Compare commits
2 commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
54d6deb4cb | ||
|
|
d461c2c5e7 |
3 changed files with 170 additions and 1 deletions
|
|
@ -0,0 +1,52 @@
|
|||
From 5d201df72f3d4f4cb8b8f75f980169b03507da38 Mon Sep 17 00:00:00 2001
|
||||
From: Tobias Stoeckmann <tobias@stoeckmann.org>
|
||||
Date: Tue, 28 Nov 2017 21:38:07 +0100
|
||||
Subject: [PATCH] cursor: Fix heap overflows when parsing malicious files.
|
||||
|
||||
It is possible to trigger heap overflows due to an integer overflow
|
||||
while parsing images.
|
||||
|
||||
The integer overflow occurs because the chosen limit 0x10000 for
|
||||
dimensions is too large for 32 bit systems, because each pixel takes
|
||||
4 bytes. Properly chosen values allow an overflow which in turn will
|
||||
lead to less allocated memory than needed for subsequent reads.
|
||||
|
||||
See also: https://cgit.freedesktop.org/xorg/lib/libXcursor/commit/?id=4794b5dd34688158fb51a2943032569d3780c4b8
|
||||
Fixes: https://bugs.freedesktop.org/show_bug.cgi?id=103961
|
||||
|
||||
Signed-off-by: Tobias Stoeckmann <tobias@stoeckmann.org>
|
||||
[Pekka: add link to the corresponding libXcursor commit]
|
||||
Signed-off-by: Pekka Paalanen <pekka.paalanen@collabora.co.uk>
|
||||
---
|
||||
cursor/xcursor.c | 8 +++++++-
|
||||
1 file changed, 7 insertions(+), 1 deletion(-)
|
||||
|
||||
diff --git a/cursor/xcursor.c b/cursor/xcursor.c
|
||||
index ca41c4ac611f..689c7026729d 100644
|
||||
--- a/cursor/xcursor.c
|
||||
+++ b/cursor/xcursor.c
|
||||
@@ -202,6 +202,11 @@ XcursorImageCreate (int width, int height)
|
||||
{
|
||||
XcursorImage *image;
|
||||
|
||||
+ if (width < 0 || height < 0)
|
||||
+ return NULL;
|
||||
+ if (width > XCURSOR_IMAGE_MAX_SIZE || height > XCURSOR_IMAGE_MAX_SIZE)
|
||||
+ return NULL;
|
||||
+
|
||||
image = malloc (sizeof (XcursorImage) +
|
||||
width * height * sizeof (XcursorPixel));
|
||||
if (!image)
|
||||
@@ -482,7 +487,8 @@ _XcursorReadImage (XcursorFile *file,
|
||||
if (!_XcursorReadUInt (file, &head.delay))
|
||||
return NULL;
|
||||
/* sanity check data */
|
||||
- if (head.width >= 0x10000 || head.height > 0x10000)
|
||||
+ if (head.width > XCURSOR_IMAGE_MAX_SIZE ||
|
||||
+ head.height > XCURSOR_IMAGE_MAX_SIZE)
|
||||
return NULL;
|
||||
if (head.width == 0 || head.height == 0)
|
||||
return NULL;
|
||||
--
|
||||
2.14.3
|
||||
|
||||
104
Switch-graphviz-files-to-use-HTML-style-labels.patch
Normal file
104
Switch-graphviz-files-to-use-HTML-style-labels.patch
Normal file
|
|
@ -0,0 +1,104 @@
|
|||
From b0d9d7fae7752f3d5f15b15d08986a8e602c832f Mon Sep 17 00:00:00 2001
|
||||
From: "Owen W. Taylor" <otaylor@fishsoup.net>
|
||||
Date: Thu, 1 Jun 2017 18:03:28 -0400
|
||||
Subject: [PATCH] Switch graphviz files to use HTML-style labels
|
||||
|
||||
With recent versions of graphviz, generation of the diagrams in the documentation
|
||||
fails with:
|
||||
|
||||
/usr/bin/dot -Tpng -oxml/x-architecture.png dot/x-architecture.gv
|
||||
Warning: flat edge between adjacent nodes one of which has a record shape - replace records with HTML-like labels
|
||||
Edge xserver -> comp
|
||||
Error: getsplinepoints: no spline points available for edge (xserver,comp)
|
||||
Error: lost xserver comp edge
|
||||
Error: lost xserver comp edge
|
||||
Error: lost comp xserver edge
|
||||
Error: lost comp xserver edge
|
||||
|
||||
http://www.graphviz.org/content/i-havent-been-able-render-these-files-graphviz-226 indicates
|
||||
that the error message basically means that the authors of graphviz consider record-style
|
||||
labels to be deprecated and are no longer fixing errors with them. This patch changes
|
||||
the labels to be in the HTML style, which seems to require duplicating style between all
|
||||
the nodes, but it's not like these files are often edited.
