?

  2. rodtvs commented on May 31, 2026

    @rodtvs
    Author

    Was this not already fixed with 4.6.4 with 50052ea?

    I think No, commit 50052ea (released as 4.6.4) fixes a different vulnerability argument injection in ev_spawn (shell/ev-application.c). The 2 issues I reported are in backend/epub/epub-document.c, libdocument/ev-attachment.c, shell/ev-sidebar-attachments.c, and shell/ev-window.c. None of these files have been modified between ef5a50d (the commit my report was filed against) and tag 4.6.5. The reported vulnerabilities are still present in the current code.

  3. yochananmarqos commented on May 31, 2026

    @yochananmarqos

    Oh, I was just going by this GNOME blog post.

  4. clefebvre commented on Sep 4, 2026

    @clefebvre
    Member

    EPUB support was removed from Xreader and reimplemented in Xepub: https://github.com/xapp-project/xepub.

  5. clefebvre commented on Oct 6, 2026

    @clefebvre
    Member

    Sorry, I closed this one by mistake while closing epub related issues.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions