Blame SOURCES/0001-Multiple-security-disclosure-issues.patch

a80764
diff --git a/cups/http-private.h b/cups/http-private.h
a80764
index f2640f1..b7f9b6e 100644
a80764
--- a/cups/http-private.h
a80764
+++ b/cups/http-private.h
a80764
@@ -380,6 +380,7 @@ extern const char	*_httpResolveURI(const char *uri, char *resolved_uri,
a80764
 					 int (*cb)(void *context),
a80764
 					 void *context);
a80764
 extern int		_httpUpdate(http_t *http, http_status_t *status);
a80764
+extern size_t           _httpTLSPending(http_t *http);
a80764
 extern int		_httpWait(http_t *http, int msec, int usessl);
a80764
 
a80764
 extern void		_httpTLSSetOptions(int options);
a80764
diff --git a/cups/http.c b/cups/http.c
a80764
index e02b66d..128a52a 100644
a80764
--- a/cups/http.c
a80764
+++ b/cups/http.c
a80764
@@ -1817,7 +1817,7 @@ httpPrintf(http_t     *http,		/* I - Connection to server */
a80764
 	   ...)				/* I - Additional args as needed */
a80764
 {
a80764
   int		bytes;			/* Number of bytes to write */
a80764
-  char		buf[16384];		/* Buffer for formatted string */
a80764
+  char		buf[65536];		/* Buffer for formatted string */
a80764
   va_list	ap;			/* Variable argument pointer */
a80764
 
a80764
 
a80764
@@ -1829,7 +1829,12 @@ httpPrintf(http_t     *http,		/* I - Connection to server */
a80764
 
a80764
   DEBUG_printf(("3httpPrintf: %s", buf));
a80764
 
a80764
-  if (http->data_encoding == HTTP_ENCODE_FIELDS)
a80764
+  if (bytes > (ssize_t)(sizeof(buf) - 1))
a80764
+  {
a80764
+    http->error = ENOMEM;
a80764
+    return (-1);
a80764
+  }
a80764
+  else if (http->data_encoding == HTTP_ENCODE_FIELDS)
a80764
     return (httpWrite2(http, buf, bytes));
a80764
   else
a80764
   {
a80764
diff --git a/cups/ipp.c b/cups/ipp.c
a80764
index 0384792..2b613d7 100644
a80764
--- a/cups/ipp.c
a80764
+++ b/cups/ipp.c
a80764
@@ -3847,9 +3847,7 @@ ippSetValueTag(
a80764
         break;
a80764
 
a80764
     case IPP_TAG_NAME :
a80764
-        if (temp_tag != IPP_TAG_KEYWORD && temp_tag != IPP_TAG_URI &&
a80764
-            temp_tag != IPP_TAG_URISCHEME && temp_tag != IPP_TAG_LANGUAGE &&
a80764
-            temp_tag != IPP_TAG_MIMETYPE)
a80764
+        if (temp_tag != IPP_TAG_KEYWORD)
a80764
           return (0);
a80764
 
a80764
         (*attr)->value_tag = (ipp_tag_t)(IPP_TAG_NAME | ((*attr)->value_tag & IPP_TAG_COPY));
a80764
@@ -3857,10 +3855,7 @@ ippSetValueTag(
a80764
 
a80764
     case IPP_TAG_NAMELANG :
a80764
     case IPP_TAG_TEXTLANG :
a80764
-        if (value_tag == IPP_TAG_NAMELANG &&
a80764
-            (temp_tag != IPP_TAG_NAME && temp_tag != IPP_TAG_KEYWORD &&
a80764
-             temp_tag != IPP_TAG_URI && temp_tag != IPP_TAG_URISCHEME &&
a80764
-             temp_tag != IPP_TAG_LANGUAGE && temp_tag != IPP_TAG_MIMETYPE))
a80764
+        if (value_tag == IPP_TAG_NAMELANG && (temp_tag != IPP_TAG_NAME && temp_tag != IPP_TAG_KEYWORD))
a80764
           return (0);
a80764
 
a80764
         if (value_tag == IPP_TAG_TEXTLANG && temp_tag != IPP_TAG_TEXT)
a80764
diff --git a/cups/snmp.c b/cups/snmp.c
a80764
index 0c0e520..ff4fcd4 100644
a80764
--- a/cups/snmp.c
a80764
+++ b/cups/snmp.c
a80764
@@ -1279,6 +1279,9 @@ asn1_get_integer(
a80764
   int	value;				/* Integer value */
a80764
 
