Compare commits

...
Sign in to create a new pull request.

5 commits

Author SHA1 Message Date
David Cantrell
ec74c6331f Fix 'guiutil.py:147:set_text:TypeError: Gtk.Entry.set_text()
argument 1 must be string, not dbus.Boolean' (#740256)
2012-04-25 11:43:36 -04:00
David Cantrell
7156261d57 Fix CVE-2012-2095 (#811763) 2012-04-13 10:36:53 -04:00
David Cantrell
23a76d9656 Fix CVS-2012-0813 (#785147) 2012-01-27 14:36:31 -05:00
David Cantrell
496bc86752 Initialize appGui._wired_showing in __init__ (#723553)
Make sure check and message in wicd-cli are a lambda (#712435)
2011-08-19 16:10:31 -04:00
David Cantrell
bd5839e538 Correct systemd unit file for wicd, add D-Bus service file (#699116)
Move docs to the wicd-common subpackage
Correct /etc/dbus-1/system.d/wicd.conf (#699116)
2011-08-11 17:05:39 -04:00
11 changed files with 380 additions and 5 deletions

11
org.wicd.daemon.service Normal file
View file

@ -0,0 +1,11 @@
# This D-Bus service activation file is only for systemd support since
# an auto-activated wicd would be quite surprising for those people
# who have wicd installed but turned off. Thus the Exec path available to
# D-Bus is /bin/false, but systemd knows the real Exec path due to the
# wicd systemd .service file.
[D-BUS Service]
Name=org.wicd.daemon
Exec=/bin/false
User=root
SystemdService=dbus-org.wicd.daemon.service

View file

@ -0,0 +1,19 @@
diff -up wicd-1.7.0/wicd/configmanager.py.CVE-2012-0813 wicd-1.7.0/wicd/configmanager.py
--- wicd-1.7.0/wicd/configmanager.py.CVE-2012-0813 2012-01-27 14:34:12.779219466 -0500
+++ wicd-1.7.0/wicd/configmanager.py 2012-01-27 14:34:33.534091679 -0500
@@ -97,8 +97,13 @@ class ConfigManager(RawConfigParser):
ret = ret[3:-3]
if default:
if self.debug:
- print ''.join(['found ', option, ' in configuration ',
- str(ret)])
+ # mask out sensitive information
+ if option in ['apsk', 'password', 'identity', 'private_key', \
+ 'private_key_passwd', 'key', 'passphrase']:
+ print ''.join(['found ', option, ' in configuration *****'])
+ else:
+ print ''.join(['found ', option, ' in configuration ',
+ str(ret)])
else:
if default != "__None__":
print 'did not find %s in configuration, setting default %s' % (option, str(default))

View file

@ -0,0 +1,91 @@
diff -up wicd-1.7.0/wicd/wicd-daemon.py.CVE-2012-2095 wicd-1.7.0/wicd/wicd-daemon.py
--- wicd-1.7.0/wicd/wicd-daemon.py.CVE-2012-2095 2012-04-13 10:17:46.356047035 -0400
+++ wicd-1.7.0/wicd/wicd-daemon.py 2012-04-13 10:18:35.018046979 -0400
@@ -978,6 +978,28 @@ class WirelessDaemon(dbus.service.Object
"wireless-settings.conf"),
debug=debug)
+ self._validProperties = (
+ 'bssid',
+ 'essid',
+ 'hidden',
+ 'channel',
+ 'mode',
+ 'enctype',
+ 'encryption_method',
+ 'key',
+ 'automatic',
+ 'ip',
+ 'netmask',
+ 'broadcast',
+ 'gateway',
+ 'use_static_dns',
+ 'use_global_dns',
+ 'dns1',
+ 'dns2',
+ 'dns3',
+ 'use_settings_globally',
+ )
+
def get_debug_mode(self):
return self._debug_mode
def set_debug_mode(self, mode):
@@ -1086,9 +1108,9 @@ class WirelessDaemon(dbus.service.Object
def SetWirelessProperty(self, netid, prop, value):
""" Sets property to value in network specified. """
# We don't write script settings here.
- if (prop.strip()).endswith("script"):
- print "Setting script properties through the daemon is not" \
- + " permitted."
+ if prop.strip() not in self._validProperties:
+ print "Trying to set invalid property (or property not " \
+ "permitted): "+ prop.strip() + "."
return False
self.LastScan[netid][prop] = misc.to_unicode(misc.Noneify(value))
@@ -1365,6 +1387,25 @@ class WiredDaemon(dbus.service.Object):
"wired-settings.conf"),
debug=debug)
+ self._validProperties = (
+ 'ip',
+ 'broadcast',
+ 'netmask',
+ 'gateway',
+ 'search_domain',
+ 'dns_domain',
+ 'dns1',
+ 'dns2',
+ 'dns3',
+ 'encryption_enabled',
+ 'default',
+ 'dhcphostname',
+ 'lastused',
+ 'profilename',
+ 'use_global_dns',
+ 'use_static_dns',
+ )
+
def get_debug_mode(self):
return self._debug_mode
def set_debug_mode(self, mode):
@@ -1405,14 +1446,14 @@ class WiredDaemon(dbus.service.Object):
return str(iface)
@dbus.service.method('org.wicd.daemon.wired')
- def SetWiredProperty(self, property, value):
+ def SetWiredProperty(self, prop, value):
""" Sets the given property to the given value. """
if self.WiredNetwork:
- if (property.strip()).endswith("script"):
- print "Setting script properties through the daemon" \
- + " is not permitted."
+ if prop.strip() not in self._validProperties:
+ print "Trying to set invalid property (or property not " \
+ "permitted): "+ prop.strip() + "."
return False
- self.WiredNetwork[property] = misc.to_unicode(misc.Noneify(value))
+ self.WiredNetwork[prop] = misc.to_unicode(misc.Noneify(value))
return True
else:
print 'SetWiredProperty: WiredNetwork does not exist'

