diff options
| author | Hitendra Prajapati <hprajapati@mvista.com> | 2022-07-22 19:05:04 +0530 |
|---|---|---|
| committer | Richard Purdie <richard.purdie@linuxfoundation.org> | 2022-08-08 16:23:33 +0100 |
| commit | d32392304723d9cfd16bde573c311d8ce1238810 (patch) | |
| tree | c07a99c97a181f3a728903ce7e3b1c23918af87c | |
| parent | d695bd0d3dc66f2111a25c6922f617be2d991071 (diff) | |
| download | poky-d32392304723d9cfd16bde573c311d8ce1238810.tar.gz | |
gnupg: CVE-2022-34903 possible signature forgery via injection into the status line
Source: https://git.gnupg.org/cgi-bin/gitweb.cgi?p=gnupg.git
MR: 119424
Type: Security Fix
Disposition: Backport from https://git.gnupg.org/cgi-bin/gitweb.cgi?p=gnupg.git;a=commit;h=34c649b3601383cd11dbc76221747ec16fd68e1b
ChangeID: 97de66d6aa74e12cb1bf82fe85ee62e2530fccf6
Description:
CVE-2022-34903 gnupg: possible signature forgery via injection into the status line.
(From OE-Core rev: 2bf155d59e33972bbb1780e34753199b5a9192a0)
Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
| -rw-r--r-- | meta/recipes-support/gnupg/gnupg/CVE-2022-34903.patch | 44 | ||||
| -rw-r--r-- | meta/recipes-support/gnupg/gnupg_2.2.27.bb | 1 |
2 files changed, 45 insertions, 0 deletions
diff --git a/meta/recipes-support/gnupg/gnupg/CVE-2022-34903.patch b/meta/recipes-support/gnupg/gnupg/CVE-2022-34903.patch new file mode 100644 index 0000000000..5992949d35 --- /dev/null +++ b/meta/recipes-support/gnupg/gnupg/CVE-2022-34903.patch | |||
| @@ -0,0 +1,44 @@ | |||
| 1 | From 2f05fc96b1332caf97176841b1152da3f0aa16a8 Mon Sep 17 00:00:00 2001 | ||
| 2 | From: Hitendra Prajapati <hprajapati@mvista.com> | ||
| 3 | Date: Fri, 22 Jul 2022 17:52:36 +0530 | ||
| 4 | Subject: [PATCH] CVE-2022-34903 | ||
| 5 | |||
| 6 | Upstream-Status: Backport [https://git.gnupg.org/cgi-bin/gitweb.cgi?p=gnupg.git;a=commit;h=34c649b3601383cd11dbc76221747ec16fd68e1b] | ||
| 7 | CVE: CVE-2022-34903 | ||
| 8 | Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com> | ||
| 9 | --- | ||
| 10 | g10/cpr.c | 13 ++++--------- | ||
| 11 | 1 file changed, 4 insertions(+), 9 deletions(-) | ||
| 12 | |||
| 13 | diff --git a/g10/cpr.c b/g10/cpr.c | ||
| 14 | index d502e8b..bc4b715 100644 | ||
| 15 | --- a/g10/cpr.c | ||
| 16 | +++ b/g10/cpr.c | ||
| 17 | @@ -328,20 +328,15 @@ write_status_text_and_buffer (int no, const char *string, | ||
| 18 | } | ||
| 19 | first = 0; | ||
| 20 | } | ||
| 21 | - for (esc=0, s=buffer, n=len; n && !esc; s++, n--) | ||
| 22 | + for (esc=0, s=buffer, n=len; n; s++, n--) | ||
| 23 | { | ||
| 24 | if (*s == '%' || *(const byte*)s <= lower_limit | ||
| 25 | || *(const byte*)s == 127 ) | ||
| 26 | esc = 1; | ||
| 27 | if (wrap && ++count > wrap) | ||
| 28 | - { | ||
| 29 | - dowrap=1; | ||
| 30 | - break; | ||
| 31 | - } | ||
| 32 | - } | ||
| 33 | - if (esc) | ||
| 34 | - { | ||
| 35 | - s--; n++; | ||
| 36 | + dowrap=1; | ||
| 37 | + if (esc || dowrap) | ||
| 38 | + break; | ||
| 39 | } | ||
| 40 | if (s != buffer) | ||
| 41 | es_fwrite (buffer, s-buffer, 1, statusfp); | ||
| 42 | -- | ||
| 43 | 2.25.1 | ||
| 44 | |||
diff --git a/meta/recipes-support/gnupg/gnupg_2.2.27.bb b/meta/recipes-support/gnupg/gnupg_2.2.27.bb index 18bb855769..bd09b02017 100644 --- a/meta/recipes-support/gnupg/gnupg_2.2.27.bb +++ b/meta/recipes-support/gnupg/gnupg_2.2.27.bb | |||
| @@ -20,6 +20,7 @@ SRC_URI = "${GNUPG_MIRROR}/${BPN}/${BPN}-${PV}.tar.bz2 \ | |||
| 20 | file://0003-dirmngr-uses-libgpg-error.patch \ | 20 | file://0003-dirmngr-uses-libgpg-error.patch \ |
| 21 | file://0004-autogen.sh-fix-find-version-for-beta-checking.patch \ | 21 | file://0004-autogen.sh-fix-find-version-for-beta-checking.patch \ |
| 22 | file://0001-Woverride-init-is-not-needed-with-gcc-9.patch \ | 22 | file://0001-Woverride-init-is-not-needed-with-gcc-9.patch \ |
| 23 | file://CVE-2022-34903.patch \ | ||
| 23 | " | 24 | " |
| 24 | SRC_URI_append_class-native = " file://0001-configure.ac-use-a-custom-value-for-the-location-of-.patch \ | 25 | SRC_URI_append_class-native = " file://0001-configure.ac-use-a-custom-value-for-the-location-of-.patch \ |
| 25 | file://relocate.patch" | 26 | file://relocate.patch" |
