app-text/atril: Fix CVE-2017-1000083
authorNP-Hardass <NP-Hardass@gentoo.org>
Fri, 23 Feb 2018 20:19:06 +0000 (15:19 -0500)
committerNP-Hardass <NP-Hardass@gentoo.org>
Fri, 23 Feb 2018 20:22:55 +0000 (15:22 -0500)
Bug: https://bugs.gentoo.org/624880
Package-Manager: Portage-2.3.24, Repoman-2.3.6

app-text/atril/atril-1.12.2-r5.ebuild [moved from app-text/atril/atril-1.12.2-r4.ebuild with 96% similarity]
app-text/atril/atril-1.14.2-r2.ebuild [moved from app-text/atril/atril-1.14.2-r1.ebuild with 96% similarity]
app-text/atril/atril-1.16.1-r2.ebuild [moved from app-text/atril/atril-1.16.1-r1.ebuild with 96% similarity]
app-text/atril/files/atril-cve-2017-1000083.patch [new file with mode: 0644]

similarity index 96%
rename from app-text/atril/atril-1.12.2-r4.ebuild
rename to app-text/atril/atril-1.12.2-r5.ebuild
index aa353029fbdfded374e821e125e46cdbb0d393e2..360dac80db220b05b1e61e245612660d1147126d 100644 (file)
@@ -1,4 +1,4 @@
-# Copyright 1999-2017 Gentoo Foundation
+# Copyright 1999-2018 Gentoo Foundation
 # Distributed under the terms of the GNU General Public License v2
 
 EAPI=6
@@ -67,6 +67,8 @@ DEPEND="${RDEPEND}
 # Tests use dogtail which is not available on Gentoo.
 RESTRICT="test"
 
+FILES=( "${FILESDIR}/${PN}-cve-2017-1000083.patch" )
+
 src_configure() {
        # Passing --disable-help would drop offline help, that would be inconsistent
        # with helps of the most of GNOME apps that doesn't require network for that.
similarity index 96%
rename from app-text/atril/atril-1.14.2-r1.ebuild
rename to app-text/atril/atril-1.14.2-r2.ebuild
index 12e1ae529a2d9becbade8de21d8de21793850852..792c2c2e6a067757eda7c8147ab928a3fcd51431 100644 (file)
@@ -1,4 +1,4 @@
-# Copyright 1999-2017 Gentoo Foundation
+# Copyright 1999-2018 Gentoo Foundation
 # Distributed under the terms of the GNU General Public License v2
 
 EAPI=6
@@ -69,6 +69,8 @@ DEPEND="${COMMON_DEPEND}
 # Tests use dogtail which is not available on Gentoo.
 RESTRICT="test"
 
+FILES=( "${FILESDIR}/${PN}-cve-2017-1000083.patch" )
+
 src_configure() {
        # Passing --disable-help would drop offline help, that would be inconsistent
        # with helps of the most of GNOME apps that doesn't require network for that.
similarity index 96%
rename from app-text/atril/atril-1.16.1-r1.ebuild
rename to app-text/atril/atril-1.16.1-r2.ebuild
index 4259cddf89bc429a7795a5eb0fb6fb92f149fd3f..24aad9d4f3c7e2088c289398291de1814a9692d1 100644 (file)
@@ -1,4 +1,4 @@
-# Copyright 1999-2017 Gentoo Foundation
+# Copyright 1999-2018 Gentoo Foundation
 # Distributed under the terms of the GNU General Public License v2
 
 EAPI=6
@@ -68,6 +68,8 @@ DEPEND="${COMMON_DEPEND}
 # Tests use dogtail which is not available on Gentoo.
 RESTRICT="test"
 
+FILES=( "${FILESDIR}/${PN}-cve-2017-1000083.patch" )
+
 src_configure() {
        # Passing --disable-help would drop offline help, that would be inconsistent
        # with helps of the most of GNOME apps that doesn't require network for that.
diff --git a/app-text/atril/files/atril-cve-2017-1000083.patch b/app-text/atril/files/atril-cve-2017-1000083.patch
new file mode 100644 (file)
index 0000000..29c81f7
--- /dev/null
@@ -0,0 +1,28 @@
+From f4291fd62f7dfe6460d2406a979ccfac0c68dd59 Mon Sep 17 00:00:00 2001
+From: ZenWalker <scow@riseup.net>
+Date: Wed, 19 Jul 2017 11:00:09 +0200
+Subject: [PATCH] comics: make the files containing "--checkpoint-action="
+ unsupported
+
+Fixes #257
+---
+ backend/comics/comics-document.c | 6 ++++++
+ 1 file changed, 6 insertions(+)
+
+diff --git a/backend/comics/comics-document.c b/backend/comics/comics-document.c
+index 9f945c6..4d4d293 100644
+--- a/backend/comics/comics-document.c
++++ b/backend/comics/comics-document.c
+@@ -983,6 +983,12 @@ extract_argv (EvDocument *document, gint page)
+       char *command_line, *quoted_archive, *quoted_filename;
+       GError *err = NULL;
+ 
++      if (g_strrstr (comics_document->page_names->pdata[page], "--checkpoint-action="))
++      {
++              g_warning ("File unsupported\n");
++              gtk_main_quit ();
++      }
++
+         if (page >= comics_document->page_names->len)
+                 return NULL;
+