34
wicd-1.7.0-bz740256.patch Normal file
View file

@ -0,0 +1,34 @@
diff -up wicd-1.7.0/gtk/guiutil.py.orig wicd-1.7.0/gtk/guiutil.py
--- wicd-1.7.0/gtk/guiutil.py.orig 2010-01-14 23:49:11.000000000 -0500
+++ wicd-1.7.0/gtk/guiutil.py 2012-04-25 11:40:30.747191654 -0400
@@ -106,13 +106,12 @@ def string_input(prompt, secondary, text
dialog.vbox.pack_end(hbox, True, True, 0)
dialog.show_all()
+ text = ''
if dialog.run() == gtk.RESPONSE_OK:
- text = entry.get_text()
- dialog.destroy()
- return text
- else:
- dialog.destroy()
- return None
+ text = entry.get_text().strip()
+
+ dialog.destroy()
+ return text
class SmallLabel(gtk.Label):
def __init__(self, text=''):
diff -up wicd-1.7.0/gtk/netentry.py.orig wicd-1.7.0/gtk/netentry.py
--- wicd-1.7.0/gtk/netentry.py.orig 2010-01-14 23:49:11.000000000 -0500
+++ wicd-1.7.0/gtk/netentry.py 2012-04-25 11:41:06.364192922 -0400
@@ -725,7 +725,7 @@ class WiredNetworkEntry(NetworkEntry):
"will not be used by the computer. It " +
"allows you to " +
"easily distinguish between different network " +
- "profiles.", "Profile name:").strip()
+ "profiles.", "Profile name:")
# if response is "" or None
if not response:

View file

@ -0,0 +1,50 @@
diff -up wicd-1.7.0/cli/wicd-cli.py.orig wicd-1.7.0/cli/wicd-cli.py
--- wicd-1.7.0/cli/wicd-cli.py.orig 2010-01-14 23:49:11.000000000 -0500
+++ wicd-1.7.0/cli/wicd-cli.py 2011-08-05 11:09:57.561058338 -0400
@@ -43,6 +43,10 @@ except dbus.DBusException:
print 'Error: Could not connect to the daemon. Please make sure it is running.'
sys.exit(3)
+if daemon is None:
+ print 'Error connecting to wicd via D-Bus. Please make sure the wicd service is running.'
+ sys.exit(3)
+
parser = optparse.OptionParser()
parser.add_option('--network', '-n', type='int', default=-1)
diff -up wicd-1.7.0/curses/wicd-curses.py.orig wicd-1.7.0/curses/wicd-curses.py
--- wicd-1.7.0/curses/wicd-curses.py.orig 2010-01-14 23:49:11.000000000 -0500
+++ wicd-1.7.0/curses/wicd-curses.py 2011-08-05 11:09:00.248056606 -0400
@@ -1016,6 +1016,10 @@ def setup_dbus(force=True):
wireless = dbus_ifaces['wireless']
wired = dbus_ifaces['wired']
+ if daemon is None:
+ print 'Error connecting to wicd via D-Bus. Please make sure the wicd service is running.'
+ sys.exit(3)
+
netentry_curses.dbus_init(dbus_ifaces)
return True
diff -up wicd-1.7.0/gtk/gui.py.orig wicd-1.7.0/gtk/gui.py
--- wicd-1.7.0/gtk/gui.py.orig 2010-01-14 23:49:11.000000000 -0500
+++ wicd-1.7.0/gtk/gui.py 2011-08-05 10:49:08.392177338 -0400
@@ -146,6 +146,17 @@ class appGui(object):
""" Initializes everything needed for the GUI. """
setup_dbus()
+ if daemon is None:
+ errmsg = "Error connecting to wicd service via D-Bus." + \
+ "Please ensure the wicd service is running."
+ d = gtk.MessageDialog(parent=None,
+ flags=gtk.DIALOG_MODAL,
+ type=gtk.MESSAGE_ERROR,
+ buttons=gtk.BUTTONS_OK,
+ message_format=errmsg)
+ d.run()
+ sys.exit(1)
+
self.tray = tray
gladefile = os.path.join(wpath.gtk, "wicd.glade")
diff -up wicd-1.7.0/gtk/wicd-client.py.orig wicd-1.7.0/gtk/wicd-client.py

