Blame SOURCES/sudo-1.8.6p7-newbase64decoder.patch

72fdaf
diff -up sudo-1.8.6p7/plugins/sudoers/match.c.newbase64decoder sudo-1.8.6p7/plugins/sudoers/match.c
72fdaf
--- sudo-1.8.6p7/plugins/sudoers/match.c.newbase64decoder	2015-09-01 13:35:42.746241825 +0200
72fdaf
+++ sudo-1.8.6p7/plugins/sudoers/match.c	2015-09-01 13:40:52.360233611 +0200
72fdaf
@@ -510,53 +510,60 @@ command_matches_glob(char *sudoers_cmnd,
72fdaf
 }
72fdaf
 
72fdaf
 /*
72fdaf
+ * base64 decoder
72fdaf
+ * PUBLIC DOMAIN - Jon Mayo - November 13, 2003
72fdaf
+ */
72fdaf
+static const uint8_t base64dec_tab[256]= {
72fdaf
+  255,255,255,255,255,255,255,255,255,255,255,255,255,255,255,255,
72fdaf
+  255,255,255,255,255,255,255,255,255,255,255,255,255,255,255,255,
72fdaf
+  255,255,255,255,255,255,255,255,255,255,255, 62,255,255,255, 63,
72fdaf
+  52, 53, 54, 55, 56, 57, 58, 59, 60, 61,255,255,255,  0,255,255,
72fdaf
+  255,  0,  1,  2,  3,  4,  5,  6,  7,  8,  9, 10, 11, 12, 13, 14,
72fdaf
+  15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25,255,255,255,255,255,
72fdaf
+  255, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 36, 37, 38, 39, 40,
72fdaf
+  41, 42, 43, 44, 45, 46, 47, 48, 49, 50, 51,255,255,255,255,255,
72fdaf
+  255,255,255,255,255,255,255,255,255,255,255,255,255,255,255,255,
72fdaf
+  255,255,255,255,255,255,255,255,255,255,255,255,255,255,255,255,
72fdaf
+  255,255,255,255,255,255,255,255,255,255,255,255,255,255,255,255,
72fdaf
+  255,255,255,255,255,255,255,255,255,255,255,255,255,255,255,255,
72fdaf
+  255,255,255,255,255,255,255,255,255,255,255,255,255,255,255,255,
72fdaf
+  255,255,255,255,255,255,255,255,255,255,255,255,255,255,255,255,
72fdaf
+  255,255,255,255,255,255,255,255,255,255,255,255,255,255,255,255,
72fdaf
+  255,255,255,255,255,255,255,255,255,255,255,255,255,255,255,255,
72fdaf
+};
72fdaf
+
72fdaf
+/*
72fdaf
  * Decode a NUL-terminated string in base64 format and store the
72fdaf
  * result in dst.
72fdaf
  */
72fdaf
 size_t
72fdaf
-base64_decode(const char *str, unsigned char *dst, size_t dsize)
72fdaf
+base64_decode(const char *in, unsigned char *out, size_t out_len)
72fdaf
 {
72fdaf
-    static const char b64[] =
72fdaf
-	"ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/";
72fdaf
-    const unsigned char *dst0 = dst;
72fdaf
-    const unsigned char *dend = dst + dsize;
72fdaf
-    unsigned char ch[4];
72fdaf
-    char *pos;
72fdaf
-    int i;
72fdaf
-    debug_decl(base64_decode, SUDO_DEBUG_MATCH)
72fdaf
+  size_t in_len = strlen(in);
72fdaf
+  size_t ii, io;
72fdaf
+  uint_least32_t v;
72fdaf
+  size_t rem;
72fdaf
 
72fdaf
-    /*
72fdaf
-     * Convert from base64 to binary.  Each base64 char holds 6 bits of data
72fdaf
-     * so 4 base64 chars equals 3 chars of data.
72fdaf
-     * Padding (with the '=' char) may or may not be present.
72fdaf
-     */
72fdaf
-    while (*str != '\0') {
72fdaf
-	for (i = 0; i < 4; i++) {
72fdaf
-	    switch (*str) {
72fdaf
-	    case '=':
72fdaf
-		str++;
72fdaf
-		/* FALLTHROUGH */
72fdaf
-	    case '\0':
72fdaf
-		ch[i] = '=';
72fdaf
-		break;
72fdaf
-	    default:
72fdaf
-		if ((pos = strchr(b64, *str++)) == NULL)
72fdaf
-		    debug_return_size_t((size_t)-1);
72fdaf
-		ch[i] = (unsigned char)(pos - b64);
72fdaf
-		break;
72fdaf
-	    }
72fdaf
-	}
72fdaf
-	if (ch[0] == '=' || ch[1] == '=' || dst == dend)
72fdaf
-	    break;
72fdaf
-	*dst++ = (ch[0] << 2) | ((ch[1] & 0x30) >> 4);
72fdaf
-	if (ch[2] == '=' || dst == dend)
72fdaf
-	    break;
72fdaf
-	*dst++ = ((ch[1] & 0x0f) << 4) | ((ch[2] & 0x3c) >> 2);
72fdaf
-	if (ch[3] == '=' || dst == dend)
72fdaf
-	    break;
72fdaf
-	*dst++ = ((ch[2] & 0x03) << 6) | ch[3];
72fdaf
+  for(io=0,ii=0,v=0,rem=0;ii
72fdaf
+    unsigned char ch;
72fdaf
+    if(isspace(in[ii])) continue;
72fdaf
+    if(in[ii]=='=') break; /* stop at = */
72fdaf
+    ch=base64dec_tab[(size_t)in[ii]];
72fdaf
+    if(ch==255) break; /* stop at a parse error */
72fdaf
+    v=(v<<6)|ch;
72fdaf
+    rem+=6;
72fdaf
+    if(rem>=8) {
72fdaf
+      rem-=8;
72fdaf
+      if(io>=out_len) return -1; /* truncation is failure */
72fdaf
+      out[io++]=(v>>rem)&255;
72fdaf
     }
72fdaf
-    debug_return_size_t((size_t)(dst - dst0));
72fdaf
+  }
72fdaf
+  if(rem>=8) {
72fdaf
+    rem-=8;
72fdaf
+    if(io>=out_len) return -1; /* truncation is failure */
72fdaf
+    out[io++]=(v>>rem)&255;
72fdaf
+  }
72fdaf
+  return io;
72fdaf
 }
72fdaf
 
72fdaf
 static bool