mirror of
https://github.com/CalcProgrammer1/OpenRGB.git
synced 2026-09-16 23:28:04 -04:00
Address security issues in release_candidate_1.0rc3
- CVE-2026-59682: OpenRGB: arbitrary file overwrite and deletion local and remote - CVE-2026-59683: OpenRGB: local and remote system compromise via arbitrary file write using attacker controlled strings - CVE-2026-18794: OpenRGB: insufficient input data checks lead to Denial-of-Service, memory overread and overwrite
This commit is contained in:
1 parent
6fbcf62d76
commit
d2dd9dcc73
7 files changed
+61
-7
No files matched your search
+3
-3
@@ -66,7 +66,7 @@ bool ProfileManager::SaveProfile(std::string profile_name, bool sizes)
|
||||
/*---------------------------------------------------------*\
|
||||
| Open an output file in binary mode |
|
||||
\*---------------------------------------------------------*/
|
||||
filesystem::path profile_path = configuration_directory / filesystem::u8path(filename);
|
||||
filesystem::path profile_path = configuration_directory / filesystem::u8path(StringUtils::make_filename(filename));
|
||||
std::ofstream controller_file(profile_path, std::ios::out | std::ios::binary | std::ios::trunc);
|
||||
|
||||
/*---------------------------------------------------------*\
|
||||
@@ -149,7 +149,7 @@ std::vector<RGBController*> ProfileManager::LoadProfileToList
|
||||
unsigned int controller_size;
|
||||
unsigned int controller_offset = 0;
|
||||
|
||||
filesystem::path filename = configuration_directory / filesystem::u8path(profile_name);
|
||||
filesystem::path filename = configuration_directory / filesystem::u8path(StringUtils::make_filename(profile_name));
|
||||
|
||||
/*---------------------------------------------------------*\
|
||||
| Determine file extension |
|
||||
@@ -437,7 +437,7 @@ void ProfileManager::DeleteProfile(std::string profile_name)
|
||||
{
|
||||
profile_name = StringUtils::remove_null_terminating_chars(profile_name);
|
||||
|
||||
filesystem::path filename = configuration_directory / profile_name;
|
||||
filesystem::path filename = configuration_directory / StringUtils::make_filename(profile_name);
|
||||
filename.concat(".orp");
|
||||
|
||||
filesystem::remove(filename);
|
||||
|
||||
Reference in new issue
Block a user