View file

@ -0,0 +1,54 @@
diff -up wicd-1.7.0/in/other=wicd.conf.in.orig wicd-1.7.0/in/other=wicd.conf.in
--- wicd-1.7.0/in/other=wicd.conf.in.orig 2010-01-14 23:49:11.000000000 -0500
+++ wicd-1.7.0/in/other=wicd.conf.in 2011-08-11 16:57:20.818332542 -0400
@@ -7,41 +7,24 @@
<allow own="org.wicd.daemon"/>
<allow send_destination="org.wicd.daemon"/>
<allow send_interface="org.wicd.daemon"/>
- <allow send_destination="org.wicd.daemon.wireless"/>
- <allow send_interface="org.wicd.daemon.wireless"/>
- <allow send_destination="org.wicd.daemon.wired"/>
- <allow send_interface="org.wicd.daemon.wired"/>
+ <allow send_destination="org.wicd.daemon.wireless"/>
+ <allow send_interface="org.wicd.daemon.wireless"/>
+ <allow send_destination="org.wicd.daemon.wired"/>
+ <allow send_interface="org.wicd.daemon.wired"/>
</policy>
<policy context="default">
<deny own="org.wicd.daemon"/>
</policy>
- <!-- This Unix group will have permission to use Wicd's gui -->
- <policy group="%WICDGROUP%">
- <allow send_destination="org.wicd.daemon"/>
- <allow send_interface="org.wicd.daemon"/>
- <allow send_interface="org.freedesktop.DBus.Introspectable"/>
- <!-- The Introspectable allow shouldn't be needed here, but
- it seems that a few distributions aren't yet allowing
- it in their hal configs, and we need it here, so... -->
- </policy>
-
- <!-- Comment the block below if you do not want all users logged in
- locally to have permission to use wicd-client. This ignores the
- group based permission model defined above for the "%WICDGROUP%"
- group. Note that this only applies if you are using ConsoleKit -
- if you do not have ConsoleKit installed and in use, then this
- block makes no difference either way. -->
-
<policy at_console="true">
<allow send_destination="org.wicd.daemon"/>
<allow send_interface="org.wicd.daemon"/>
- <allow send_destination="org.wicd.daemon.wireless"/>
- <allow send_interface="org.wicd.daemon.wireless"/>
- <allow send_destination="org.wicd.daemon.wired"/>
- <allow send_interface="org.wicd.daemon.wired"/>
- <allow send_interface="org.freedesktop.DBus.Introspectable"/>
+ <allow send_destination="org.wicd.daemon.wireless"/>
+ <allow send_interface="org.wicd.daemon.wireless"/>
+ <allow send_destination="org.wicd.daemon.wired"/>
+ <allow send_interface="org.wicd.daemon.wired"/>
+ <allow send_interface="org.freedesktop.DBus.Introspectable"/>
</policy>
</busconfig>

