Severity: medium Category: security Location:src/shared/metadata.c:96-107, src/shared/file.c:61-77
Description:
When metadata preservation is enabled (-M/--preserve), the receiver restores the source file mode with chmod(path, metadata->mode & 07777). No validation is performed on the received mode. A malicious client can send a file with S_ISUID/S_ISGID/S_IWOTH bits set. If the server runs as root, this can create setuid executables or world-writable files on the destination system, leading to privilege escalation or unauthorized modification.
Suggested fix:
Strip dangerous mode bits by default (S_ISUID, S_ISGID, S_IWOTH) unless a new --preserve-perms=full or --super flag is used.
Validate that the received uid/gid are acceptable for the running user (e.g., do not allow chown to root unless running as root).
Consider refusing to setuid/setgid unless explicitly allowed by a server-side configuration flag.
Labels: security, privilege-escalation
**Severity:** medium
**Category:** security
**Location:** `src/shared/metadata.c:96-107`, `src/shared/file.c:61-77`
**Description:**
When metadata preservation is enabled (`-M`/`--preserve`), the receiver restores the source file mode with `chmod(path, metadata->mode & 07777)`. No validation is performed on the received mode. A malicious client can send a file with `S_ISUID`/`S_ISGID`/`S_IWOTH` bits set. If the server runs as root, this can create setuid executables or world-writable files on the destination system, leading to privilege escalation or unauthorized modification.
**Suggested fix:**
1. Strip dangerous mode bits by default (`S_ISUID`, `S_ISGID`, `S_IWOTH`) unless a new `--preserve-perms=full` or `--super` flag is used.
2. Validate that the received uid/gid are acceptable for the running user (e.g., do not allow chown to root unless running as root).
3. Consider refusing to setuid/setgid unless explicitly allowed by a server-side configuration flag.
**Labels:** security, privilege-escalation
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Severity: medium
Category: security
Location:
src/shared/metadata.c:96-107,src/shared/file.c:61-77Description:
When metadata preservation is enabled (
-M/--preserve), the receiver restores the source file mode withchmod(path, metadata->mode & 07777). No validation is performed on the received mode. A malicious client can send a file withS_ISUID/S_ISGID/S_IWOTHbits set. If the server runs as root, this can create setuid executables or world-writable files on the destination system, leading to privilege escalation or unauthorized modification.Suggested fix:
S_ISUID,S_ISGID,S_IWOTH) unless a new--preserve-perms=fullor--superflag is used.Labels: security, privilege-escalation