T09 · Insecure Skill Coding Practices
- Location
scripts/vidiq.sh:91- Finding
Command Execution Through Unvalidated Bash Arithmetic Expressions
- Content
View full analysis
/dev/null else INTERVAL=$(( DUR / (N - 1) )) for i in $(seq 1 "$N"); do TS=$(( (i - 1) * INTERVAL )) if (( TS > DUR )); then TS=$DUR; fi FNAME=$(printf "frame_%03d_%02dm%02ds.jpg" "$i" "$((TS/60))" "$((TS%60))") ffmpeg -y -ss "$TS" -i "$LOCAL" -frames:v 1 -q:v 2 "$OUTDIR/$FNAME" 2>/dev/null echo " [$i/$N] ${TS}s -> $FNAME" done fi ``` ```bash mosaic) COLS="${1:-4}" N="${2:-16}" OUT="$WORK/mosaic_$(date +%s).jpg" DUR=$(get_duration) echo "[vidiq] Creating ${COLS}x mosaic from $N frames..." TMPDIR="$WORK/.mosaic_tmp_$$" mkdir -p "$TMPDIR" INTERVAL=$(( DUR / N )) for i in $(seq 1 "$N"); do TS=$(( (i - 1) * INTERVAL + INTERVAL / 2 )) ffmpeg -y -ss "$TS" -i "$LOCAL" -frames:v 1 -q:v 3 -vf "scale=320:-1" "$TMPDIR/f$(printf '%03d' $i).jpg" 2>/dev/null done ffmpeg -y -pattern_type glob -i "$TMPDIR/f*.jpg" \ -vf "tile=${COLS}x$(( (N + COLS - 1) / COLS ))" -q:v 2 "$OUT" 2>/dev/null ``` ### Technical Analysis The `frames` and `mosaic` commands assign caller-controlled strings directly to `N` and `COLS`. Those values are subsequently referenced in Bash arithmetic contexts such as: ```bash (( N == 1 )) $(( DUR / (N - 1) )) $(( DUR / N )) $(( (N + COLS - 1) / COLS )) ``` Bash arithmetic evaluation does not merely convert an arbitrary string into an integer. Variable values ...[truncated 1811 chars]- Remediation
View remediation
&2 exit 2 fi if (( 10#$value > maximum )); then printf '[vidiq] ERROR: %s must not exceed %d\n' "$name" "$maximum" >&2 exit 2 fi } N="${1:-10}" validate_positive_integer "frame count" "$N" 1000 N=$((10#$N)) ``` For mosaics, validate both dimensions independently: ```bash COLS="${1:-4}" N="${2:-16}" validate_positive_integer "column count" "$COLS" 50 validate_positive_integer "frame count" "$N" 1000 COLS=$((10#$COLS)) N=$((10#$N)) ``` Additional hardening should include: - Rejecting zero before any division. - Setting practical limits for frame counts, columns, GIF durations, and other resource-sensitive parameters. - Validating timestamps and scene thresholds against strict accepted formats. - Avoiding the treatment of untrusted strings as arithmetic expressions. - Applying execution time, file-size, disk-space, and process limits around expensive `ffmpeg` operations. ]]>
