Browse Source

fix(lib): fix potential command injection in `title` and `spectrum` functions

The `title` function unsafely prints its input without sanitization, which if used
with custom user code that calls it, it could trigger command injection.

The `spectrum_ls` and `spectrum_bls` could similarly be exploited if a variable is
changed in the user's shell environment with a carefully crafted value. This is
highly unlikely to occur (and if possible, other methods would be used instead),
but with this change the exploit of these two functions is now impossible.
Marc Cornellà 2 years ago
parent
commit
a263cdac9c
2 changed files with 10 additions and 9 deletions
  1. 4 2
      lib/spectrum.zsh
  2. 6 7
      lib/termsupport.zsh

+ 4 - 2
lib/spectrum.zsh

@@ -20,16 +20,18 @@ done
 
 
 # Show all 256 colors with color number
 # Show all 256 colors with color number
 function spectrum_ls() {
 function spectrum_ls() {
+  setopt localoptions nopromptsubst
   local ZSH_SPECTRUM_TEXT=${ZSH_SPECTRUM_TEXT:-Arma virumque cano Troiae qui primus ab oris}
   local ZSH_SPECTRUM_TEXT=${ZSH_SPECTRUM_TEXT:-Arma virumque cano Troiae qui primus ab oris}
   for code in {000..255}; do
   for code in {000..255}; do
-    print -P -- "$code: $FG[$code]$ZSH_SPECTRUM_TEXT%{$reset_color%}"
+    print -P -- "$code: ${FG[$code]}${ZSH_SPECTRUM_TEXT}%{$reset_color%}"
   done
   done
 }
 }
 
 
 # Show all 256 colors where the background is set to specific color
 # Show all 256 colors where the background is set to specific color
 function spectrum_bls() {
 function spectrum_bls() {
+  setopt localoptions nopromptsubst
   local ZSH_SPECTRUM_TEXT=${ZSH_SPECTRUM_TEXT:-Arma virumque cano Troiae qui primus ab oris}
   local ZSH_SPECTRUM_TEXT=${ZSH_SPECTRUM_TEXT:-Arma virumque cano Troiae qui primus ab oris}
   for code in {000..255}; do
   for code in {000..255}; do
-    print -P -- "$code: $BG[$code]$ZSH_SPECTRUM_TEXT%{$reset_color%}"
+    print -P -- "$code: ${BG[$code]}${ZSH_SPECTRUM_TEXT}%{$reset_color%}"
   done
   done
 }
 }

+ 6 - 7
lib/termsupport.zsh

@@ -7,8 +7,7 @@
 # (In screen, only short_tab_title is used)
 # (In screen, only short_tab_title is used)
 # Limited support for Apple Terminal (Terminal can't set window and tab separately)
 # Limited support for Apple Terminal (Terminal can't set window and tab separately)
 function title {
 function title {
-  emulate -L zsh
-  setopt prompt_subst
+  setopt localoptions nopromptsubst
 
 
   # Don't set the title if inside emacs, unless using vterm
   # Don't set the title if inside emacs, unless using vterm
   [[ -n "$INSIDE_EMACS" && "$INSIDE_EMACS" != vterm ]] && return
   [[ -n "$INSIDE_EMACS" && "$INSIDE_EMACS" != vterm ]] && return
@@ -48,13 +47,13 @@ fi
 
 
 # Runs before showing the prompt
 # Runs before showing the prompt
 function omz_termsupport_precmd {
 function omz_termsupport_precmd {
-  [[ "${DISABLE_AUTO_TITLE:-}" == true ]] && return
-  title $ZSH_THEME_TERM_TAB_TITLE_IDLE $ZSH_THEME_TERM_TITLE_IDLE
+  [[ "${DISABLE_AUTO_TITLE:-}" != true ]] || return
+  title "$ZSH_THEME_TERM_TAB_TITLE_IDLE" "$ZSH_THEME_TERM_TITLE_IDLE"
 }
 }
 
 
 # Runs before executing the command
 # Runs before executing the command
 function omz_termsupport_preexec {
 function omz_termsupport_preexec {
-  [[ "${DISABLE_AUTO_TITLE:-}" == true ]] && return
+  [[ "${DISABLE_AUTO_TITLE:-}" != true ]] || return
 
 
   emulate -L zsh
   emulate -L zsh
   setopt extended_glob
   setopt extended_glob
@@ -97,10 +96,10 @@ function omz_termsupport_preexec {
   fi
   fi
 
 
   # cmd name only, or if this is sudo or ssh, the next cmd
   # cmd name only, or if this is sudo or ssh, the next cmd
-  local CMD=${1[(wr)^(*=*|sudo|ssh|mosh|rake|-*)]:gs/%/%%}
+  local CMD="${1[(wr)^(*=*|sudo|ssh|mosh|rake|-*)]:gs/%/%%}"
   local LINE="${2:gs/%/%%}"
   local LINE="${2:gs/%/%%}"
 
 
-  title '$CMD' '%100>...>$LINE%<<'
+  title "$CMD" "%100>...>${LINE}%<<"
 }
 }
 
 
 autoload -Uz add-zsh-hook
 autoload -Uz add-zsh-hook