In-app reader
options.fileName is used to build a filesystem path
(path.join(tempDir.name, fileName)) and the caller-supplied document buffer is
written there, but fileName is never reduced to a base name. A fileName containing
"../" escapes the temporary directory, so a caller can write arbitrary content to an
arbitrary path the process can write to (e.g. ~/.ssh/authorized_keys, an /etc/cron.d
entry, or a web root).
Version 1.8.2 uses path.basename on filename to make sure the temp directory can not be escaped.
Make sure you supply the filename yourself and don't have it user supplied or use path.basename on filename before using it in libreoffice-convert.
Discussion
Sign in to join the discussion.
Keep reading
Optional: create a free account to save items, track programs, and sync across web + app. Reading stays free.