diff --git a/.gitignore b/.gitignore index 1527c7a..ee3e2c4 100644 --- a/.gitignore +++ b/.gitignore @@ -7,23 +7,3 @@ lzma465.tar.bz2 /upx-3.91-src.tar.bz2 /upx-3.93-src.tar.xz /upx-3.94-src.tar.xz -/upx-3.95.tar.gz -/upx-lzma-sdk-3.95.tar.gz -/upx-3.96-src.tar.xz -/upx-lzma-sdk-3.96.tar.gz -/upx-4.0.0-src.tar.xz -/upx-4.0.1-src.tar.xz -/upx-4.0.2-src.tar.xz -/upx-4.1.0-src.tar.xz -/upx-4.2.0-src.tar.xz -/upx-4.2.1-src.tar.xz -/upx-4.2.2-src.tar.xz -/upx-4.2.3-src.tar.xz -/upx-4.2.4-src.tar.xz -/upx-5.0.0-src.tar.xz -/upx-5.0.1-src.tar.xz -/upx-5.0.2-src.tar.xz -/upx-5.1.0-src.tar.xz -/upx-5.1.1-src.tar.xz -/upx-5.2.0-src.tar.xz -/upx-5.2.1-src.tar.xz diff --git a/ef336dbcc6dc8344482f8cf6c909ae96c3286317.patch b/ef336dbcc6dc8344482f8cf6c909ae96c3286317.patch new file mode 100644 index 0000000..ef34336 --- /dev/null +++ b/ef336dbcc6dc8344482f8cf6c909ae96c3286317.patch @@ -0,0 +1,67 @@ +From ef336dbcc6dc8344482f8cf6c909ae96c3286317 Mon Sep 17 00:00:00 2001 +From: John Reiser +Date: Mon, 2 Oct 2017 21:47:40 -0700 +Subject: [PATCH] Protect against bad crafted input. + +https://github.com/upx/upx/issues/128 + modified: p_lx_elf.cpp +--- + src/p_lx_elf.cpp | 20 ++++++++++++++++++++ + 1 file changed, 20 insertions(+) + +diff --git a/src/p_lx_elf.cpp b/src/p_lx_elf.cpp +index e6336425..9272cf9b 100644 +--- a/src/p_lx_elf.cpp ++++ b/src/p_lx_elf.cpp +@@ -245,8 +245,15 @@ PackLinuxElf32::PackLinuxElf32help1(InputFile *f) + sz_phdrs = 0; + return; + } ++ if (0==e_phnum) throwCantUnpack("0==e_phnum"); + e_phoff = get_te32(&ehdri.e_phoff); ++ if ((unsigned long)file_size < ((unsigned long)e_phoff + e_phnum * sizeof(Elf32_Phdr))) { ++ throwCantUnpack("bad e_phoff"); ++ } + e_shoff = get_te32(&ehdri.e_shoff); ++ if ((unsigned long)file_size < ((unsigned long)e_shoff + e_shnum * sizeof(Elf32_Shdr))) { ++ throwCantUnpack("bad e_shoff"); ++ } + sz_phdrs = e_phnum * e_phentsize; + + if (f && Elf32_Ehdr::ET_DYN!=e_type) { +@@ -661,8 +668,15 @@ PackLinuxElf64::PackLinuxElf64help1(InputFile *f) + sz_phdrs = 0; + return; + } ++ if (0==e_phnum) throwCantUnpack("0==e_phnum"); + e_phoff = get_te64(&ehdri.e_phoff); ++ if ((unsigned long)file_size < (e_phoff + e_phnum * sizeof(Elf64_Phdr))) { ++ throwCantUnpack("bad e_phoff"); ++ } + e_shoff = get_te64(&ehdri.e_shoff); ++ if ((unsigned long)file_size < (e_shoff + e_shnum * sizeof(Elf64_Shdr))) { ++ throwCantUnpack("bad e_shoff"); ++ } + sz_phdrs = e_phnum * e_phentsize; + + if (f && Elf64_Ehdr::ET_DYN!=e_type) { +@@ -3490,6 +3504,9 @@ void PackLinuxElf64::pack4(OutputFile *fo, Filter &ft) + + void PackLinuxElf64::unpack(OutputFile *fo) + { ++ if (e_phoff != sizeof(Elf64_Ehdr)) {// Phdrs not contiguous with Ehdr ++ throwCantUnpack("bad e_phoff"); ++ } + unsigned const c_phnum = get_te16(&ehdri.e_phnum); + upx_uint64_t old_data_off = 0; + upx_uint64_t old_data_len = 0; +@@ -4110,6 +4127,9 @@ Elf64_Sym const *PackLinuxElf64::elf_lookup(char const *name) const + + void PackLinuxElf32::unpack(OutputFile *fo) + { ++ if (e_phoff != sizeof(Elf32_Ehdr)) {// Phdrs not contiguous with Ehdr ++ throwCantUnpack("bad e_phoff"); ++ } + unsigned const c_phnum = get_te16(&ehdri.e_phnum); + unsigned old_data_off = 0; + unsigned old_data_len = 0; diff --git a/sources b/sources index dd2477c..1fbf908 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (upx-5.2.1-src.tar.xz) = 38fa0aa9940d9518df5bf07725ed65391d1a965cac4feace190819e7bd8125e4ed23a3795cf0fb7d4df09fbca66158265ae5774a3c48f5b55e3905fc7b962bc4 +SHA512 (upx-3.94-src.tar.xz) = b9e8e6e13b2a267a30a9c4e572243c4ebeff9600044193de38c84e8943e3cd30c9cdd7b270cc0bdf14c1078ac15250906238f8272cd97a7eb40f2588965c6151 diff --git a/upx-3.03-pefile-strictproto.patch b/upx-3.03-pefile-strictproto.patch new file mode 100644 index 0000000..e16d71b --- /dev/null +++ b/upx-3.03-pefile-strictproto.patch @@ -0,0 +1,7 @@ +--- src/pefile.cpp.orig 2009-02-27 10:01:44.000000000 -0600 ++++ src/pefile.cpp 2009-02-27 10:01:44.000000000 -0600 +@@ -1352,2 +1352,2 @@ +- char *delim1 = strchr(keep, '/'); +- char *delim2 = strchr(keep, ','); ++ const char *delim1 = strchr(keep, '/'); ++ const char *delim2 = strchr(keep, ','); diff --git a/upx-3.07-use-lzma-sdk-lib.patch b/upx-3.07-use-lzma-sdk-lib.patch new file mode 100644 index 0000000..1a8b63e --- /dev/null +++ b/upx-3.07-use-lzma-sdk-lib.patch @@ -0,0 +1,102 @@ +diff -up upx-3.07-src/src/compress_lzma.cpp.use-lib upx-3.07-src/src/compress_lzma.cpp +--- upx-3.07-src/src/compress_lzma.cpp.use-lib 2010-09-08 11:07:00.000000000 -0400 ++++ upx-3.07-src/src/compress_lzma.cpp 2011-08-09 14:43:45.097077927 -0400 +@@ -340,11 +338,9 @@ error: + #undef _NO_EXCEPTIONS + #if (WITH_LZMA >= 0x449) + # define INITGUID 1 +-//# include "CPP/7zip/Compress/LZMA/LZMADecoder.h" + # include "CPP/7zip/Compress/LZMA/LZMAEncoder.h" + #else + # include "C/Common/MyInitGuid.h" +-//# include "C/7zip/Compress/LZMA/LZMADecoder.h" + # include "C/7zip/Compress/LZMA/LZMAEncoder.h" + #endif + +@@ -416,29 +412,6 @@ STDMETHODIMP ProgressInfo::SetRatioInfo( + # pragma warning(disable: 424) // #424: extra ";" ignored + #endif + +-#if (WITH_LZMA >= 0x449) +-# include "C/Alloc.c" +-# include "C/7zCrc.c" +-# include "C/Compress/Lz/MatchFinder.c" +-//# include "CPP/7zip/Common/InBuffer.cpp" +-# include "CPP/7zip/Common/OutBuffer.cpp" +-# include "CPP/7zip/Common/StreamUtils.cpp" +-//# include "CPP/7zip/Compress/LZ/LZOutWindow.cpp" +-//# include "CPP/7zip/Compress/LZMA/LZMADecoder.cpp" +-# include "CPP/7zip/Compress/LZMA/LZMAEncoder.cpp" +-# include "CPP/7zip/Compress/RangeCoder/RangeCoderBit.cpp" +-#else +-# include "C/Common/Alloc.cpp" +-# include "C/Common/CRC.cpp" +-//# include "C/7zip/Common/InBuffer.cpp" +-# include "C/7zip/Common/OutBuffer.cpp" +-# include "C/7zip/Common/StreamUtils.cpp" +-# include "C/7zip/Compress/LZ/LZInWindow.cpp" +-//# include "C/7zip/Compress/LZ/LZOutWindow.cpp" +-//# include "C/7zip/Compress/LZMA/LZMADecoder.cpp" +-# include "C/7zip/Compress/LZMA/LZMAEncoder.cpp" +-# include "C/7zip/Compress/RangeCoder/RangeCoderBit.cpp" +-#endif + #undef RC_NORMALIZE + + +@@ -563,7 +536,6 @@ error: + + #undef _LZMA_PROB32 + #include "C/LzmaDec.h" +-#include "C/LzmaDec.c" + + + int upx_lzma_decompress ( const upx_bytep src, unsigned src_len, +@@ -662,10 +634,8 @@ error: + #undef _LZMA_LOC_OPT + #if (WITH_LZMA >= 0x449) + # include "C/Compress/Lzma/LzmaDecode.h" +-# include "C/Compress/Lzma/LzmaDecode.c" + #else + # include "C/7zip/Compress/LZMA_C/LzmaDecode.h" +-# include "C/7zip/Compress/LZMA_C/LzmaDecode.c" + #endif + + int upx_lzma_decompress ( const upx_bytep src, unsigned src_len, +diff -up upx-3.07-src/src/Makefile.use-lib upx-3.07-src/src/Makefile +--- upx-3.07-src/src/Makefile.use-lib 2011-08-09 14:44:35.619476678 -0400 ++++ upx-3.07-src/src/Makefile 2011-08-09 14:44:10.731772723 -0400 +@@ -57,7 +57,7 @@ ifneq ($(wildcard $(UPX_UCLDIR)/include/ + INCLUDES += -I$(UPX_UCLDIR)/include + LIBS += $(addprefix -L,$(dir $(wildcard $(UPX_UCLDIR)/libucl$(libext) $(UPX_UCLDIR)/src/.libs/libucl$(libext)))) + endif +-LIBS += -lucl -lz ++LIBS += -lucl -lz -llzmasdk + # you should set envvar UPX_LZMADIR to point to your unpacked LZMA SDK + include $(top_srcdir)/src/stub/src/c/Makevars.lzma + ifneq ($(UPX_LZMA_VERSION),) +diff -up upx-3.07-src/src/stub/src/c/lzma_d_c.c.use-lib upx-3.07-src/src/stub/src/c/lzma_d_c.c +--- upx-3.07-src/src/stub/src/c/lzma_d_c.c.use-lib 2010-09-08 11:07:00.000000000 -0400 ++++ upx-3.07-src/src/stub/src/c/lzma_d_c.c 2011-08-09 14:43:45.098077915 -0400 +@@ -100,11 +100,6 @@ int LzmaDecode(CLzmaDecoderState *, cons + #if (ACC_CC_BORLANDC) + #include "LzmaDecode.c" + #else +-#if (WITH_LZMA >= 0x449) +-# include "C/Compress/Lzma/LzmaDecode.c" +-#else +-# include "C/7zip/Compress/LZMA_C/LzmaDecode.c" +-#endif + #endif + #undef char + #undef CLzmaDecoderState +--- upx-3.91-src/src/compress_lzma.cpp~ 2013-10-28 07:35:17.000000000 -0500 ++++ upx-3.91-src/src/compress_lzma.cpp 2013-10-28 07:37:45.121258359 -0500 +@@ -233,8 +233,6 @@ + #define _7ZIP_ST 1 + #define kLiteralNextStates kLiteralNextStates_enc + #include "C/LzmaEnc.h" +-#include "C/LzmaEnc.c" +-#include "C/LzFind.c" + #undef kLiteralNextStates + #undef kNumFullDistances + diff --git a/upx-whitespace.patch b/upx-whitespace.patch new file mode 100644 index 0000000..9657b2b --- /dev/null +++ b/upx-whitespace.patch @@ -0,0 +1,11 @@ +--- src/Makefile~ 2017-01-29 10:53:00.000000000 -0600 ++++ src/Makefile 2017-03-30 10:03:12.447172055 -0500 +@@ -86,7 +86,7 @@ + $($(notdir $@).PRE_LINK_STEP) + $(strip $(CXXLD) $(call ee,CXXFLAGS) $(call ee,LDFLAGS) -o $@ $(upx_OBJECTS) $(call ee,LDADD) $(call ee,LIBS)) + $($(notdir $@).POST_LINK_STEP) +- $(CHECK_WHITESPACE) ++# $(CHECK_WHITESPACE) + + %.o : %.cpp | ./.depend + $(strip $(CXX) $(call ee,CPPFLAGS) $(call ee,CXXFLAGS) -o $@ -c $<) diff --git a/upx.spec b/upx.spec index e444b9c..ad82650 100644 --- a/upx.spec +++ b/upx.spec @@ -1,19 +1,23 @@ Name: upx -Version: 5.2.1 +Version: 3.94 Release: 