72928432f1ddaa244e02067dd7fc14948a4a5ce4
Author Marc Cornellà <hello@mcornella.com> Committer Marc Cornellà <hello@mcornella.com> Date 2021-11-11 21:45 UTC
Message fix(plugins): fix potential command injection in `rand-quote` and `hitokoto`
The `rand-quote` plugin uses quotationspage.com and prints part of its content to the
shell without sanitization, which could trigger command injection. There is no evidence
that this has been exploited, but this commit removes all possibility for exploit.
Similarly, the `hitokoto` plugin uses the hitokoto.cn website to print quotes to the
shell, also without sanitization. Furthermore, there is also no evidence that this has
been exploited, but with this change it is now impossible.
Diff 1 diff --git a/plugins/hitokoto/hitokoto.plugin.zsh b/plugins/hitokoto/hitokoto.plugin.zsh
2 index 8646ebf3b48e9aa735b673a650d4f2c30d170933..e346d18c515af4c81152656e8cdf1b8907c9bc74 100644
3 --- a/plugins/hitokoto/hitokoto.plugin.zsh
4 +++ b/plugins/hitokoto/hitokoto.plugin.zsh
5 @@ -1,14 +1,18 @@
6 if ! (( $+commands[curl] )); then
7 - echo "hitokoto plugin needs curl to work" >&2
8 - return
9 + echo "hitokoto plugin needs curl to work" >&2
10 + return
11 fi
12
13 function hitokoto {
14 - emulate -L zsh
15 - Q=$(curl -s --connect-timeout 2 "https://v1.hitokoto.cn" | jq -j '.hitokoto+"\t"+.from')
16 + setopt localoptions nopromptsubst
17
18 - TXT=$(echo "$Q" | awk -F '\t' '{print $1}')
19 - WHO=$(echo "$Q" | awk -F '\t' '{print $2}')
20 + # Get hitokoto data
21 + local -a data
22 + data=("${(ps:\n:)"$(command curl -s --connect-timeout 2 "https://v1.hitokoto.cn" | command jq -j '.hitokoto+"\n"+.from')"}")
23
24 - [[ -n "$WHO" && -n "$TXT" ]] && print -P "%F{3}${WHO}%f: “%F{5}${TXT}%f”"
25 + # Exit if could not fetch hitokoto
26 + [[ -n "$data" ]] || return 0
27 +
28 + local quote="${data[1]}" author="${data[2]}"
29 + print -P "%F{3}${author}%f: “%F{5}${quote}%f”"
30 }
31 diff --git a/plugins/rand-quote/rand-quote.plugin.zsh b/plugins/rand-quote/rand-quote.plugin.zsh
32 index 371b997d389ebca156b857d65d1e02b0fb9d1ea7..23c21dc8f24b887a3dd42493bf572899fba1e7cf 100644
33 --- a/plugins/rand-quote/rand-quote.plugin.zsh
34 +++ b/plugins/rand-quote/rand-quote.plugin.zsh
35 @@ -1,14 +1,23 @@
36 if ! (( $+commands[curl] )); then
37 - echo "rand-quote plugin needs curl to work" >&2
38 - return
39 + echo "rand-quote plugin needs curl to work" >&2
40 + return
41 fi
42
43 function quote {
44 - emulate -L zsh
45 - Q=$(curl -s --connect-timeout 2 "http://www.quotationspage.com/random.php" | iconv -c -f ISO-8859-1 -t UTF-8 | grep -m 1 "dt ")
46 + setopt localoptions nopromptsubst
47
48 - TXT=$(echo "$Q" | sed -e 's/<\/dt>.*//g' -e 's/.*html//g' -e 's/^[^a-zA-Z]*//' -e 's/<\/a..*$//g')
49 - WHO=$(echo "$Q" | sed -e 's/.*\/quotes\///g' -e 's/<.*//g' -e 's/.*">//g')
50 + # Get random quote data
51 + local data
52 + data="$(command curl -s --connect-timeout 2 "http://www.quotationspage.com/random.php" \
53 + | iconv -c -f ISO-8859-1 -t UTF-8 \
54 + | command grep -a -m 1 'dt class="quote"')"
55
56 - [[ -n "$WHO" && -n "$TXT" ]] && print -P "%F{3}${WHO}%f: “%F{5}${TXT}%f”"
57 + # Exit if could not fetch random quote
58 + [[ -n "$data" ]] || return 0
59 +
60 + local quote author
61 + quote=$(sed -e 's|</dt>.*||g' -e 's|.*html||g' -e 's|^[^a-zA-Z]*||' -e 's|</a..*$||g' <<< "$data")
62 + author=$(sed -e 's|.*/quotes/||g' -e 's|<.*||g' -e 's|.*">||g' <<< "$data")
63 +
64 + print -P "%F{3}${author}%f: “%F{5}${quote}%f”"
65 }