Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package gpsd for openSUSE:Factory checked in 
at 2026-07-15 16:25:45
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/gpsd (Old)
 and      /work/SRC/openSUSE:Factory/.gpsd.new.1991 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "gpsd"

Wed Jul 15 16:25:45 2026 rev:71 rq:1365660 version:3.27.5

Changes:
--------
--- /work/SRC/openSUSE:Factory/gpsd/gpsd.changes        2026-06-19 
17:15:55.570805766 +0200
+++ /work/SRC/openSUSE:Factory/.gpsd.new.1991/gpsd.changes      2026-07-15 
16:30:57.540699958 +0200
@@ -1,0 +2,9 @@
+Fri Jul 10 07:32:57 UTC 2026 - Arjen de Korte <[email protected]>
+
+- Fix for gpsprof gnuplot command injection via attacker-controlled
+  GPS metadata (CVE-2026-58459 [bsc#1271191])
+  + 4c06658.patch
+  + 5581ba1.patch
+  + 1a6bb7b.patch
+
+-------------------------------------------------------------------

New:
----
  1a6bb7b.patch
  4c06658.patch
  5581ba1.patch

----------(New B)----------
  New:  + 5581ba1.patch
  + 1a6bb7b.patch
  New:  GPS metadata (CVE-2026-58459 [bsc#1271191])
  + 4c06658.patch
  + 5581ba1.patch
  New:  + 4c06658.patch
  + 5581ba1.patch
  + 1a6bb7b.patch
----------(New E)----------

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ gpsd.spec ++++++
--- /var/tmp/diff_new_pack.vvNuoV/_old  2026-07-15 16:30:58.692739872 +0200
+++ /var/tmp/diff_new_pack.vvNuoV/_new  2026-07-15 16:30:58.696740011 +0200
@@ -38,6 +38,10 @@
 # PATCH-FIX-UPSTREAM update-desktop-files.patch bugno [email protected]
 # update .desktop files with SUSE fixes
 Patch2:         update-desktop-files.patch
+# PATCH-FIX-UPSTREAM - https://gitlab.com/gpsd/gpsd/-/work_items/404
+Patch3:         https://github.com/ntpsec/gpsd/commit/5581ba1.patch
+Patch4:         https://github.com/ntpsec/gpsd/commit/1a6bb7b.patch
+Patch5:         https://github.com/ntpsec/gpsd/commit/4c06658.patch
 BuildRequires:  chrpath
 BuildRequires:  fdupes
 BuildRequires:  gcc-c++

++++++ 1a6bb7b.patch ++++++
>From 1a6bb7bcbdf58aa940132e630870af061dc88537 Mon Sep 17 00:00:00 2001
From: "Gary E. Miller" <[email protected]>
Date: Tue, 7 Jul 2026 13:41:54 -0700
Subject: [PATCH] clients/gpsprof.py.in: Quote back ticks in title.

Someone could use the back tick to break out of the string and add
gnuplot commnds.

For issue 404.
Reported by: CuB3y0nd, and Wade Sparks <[email protected]>
---
 clients/gpsprof.py.in | 6 ++++--
 1 file changed, 4 insertions(+), 2 deletions(-)

diff --git a/clients/gpsprof.py.in b/clients/gpsprof.py.in
index 261e72665..202214769 100644
--- a/clients/gpsprof.py.in
+++ b/clients/gpsprof.py.in
@@ -198,8 +198,9 @@ class plotter(object):
         if 'subtype' in self.device:
             desc += "\\n%s" % self.device['subtype']
 
-        # escape ", and \n, for gnuplot, to not break strings
+        # escape ", `, and \n, for gnuplot, to not break strings
         desc = desc.replace('"', '\\042')
+        desc = desc.replace('`', '\\140')
         desc = desc.replace('\n', '')
 
         return desc
@@ -1268,8 +1269,9 @@ if __name__ == '__main__':
             options.title = plot.whatami()
         if options.subtitle:
             options.title += '\\n' + options.subtitle
-        # escape " for gnuplot, to not break strings
+        # escape ",  and`, for gnuplot, to not break strings
         options.title = options.title.replace('"', '\\042')
+        options.title = options.title.replace('"', '\\140')
         term_opts = ""
         truecolor_terms = ['png', 'sixelgd', 'wxt']
         if options.terminal in truecolor_terms:

++++++ 4c06658.patch ++++++
>From 4c06658e988f4ced1a7a574ce082a22ef625df56 Mon Sep 17 00:00:00 2001
From: "Gary E. Miller" <[email protected]>
Date: Tue, 7 Jul 2026 14:23:56 -0700
Subject: [PATCH] clients/gpsprof.py.in: Quote back ticks in title.

