Blame SOURCES/0047-curl-7.61.1-CVE-2023-23916.patch

746a53
From 95f873ff983a1ae57415b3c16a881e74432cf8b8 Mon Sep 17 00:00:00 2001
746a53
From: Fabian Keil <fk@fabiankeil.de>
746a53
Date: Tue, 9 Feb 2021 14:04:32 +0100
746a53
Subject: [PATCH 1/2] runtests.pl: support the nonewline attribute for the data
746a53
 part
746a53
746a53
Closes #8239
746a53
746a53
Upstream-commit: 736847611a40c01e7c290407e22e2f0f5f8efd6a
746a53
Signed-off-by: Kamil Dudka <kdudka@redhat.com>
746a53
---
746a53
 tests/runtests.pl      |  7 +++++++
746a53
 tests/server/getpart.c | 11 ++++++++++-
746a53
 2 files changed, 17 insertions(+), 1 deletion(-)
746a53
746a53
diff --git a/tests/runtests.pl b/tests/runtests.pl
746a53
index 40315aa..2e1500d 100755
746a53
--- a/tests/runtests.pl
746a53
+++ b/tests/runtests.pl
746a53
@@ -3817,6 +3817,13 @@ sub singletest {
746a53
     else {
746a53
         # check against the data section
746a53
         @reply = getpart("reply", "data");
746a53
+        if(@reply) {
746a53
+            my %hash = getpartattr("reply", "data");
746a53
+            if($hash{'nonewline'}) {
746a53
+                # cut off the final newline from the final line of the data
746a53
+                chomp($reply[$#reply]);
746a53
+            }
746a53
+        }
746a53
         # get the mode attribute
746a53
         my $filemode=$replyattr{'mode'};
746a53
         if($filemode && ($filemode eq "text") && $has_textaware) {
746a53
diff --git a/tests/server/getpart.c b/tests/server/getpart.c
746a53
index 32b55bc..f8fe3f6 100644
746a53
--- a/tests/server/getpart.c
746a53
+++ b/tests/server/getpart.c
746a53
@@ -5,7 +5,7 @@
746a53
  *                            | (__| |_| |  _ <| |___
746a53
  *                             \___|\___/|_| \_\_____|
746a53
  *
746a53
- * Copyright (C) 1998 - 2017, Daniel Stenberg, <daniel@haxx.se>, et al.
746a53
+ * Copyright (C) 1998 - 2022, Daniel Stenberg, <daniel@haxx.se>, et al.
746a53
  *
746a53
  * This software is licensed as described in the file COPYING, which
746a53
  * you should have received as part of this distribution. The terms
746a53
@@ -295,6 +295,7 @@ int getpart(char **outbuf, size_t *outlen,
746a53
   size_t outalloc = 256;
746a53
   int in_wanted_part = 0;
746a53
   int base64 = 0;
746a53
+  int nonewline = 0;
746a53
   int error;
746a53
 
746a53
   enum {
746a53
@@ -360,6 +361,8 @@ int getpart(char **outbuf, size_t *outlen,
746a53
             if(error)
746a53
               return error;
746a53
           }
746a53
+          if(nonewline)
746a53
+            (*outlen)--;
746a53
           break;
746a53
         }
746a53
       }
746a53
@@ -377,6 +380,8 @@ int getpart(char **outbuf, size_t *outlen,
746a53
             if(error)
746a53
               return error;
746a53
           }
746a53
+          if(nonewline)
746a53
+            (*outlen)--;
746a53
           break;
746a53
         }
746a53
       }
746a53
@@ -451,6 +456,10 @@ int getpart(char **outbuf, size_t *outlen,
746a53
               /* bit rough test, but "mostly" functional, */
746a53
               /* treat wanted part data as base64 encoded */
746a53
               base64 = 1;
746a53
+          if(strstr(patt, "nonewline=")) {
746a53
+            show(("* setting nonewline\n"));
746a53
+            nonewline = 1;
746a53
+          }
746a53
         }
746a53
         continue;
746a53
       }
746a53
-- 
746a53
2.39.1
746a53
746a53
746a53
From bc5fc958b017895728962c9d44c469418cbec1a0 Mon Sep 17 00:00:00 2001
746a53
From: Patrick Monnerat <patrick@monnerat.net>
746a53
Date: Mon, 13 Feb 2023 08:33:09 +0100
746a53
Subject: [PATCH 2/2] content_encoding: do not reset stage counter for each
746a53
 header
746a53
746a53
Test 418 verifies
746a53
746a53
Closes #10492
746a53
746a53
Upstream-commit: 119fb187192a9ea13dc90d9d20c215fc82799ab9
746a53
Signed-off-by: Kamil Dudka <kdudka@redhat.com>
746a53
---
746a53
 lib/content_encoding.c  |   7 +-
746a53
 lib/urldata.h           |   1 +
746a53
 tests/data/Makefile.inc |   1 +
746a53
 tests/data/test387      |   2 +-
746a53
 tests/data/test418      | 152 ++++++++++++++++++++++++++++++++++++++++
746a53
 5 files changed, 158 insertions(+), 5 deletions(-)
746a53
 create mode 100644 tests/data/test418
746a53
746a53
diff --git a/lib/content_encoding.c b/lib/content_encoding.c
746a53
index bfc13e2..94344d6 100644
746a53
--- a/lib/content_encoding.c
746a53
+++ b/lib/content_encoding.c
746a53
@@ -944,7 +944,6 @@ CURLcode Curl_build_unencoding_stack(struct connectdata *conn,
746a53
 {
746a53
   struct Curl_easy *data = conn->data;
746a53
   struct SingleRequest *k = &data->req;
746a53
-  int counter = 0;
746a53
 
