Blame SOURCES/0005-Fix-CVE-2022-4883-compression-commands-depend-on-PAT.patch

a4ac63
From 66854ee1d187095186ae718979baf771c177002a Mon Sep 17 00:00:00 2001
a4ac63
From: Alan Coopersmith <alan.coopersmith@oracle.com>
a4ac63
Date: Fri, 6 Jan 2023 12:50:48 -0800
a4ac63
Subject: [PATCH libXpm 5/5] Fix CVE-2022-4883: compression commands depend on
a4ac63
 $PATH
a4ac63
a4ac63
By default, on all platforms except MinGW, libXpm will detect if a
a4ac63
filename ends in .Z or .gz, and will when reading such a file fork off
a4ac63
an uncompress or gunzip command to read from via a pipe, and when
a4ac63
writing such a file will fork off a compress or gzip command to write
a4ac63
to via a pipe.
a4ac63
a4ac63
In libXpm 3.5.14 or older these are run via execlp(), relying on $PATH
a4ac63
to find the commands.  If libXpm is called from a program running with
a4ac63
raised privileges, such as via setuid, then a malicious user could set
a4ac63
$PATH to include programs of their choosing to be run with those
a4ac63
privileges.
a4ac63
a4ac63
Signed-off-by: Alan Coopersmith <alan.coopersmith@oracle.com>
a4ac63
---
a4ac63
 README       | 12 ++++++++++++
a4ac63
 configure.ac | 14 ++++++++++++++
a4ac63
 src/RdFToI.c | 17 ++++++++++++++---
a4ac63
 src/WrFFrI.c |  4 ++--
a4ac63
 4 files changed, 42 insertions(+), 5 deletions(-)
a4ac63
a4ac63
diff --git a/README b/README
a4ac63
index f532bef..c7d6dbf 100644
a4ac63
--- a/README
a4ac63
+++ b/README
a4ac63
@@ -38,3 +38,15 @@ if it can't find the file it was asked to open.  It relies on the
a4ac63
 --enable-open-zfile feature to open the file, and is enabled by default
a4ac63
 when --enable-open-zfile is enabled, and can be disabled by passing the
a4ac63
 --disable-stat-zfile flag to the configure script.
a4ac63
+
a4ac63
+All of these commands will be executed with whatever userid & privileges the
a4ac63
+function is called with, relying on the caller to ensure the correct euid,
a4ac63
+egid, etc. are set before calling.
a4ac63
+
a4ac63
+To reduce risk, the paths to these commands are now set at configure time to
a4ac63
+the first version found in the PATH used to run configure, and do not depend
a4ac63
+on the PATH environment variable set at runtime.
a4ac63
+
a4ac63
+To specify paths to be used for these commands instead of searching $PATH, pass
a4ac63
+the XPM_PATH_COMPRESS, XPM_PATH_UNCOMPRESS, XPM_PATH_GZIP, and XPM_PATH_GUNZIP
a4ac63
+variables to the configure command.
a4ac63
diff --git a/configure.ac b/configure.ac
a4ac63
index 4a8d6de..c1da348 100644
a4ac63
--- a/configure.ac
a4ac63
+++ b/configure.ac
a4ac63
@@ -48,6 +48,14 @@ if test "x$USE_GETTEXT" = "xyes" ; then
a4ac63
 fi
a4ac63
 AM_CONDITIONAL(USE_GETTEXT, test "x$USE_GETTEXT" = "xyes")
a4ac63
 
a4ac63
+dnl Helper macro to find absolute path to program and add a #define for it
a4ac63
+AC_DEFUN([XPM_PATH_PROG],[
a4ac63
+AC_PATH_PROG([$1], [$2], [])
a4ac63
+AS_IF([test "x$$1" = "x"],
a4ac63
+      [AC_MSG_ERROR([$2 not found, set $1 or use --disable-stat-zfile])])
a4ac63
+AC_DEFINE_UNQUOTED([$1], ["$$1"], [Path to $2])
a4ac63
+]) dnl End of AC_DEFUN([XPM_PATH_PROG]...
a4ac63
+
a4ac63
 # Optional feature: When a filename ending in .Z or .gz is requested,
a4ac63
 # open a pipe to a newly forked compress/uncompress/gzip/gunzip command to
a4ac63
 # handle it.
a4ac63
@@ -63,6 +71,12 @@ AC_ARG_ENABLE(open-zfile,
a4ac63
 AC_MSG_RESULT([$OPEN_ZFILE])
a4ac63
 if test x$OPEN_ZFILE = xno ; then
a4ac63
         AC_DEFINE(NO_ZPIPE, 1, [Define to 1 to disable decompression via pipes])
a4ac63
+else
a4ac63
+        XPM_PATH_PROG([XPM_PATH_COMPRESS], [compress])
a4ac63
+        XPM_PATH_PROG([XPM_PATH_UNCOMPRESS], [uncompress])
a4ac63
+        XPM_PATH_PROG([XPM_PATH_GZIP], [gzip])
a4ac63
+        XPM_PATH_PROG([XPM_PATH_GUNZIP], [gunzip])
a4ac63
+        AC_CHECK_FUNCS([closefrom close_range], [break])
a4ac63
 fi
a4ac63
 
