diff --git a/.gitignore b/.gitignore index 1049786..e8f33e0 100644 --- a/.gitignore +++ b/.gitignore @@ -1 +1 @@ -xml-security-c-1.5.1.tar.gz +xml-security-c-*.tar.gz diff --git a/sources b/sources index 62c55a2..45ff318 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -2c47c4ec12e8d6abe967aa5e5e99000c xml-security-c-1.5.1.tar.gz +SHA512 (xml-security-c-2.0.4.tar.gz) = c2a83b0415ec0a83c932bffb709beac5763e20397f3ec4dfb350a3190de878a860b75482c095b9ac1cae3bbfbcc968b2a26ea912816b0dd4456c7ea0e07f3060 diff --git a/xml-security-c-1.5.1-CVE-2011-2516.patch b/xml-security-c-1.5.1-CVE-2011-2516.patch deleted file mode 100644 index 7ba5d9e..0000000 --- a/xml-security-c-1.5.1-CVE-2011-2516.patch +++ /dev/null @@ -1,192 +0,0 @@ -diff -up xml-security-c-1.5.1/src/dsig/DSIGAlgorithmHandlerDefault.cpp.orig xml-security-c-1.5.1/src/dsig/DSIGAlgorithmHandlerDefault.cpp ---- xml-security-c-1.5.1/src/dsig/DSIGAlgorithmHandlerDefault.cpp.orig 2009-07-21 17:48:45.000000000 +0300 -+++ xml-security-c-1.5.1/src/dsig/DSIGAlgorithmHandlerDefault.cpp 2011-07-08 10:49:00.000000000 +0300 -@@ -42,6 +42,7 @@ - - XERCES_CPP_NAMESPACE_USE - -+#define MAXB64BUFSIZE 2048 - - // -------------------------------------------------------------------------------- - // Some useful utility functions -@@ -53,10 +54,10 @@ bool compareBase64StringToRaw(const char - unsigned int rawLen, - unsigned int maxCompare = 0) { - // Decode a base64 buffer and then compare the result to a raw buffer -- // Compare at most maxCompare bits (if maxComare > 0) -+ // Compare at most maxCompare bits (if maxCompare > 0) - // Note - whilst the other parameters are bytes, maxCompare is bits - -- unsigned char outputStr[1024]; -+ unsigned char outputStr[MAXB64BUFSIZE]; - unsigned int outputLen = 0; - - XSECCryptoBase64 * b64 = XSECPlatformUtils::g_cryptoProvider->base64(); -@@ -71,8 +72,8 @@ bool compareBase64StringToRaw(const char - Janitor j_b64(b64); - - b64->decodeInit(); -- outputLen = b64->decode((unsigned char *) b64Str, (unsigned int) strlen((char *) b64Str), outputStr, 1024); -- outputLen += b64->decodeFinish(&outputStr[outputLen], 1024 - outputLen); -+ outputLen = b64->decode((unsigned char *) b64Str, (unsigned int) strlen((char *) b64Str), outputStr, MAXB64BUFSIZE); -+ outputLen += b64->decodeFinish(&outputStr[outputLen], MAXB64BUFSIZE - outputLen); - - // Compare - -@@ -144,7 +145,7 @@ void convertRawToBase64String(safeBuffer - // Translate the rawbuffer (at most maxBits or rawLen - whichever is smaller) - // to a base64 string - -- unsigned char b64Str[1024]; -+ unsigned char b64Str[MAXB64BUFSIZE]; - unsigned int outputLen = 0; - - XSECCryptoBase64 * b64 = XSECPlatformUtils::g_cryptoProvider->base64(); -@@ -175,8 +176,8 @@ void convertRawToBase64String(safeBuffer - size = rawLen; - - b64->encodeInit(); -- outputLen = b64->encode((unsigned char *) raw, rawLen, b64Str, 1024); -- outputLen += b64->encodeFinish(&b64Str[outputLen], 1024 - outputLen); -+ outputLen = b64->encode((unsigned char *) raw, rawLen, b64Str, MAXB64BUFSIZE - 1); -+ outputLen += b64->encodeFinish(&b64Str[outputLen], MAXB64BUFSIZE - outputLen - 1); - b64Str[outputLen] = '\0'; - - // Copy out -@@ -380,7 +381,10 @@ unsigned int DSIGAlgorithmHandlerDefault - - // Now check the calculated hash - -- char b64Buf[1024]; -+ // For now, use a fixed length buffer, but expand it, -+ // and detect if the signature size exceeds what we can -+ // handle. -+ char