diff --git a/.gitignore b/.gitignore index 5710765..1b740aa 100644 --- a/.gitignore +++ b/.gitignore @@ -11,3 +11,5 @@ pure-ftpd-1.0.29.tar.bz2 /pure-ftpd-1.0.47.tar.bz2 /pure-ftpd-1.0.48.tar.bz2 /pure-ftpd-1.0.49.tar.bz2 +/pure-ftpd-1.0.51.tar.bz2 +/pure-ftpd-1.0.52.tar.bz2 diff --git a/0001-diraliases-always-set-the-tail-of-the-list-to-NULL.patch b/0001-diraliases-always-set-the-tail-of-the-list-to-NULL.patch deleted file mode 100644 index d5b2523..0000000 --- a/0001-diraliases-always-set-the-tail-of-the-list-to-NULL.patch +++ /dev/null @@ -1,34 +0,0 @@ -From 8d0d42542e2cb7a56d645fbe4d0ef436e38bcefa Mon Sep 17 00:00:00 2001 -From: Frank Denis -Date: Tue, 18 Feb 2020 18:36:58 +0100 -Subject: [PATCH] diraliases: always set the tail of the list to NULL - -Spotted and reported by Antonio Norales from GitHub Security Labs. -Thanks! ---- - src/diraliases.c | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/src/diraliases.c b/src/diraliases.c -index 4002a36..fb70273 100644 ---- a/src/diraliases.c -+++ b/src/diraliases.c -@@ -93,7 +93,6 @@ int init_aliases(void) - (tail->dir = strdup(dir)) == NULL) { - die_mem(); - } -- tail->next = NULL; - } else { - DirAlias *curr; - -@@ -105,6 +104,7 @@ int init_aliases(void) - tail->next = curr; - tail = curr; - } -+ tail->next = NULL; - } - fclose(fp); - aliases_up++; --- -2.25.4 - diff --git a/0001-listdir-reuse-a-single-buffer-to-store-every-file-na.patch b/0001-listdir-reuse-a-single-buffer-to-store-every-file-na.patch deleted file mode 100644 index efed2f3..0000000 --- a/0001-listdir-reuse-a-single-buffer-to-store-every-file-na.patch +++ /dev/null @@ -1,70 +0,0 @@ -From aea56f4bcb9948d456f3fae4d044fd3fa2e19706 Mon Sep 17 00:00:00 2001 -From: Frank Denis -Date: Mon, 30 Dec 2019 17:40:04 +0100 -Subject: [PATCH] listdir(): reuse a single buffer to store every file name to - display - -Allocating a new buffer for each entry is useless. - -And as these buffers are allocated on the stack, on systems with a -small stack size, with many entries, the limit can easily be reached, -causing a stack exhaustion and aborting the user session. - -Reported by Antonio Morales from the GitHub Security Lab team, thanks! ---- - src/ls.c | 15 ++++++++------- - 1 file changed, 8 insertions(+), 7 deletions(-) - -diff --git a/src/ls.c b/src/ls.c -index cf804c7..f8a588f 100644 ---- a/src/ls.c -+++ b/src/ls.c -@@ -661,6 +661,8 @@ static void listdir(unsigned int depth, int f, void * const tls_fd, - char *names; - PureFileInfo *s; - PureFileInfo *r; -+ char *alloca_subdir; -+ size_t sizeof_subdir; - int d; - - if (depth >= max_ls_depth || matches >= max_ls_files) { -@@ -690,14 +692,12 @@ static void listdir(unsigned int depth, int f, void * const tls_fd, - } - outputfiles(f, tls_fd); - r = dir; -+ sizeof_subdir = PATH_MAX + 1U; -+ if ((alloca_subdir = ALLOCA(sizeof_subdir)) == NULL) { -+ goto toomany; -+ } - while (opt_R && r != s) { - if (r->name_offset != (size_t) -1 && !chdir(FI_NAME(r))) { -- char *alloca_subdir; -- const size_t sizeof_subdir = PATH_MAX + 1U; -- -- if ((alloca_subdir = ALLOCA(sizeof_subdir)) == NULL) { -- goto toomany; -- } - if (SNCHECK(snprintf(alloca_subdir, sizeof_subdir, "%s/%s", - name, FI_NAME(r)), sizeof_subdir)) { - goto nolist; -@@ -706,8 +706,8 @@ static void listdir(unsigned int depth, int f, void * const tls_fd, - wrstr(f, tls_fd, alloca_subdir); - wrstr(f, tls_fd, ":\r\n\r\n"); - listdir(depth + 1U, f, tls_fd, alloca_subdir); -+ - nolist: -- ALLOCA_FREE(alloca_subdir); - if (matches >= max_ls_files) { - goto toomany; - } -@@ -720,6 +720,7 @@ static void listdir(unsigned int depth, int f, void * const tls_fd, - r++; - } - toomany: -+ ALLOCA_FREE(alloca_subdir); - free(names); - free(dir); - names = NULL; --- -2.20.1 - diff --git a/0001-pure_strcmp-len-s2-can-be-len-s1.patch b/0001-pure_strcmp-len-s2-can-be-len-s1.patch deleted file mode 100644 index 375b970..0000000 --- a/0001-pure_strcmp-len-s2-can-be-len-s1.patch +++ /dev/null @@ -1,28 +0,0 @@ -From bf6fcd4935e95128cf22af5924cdc8fe5c0579da Mon Sep 17 00:00:00 2001 -From: Frank Denis -Date: Mon, 24 Feb 2020 15:19:43 +0100 -Subject: [PATCH] pure_strcmp(): len(s2) can be > len(s1) - -Reported by Antonio Morales from GitHub Security Labs, thanks! ---- - src/utils.c | 6 +++++- - 1 file changed, 5 insertions(+), 1 deletion(-) - -diff --git a/src/utils.c b/src/utils.c -index f41492d..5e88104 100644 ---- a/src/utils.c -+++ b/src/utils.c -@@ -45,5 +45,9 @@ int pure_memcmp(const void * const b1_, const void * const b2_, size_t len) - - int pure_strcmp(const char * const s1, const char * const s2) - { -- return pure_memcmp(s1, s2, strlen(s1) + 1U); -+ const size_t s1_len = strlen(s1); -+ const size_t s2_len = strlen(s2); -+ const size_t len = (s1_len < s2_len) ? s1_len : s2_len; -+ -+ return pure_memcmp(s1, s2, len + 1); - } --- -2.25.4 - diff --git a/pure-ftpd.pure-ftpwho.consoleapp b/pure-ftpd.pure-ftpwho.consoleapp deleted file mode 100644 index 8452f88..0000000 --- a/pure-ftpd.pure-ftpwho.consoleapp +++ /dev/null @@ -1,3 +0,0 @@ -USER=root -PROGRAM=/usr/sbin/pure-ftpwho -GUI=no diff --git a/pure-ftpd.pure-ftpwho.pam b/pure-ftpd.pure-ftpwho.pam deleted file mode 100644 index 268cc92..0000000 --- a/pure-ftpd.pure-ftpwho.pam +++ /dev/null @@ -1,4 +0,0 @@ -#%PAM-1.0 -auth sufficient pam_rootok.so -auth required pam_localuser.so -account required pam_permit.so diff --git a/pure-ftpd.spec b/pure-ftpd.spec index 875ec60..9159c7b 100644 --- a/pure-ftpd.spec +++ b/pure-ftpd.spec @@ -1,30 +1,25 @@ Name: pure-ftpd -Version: 1.0.49 -Release: 4%{?dist} +Version: 1.0.52 +Release: 2%{?dist} Summary: Lightweight, fast and secure FTP server -License: BSD +# Automatically converted from old format: BSD - review is highly recommended. +License: LicenseRef-Callaway-BSD URL: http://www.pureftpd.org Source0: http://download.pureftpd.org/pub/pure-ftpd/releases/pure-ftpd-%{version}.tar.bz2 Source1: pure-ftpd.service Source2: pure-ftpd.logrotate -Source4: pure-ftpd.pure-ftpwho.pam -Source5: pure-ftpd.pure-ftpwho.consoleapp Source6: pure-ftpd.README.SELinux Source7: pure-ftpd.pureftpd.te Source8: pure-ftpd-with-tls-init.service Source9: pure-ftpd-with-tls.service Patch0: 0001-modify-pam.patch Patch1: 0002-fedora-specific-config-file.patch -# Upstream patch: -Patch2: 0001-listdir-reuse-a-single-buffer-to-store-every-file-na.patch -# Upstream patch: -Patch3: 0001-diraliases-always-set-the-tail-of-the-list-to-NULL.patch -# Upstream patch: -Patch4: 0001-pure_strcmp-len-s2-can-be-len-s1.patch Provides: ftpserver +BuildRequires: make BuildRequires: pam-devel, libcap-devel +BuildRequires: libxcrypt-devel %{!?_without_ldap:BuildRequires: openldap-devel} %{!?_without_mysql:BuildRequires: mariadb-connector-c-devel} %{!?_without_pgsql:BuildRequires: libpq-devel} @@ -36,7 +31,7 @@ BuildRequires: gcc Requires(post): systemd Requires(preun): systemd Requires(postun): systemd -Requires: logrotate, usermode +Requires: logrotate %{!?