Blame SOURCES/0031-curl-7.61.1-CVE-2021-22924.patch

c3d52c
From 74ba80e293eb2521d28916b24c3be59b3baf688a Mon Sep 17 00:00:00 2001
c3d52c
From: Daniel Stenberg <daniel@haxx.se>
c3d52c
Date: Thu, 18 Feb 2021 10:13:56 +0100
c3d52c
Subject: [PATCH 1/2] urldata: remove the _ORIG suffix from string names
c3d52c
c3d52c
It doesn't provide any useful info but only makes the names longer.
c3d52c
c3d52c
Closes #6624
c3d52c
c3d52c
Upstream-commit: 70472a44deaff387cf8c8c197e04f3add2a96e2e
c3d52c
Signed-off-by: Kamil Dudka <kdudka@redhat.com>
c3d52c
---
c3d52c
 lib/setopt.c         | 32 ++++++++++++++++----------------
c3d52c
 lib/url.c            | 32 ++++++++++++++++----------------
c3d52c
 lib/urldata.h        | 28 ++++++++++++++--------------
c3d52c
 lib/vtls/cyassl.c    |  2 +-
c3d52c
 lib/vtls/darwinssl.c |  4 ++--
c3d52c
 lib/vtls/gskit.c     |  2 +-
c3d52c
 lib/vtls/gtls.c      |  2 +-
c3d52c
 lib/vtls/mbedtls.c   |  2 +-
c3d52c
 lib/vtls/nss.c       |  2 +-
c3d52c
 lib/vtls/openssl.c   |  2 +-
c3d52c
 lib/vtls/polarssl.c  |  2 +-
c3d52c
 lib/vtls/schannel.c  |  2 +-
c3d52c
 12 files changed, 56 insertions(+), 56 deletions(-)
c3d52c
c3d52c
diff --git a/lib/setopt.c b/lib/setopt.c
c3d52c
index 4f04962..b07ccfe 100644
c3d52c
--- a/lib/setopt.c
c3d52c
+++ b/lib/setopt.c
c3d52c
@@ -133,7 +133,7 @@ CURLcode Curl_vsetopt(struct Curl_easy *data, CURLoption option,
c3d52c
     break;
c3d52c
   case CURLOPT_SSL_CIPHER_LIST:
c3d52c
     /* set a list of cipher we want to use in the SSL connection */
c3d52c
-    result = Curl_setstropt(&data->set.str[STRING_SSL_CIPHER_LIST_ORIG],
c3d52c
+    result = Curl_setstropt(&data->set.str[STRING_SSL_CIPHER_LIST],
c3d52c
                             va_arg(param, char *));
c3d52c
     break;
c3d52c
   case CURLOPT_PROXY_SSL_CIPHER_LIST:
c3d52c
@@ -145,7 +145,7 @@ CURLcode Curl_vsetopt(struct Curl_easy *data, CURLoption option,
c3d52c
   case CURLOPT_TLS13_CIPHERS:
c3d52c
     if(Curl_ssl_tls13_ciphersuites()) {
c3d52c
       /* set preferred list of TLS 1.3 cipher suites */
c3d52c
-      result = Curl_setstropt(&data->set.str[STRING_SSL_CIPHER13_LIST_ORIG],
c3d52c
+      result = Curl_setstropt(&data->set.str[STRING_SSL_CIPHER13_LIST],
c3d52c
                               va_arg(param, char *));
c3d52c
     }
c3d52c
     else
c3d52c
@@ -1532,7 +1532,7 @@ CURLcode Curl_vsetopt(struct Curl_easy *data, CURLoption option,
c3d52c
     /*
c3d52c
      * String that holds file name of the SSL certificate to use
c3d52c
      */
c3d52c
-    result = Curl_setstropt(&data->set.str[STRING_CERT_ORIG],
c3d52c
+    result = Curl_setstropt(&data->set.str[STRING_CERT],
c3d52c
                             va_arg(param, char *));
c3d52c
     break;
c3d52c
   case CURLOPT_PROXY_SSLCERT:
c3d52c
@@ -1546,7 +1546,7 @@ CURLcode Curl_vsetopt(struct Curl_easy *data, CURLoption option,
c3d52c
     /*
c3d52c
      * String that holds file type of the SSL certificate to use
c3d52c
      */
c3d52c
-    result = Curl_setstropt(&data->set.str[STRING_CERT_TYPE_ORIG],
c3d52c
+    result = Curl_setstropt(&data->set.str[STRING_CERT_TYPE],
c3d52c
                             va_arg(param, char *));
c3d52c
     break;
c3d52c
   case CURLOPT_PROXY_SSLCERTTYPE:
c3d52c
@@ -1560,7 +1560,7 @@ CURLcode Curl_vsetopt(struct Curl_easy *data, CURLoption option,
c3d52c
     /*
c3d52c
      * String that holds file name of the SSL key to use
c3d52c
      */
c3d52c
-    result = Curl_setstropt(&data->set.str[STRING_KEY_ORIG],
c3d52c
+    result = Curl_setstropt(&data->set.str[STRING_KEY],
c3d52c
                             va_arg(param, char *));
c3d52c
     break;
c3d52c
   case CURLOPT_PROXY_SSLKEY:
c3d52c
@@ -1574,7 +1574,7 @@ CURLcode Curl_vsetopt(struct Curl_easy *data, CURLoption option,
c3d52c
     /*
c3d52c
      * String that holds file type of the SSL key to use
c3d52c
      */
c3d52c
-    result = Curl_setstropt(&data->set.str[STRING_KEY_TYPE_ORIG],
c3d52c
+    result = Curl_setstropt(&data->set.str[STRING_KEY_TYPE],
c3d52c
                             va_arg(param, char *));
c3d52c
     break;
c3d52c
   case CURLOPT_PROXY_SSLKEYTYPE:
c3d52c
@@ -1588,7 +1588,7 @@ CURLcode Curl_vsetopt(struct Curl_easy *data, CURLoption option,
c3d52c
     /*
c3d52c
      * String that holds the SSL or SSH private key password.
c3d52c
      */
c3d52c
-    result = Curl_setstropt(&data->set.str[STRING_KEY_PASSWD_ORIG],
c3d52c
+    result = Curl_setstropt(&data->set.str[STRING_KEY_PASSWD],
c3d52c
                             va_arg(param, char *));
c3d52c
     break;
c3d52c
   case CURLOPT_PROXY_KEYPASSWD:
c3d52c
@@ -1815,7 +1815,7 @@ CURLcode Curl_vsetopt(struct Curl_easy *data, CURLoption option,
c3d52c
      */
c3d52c
 #ifdef USE_SSL
c3d52c
     if(Curl_ssl->supports & SSLSUPP_PINNEDPUBKEY)
c3d52c
-      result = Curl_setstropt(&data->set.str[STRING_SSL_PINNEDPUBLICKEY_ORIG],
c3d52c
+      result = Curl_setstropt(&data->set.str[STRING_SSL_PINNEDPUBLICKEY],
c3d52c
                               va_arg(param, char *));
c3d52c
     else
c3d52c
 #endif
c3d52c
@@ -1838,7 +1838,7 @@ CURLcode Curl_vsetopt(struct Curl_easy *data, CURLoption option,
c3d52c
     /*
c3d52c
      * Set CA info for SSL connection. Specify file name of the CA certificate
c3d52c
      */
c3d52c
-    result = Curl_setstropt(&data->set.str[STRING_SSL_CAFILE_ORIG],
c3d52c
+    result = Curl_setstropt(&data->set.str[STRING_SSL_CAFILE],
c3d52c
                             va_arg(param, char *));
c3d52c
     break;
c3d52c
   case CURLOPT_PROXY_CAINFO:
c3d52c
@@ -1857,7 +1857,7 @@ CURLcode Curl_vsetopt(struct Curl_easy *data, CURLoption option,
c3d52c
 #ifdef USE_SSL
c3d52c
     if(Curl_ssl->supports & SSLSUPP_CA_PATH)
c3d52c
       /* This does not work on windows. */
c3d52c
-      result = Curl_setstropt(&data->set.str[STRING_SSL_CAPATH_ORIG],
c3d52c
+      result = Curl_setstropt(&data->set.str[STRING_SSL_CAPATH],
c3d52c
                               va_arg(param, char *));
c3d52c
     else
c3d52c
 #endif
c3d52c
@@ -1882,7 +1882,7 @@ CURLcode Curl_vsetopt(struct Curl_easy *data, CURLoption option,
c3d52c
      * Set CRL file info for SSL connection. Specify file name of the CRL
c3d52c
      * to check certificates revocation
c3d52c
      */
c3d52c
-    result = Curl_setstropt(&data->set.str[STRING_SSL_CRLFILE_ORIG],
c3d52c
+    result = Curl_setstropt(&data->set.str[STRING_SSL_CRLFILE],
c3d52c
                             va_arg(param, char *));
c3d52c
     break;
c3d52c
   case CURLOPT_PROXY_CRLFILE:
c3d52c
@@ -1898,7 +1898,7 @@ CURLcode Curl_vsetopt(struct Curl_easy *data, CURLoption option,
c3d52c
      * Set Issuer certificate file
c3d52c
      * to check certificates issuer
c3d52c
      */
c3d52c
-    result = Curl_setstropt(&data->set.str[STRING_SSL_ISSUERCERT_ORIG],
c3d52c
+    result = Curl_setstropt(&data->set.str[STRING_SSL_ISSUERCERT],
c3d52c
                             va_arg(param, char *));
c3d52c
     break;
c3d52c
   case CURLOPT_TELNETOPTIONS:
c3d52c
@@ -2449,9 +2449,9 @@ CURLcode Curl_vsetopt(struct Curl_easy *data, CURLoption option,
c3d52c
     break;
c3d52c
 #ifdef USE_TLS_SRP
c3d52c
   case CURLOPT_TLSAUTH_USERNAME:
c3d52c
-    result = Curl_setstropt(&data->set.str[STRING_TLSAUTH_USERNAME_ORIG],
c3d52c
+    result = Curl_setstropt(&data->set.str[STRING_TLSAUTH_USERNAME],
c3d52c
                             va_arg(param, char *));
c3d52c
-    if(data->set.str[STRING_TLSAUTH_USERNAME_ORIG] && !data->set.ssl.authtype)
c3d52c
+    if(data->set.str[STRING_TLSAUTH_USERNAME] && !data->set.ssl.authtype)
c3d52c
       data->set.ssl.authtype = CURL_TLSAUTH_SRP; /* default to SRP */
c3d52c
     break;
c3d52c
   case CURLOPT_PROXY_TLSAUTH_USERNAME:
c3d52c
@@ -2462,9 +2462,9 @@ CURLcode Curl_vsetopt(struct Curl_easy *data, CURLoption option,
c3d52c
       data->set.proxy_ssl.authtype = CURL_TLSAUTH_SRP; /* default to SRP */
c3d52c
     break;
c3d52c
   case CURLOPT_TLSAUTH_PASSWORD:
c3d52c
-    result = Curl_setstropt(&data->set.str[STRING_TLSAUTH_PASSWORD_ORIG],
c3d52c
+    result = Curl_setstropt(&data->set.str[STRING_TLSAUTH_PASSWORD],
c3d52c
                             va_arg(param, char *));
c3d52c
-    if(data->set.str[STRING_TLSAUTH_USERNAME_ORIG] && !data->set.ssl.authtype)
c3d52c
+    if(data->set.str[STRING_TLSAUTH_USERNAME] && !data->set.ssl.authtype)
c3d52c
       data->set.ssl.authtype = CURL_TLSAUTH_SRP; /* default to SRP */
c3d52c
     break;
c3d52c
   case CURLOPT_PROXY_TLSAUTH_PASSWORD:
c3d52c
diff --git a/lib/url.c b/lib/url.c
c3d52c
index bb9d107..a6bc012 100644
c3d52c
--- a/lib/url.c
c3d52c
+++ b/lib/url.c
c3d52c
@@ -496,7 +496,7 @@ CURLcode Curl_init_userdefined(struct Curl_easy *data)
c3d52c
    */
c3d52c
   if(Curl_ssl_backend() != CURLSSLBACKEND_SCHANNEL) {
c3d52c
 #if defined(CURL_CA_BUNDLE)
c3d52c
-    result = Curl_setstropt(&set->str[STRING_SSL_CAFILE_ORIG], CURL_CA_BUNDLE);
c3d52c
+    result = Curl_setstropt(&set->str[STRING_SSL_CAFILE], CURL_CA_BUNDLE);
c3d52c
     if(result)
c3d52c
       return result;
c3d52c
 