b64Buf[MAXB64BUFSIZE]; - unsigned int b64Len; - safeBuffer b64SB; - -@@ -400,7 +404,7 @@ unsigned int DSIGAlgorithmHandlerDefault - hash, - hashLen, - (char *) b64Buf, -- 1024); -+ MAXB64BUFSIZE); - - if (b64Len <= 0) { - -@@ -408,6 +412,12 @@ unsigned int DSIGAlgorithmHandlerDefault - "Unknown error occured during a DSA Signing operation"); - - } -+ else if (b64Len >= MAXB64BUFSIZE) { -+ -+ throw XSECException(XSECException::AlgorithmMapperError, -+ "DSA Signing operation exceeded size of buffer"); -+ -+ } - - if (b64Buf[b64Len-1] == '\n') - b64Buf[b64Len-1] = '\0'; -@@ -430,7 +440,7 @@ unsigned int DSIGAlgorithmHandlerDefault - hash, - hashLen, - (char *) b64Buf, -- 1024, -+ MAXB64BUFSIZE, - hm); - - if (b64Len <= 0) { -@@ -439,6 +449,12 @@ unsigned int DSIGAlgorithmHandlerDefault - "Unknown error occured during a RSA Signing operation"); - - } -+ else if (b64Len >= MAXB64BUFSIZE) { -+ -+ throw XSECException(XSECException::AlgorithmMapperError, -+ "RSA Signing operation exceeded size of buffer"); -+ -+ } - - // Clean up some "funnies" and make sure the string is NULL terminated - -@@ -471,7 +487,7 @@ unsigned int DSIGAlgorithmHandlerDefault - hashLen, - outputLength); - -- strncpy(b64Buf, (char *) b64SB.rawBuffer(), 1024); -+ strncpy(b64Buf, (char *) b64SB.rawBuffer(), MAXB64BUFSIZE); - break; - - default : -diff -up xml-security-c-1.5.1/src/enc/OpenSSL/OpenSSLCryptoKeyDSA.cpp.orig xml-security-c-1.5.1/src/enc/OpenSSL/OpenSSLCryptoKeyDSA.cpp ---- xml-security-c-1.5.1/src/enc/OpenSSL/OpenSSLCryptoKeyDSA.cpp.orig 2008-12-08 20:52:47.000000000 +0200 -+++ xml-security-c-1.5.1/src/enc/OpenSSL/OpenSSLCryptoKeyDSA.cpp 2011-07-08 11:21:12.000000000 +0300 -@@ -33,6 +33,10 @@ - #include - #include - -+#include -+ -+XSEC_USING_XERCES(ArrayJanitor); -+ - #include - - OpenSSLCryptoKeyDSA::OpenSSLCryptoKeyDSA() : mp_dsaKey(NULL) { -@@ -157,8 +161,9 @@ bool OpenSSLCryptoKeyDSA::verifyBase64Si - "OpenSSL:DSA - Attempt to validate signature with empty key"); - } - -- unsigned char sigVal[512]; - int sigValLen; -+ unsigned char* sigVal = new unsigned char[sigLen + 1]; -+ ArrayJanitor j_sigVal(sigVal); - int err; - - EVP_ENCODE_CTX m_dctx; -@@ -271,10 +276,10 @@ unsigned int OpenSSLCryptoKeyDSA::signBa - - // Now turn the signature into a base64 string - -- unsigned char rawSigBuf[256]; -- unsigned int rawLen; -- -- rawLen = BN_bn2bin(dsa_sig->r, rawSigBuf); -+ unsigned char* rawSigBuf = new unsigned char[(BN_num_bits(dsa_sig->r) + BN_num_bits(dsa_sig->s)) / 8]; -+ ArrayJanitor j_sigbuf(rawSigBuf); -+ -+ unsigned int rawLen = BN_bn2bin(dsa_sig->r, rawSigBuf); - - if (rawLen <= 0) { - -diff -up xml-security-c-1.5.1/src/enc/OpenSSL/OpenSSLCryptoKeyRSA.cpp.orig xml-security-c-1.5.1/src/enc/OpenSSL/OpenSSLCryptoKeyRSA.cpp ---- xml-security-c-1.5.1/src/enc/OpenSSL/OpenSSLCryptoKeyRSA.cpp.orig 2008-12-08 20:52:47.000000000 +0200 -+++ xml-security-c-1.5.1/src/enc/OpenSSL/OpenSSLCryptoKeyRSA.cpp 2011-07-08 10:48:58.000000000 +0300 -@@ -186,21 +186,20 @@ bool OpenSSLCryptoKeyRSA::verifySHA1PKCS - "OpenSSL:RSA - Attempt to validate signature with empty key"); - } - -- unsigned char sigVal[1024]; -- int sigValLen; -- -- EVP_ENCODE_CTX m_dctx; -- int rc; -- -- char * cleanedBase64Signature; -+ char* cleanedBase64Signature; - unsigned int cleanedBase64SignatureLen = 0; - - cleanedBase64Signature = - XSECCryptoBase64::cleanBuffer(base64Signature, sigLen, cleanedBase64SignatureLen); - ArrayJanitor