1%{?dist} Summary: Ultimate Packer for eXecutables -License: GPL-2.0-or-later AND LicenseRef-Fedora-Public-Domain -URL: https://github.com/upx/upx -Source0: %{url}/releases/download/v%{version}/%{name}-%{version}-src.tar.xz +Group: Applications/Archiving +License: GPLv2+ and Public Domain +URL: http://upx.sourceforge.net/ +Source0: http://upx.sourceforge.net/download/%{name}-%{version}-src.tar.xz +#Patch0: upx-3.03-pefile-strictproto.patch +#Patch1: upx-3.07-use-lzma-sdk-lib.patch +#Patch2: upx-fallthrough.patch +Patch3: upx-whitespace.patch +Patch4: ef336dbcc6dc8344482f8cf6c909ae96c3286317.patch +BuildRoot: %{_tmppath}/%{name}-%{version}-%{release}-root-%(%{__id_u} -n) + -BuildRequires: make -BuildRequires: gcc-c++ -BuildRequires: cmake BuildRequires: ucl-devel >= 1.01 BuildRequires: zlib-devel -BuildRequires: perl-podlators -Provides: bundled(lzma-sdk) = 4.43 +BuildRequires: lzma-sdk-devel %description UPX is a free, portable, extendable, high-performance executable @@ -23,166 +27,40 @@ executables suffer no memory overhead or other drawbacks. %prep -%setup -qn %{name}-%{version}-src +%setup -q -n %{name}-%{version}-src +sed -i -e 's/ -O2/ /' -e 's/ -Werror//' src/Makefile +#%patch0 -p0 +#%patch1 -p1 -b .use-lib +#%patch2 -p0 +%patch3 -p0 +%patch4 -p1 %build -%cmake -%cmake_build +export CXX="g++" +export CXXFLAGS="$RPM_OPT_FLAGS" # export, not to make so it won't trump all +UPX_LZMA_VERSION=0x465 UPX_LZMADIR=%{_includedir}/lzma465 make %{?_smp_mflags} -C src +make -C doc %install -%cmake_install -mv %{buildroot}%{_datadir}/doc/upx/upx-doc.* . -rm -f %{buildroot}%{_datadir}/doc/upx/* +rm -rf $RPM_BUILD_ROOT +install -Dpm 644 doc/upx.1 $RPM_BUILD_ROOT%{_mandir}/man1/upx.1 +install -Dpm 755 src/upx.out $RPM_BUILD_ROOT%{_bindir}/upx + + +%clean +rm -rf $RPM_BUILD_ROOT + %files -%license COPYING LICENSE -%doc NEWS README README.SRC doc/THANKS.txt upx-doc.* +%defattr(-,root,root,-) +%doc BUGS COPYING LICENSE NEWS PROJECTS README README.1ST THANKS %{_bindir}/upx %{_mandir}/man1/upx.1* %changelog -* Thu Aug 27 2026 Gwyn Ciesla - 5.2.1-1 -- 5.2.1 - -* Fri Jul 17 2026 Fedora Release Engineering - 5.2.0-2 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild - -* Thu Jun 11 2026 Gwyn Ciesla - 5.2.0-1 -- 5.2.0 - -* Thu Mar 05 2026 Gwyn Ciesla - 5.1.1-1 -- 5.1.1 - -* Sat Jan 17 2026 Fedora Release Engineering - 5.1.0-2 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild - -* Wed Jan 07 2026 Gwyn Ciesla - 5.1.0-1 -- 5.1.0 - -* Fri Jul 25 2025 Fedora Release Engineering - 5.0.2-2 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild - -* Mon Jul 21 2025 Gwyn Ciesla - 5.0.2-1 -- 5.0.2 - -* Tue May 06 2025 Gwyn Ciesla - 5.0.1-1 -- 5.0.1 - -* Thu Feb 20 2025 Gwyn Ciesla - 5.0.0-1 -- 5.0.0 - -* Sun Jan 19 2025 Fedora Release Engineering - 4.2.4-4 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild - -* Wed Dec 18 2024 Gwyn Ciesla - 4.2.4-3 -- Provide bundled lzma-sdk - -* Sat Jul 20 2024 Fedora Release Engineering - 