|
||||
|
||||
The result is not exactly the same but is quite similar.
|
||||
---
|
||||
doc/doxygen/dot/wayland-architecture.gv | 13 +++++--------
|
||||
doc/doxygen/dot/x-architecture.gv | 17 ++++++++---------
|
||||
2 files changed, 13 insertions(+), 17 deletions(-)
|
||||
|
||||
diff --git a/doc/doxygen/dot/wayland-architecture.gv b/doc/doxygen/dot/wayland-architecture.gv
|
||||
index 2d5db84..f2c3507 100644
|
||||
--- a/doc/doxygen/dot/wayland-architecture.gv
|
||||
+++ b/doc/doxygen/dot/wayland-architecture.gv
|
||||
@@ -9,21 +9,18 @@ digraph arch_wayland {
|
||||
]
|
||||
|
||||
node[
|
||||
- shape="Mrecord",
|
||||
color=none,
|
||||
- fillcolor="#ffbc00",
|
||||
- style="filled",
|
||||
+ margin=0,
|
||||
fontname="DejaVu Sans",
|
||||
fontsize="18",
|
||||
]
|
||||
|
||||
- c1 [label="Wayland Client", URL="#c1"]
|
||||
- c2 [label="Wayland Client", URL="#c2"]
|
||||
+ c1 [label=<<TABLE STYLE="rounded" BGCOLOR="#ffbc00"><TR><TD>Wayland Client</TD></TR></TABLE>>, URL="#c1"]
|
||||
+ c2 [label=<<TABLE STYLE="rounded" BGCOLOR="#ffbc00"><TR><TD>Wayland Client</TD></TR></TABLE>>, URL="#c2"]
|
||||
|
||||
- comp [tooltip="Wayland Compositor", label="|{|Wayland\nCompositor|}|", URL="#comp"]
|
||||
-
|
||||
- impl [tooltip="KMS evdev Kernel", label="|{{KMS|evdev}|Kernel}|", URL="#impl"]
|
||||
+ comp [tooltip="Wayland Compositor", label=<<TABLE STYLE="rounded" BGCOLOR="#ffbc00"><TR><TD><BR/>Wayland<BR/>Compositor<BR/><BR/></TD></TR></TABLE>>, URL="#comp"]
|
||||
|
||||
+ impl [tooltip="KMS evdev Kernel", label=<<TABLE STYLE="rounded" BGCOLOR="#ffbc00"><TR><TD>KMS</TD><TD>evdev</TD></TR><TR><TD COLSPAN="2">Kernel</TD></TR></TABLE>>, URL="#impl"]
|
||||
|
||||
c1 -> comp [taillabel="③", labeldistance=2.5, URL="#step_3"];
|
||||
c2 -> comp;
|
||||
diff --git a/doc/doxygen/dot/x-architecture.gv b/doc/doxygen/dot/x-architecture.gv
|
||||
index 4ea49bf..b223d1d 100644
|
||||
--- a/doc/doxygen/dot/x-architecture.gv
|
||||
+++ b/doc/doxygen/dot/x-architecture.gv
|
||||
@@ -9,28 +9,27 @@ digraph arch_x {
|
||||
]
|
||||
|
||||
node[
|
||||
- shape="Mrecord",
|
||||
+ shape="none",
|
||||
color=none,
|
||||
- fillcolor="#ffbc00",
|
||||
- style="filled",
|
||||
+ margin=0,
|
||||
fontname="DejaVu Sans",
|
||||
fontsize="18",
|
||||
]
|
||||
|
||||
{
|
||||
rank=same;
|
||||
- c1 [label="X Client", URL="#c1"]
|
||||
- c3 [label="X Client", URL="#c3"]
|
||||
+ c1 [label=<<TABLE STYLE="rounded" BGCOLOR="#ffbc00"><TR><TD>X Client</TD></TR></TABLE>>, URL="#c1"]
|
||||
+ c3 [label=<<TABLE STYLE="rounded" BGCOLOR="#ffbc00"><TR><TD>X Client</TD></TR></TABLE>>, URL="#c3"]
|
||||
}
|
||||
- c2 [label="X Client", URL="#c2"]
|
||||
