<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.kde.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.6"
          urlbase="https://bugs.kde.org/"
          
          maintainer="sysadmin@kde.org"
>

    <bug>
          <bug_id>392554</bug_id>
          
          <creation_ts>2018-03-31 09:12:20 +0000</creation_ts>
          <short_desc>security: escaping from bracketed paste seems to be possible</short_desc>
          <delta_ts>2022-01-11 00:09:07 +0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>2</classification_id>
          <classification>Applications</classification>
          <product>konsole</product>
          <component>copy-paste</component>
          <version>17.12.2</version>
          <rep_platform>Other</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>CONFIRMED</bug_status>
          <resolution></resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>NOR</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Tomas Pospisek">tpo_deb</reporter>
          <assigned_to name="Konsole Bugs">konsole-bugs-null</assigned_to>
          <cc>dean</cc>
    
    <cc>gabrielfernnd</cc>
    
    <cc>j</cc>
    
    <cc>jbb</cc>
    
    <cc>martin.sandsmark</cc>
    
    <cc>ninjalj</cc>
    
    <cc>simonandric5</cc>
          
          <cf_commitlink></cf_commitlink>
          <cf_versionfixedin></cf_versionfixedin>
          <cf_sentryurl></cf_sentryurl>
          <votes>0</votes>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>1742173</commentid>
    <comment_count>0</comment_count>
    <who name="Tomas Pospisek">tpo_deb</who>
    <bug_when>2018-03-31 09:12:20 +0000</bug_when>
    <thetext>According to a recent LWN article, escaping &apos;bracketed paste&apos; seems to be possible in konsole: https://lwn.net/Articles/749992/.

Another way to escape &apos;bracketed paste&apos; seems to be ^O which makes bach execute the current line:  https://lwn.net/Articles/750630/</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1742340</commentid>
    <comment_count>1</comment_count>
    <who name="Egmont Koblinger">egmont</who>
    <bug_when>2018-03-31 20:34:11 +0000</bug_when>
    <thetext>I can&apos;t access the first article, but I guess it points out that the paste buffer might contain the terminating sequence of bracketed paste (\e[201~) which then pastes the rest without being bracketed. I can confirm this bug.

I don&apos;t understand the second one: similarly to the one who responded there, I get a literal ^O printed in bash.

FYI: relevant gnome-terminal (vte) issues are:
https://bugzilla.gnome.org/show_bug.cgi?id=753197
https://bugzilla.gnome.org/show_bug.cgi?id=794653</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1742359</commentid>
    <comment_count>2</comment_count>
    <who name="Tomas Pospisek">tpo_deb</who>
    <bug_when>2018-03-31 22:00:26 +0000</bug_when>
    <thetext>&gt; I can&apos;t access the first article

I was assuming wrongly, I am very sorry - here are the relevant parts from the article:

&quot;Unfortunately, Horn&apos;s test page [http://thejh.net/misc/website-terminal-copy-paste] also shows how to bypass this protection, by including the end-of-pasted-text sequence in the pasted text itself, thus ending the bracketed mode prematurely. [...] in my tests, Konsole fails to properly escape the second test, even with .inputrc properly configured [&apos;set enable-bracketed-paste on&apos; in ~/.inputrc]&quot; (Antoine Beaupré)

And:

&quot;In bash, ^O causes code execution. [Such as:]

 &lt;html&gt;$ echo Hello &lt;span style=&quot;position: absolute; left: -100px; top: -100px&quot;&gt;| cowsay pwned&amp;#15;&lt;/span&gt; world&lt;/html&gt;

Do you have bracket paste enabled in inputrc? My exploit doesn&apos;t defeat it, although it could. It&apos;s a matter of adding &amp;#27;[201~ before &amp;#15;.&quot; (Jakub Wilk)</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1742361</commentid>
    <comment_count>3</comment_count>
    <who name="Egmont Koblinger">egmont</who>
    <bug_when>2018-03-31 22:04:34 +0000</bug_when>
    <thetext>&gt; [...] It&apos;s a matter of adding &amp;#27;[201~ before &amp;#15;.

Well, if you can escape from bracketed paste mode then of course later on you can do all sorts of nasty things. I don&apos;t even see the need for the ^O trick, the same can be achieved using a regular newline.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1743348</commentid>
    <comment_count>4</comment_count>
    <who name="Dean Serenevy">dean</who>
    <bug_when>2018-04-05 14:55:12 +0000</bug_when>
    <thetext>FYI, here is a link to the article for non-subscribers (Note: meets their acceptable use policy for links bypassing the paywall):  https://lwn.net/SubscriberLink/749992/d3a6b4d1e90c2f39/</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1743711</commentid>
    <comment_count>5</comment_count>
    <who name="Kurt Hindenburg">khindenburg</who>
    <bug_when>2018-04-07 15:44:50 +0000</bug_when>
    <thetext>https://commits.kde.org/konsole/0b482990279d6684089a404df7473f0354c284c3

remove all ESC from bracketed paste</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1749434</commentid>
    <comment_count>6</comment_count>
    <who name="Christoph Feck">cfeck</who>
    <bug_when>2018-05-02 01:54:21 +0000</bug_when>
    <thetext>Kurt, does the commit from comment #5 fix this issue?</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>2023839</commentid>
    <comment_count>7</comment_count>
    <who name="Gabriel Fernandes">gabrielfernnd</who>
    <bug_when>2021-04-09 14:40:12 +0000</bug_when>
    <thetext>I found that if you clear konsole with (ctrl + shift + k) bracketed-paste doesn&apos;t work anymore in the now-cleared terminal. Unless you reset the terminal.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>2045414</commentid>
    <comment_count>8</comment_count>
    <who name="Martin Sandsmark">martin.sandsmark</who>
    <bug_when>2021-07-06 12:46:02 +0000</bug_when>
    <thetext>CCing Jonah on this as well since he refactored the copy&amp;paste code. But I think it might be a duplicate?</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>2091890</commentid>
    <comment_count>9</comment_count>
    <who name="">ninjalj</who>
    <bug_when>2022-01-11 00:09:07 +0000</bug_when>
    <thetext>(In reply to Gabriel Fernandes from comment #7)
&gt; I found that if you clear konsole with (ctrl + shift + k) bracketed-paste
&gt; doesn&apos;t work anymore in the now-cleared terminal. Unless you reset the
&gt; terminal.

ctrl + shift + k (clear scrollback and reset) does a hard reset (RIS - Reset to Initial State), which, among many other things, resets the bracketed-paste mode. xterm does the same if you select &quot;Reset and Clear Saved Lines&quot; from its ctrl+middle click menu.

Both bash and zsh apparently re-enable bracketed-paste as soon as they can print a prompt.</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>