New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
CPP: Add query for CWE-243 Creation of chroot Jail Without Changing Working Directory #6948
base: main
Are you sure you want to change the base?
Conversation
| not exists(ConditionalStmt cotmp | cotmp.getControllingExpr().getAChild*() = fc) and | ||
| not exists(Loop lptmp | lptmp.getCondition().getAChild*() = fc) and | ||
| not exists(ReturnStmt rttmp | rttmp.getExpr().getAChild*() = fc) and | ||
| not exists(Assignment astmp | astmp.getAChild*() = fc) and | ||
| not exists(Initializer ittmp | ittmp.getExpr().getAChild*() = fc) and |
If you just want to ensure that the return value of fc isn't checked, you can replace all of these conditions with this:
| not exists(ConditionalStmt cotmp | cotmp.getControllingExpr().getAChild*() = fc) and | |
| not exists(Loop lptmp | lptmp.getCondition().getAChild*() = fc) and | |
| not exists(ReturnStmt rttmp | rttmp.getExpr().getAChild*() = fc) and | |
| not exists(Assignment astmp | astmp.getAChild*() = fc) and | |
| not exists(Initializer ittmp | ittmp.getExpr().getAChild*() = fc) and | |
| fc instanceof ExprInVoidContext |
Thanks for the suggestion.
I'll take a look at the tests and accept it.
| fctmp.getASuccessor*() = fcp or | ||
| fcp.getASuccessor*() = fctmp |
You don't have to fix this, but I thought I should mention this:
Like I mentioned here, using Expr.getASuccessor*() (instead of BasicBlock.getASuccessor*()) likely means that your query may perform poorly on large projects. It may not be a problem since the optimizer may be able to help you out, but if we're ever to promote your query out of the experimental directory, this is something that we have to fix. If you do that fix for us, it may end up with a better final score.
cpp/ql/src/experimental/Security/CWE/CWE-243/IncorrectChangingWorkingDirectory.ql
Outdated
Show resolved
Hide resolved
cpp/ql/src/experimental/Security/CWE/CWE-243/IncorrectChangingWorkingDirectory.ql
Show resolved
Hide resolved
cpp/ql/src/experimental/Security/CWE/CWE-243/IncorrectChangingWorkingDirectory.ql
Show resolved
Hide resolved
cpp/ql/src/experimental/Security/CWE/CWE-243/IncorrectChangingWorkingDirectory.ql
Outdated
Show resolved
Hide resolved
cpp/ql/src/experimental/Security/CWE/CWE-243/IncorrectChangingWorkingDirectory.ql
Outdated
Show resolved
Hide resolved
cpp/ql/src/experimental/Security/CWE/CWE-243/IncorrectChangingWorkingDirectory.ql
Outdated
Show resolved
Hide resolved
|
Good afternoon. |
Co-authored-by: Mathias Vorreiter Pedersen <mathiasvp@github.com>
The request looks for situations of incorrect work with the setting of the working directory. first of all, this is the lack of checking the return value by the set function, secondly, it is the lack of setting after using the chroot call.
CVE-2008-5110
links to real work results, I will add later. I am currently working on them with developers.
The text was updated successfully, but these errors were encountered: