Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.bugs.dist > #1260426 > unrolled thread

Bug#1114635: python-internetarchive: CVE-2025-58438: Directory Traversal in File.download()

Started bySalvatore Bonaccorso <carnil@debian.org>
First post2025-09-07 20:40 +0200
Last post2025-09-18 22:10 +0200
Articles 5 — 3 participants

Back to article view | Back to linux.debian.bugs.dist


Contents

  Bug#1114635: python-internetarchive: CVE-2025-58438: Directory Traversal in File.download() Salvatore Bonaccorso <carnil@debian.org> - 2025-09-07 20:40 +0200
    Bug#1114635: python-internetarchive: CVE-2025-58438: Directory Traversal in File.download() Antoine Beaupré <anarcat@debian.org> - 2025-09-08 16:10 +0200
      Bug#1114635: python-internetarchive: CVE-2025-58438: Directory Traversal in File.download() Antoine Beaupré <anarcat@debian.org> - 2025-09-09 20:10 +0200
        Bug#1114635: python-internetarchive: CVE-2025-58438: Directory Traversal in File.download() Salvatore Bonaccorso <carnil@debian.org> - 2025-09-11 22:10 +0200
    Bug#1114635: python-internetarchive: CVE-2025-58438: Directory Traversal in File.download() Moritz Mühlenhoff <jmm@inutil.org> - 2025-09-18 22:10 +0200

#1260426 — Bug#1114635: python-internetarchive: CVE-2025-58438: Directory Traversal in File.download()

FromSalvatore Bonaccorso <carnil@debian.org>
Date2025-09-07 20:40 +0200
SubjectBug#1114635: python-internetarchive: CVE-2025-58438: Directory Traversal in File.download()
Message-ID<LsssV-dzcl-1@gated-at.bofh.it>
Source: python-internetarchive
Version: 5.4.0-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: carnil@debian.org, Debian Security Team <team@security.debian.org>

Hi,

The following vulnerability was published for python-internetarchive.

CVE-2025-58438[0]:
| internetarchive is a Python and Command-Line Interface to
| Archive.org In versions 5.5.0 and below, there is a directory
| traversal (path traversal) vulnerability in the File.download()
| method of the internetarchive library. The file.download() method
| does not properly sanitize user-supplied filenames or validate the
| final download path. A maliciously crafted filename could contain
| path traversal sequences (e.g.,
| ../../../../windows/system32/file.txt) or illegal characters that,
| when processed, would cause the file to be written outside of the
| intended target directory. An attacker could potentially overwrite
| critical system files or application configuration files, leading to
| a denial of service, privilege escalation, or remote code execution,
| depending on the context in which the library is used.  The
| vulnerability is particularly critical for users on Windows systems,
| but all operating systems are affected. This issue is fixed in
| version 5.5.1.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2025-58438
    https://www.cve.org/CVERecord?id=CVE-2025-58438
[1] https://github.com/jjjake/internetarchive/security/advisories/GHSA-wx3r-v6h7-frjp
[2] https://github.com/jjjake/internetarchive/commit/cba2d459e10a9489fb35caeba0b03e80f5f5d7c2

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

[toc] | [next] | [standalone]


#1260525

FromAntoine Beaupré <anarcat@debian.org>
Date2025-09-08 16:10 +0200
Message-ID<LsKJb-dMYQ-1@gated-at.bofh.it>
In reply to#1260426
On 2025-09-07 20:29:19, Salvatore Bonaccorso wrote:
> Source: python-internetarchive
> Version: 5.4.0-1
> Severity: important
> Tags: security upstream
> X-Debbugs-Cc: carnil@debian.org, Debian Security Team <team@security.debian.org>
>
> Hi,
>
> The following vulnerability was published for python-internetarchive.
>
> CVE-2025-58438[0]:
> | internetarchive is a Python and Command-Line Interface to
> | Archive.org In versions 5.5.0 and below, there is a directory
> | traversal (path traversal) vulnerability in the File.download()
> | method of the internetarchive library. The file.download() method
> | does not properly sanitize user-supplied filenames or validate the
> | final download path. A maliciously crafted filename could contain
> | path traversal sequences (e.g.,
> | ../../../../windows/system32/file.txt) or illegal characters that,
> | when processed, would cause the file to be written outside of the
> | intended target directory. An attacker could potentially overwrite
> | critical system files or application configuration files, leading to
> | a denial of service, privilege escalation, or remote code execution,
> | depending on the context in which the library is used.  The
> | vulnerability is particularly critical for users on Windows systems,
> | but all operating systems are affected. This issue is fixed in
> | version 5.5.1.
>
>
> If you fix the vulnerability please also make sure to include the
> CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