c3d52c
@@ -506,7 +506,7 @@ CURLcode Curl_init_userdefined(struct Curl_easy *data)
c3d52c
       return result;
c3d52c
 #endif
c3d52c
 #if defined(CURL_CA_PATH)
c3d52c
-    result = Curl_setstropt(&set->str[STRING_SSL_CAPATH_ORIG], CURL_CA_PATH);
c3d52c
+    result = Curl_setstropt(&set->str[STRING_SSL_CAPATH], CURL_CA_PATH);
c3d52c
     if(result)
c3d52c
       return result;
c3d52c
 
c3d52c
@@ -4333,9 +4333,9 @@ static CURLcode create_conn(struct Curl_easy *data,
c3d52c
      that will be freed as part of the Curl_easy struct, but all cloned
c3d52c
      copies will be separately allocated.
c3d52c
   */
c3d52c
-  data->set.ssl.primary.CApath = data->set.str[STRING_SSL_CAPATH_ORIG];
c3d52c
+  data->set.ssl.primary.CApath = data->set.str[STRING_SSL_CAPATH];
c3d52c
   data->set.proxy_ssl.primary.CApath = data->set.str[STRING_SSL_CAPATH_PROXY];
c3d52c
-  data->set.ssl.primary.CAfile = data->set.str[STRING_SSL_CAFILE_ORIG];
c3d52c
+  data->set.ssl.primary.CAfile = data->set.str[STRING_SSL_CAFILE];
c3d52c
   data->set.proxy_ssl.primary.CAfile = data->set.str[STRING_SSL_CAFILE_PROXY];
c3d52c
   data->set.ssl.primary.random_file = data->set.str[STRING_SSL_RANDOM_FILE];
c3d52c
   data->set.proxy_ssl.primary.random_file =
c3d52c
@@ -4343,34 +4343,34 @@ static CURLcode create_conn(struct Curl_easy *data,
c3d52c
   data->set.ssl.primary.egdsocket = data->set.str[STRING_SSL_EGDSOCKET];
c3d52c
   data->set.proxy_ssl.primary.egdsocket = data->set.str[STRING_SSL_EGDSOCKET];
c3d52c
   data->set.ssl.primary.cipher_list =
c3d52c
-    data->set.str[STRING_SSL_CIPHER_LIST_ORIG];
c3d52c
+    data->set.str[STRING_SSL_CIPHER_LIST];
c3d52c
   data->set.proxy_ssl.primary.cipher_list =
c3d52c
     data->set.str[STRING_SSL_CIPHER_LIST_PROXY];
c3d52c
   data->set.ssl.primary.cipher_list13 =
c3d52c
-    data->set.str[STRING_SSL_CIPHER13_LIST_ORIG];
c3d52c
+    data->set.str[STRING_SSL_CIPHER13_LIST];
c3d52c
   data->set.proxy_ssl.primary.cipher_list13 =
c3d52c
     data->set.str[STRING_SSL_CIPHER13_LIST_PROXY];
c3d52c
 
c3d52c
-  data->set.ssl.CRLfile = data->set.str[STRING_SSL_CRLFILE_ORIG];
c3d52c
+  data->set.ssl.CRLfile = data->set.str[STRING_SSL_CRLFILE];
c3d52c
   data->set.proxy_ssl.CRLfile = data->set.str[STRING_SSL_CRLFILE_PROXY];
c3d52c
-  data->set.ssl.issuercert = data->set.str[STRING_SSL_ISSUERCERT_ORIG];
c3d52c
+  data->set.ssl.issuercert = data->set.str[STRING_SSL_ISSUERCERT];
c3d52c
   data->set.proxy_ssl.issuercert = data->set.str[STRING_SSL_ISSUERCERT_PROXY];
c3d52c
-  data->set.ssl.cert = data->set.str[STRING_CERT_ORIG];
c3d52c
+  data->set.ssl.cert = data->set.str[STRING_CERT];
c3d52c
   data->set.proxy_ssl.cert = data->set.str[STRING_CERT_PROXY];
c3d52c
-  data->set.ssl.cert_type = data->set.str[STRING_CERT_TYPE_ORIG];
c3d52c
+  data->set.ssl.cert_type = data->set.str[STRING_CERT_TYPE];
c3d52c
   data->set.proxy_ssl.cert_type = data->set.str[STRING_CERT_TYPE_PROXY];
c3d52c
-  data->set.ssl.key = data->set.str[STRING_KEY_ORIG];
c3d52c
+  data->set.ssl.key = data->set.str[STRING_KEY];
c3d52c
   data->set.proxy_ssl.key = data->set.str[STRING_KEY_PROXY];
c3d52c
-  data->set.ssl.key_type = data->set.str[STRING_KEY_TYPE_ORIG];
c3d52c
+  data->set.ssl.key_type = data->set.str[STRING_KEY_TYPE];
c3d52c
   data->set.proxy_ssl.key_type = data->set.str[STRING_KEY_TYPE_PROXY];
c3d52c
-  data->set.ssl.key_passwd = data->set.str[STRING_KEY_PASSWD_ORIG];
c3d52c
+  data->set.ssl.key_passwd = data->set.str[STRING_KEY_PASSWD];
c3d52c
   data->set.proxy_ssl.key_passwd = data->set.str[STRING_KEY_PASSWD_PROXY];
c3d52c
-  data->set.ssl.primary.clientcert = data->set.str[STRING_CERT_ORIG];
c3d52c
+  data->set.ssl.primary.clientcert = data->set.str[STRING_CERT];
c3d52c
   data->set.proxy_ssl.primary.clientcert = data->set.str[STRING_CERT_PROXY];
c3d52c
 #ifdef USE_TLS_SRP
c3d52c
-  data->set.ssl.username = data->set.str[STRING_TLSAUTH_USERNAME_ORIG];
c3d52c
+  data->set.ssl.username = data->set.str[STRING_TLSAUTH_USERNAME];
c3d52c
   data->set.proxy_ssl.username = data->set.str[STRING_TLSAUTH_USERNAME_PROXY];
c3d52c
-  data->set.ssl.password = data->set.str[STRING_TLSAUTH_PASSWORD_ORIG];
c3d52c
+  data->set.ssl.password = data->set.str[STRING_TLSAUTH_PASSWORD];
c3d52c
   data->set.proxy_ssl.password = data->set.str[STRING_TLSAUTH_PASSWORD_PROXY];
c3d52c
 #endif
c3d52c
 
