Files
DeDRM_tools/DeDRM_plugin
JMR-devandClaude Opus 4.8 768d49094c Fix path traversal in Topaz extraction (arbitrary file write)
The Topaz header record "tag" is read verbatim from the untrusted book
file by bookReadString() and then used unsanitized to build the output
filename in extractFiles(). A crafted tag such as "../../foo" let a
malicious .azw/Topaz file write attacker-controlled bytes outside the
extraction directory. The payload content requires no book key, since an
unencrypted record with compressedLength == 0 is returned raw.

Strip the record name to its basename before joining it to destdir so
traversal sequences (../, /, \) can no longer escape, and add an
abspath-based containment check as defense in depth.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-22 18:21:42 -05:00
..
2023-08-06 15:49:52 +02:00
2023-08-02 07:39:35 +02:00
2023-08-03 21:53:16 +02:00
2023-08-03 20:01:38 +02:00
2023-08-03 20:45:06 +02:00
2023-08-06 15:49:52 +02:00
2021-11-17 21:53:24 +01:00
2023-08-06 15:49:52 +02:00
2024-11-10 13:10:11 +00:00
2021-12-29 12:18:06 +00:00
2023-08-06 15:49:52 +02:00
2023-08-06 15:49:52 +02:00
2023-08-06 15:49:52 +02:00
2023-12-21 11:57:39 +01:00
2024-11-10 20:15:33 +01:00
2023-08-03 20:45:06 +02:00
2023-08-03 20:01:38 +02:00
2023-08-06 15:49:52 +02:00
2023-08-06 15:49:52 +02:00
2022-01-11 07:57:02 +01:00
2023-08-03 20:45:06 +02:00
2022-08-07 09:30:24 +02:00
2022-03-19 16:02:33 +01:00