T09 · Insecure Skill Coding Practices
- Location
scripts/build_deb.sh:23- Finding
Predictable Temporary Build Directory Permits Local Filesystem Manipulation
- Content
View full analysis
"$PKG_DIR/DEBIAN/control" << EOF Package: ${APPID} Version: ${VERSION} Section: utils Priority: optional Architecture: ${ARCH} Maintainer: $(whoami) <$(whoami)@localhost> Description: UOS Application EOF ``` A local attacker who creates the predicted path first may populate it with attacker-controlled directories or symbolic links. Subsequent writes and copies can then target locations selected by the attacker, subject to the victim user's filesystem permissions. The attacker may also alter files in the build tree and thereby tamper with the generated package. ### Attack Path 1. A local attacker monitors process identifiers or repeatedly creates likely future paths such as `/tmp/uos_build_12345`. 2. Before the victim starts the build, the attacker creates the predicted directory and places crafted subdirectories or symbolic links within it. 3. The victim executes `scripts/build_deb.sh`. 4. `mkdir -p` accepts the pre-existing path instead of establishing a new, p ...[truncated 844 chars]- Remediation
View remediation
&2 exit 1 } chmod 700 "$BUILD_DIR" trap 'rm -rf -- "$BUILD_DIR"' EXIT HUP INT TERM ``` Additional hardening measures include: 1. Reject symbolic links in any sensitive destination path. 2. Verify that generated package directories remain beneath the canonical temporary directory. 3. Use `umask 077` before creating temporary files. 4. Avoid relying on process IDs, timestamps, or other predictable values for temporary names. 5. Keep the cleanup command quoted and include `--` before the path. ]]>
