From 9e8fb6e2a2a56ae23472322d34812f65d811e610 Mon Sep 17 00:00:00 2001 From: Karolina Surma Date: Mon, 17 May 2021 13:38:13 +0200 Subject: [PATCH] Backport security fix from pip 21.1.1 --- ...git-references-on-unicode-separators.patch | 34 +++++++++++++++++++ python-pip.spec | 12 ++++++- 2 files changed, 45 insertions(+), 1 deletion(-) create mode 100644 don-t-split-git-references-on-unicode-separators.patch diff --git a/don-t-split-git-references-on-unicode-separators.patch b/don-t-split-git-references-on-unicode-separators.patch new file mode 100644 index 0000000..707e1e8 --- /dev/null +++ b/don-t-split-git-references-on-unicode-separators.patch @@ -0,0 +1,34 @@ +From 71ded0935e6c87d6e14439f667990de18bf82cb0 Mon Sep 17 00:00:00 2001 +From: Karolina Surma +Date: Mon, 17 May 2021 13:34:47 +0200 +Subject: [PATCH] Don't split git references on unicode separators + +--- + src/pip/_internal/vcs/git.py | 10 ++++++++-- + 1 file changed, 8 insertions(+), 2 deletions(-) + +diff --git a/src/pip/_internal/vcs/git.py b/src/pip/_internal/vcs/git.py +index a9c7fb6..b38625e 100644 +--- a/src/pip/_internal/vcs/git.py ++++ b/src/pip/_internal/vcs/git.py +@@ -142,9 +142,15 @@ class Git(VersionControl): + pass + + refs = {} +- for line in output.strip().splitlines(): ++ # NOTE: We do not use splitlines here since that would split on other ++ # unicode separators, which can be maliciously used to install a ++ # different revision. ++ for line in output.strip().split("\n"): ++ line = line.rstrip("\r") ++ if not line: ++ continue + try: +- sha, ref = line.split() ++ sha, ref = line.split(" ", maxsplit=2) + except ValueError: + # Include the offending line to simplify troubleshooting if + # this error ever occurs. +-- +2.31.1 + diff --git a/python-pip.spec b/python-pip.spec index e1a1b86..b1888d3 100644 --- a/python-pip.spec +++ b/python-pip.spec @@ -19,7 +19,7 @@ Name: python-%{srcname} # When updating, update the bundled libraries versions bellow! # You can use vendor_meta.sh in the dist git repo Version: %{base_version}%{?prerel:~%{prerel}} -Release: 1%{?dist} +Release: 2%{?dist} Summary: A tool for installing and managing Python packages # We bundle a lot of libraries with pip, which itself is under MIT license. @@ -92,6 +92,13 @@ Patch4: dummy-certifi.patch # this warning is juts moot. Also, the warning breaks CPython test suite. Patch5: nowarn-pip._internal.main.patch +# Don't split git references on unicode separators, +# which could be maliciously used to install a different revision on the +# repository. +# Security patch backported from pip 21.1.1 +# Upstream PR: https://github.com/pypa/pip/pull/9827 +Patch8: don-t-split-git-references-on-unicode-separators.patch + # Downstream only patch # Users might have local installations of pip from using # `pip install --user --upgrade pip` on older/newer versions. @@ -401,6 +408,9 @@ pytest_k='not completion and %{python_wheeldir}/%{python_wheelname} %changelog +* Mon May 17 2021 Karolina Surma - 20.2.2-2 +- Backport security fix from pip 21.1.1 + * Wed Aug 05 2020 Tomas Orsava - 20.2.2-1 - Update to 20.2.2 (#1838553)