a80764
 
a80764
+  if (*buffer >= bufend)
a80764
+    return (0);
a80764
+
a80764
   if (length > sizeof(int))
a80764
   {
a80764
     (*buffer) += length;
a80764
@@ -1305,6 +1308,9 @@ asn1_get_length(unsigned char **buffer,	/* IO - Pointer in buffer */
a80764
   unsigned	length;			/* Length */
a80764
 
a80764
 
a80764
+  if (*buffer >= bufend)
a80764
+    return (0);
a80764
+
a80764
   length = **buffer;
a80764
   (*buffer) ++;
a80764
 
a80764
@@ -1347,6 +1353,9 @@ asn1_get_oid(
a80764
   int		number;			/* OID number */
a80764
 
a80764
 
a80764
+  if (*buffer >= bufend)
a80764
+    return (0);
a80764
+
a80764
   valend = *buffer + length;
a80764
   oidptr = oid;
a80764
   oidend = oid + oidsize - 1;
a80764
@@ -1395,9 +1404,12 @@ asn1_get_packed(
a80764
   int	value;				/* Value */
a80764
 
a80764
 
a80764
+  if (*buffer >= bufend)
a80764
+    return (0);
a80764
+
a80764
   value = 0;
a80764
 
a80764
-  while ((**buffer & 128) && *buffer < bufend)
a80764
+  while (*buffer < bufend && (**buffer & 128))
a80764
   {
a80764
     value = (value << 7) | (**buffer & 127);
a80764
     (*buffer) ++;
a80764
@@ -1425,6 +1437,9 @@ asn1_get_string(
a80764
     char          *string,		/* I  - String buffer */
a80764
     int           strsize)		/* I  - String buffer size */
a80764
 {
a80764
+  if (*buffer >= bufend)
a80764
+    return (NULL);
a80764
+
a80764
   if (length > (bufend - *buffer))
a80764
     length = bufend - *buffer;
a80764
 
a80764
@@ -1475,6 +1490,9 @@ asn1_get_type(unsigned char **buffer,	/* IO - Pointer in buffer */
a80764
   int	type;				/* Type */
a80764
 
a80764
 
a80764
+  if (*buffer >= bufend)
a80764
+    return (0);
a80764
+
a80764
   type = **buffer;
a80764
   (*buffer) ++;
a80764
 
a80764
diff --git a/scheduler/client.c b/scheduler/client.c
a80764
index 6e2f7e6..e20344d 100644
a80764
--- a/scheduler/client.c
a80764
+++ b/scheduler/client.c
a80764
@@ -770,6 +770,23 @@ cupsdReadClient(cupsd_client_t *con)	/* I - Client to read from */
a80764
 		  con->request ? ipp_states[con->request->state] : "",
a80764
 		  con->file);
a80764
 
a80764
+  if (con->http.error == EPIPE &&
a80764
+      (con->http.used == 0
a80764
+#ifdef HAVE_SSL
a80764
+        || _httpTLSPending(&(con->http)) == 0
a80764
+#endif /* HAVE_SSL */
a80764
+      ) && recv(con->http.fd, buf, 1, MSG_PEEK) < 1)
a80764
+  {
a80764
+   /*
a80764
+    * Connection closed...
a80764
+    */
a80764
+
a80764
+    cupsdLogMessage(CUPSD_LOG_DEBUG, "[Client %d] Closing on EOF.", con->http.fd);
a80764
+    cupsdCloseClient(con);
a80764
+    return;
a80764
+  }
a80764
+
a80764
+
a80764
 #ifdef HAVE_SSL
a80764
   if (con->auto_ssl)
a80764
   {
a80764
diff --git a/scheduler/tls-openssl.c b/scheduler/tls-openssl.c
a80764
index 759f393..a7a8e85 100644
a80764
--- a/scheduler/tls-openssl.c
a80764
+++ b/scheduler/tls-openssl.c
a80764
@@ -144,6 +144,17 @@ cupsdStartTLS(cupsd_client_t *con)	/* I - Client connection */
a80764
 }
a80764
 
a80764
 
a80764
+/*
a80764
+ * '_httpTLSPending()' - Return the number of pending TLS-encrypted bytes.
a80764
+ */
a80764
+
a80764
+size_t                                  /* O - Bytes available */
a80764
+_httpTLSPending(http_t *http)           /* I - HTTP connection */
a80764
+{
a80764
+  return (SSL_pending(http->tls));
a80764
+}
a80764
+
a80764
+
a80764
 /*
a80764
  * 'make_certificate()' - Make a self-signed SSL/TLS certificate.
a80764
  */