mirror of
https://github.com/NixOS/nixpkgs.git
synced 2026-10-02 04:50:21 +00:00
Merge pull request #256380 from risicle/ris-trafficserver-CVE-2022-47185-CVE-2023-33934-r23.05
[23.05] trafficserver: add patches for CVE-2022-47185 & CVE-2023-33934
This commit is contained in:
@@ -0,0 +1,101 @@
|
||||
Based on upstream fbb6acb1caac752e6719b912e0de971691c1ad99, adjusted to
|
||||
apply cleanly to 9.1.4
|
||||
|
||||
diff --git a/proxy/hdrs/URL.cc b/proxy/hdrs/URL.cc
|
||||
index 8124bb9f2..90973bbdd 100644
|
||||
--- a/proxy/hdrs/URL.cc
|
||||
+++ b/proxy/hdrs/URL.cc
|
||||
@@ -1524,8 +1524,13 @@ done:
|
||||
// correcting this behavior, therefore, we maintain the current
|
||||
// functionality but add state to determine whether the path was
|
||||
// absolutely empty so we can reconstruct such URLs.
|
||||
- ++path_start;
|
||||
+ //
|
||||
+ // Remove all preceding slashes
|
||||
+ while (path_start < path_end && *path_start == '/') {
|
||||
+ ++path_start;
|
||||
+ }
|
||||
}
|
||||
+
|
||||
url_path_set(heap, url, path_start, path_end - path_start, copy_strings);
|
||||
} else if (!nothing_after_host) {
|
||||
// There was no path set via '/': it is absolutely empty. However, if there
|
||||
@@ -1577,7 +1582,10 @@ url_parse_http_regex(HdrHeap *heap, URLImpl *url, const char **start, const char
|
||||
cur = static_cast<const char *>(memchr(cur, '/', end - cur));
|
||||
if (cur) {
|
||||
host_end = cur;
|
||||
- ++cur;
|
||||
+ // Remove all preceding slashes
|
||||
+ while (cur < end && *cur == '/') {
|
||||
+ cur++;
|
||||
+ }
|
||||
} else {
|
||||
host_end = cur = end;
|
||||
}
|
||||
diff --git a/proxy/hdrs/unit_tests/test_URL.cc b/proxy/hdrs/unit_tests/test_URL.cc
|
||||
index 115aeee5d..a06d1d5d0 100644
|
||||
--- a/proxy/hdrs/unit_tests/test_URL.cc
|
||||
+++ b/proxy/hdrs/unit_tests/test_URL.cc
|
||||
@@ -173,6 +173,14 @@ constexpr bool VERIFY_HOST_CHARACTERS = true;
|
||||
|
||||
// clang-format off
|
||||
std::vector<url_parse_test_case> url_parse_test_cases = {
|
||||
+ {
|
||||
+ "///dir////index.html",
|
||||
+ "/dir////index.html",
|
||||
+ VERIFY_HOST_CHARACTERS,
|
||||
+ "/dir////index.html",
|
||||
+ IS_VALID,
|
||||
+ IS_VALID
|
||||
+ },
|
||||
{
|
||||
"/index.html",
|
||||
"/index.html",
|
||||
@@ -183,9 +191,9 @@ std::vector<url_parse_test_case> url_parse_test_cases = {
|
||||
},
|
||||
{
|
||||
"//index.html",
|
||||
- "//index.html",
|
||||
+ "/index.html",
|
||||
VERIFY_HOST_CHARACTERS,
|
||||
- "//index.html",
|
||||
+ "/index.html",
|
||||
IS_VALID,
|
||||
IS_VALID
|
||||
},
|
||||
@@ -215,9 +223,9 @@ std::vector<url_parse_test_case> url_parse_test_cases = {
|
||||
// with two slash characters ("//"). We have historically allowed this,
|
||||
// however, and will continue to do so.
|
||||
"https:////",
|
||||
- "https:////",
|
||||
+ "https:///",
|
||||
VERIFY_HOST_CHARACTERS,
|
||||
- "https:////",
|
||||
+ "https:///",
|
||||
IS_VALID,
|
||||
IS_VALID
|
||||
},
|
||||
@@ -257,9 +265,9 @@ std::vector<url_parse_test_case> url_parse_test_cases = {
|
||||
},
|
||||
{
|
||||
"https://www.example.com//",
|
||||
- "https://www.example.com//",
|
||||
+ "https://www.example.com/",
|
||||
VERIFY_HOST_CHARACTERS,
|
||||
- "https://www.example.com//",
|
||||
+ "https://www.example.com/",
|
||||
IS_VALID,
|
||||
IS_VALID
|
||||
},
|
||||
@@ -313,9 +321,9 @@ std::vector<url_parse_test_case> url_parse_test_cases = {
|
||||
},
|
||||
{
|
||||
"https://www.example.com//a/path",
|
||||
- "https://www.example.com//a/path",
|
||||
+ "https://www.example.com/a/path",
|
||||
VERIFY_HOST_CHARACTERS,
|
||||
- "https://www.example.com//a/path",
|
||||
+ "https://www.example.com/a/path",
|
||||
IS_VALID,
|
||||
IS_VALID
|
||||
},
|
||||
@@ -74,6 +74,18 @@ stdenv.mkDerivation rec {
|
||||
})
|
||||
./9.1.4-CVE-2023-33933.patch
|
||||
./9.1.4-CVE-2023-30631.patch
|
||||
|
||||
(fetchpatch {
|
||||
name = "CVE-2022-47185.patch";
|
||||
url = "https://github.com/apache/trafficserver/commit/5d0835ea5a57003798497d07331fa4f89823c750.patch";
|
||||
sha256 = "sha256-h4vaa7UwWFmJ9ZOtZsHuExcZQMFG8IER4WFp1r7Ym+U=";
|
||||
})
|
||||
(fetchpatch {
|
||||
name = "CVE-2023-33934.patch";
|
||||
url = "https://github.com/apache/trafficserver/commit/32d93ad084d18ee592754e3736d960a4fd8ddfd2.patch";
|
||||
sha256 = "sha256-z3rCUe7MhKwnn8wzW6ba5ojdSAIhHkL/PNZqm04gNf4=";
|
||||
})
|
||||
./9.1.4-CVE-2023-33934.supplemental.patch
|
||||
];
|
||||
|
||||
# NOTE: The upstream README indicates that flex is needed for some features,
|
||||
|
||||
Reference in New Issue
Block a user