View file

@ -0,0 +1,27 @@
diff -up wicd-1.7.0/curses/wicd-curses.py.orig wicd-1.7.0/curses/wicd-curses.py
--- wicd-1.7.0/curses/wicd-curses.py.orig 2011-08-11 17:01:29.969340068 -0400
+++ wicd-1.7.0/curses/wicd-curses.py 2011-08-11 17:01:30.159340092 -0400
@@ -1033,7 +1033,7 @@ if __name__ == '__main__':
parser = OptionParser(version="wicd-curses-%s (using wicd %s)" % (CURSES_REV,daemon.Hello()))
except Exception, e:
if "DBus.Error.AccessDenied" in e.get_dbus_name():
- print language['access_denied_wc'].replace('$A','\033[1;34m'+wpath.wicd_group+'\033[0m')
+ print language['access_denied_wc']
sys.exit(1)
else:
raise
diff -up wicd-1.7.0/wicd/translations.py.orig wicd-1.7.0/wicd/translations.py
--- wicd-1.7.0/wicd/translations.py.orig 2010-01-14 23:49:23.000000000 -0500
+++ wicd-1.7.0/wicd/translations.py 2011-08-11 17:01:30.179340042 -0400
@@ -214,9 +214,9 @@ language['connection_established'] = _('
language['disconnected'] = _('''Disconnected''')
language['establishing_connection'] = _('''Establishing connection...''')
language['association_failed'] = _('''Connection failed: Could not contact the wireless access point.''')
-language['access_denied'] = _('''Unable to contact the Wicd daemon due to an access denied error from DBus. Please check that your user is in the $A group.''')
+language['access_denied'] = _('''Unable to contact the Wicd daemon due to an access denied error from DBus. Please check your D-Bus policy configuration.''')
language['disconnecting_active'] = _('''Disconnecting active connections...''')
-language['access_denied_wc'] = _('''ERROR: wicd-curses was denied access to the wicd daemon: please check that your user is in the "$A" group.''')
+language['access_denied_wc'] = _('''ERROR: wicd-curses was denied access to the wicd daemon: please check your D-Bus policy configuration.''')
language['post_disconnect_script'] = _('''Run post-disconnect script''')
language['resume_script'] = _('''Resume script''')
language['suspend_script'] = _('''Suspend script''')

View file

@ -0,0 +1,13 @@
diff -up wicd-1.7.0/cli/wicd-cli.py.orig wicd-1.7.0/cli/wicd-cli.py
--- wicd-1.7.0/cli/wicd-cli.py.orig 2011-08-19 15:24:57.413159478 -0400
+++ wicd-1.7.0/cli/wicd-cli.py 2011-08-19 15:31:49.790055545 -0400
@@ -195,6 +195,9 @@ if options.connect:
check = lambda: wired.CheckIfWiredConnecting()
message = lambda: wired.CheckWiredConnectingMessage()
+ else:
+ check = lambda: False
+ message = lambda: False
# update user on what the daemon is doing
last = None

View file

@ -0,0 +1,11 @@
diff -up wicd-1.7.0/gtk/gui.py.orig wicd-1.7.0/gtk/gui.py
--- wicd-1.7.0/gtk/gui.py.orig 2011-08-19 14:53:37.667180427 -0400
+++ wicd-1.7.0/gtk/gui.py 2011-08-19 14:55:43.657056952 -0400
@@ -220,6 +220,7 @@ class appGui(object):
self.refreshing = False
self.prev_state = None
self.update_cb = None
+ self._wired_showing = False
self.network_list.set_sensitive(False)
label = gtk.Label("%s..." % language['scanning'])
self.network_list.pack_start(label)

View file

@ -1,11 +1,15 @@
[Unit]
Description=Wicd a wireless and wired network manager for Linux
After=syslog.target
Wants=network.target
Before=network.target
Conflicts=NetworkManager.service
[Service]
Type=forking
ExecStart=/usr/sbin/wicd
ExecStop=/usr/sbin/wicd -k
Type=dbus
BusName=org.wicd.daemon
ExecStart=/usr/sbin/wicd --no-daemon
[Install]
WantedBy=multi-user.target
Alias=dbus-org.wicd.daemon.service

