mirror of
https://github.com/hrydgard/ppsspp.git
synced 2026-10-01 14:58:14 +00:00
Store: reject path traversal in the store index's "file" field
entry.file comes from the remote store catalog (index.json) and is joined onto DIRECTORY_GAME verbatim in OnLaunchClick() - Path::operator/ does plain string concatenation with no ".." normalization. On platforms/builds where the index isn't fetched over HTTPS (SYSPROP_SUPPORTS_HTTPS false), a network MITM or a compromised store backend could use a crafted "file" value to make "Launch" boot an arbitrary host file path instead of the selected store item. Reuse the existing HasParentDirComponent() helper to reject such entries.
This commit is contained in:
1 parent
7f7fe3c712
commit
e35764d8e0
1 file changed
+7
@@ -34,6 +34,7 @@
|
||||
#include "Core/Config.h"
|
||||
#include "Core/System.h"
|
||||
#include "Core/Util/GameManager.h"
|
||||
#include "Core/Util/PathUtil.h"
|
||||
#include "UI/EmuScreen.h"
|
||||
#include "UI/Store.h"
|
||||
|
||||
@@ -498,6 +499,12 @@ void StoreScreen::ParseListing(const std::string &json) {
|
||||
const char *file = game.getStringOr("file", nullptr);
|
||||
if (!file)
|
||||
continue;
|
||||
// entry_.file gets joined onto DIRECTORY_GAME verbatim in OnLaunchClick()
|
||||
// (Path::operator/ does no ".." normalization); on platforms/builds where
|
||||
// the store index isn't fetched over HTTPS, a MITM'd or compromised
|
||||
// response could otherwise point "launch" at an arbitrary host path.
|
||||
if (HasParentDirComponent(file))
|
||||
continue;
|
||||
e.file = file;
|
||||
entries_.push_back(e);
|
||||
}
|
||||
|
||||
Reference in new issue
Block a user