|
 |
87cf9a |
diff -up cups-1.6.3/scheduler/client.c.CVE-2014-5029-5030-5031 cups-1.6.3/scheduler/client.c
|
|
 |
87cf9a |
--- cups-1.6.3/scheduler/client.c.CVE-2014-5029-5030-5031 2014-09-02 11:42:02.465900694 +0100
|
|
 |
87cf9a |
+++ cups-1.6.3/scheduler/client.c 2014-09-02 11:42:44.383119863 +0100
|
|
 |
87cf9a |
@@ -3180,7 +3180,7 @@ get_file(cupsd_client_t *con, /* I - C
|
|
 |
87cf9a |
* then fallback to the default one...
|
|
 |
87cf9a |
*/
|
|
 |
87cf9a |
|
|
 |
87cf9a |
- if ((status = stat(filename, filestats)) != 0 && language[0] &&
|
|
 |
87cf9a |
+ if ((status = lstat(filename, filestats)) != 0 && language[0] &&
|
|
 |
87cf9a |
strncmp(con->uri, "/icons/", 7) &&
|
|
 |
87cf9a |
strncmp(con->uri, "/ppd/", 5) &&
|
|
 |
87cf9a |
strncmp(con->uri, "/rss/", 5) &&
|
|
 |
87cf9a |
@@ -3278,13 +3278,13 @@ get_file(cupsd_client_t *con, /* I - C
|
|
 |
87cf9a |
plen = len - (ptr - filename);
|
|
 |
87cf9a |
|
|
 |
87cf9a |
strlcpy(ptr, "index.html", plen);
|
|
 |
87cf9a |
- status = stat(filename, filestats);
|
|
 |
87cf9a |
+ status = lstat(filename, filestats);
|
|
 |
87cf9a |
|
|
 |
87cf9a |
#ifdef HAVE_JAVA
|
|
 |
87cf9a |
if (status)
|
|
 |
87cf9a |
{
|
|
 |
87cf9a |
strlcpy(ptr, "index.class", plen);
|
|
 |
87cf9a |
- status = stat(filename, filestats);
|
|
 |
87cf9a |
+ status = lstat(filename, filestats);
|
|
 |
87cf9a |
}
|
|
 |
87cf9a |
#endif /* HAVE_JAVA */
|
|
 |
87cf9a |
|
|
 |
87cf9a |
@@ -3292,7 +3292,7 @@ get_file(cupsd_client_t *con, /* I - C
|
|
 |
87cf9a |
if (status)
|
|
 |
87cf9a |
{
|
|
 |
87cf9a |
strlcpy(ptr, "index.pl", plen);
|
|
 |
87cf9a |
- status = stat(filename, filestats);
|
|
 |
87cf9a |
+ status = lstat(filename, filestats);
|
|
 |
87cf9a |
}
|
|
 |
87cf9a |
#endif /* HAVE_PERL */
|
|
 |
87cf9a |
|
|
 |
87cf9a |
@@ -3300,7 +3300,7 @@ get_file(cupsd_client_t *con, /* I - C
|
|
 |
87cf9a |
if (status)
|
|
 |
87cf9a |
{
|
|
 |
87cf9a |
strlcpy(ptr, "index.php", plen);
|
|
 |
87cf9a |
- status = stat(filename, filestats);
|
|
 |
87cf9a |
+ status = lstat(filename, filestats);
|
|
 |
87cf9a |
}
|
|
 |
87cf9a |
#endif /* HAVE_PHP */
|
|
 |
87cf9a |
|
|
 |
87cf9a |
@@ -3308,18 +3308,39 @@ get_file(cupsd_client_t *con, /* I - C
|
|
 |
87cf9a |
if (status)
|
|
 |
87cf9a |
{
|
|
 |
87cf9a |
strlcpy(ptr, "index.pyc", plen);
|
|
 |
87cf9a |
- status = stat(filename, filestats);
|
|
 |
87cf9a |
+ status = lstat(filename, filestats);
|
|
 |
87cf9a |
}
|
|
 |
87cf9a |
|
|
 |
87cf9a |
if (status)
|
|
 |
87cf9a |
{
|
|
 |
87cf9a |
strlcpy(ptr, "index.py", plen);
|
|
 |
87cf9a |
- status = stat(filename, filestats);
|
|
 |
87cf9a |
+ status = lstat(filename, filestats);
|
|
 |
87cf9a |
}
|
|
 |
87cf9a |
#endif /* HAVE_PYTHON */
|
|
 |
87cf9a |
|
|
 |
87cf9a |
}
|
|
 |
87cf9a |
while (status && language[0]);
|
|
 |
87cf9a |
+
|
|
 |
87cf9a |
+ /*
|
|
 |
87cf9a |
+ * If we've found a symlink, 404 the sucker to avoid disclosing information.
|
|
 |
87cf9a |
+ */
|
|
 |
87cf9a |
+
|
|
 |
87cf9a |
+ if (!status && S_ISLNK(filestats->st_mode))
|
|
 |
87cf9a |
+ {
|
|
 |
87cf9a |
+ cupsdLogMessage(CUPSD_LOG_INFO, "[Client %d] Symlinks such as \"%s\" are not allowed.", con->http.fd, filename);
|
|
 |
87cf9a |
+ return (NULL);
|
|
 |
87cf9a |
+ }
|
|
 |
87cf9a |
+
|
|
 |
87cf9a |
+ /*
|
|
 |
87cf9a |
+ * Similarly, if the file/directory does not have world read permissions, do
|
|
 |
87cf9a |
+ * not allow access...
|
|
 |
87cf9a |
+ */
|
|
 |
87cf9a |
+
|
|
 |
87cf9a |
+ if (!status && !(filestats->st_mode & S_IROTH))
|
|
 |
87cf9a |
+ {
|
|
 |
87cf9a |
+ cupsdLogMessage(CUPSD_LOG_INFO, "[Client %d] Files/directories such as \"%s\" must be world-readable.", con->http.fd, filename);
|
|
 |
87cf9a |
+ return (NULL);
|
|
 |
87cf9a |
+ }
|
|
 |
87cf9a |
}
|
|
 |
87cf9a |
|
|
 |
87cf9a |
cupsdLogMessage(CUPSD_LOG_DEBUG2,
|