View file

@ -9,7 +9,7 @@
Name: wicd
Version: 1.7.0
Release: 8%{?dist}
Release: 13%{?dist}
Summary: Wireless and wired network connection manager
Group: System Environment/Base
@ -18,8 +18,18 @@ URL: http://wicd.sourceforge.net/
Source0: http://downloads.sourceforge.net/%{name}/%{name}-%{version}.tar.bz2
Source1: wicd.logrotate
Source2: wicd.service
Source3: org.wicd.daemon.service
Patch0: wicd-1.7.0-remove-WHEREAREMYFILES.patch
Patch1: wicd-1.7.0-deepcopy.patch
Patch2: wicd-1.7.0-dbus-failure.patch
Patch3: wicd-1.7.0-error-messages.patch
Patch4: wicd-1.7.0-dbus-policy.patch
Patch5: wicd-1.7.0-wired_showing.patch
Patch6: wicd-1.7.0-initialize-check-and-message.patch
Patch7: wicd-1.7.0-CVE-2012-0813.patch
Patch8: wicd-1.7.0-CVE-2012-2095.patch
Patch9: wicd-1.7.0-bz740256.patch
BuildRoot: %{_tmppath}/%{name}-%{version}-%{release}-root-%(id -u -n)
BuildRequires: python2-devel
@ -90,6 +100,34 @@ Client program for wicd that uses a GTK+ interface.
# Use cPickle instead of deepcopy in configmanager.py
%patch1 -p1
# Handle D-Bus connection failures a little better
%patch2 -p1
# Direct users to D-Bus policy configuration on connection failure
%patch3 -p1
# Allow users at the console to control wicd
%patch4 -p1
# Initialize appGui._wired_showing in __init__
%patch5 -p1
# Make sure check and message are always a lambda
%patch6 -p1
# Fix CVE-2012-0813
# Patch based on upstream:
# http://bazaar.launchpad.net/~wicd-devel/wicd/experimental/revision/682
%patch7 -p1
# Fix CVE-2012-2095
# Patch based on upstream:
# http://bazaar.launchpad.net/~wicd-devel/wicd/experimental/revision/751
%patch8 -p1
# Fix BZ #740256
%patch9 -p1
%build
# NOTE: --etc is where dhclient.conf.template goes
%{__python} setup.py configure \
@ -136,6 +174,9 @@ install -m 0644 %{SOURCE1} %{buildroot}%{_sysconfdir}/logrotate.d/wicd
mkdir -p %{buildroot}%{_systemd_unitdir}
install -m 0644 %{SOURCE2} %{buildroot}%{_systemd_unitdir}/wicd.service
mkdir -p %{buildroot}%{_datadir}/dbus-1/system-services
install -m 0644 %{SOURCE3} %{buildroot}%{_datadir}/dbus-1/system-services/org.wicd.daemon.service
desktop-file-install \
--remove-category="Application" \
--delete-original \
@ -190,11 +231,11 @@ gtk-update-icon-cache %{_datadir}/icons/hicolor &>/dev/null || :
%files
%defattr(-,root,root,-)
%doc AUTHORS CHANGES LICENSE NEWS README other/WHEREAREMYFILES
%{_libdir}/pm-utils/sleep.d/91wicd
%files common -f %{name}.lang
%defattr(-,root,root,-)
%doc AUTHORS CHANGES LICENSE NEWS README other/WHEREAREMYFILES
%dir %{python_sitelib}/wicd
%dir %{_sysconfdir}/wicd
%dir %{_sysconfdir}/wicd/encryption
@ -228,6 +269,7 @@ gtk-update-icon-cache %{_datadir}/icons/hicolor &>/dev/null || :
%{_bindir}/wicd-client
%{_sbindir}/wicd
%{_datadir}/applications/wicd.desktop
%{_datadir}/dbus-1/system-services/org.wicd.daemon.service
%{_datadir}/man/man1/wicd-client.1*
%{_datadir}/man/man5/wicd-manager-settings.conf.5*
%{_datadir}/man/man5/wicd-wired-settings.conf.5*
@ -270,6 +312,25 @@ gtk-update-icon-cache %{_datadir}/icons/hicolor &>/dev/null || :
%{_datadir}/icons/hicolor/scalable/apps/wicd-gtk.svg
%changelog
* Wed Apr 25 2012 David Cantrell <dcantrell@redhat.com> - 1.7.0-13
- Fix 'guiutil.py:147:set_text:TypeError: Gtk.Entry.set_text()
argument 1 must be string, not dbus.Boolean' (#740256)
* Fri Apr 13 2012 David Cantrell <dcantrell@redhat.com> - 1.7.0-12
- Fix CVE-2012-2095 (#811763)
* Fri Jan 27 2012 David Cantrell <dcantrell@redhat.com> - 1.7.0-11
- Fix CVE-2012-0813 (#785147)
* Fri Aug 19 2011 David Cantrell <dcantrell@redhat.com> - 1.7.0-10
- Initialize appGui._wired_showing in __init__ (#723553)
- Make sure check and message in wicd-cli are a lambda (#712435)
* Thu Aug 11 2011 David Cantrell <dcantrell@redhat.com> - 1.7.0-9
- Correct systemd unit file for wicd, add D-Bus service file (#699116)
- Move docs to the wicd-common subpackage
- Correct /etc/dbus-1/system.d/wicd.conf (#699116)
* Mon May 09 2011 Bill Nottingham <notting@redhat.com> - 1.7.0-8
- fix systemd scriptlets for upgrade