I have a upload ready for unstable already, changelog looks like this:

python-internetarchive (5.5.1-1) unstable; urgency=high

  * new upstream release (Closes: #1114635, CVE-2025-58438)

 -- Antoine Beaupré <anarcat@debian.org>  Mon, 08 Sep 2025 09:50:19 -0400

does that look sane? can i upload to unstable as is?

i also wonder how to fix this in stable. we're only two versions behind
upstream there (one minor, one major, and the security fix), so the diff
is pretty darn small. The security patch for 5.5.1 is:

 7 files changed, 302 insertions(+), 5 deletions(-)

and the diff from 5.4.0 (stable) to 5.5.1 is:

 21 files changed, 560 insertions(+), 88 deletions(-)

Is it really worth just doing that backport? We'd be avoiding:

> # 5.4.0
> 
> Features and Improvements
> 
>     Stop setting scanner on upload per policy change.
> 
> Bugfixes
> 
>     Fixed bug where REMOVE_TAG was not working with indexed keys.
>     Fixed argument validation and option parsing in ia download.
> 
> # 5.5.0
> 
> Features and Improvements
> 
>     Added --parameters option to ia metadata.

... feels like mostly small features and bugfixes to me...

Thanks for the feedback,

a.

-- 
Le féminisme n'a jamais tué personne
Le machisme tue tous les jours.
                        - Benoîte Groulx

[toc] | [prev] | [next] | [standalone]


#1260702

FromAntoine Beaupré <anarcat@debian.org>
Date2025-09-09 20:10 +0200
Message-ID<LtaWZ-e5DH-11@gated-at.bofh.it>
In reply to#1260525
On 2025-09-08 10:00:13, Antoine Beaupré wrote:
> On 2025-09-07 20:29:19, Salvatore Bonaccorso wrote:
>> Source: python-internetarchive
>> Version: 5.4.0-1
>> Severity: important
>> Tags: security upstream
>> X-Debbugs-Cc: carnil@debian.org, Debian Security Team <team@security.debian.org>
>>
>> Hi,
>>
>> The following vulnerability was published for python-internetarchive.
>>
>> CVE-2025-58438[0]:
>> | internetarchive is a Python and Command-Line Interface to
>> | Archive.org In versions 5.5.0 and below, there is a directory
>> | traversal (path traversal) vulnerability in the File.download()
>> | method of the internetarchive library. The file.download() method
>> | does not properly sanitize user-supplied filenames or validate the
>> | final download path. A maliciously crafted filename could contain
>> | path traversal sequences (e.g.,
>> | ../../../../windows/system32/file.txt) or illegal characters that,
>> | when processed, would cause the file to be written outside of the
>> | intended target directory. An attacker could potentially overwrite
>> | critical system files or application configuration files, leading to
>> | a denial of service, privilege escalation, or remote code execution,
>> | depending on the context in which the library is used.  The
>> | vulnerability is particularly critical for users on Windows systems,
>> | but all operating systems are affected. This issue is fixed in
>> | version 5.5.1.
>>
>>
>> If you fix the vulnerability please also make sure to include the
>> CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
>
> I have a upload ready for unstable already, changelog looks like this:
>
> python-internetarchive (5.5.1-1) unstable; urgency=high
>
>   * new upstream release (Closes: #1114635, CVE-2025-58438)
>
>  -- Antoine Beaupré <anarcat@debian.org>  Mon, 08 Sep 2025 09:50:19 -0400
>
> does that look sane? can i upload to unstable as is?

So i've uploaded that to unstable already...


[...]

> Is it really worth just doing that backport? We'd be avoiding:

[...]

> ... feels like mostly small features and bugfixes to me...

Not having had any feedback on this, i've prepared a debdiff for a
simpler backport of the patch (as opposed to the whole upstream), see
the attachment.

I am waiting on input from the security team before performing this
upload, as directed by:

https://www.debian.org/doc/manuals/developers-reference/pkgs.html#security-uploads

i have not checked whether bookworm also needs a kick, i assume it
does, but the version there is far older and the backport will be much
more challenging.

i would recommend dropping security support for that version.

a.