c3d52c
diff --git a/lib/urldata.h b/lib/urldata.h
c3d52c
index c70290a..1f8f364 100644
c3d52c
--- a/lib/urldata.h
c3d52c
+++ b/lib/urldata.h
c3d52c
@@ -1366,9 +1366,9 @@ struct DynamicStatic {
c3d52c
 struct Curl_multi;    /* declared and used only in multi.c */
c3d52c
 
c3d52c
 enum dupstring {
c3d52c
-  STRING_CERT_ORIG,       /* client certificate file name */
c3d52c
+  STRING_CERT,            /* client certificate file name */
c3d52c
   STRING_CERT_PROXY,      /* client certificate file name */
c3d52c
-  STRING_CERT_TYPE_ORIG,  /* format for certificate (default: PEM)*/
c3d52c
+  STRING_CERT_TYPE,       /* format for certificate (default: PEM)*/
c3d52c
   STRING_CERT_TYPE_PROXY, /* format for certificate (default: PEM)*/
c3d52c
   STRING_COOKIE,          /* HTTP cookie string to send */
c3d52c
   STRING_COOKIEJAR,       /* dump all cookies to this file */
c3d52c
@@ -1379,11 +1379,11 @@ enum dupstring {
c3d52c
   STRING_FTP_ACCOUNT,     /* ftp account data */
c3d52c
   STRING_FTP_ALTERNATIVE_TO_USER, /* command to send if USER/PASS fails */
c3d52c
   STRING_FTPPORT,         /* port to send with the FTP PORT command */
c3d52c
-  STRING_KEY_ORIG,        /* private key file name */
c3d52c
+  STRING_KEY,             /* private key file name */
c3d52c
   STRING_KEY_PROXY,       /* private key file name */
c3d52c
-  STRING_KEY_PASSWD_ORIG, /* plain text private key password */
c3d52c
+  STRING_KEY_PASSWD,      /* plain text private key password */
c3d52c
   STRING_KEY_PASSWD_PROXY, /* plain text private key password */
c3d52c
-  STRING_KEY_TYPE_ORIG,   /* format for private key (default: PEM) */
c3d52c
+  STRING_KEY_TYPE,        /* format for private key (default: PEM) */
c3d52c
   STRING_KEY_TYPE_PROXY,  /* format for private key (default: PEM) */
c3d52c
   STRING_KRB_LEVEL,       /* krb security level */
c3d52c
   STRING_NETRC_FILE,      /* if not NULL, use this instead of trying to find
c3d52c
@@ -1393,22 +1393,22 @@ enum dupstring {
c3d52c
   STRING_SET_RANGE,       /* range, if used */
c3d52c
   STRING_SET_REFERER,     /* custom string for the HTTP referer field */
c3d52c
   STRING_SET_URL,         /* what original URL to work on */
c3d52c
-  STRING_SSL_CAPATH_ORIG, /* CA directory name (doesn't work on windows) */
c3d52c
+  STRING_SSL_CAPATH,      /* CA directory name (doesn't work on windows) */
c3d52c
   STRING_SSL_CAPATH_PROXY, /* CA directory name (doesn't work on windows) */
c3d52c
-  STRING_SSL_CAFILE_ORIG, /* certificate file to verify peer against */
c3d52c
+  STRING_SSL_CAFILE,      /* certificate file to verify peer against */
c3d52c
   STRING_SSL_CAFILE_PROXY, /* certificate file to verify peer against */
c3d52c
-  STRING_SSL_PINNEDPUBLICKEY_ORIG, /* public key file to verify peer against */
c3d52c
+  STRING_SSL_PINNEDPUBLICKEY, /* public key file to verify peer against */
c3d52c
   STRING_SSL_PINNEDPUBLICKEY_PROXY, /* public key file to verify proxy */
c3d52c
-  STRING_SSL_CIPHER_LIST_ORIG, /* list of ciphers to use */
c3d52c
+  STRING_SSL_CIPHER_LIST, /* list of ciphers to use */
c3d52c
   STRING_SSL_CIPHER_LIST_PROXY, /* list of ciphers to use */
c3d52c
-  STRING_SSL_CIPHER13_LIST_ORIG, /* list of TLS 1.3 ciphers to use */
c3d52c
+  STRING_SSL_CIPHER13_LIST, /* list of TLS 1.3 ciphers to use */
c3d52c
   STRING_SSL_CIPHER13_LIST_PROXY, /* list of TLS 1.3 ciphers to use */
c3d52c
   STRING_SSL_EGDSOCKET,   /* path to file containing the EGD daemon socket */
c3d52c
   STRING_SSL_RANDOM_FILE, /* path to file containing "random" data */
c3d52c
   STRING_USERAGENT,       /* User-Agent string */
c3d52c
-  STRING_SSL_CRLFILE_ORIG, /* crl file to check certificate */
c3d52c
+  STRING_SSL_CRLFILE,     /* crl file to check certificate */
c3d52c
   STRING_SSL_CRLFILE_PROXY, /* crl file to check certificate */
c3d52c
-  STRING_SSL_ISSUERCERT_ORIG, /* issuer cert file to check certificate */
c3d52c
+  STRING_SSL_ISSUERCERT, /* issuer cert file to check certificate */
c3d52c
   STRING_SSL_ISSUERCERT_PROXY, /* issuer cert file to check certificate */
c3d52c
   STRING_SSL_ENGINE,      /* name of ssl engine */
c3d52c
   STRING_USERNAME,        /* <username>, if used */
c3d52c
@@ -1433,9 +1433,9 @@ enum dupstring {
c3d52c
   STRING_MAIL_AUTH,
c3d52c
 
c3d52c
 #ifdef USE_TLS_SRP
c3d52c
-  STRING_TLSAUTH_USERNAME_ORIG,  /* TLS auth <username> */
c3d52c
+  STRING_TLSAUTH_USERNAME,  /* TLS auth <username> */
c3d52c
   STRING_TLSAUTH_USERNAME_PROXY, /* TLS auth <username> */
c3d52c
-  STRING_TLSAUTH_PASSWORD_ORIG,  /* TLS auth <password> */
c3d52c
+  STRING_TLSAUTH_PASSWORD,  /* TLS auth <password> */
c3d52c
   STRING_TLSAUTH_PASSWORD_PROXY, /* TLS auth <password> */
c3d52c
 #endif
c3d52c
   STRING_BEARER,                /* <bearer>, if used */
c3d52c
diff --git a/lib/vtls/cyassl.c b/lib/vtls/cyassl.c
c3d52c
index e10398a..ffd116d 100644
c3d52c
--- a/lib/vtls/cyassl.c
c3d52c
+++ b/lib/vtls/cyassl.c
c3d52c
@@ -474,7 +474,7 @@ cyassl_connect_step2(struct connectdata *conn,
c3d52c
     conn->http_proxy.host.dispname : conn->host.dispname;
c3d52c
   const char * const pinnedpubkey = SSL_IS_PROXY() ?
c3d52c
                         data->set.str[STRING_SSL_PINNEDPUBLICKEY_PROXY] :
c3d52c
-                        data->set.str[STRING_SSL_PINNEDPUBLICKEY_ORIG];
c3d52c
+                        data->set.str[STRING_SSL_PINNEDPUBLICKEY];
c3d52c
 
c3d52c
   conn->recv[sockindex] = cyassl_recv;
c3d52c
   conn->send[sockindex] = cyassl_send;
c3d52c
diff --git a/lib/vtls/darwinssl.c b/lib/vtls/darwinssl.c
c3d52c
index 1aea0dc..572e8bf 100644
c3d52c
--- a/lib/vtls/darwinssl.c
c3d52c
+++ b/lib/vtls/darwinssl.c
c3d52c
@@ -2449,9 +2449,9 @@ darwinssl_connect_step2(struct connectdata *conn, int sockindex)
c3d52c
     connssl->connecting_state = ssl_connect_3;
c3d52c
 
c3d52c
 #ifdef DARWIN_SSL_PINNEDPUBKEY
c3d52c
-    if(data->set.str[STRING_SSL_PINNEDPUBLICKEY_ORIG]) {
c3d52c
+    if(data->set.str[STRING_SSL_PINNEDPUBLICKEY]) {
c3d52c
       CURLcode result = pkp_pin_peer_pubkey(data, BACKEND->ssl_ctx,
c3d52c
-                            data->set.str[STRING_SSL_PINNEDPUBLICKEY_ORIG]);
c3d52c
+                            data->set.str[STRING_SSL_PINNEDPUBLICKEY]);
c3d52c
       if(result) {
c3d52c
         failf(data, "SSL: public key does not match pinned public key!");
c3d52c
         return result;
c3d52c
diff --git a/lib/vtls/gskit.c b/lib/vtls/gskit.c
c3d52c
index a0b4960..b4c7b8a 100644
c3d52c
--- a/lib/vtls/gskit.c
c3d52c
+++ b/lib/vtls/gskit.c
c3d52c
@@ -1136,7 +1136,7 @@ static CURLcode gskit_connect_step3(struct connectdata *conn, int sockindex)
c3d52c
 
c3d52c
   /* Check pinned public key. */
c3d52c
   ptr = SSL_IS_PROXY() ? data->set.str[STRING_SSL_PINNEDPUBLICKEY_PROXY] :
c3d52c
-                         data->set.str[STRING_SSL_PINNEDPUBLICKEY_ORIG];
c3d52c
+    data->set.str[STRING_SSL_PINNEDPUBLICKEY];
c3d52c
   if(!result && ptr) {
c3d52c
     curl_X509certificate x509;
c3d52c
     curl_asn1Element *p;
c3d52c
diff --git a/lib/vtls/gtls.c b/lib/vtls/gtls.c
c3d52c
index 207b0fd..c5eb948 100644
c3d52c
--- a/lib/vtls/gtls.c
c3d52c
+++ b/lib/vtls/gtls.c
c3d52c
@@ -1329,7 +1329,7 @@ gtls_connect_step3(struct connectdata *conn,
c3d52c
   }
c3d52c
 
c3d52c
   ptr = SSL_IS_PROXY() ? data->set.str[STRING_SSL_PINNEDPUBLICKEY_PROXY] :
c3d52c
-        data->set.str[STRING_SSL_PINNEDPUBLICKEY_ORIG];
c3d52c
+    data->set.str[STRING_SSL_PINNEDPUBLICKEY];
c3d52c
   if(ptr) {
c3d52c
     result = pkp_pin_peer_pubkey(data, x509_cert, ptr);
c3d52c
     if(result != CURLE_OK) {
c3d52c
diff --git a/lib/vtls/mbedtls.c b/lib/vtls/mbedtls.c
c3d52c
index d7759dc..48010ae 100644
c3d52c
--- a/lib/vtls/mbedtls.c
c3d52c
+++ b/lib/vtls/mbedtls.c
c3d52c
@@ -540,7 +540,7 @@ mbed_connect_step2(struct connectdata *conn,
c3d52c
   const mbedtls_x509_crt *peercert;
c3d52c
   const char * const pinnedpubkey = SSL_IS_PROXY() ?
c3d52c
         data->set.str[STRING_SSL_PINNEDPUBLICKEY_PROXY] :
c3d52c
-        data->set.str[STRING_SSL_PINNEDPUBLICKEY_ORIG];
c3d52c
+        data->set.str[STRING_SSL_PINNEDPUBLICKEY];
c3d52c
 
c3d52c
 #ifdef HAS_ALPN
c3d52c
   const char *next_protocol;
c3d52c
diff --git a/lib/vtls/nss.c b/lib/vtls/nss.c
c3d52c
index 89f8183..366bf9e 100644
c3d52c
--- a/lib/vtls/nss.c
c3d52c
+++ b/lib/vtls/nss.c
c3d52c
@@ -2067,7 +2067,7 @@ static CURLcode nss_do_connect(struct connectdata *conn, int sockindex)
c3d52c
     &data->set.proxy_ssl.certverifyresult : &data->set.ssl.certverifyresult;
c3d52c
   const char * const pinnedpubkey = SSL_IS_PROXY() ?
c3d52c
               data->set.str[STRING_SSL_PINNEDPUBLICKEY_PROXY] :
c3d52c
-              data->set.str[STRING_SSL_PINNEDPUBLICKEY_ORIG];
c3d52c
+              data->set.str[STRING_SSL_PINNEDPUBLICKEY];
c3d52c
 
