fix(lib): fix `omz_urldecode` unsafe eval bug
The `omz_urldecode` function uses an eval to decode the input which can be
exploited to inject commands. This is used only in the svn plugin and it
requires a complex process to exploit, so it is highly unlikely to have been
used by an attacker.
Diff
1diff --git a/lib/functions.zsh b/lib/functions.zsh
2index fc53611b82649b7fccaa6c4d77d1bc0d06d9ae30..61f4dd49e0e877b71a1e2ad2069e6fbab26f2df3 100644
3--- a/lib/functions.zsh
4+++ b/lib/functions.zsh
5@@ -237,12 +237,11 @@ function omz_urldecode {
6 tmp=${tmp:gs/\\/\\\\/}
7 # Handle %-escapes by turning them into `\xXX` printf escapes
8 tmp=${tmp:gs/%/\\x/}
9- local decoded
10- eval "decoded=\$'$tmp'"
11+ local decoded="$(printf -- "$tmp")"
1213 # Now we have a UTF-8 encoded string in the variable. We need to re-encode
14 # it if caller is in a non-UTF-8 locale.
15- local safe_encodings
16+ local -a safe_encodings
17 safe_encodings=(UTF-8 utf8 US-ASCII)
18 if [[ -z ${safe_encodings[(r)$caller_encoding]} ]]; then
19 decoded=$(echo -E "$decoded" | iconv -f UTF-8 -t $caller_encoding)