T09 · Insecure Skill Coding Practices
- Location
scripts/script.sh:124- Finding
Arbitrary Command Execution Through Unvalidated Arithmetic Expressions
- Content
View full analysis
"$outfile" ;; circle) svg_shape_circle "$size" "$color" > "$outfile" ;; square|check|close|plus|minus) svg_shape_square "$size" "$color" > "$outfile" ;; star|heart|bookmark) svg_shape_star "$size" "$color" > "$outfile" ;; *) svg_shape_placeholder "$size" "$color" "$name" > "$outfile" ;; esac } ``` The resulting value is evaluated in arithmetic contexts such as: ```bash local r=$(( size/2 - 2 )) ``` and: ```bash ``` ### Technical Analysis The `--size` argument is stored without verifying that it contains only a positive decimal integer. The value subsequently reaches multiple Bash arithmetic contexts. Bash arithmetic evaluation can recursively interpret variable contents as arithmetic expressions. Malicious arithmetic syntax, particularly expressions using array subscripts and command substitutions, can therefore cause shell commands embedded in the supplied value to execute during icon generation. Normal shell quoting around `"$size"` when passing it to an icon function does not make its later use in `$((...))` safe. The dangerous interpretation occurs inside the arithmetic evaluation itself. ### Attack Path 1. An ...[truncated 1382 chars]- Remediation
View remediation
= 4 && 10#$value <= 4096 )) || die "Size must be between 4 and 4096" } ``` Call validation immediately after parsing: ```bash validate_size "$size" size=$((10#$size)) ``` Apply equivalent validation independently to every entry accepted through `--sizes`. Reject empty entries, signs, whitespace, arithmetic operators, variable names, brackets, command substitutions, and values outside a reasonable resource limit. Do not rely on quoting alone to protect values later interpreted by Bash arithmetic evaluation. ]]>