c3d52c
 
c3d52c
   /* check timeout situation */
c3d52c
diff --git a/lib/vtls/openssl.c b/lib/vtls/openssl.c
c3d52c
index 35cd652..8c97c1d 100644
c3d52c
--- a/lib/vtls/openssl.c
c3d52c
+++ b/lib/vtls/openssl.c
c3d52c
@@ -3388,7 +3388,7 @@ static CURLcode servercert(struct connectdata *conn,
c3d52c
     result = CURLE_OK;
c3d52c
 
c3d52c
   ptr = SSL_IS_PROXY() ? data->set.str[STRING_SSL_PINNEDPUBLICKEY_PROXY] :
c3d52c
-                         data->set.str[STRING_SSL_PINNEDPUBLICKEY_ORIG];
c3d52c
+    data->set.str[STRING_SSL_PINNEDPUBLICKEY];
c3d52c
   if(!result && ptr) {
c3d52c
     result = pkp_pin_peer_pubkey(data, BACKEND->server_cert, ptr);
c3d52c
     if(result)
c3d52c
diff --git a/lib/vtls/polarssl.c b/lib/vtls/polarssl.c
c3d52c
index 604cb4c..f284ad1 100644
c3d52c
--- a/lib/vtls/polarssl.c
c3d52c
+++ b/lib/vtls/polarssl.c
c3d52c
@@ -459,7 +459,7 @@ polarssl_connect_step2(struct connectdata *conn,
c3d52c
   char buffer[1024];
c3d52c
   const char * const pinnedpubkey = SSL_IS_PROXY() ?
c3d52c
             data->set.str[STRING_SSL_PINNEDPUBLICKEY_PROXY] :
c3d52c
-            data->set.str[STRING_SSL_PINNEDPUBLICKEY_ORIG];
c3d52c
+            data->set.str[STRING_SSL_PINNEDPUBLICKEY];
c3d52c
 
c3d52c
 
c3d52c
   char errorbuf[128];
c3d52c
diff --git a/lib/vtls/schannel.c b/lib/vtls/schannel.c
c3d52c
index 8f6c301..95c060b 100644
c3d52c
--- a/lib/vtls/schannel.c
c3d52c
+++ b/lib/vtls/schannel.c
c3d52c
@@ -1060,7 +1060,7 @@ schannel_connect_step2(struct connectdata *conn, int sockindex)
c3d52c
 
c3d52c
   pubkey_ptr = SSL_IS_PROXY() ?
c3d52c
     data->set.str[STRING_SSL_PINNEDPUBLICKEY_PROXY] :
c3d52c
-    data->set.str[STRING_SSL_PINNEDPUBLICKEY_ORIG];
c3d52c
+    data->set.str[STRING_SSL_PINNEDPUBLICKEY];
c3d52c
   if(pubkey_ptr) {
c3d52c
     result = pkp_pin_peer_pubkey(conn, sockindex, pubkey_ptr);
c3d52c
     if(result) {
c3d52c
-- 
c3d52c
2.31.1
c3d52c
c3d52c
c3d52c
From 040fa4f60f9b809972d51184dfa4980ba44d8b6b Mon Sep 17 00:00:00 2001
c3d52c
From: Daniel Stenberg <daniel@haxx.se>
c3d52c
Date: Sat, 19 Jun 2021 00:42:28 +0200
c3d52c
Subject: [PATCH 2/2] vtls: fix connection reuse checks for issuer cert and
c3d52c
 case sensitivity
c3d52c
c3d52c
CVE-2021-22924
c3d52c
c3d52c
Reported-by: Harry Sintonen
c3d52c
Bug: https://curl.se/docs/CVE-2021-22924.html
c3d52c
c3d52c
Upstream-commit: 5ea3145850ebff1dc2b13d17440300a01ca38161
c3d52c
Signed-off-by: Kamil Dudka <kdudka@redhat.com>
c3d52c
---
c3d52c
 lib/url.c          |  5 +++--
c3d52c
 lib/urldata.h      |  2 +-
c3d52c
 lib/vtls/gtls.c    | 10 +++++-----
c3d52c
 lib/vtls/nss.c     |  4 ++--
c3d52c
 lib/vtls/openssl.c | 12 ++++++------
c3d52c
 lib/vtls/vtls.c    | 21 ++++++++++++++++-----
c3d52c
 6 files changed, 33 insertions(+), 21 deletions(-)
c3d52c
c3d52c
diff --git a/lib/url.c b/lib/url.c
c3d52c
index a6bc012..4803653 100644
c3d52c
--- a/lib/url.c
c3d52c
+++ b/lib/url.c
c3d52c
@@ -4337,6 +4337,9 @@ static CURLcode create_conn(struct Curl_easy *data,
c3d52c
   data->set.proxy_ssl.primary.CApath = data->set.str[STRING_SSL_CAPATH_PROXY];
c3d52c
   data->set.ssl.primary.CAfile = data->set.str[STRING_SSL_CAFILE];
c3d52c
   data->set.proxy_ssl.primary.CAfile = data->set.str[STRING_SSL_CAFILE_PROXY];
c3d52c
+  data->set.ssl.primary.issuercert = data->set.str[STRING_SSL_ISSUERCERT];
c3d52c
+  data->set.proxy_ssl.primary.issuercert =
c3d52c
+    data->set.str[STRING_SSL_ISSUERCERT_PROXY];
c3d52c
   data->set.ssl.primary.random_file = data->set.str[STRING_SSL_RANDOM_FILE];
c3d52c
   data->set.proxy_ssl.primary.random_file =
c3d52c
     data->set.str[STRING_SSL_RANDOM_FILE];
c3d52c
@@ -4353,8 +4356,6 @@ static CURLcode create_conn(struct Curl_easy *data,
c3d52c
 
c3d52c
   data->set.ssl.CRLfile = data->set.str[STRING_SSL_CRLFILE];
c3d52c
   data->set.proxy_ssl.CRLfile = data->set.str[STRING_SSL_CRLFILE_PROXY];
c3d52c
-  data->set.ssl.issuercert = data->set.str[STRING_SSL_ISSUERCERT];
c3d52c
-  data->set.proxy_ssl.issuercert = data->set.str[STRING_SSL_ISSUERCERT_PROXY];
c3d52c
   data->set.ssl.cert = data->set.str[STRING_CERT];
c3d52c
   data->set.proxy_ssl.cert = data->set.str[STRING_CERT_PROXY];
c3d52c
   data->set.ssl.cert_type = data->set.str[STRING_CERT_TYPE];
c3d52c
diff --git a/lib/urldata.h b/lib/urldata.h
c3d52c
index 1f8f364..72a36fb 100644
c3d52c
--- a/lib/urldata.h
c3d52c
+++ b/lib/urldata.h
c3d52c
@@ -223,6 +223,7 @@ struct ssl_primary_config {
c3d52c
   bool sessionid;        /* cache session IDs or not */
c3d52c
   char *CApath;          /* certificate dir (doesn't work on windows) */
c3d52c
   char *CAfile;          /* certificate to verify peer against */
c3d52c
+  char *issuercert;      /* optional issuer certificate filename */
c3d52c
   char *clientcert;
c3d52c
   char *random_file;     /* path to file containing "random" data */
c3d52c
   char *egdsocket;       /* path to file containing the EGD daemon socket */
c3d52c
@@ -238,7 +239,6 @@ struct ssl_config_data {
c3d52c
   bool no_partialchain;  /* don't accept partial certificate chains */
c3d52c
   long certverifyresult; /* result from the certificate verification */
c3d52c
   char *CRLfile;   /* CRL to check certificate revocation */
c3d52c
-  char *issuercert;/* optional issuer certificate filename */
c3d52c
   curl_ssl_ctx_callback fsslctx; /* function to initialize ssl ctx */
c3d52c
   void *fsslctxp;        /* parameter for call back */
c3d52c
   bool certinfo;         /* gather lots of certificate info */
c3d52c
diff --git a/lib/vtls/gtls.c b/lib/vtls/gtls.c
c3d52c
index c5eb948..0cb59c8 100644
c3d52c
--- a/lib/vtls/gtls.c
c3d52c
+++ b/lib/vtls/gtls.c
c3d52c
@@ -1002,7 +1002,7 @@ gtls_connect_step3(struct connectdata *conn,
c3d52c
   if(!chainp) {
c3d52c
     if(SSL_CONN_CONFIG(verifypeer) ||
c3d52c
        SSL_CONN_CONFIG(verifyhost) ||
c3d52c
-       SSL_SET_OPTION(issuercert)) {
c3d52c
+       SSL_CONN_CONFIG(issuercert)) {
c3d52c
 #ifdef USE_TLS_SRP
c3d52c
       if(SSL_SET_OPTION(authtype) == CURL_TLSAUTH_SRP
c3d52c
          && SSL_SET_OPTION(username) != NULL
c3d52c
@@ -1184,21 +1184,21 @@ gtls_connect_step3(struct connectdata *conn,
c3d52c
        gnutls_x509_crt_t format */
c3d52c
     gnutls_x509_crt_import(x509_cert, chainp, GNUTLS_X509_FMT_DER);
c3d52c
 
c3d52c
-  if(SSL_SET_OPTION(issuercert)) {
c3d52c
+  if(SSL_CONN_CONFIG(issuercert)) {
c3d52c
     gnutls_x509_crt_init(&x509_issuer);
c3d52c
-    issuerp = load_file(SSL_SET_OPTION(issuercert));
c3d52c
+    issuerp = load_file(SSL_CONN_CONFIG(issuercert));
c3d52c
     gnutls_x509_crt_import(x509_issuer, &issuerp, GNUTLS_X509_FMT_PEM);
c3d52c
     rc = gnutls_x509_crt_check_issuer(x509_cert, x509_issuer);
c3d52c
     gnutls_x509_crt_deinit(x509_issuer);
c3d52c
     unload_file(issuerp);
c3d52c
     if(rc <= 0) {
c3d52c
       failf(data, "server certificate issuer check failed (IssuerCert: %s)",
c3d52c
-            SSL_SET_OPTION(issuercert)?SSL_SET_OPTION(issuercert):"none");
c3d52c
+            SSL_CONN_CONFIG(issuercert)?SSL_CONN_CONFIG(issuercert):"none");
c3d52c
       gnutls_x509_crt_deinit(x509_cert);
c3d52c
       return CURLE_SSL_ISSUER_ERROR;
c3d52c
     }
c3d52c
     infof(data, "\t server certificate issuer check OK (Issuer Cert: %s)\n",
c3d52c
-          SSL_SET_OPTION(issuercert)?SSL_SET_OPTION(issuercert):"none");
c3d52c
+          SSL_CONN_CONFIG(issuercert)?SSL_CONN_CONFIG(issuercert):"none");
c3d52c
   }
c3d52c
 
c3d52c
   size = sizeof(certbuf);
c3d52c
diff --git a/lib/vtls/nss.c b/lib/vtls/nss.c
c3d52c
index 366bf9e..2d9581d 100644
c3d52c
--- a/lib/vtls/nss.c
c3d52c
+++ b/lib/vtls/nss.c
c3d52c
@@ -2095,9 +2095,9 @@ static CURLcode nss_do_connect(struct connectdata *conn, int sockindex)
c3d52c
   if(result)
c3d52c
     goto error;
c3d52c
 
c3d52c
-  if(SSL_SET_OPTION(issuercert)) {
c3d52c
+  if(SSL_CONN_CONFIG(issuercert)) {
c3d52c
     SECStatus ret = SECFailure;
c3d52c
-    char *nickname = dup_nickname(data, SSL_SET_OPTION(issuercert));
c3d52c
+    char *nickname = dup_nickname(data, SSL_CONN_CONFIG(issuercert));
c3d52c
     if(nickname) {
c3d52c
       /* we support only nicknames in case of issuercert for now */
c3d52c
       ret = check_issuer_cert(BACKEND->handle, nickname);
c3d52c
diff --git a/lib/vtls/openssl.c b/lib/vtls/openssl.c
c3d52c
index 8c97c1d..28eaa6d 100644
c3d52c
--- a/lib/vtls/openssl.c
c3d52c
+++ b/lib/vtls/openssl.c
c3d52c
@@ -3311,11 +3311,11 @@ static CURLcode servercert(struct connectdata *conn,
c3d52c
        deallocating the certificate. */
c3d52c
 