+ c2 [label=<<TABLE STYLE="rounded" BGCOLOR="#ffbc00"><TR><TD>X Client</TD></TR></TABLE>>, URL="#c2"]
|
||||
|
||||
{
|
||||
rank=same;
|
||||
- xserver [tooltip="X Server", label="|{|X Server|}|", URL="#xserver"]
|
||||
- comp [tooltip="Compositor", label="|{|Compositor|}|", URL="#comp"]
|
||||
+ xserver [tooltip="X Server", label=<<TABLE STYLE="rounded" BGCOLOR="#ffbc00"><TR><TD><BR/>X Server<BR/><BR/></TD></TR></TABLE>>, URL="#xserver"]
|
||||
+ comp [tooltip="Compositor", label=<<TABLE STYLE="rounded" BGCOLOR="#ffbc00"><TR><TD><BR/>Compositor<BR/><BR/></TD></TR></TABLE>>, URL="#comp"]
|
||||
}
|
||||
|
||||
- impl [tooltip="KMS evdev Kernel", label="|{{KMS|evdev}|Kernel}|", URL="#impl"]
|
||||
+ impl [tooltip="KMS evdev Kernel", label=<<TABLE STYLE="rounded" BGCOLOR="#ffbc00"><TR><TD>KMS</TD><TD>evdev</TD></TR><TR><TD COLSPAN="2">Kernel</TD></TR></TABLE>>, URL="#impl"]
|
||||
|
||||
c1 -> xserver [taillabel="③", labeldistance=2, URL="#step_3"];
|
||||
c2 -> xserver;
|
||||
--
|
||||
2.13.0
|
||||
|
||||
15
wayland.spec
15
wayland.spec
|
|
@ -1,6 +1,6 @@
|
|||
Name: wayland
|
||||
Version: 1.13.0
|
||||
Release: 1%{?dist}
|
||||
Release: 3%{?dist}
|
||||
Summary: Wayland Compositor Infrastructure
|
||||
|
||||
License: MIT
|
||||
|
|
@ -8,6 +8,11 @@ URL: http://wayland.freedesktop.org/
|
|||
Source0: http://wayland.freedesktop.org/releases/%{name}-%{version}.tar.xz
|
||||
# Fix the tests to pass on ppc64
|
||||
Patch0: tests-Fix-new-ID-type-handling-in-argument_from_va_list-test.patch
|
||||
# https://lists.freedesktop.org/archives/wayland-devel/2017-June/034218.html
|
||||
Patch1: Switch-graphviz-files-to-use-HTML-style-labels.patch
|
||||
# https://lists.freedesktop.org/archives/wayland-devel/2017-November/035979.html
|
||||
# Backported from upstream
|
||||
Patch2: 0001-cursor-Fix-heap-overflows-when-parsing-malicious-fil.patch
|
||||
|
||||
BuildRequires: chrpath
|
||||
BuildRequires: docbook-style-xsl
|
||||
|
|
@ -70,6 +75,8 @@ Wayland server library
|
|||
%prep
|
||||
%setup -q
|
||||
%patch0 -p1
|
||||
%patch1 -p1
|
||||
%patch2 -p1
|
||||
|
||||
|
||||
%build
|
||||
|
|
@ -130,6 +137,12 @@ XDG_RUNTIME_DIR=$PWD/tests/run make check || \
|
|||
%{_libdir}/libwayland-server.so.0*
|
||||
|
||||
%changelog
|
||||
* Tue Dec 12 2017 Kalev Lember <klember@redhat.com> - 1.13.0-3
|
||||
- cursor: Fix heap overflows when parsing malicious files (#1522638)
|
||||
|
||||
* Thu Jun 1 2017 Owen Taylor otaylor@redhat.com> - 1.13.0-2
|
||||
- Add a patch fixing a build error with newer versions of graphviz
|
||||
|
||||
* Wed Feb 22 2017 Kalev Lember <klember@redhat.com> - 1.13.0-1
|
||||
- Update to 1.13.0
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue