!85 修复cve-2022-48337造成的后续问题
From: @leeffo Reviewed-by: @weidongkl Signed-off-by: @weidongkl
This commit is contained in:
commit
263d1909ab
25
backport-0002-CVE-2022-48337.patch
Normal file
25
backport-0002-CVE-2022-48337.patch
Normal file
@ -0,0 +1,25 @@
|
||||
From ab998b90206733f2cd9b009dcdb8e5567834ed3b Mon Sep 17 00:00:00 2001
|
||||
From: Super User <root@localhost.localdomain>
|
||||
Date: Mon, 25 Sep 2023 14:32:05 +0800
|
||||
Subject: [PATCH] backport 0002 CVE-2022-48337
|
||||
|
||||
---
|
||||
lib-src/etags.c | 2 ++
|
||||
1 file changed, 2 insertions(+)
|
||||
|
||||
diff --git a/lib-src/etags.c b/lib-src/etags.c
|
||||
index 5d0eed2..5399008 100644
|
||||
--- a/lib-src/etags.c
|
||||
+++ b/lib-src/etags.c
|
||||
@@ -1680,6 +1680,8 @@ process_file_name (char *file, language *lang)
|
||||
int buf_len = strlen (compr->command) + strlen (" > ") + strlen (new_real_name) + strlen (new_tmp_name) + 1;
|
||||
char *cmd = xmalloc (buf_len);
|
||||
snprintf (cmd, buf_len, "%s %s > %s", compr->command, new_real_name, new_tmp_name);
|
||||
+ free (new_real_name);
|
||||
+ free (new_tmp_name);
|
||||
#endif
|
||||
int tmp_errno;
|
||||
if (system (cmd) == -1)
|
||||
--
|
||||
2.41.0
|
||||
|
||||
@ -4,7 +4,7 @@
|
||||
Name: emacs
|
||||
Epoch: 1
|
||||
Version: 27.1
|
||||
Release: 9
|
||||
Release: 10
|
||||
Summary: An extensible GNU text editor
|
||||
License: GPLv3+ and CC0-1.0
|
||||
URL: http://www.gnu.org/software/emacs
|
||||
@ -25,6 +25,7 @@ Patch6001: backport-CVE-2022-48337.patch
|
||||
Patch6002: backport-CVE-2022-48338.patch
|
||||
Patch6003: backport-CVE-2022-48339.patch
|
||||
Patch6004: backport-CVE-2023-28617.patch
|
||||
Patch6005: backport-0002-CVE-2022-48337.patch
|
||||
|
||||
BuildRequires: gcc atk-devel cairo-devel freetype-devel fontconfig-devel dbus-devel giflib-devel
|
||||
BuildRequires: glibc-devel zlib-devel gnutls-devel libselinux-devel GConf2-devel alsa-lib-devel
|
||||
@ -402,6 +403,9 @@ fi
|
||||
%{_mandir}/*/*
|
||||
|
||||
%changelog
|
||||
* Mon Sep 25 2023 leeffo <liweiganga@uniontech.com> - 1:27.1-10
|
||||
- fix CVE-2022-48337
|
||||
|
||||
* Fri Mar 24 2023 zhangpan <zhangpan103@h-partners.com> - 1:27.1-9
|
||||
- fix CVE-2023-28617
|
||||
|
||||
|
||||
Loading…
x
Reference in New Issue
Block a user