4.2.4-2 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild - -* Tue May 21 2024 Gwyn Ciesla - 4.2.4-1 -- 4.2.4 - -* Thu Mar 28 2024 Gwyn Ciesla - 4.2.3-1 -- 4.2.3 - -* Sat Jan 27 2024 Fedora Release Engineering - 4.2.2-2 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild - -* Thu Jan 04 2024 Gwyn Ciesla - 4.2.2-1 -- 4.2.2 - -* Thu Nov 02 2023 Gwyn Ciesla - 4.2.1-1 -- 4.2.1 - -* Fri Oct 27 2023 Gwyn Ciesla - 4.2.0-1 -- 4.2.0 - -* Wed Aug 09 2023 Gwyn Ciesla - 4.1.0-1 -- 4.1.0 - -* Sat Jul 22 2023 Fedora Release Engineering - 4.0.2-3 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild - -* Sun Mar 05 2023 Gwyn Ciesla - 4.0.2-2 -- migrated to SPDX license - -* Wed Feb 01 2023 Gwyn Ciesla - 4.0.2-1 -- 4.0.2 - -* Sat Jan 21 2023 Fedora Release Engineering - 4.0.1-3 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild - -* Thu Jan 12 2023 Gwyn Ciesla - 4.0.1-2 -- Patches for CVE-2023-23456, CVE-2023-23457 - -* Thu Nov 17 2022 Gwyn Ciesla - 4.0.1-1 -- 4.0.1 - -* Fri Nov 04 2022 Gwyn Ciesla - 4.0.0-1 -- 4.0.0 - -* Sat Jul 23 2022 Fedora Release Engineering - 3.96-12 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild - -* Sat Jan 22 2022 Fedora Release Engineering - 3.96-11 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild - -* Fri Jul 23 2021 Fedora Release Engineering - 3.96-10 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild - -* Tue May 18 2021 Gwyn Ciesla - 3.96-9 -- Patch for CVE-2020-24119 - -* Thu Mar 11 2021 Gwyn Ciesla - 3.96-8 -- Patch for CVE-2021-20285 - -* Wed Jan 27 2021 Fedora Release Engineering - 3.96-7 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild - -* Mon Aug 10 2020 Gwyn Ciesla - 3.96-6 -- Make PE load config directory address dword aligned - -* Wed Jul 29 2020 Fedora Release Engineering - 3.96-5 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild - -* Mon Apr 20 2020 Gwyn Ciesla - 3.96-4 -- Patch for segfault using preserve-build-id. - -* Fri Jan 31 2020 Fedora Release Engineering - 3.96-3 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild - -* Fri Jan 24 2020 Gwyn Ciesla - 3.96-2 -- EVR bump for koji issue. - -* Fri Jan 24 2020 Gwyn Ciesla - 3.96-1 -- 3.96 - -* Fri Jan 17 2020 Gwyn Ciesla - 3.95-5 -- Upstream patch for CVE-2019-20021 - -* Thu Aug 01 2019 Gwyn Ciesla - 3.95-4 -- Upstream patches for CVE-2019-14295 and CVE-2019-14296. - -* Sat Jul 27 2019 Fedora Release Engineering - 3.95-3 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild - -* Sun Feb 03 2019 Fedora Release Engineering - 3.95-2 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild - -* Mon Aug 27 2018 Gwyn Ciesla - 3.95-1 -- 3.95. -- Switch to upstream's lzma fork. - -* Sat Jul 14 2018 Fedora Release Engineering - 3.94-3 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild - -* Fri Feb 09 2018 Fedora Release Engineering - 3.94-2 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild - * Tue Oct 10 2017 Gwyn Ciesla - 3.94-1 - 3.94, plus patch for CVE-2017-15056.