This project used electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. Affected of this project are vulnerable to Arbitrary Code Execution allowing out-of-package code execution when apps are launched as command-line executables.
```diff
diff --git a/lib/internal/modules/run_main.js b/lib/internal/modules/run_main.js
- index 5a50d5d6afab6e6648f72a1c0efa1df4cd80bcd9..0be45309028b00a6957ee473322a9452a7fa7d67 100644
--- a/lib/internal/modules/run_main.js
+ +++ b/lib/internal/modules/run_main.js
@@ -13,6 +13,12 @@ const {
```
CWE-94
`CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:L`
CVE-2023-39956
Co-authored-by: k9ert <k9ert@gmx.de>
|
||
|---|---|---|
| .. | ||
| bitcoind | ||
| electron | ||
| hooks | ||
| tor | ||
| windll | ||
| build-ci.sh | ||
| build-win-ci.bat | ||
| build-win.bat | ||
| hwibridge.py | ||
| hwibridge.spec | ||
| README.md | ||
| requirements.in | ||
| requirements.txt | ||
| specterd.py | ||
| specterd.spec | ||
Build scripts
Run build-<your-os> <version_number> file to build everything.
For example, build-osx.sh 1.2.3 will create SpecterDesktop-1.2.3.dmg and specterd-1.2.3-osx.zip in the release folder.
If you're making a real release, you should append "make hash" at the end of your command calling the build script.
This will update the file hash and version name the Specter Desktop app expects to download from GitHub.
Pyinstaller build
Install requirements:
virtualenv --python=python3 .buildenv
source .buildenv/bin/activate
pip3 install -r requirements.txt --require-hashes
cd pyinstaller
pip3 install -r requirements.txt --require-hashes
Now run:
pyinstaller specterd.spec
And for HWIBridge, run:
pyinstaller hwibridge.spec
Code signing the macOS app for Apple GateKeeper
Note: for this, you'll need to have an active Apple Developer account
If this is the first time you go through this process, you'll need to first set up the following:
Apple Developer Certificate for Code-Signing
- Go to the Apple Developer website: https://developer.apple.com
- Click
Account->Certificates, Identifiers & Profiles - Click the
+icon to create a new certificate. SelectDeveloper ID Applicationand clickContinue - You'll need now to create a certificate signing request, which you can do by following these instructions: https://help.apple.com/developer-account/#/devbfa00fef7, After that you should be able to generate and download the certificate.
- Download the certificate, then double-click the downloaded certificate to install it in your keychain.
App Specific Password for authenticating to iTunesConnect for notarization
- Sign into you Apple ID account: https://appleid.apple.com
- Go to
Security->App Specific Passwordsand clickGenerate Password…, you'll be asked to enter a label and clickCreate, then you'll receive a new password. - Copy the password generated, then open the Terminal and run:
xcrun altool --store-password-in-keychain-item "AC_PASSWORD" -u "<your-apple-id>" -p "<the-generated-password>"
After having these set up, you can use the automated script to sign by passing it 2 extra parameters:
- Your certificate name, which you can see on the Keychain app going to the sidebar ->
My Certificatesand copying the name of the certificate you've created in step 1. - Your Apple ID.
With these two, you can run the command like so:
./build-osx.sh <version_number> "<certificate_name>" "<apple_id>" "make-hash"
Note: "make-hash" is optional and will automatically calculate hash of specterd generated for the macOS app. Should be used only for real release.
This should take 10 minutes, during which you should receive an email from Apple notifying whatever the notarization was successful.
If for some reason the notarization failed, you'll be able to get the reason by copying the Request Identifier (you should be able to find this in the email and in the logs).
Then run the following command:
xcrun altool --verbose --notarization-info <request_identifier> -u "<apple_id>" -p "@keychain:AC_PASSWORD"
This will output a long message, at the end of which you should have be able to find the LogFileURL:.
This URL should contain a JSON with the issues found by Apple and which you'll need to fix to be able to pass Apple's notarization.