6cb41b70a6d04301fd50cd5862ecd705ba226c0e

Author
Marc Cornellà <hello@mcornella.com>
Committer
Marc Cornellà <hello@mcornella.com>
Date

Message

fix(lib): fix `omz_urldecode` unsafe eval bug

The `omz_urldecode` function uses an eval to decode the input which can be
exploited to inject commands. This is used only in the svn plugin and it
requires a complex process to exploit, so it is highly unlikely to have been
used by an attacker.

Diff

 1diff --git a/lib/functions.zsh b/lib/functions.zsh
 2index fc53611b82649b7fccaa6c4d77d1bc0d06d9ae30..61f4dd49e0e877b71a1e2ad2069e6fbab26f2df3 100644
 3--- a/lib/functions.zsh
 4+++ b/lib/functions.zsh
 5@@ -237,12 +237,11 @@ function omz_urldecode {
 6   tmp=${tmp:gs/\\/\\\\/}
 7   # Handle %-escapes by turning them into `\xXX` printf escapes
 8   tmp=${tmp:gs/%/\\x/}
 9-  local decoded
10-  eval "decoded=\$'$tmp'"
11+  local decoded="$(printf -- "$tmp")"
12 
13   # Now we have a UTF-8 encoded string in the variable. We need to re-encode
14   # it if caller is in a non-UTF-8 locale.
15-  local safe_encodings
16+  local -a safe_encodings
17   safe_encodings=(UTF-8 utf8 US-ASCII)
18   if [[ -z ${safe_encodings[(r)$caller_encoding]} ]]; then
19     decoded=$(echo -E "$decoded" | iconv -f UTF-8 -t $caller_encoding)