Blame SOURCES/db-5.3.28-fix-CWE-686-398.patch

b30d9d
This patch fixes: CWE-686,CWE-398
b30d9d
b30d9d
diff -ur db-5.3.28/src/log/log_verify_int.c new/src/log/log_verify_int.c
b30d9d
--- db-5.3.28/src/log/log_verify_int.c	2013-09-09 17:35:08.000000000 +0200
b30d9d
+++ new/src/log/log_verify_int.c	2021-08-05 13:33:06.378608924 +0200
b30d9d
@@ -433,9 +433,9 @@
b30d9d
 		putflag = DB_CURRENT;
b30d9d
 		doput = 1;
b30d9d
 	}
b30d9d
+    if (doput)
b30d9d
+        ret = __dbc_put(csr, &key, &data, putflag);
b30d9d
 
b30d9d
-	if (doput && (ret = __dbc_put(csr, &key, &data, putflag)) != 0)
b30d9d
-		goto err;
b30d9d
 err:
b30d9d
 	if (csr != NULL && (tret = __dbc_close(csr)) != 0 && ret == 0)
b30d9d
 		ret = tret;
b30d9d
diff -ur db-5.3.28/src/log/log_verify_util.c new/src/log/log_verify_util.c
b30d9d
--- db-5.3.28/src/log/log_verify_util.c	2013-09-09 17:35:08.000000000 +0200
b30d9d
+++ new/src/log/log_verify_util.c	2021-08-04 15:10:07.900854238 +0200
b30d9d
@@ -2140,8 +2140,7 @@
b30d9d
 	for (ret = __dbc_pget(csr, &key, &data2, &data, DB_SET); ret == 0;
b30d9d
 	    ret = __dbc_pget(csr, &key, &data2, &data, DB_NEXT_DUP))
b30d9d
 		BDBOP(__db_put(pdb, lvh->ip, NULL, &data2, &key2, 0));
b30d9d
-	if ((ret = __del_txn_pages(lvh, ctxn)) != 0 && ret != DB_NOTFOUND)
b30d9d
-		goto err;
b30d9d
+    ret = __del_txn_pages(lvh, ctxn);
b30d9d
 err:
b30d9d
 	if (csr != NULL && (tret = __dbc_close(csr)) != 0 && ret == 0)
b30d9d
 		ret = tret;
b30d9d
diff -ur db-5.3.28/src/rep/rep_backup.c new/src/rep/rep_backup.c
b30d9d
--- db-5.3.28/src/rep/rep_backup.c	2013-09-09 17:35:09.000000000 +0200
b30d9d
+++ new/src/rep/rep_backup.c	2021-08-04 14:47:51.967782566 +0200
b30d9d
@@ -542,8 +542,6 @@
b30d9d
 
b30d9d
 	ret = __memp_fput(dbp->mpf, ip, pagep, dbc->priority);
b30d9d
 	pagep = NULL;
b30d9d
-	if (ret != 0)
b30d9d
-		goto err;
b30d9d
 err:
b30d9d
 	/*
b30d9d
 	 * Check status of pagep in case any new error paths out leave
b30d9d
diff -ur db-5.3.28/util/db_dump185.c new/util/db_dump185.c
b30d9d
--- db-5.3.28/util/db_dump185.c	2013-09-09 17:35:12.000000000 +0200
b30d9d
+++ new/util/db_dump185.c	2021-08-04 14:45:37.592794678 +0200
b30d9d
@@ -19,7 +19,7 @@
b30d9d
 #include <stdio.h>
b30d9d
 #include <stdlib.h>
b30d9d
 #include <string.h>
b30d9d
-
b30d9d
+#include <unistd.h>
b30d9d
 #ifdef HAVE_DB_185_H
b30d9d
 #include <db_185.h>
b30d9d
 #else