j_cleanedBase64Signature(cleanedBase64Signature); - -+ int sigValLen; -+ unsigned char* sigVal = new unsigned char[sigLen + 1]; -+ ArrayJanitor j_sigVal(sigVal); -+ -+ EVP_ENCODE_CTX m_dctx; - EVP_DecodeInit(&m_dctx); -- rc = EVP_DecodeUpdate(&m_dctx, -+ int rc = EVP_DecodeUpdate(&m_dctx, - sigVal, - &sigValLen, - (unsigned char *) cleanedBase64Signature, diff --git a/xml-security-c.spec b/xml-security-c.spec index a3d298d..650efee 100644 --- a/xml-security-c.spec +++ b/xml-security-c.spec @@ -1,17 +1,20 @@ -Name: xml-security-c -Version: 1.5.1 -Release: 4%{?dist} -Summary: C++ Implementation of W3C security standards for XML - -Group: System Environment/Libraries -License: ASL 2.0 -URL: http://santuario.apache.org/c/ -Source: http://santuario.apache.org/dist/c-library/%{name}-%{version}.tar.gz -Patch0: xml-security-c-1.5.1-CVE-2011-2516.patch -BuildRoot: %{_tmppath}/%{name}-%{version}-%{release}-root-%(%{__id_u} -n) - -BuildRequires: xerces-c-devel xalan-c-devel openssl-devel -BuildRequires: pkgconfig +Summary: C++ Implementation of W3C security standards for XML +Name: xml-security-c +Version: 2.0.4 +Release: 11%{?dist} +# Automatically converted from old format: ASL 2.0 - review is highly recommended. +License: Apache-2.0 +URL: http://santuario.apache.org/cindex.html +Source0: https://www.apache.org/dist/santuario/c-library/%{name}-%{version}.tar.gz +BuildRequires: make +BuildRequires: autoconf +BuildRequires: automake +BuildRequires: gcc-c++ +BuildRequires: libtool +BuildRequires: openssl-devel +BuildRequires: pkgconfig +BuildRequires: xalan-c-devel +BuildRequires: xerces-c-devel %description The xml-security-c library is a C++ implementation of the XML Digital Signature @@ -19,72 +22,212 @@ specification. The library makes use of the Apache XML project's Xerces-C XML Parser and Xalan-C XSLT processor. The latter is used for processing XPath and XSLT transforms. - -%package devel -Summary: Development files for xml-security-c -Group: Development/Libraries -Requires: %{name} = %{version}-%{release} -Requires: xerces-c-devel xalan-c-devel openssl-devel -# There are a number of headers that can use NSS if HAVE_NSS is set to 1 -# Current build does not set it (configure does not even check for NSS) -# so we do not include this dependency for now. -# Requires: nss-devel +%package devel +Summary: Development files for xml-security-c +Requires: %{name}%{?_isa} = %{version}-%{release} +Requires: libstdc++-devel +Requires: openssl-devel +Requires: xalan-c-devel +Requires: xerces-c-devel %description devel This package provides development files for xml-security-c, a C++ library for XML Digital Signatures. - %prep -%setup -q -%patch0 -p1 -# Remove bogus "-O2" from CXXFLAGS to avoid overriding RPM_OPT_FLAGS. -sed -i -e 's/-O2 -DNDEBUG/-DNDEBUG/g' configure +%autosetup -p1 %build -%configure --disable-static -make %{?_smp_mflags} - -%check -# Verify that what was compiled actually works. -./bin/xtest +autoreconf -fiv +%configure \ + --disable-debug \ + --disable-static \ + --without-nss \ + --with-openssl \ + --with-xalan \ + %{nil} +%make_build %install -rm -rf $RPM_BUILD_ROOT -make install DESTDIR=$RPM_BUILD_ROOT CPPROG="cp -p" - -# We do not ship .la files. -rm -f $RPM_BUILD_ROOT%{_libdir}/*.la - -# Do not ship library test utilities. These are only needed for -# xml-security-c developers and they should have the whole source anyway. -rm -rf $RPM_BUILD_ROOT%{_bindir} - -%post -p /sbin/ldconfig - -%postun -p /sbin/ldconfig - - -%clean -rm -rf $RPM_BUILD_ROOT +%make_install +%check +./xsec/xsec-xtest %files -%defattr(-,root,root,-) -%{_libdir}/libxml-security-c.so.