T07 · Tool Hijacking and Spoofing
- Location
scripts/office/soffice.py:24- Finding
Untrusted Shared Temporary Library Loaded Through LD_PRELOAD
- Content
View full analysis
dict: env = os.environ.copy() env["SAL_USE_VCLPLUGIN"] = "svp" if _needs_shim(): shim = _ensure_shim() env["LD_PRELOAD"] = str(shim) return env def run_soffice(args: list[str], **kwargs) -> subprocess.CompletedProcess: env = get_soffice_env() return subprocess.run(["soffice"] + args, env=env, **kwargs) _SHIM_SO = Path(tempfile.gettempdir()) / "lo_socket_shim.so" def _needs_shim() -> bool: try: s = socket.socket(socket.AF_UNIX, socket.SOCK_STREAM) s.close() return False except OSError: return True def _ensure_shim() -> Path: if _SHIM_SO.exists(): return _SHIM_SO src = Path(tempfile.gettempdir()) / "lo_socket_shim.c" src.write_text(_SHIM_SOURCE) subprocess.run( ["gcc", "-shared", "-fPIC", "-o", str(_SHIM_SO), str(src), "-ldl"], check=True, capture_output=True, ) src.unlink() return _SHIM_SO ``` ### Technical Analysis The application stores its preload library at the fixed shared-temporary path `/tmp/lo_socket_shim.so`. When the file already exists, `_ensure_shim()` returns it without verifying: - File ownership - File permissions - Whether it is a symbolic link - Whether it is a regular file - Its content or cryptographic digest - Whether it was produced by the current process When Unix-domain sockets are unavailable, the returned path is assigned to `LD_PRELOAD`. LibreOffice is then executed with that environment, causing the operating-system dynamic loader to load the referenced library before starting the application. The predictable source path `/tmp/lo_socket_shim.c` and non-atomic compilation output introduce additional symbolic-link and time-of-c ...[truncated 1544 chars]- Remediation
View remediation