_without_tls:Requires: sscg} @@ -152,12 +147,6 @@ install -p -m 644 pam/pure-ftpd $RPM_BUILD_ROOT%{_sysconfdir}/pam.d/ install -d -m 755 $RPM_BUILD_ROOT%{_sysconfdir}/logrotate.d install -p -m 644 %{SOURCE2} $RPM_BUILD_ROOT%{_sysconfdir}/logrotate.d/%{name} -# pure-ftpwho and non-root users -install -d -m 755 $RPM_BUILD_ROOT%{_sysconfdir}/security/console.apps -install -p -m 644 %{SOURCE4} $RPM_BUILD_ROOT%{_sysconfdir}/pam.d/pure-ftpwho -install -p -m 644 %{SOURCE5} $RPM_BUILD_ROOT%{_sysconfdir}/security/console.apps/pure-ftpwho -ln -s consolehelper $RPM_BUILD_ROOT%{_bindir}/pure-ftpwho - # SELinux support pushd selinux echo "%{_sbindir}/pure-ftpd system_u:object_r:ftpd_exec_t:s0" > pureftpd.fc @@ -220,8 +209,6 @@ fi %config(noreplace) %{_sysconfdir}/%{name} %config(noreplace) %{_sysconfdir}/pam.d/%{name} %config(noreplace) %{_sysconfdir}/logrotate.d/%{name} -%config(noreplace) %{_sysconfdir}/pam.d/pure-ftpwho -%config(noreplace) %{_sysconfdir}/security/console.apps/pure-ftpwho %{!?_without_tls:%{_sysconfdir}/pki/%{name}} %{_mandir}/man8/* %dir /var/ftp/ @@ -233,14 +220,76 @@ fi %changelog -* Wed May 06 2020 Ondřej Lysoněk - 1.0.49-4 +* Fri Jul 25 2025 Fedora Release Engineering - 1.0.52-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild + +* Tue May 20 2025 Jonathan Wright - 1.0.52-1 +- update to 1.0.52 rhbz#2313435 +- Fixes CVE-2024-48208 rhbz#2343476 + +* Sat Feb 01 2025 Björn Esser - 1.0.51-9 +- Add explicit BR: libxcrypt-devel + +* Sat Jan 18 2025 Fedora Release Engineering - 1.0.51-8 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild + +* Wed Sep 04 2024 Miroslav Suchý - 1.0.51-7 +- convert license to SPDX + +* Fri Jul 19 2024 Fedora Release Engineering - 1.0.51-6 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild + +* Fri Jan 26 2024 Fedora Release Engineering - 1.0.51-5 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild + +* Sun Jan 21 2024 Fedora Release Engineering - 1.0.51-4 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild + +* Fri Jul 21 2023 Fedora Release Engineering - 1.0.51-3 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild + +* Fri Jan 20 2023 Fedora Release Engineering - 1.0.51-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild + +* Thu Jul 21 2022 Jonathan Wright - 1.0.51-1 +- New version +- Resolves: rhbz#2026153 +- Remove usermode dependency and non-root "ftpwho" +- Resolves: rhbz#502754 + +* Fri Jan 21 2022 Fedora Release Engineering - 1.0.49-12 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild + +* Tue Sep 14 2021 Sahana Prasad - 1.0.49-11 +- Rebuilt with OpenSSL 3.0.0 + +* Fri Jul 23 2021 Fedora Release Engineering - 1.0.49-10 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild + +* Tue Mar 02 2021 Zbigniew Jędrzejewski-Szmek - 1.0.49-9 +- Rebuilt for updated systemd-rpm-macros + See https://pagure.io/fesco/issue/2583. + +* Mon Feb 08 2021 Pavel Raiskup - 1.0.49-8 +- rebuild for libpq ABI fix rhbz#1908268 + +* Wed Jan 27 2021 Fedora Release Engineering - 1.0.49-7 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild + +* Tue Jul 28 2020 Fedora Release Engineering - 1.0.49-6 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild + +* Wed May 06 2020 Ondřej Lysoněk - 1.0.49-5 - Fix CVE-2020-9365 and CVE-2020-9274 -- Resolves: rhbz#1828689 -- Resolves: rhbz#1831060 +- Resolves: rhbz#1828688 +- Resolves: rhbz#1831059 + +* Thu Jan 30 2020 Fedora Release Engineering - 1.0.49-4 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild * Mon Jan 27 2020 Ondřej Lysoněk - 1.0.49-3 - Fix potential stack exhaustion in function listdir (CVE-2019-20176) -- Resolves: rhbz#1795153 +- Resolves: rhbz#1795152 * Fri Jul 26 2019 Fedora Release Engineering - 1.0.49-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild diff --git a/sources b/sources index 0709f30..920b4eb 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (pure-ftpd-1.0.49.tar.bz2) = b44896d6fe2cda9169b1db93c5260bb892af14a173f2d25e60dd6530afe85d8e9156985609e35da7e5550dc123afb42bc5012beb9fca9011054cf0ed8b2eddef +SHA512 (pure-ftpd-1.0.52.tar.bz2) = c7b6f76c1429d2cbf9d740c3408464564e023716ebf8361231ba5021f81804575049910c9874970c83c98f927cd496899e5c30625e4dee6538497f9179632c23