cyrus-sasl: patch CVE-2019-19906 17114/head
authorMichal Vasilek <michal.vasilek@nic.cz>
Fri, 12 Nov 2021 17:09:39 +0000 (18:09 +0100)
committerMichal Vasilek <michal.vasilek@nic.cz>
Sat, 13 Nov 2021 15:11:23 +0000 (16:11 +0100)
Signed-off-by: Michal Vasilek <michal.vasilek@nic.cz>
(cherry picked from commit f7717bd382d4f03c6353beaaf198d29a34c8e6ab)

libs/cyrus-sasl/Makefile
libs/cyrus-sasl/patches/CVE-2019-19906.patch [new file with mode: 0644]

index 2a670e9b6e94b0556edaeabe267f5fc09ada1104..04796f3b3059c85151f5220ed01227fd4cbee709 100644 (file)
@@ -9,7 +9,7 @@ include $(TOPDIR)/rules.mk
 
 PKG_NAME:=cyrus-sasl
 PKG_VERSION:=2.1.27
-PKG_RELEASE:=1
+PKG_RELEASE:=2
 
 PKG_MAINTAINER:=W. Michael Petullo <mike@flyn.org>
 
diff --git a/libs/cyrus-sasl/patches/CVE-2019-19906.patch b/libs/cyrus-sasl/patches/CVE-2019-19906.patch
new file mode 100644 (file)
index 0000000..1b9fdfa
--- /dev/null
@@ -0,0 +1,23 @@
+From dcc9f51cbd4ed622cfb0f9b1c141eb2ffe3b12f1 Mon Sep 17 00:00:00 2001
+From: Quanah Gibson-Mount <quanah@symas.com>
+Date: Tue, 18 Feb 2020 19:05:12 +0000
+Subject: [PATCH] Fix #587
+
+Off by one error in common.c, CVE-2019-19906.
+
+Thanks to Stephan Zeisberg for reporting
+---
+ lib/common.c | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+--- a/lib/common.c
++++ b/lib/common.c
+@@ -190,7 +190,7 @@ int _sasl_add_string(char **out, size_t
+   if (add==NULL) add = "(null)";
+-  addlen=strlen(add); /* only compute once */
++  addlen=strlen(add)+1; /* only compute once */
+   if (_buf_alloc(out, alloclen, (*outlen)+addlen)!=SASL_OK)
+     return SASL_NOMEM;