c3d52c
     /* e.g. match issuer name with provided issuer certificate */
c3d52c
-    if(SSL_SET_OPTION(issuercert)) {
c3d52c
-      if(BIO_read_filename(fp, SSL_SET_OPTION(issuercert)) <= 0) {
c3d52c
+    if(SSL_CONN_CONFIG(issuercert)) {
c3d52c
+      if(BIO_read_filename(fp, SSL_CONN_CONFIG(issuercert)) <= 0) {
c3d52c
         if(strict)
c3d52c
           failf(data, "SSL: Unable to open issuer cert (%s)",
c3d52c
-                SSL_SET_OPTION(issuercert));
c3d52c
+                SSL_CONN_CONFIG(issuercert));
c3d52c
         BIO_free(fp);
c3d52c
         X509_free(BACKEND->server_cert);
c3d52c
         BACKEND->server_cert = NULL;
c3d52c
@@ -3326,7 +3326,7 @@ static CURLcode servercert(struct connectdata *conn,
c3d52c
       if(!issuer) {
c3d52c
         if(strict)
c3d52c
           failf(data, "SSL: Unable to read issuer cert (%s)",
c3d52c
-                SSL_SET_OPTION(issuercert));
c3d52c
+                SSL_CONN_CONFIG(issuercert));
c3d52c
         BIO_free(fp);
c3d52c
         X509_free(issuer);
c3d52c
         X509_free(BACKEND->server_cert);
c3d52c
@@ -3337,7 +3337,7 @@ static CURLcode servercert(struct connectdata *conn,
c3d52c
       if(X509_check_issued(issuer, BACKEND->server_cert) != X509_V_OK) {
c3d52c
         if(strict)
c3d52c
           failf(data, "SSL: Certificate issuer check failed (%s)",
c3d52c
-                SSL_SET_OPTION(issuercert));
c3d52c
+                SSL_CONN_CONFIG(issuercert));
c3d52c
         BIO_free(fp);
c3d52c
         X509_free(issuer);
c3d52c
         X509_free(BACKEND->server_cert);
c3d52c
@@ -3346,7 +3346,7 @@ static CURLcode servercert(struct connectdata *conn,
c3d52c
       }
c3d52c
 
c3d52c
       infof(data, " SSL certificate issuer check ok (%s)\n",
c3d52c
-            SSL_SET_OPTION(issuercert));
c3d52c
+            SSL_CONN_CONFIG(issuercert));
c3d52c
       X509_free(issuer);
c3d52c
     }
c3d52c
 
c3d52c
diff --git a/lib/vtls/vtls.c b/lib/vtls/vtls.c
c3d52c
index b61c640..18672a5 100644
c3d52c
--- a/lib/vtls/vtls.c
c3d52c
+++ b/lib/vtls/vtls.c
c3d52c
@@ -82,6 +82,15 @@
c3d52c
   else                                       \
c3d52c
     dest->var = NULL;
c3d52c
 
c3d52c
+static bool safecmp(char *a, char *b)
c3d52c
+{
c3d52c
+  if(a && b)
c3d52c
+    return !strcmp(a, b);
c3d52c
+  else if(!a && !b)
c3d52c
+    return TRUE; /* match */
c3d52c
+  return FALSE; /* no match */
c3d52c
+}
c3d52c
+
c3d52c
 bool
c3d52c
 Curl_ssl_config_matches(struct ssl_primary_config* data,
c3d52c
                         struct ssl_primary_config* needle)
c3d52c
@@ -91,11 +100,11 @@ Curl_ssl_config_matches(struct ssl_primary_config* data,
c3d52c
      (data->verifypeer == needle->verifypeer) &&
c3d52c
      (data->verifyhost == needle->verifyhost) &&
c3d52c
      (data->verifystatus == needle->verifystatus) &&
c3d52c
-     Curl_safe_strcasecompare(data->CApath, needle->CApath) &&
c3d52c
-     Curl_safe_strcasecompare(data->CAfile, needle->CAfile) &&
c3d52c
-     Curl_safe_strcasecompare(data->clientcert, needle->clientcert) &&
c3d52c
-     Curl_safe_strcasecompare(data->random_file, needle->random_file) &&
c3d52c
-     Curl_safe_strcasecompare(data->egdsocket, needle->egdsocket) &&
c3d52c
+     safecmp(data->CApath, needle->CApath) &&
c3d52c
+     safecmp(data->CAfile, needle->CAfile) &&
c3d52c
+     safecmp(data->clientcert, needle->clientcert) &&
c3d52c
+     safecmp(data->random_file, needle->random_file) &&
c3d52c
+     safecmp(data->egdsocket, needle->egdsocket) &&
c3d52c
      Curl_safe_strcasecompare(data->cipher_list, needle->cipher_list) &&
c3d52c
      Curl_safe_strcasecompare(data->cipher_list13, needle->cipher_list13))
c3d52c
     return TRUE;
c3d52c
@@ -116,6 +125,7 @@ Curl_clone_primary_ssl_config(struct ssl_primary_config *source,
c3d52c
 
c3d52c
   CLONE_STRING(CApath);
c3d52c
   CLONE_STRING(CAfile);
c3d52c
+  CLONE_STRING(issuercert);
c3d52c
   CLONE_STRING(clientcert);
c3d52c
   CLONE_STRING(random_file);
c3d52c
   CLONE_STRING(egdsocket);
c3d52c
@@ -129,6 +139,7 @@ void Curl_free_primary_ssl_config(struct ssl_primary_config* sslc)
c3d52c
 {
c3d52c
   Curl_safefree(sslc->CApath);
c3d52c
   Curl_safefree(sslc->CAfile);
c3d52c
+  Curl_safefree(sslc->issuercert);
c3d52c
   Curl_safefree(sslc->clientcert);
c3d52c
   Curl_safefree(sslc->random_file);
c3d52c
   Curl_safefree(sslc->egdsocket);
c3d52c
-- 
c3d52c
2.31.1
c3d52c