diff options
author | Zhixiong Chi <zhixiong.chi@windriver.com> | 2016-09-22 15:54:20 +0800 |
---|---|---|
committer | Richard Purdie <richard.purdie@linuxfoundation.org> | 2016-09-27 09:05:56 +0100 |
commit | 45bc60015cd465b336e80cac08f16ffb37b53f3a (patch) | |
tree | adf530ad36e20e50ab39a567f31b73652f13d03d /meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/0002-Remove-newlines-from-wpa_supplicant-config-network-o.patch | |
parent | e6c1d03d3d161cbbda254a5dae7008ff7e37d874 (diff) | |
download | poky-45bc60015cd465b336e80cac08f16ffb37b53f3a.tar.gz |
wpa_supplicant: Security Advisory-CVE-2016-4476
Add CVE-2016-4476 patch for avoiding \n and \r characters in passphrase
parameters, which allows remote attackers to cause a denial of service
(daemon outage) via a crafted WPS operation.
Patches came from http://w1.fi/security/2016-1/
(From OE-Core rev: ed610b68f7e19644c89d7131e34c990a02403c62)
(From OE-Core rev: 6ef620c717c43a29f51ccd298c84070552bdfe52)
Signed-off-by: Zhixiong Chi <zhixiong.chi@windriver.com>
Signed-off-by: Ross Burton <ross.burton@intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Signed-off-by: Armin Kuster <akuster@mvista.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Diffstat (limited to 'meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/0002-Remove-newlines-from-wpa_supplicant-config-network-o.patch')
-rw-r--r-- | meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/0002-Remove-newlines-from-wpa_supplicant-config-network-o.patch | 86 |
1 files changed, 86 insertions, 0 deletions
diff --git a/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/0002-Remove-newlines-from-wpa_supplicant-config-network-o.patch b/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/0002-Remove-newlines-from-wpa_supplicant-config-network-o.patch new file mode 100644 index 0000000000..cc7b01ad57 --- /dev/null +++ b/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/0002-Remove-newlines-from-wpa_supplicant-config-network-o.patch | |||
@@ -0,0 +1,86 @@ | |||
1 | From 0fe5a234240a108b294a87174ad197f6b5cb38e9 Mon Sep 17 00:00:00 2001 | ||
2 | From: Paul Stewart <pstew@google.com> | ||
3 | Date: Thu, 3 Mar 2016 15:40:19 -0800 | ||
4 | Subject: [PATCH 2/2] Remove newlines from wpa_supplicant config network | ||
5 | output | ||
6 | |||
7 | Spurious newlines output while writing the config file can corrupt the | ||
8 | wpa_supplicant configuration. Avoid writing these for the network block | ||
9 | parameters. This is a generic filter that cover cases that may not have | ||
10 | been explicitly addressed with a more specific commit to avoid control | ||
11 | characters in the psk parameter. | ||
12 | |||
13 | Upstream-Status: Backport | ||
14 | |||
15 | CVE: CVE-2016-4476 | ||
16 | |||
17 | Signed-off-by: Paul Stewart <pstew@google.com> | ||
18 | Signed-off-by: Zhixiong Chi <Zhixiong.Chi.wrs.com> | ||
19 | --- | ||
20 | src/utils/common.c | 11 +++++++++++ | ||
21 | src/utils/common.h | 1 + | ||
22 | wpa_supplicant/config.c | 15 +++++++++++++-- | ||
23 | 3 files changed, 25 insertions(+), 2 deletions(-) | ||
24 | |||
25 | diff --git a/src/utils/common.c b/src/utils/common.c | ||
26 | index 27b7c02..9856463 100644 | ||
27 | --- a/src/utils/common.c | ||
28 | +++ b/src/utils/common.c | ||
29 | @@ -709,6 +709,17 @@ int has_ctrl_char(const u8 *data, size_t len) | ||
30 | } | ||
31 | |||
32 | |||
33 | +int has_newline(const char *str) | ||
34 | +{ | ||
35 | + while (*str) { | ||
36 | + if (*str == '\n' || *str == '\r') | ||
37 | + return 1; | ||
38 | + str++; | ||
39 | + } | ||
40 | + return 0; | ||
41 | +} | ||
42 | + | ||
43 | + | ||
44 | size_t merge_byte_arrays(u8 *res, size_t res_len, | ||
45 | const u8 *src1, size_t src1_len, | ||
46 | const u8 *src2, size_t src2_len) | ||
47 | diff --git a/src/utils/common.h b/src/utils/common.h | ||
48 | index a972240..d19927b 100644 | ||
49 | --- a/src/utils/common.h | ||
50 | +++ b/src/utils/common.h | ||
51 | @@ -489,6 +489,7 @@ const char * wpa_ssid_txt(const u8 *ssid, size_t ssid_len); | ||
52 | char * wpa_config_parse_string(const char *value, size_t *len); | ||
53 | int is_hex(const u8 *data, size_t len); | ||
54 | int has_ctrl_char(const u8 *data, size_t len); | ||
55 | +int has_newline(const char *str); | ||
56 | size_t merge_byte_arrays(u8 *res, size_t res_len, | ||
57 | const u8 *src1, size_t src1_len, | ||
58 | const u8 *src2, size_t src2_len); | ||
59 | diff --git a/wpa_supplicant/config.c b/wpa_supplicant/config.c | ||
60 | index fdd9643..eb97cd5 100644 | ||
61 | --- a/wpa_supplicant/config.c | ||
62 | +++ b/wpa_supplicant/config.c | ||
63 | @@ -2699,8 +2699,19 @@ char * wpa_config_get(struct wpa_ssid *ssid, const char *var) | ||
64 | |||
65 | for (i = 0; i < NUM_SSID_FIELDS; i++) { | ||
66 | const struct parse_data *field = &ssid_fields[i]; | ||
67 | - if (os_strcmp(var, field->name) == 0) | ||
68 | - return field->writer(field, ssid); | ||
69 | + if (os_strcmp(var, field->name) == 0) { | ||
70 | + char *ret = field->writer(field, ssid); | ||
71 | + | ||
72 | + if (ret && has_newline(ret)) { | ||
73 | + wpa_printf(MSG_ERROR, | ||
74 | + "Found newline in value for %s; not returning it", | ||
75 | + var); | ||
76 | + os_free(ret); | ||
77 | + ret = NULL; | ||
78 | + } | ||
79 | + | ||
80 | + return ret; | ||
81 | + } | ||
82 | } | ||
83 | |||
84 | return NULL; | ||
85 | -- | ||
86 | 1.9.1 | ||