diff --git a/DeDRM_plugin/topazextract.py b/DeDRM_plugin/topazextract.py index 97d75a7..4f2c057 100644 --- a/DeDRM_plugin/topazextract.py +++ b/DeDRM_plugin/topazextract.py @@ -358,7 +358,16 @@ class TopazBook: destdir = os.path.join(outdir,"page") if name == b'glyphs': destdir = os.path.join(outdir,"glyphs") + # The record name is read verbatim from the (untrusted) book + # file, so strip any directory components to stop a crafted + # name (e.g. "../../foo") from writing outside of destdir. + fname = os.path.basename(fname) outputFile = os.path.join(destdir,fname) + # Defense in depth: never let the resolved path escape destdir. + real_out = os.path.abspath(outputFile) + real_dir = os.path.abspath(destdir) + if not (real_out == real_dir or real_out.startswith(real_dir + os.sep)): + raise DrmException("Invalid book record name: {0}".format(repr(name))) print(".", end=' ') record = self.getBookPayloadRecord(name,index) if isinstance(record, str):