From 037af6890fe6fdb84a08d3c86083e847c90ec0ad Mon Sep 17 00:00:00 2001
From: Aleksander Machniak <alec@alec.pl>
Date: Tue, 22 Oct 2013 08:17:26 -0400
Subject: [PATCH] Fix vulnerability in handling _session argument of utils/save-prefs (#1489382)

---
 program/steps/mail/attachments.inc |   24 +++++++++++++-----------
 1 files changed, 13 insertions(+), 11 deletions(-)

diff --git a/program/steps/mail/attachments.inc b/program/steps/mail/attachments.inc
index 21a9f5b..f83f689 100644
--- a/program/steps/mail/attachments.inc
+++ b/program/steps/mail/attachments.inc
@@ -27,8 +27,10 @@
 $COMPOSE_ID = get_input_value('_id', RCUBE_INPUT_GPC);
 $COMPOSE    = null;
 
-if ($COMPOSE_ID && $_SESSION['compose_data_'.$COMPOSE_ID])
-  $COMPOSE =& $_SESSION['compose_data_'.$COMPOSE_ID];
+if ($COMPOSE_ID && $_SESSION['compose_data_' . $COMPOSE_ID]) {
+  $SESSION_KEY = 'compose_data_' . $COMPOSE_ID;
+  $COMPOSE =& $_SESSION[$SESSION_KEY];
+}
 
 if (!$COMPOSE) {
   die("Invalid session var!");
@@ -45,7 +47,7 @@
     $attachment = $RCMAIL->plugins->exec_hook('attachment_delete', $attachment);
   if ($attachment['status']) {
     if (is_array($COMPOSE['attachments'][$id])) {
-      unset($COMPOSE['attachments'][$id]);
+      $RCMAIL->session->remove($SESSION_KEY.'.attachments.'.$id);
       $OUTPUT->command('remove_from_attachment_list', "rcmfile$id");
     }
   }
@@ -77,11 +79,7 @@
   exit;
 }
 
-// attachment upload action
-
-if (!is_array($COMPOSE['attachments'])) {
-  $COMPOSE['attachments'] = array();
-}
+/*****  attachment upload action  *****/
 
 // clear all stored output properties (like scripts and env vars)
 $OUTPUT->reset();
@@ -89,6 +87,8 @@
 $uploadid = get_input_value('_uploadid', RCUBE_INPUT_GET);
 
 if (is_array($_FILES['_attachments']['tmp_name'])) {
+  $multiple = count($_FILES['_attachments']['tmp_name']) > 1;
+
   foreach ($_FILES['_attachments']['tmp_name'] as $i => $filepath) {
     // Process uploaded attachment if there is no error
     $err = $_FILES['_attachments']['error'][$i];
@@ -110,7 +110,7 @@
 
       // store new attachment in session
       unset($attachment['status'], $attachment['abort']);
-      $COMPOSE['attachments'][$id] = $attachment;
+      $RCMAIL->session->append($SESSION_KEY.'.attachments', $id, $attachment);
 
       if (($icon = $COMPOSE['deleteicon']) && is_file($icon)) {
         $button = html::img(array(
@@ -149,8 +149,10 @@
         $msg = rcube_label('fileuploaderror');
       }
 
-      $OUTPUT->command('display_message', $msg, 'error');
-      $OUTPUT->command('remove_from_attachment_list', $uploadid);
+      if ($attachment['error'] || $err != UPLOAD_ERR_NO_FILE) {
+        $OUTPUT->command('display_message', $msg, 'error');
+        $OUTPUT->command('remove_from_attachment_list', $uploadid);
+      }
     }
   }
 }

--
Gitblit v1.9.1