aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorNatanael Copa <ncopa@alpinelinux.org>2013-08-30 10:00:24 +0000
committerNatanael Copa <ncopa@alpinelinux.org>2013-08-30 11:32:01 +0000
commit921298d100ce1bee3a8d45a5aefb2b210d559c64 (patch)
treeed4e0e55e656ddaa4c6b09ad85cb43da5c386c23
parent75137e0d9bbc0ea7a67ab775f312c909e31a442b (diff)
downloadaports-921298d100ce1bee3a8d45a5aefb2b210d559c64.tar.bz2
aports-921298d100ce1bee3a8d45a5aefb2b210d559c64.tar.xz
main/lcms: fix CVE-2013-4276
fixes #2242
-rw-r--r--main/lcms/APKBUILD17
-rw-r--r--main/lcms/CVE-2013-4276.patch62
2 files changed, 76 insertions, 3 deletions
diff --git a/main/lcms/APKBUILD b/main/lcms/APKBUILD
index 94e50ce470..810291f84f 100644
--- a/main/lcms/APKBUILD
+++ b/main/lcms/APKBUILD
@@ -1,7 +1,7 @@
# Maintainer: Natanael Copa <ncopa@alpinelinux.org>
pkgname=lcms
pkgver=1.19
-pkgrel=2
+pkgrel=3
pkgdesc="Lightweight color management development library/engine"
url="http://www.littlecms.com"
arch="all"
@@ -9,9 +9,19 @@ license="custom"
depends=
makedepends="tiff-dev jpeg-dev zlib-dev"
subpackages="$pkgname-dev $pkgname-doc liblcms"
-source="http://downloads.sourceforge.net/project/lcms/lcms/$pkgver/lcms-$pkgver.tar.gz"
+source="http://downloads.sourceforge.net/project/lcms/lcms/$pkgver/lcms-$pkgver.tar.gz
+ CVE-2013-4276.patch"
_builddir="$srcdir"/$pkgname-$pkgver
+prepare() {
+ cd "$_builddir"
+ for i in $source; do
+ case $i in
+ *.patch) msg $i; patch -p1 -i "$srcdir"/$i || return 1;;
+ esac
+ done
+}
+
build() {
cd "$_builddir"
./configure --prefix=/usr
@@ -30,4 +40,5 @@ liblcms() {
mv "$pkgdir"/usr/lib/liblcms.so.* "$subpkgdir"/usr/lib/
}
-md5sums="8af94611baf20d9646c7c2c285859818 lcms-1.19.tar.gz"
+md5sums="8af94611baf20d9646c7c2c285859818 lcms-1.19.tar.gz
+fa1db4861cfa05f4c4a2c826e1c35502 CVE-2013-4276.patch"
diff --git a/main/lcms/CVE-2013-4276.patch b/main/lcms/CVE-2013-4276.patch
new file mode 100644
index 0000000000..8f2f322978
--- /dev/null
+++ b/main/lcms/CVE-2013-4276.patch
@@ -0,0 +1,62 @@
+diff -ur lcms-1.19.dfsg/samples/icctrans.c lcms-1.19.dfsg-patched/samples/icctrans.c
+--- lcms-1.19.dfsg/samples/icctrans.c 2009-10-30 15:57:45.000000000 +0000
++++ lcms-1.19.dfsg-patched/samples/icctrans.c 2013-08-06 11:53:14.385266647 +0100
+@@ -86,6 +86,8 @@
+ static LPcmsNAMEDCOLORLIST InputColorant = NULL;
+ static LPcmsNAMEDCOLORLIST OutputColorant = NULL;
+
++unsigned int Buffer_size = 4096;
++
+
+ // isatty replacement
+
+@@ -500,7 +502,7 @@
+
+ Prefix[0] = 0;
+ if (!lTerse)
+- sprintf(Prefix, "%s=", C);
++ snprintf(Prefix, 20, "%s=", C);
+
+ if (InHexa)
+ {
+@@ -648,7 +650,9 @@
+ static
+ void GetLine(char* Buffer)
+ {
+- scanf("%s", Buffer);
++ char User_buffer[Buffer_size];
++ fgets(User_buffer, (Buffer_size - 1), stdin);
++ sscanf(User_buffer,"%s", Buffer);
+
+ if (toupper(Buffer[0]) == 'Q') { // Quit?
+
+@@ -668,7 +672,7 @@
+ static
+ double GetAnswer(const char* Prompt, double Range)
+ {
+- char Buffer[4096];
++ char Buffer[Buffer_size];
+ double val = 0.0;
+
+ if (Range == 0.0) { // Range 0 means double value
+@@ -738,7 +742,7 @@
+ static
+ WORD GetIndex(void)
+ {
+- char Buffer[4096], Name[40], Prefix[40], Suffix[40];
++ char Buffer[Buffer_size], Name[40], Prefix[40], Suffix[40];
+ int index, max;
+
+ max = cmsNamedColorCount(hTrans)-1;
+diff -ur lcms-1.19.dfsg/tifficc/tiffdiff.c lcms-1.19.dfsg-patched/tifficc/tiffdiff.c
+--- lcms-1.19.dfsg/tifficc/tiffdiff.c 2009-10-30 15:57:46.000000000 +0000
++++ lcms-1.19.dfsg-patched/tifficc/tiffdiff.c 2013-08-06 11:49:06.698951157 +0100
+@@ -633,7 +633,7 @@
+ cmsIT8SetSheetType(hIT8, "TIFFDIFF");
+
+
+- sprintf(Buffer, "Differences between %s and %s", TiffName1, TiffName2);
++ snprintf(Buffer, 256, "Differences between %s and %s", TiffName1, TiffName2);
+
+ cmsIT8SetComment(hIT8, Buffer);
+