mirror of
https://git.in.rschanz.org/ryan77627/guix.git
synced 2024-12-25 05:48:07 -05:00
gnu: p7zip: Fix CVE-2016-9256.
* gnu/packages/compression.scm (p7zip)[source]: Add patch. * gnu/packages/patches/p7zip-CVE-2016-9296.patch: New file. * gnu/local.mk (dist_patch_DATA): Register it.
This commit is contained in:
parent
b352b57655
commit
1ac675a583
3 changed files with 27 additions and 1 deletions
|
@ -797,6 +797,7 @@ dist_patch_DATA = \
|
||||||
%D%/packages/patches/openssl-c-rehash-in.patch \
|
%D%/packages/patches/openssl-c-rehash-in.patch \
|
||||||
%D%/packages/patches/orpheus-cast-errors-and-includes.patch \
|
%D%/packages/patches/orpheus-cast-errors-and-includes.patch \
|
||||||
%D%/packages/patches/ots-no-include-missing-file.patch \
|
%D%/packages/patches/ots-no-include-missing-file.patch \
|
||||||
|
%D%/packages/patches/p7zip-CVE-2016-9296.patch \
|
||||||
%D%/packages/patches/p7zip-remove-unused-code.patch \
|
%D%/packages/patches/p7zip-remove-unused-code.patch \
|
||||||
%D%/packages/patches/patchelf-page-size.patch \
|
%D%/packages/patches/patchelf-page-size.patch \
|
||||||
%D%/packages/patches/patchelf-rework-for-arm.patch \
|
%D%/packages/patches/patchelf-rework-for-arm.patch \
|
||||||
|
|
|
@ -924,7 +924,8 @@ (define-public p7zip
|
||||||
(delete-file-recursively "CPP/7zip/Archive/Rar")
|
(delete-file-recursively "CPP/7zip/Archive/Rar")
|
||||||
(delete-file-recursively "CPP/7zip/Compress/Rar")
|
(delete-file-recursively "CPP/7zip/Compress/Rar")
|
||||||
#t))
|
#t))
|
||||||
(patches (search-patches "p7zip-remove-unused-code.patch"))))
|
(patches (search-patches "p7zip-CVE-2016-9296.patch"
|
||||||
|
"p7zip-remove-unused-code.patch"))))
|
||||||
(build-system gnu-build-system)
|
(build-system gnu-build-system)
|
||||||
(arguments
|
(arguments
|
||||||
`(#:make-flags
|
`(#:make-flags
|
||||||
|
|
24
gnu/packages/patches/p7zip-CVE-2016-9296.patch
Normal file
24
gnu/packages/patches/p7zip-CVE-2016-9296.patch
Normal file
|
@ -0,0 +1,24 @@
|
||||||
|
From: Robert Luberda <robert@debian.org>
|
||||||
|
Date: Sat, 19 Nov 2016 08:48:08 +0100
|
||||||
|
Subject: Fix nullptr dereference (CVE-2016-9296)
|
||||||
|
|
||||||
|
Patch taken from https://sourceforge.net/p/p7zip/bugs/185/
|
||||||
|
This patch file taken from Debian's patch set for p7zip
|
||||||
|
---
|
||||||
|
CPP/7zip/Archive/7z/7zIn.cpp | 3 ++-
|
||||||
|
1 file changed, 2 insertions(+), 1 deletion(-)
|
||||||
|
|
||||||
|
diff --git a/CPP/7zip/Archive/7z/7zIn.cpp b/CPP/7zip/Archive/7z/7zIn.cpp
|
||||||
|
index b0c6b98..7c6dde2 100644
|
||||||
|
--- a/CPP/7zip/Archive/7z/7zIn.cpp
|
||||||
|
+++ b/CPP/7zip/Archive/7z/7zIn.cpp
|
||||||
|
@@ -1097,7 +1097,8 @@ HRESULT CInArchive::ReadAndDecodePackedStreams(
|
||||||
|
if (CrcCalc(data, unpackSize) != folders.FolderCRCs.Vals[i])
|
||||||
|
ThrowIncorrect();
|
||||||
|
}
|
||||||
|
- HeadersSize += folders.PackPositions[folders.NumPackStreams];
|
||||||
|
+ if (folders.PackPositions)
|
||||||
|
+ HeadersSize += folders.PackPositions[folders.NumPackStreams];
|
||||||
|
return S_OK;
|
||||||
|
}
|
||||||
|
|
Loading…
Reference in a new issue