summaryrefslogtreecommitdiffstats
path: root/meta/recipes-support/curl/curl/CVE-2022-43551.patch
diff options
context:
space:
mode:
Diffstat (limited to 'meta/recipes-support/curl/curl/CVE-2022-43551.patch')
-rw-r--r--meta/recipes-support/curl/curl/CVE-2022-43551.patch32
1 files changed, 32 insertions, 0 deletions
diff --git a/meta/recipes-support/curl/curl/CVE-2022-43551.patch b/meta/recipes-support/curl/curl/CVE-2022-43551.patch
new file mode 100644
index 0000000000..7c617ef1db
--- /dev/null
+++ b/meta/recipes-support/curl/curl/CVE-2022-43551.patch
@@ -0,0 +1,32 @@
1From 08aa76b7b24454a89866aaef661ea90ae3d57900 Mon Sep 17 00:00:00 2001
2From: Daniel Stenberg <daniel@haxx.se>
3Date: Mon, 19 Dec 2022 08:36:55 +0100
4Subject: [PATCH] http: use the IDN decoded name in HSTS checks
5
6Otherwise it stores the info HSTS into the persistent cache for the IDN
7name which will not match when the HSTS status is later checked for
8using the decoded name.
9
10Reported-by: Hiroki Kurosawa
11
12Closes #10111
13
14Upstream-Status: Backport [https://github.com/curl/curl/commit/9e71901634e276dd]
15Signed-off-by: Robert Joslyn <robert.joslyn@redrectangle.org>
16---
17 lib/http.c | 2 +-
18 1 file changed, 1 insertion(+), 1 deletion(-)
19
20diff --git a/lib/http.c b/lib/http.c
21index b0ad28e..8b18e8d 100644
22--- a/lib/http.c
23+++ b/lib/http.c
24@@ -3654,7 +3654,7 @@ CURLcode Curl_http_header(struct Curl_easy *data, struct connectdata *conn,
25 else if(data->hsts && checkprefix("Strict-Transport-Security:", headp) &&
26 (conn->handler->flags & PROTOPT_SSL)) {
27 CURLcode check =
28- Curl_hsts_parse(data->hsts, data->state.up.hostname,
29+ Curl_hsts_parse(data->hsts, conn->host.name,
30 headp + strlen("Strict-Transport-Security:"));
31 if(check)
32 infof(data, "Illegal STS header skipped");