* - +%{_libdir}/libxml-security-c.so.20{,.*} %files devel -%defattr(-,root,root,-) +%license LICENSE.txt +%doc CHANGELOG.txt NOTICE.txt %{_includedir}/xsec %{_libdir}/libxml-security-c.so - -# Upstream does not provide any docs (yet!) -# %doc CHANGELOG.txt +%{_libdir}/pkgconfig/xml-security-c.pc +%exclude %{_bindir}/* %changelog -* Fri Jul 08 2011 Antti Andreimann - 1.5.1-4 -- Backported a patch to fix CVE-2011-2516 (#719698) +* Fri Jul 17 2026 Fedora Release Engineering - 2.0.4-11 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild + +* Fri Jun 12 2026 Yaakov Selkowitz - 2.0.4-10 +- Rebuilt for openssl 4.0 + +* Sat Jan 17 2026 Fedora Release Engineering - 2.0.4-9 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild + +* Fri Jul 25 2025 Fedora Release Engineering - 2.0.4-8 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild + +* Sun Jan 19 2025 Fedora Release Engineering - 2.0.4-7 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild + +* Fri Oct 18 2024 Pete Walter - 2.0.4-6 +- Rebuild for xerces-c 3.3 + +* Wed Jul 24 2024 Miroslav Suchý - 2.0.4-5 +- convert license to SPDX + +* Sat Jul 20 2024 Fedora Release Engineering - 2.0.4-4 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild + +* Sat Jan 27 2024 Fedora Release Engineering - 2.0.4-3 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild + +* Sat Jul 22 2023 Fedora Release Engineering - 2.0.4-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild + +* Thu Jan 26 2023 Yaakov Selkowitz - 2.0.4-1 +- Update to 2.0.4 + +* Sat Jan 21 2023 Fedora Release Engineering - 2.0.2-13 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild + +* Sat Jul 23 2022 Fedora Release Engineering - 2.0.2-12 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild + +* Sat Jan 22 2022 Fedora Release Engineering - 2.0.2-11 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild + +* Tue Sep 14 2021 Sahana Prasad - 2.0.2-10 +- Rebuilt with OpenSSL 3.0.0 + +* Fri Jul 23 2021 Fedora Release Engineering - 2.0.2-9 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild + +* Thu Jan 28 2021 Fedora Release Engineering - 2.0.2-8 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild + +* Mon Dec 7 18:18:40 EST 2020 Benjamin A. Beasley - 2.0.2-7 +- Work around removed XALAN_USING_XALAN compatibility macro in xalan-c 1.12 + +* Mon Dec 7 19:42:40 CET 2020 Zbigniew Jędrzejewski-Szmek - 2.0.2-6 +- Rebuilt for xalan-c 1.12.0 + +* Wed Jul 29 2020 Fedora Release Engineering - 2.0.2-5 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild + +* Fri Jan 31 2020 Fedora Release Engineering - 2.0.2-4 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild + +* Sat Jul 27 2019 Fedora Release Engineering - 2.0.2-3 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild + +* Sun Feb 03 2019 Fedora Release Engineering - 2.0.2-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild + +* Wed Jan 30 2019 Tomasz Kłoczko - 2.0.2-1 +- use %%exclude does not cause include those files into package %%files (revert last commit) +- format text to 80 col +- use https:// in Source0 url +- improved BuildRequires + +* Fri Nov 16 2018 Pete Walter - 2.0.2-1 +- Update to 2.0.2 +- Remove explicit attr modes + +* Wed Jul 18 2018 Tomasz Kłoczko - 1.7.3-5 +- added /usr/bin/c++ to BuildRequires + +* Sat