diff options
| author | Daniil Baturin <daniil@vyos.io> | 2026-09-08 12:33:08 +0100 |
|---|---|---|
| committer | GitHub <noreply@github.com> | 2026-09-08 12:33:08 +0100 |
| commit | e152d756fdd9d43c31e3ce3a79c64370f2df9615 (patch) | |
| tree | 87ff653360f3f0cf437a8d34547a1da8779e82cc /src | |
| parent | b0fb31d32f05691ed568b29a71d7963cb28aa053 (diff) | |
| parent | 0d4fd05058a855eef627a65f2b005a7c557ae022 (diff) | |
| download | vyos-1x-e152d756fdd9d43c31e3ce3a79c64370f2df9615.tar.gz vyos-1x-e152d756fdd9d43c31e3ce3a79c64370f2df9615.zip | |
Merge pull request #5450 from vyos/T8497-vyos-system-update-check-vulnarability
update-checker: T8497: fix command injection via crafted update server response
Diffstat (limited to 'src')
| -rwxr-xr-x | src/op_mode/image_installer.py | 5 | ||||
| -rwxr-xr-x | src/system/vyos-system-update-check.py | 2 |
2 files changed, 2 insertions, 5 deletions
diff --git a/src/op_mode/image_installer.py b/src/op_mode/image_installer.py index fb28f182e..b325df9bd 100755 --- a/src/op_mode/image_installer.py +++ b/src/op_mode/image_installer.py @@ -737,10 +737,7 @@ def image_fetch(image_path: str, vrf: str = None, # Latest version gets url from configured "system update-check url" if image_path == 'latest': - command = external_latest_image_url_script - if vrf: - command = f'ip vrf exec {vrf} {command}' - code, output = rc_cmd(command, env=environ) + code, output = rc_cmd(external_latest_image_url_script, vrf=vrf, env=environ) if code: print(output) exit(MSG_INFO_INSTALL_EXIT) diff --git a/src/system/vyos-system-update-check.py b/src/system/vyos-system-update-check.py index b7d1fc7c5..b1b6e138c 100755 --- a/src/system/vyos-system-update-check.py +++ b/src/system/vyos-system-update-check.py @@ -59,7 +59,7 @@ if __name__ == '__main__': url = jmespath.search('[0].url', remote_data) remote_version = jmespath.search('[0].version', remote_data) if local_version != remote_version and remote_version: - call(f'wall -n "Update available: {remote_version} \nUpdate URL: {url}"') + call(['wall', '-n', f"Update available: {remote_version} \nUpdate URL: {url}"]) # MOTD used in /run/motd.d/10-vyos-update motd_file.parent.mkdir(exist_ok=True) motd_file.write_text(f'---\n' |
