diff options
Diffstat (limited to 'meta/recipes-extended/cups/cups')
4 files changed, 35 insertions, 167 deletions
diff --git a/meta/recipes-extended/cups/cups/0002-don-t-try-to-run-generated-binaries.patch b/meta/recipes-extended/cups/cups/0002-don-t-try-to-run-generated-binaries.patch index ea248e4710..2bc26edbfc 100644 --- a/meta/recipes-extended/cups/cups/0002-don-t-try-to-run-generated-binaries.patch +++ b/meta/recipes-extended/cups/cups/0002-don-t-try-to-run-generated-binaries.patch | |||
@@ -26,48 +26,6 @@ index 32e2e0b..f1478d4 100644 | |||
26 | 26 | ||
27 | 27 | ||
28 | # | 28 | # |
29 | @@ -205,9 +205,9 @@ ppdc-static: ppdc.o libcupsppdc.a ../cups/$(LIBCUPSSTATIC) foo.drv foo-fr.po | ||
30 | $(LD_CXX) $(ARCHFLAGS) $(ALL_LDFLAGS) -o ppdc-static ppdc.o libcupsppdc.a \ | ||
31 | $(LINKCUPSSTATIC) | ||
32 | $(CODE_SIGN) -s "$(CODE_SIGN_IDENTITY)" $@ | ||
33 | - echo Testing PPD compiler... | ||
34 | - ./ppdc-static -l en,fr -I ../data foo.drv | ||
35 | - ./ppdc-static -l en,fr -z -I ../data foo.drv | ||
36 | +# echo Testing PPD compiler... | ||
37 | +# ./ppdc-static -l en,fr -I ../data foo.drv | ||
38 | +# ./ppdc-static -l en,fr -z -I ../data foo.drv | ||
39 | |||
40 | |||
41 | # | ||
42 | @@ -235,17 +235,17 @@ ppdi-static: ppdc-static ppdi.o libcupsppdc.a ../cups/$(LIBCUPSSTATIC) | ||
43 | $(LD_CXX) $(ARCHFLAGS) $(ALL_LDFLAGS) -o ppdi-static ppdi.o libcupsppdc.a \ | ||
44 | $(LINKCUPSSTATIC) | ||
45 | $(CODE_SIGN) -s "$(CODE_SIGN_IDENTITY)" $@ | ||
46 | - echo Testing PPD importer... | ||
47 | - $(RM) -r ppd ppd2 sample-import.drv | ||
48 | - ./ppdc-static -l en -I ../data sample.drv | ||
49 | - ./ppdi-static -I ../data -o sample-import.drv ppd/* | ||
50 | - ./ppdc-static -l en -I ../data -d ppd2 sample-import.drv | ||
51 | - if diff -r ppd ppd2 >/dev/null; then \ | ||
52 | - echo PPD import OK; \ | ||
53 | - else \ | ||
54 | - echo PPD import FAILED; \ | ||
55 | - exit 1; \ | ||
56 | - fi | ||
57 | +# echo Testing PPD importer... | ||
58 | +# $(RM) -r ppd ppd2 sample-import.drv | ||
59 | +# ./ppdc-static -l en -I ../data sample.drv | ||
60 | +# ./ppdi-static -I ../data -o sample-import.drv ppd/* | ||
61 | +# ./ppdc-static -l en -I ../data -d ppd2 sample-import.drv | ||
62 | +# if diff -r ppd ppd2 >/dev/null; then \ | ||
63 | +# echo PPD import OK; \ | ||
64 | +# else \ | ||
65 | +# echo PPD import FAILED; \ | ||
66 | +# exit 1; \ | ||
67 | +# fi | ||
68 | |||
69 | |||
70 | # | ||
71 | -- | 29 | -- |
72 | 2.17.1 | 30 | 2.17.1 |
73 | 31 | ||
diff --git a/meta/recipes-extended/cups/cups/0003-cups_1.4.6.bb-Fix-build-on-ppc64.patch b/meta/recipes-extended/cups/cups/0003-cups_1.4.6.bb-Fix-build-on-ppc64.patch deleted file mode 100644 index b48c7a9ad2..0000000000 --- a/meta/recipes-extended/cups/cups/0003-cups_1.4.6.bb-Fix-build-on-ppc64.patch +++ /dev/null | |||
@@ -1,51 +0,0 @@ | |||
1 | From 66c2079ae91389ee0f9d704bf0d2cccd53b2c603 Mon Sep 17 00:00:00 2001 | ||
2 | From: Khem Raj <raj.khem@gmail.com> | ||
3 | Date: Sun, 22 Jul 2012 16:54:17 -0700 | ||
4 | Subject: [PATCH 3/4] cups_1.4.6.bb: Fix build on ppc64 | ||
5 | |||
6 | Make CUPS_SERVERBIN relative to libdir otherwise on 64bit arches | ||
7 | e.g. ppc64 where base libdir is lib64 this does not go well | ||
8 | |||
9 | Signed-off-by: Khem Raj <raj.khem@gmail.com> | ||
10 | Upstream-Status: Inappropriate [OE config specific] | ||
11 | |||
12 | Update on 20190904: | ||
13 | Redefine CUPS_SERVERBIN to "$libexecdir/cups" which solves file confliction | ||
14 | when multilib is enabled. | ||
15 | |||
16 | Signed-off-by: Kai Kang <kai.kang@windriver.com> | ||
17 | |||
18 | --- | ||
19 | config-scripts/cups-directories.m4 | 2 +- | ||
20 | configure | 2 +- | ||
21 | 2 files changed, 2 insertions(+), 2 deletions(-) | ||
22 | |||
23 | diff --git a/config-scripts/cups-directories.m4 b/config-scripts/cups-directories.m4 | ||
24 | index b74083a..9a5abb2 100644 | ||
25 | --- a/config-scripts/cups-directories.m4 | ||
26 | +++ b/config-scripts/cups-directories.m4 | ||
27 | @@ -270,7 +270,7 @@ case "$host_os_name" in | ||
28 | *) | ||
29 | # All others | ||
30 | INSTALL_SYSV="install-sysv" | ||
31 | - CUPS_SERVERBIN="$exec_prefix/lib/cups" | ||
32 | + CUPS_SERVERBIN="$libexecdir/cups" | ||
33 | ;; | ||
34 | esac | ||
35 | |||
36 | diff --git a/configure b/configure | ||
37 | index d3df145..bc68a6c 100755 | ||
38 | --- a/configure | ||
39 | +++ b/configure | ||
40 | @@ -6420,7 +6420,7 @@ case "$host_os_name" in | ||
41 | *) | ||
42 | # All others | ||
43 | INSTALL_SYSV="install-sysv" | ||
44 | - CUPS_SERVERBIN="$exec_prefix/lib/cups" | ||
45 | + CUPS_SERVERBIN="$libexecdir/cups" | ||
46 | ;; | ||
47 | esac | ||
48 | |||
49 | -- | ||
50 | 2.17.1 | ||
51 | |||
diff --git a/meta/recipes-extended/cups/cups/CVE-2020-10001.patch b/meta/recipes-extended/cups/cups/CVE-2020-10001.patch deleted file mode 100644 index 09a0a5765d..0000000000 --- a/meta/recipes-extended/cups/cups/CVE-2020-10001.patch +++ /dev/null | |||
@@ -1,74 +0,0 @@ | |||
1 | From efbea1742bd30f842fbbfb87a473e5c84f4162f9 Mon Sep 17 00:00:00 2001 | ||
2 | From: Michael R Sweet <msweet@msweet.org> | ||
3 | Date: Mon, 1 Feb 2021 15:02:32 -0500 | ||
4 | Subject: [PATCH] Fix a buffer (read) overflow in ippReadIO (CVE-2020-10001) | ||
5 | |||
6 | Upstream-Status: Backport | ||
7 | CVE: CVE-2020-10001 | ||
8 | |||
9 | Reference to upstream patch: | ||
10 | [https://github.com/OpenPrinting/cups/commit/efbea1742bd30f842fbbfb87a473e5c84f4162f9] | ||
11 | |||
12 | [SG: Addapted for version 2.3.3] | ||
13 | Signed-off-by: Stefan Ghinea <stefan.ghinea@windriver.com> | ||
14 | --- | ||
15 | CHANGES.md | 2 ++ | ||
16 | cups/ipp.c | 8 +++++--- | ||
17 | 2 files changed, 7 insertions(+), 3 deletions(-) | ||
18 | |||
19 | diff --git a/CHANGES.md b/CHANGES.md | ||
20 | index df72892..5ca12da 100644 | ||
21 | --- a/CHANGES.md | ||
22 | +++ b/CHANGES.md | ||
23 | @@ -4,6 +4,8 @@ CHANGES - 2.3.3 - 2020-04-24 | ||
24 | Changes in CUPS v2.3.3 | ||
25 | ---------------------- | ||
26 | |||
27 | +- Security: Fixed a buffer (read) overflow in the `ippReadIO` function | ||
28 | + (CVE-2020-10001) | ||
29 | - CVE-2020-3898: The `ppdOpen` function did not handle invalid UI | ||
30 | constraint. `ppdcSource::get_resolution` function did not handle | ||
31 | invalid resolution strings. | ||
32 | diff --git a/cups/ipp.c b/cups/ipp.c | ||
33 | index 3d52934..adbb26f 100644 | ||
34 | --- a/cups/ipp.c | ||
35 | +++ b/cups/ipp.c | ||
36 | @@ -2866,7 +2866,8 @@ ippReadIO(void *src, /* I - Data source */ | ||
37 | unsigned char *buffer, /* Data buffer */ | ||
38 | string[IPP_MAX_TEXT], | ||
39 | /* Small string buffer */ | ||
40 | - *bufptr; /* Pointer into buffer */ | ||
41 | + *bufptr, /* Pointer into buffer */ | ||
42 | + *bufend; /* End of buffer */ | ||
43 | ipp_attribute_t *attr; /* Current attribute */ | ||
44 | ipp_tag_t tag; /* Current tag */ | ||
45 | ipp_tag_t value_tag; /* Current value tag */ | ||
46 | @@ -3441,6 +3442,7 @@ ippReadIO(void *src, /* I - Data source */ | ||
47 | } | ||
48 | |||
49 | bufptr = buffer; | ||
50 | + bufend = buffer + n; | ||
51 | |||
52 | /* | ||
53 | * text-with-language and name-with-language are composite | ||
54 | @@ -3454,7 +3456,7 @@ ippReadIO(void *src, /* I - Data source */ | ||
55 | |||
56 | n = (bufptr[0] << 8) | bufptr[1]; | ||
57 | |||
58 | - if ((bufptr + 2 + n) >= (buffer + IPP_BUF_SIZE) || n >= (int)sizeof(string)) | ||
59 | + if ((bufptr + 2 + n + 2) > bufend || n >= (int)sizeof(string)) | ||
60 | { | ||
61 | _cupsSetError(IPP_STATUS_ERROR_INTERNAL, | ||
62 | _("IPP language length overflows value."), 1); | ||
63 | @@ -3481,7 +3483,7 @@ ippReadIO(void *src, /* I - Data source */ | ||
64 | bufptr += 2 + n; | ||
65 | n = (bufptr[0] << 8) | bufptr[1]; | ||
66 | |||
67 | - if ((bufptr + 2 + n) >= (buffer + IPP_BUF_SIZE)) | ||
68 | + if ((bufptr + 2 + n) > bufend) | ||
69 | { | ||
70 | _cupsSetError(IPP_STATUS_ERROR_INTERNAL, | ||
71 | _("IPP string length overflows value."), 1); | ||
72 | -- | ||
73 | 2.17.1 | ||
74 | |||
diff --git a/meta/recipes-extended/cups/cups/libexecdir.patch b/meta/recipes-extended/cups/cups/libexecdir.patch new file mode 100644 index 0000000000..7ccad94f0f --- /dev/null +++ b/meta/recipes-extended/cups/cups/libexecdir.patch | |||
@@ -0,0 +1,35 @@ | |||
1 | From 1724f7bcdbcfdb445778f8a2e530c5c094c18c10 Mon Sep 17 00:00:00 2001 | ||
2 | From: Ross Burton <ross.burton@arm.com> | ||
3 | Date: Tue, 13 Jul 2021 12:56:30 +0100 | ||
4 | Subject: [PATCH] Use $libexecdir instead of hardcoding $prefix/lib as this | ||
5 | breaks multilib builds. | ||
6 | |||
7 | Upstream-Status: Pending | ||
8 | Signed-off-by: Ross Burton <ross.burton@arm.com> | ||
9 | |||
10 | --- | ||
11 | config-scripts/cups-directories.m4 | 4 ++-- | ||
12 | 1 file changed, 2 insertions(+), 2 deletions(-) | ||
13 | |||
14 | diff --git a/config-scripts/cups-directories.m4 b/config-scripts/cups-directories.m4 | ||
15 | index 2033d47..230166e 100644 | ||
16 | --- a/config-scripts/cups-directories.m4 | ||
17 | +++ b/config-scripts/cups-directories.m4 | ||
18 | @@ -239,7 +239,7 @@ AC_SUBST([CUPS_REQUESTS]) | ||
19 | AS_CASE(["$host_os_name"], [*-gnu], [ | ||
20 | # GNUs | ||
21 | INSTALL_SYSV="install-sysv" | ||
22 | - CUPS_SERVERBIN="$exec_prefix/lib/cups" | ||
23 | + CUPS_SERVERBIN="$libexecdir/cups" | ||
24 | ], [*bsd* | darwin*], [ | ||
25 | # *BSD and Darwin (macOS) | ||
26 | INSTALL_SYSV="" | ||
27 | @@ -247,7 +247,7 @@ AS_CASE(["$host_os_name"], [*-gnu], [ | ||
28 | ], [*], [ | ||
29 | # All others | ||
30 | INSTALL_SYSV="install-sysv" | ||
31 | - CUPS_SERVERBIN="$exec_prefix/lib/cups" | ||
32 | + CUPS_SERVERBIN="$libexecdir/cups" | ||
33 | ]) | ||
34 | |||
35 | AC_DEFINE_UNQUOTED([CUPS_SERVERBIN], ["$CUPS_SERVERBIN"], [Location of server programs.]) | ||