diff --git a/0001-Restrict-third-party-access-to-cookie-jar-CVE-2012-0.patch b/0001-Restrict-third-party-access-to-cookie-jar-CVE-2012-0.patch new file mode 100644 index 0000000..e0c7363 --- /dev/null +++ b/0001-Restrict-third-party-access-to-cookie-jar-CVE-2012-0.patch @@ -0,0 +1,79 @@ +From 0d747f8715f2b9d2acddda8748e0c3f838f197de Mon Sep 17 00:00:00 2001 +From: Luca Bruno +Date: Sat, 11 Feb 2012 15:23:14 +0100 +Subject: [PATCH] Restrict third-party access to cookie jar (CVE-2012-0843) + +Make sure new cookie jar is created with no permission for "others", +and remove excessive rights on existing jar if any. +This fixes CVE-2012-0843 and uzbl bug #291. + +Signed-off-by: Luca Bruno +--- + examples/data/plugins/cookies.py | 20 +++++++++++++++++++- + 1 files changed, 19 insertions(+), 1 deletions(-) + +diff --git a/examples/data/plugins/cookies.py b/examples/data/plugins/cookies.py +index e29ee36..721feef 100644 +--- a/examples/data/plugins/cookies.py ++++ b/examples/data/plugins/cookies.py +@@ -2,7 +2,7 @@ + forwards cookies to all other instances connected to the event manager""" + + from collections import defaultdict +-import os, re ++import os, re, stat + + # these are symbolic names for the components of the cookie tuple + symbolic = {'domain': 0, 'path':1, 'name':2, 'value':3, 'scheme':4, 'expires':5} +@@ -32,6 +32,14 @@ class ListStore(list): + class TextStore(object): + def __init__(self, filename): + self.filename = filename ++ try: ++ # make sure existing cookie jar is not world-open ++ perm_mode = os.stat(self.filename).st_mode ++ if (perm_mode & (stat.S_IRWXO | stat.S_IRWXG)) > 0: ++ safe_perm = stat.S_IMODE(perm_mode) & ~(stat.S_IRWXO | stat.S_IRWXG) ++ os.chmod(self.filename, safe_perm) ++ except OSError: ++ pass + + def as_event(self, cookie): + """Convert cookie.txt row to uzbls cookie event format""" +@@ -76,16 +84,25 @@ class TextStore(object): + # delete equal cookies (ignoring expire time, value and secure flag) + self.delete_cookie(None, cookie[:-3]) + ++ # restrict umask before creating the cookie jar ++ curmask=os.umask(0) ++ os.umask(curmask| stat.S_IRWXO | stat.S_IRWXG) ++ + first = not os.path.exists(self.filename) + with open(self.filename, 'a') as f: + if first: + print >> f, "# HTTP Cookie File" + print >> f, '\t'.join(self.as_file(cookie)) ++ os.umask(curmask) + + def delete_cookie(self, rkey, key): + if not os.path.exists(self.filename): + return + ++ # restrict umask before creating the cookie jar ++ curmask=os.umask(0) ++ os.umask(curmask | stat.S_IRWXO | stat.S_IRWXG) ++ + # read all cookies + with open(self.filename, 'r') as f: + cookies = f.readlines() +@@ -96,6 +113,7 @@ class TextStore(object): + c = self.as_event(l.split('\t')) + if c is None or not match(key, c): + print >> f, l, ++ os.umask(curmask) + + xdg_data_home = os.environ.get('XDG_DATA_HOME', os.path.join(os.environ['HOME'], '.local/share')) + DefaultStore = TextStore(os.path.join(xdg_data_home, 'uzbl/cookies.txt')) +-- +1.7.9.1 + diff --git a/uzbl.spec b/uzbl.spec index c1dc739..8184776 100644 --- a/uzbl.spec +++ b/uzbl.spec @@ -1,11 +1,10 @@ %global uzblcommit e7578e27c -%global vim_version 73 Name: uzbl Summary: Lightweight WebKit browser following the UNIX philosophy Group: Applications/Internet Version: 0 -Release: 0.25.20110402git%{uzblcommit}%{?dist} +Release: 0.26.20110402git%{uzblcommit}%{?dist} License: GPLv3 URL: http://www.uzbl.org # The source for this package was pulled from upstream's vcs. Use the @@ -17,8 +16,12 @@ URL: http://www.uzbl.org # gzip -c > ../uzbl-${uzblcommit}.tar.gz Source0: %{name}-%{uzblcommit}.tar.gz Source1: %{name}.desktop +# RPM handles docs for us, won't be upstreamed Patch0: %{name}-makefile.patch +# Fedora-specific, won't be upstreamed Patch1: 0001-Fedora-specific-error-messages-on-no-configs.patch +# From upstream +Patch5: 0001-Restrict-third-party-access-to-cookie-jar-CVE-2012-0.patch BuildRequires: webkitgtk-devel BuildRequires: desktop-file-utils @@ -88,7 +91,7 @@ Default configuration for uzbl. %package vim Summary: Vim highlighting for uzbl's config Group: Applications/Text -Requires: vim-enhanced +Requires: vim-filesystem %description vim Highlighting files for uzbl's configuration. @@ -96,8 +99,9 @@ Highlighting files for uzbl's configuration. %prep %setup -q -n %{name}-%{uzblcommit} -%patch0 -p1 -%patch1 -p1 +%patch0 -p1 -b .makefile +%patch1 -p1 -b .fedora +%patch5 -p1 -b .cookie-perms mkdir -p icons/hicolor/32x32/apps mv examples/data/uzbl.png icons/hicolor/32x32/apps @@ -116,12 +120,12 @@ cp -pr icons %{buildroot}%{_datadir} desktop-file-install --dir=%{buildroot}%{_datadir}/applications \ %{SOURCE1} -mkdir -p %{buildroot}%{_datadir}/vim/vim%{vim_version}/ftdetect/ -install -p extras/vim/ftdetect/uzbl.vim %{buildroot}%{_datadir}/vim/vim%{vim_version}/ftdetect/uzbl.vim -mkdir -p %{buildroot}%{_datadir}/vim/vim%{vim_version}/ftplugin/ -install -p extras/vim/ftplugin/uzbl.vim %{buildroot}%{_datadir}/vim/vim%{vim_version}/ftplugin/uzbl.vim -mkdir -p %{buildroot}%{_datadir}/vim/vim%{vim_version}/syntax/ -install -p extras/vim/syntax/uzbl.vim %{buildroot}%{_datadir}/vim/vim%{vim_version}/syntax/uzbl.vim +mkdir -p %{buildroot}%{_datadir}/vim/vimfiles/ftdetect/ +install -p extras/vim/ftdetect/uzbl.vim %{buildroot}%{_datadir}/vim/vimfiles/ftdetect/uzbl.vim +mkdir -p %{buildroot}%{_datadir}/vim/vimfiles/ftplugin/ +install -p extras/vim/ftplugin/uzbl.vim %{buildroot}%{_datadir}/vim/vimfiles/ftplugin/uzbl.vim +mkdir -p %{buildroot}%{_datadir}/vim/vimfiles/syntax/ +install -p extras/vim/syntax/uzbl.vim %{buildroot}%{_datadir}/vim/vimfiles/syntax/uzbl.vim %post @@ -165,12 +169,16 @@ gtk-update-icon-cache %{_datadir}/icons/hicolor &>/dev/null || : %files vim %defattr(-, root, root, -) -%{_datadir}/vim/vim%{vim_version}/ftdetect/uzbl.vim -%{_datadir}/vim/vim%{vim_version}/ftplugin/uzbl.vim -%{_datadir}/vim/vim%{vim_version}/syntax/uzbl.vim +%{_datadir}/vim/vimfiles/ftdetect/uzbl.vim +%{_datadir}/vim/vimfiles/ftplugin/uzbl.vim +%{_datadir}/vim/vimfiles/syntax/uzbl.vim %changelog +* Thu Feb 23 2012 Ben Boeckel - 0-0.26.20110402gite7578e27c +- Lock down permissions on cookie files (CVE-2012-0843) +- Clean up vim subpackage + * Mon Apr 4 2011 Daiki Ueno - 0-0.25.20110402gite7578e27c - New upstream snapshot - Don't install removed uzbl-cookie-manager and related files.