app-editors/nedit: security patch added
authorAmy Winston <amynka@gentoo.org>
Mon, 14 Mar 2016 16:59:07 +0000 (17:59 +0100)
committerAmy Winston <amynka@gentoo.org>
Mon, 14 Mar 2016 17:02:54 +0000 (18:02 +0100)
Package-Manager: portage-2.2.26

app-editors/nedit/files/nedit-5.5_p20110116-security.patch [new file with mode: 0644]
app-editors/nedit/files/nedit-5.6-security.patch [new file with mode: 0644]
app-editors/nedit/nedit-5.5_p20110116-r3.ebuild
app-editors/nedit/nedit-5.6-r1.ebuild

diff --git a/app-editors/nedit/files/nedit-5.5_p20110116-security.patch b/app-editors/nedit/files/nedit-5.5_p20110116-security.patch
new file mode 100644 (file)
index 0000000..b24ef23
--- /dev/null
@@ -0,0 +1,63 @@
+Index: nedit-5.5/source/file.c
+===================================================================
+--- nedit-5.5.orig/source/file.c       2004-08-24 11:37:24.000000000 +0200
++++ nedit-5.5/source/file.c    2010-03-27 18:44:01.000000000 +0100
+@@ -1314,7 +1314,7 @@
+ */
+ void PrintString(const char *string, int length, Widget parent, const char *jobName)
+ {
+-    char tmpFileName[L_tmpnam];    /* L_tmpnam defined in stdio.h */
++    char *tmpFileName=strdup("/tmp/neditXXXXXX");
+     FILE *fp;
+     int fd;
+@@ -1325,14 +1325,10 @@
+           1. Create a filename
+           2. Open the file with the O_CREAT|O_EXCL flags
+       So all an attacker can do is a DoS on the print function. */
+-    tmpnam(tmpFileName);
++    fd = mkstemp(tmpFileName);
+     /* open the temporary file */
+-#ifdef VMS
+-    if ((fp = fopen(tmpFileName, "w", "rfm = stmlf")) == NULL)
+-#else
+-    if ((fd = open(tmpFileName, O_CREAT|O_EXCL|O_WRONLY, S_IRUSR | S_IWUSR)) < 0 || (fp = fdopen(fd, "w")) == NULL)
+-#endif /* VMS */
++    if ((fp = fdopen(fd, "w")) == NULL)
+     {
+         DialogF(DF_WARN, parent, 1, "Error while Printing",
+                 "Unable to write file for printing:\n%s", "OK",
+@@ -1346,7 +1342,7 @@
+     
+     /* write to the file */
+ #ifdef IBM_FWRITE_BUG
+-    write(fileno(fp), string, length);
++    write(fd, string, length);
+ #else
+     fwrite(string, sizeof(char), length, fp);
+ #endif
+@@ -1356,6 +1352,7 @@
+                 "%s not printed:\n%s", "OK", jobName, errorString());
+         fclose(fp); /* should call close(fd) in turn! */
+         remove(tmpFileName);
++      free(tmpFileName);
+         return;
+     }
+     
+@@ -1366,6 +1363,7 @@
+                 "Error closing temp. print file:\n%s", "OK",
+                 errorString());
+         remove(tmpFileName);
++      free(tmpFileName);
+         return;
+     }
+@@ -1377,6 +1375,7 @@
+     PrintFile(parent, tmpFileName, jobName);
+     remove(tmpFileName);
+ #endif /*VMS*/
++    free(tmpFileName);
+     return;
+ }
diff --git a/app-editors/nedit/files/nedit-5.6-security.patch b/app-editors/nedit/files/nedit-5.6-security.patch
new file mode 100644 (file)
index 0000000..b24ef23
--- /dev/null
@@ -0,0 +1,63 @@
+Index: nedit-5.5/source/file.c
+===================================================================
+--- nedit-5.5.orig/source/file.c       2004-08-24 11:37:24.000000000 +0200
++++ nedit-5.5/source/file.c    2010-03-27 18:44:01.000000000 +0100
+@@ -1314,7 +1314,7 @@
+ */
+ void PrintString(const char *string, int length, Widget parent, const char *jobName)
+ {
+-    char tmpFileName[L_tmpnam];    /* L_tmpnam defined in stdio.h */
++    char *tmpFileName=strdup("/tmp/neditXXXXXX");
+     FILE *fp;
+     int fd;
+@@ -1325,14 +1325,10 @@
+           1. Create a filename
+           2. Open the file with the O_CREAT|O_EXCL flags
+       So all an attacker can do is a DoS on the print function. */
+-    tmpnam(tmpFileName);
++    fd = mkstemp(tmpFileName);
+     /* open the temporary file */
+-#ifdef VMS
+-    if ((fp = fopen(tmpFileName, "w", "rfm = stmlf")) == NULL)
+-#else
+-    if ((fd = open(tmpFileName, O_CREAT|O_EXCL|O_WRONLY, S_IRUSR | S_IWUSR)) < 0 || (fp = fdopen(fd, "w")) == NULL)
+-#endif /* VMS */
++    if ((fp = fdopen(fd, "w")) == NULL)
+     {
+         DialogF(DF_WARN, parent, 1, "Error while Printing",
+                 "Unable to write file for printing:\n%s", "OK",
+@@ -1346,7 +1342,7 @@
+     
+     /* write to the file */
+ #ifdef IBM_FWRITE_BUG
+-    write(fileno(fp), string, length);
++    write(fd, string, length);
+ #else
+     fwrite(string, sizeof(char), length, fp);
+ #endif
+@@ -1356,6 +1352,7 @@
+                 "%s not printed:\n%s", "OK", jobName, errorString());
+         fclose(fp); /* should call close(fd) in turn! */
+         remove(tmpFileName);
++      free(tmpFileName);
+         return;
+     }
+     
+@@ -1366,6 +1363,7 @@
+                 "Error closing temp. print file:\n%s", "OK",
+                 errorString());
+         remove(tmpFileName);
++      free(tmpFileName);
+         return;
+     }
+@@ -1377,6 +1375,7 @@
+     PrintFile(parent, tmpFileName, jobName);
+     remove(tmpFileName);
+ #endif /*VMS*/
++    free(tmpFileName);
+     return;
+ }
index 0acd3788fd2f97413dbcaf798f41884da1a92eee..86ab916481862f303923233192136d41dc007f54 100644 (file)
@@ -29,7 +29,8 @@ src_prepare() {
        #respecting LDFLAGS, bug #208189
        epatch \
                "${FILESDIR}"/nedit-5.5_p20090914-ldflags.patch \
-               "${FILESDIR}"/${P}-40_Pointer_to_Integer.patch
+               "${FILESDIR}"/${P}-40_Pointer_to_Integer.patch \
+               "${FILESDIR}"/${P}-security.patch
 
        sed \
                -e "s:bin/:${EPREFIX}/bin/:g" \
index c8b0da39a43f123530cd829febf982b31f23c314..68ebc4b934a42033455e537f0391877f95db56eb 100644 (file)
@@ -30,7 +30,8 @@ src_prepare() {
        epatch \
                "${FILESDIR}"/${P}-format.patch \
                "${FILESDIR}"/${P}-ldflags.patch \
-               "${FILESDIR}"/${P}-40_Pointer_to_Integer.patch
+               "${FILESDIR}"/${P}-40_Pointer_to_Integer.patch \
+               "${FILESDIR}"/${P}-security.patch
        sed \
                -e "s:bin/:${EPREFIX}/bin/:g" \
                -i Makefile source/preferences.c source/help_data.h source/nedit.c Xlt/Makefile || die