Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package gpsd for openSUSE:Factory checked in at 2026-07-15 16:25:45 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/gpsd (Old) and /work/SRC/openSUSE:Factory/.gpsd.new.1991 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "gpsd" Wed Jul 15 16:25:45 2026 rev:71 rq:1365660 version:3.27.5 Changes: -------- --- /work/SRC/openSUSE:Factory/gpsd/gpsd.changes 2026-06-19 17:15:55.570805766 +0200 +++ /work/SRC/openSUSE:Factory/.gpsd.new.1991/gpsd.changes 2026-07-15 16:30:57.540699958 +0200 @@ -1,0 +2,9 @@ +Fri Jul 10 07:32:57 UTC 2026 - Arjen de Korte <[email protected]> + +- Fix for gpsprof gnuplot command injection via attacker-controlled + GPS metadata (CVE-2026-58459 [bsc#1271191]) + + 4c06658.patch + + 5581ba1.patch + + 1a6bb7b.patch + +------------------------------------------------------------------- New: ---- 1a6bb7b.patch 4c06658.patch 5581ba1.patch ----------(New B)---------- New: + 5581ba1.patch + 1a6bb7b.patch New: GPS metadata (CVE-2026-58459 [bsc#1271191]) + 4c06658.patch + 5581ba1.patch New: + 4c06658.patch + 5581ba1.patch + 1a6bb7b.patch ----------(New E)---------- ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ gpsd.spec ++++++ --- /var/tmp/diff_new_pack.vvNuoV/_old 2026-07-15 16:30:58.692739872 +0200 +++ /var/tmp/diff_new_pack.vvNuoV/_new 2026-07-15 16:30:58.696740011 +0200 @@ -38,6 +38,10 @@ # PATCH-FIX-UPSTREAM update-desktop-files.patch bugno [email protected] # update .desktop files with SUSE fixes Patch2: update-desktop-files.patch +# PATCH-FIX-UPSTREAM - https://gitlab.com/gpsd/gpsd/-/work_items/404 +Patch3: https://github.com/ntpsec/gpsd/commit/5581ba1.patch +Patch4: https://github.com/ntpsec/gpsd/commit/1a6bb7b.patch +Patch5: https://github.com/ntpsec/gpsd/commit/4c06658.patch BuildRequires: chrpath BuildRequires: fdupes BuildRequires: gcc-c++ ++++++ 1a6bb7b.patch ++++++ >From 1a6bb7bcbdf58aa940132e630870af061dc88537 Mon Sep 17 00:00:00 2001 From: "Gary E. Miller" <[email protected]> Date: Tue, 7 Jul 2026 13:41:54 -0700 Subject: [PATCH] clients/gpsprof.py.in: Quote back ticks in title. Someone could use the back tick to break out of the string and add gnuplot commnds. For issue 404. Reported by: CuB3y0nd, and Wade Sparks <[email protected]> --- clients/gpsprof.py.in | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/clients/gpsprof.py.in b/clients/gpsprof.py.in index 261e72665..202214769 100644 --- a/clients/gpsprof.py.in +++ b/clients/gpsprof.py.in @@ -198,8 +198,9 @@ class plotter(object): if 'subtype' in self.device: desc += "\\n%s" % self.device['subtype'] - # escape ", and \n, for gnuplot, to not break strings + # escape ", `, and \n, for gnuplot, to not break strings desc = desc.replace('"', '\\042') + desc = desc.replace('`', '\\140') desc = desc.replace('\n', '') return desc @@ -1268,8 +1269,9 @@ if __name__ == '__main__': options.title = plot.whatami() if options.subtitle: options.title += '\\n' + options.subtitle - # escape " for gnuplot, to not break strings + # escape ", and`, for gnuplot, to not break strings options.title = options.title.replace('"', '\\042') + options.title = options.title.replace('"', '\\140') term_opts = "" truecolor_terms = ['png', 'sixelgd', 'wxt'] if options.terminal in truecolor_terms: ++++++ 4c06658.patch ++++++ >From 