Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Implement local security #13

Open
2 tasks
vabold opened this issue Dec 31, 2022 · 2 comments
Open
2 tasks

Implement local security #13

vabold opened this issue Dec 31, 2022 · 2 comments
Labels
engine Code involving engine (C++) feature New code P3 Priority: Low tracking Issues covering multiple items

Comments

@vabold
Copy link
Owner

vabold commented Dec 31, 2022

Due to this application's reliance on external input, whether that be in the form of supplied ghost files or command line arguments, security is an important concern.

This is an ongoing tracking issue - any security concerns should be mentioned in the comments so I can add them here.

@vabold vabold added engine Code involving engine (C++) improvement Improvement to existing code P1 Priority: High tracking Issues covering multiple items and removed improvement Improvement to existing code labels Dec 31, 2022
@vabold vabold added P3 Priority: Low and removed P1 Priority: High labels Jan 19, 2024
@vabold
Copy link
Owner Author

vabold commented Jul 18, 2024

1123988 addresses a vulnerability in EGG::Decomp::DecodeSZS - I'm unclear on whether or not this should close the tracking item.

@malleoz
Copy link
Contributor

malleoz commented Jul 18, 2024

I don't think it should close this. We should do a complete audit of all files that can be passed in including rkg, krkg, szs, and the files archived within the szs itself. I assume there are no other vulnerabilities, but we should wait and do a full audit imo

@vabold vabold added the feature New code label Jul 19, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
engine Code involving engine (C++) feature New code P3 Priority: Low tracking Issues covering multiple items
Projects
None yet
Development

No branches or pull requests

2 participants