-- 
Premature optimization is the root of all evil
                        - Donald Knuth

[toc] | [prev] | [next] | [standalone]


#1261021

FromSalvatore Bonaccorso <carnil@debian.org>
Date2025-09-11 22:10 +0200
Message-ID<LtVMd-eAWy-7@gated-at.bofh.it>
In reply to#1260702
Hi Antoine,

[Adding CC to team@security.debian.org]

Apologies for the delay, we had other issues which needed more
attention first.

On Tue, Sep 09, 2025 at 01:58:33PM -0400, Antoine Beaupré wrote:
> On 2025-09-08 10:00:13, Antoine Beaupré wrote:
> > On 2025-09-07 20:29:19, Salvatore Bonaccorso wrote:
> >> Source: python-internetarchive
> >> Version: 5.4.0-1
> >> Severity: important
> >> Tags: security upstream
> >> X-Debbugs-Cc: carnil@debian.org, Debian Security Team <team@security.debian.org>
> >>
> >> Hi,
> >>
> >> The following vulnerability was published for python-internetarchive.
> >>
> >> CVE-2025-58438[0]:
> >> | internetarchive is a Python and Command-Line Interface to
> >> | Archive.org In versions 5.5.0 and below, there is a directory
> >> | traversal (path traversal) vulnerability in the File.download()
> >> | method of the internetarchive library. The file.download() method
> >> | does not properly sanitize user-supplied filenames or validate the
> >> | final download path. A maliciously crafted filename could contain
> >> | path traversal sequences (e.g.,
> >> | ../../../../windows/system32/file.txt) or illegal characters that,
> >> | when processed, would cause the file to be written outside of the
> >> | intended target directory. An attacker could potentially overwrite
> >> | critical system files or application configuration files, leading to
> >> | a denial of service, privilege escalation, or remote code execution,
> >> | depending on the context in which the library is used.  The
> >> | vulnerability is particularly critical for users on Windows systems,
> >> | but all operating systems are affected. This issue is fixed in
> >> | version 5.5.1.
> >>
> >>
> >> If you fix the vulnerability please also make sure to include the
> >> CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
> >
> > I have a upload ready for unstable already, changelog looks like this:
> >
> > python-internetarchive (5.5.1-1) unstable; urgency=high
> >
> >   * new upstream release (Closes: #1114635, CVE-2025-58438)
> >
> >  -- Antoine Beaupré <anarcat@debian.org>  Mon, 08 Sep 2025 09:50:19 -0400
> >
> > does that look sane? can i upload to unstable as is?
> 
> So i've uploaded that to unstable already...
> 
> 
> [...]
> 
> > Is it really worth just doing that backport? We'd be avoiding:
> 
> [...]
> 
> > ... feels like mostly small features and bugfixes to me...
> 
> Not having had any feedback on this, i've prepared a debdiff for a
> simpler backport of the patch (as opposed to the whole upstream), see
> the attachment.
> 
> I am waiting on input from the security team before performing this
> upload, as directed by:
> 
> https://www.debian.org/doc/manuals/developers-reference/pkgs.html#security-uploads
> 
> i have not checked whether bookworm also needs a kick, i assume it
> does, but the version there is far older and the backport will be much
> more challenging.
> 
> i would recommend dropping security support for that version.

We had brief discussions about python-internetarchive in the team and
think the issue might warrant a DSA.

Could you prepare debdiffs for both trixie-security and
bookworm-security (at least we should attempt, bookworm is still
security-supported for another year by regular security support
before moving to LTS)?

https://www.debian.org/doc/manuals/developers-reference/pkgs.html#bug-security
contains some additional hints (linked from your reference).

I have added python-internetarchive to our dsa-needed list, so once we
have debdiffs for review and ack, we can proceed.

Regards,
Salvatore

[toc] | [prev] | [next] | [standalone]


#1262136

FromMoritz Mühlenhoff <jmm@inutil.org>
Date2025-09-18 22:10 +0200
Message-ID<Lwt73-gnrs-7@gated-at.bofh.it>
In reply to#1260426
On Mon, Sep 15, 2025 at 03:14:30PM -0400, Antoine Beaupré wrote:
> On 2025-09-11 22:04:03, Salvatore Bonaccorso wrote:
> > Hi Antoine,
> >
> > [Adding CC to team@security.debian.org]
> >
> > Apologies for the delay, we had other issues which needed more
> > attention first.
> 
> np.

Thanks, I'll review the patches tomorrow.

Cheers,
        Moritz

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.bugs.dist


csiph-web