Second try.  Also quote "terminal".

Someone could use the back tick to break out of the string and add
gnuplot commnds.

For issue 404.
Reported by: CuB3y0nd, and Wade Sparks <[email protected]>
---
 clients/gpsprof.py.in | 14 ++++++++++----
 1 file changed, 10 insertions(+), 4 deletions(-)

diff --git a/clients/gpsprof.py.in b/clients/gpsprof.py.in
index 202214769..e91367ee3 100644
--- a/clients/gpsprof.py.in
+++ b/clients/gpsprof.py.in
@@ -200,7 +200,7 @@ class plotter(object):
 
         # escape ", `, and \n, for gnuplot, to not break strings
         desc = desc.replace('"', '\\042')
-        desc = desc.replace('`', '\\140')
+        desc = desc.replace("\x60", '\\140')
         desc = desc.replace('\n', '')
 
         return desc
@@ -1271,13 +1271,19 @@ if __name__ == '__main__':
             options.title += '\\n' + options.subtitle
         # escape ",  and`, for gnuplot, to not break strings
         options.title = options.title.replace('"', '\\042')
-        options.title = options.title.replace('"', '\\140')
+        options.title = options.title.replace("\x60", '\\140')
         term_opts = ""
         truecolor_terms = ['png', 'sixelgd', 'wxt']
         if options.terminal in truecolor_terms:
             term_opts = 'truecolor'
-        sys.stdout.write("set terminal %s size 800,950 %s\n"
-                         "set termoption enhanced\n"
+
+        # escape ", `, and \n, for gnuplot, to not break strings
+        options.terminal = options.terminal.replace('"', '\\042')
+        options.terminal = options.terminal.replace("\x60", '\\140')
+        options.terminal = options.terminal.replace('\n', '')
+
+        sys.stdout.write('set terminal "%s" size 800,950 %s\n'
+                         'set termoption enhanced\n'
                          % (options.terminal, term_opts))
         # double quotes on title so \n is parsed by gnuplot
         sys.stdout.write('set title noenhanced "%s\\n\\n"\n' % options.title)

++++++ 5581ba1.patch ++++++
>From 5581ba196d826a984fbfaf792b7d58535f9911ce Mon Sep 17 00:00:00 2001
From: "Gary E. Miller" <[email protected]>
Date: Wed, 1 Jul 2026 17:55:57 -0700
Subject: [PATCH] clients/gpsprof.py.in: Quote double quotes in title.

Someone could use the double quote to break out of the
string and add gnuplot commnds.

For issue 404.
Reported by: CuB3y0nd, and Wade Sparks <[email protected]>
---
 clients/gpsprof.py.in | 8 ++++++--
 1 file changed, 6 insertions(+), 2 deletions(-)

diff --git a/clients/gpsprof.py.in b/clients/gpsprof.py.in
index 5c18f50ff..261e72665 100644
--- a/clients/gpsprof.py.in
+++ b/clients/gpsprof.py.in
@@ -198,6 +198,10 @@ class plotter(object):
         if 'subtype' in self.device:
             desc += "\\n%s" % self.device['subtype']
 
+        # escape ", and \n, for gnuplot, to not break strings
+        desc = desc.replace('"', '\\042')
+        desc = desc.replace('\n', '')
+
         return desc
 
     def collect(self, verb, log_fp=None):
@@ -1262,10 +1266,10 @@ if __name__ == '__main__':
         # Ship the plot to standard output
         if not options.title:
             options.title = plot.whatami()
-            # escape " for gnuplot
-            options.title = options.title.replace('"', '\\"')
         if options.subtitle:
             options.title += '\\n' + options.subtitle
+        # escape " for gnuplot, to not break strings
+        options.title = options.title.replace('"', '\\042')
         term_opts = ""
         truecolor_terms = ['png', 'sixelgd', 'wxt']
         if options.terminal in truecolor_terms:

Reply via email to