aboutsummaryrefslogtreecommitdiff
diff options
context:
space:
mode:
-rwxr-xr-xtranscode.sh15
1 files changed, 15 insertions, 0 deletions
diff --git a/transcode.sh b/transcode.sh
index 7a0a9cb..15dba25 100755
--- a/transcode.sh
+++ b/transcode.sh
@@ -381,6 +381,21 @@ load_preset() {
debug "Sourcing preset file:" "$file"
+ # Reject preset files that are world-writable to prevent arbitrary users
+ # from injecting shell code.
+ #
+ # Symlinks must be resolved first: stat on a symlink returns the permissions
+ # of the symlink itself (always 777 on Linux), not the target. We use
+ # readlink -f (GNU) with a fallback to realpath for macOS/BSD.
+ local resolved_file
+ resolved_file=$(readlink -f -- "$file" 2>/dev/null || realpath -- "$file")
+ local preset_perms
+ preset_perms=$(stat -c '%a' -- "$resolved_file" 2>/dev/null || stat -f '%OLp' -- "$resolved_file")
+ if [[ "${preset_perms: -1}" =~ [2367] ]]; then
+ error "Preset file is world-writable, refusing to source:" "$resolved_file"
+ exit $EXIT_CONFIG_ERROR
+ fi
+
unset -v ffargs
ffargs=()