a4ac63
 # Optional feature: When ___.xpm is requested, also look for ___.xpm.Z & .gz
a4ac63
diff --git a/src/RdFToI.c b/src/RdFToI.c
a4ac63
index bd09611..a91d337 100644
a4ac63
--- a/src/RdFToI.c
a4ac63
+++ b/src/RdFToI.c
a4ac63
@@ -43,6 +43,7 @@
a4ac63
 #include <errno.h>
a4ac63
 #include <sys/types.h>
a4ac63
 #include <sys/wait.h>
a4ac63
+#include <unistd.h>
a4ac63
 #else
a4ac63
 #ifdef FOR_MSW
a4ac63
 #include <fcntl.h>
a4ac63
@@ -161,7 +162,17 @@ xpmPipeThrough(
a4ac63
 	    goto err;
a4ac63
 	if ( 0 == pid )
a4ac63
 	{
a4ac63
-	    execlp(cmd, cmd, arg1, (char *)NULL);
a4ac63
+#ifdef HAVE_CLOSEFROM
a4ac63
+	    closefrom(3);
a4ac63
+#elif defined(HAVE_CLOSE_RANGE)
a4ac63
+# ifdef CLOSE_RANGE_UNSHARE
a4ac63
+#  define close_range_flags CLOSE_RANGE_UNSHARE
a4ac63
+# else
a4ac63
+#  define close_range_flags 0
a4ac63
+#endif
a4ac63
+	    close_range(3, ~0U, close_range_flags);
a4ac63
+#endif
a4ac63
+	    execl(cmd, cmd, arg1, (char *)NULL);
a4ac63
 	    perror(cmd);
a4ac63
 	    goto err;
a4ac63
 	}
a4ac63
@@ -235,12 +246,12 @@ OpenReadFile(
a4ac63
 	if ( ext && !strcmp(ext, ".Z") )
a4ac63
 	{
a4ac63
 	    mdata->type = XPMPIPE;
a4ac63
-	    mdata->stream.file = xpmPipeThrough(fd, "uncompress", "-c", "r");
a4ac63
+	    mdata->stream.file = xpmPipeThrough(fd, XPM_PATH_UNCOMPRESS, "-c", "r");
a4ac63
 	}
a4ac63
 	else if ( ext && !strcmp(ext, ".gz") )
a4ac63
 	{
a4ac63
 	    mdata->type = XPMPIPE;
a4ac63
-	    mdata->stream.file = xpmPipeThrough(fd, "gunzip", "-qc", "r");
a4ac63
+	    mdata->stream.file = xpmPipeThrough(fd, XPM_PATH_GUNZIP, "-qc", "r");
a4ac63
 	}
a4ac63
 	else
a4ac63
 #endif /* z-files */
a4ac63
diff --git a/src/WrFFrI.c b/src/WrFFrI.c
a4ac63
index 067c96b..bc38f66 100644
a4ac63
--- a/src/WrFFrI.c
a4ac63
+++ b/src/WrFFrI.c
a4ac63
@@ -336,10 +336,10 @@ OpenWriteFile(
a4ac63
 #ifndef NO_ZPIPE
a4ac63
 	len = strlen(filename);
a4ac63
 	if (len > 2 && !strcmp(".Z", filename + (len - 2))) {
a4ac63
-	    mdata->stream.file = xpmPipeThrough(fd, "compress", NULL, "w");
a4ac63
+	    mdata->stream.file = xpmPipeThrough(fd, XPM_PATH_COMPRESS, NULL, "w");
a4ac63
 	    mdata->type = XPMPIPE;
a4ac63
 	} else if (len > 3 && !strcmp(".gz", filename + (len - 3))) {
a4ac63
-	    mdata->stream.file = xpmPipeThrough(fd, "gzip", "-q", "w");
a4ac63
+	    mdata->stream.file = xpmPipeThrough(fd, XPM_PATH_GZIP, "-q", "w");
a4ac63
 	    mdata->type = XPMPIPE;
a4ac63
 	} else
a4ac63
 #endif
a4ac63
-- 
a4ac63
2.39.0
a4ac63