4c06658e988f4ced1a7a574ce082a22ef625df56 Mon Sep 17 00:00:00 2001 From: "Gary E. Miller" <[email protected]> Date: Tue, 7 Jul 2026 14:23:56 -0700 Subject: [PATCH] clients/gpsprof.py.in: Quote back ticks in title. Second try. Also quote "terminal". Someone could use the back tick to break out of the string and add gnuplot commnds. For issue 404. Reported by: CuB3y0nd, and Wade Sparks <[email protected]> --- clients/gpsprof.py.in | 14 ++++++++++---- 1 file changed, 10 insertions(+), 4 deletions(-) diff --git a/clients/gpsprof.py.in b/clients/gpsprof.py.in index 202214769..e91367ee3 100644 --- a/clients/gpsprof.py.in +++ b/clients/gpsprof.py.in @@ -200,7 +200,7 @@ class plotter(object): # escape ", `, and \n, for gnuplot, to not break strings desc = desc.replace('"', '\\042') - desc = desc.replace('`', '\\140') + desc = desc.replace("\x60", '\\140') desc = desc.replace('\n', '') return desc @@ -1271,13 +1271,19 @@ if __name__ == '__main__': options.title += '\\n' + options.subtitle # escape ", and`, for gnuplot, to not break strings options.title = options.title.replace('"', '\\042') - options.title = options.title.replace('"', '\\140') + options.title = options.title.replace("\x60", '\\140') term_opts = "" truecolor_terms = ['png', 'sixelgd', 'wxt'] if options.terminal in truecolor_terms: term_opts = 'truecolor' - sys.stdout.write("set terminal %s size 800,950 %s\n" - "set termoption enhanced\n" + + # escape ", `, and \n, for gnuplot, to not break strings + options.terminal = options.terminal.replace('"', '\\042') + options.terminal = options.terminal.replace("\x60", '\\140') + options.terminal = options.terminal.replace('\n', '') + + sys.stdout.write('set terminal "%s" size 800,950 %s\n' + 'set termoption enhanced\n' % (options.terminal, term_opts)) # double quotes on title so \n is parsed by gnuplot sys.stdout.write('set title noenhanced "%s\\n\\n"\n' % options.title) ++++++ 5581ba1.patch ++++++ >From 5581ba196d826a984fbfaf792b7d58535f9911ce Mon Sep 17 00:00:00 2001 From: "Gary E. Miller" <[email protected]> Date: Wed, 1 Jul 2026 17:55:57 -0700 Subject: [PATCH] clients/gpsprof.py.in: Quote double quotes in title. Someone could use the double quote to break out of the string and add gnuplot commnds. For issue 404. Reported by: CuB3y0nd, and Wade Sparks <[email protected]> --- clients/gpsprof.py.in | 8 ++++++-- 1 file changed, 6 insertions(+), 2 deletions(-) diff --git a/clients/gpsprof.py.in b/clients/gpsprof.py.in index 5c18f50ff..261e72665 100644 --- a/clients/gpsprof.py.in +++ b/clients/gpsprof.py.in @@ -198,6 +198,10 @@ class plotter(object): if 'subtype' in self.device: desc += "\\n%s" % self.device['subtype'] + # escape ", and \n, for gnuplot, to not break strings + desc = desc.replace('"', '\\042') + desc = desc.replace('\n', '') + return desc def collect(self, verb, log_fp=None): @@ -1262,10 +1266,10 @@ if __name__ == '__main__': # Ship the plot to standard output if not options.title: options.title = plot.whatami() - # escape " for gnuplot - options.title = options.title.replace('"', '\\"') if options.subtitle: options.title += '\\n' + options.subtitle + # escape " for gnuplot, to not break strings + options.title = options.title.replace('"', '\\042') term_opts = "" truecolor_terms = ['png', 'sixelgd', 'wxt'] if options.terminal in truecolor_terms:
