Resolves: CVE-2019-8907 - remote denial of service in do_core_note in readelf.c Resolves: CVE-2019-8905 - stack-based buffer over-read in do_core_note in readelf.c Resolves: CVE-2019-8904 - stack-based buffer over-read in do_bid_note in readelf.c Resolves: CVE-2019-8906 - out-of-bounds read in do_core_note in readelf.c Closes #6
63 lines
1.9 KiB
Diff
63 lines
1.9 KiB
Diff
From 14569013793837d262084f3ac6260638d340f3bf Mon Sep 17 00:00:00 2001
|
|
From: Siteshwar Vashisht <svashisht@redhat.com>
|
|
Date: Thu, 21 Feb 2019 15:26:38 +0100
|
|
Subject: [PATCH] Upstream says it's up to distributions to add a way to
|
|
support local-magic.
|
|
|
|
---
|
|
magic/magic.local | 3 +++
|
|
src/Makefile.am | 2 +-
|
|
src/Makefile.in | 2 +-
|
|
src/apprentice.c | 2 +-
|
|
4 files changed, 6 insertions(+), 3 deletions(-)
|
|
create mode 100644 magic/magic.local
|
|
|
|
diff --git a/magic/magic.local b/magic/magic.local
|
|
new file mode 100644
|
|
index 0000000..283a863
|
|
--- /dev/null
|
|
+++ b/magic/magic.local
|
|
@@ -0,0 +1,3 @@
|
|
+# Magic local data for file(1) command.
|
|
+# Insert here your local magic data. Format is described in magic(5).
|
|
+
|
|
diff --git a/src/Makefile.am b/src/Makefile.am
|
|
index 2fbefdb..3ca3e73 100644
|
|
--- a/src/Makefile.am
|
|
+++ b/src/Makefile.am
|
|
@@ -1,4 +1,4 @@
|
|
-MAGIC = $(pkgdatadir)/magic
|
|
+MAGIC = /etc/magic:$(pkgdatadir)/magic
|
|
lib_LTLIBRARIES = libmagic.la
|
|
nodist_include_HEADERS = magic.h
|
|
|
|
diff --git a/src/Makefile.in b/src/Makefile.in
|
|
index 29567c4..8222bc1 100644
|
|
--- a/src/Makefile.in
|
|
+++ b/src/Makefile.in
|
|
@@ -337,7 +337,7 @@ target_alias = @target_alias@
|
|
top_build_prefix = @top_build_prefix@
|
|
top_builddir = @top_builddir@
|
|
top_srcdir = @top_srcdir@
|
|
-MAGIC = $(pkgdatadir)/magic
|
|
+MAGIC = /etc/magic:$(pkgdatadir)/magic
|
|
lib_LTLIBRARIES = libmagic.la
|
|
nodist_include_HEADERS = magic.h
|
|
AM_CPPFLAGS = -DMAGIC='"$(MAGIC)"'
|
|
diff --git a/src/apprentice.c b/src/apprentice.c
|
|
index eca3ae0..24b5663 100644
|
|
--- a/src/apprentice.c
|
|
+++ b/src/apprentice.c
|
|
@@ -454,7 +454,7 @@ apprentice_1(struct magic_set *ms, const char *fn, int action)
|
|
if (map == RCAST(struct magic_map *, -1))
|
|
return -1;
|
|
if (map == NULL) {
|
|
- if (ms->flags & MAGIC_CHECK)
|
|
+ if (ms->flags & MAGIC_CHECK && strcmp("/etc/magic", fn) != 0)
|
|
file_magwarn(ms, "using regular magic file `%s'", fn);
|
|
map = apprentice_load(ms, fn, action);
|
|
if (map == NULL)
|
|
--
|
|
2.17.2
|
|
|