Migrate commands to subprocess

Bug #1412554 reported by costales
266
This bug affects 2 people
Affects Status Importance Assigned to Milestone
Gufw
Fix Released
Undecided
Unassigned
gui-ufw (Ubuntu)
Fix Released
Medium
Unassigned
Nominated for Vivid by Mathew Hodson

Bug Description

Careful with these Shell Injection characters: <>|;$&`

costales (costales)
Changed in gui-ufw:
status: New → In Progress
costales (costales)
summary: - Check character in Port & IP fields
+ Migrate commands to subprocess
description: updated
costales (costales)
Changed in gui-ufw:
status: In Progress → Fix Committed
Revision history for this message
Chris J Arges (arges) wrote : Please test proposed package

Hello costales, or anyone else affected,

Accepted gui-ufw into vivid-proposed. The package will build now and be available at https://launchpad.net/ubuntu/+source/gui-ufw/15.04.4-0ubuntu0.1 in a few hours, and then in the -proposed repository.

Please help us by testing this new package. See https://wiki.ubuntu.com/Testing/EnableProposed for documentation how to enable and use -proposed. Your feedback will aid us getting this update out to other Ubuntu users.

If this package fixes the bug for you, please add a comment to this bug, mentioning the version of the package you tested, and change the tag from verification-needed to verification-done. If it does not fix the bug for you, please add a comment stating that, and change the tag to verification-failed. In either case, details of your testing will help us make a better decision.

Further information regarding the verification process can be found at https://wiki.ubuntu.com/QATeam/PerformingSRUVerification . Thank you in advance!

tags: added: verification-needed
Revision history for this message
Bernd Dietzel (l-ubuntuone1104) wrote :

No Shell injection anymore on import or export, seems OK :-)

No Problems with profile import when language in not english and profile has english name, seems OK :-)

But i do we have a Problem with the GUI ?
The Gufw Window pops up again when i close the gufw main window.
I have to close Gufw a second time to exit.

Someone else have this effect ?

-----

I tested this Gufw Version :
15.04.4-0ubuntu0.1

I am using vivid-proposed.

I was testing on this OS :
UbuntuMate 15.04

~ $ uname -a
Linux mate 3.16.0-24-generic #32-Ubuntu SMP Tue Oct 28 13:13:18 UTC 2014 i686 i686 i686 GNU/Linux

~ $ lsb_release -a
No LSB modules are available.
Distributor ID: Ubuntu
Description: Ubuntu 15.04
Release: 15.04
Codename: vivid

Revision history for this message
Bruce Newman (bruce-landshut) wrote : Re: [Bug 1412554] Re: Migrate commands to subprocess

unsuscribe

On 01/07/15 16:48, Launchpad Bug Tracker wrote:
> ** Branch linked: lp:ubuntu/vivid-proposed/gui-ufw
>

Revision history for this message
costales (costales) wrote :

On Wed, Jul 1, 2015 at 7:41 PM, Bernd Dietzel <email address hidden>
wrote:

> The Gufw Window pops up again when i close the gufw main window.
> I have to close Gufw a second time to exit.
>

Hi Bernd!
Could you purge it?
sudo apt-get purge gufw
Remove the bin files:
sudo rm /usr/bin/gufw*
Install again:
sudo apt-get install gufw

A hug and thanks for your testing :)

Revision history for this message
Bernd Dietzel (l-ubuntuone1104) wrote :

Hi costales,
yes i purged , but nothing changed after new install.

But ... i found out with "locate gufw" that there was an other copy of gufw in :

/usr/lib/python2.7/site-packages/gufw

i removed this too, and installed gufw again.

Now its closing normal :-)

Revision history for this message
costales (costales) wrote :

 /usr/lib/python2.7/site-packages/gufw

That is the install from the repositories.

How did you install the buggy? :)

Revision history for this message
Bernd Dietzel (l-ubuntuone1104) wrote :

I think this may be because i installed Gufw manually with the "All in just one command" in your INSTALL file ,
from the "bazaar" long ago in February this Year.

This may have left the files in the site-packages folder wich lead to the problem ?

Revision history for this message
costales (costales) wrote :

Yes ;) It is by that :)
Thanks for your feedback Bernd!

Revision history for this message
Bernd Dietzel (l-ubuntuone1104) wrote :

OK :-) Thank you too.

By the way, take a look in my bug report list, i found Injection in many other python programs, not only in Gufw.
Maybe you can help them to fix their code, especially Clement L. from LinuxMint seems not to be aware of the danger....

with best regards
Bernd

Revision history for this message
Bruce Newman (bruce-landshut) wrote :

No idea! Sorry!
Bruce.

On 02/07/15 19:11, costales wrote:
> /usr/lib/python2.7/site-packages/gufw
>
> That is the install from the repositories.
>
> How did you install the buggy? :)
>

Revision history for this message
Bruce Newman (bruce-landshut) wrote :

It's all a mystery to me,
Regards, Bruce.

On 02/07/15 19:39, Bernd Dietzel wrote:
> I think this may be because i installed Gufw manually with the "All in just one command" in your INSTALL file ,
> from the "bazaar" long ago in February this Year.
>
> This may have left the files in the site-packages folder wich lead to
> the problem ?
>

Revision history for this message
Bruce Newman (bruce-landshut) wrote :

I take it that you are not addressing me,
Regards, Bruce.

On 02/07/15 19:49, costales wrote:
> Yes ;) It is by that :)
> Thanks for your feedback Bernd!
>

Revision history for this message
Bruce Newman (bruce-landshut) wrote :

Me neither,
Regards, Bruce.

On 02/07/15 20:50, Bernd Dietzel wrote:
> OK :-) Thank you too.
>
> By the way, take a look in my bug report list, i found Injection in many other python programs, not only in Gufw.
> Maybe you can help them to fix their code, especially Clement L. from LinuxMint seems not to be aware of the danger....
>
> with best regards
> Bernd
>

Revision history for this message
costales (costales) wrote :

On Thu, Jul 2, 2015 at 9:50 PM, Bernd Dietzel <email address hidden>
wrote:

> take a look in my bug report list

Wow Bernd! You found a lot of injections :S
Did you create them into the uptream too? https://github.com/linuxmint

Honestly, I was thinking that these injections were only in SQL :$Really
thanks a lot for your feedback! I appreciate it :))
A big hug!

Mathew Hodson (mhodson)
Changed in gui-ufw (Ubuntu):
status: New → Fix Released
importance: Undecided → Medium
information type: Public → Public Security
costales (costales)
Changed in gui-ufw:
status: Fix Committed → Fix Released
Mathew Hodson (mhodson)
tags: added: verification-done
removed: verification-needed
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.