Jul 14 2018 Fedora Release Engineering - 1.7.3-5 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild + +* Fri Feb 09 2018 Fedora Release Engineering - 1.7.3-4 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild + +* Wed Jan 31 2018 Tomasz Kłoczko - 1.7.3-3 +- remove ldconfig scriptlets +- more cleanups + +* Wed Aug 30 2017 Tomasz Kłoczko - 1.7.3-2 +- added patch which allows build xml-security-c against openssl 1.1 +- added ac_fixes patch: do not use sed to remove hardcoded compile + options. Use patch because you will never know is such correction + still needed (added autoconf, automake and libtool to BuildRequires) +- added libstdc++-devel to BuildReqires and to devel Requires +- add explicit all %%configure options to prevent build by mistake package + against nss and force use openssl +- added --disable-debug to %%configure options +- added use %%autosetup in %%prep +- do not waste IOs on remove not packaged files and add them %%files + with %%exclude +- indent and clean spec (move patch comments to the patch) + +* Tue Aug 29 2017 Kalev Lember - 1.7.3-1 +- Update to 1.7.3 + +* Thu Aug 03 2017 Fedora Release Engineering - 1.6.1-15 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Binutils_Mass_Rebuild + +* Thu Jul 27 2017 Fedora Release Engineering - 1.6.1-14 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild + +* Sat Feb 11 2017 Fedora Release Engineering - 1.6.1-13 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild + +* Fri Feb 05 2016 Fedora Release Engineering - 1.6.1-12 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild + +* Tue Feb 02 2016 Jonathan Wakely - 1.6.1-11 +- Patched for C++11 compatibility + +* Fri Jun 19 2015 Fedora Release Engineering - 1.6.1-10 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild + +* Sat May 02 2015 Kalev Lember - 1.6.1-9 +- Rebuilt for GCC 5 C++11 ABI change + +* Mon Aug 18 2014 Fedora Release Engineering - 1.6.1-8 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild + +* Sun Jun 08 2014 Fedora Release Engineering - 1.6.1-7 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild + +* Fri Oct 11 2013 Antti Andreimann - 1.6.1-6 +- Rebuild for xalan-c 110 to 111 .so bump + +* Sun Aug 04 2013 Fedora Release Engineering - 1.6.1-5 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild + +* Fri Feb 15 2013 Fedora Release Engineering - 1.6.1-4 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild + +* Sun Jul 22 2012 Fedora Release Engineering - 1.6.1-3 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild + +* Sat Jan 14 2012 Fedora Release Engineering - 1.6.1-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild + +* Thu Jul 7 2011 Steve Traylen 1.6.1-1 +- New upstream release, Correct source URL. + +* Wed Mar 16 2011 Antti Andreimann 1.6.0-1 +- New upstream release + +* Thu Mar 10 2011 Kalev Lember - 1.5.1-5 +- Rebuilt with xerces-c 3.1 + +* Mon Feb 07 2011 Fedora Release Engineering - 1.5.1-4 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild * Sat Feb 06 2010 steve.traylen@cern.ch - 1.5.1-3 - Rebuild for xerces 2 to 3 .so bump @@ -103,7 +246,7 @@ rm -rf $RPM_BUILD_ROOT - New upstream release * Tue Apr 28 2009 Antti Andreimann - 1.4.0-2 -- Execute sed magic against configure instead of configure.ac to +- Execute sed magic against configure instead of configure.ac to avoid calling autotools - Removed build dependency on autotools. - Do not ship test binaries (not needed for end-users)