746a53
   do {
746a53
     const char *name;
746a53
@@ -979,9 +978,9 @@ CURLcode Curl_build_unencoding_stack(struct connectdata *conn,
746a53
       if(!encoding)
746a53
         encoding = &error_encoding;  /* Defer error at stack use. */
746a53
 
746a53
-      if(++counter >= MAX_ENCODE_STACK) {
746a53
-        failf(data, "Reject response due to %u content encodings",
746a53
-              counter);
746a53
+      if(k->writer_stack_depth++ >= MAX_ENCODE_STACK) {
746a53
+        failf(data, "Reject response due to more than %u content encodings",
746a53
+              MAX_ENCODE_STACK);
746a53
         return CURLE_BAD_CONTENT_ENCODING;
746a53
       }
746a53
       /* Stack the unencoding stage. */
746a53
diff --git a/lib/urldata.h b/lib/urldata.h
746a53
index 5b4b34f..8c8c20b 100644
746a53
--- a/lib/urldata.h
746a53
+++ b/lib/urldata.h
746a53
@@ -539,6 +539,7 @@ struct SingleRequest {
746a53
 
746a53
   struct curltime start;         /* transfer started at this time */
746a53
   struct curltime now;           /* current time */
746a53
+  unsigned char writer_stack_depth; /* Unencoding stack depth. */
746a53
   bool header;                  /* incoming data has HTTP header */
746a53
   enum {
746a53
     HEADER_NORMAL,              /* no bad header at all */
746a53
diff --git a/tests/data/Makefile.inc b/tests/data/Makefile.inc
746a53
index fb51cd6..86b6f85 100644
746a53
--- a/tests/data/Makefile.inc
746a53
+++ b/tests/data/Makefile.inc
746a53
@@ -66,6 +66,7 @@ test393 test394 test395 \
746a53
 \
746a53
 test400 test401 test402 test403 test404 test405 test406 test407 test408 \
746a53
 test409 \
746a53
+test418 \
746a53
 \
746a53
 test500 test501 test502 test503 test504 test505 test506 test507 test508 \
746a53
 test509 test510 test511 test512 test513 test514 test515 test516 test517 \
746a53
diff --git a/tests/data/test387 b/tests/data/test387
746a53
index 015ec25..644fc7f 100644
746a53
--- a/tests/data/test387
746a53
+++ b/tests/data/test387
746a53
@@ -47,7 +47,7 @@ Accept: */*
746a53
 61
746a53
 </errorcode>
746a53
 <stderr mode="text">
746a53
-curl: (61) Reject response due to 5 content encodings
746a53
+curl: (61) Reject response due to more than 5 content encodings
746a53
 </stderr>
746a53
 </verify>
746a53
 </testcase>
746a53
diff --git a/tests/data/test418 b/tests/data/test418
746a53
new file mode 100644
746a53
index 0000000..50e974e
746a53
--- /dev/null
746a53
+++ b/tests/data/test418
746a53
@@ -0,0 +1,152 @@
746a53
+<testcase>
746a53
+<info>
746a53
+<keywords>
746a53
+HTTP
746a53
+gzip
746a53
+</keywords>
746a53
+</info>
746a53
+
746a53
+#
746a53
+# Server-side
746a53
+<reply>
746a53
+<data nocheck="yes">
746a53
+HTTP/1.1 200 OK
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+Transfer-Encoding: gzip
746a53
+
746a53
+-foo-
746a53
+</data>
746a53
+</reply>
746a53
+
746a53
+#
746a53
+# Client-side
746a53
+<client>
746a53
+<server>
746a53
+http
746a53
+</server>
746a53
+ <name>
746a53
+Response with multiple Transfer-Encoding headers
746a53
+ </name>
746a53
+ <command>
746a53
+http://%HOSTIP:%HTTPPORT/%TESTNUMBER -sS
746a53
+</command>
746a53
+</client>
746a53
+
746a53
+#
746a53
+# Verify data after the test has been "shot"
746a53
+<verify>
746a53
+<protocol>
746a53
+GET /%TESTNUMBER HTTP/1.1
746a53
+Host: %HOSTIP:%HTTPPORT
746a53
+User-Agent: curl/7.61.1
746a53
+Accept: */*
746a53
+
746a53
+</protocol>
746a53
+
746a53
+# CURLE_BAD_CONTENT_ENCODING is 61
746a53
+<errorcode>
746a53
+61
746a53
+</errorcode>
746a53
+<stderr mode="text">
746a53
+curl: (61) Reject response due to more than 5 content encodings
746a53
+</stderr>
746a53
+</verify>
746a53
+</testcase>
746a53
-- 
746a53
2.39.1
746a53