OpenPKG CVS Repository
  http://cvs.openpkg.org/
  ____________________________________________________________________________

  Server: cvs.openpkg.org                  Name:   Ralf S. Engelschall
  Root:   /e/openpkg/cvs                   Email:  [EMAIL PROTECTED]
  Module: openpkg-src                      Date:   19-Feb-2003 16:15:20
  Branch: OPENPKG_1_2_SOLID                Handle: 2003021915151800

  Added files:              (Branch: OPENPKG_1_2_SOLID)
    openpkg-src/openssl     openssl.patch
  Modified files:           (Branch: OPENPKG_1_2_SOLID)
    openpkg-src/openssl     openssl.spec

  Log:
    add security patch (OpenPKG-SA-2003.013, CAN-2003-0078)

  Summary:
    Revision    Changes     Path
    1.7.4.1     +98 -0      openpkg-src/openssl/openssl.patch
    1.37.2.1.2.2+2  -0      openpkg-src/openssl/openssl.spec
  ____________________________________________________________________________

  patch -p0 <<'@@ .'
  Index: openpkg-src/openssl/openssl.patch
  ============================================================================
  $ cvs diff -u -r0 -r1.7.4.1 openssl.patch
  --- /dev/null 2003-02-19 16:15:19.000000000 +0100
  +++ openssl.patch     2003-02-19 16:15:20.000000000 +0100
  @@ -0,0 +1,98 @@
  +Index: ssl/s3_pkt.c
  +===================================================================
  +RCS file: /e/openssl/cvs/openssl/ssl/s3_pkt.c,v
  +retrieving revision 1.46.2.4
  +diff -u -r1.46.2.4 s3_pkt.c
  +--- ssl/s3_pkt.c     10 Jul 2002 06:57:49 -0000      1.46.2.4
  ++++ ssl/s3_pkt.c     18 Feb 2003 16:38:29 -0000
  +@@ -238,6 +238,8 @@
  +     unsigned int mac_size;
  +     int clear=0;
  +     size_t extra;
  ++    int decryption_failed_or_bad_record_mac = 0;
  ++    unsigned char *mac = NULL;
  + 
  +     rr= &(s->s3->rrec);
  +     sess=s->session;
  +@@ -353,8 +355,11 @@
  +                     /* SSLerr() and ssl3_send_alert() have been called */
  +                     goto err;
  + 
  +-            /* otherwise enc_err == -1 */
  +-            goto decryption_failed_or_bad_record_mac;
  ++            /* Otherwise enc_err == -1, which indicates bad padding
  ++             * (rec->length has not been changed in this case).
  ++             * To minimize information leaked via timing, we will perform
  ++             * the MAC computation anyway. */
  ++            decryption_failed_or_bad_record_mac = 1;
  +             }
  + 
  + #ifdef TLS_DEBUG
  +@@ -380,28 +385,46 @@
  +                     SSLerr(SSL_F_SSL3_GET_RECORD,SSL_R_PRE_MAC_LENGTH_TOO_LONG);
  +                     goto f_err;
  + #else
  +-                    goto decryption_failed_or_bad_record_mac;
  ++                    decryption_failed_or_bad_record_mac = 1;
  + #endif                      
  +                     }
  +             /* check the MAC for rr->input (it's in mac_size bytes at the tail) */
  +-            if (rr->length < mac_size)
  ++            if (rr->length >= mac_size)
  +                     {
  ++                    rr->length -= mac_size;
  ++                    mac = &rr->data[rr->length];
  ++                    }
  ++            else
  ++                    {
  ++                    /* record (minus padding) is too short to contain a MAC */
  + #if 0 /* OK only for stream ciphers */
  +                     al=SSL_AD_DECODE_ERROR;
  +                     SSLerr(SSL_F_SSL3_GET_RECORD,SSL_R_LENGTH_TOO_SHORT);
  +                     goto f_err;
  + #else
  +-                    goto decryption_failed_or_bad_record_mac;
  ++                    decryption_failed_or_bad_record_mac = 1;
  ++                    rr->length = 0;
  + #endif
  +                     }
  +-            rr->length-=mac_size;
  +             i=s->method->ssl3_enc->mac(s,md,0);
  +-            if (memcmp(md,&(rr->data[rr->length]),mac_size) != 0)
  ++            if (mac == NULL || memcmp(md, mac, mac_size) != 0)
  +                     {
  +-                    goto decryption_failed_or_bad_record_mac;
  ++                    decryption_failed_or_bad_record_mac = 1;
  +                     }
  +             }
  + 
  ++    if (decryption_failed_or_bad_record_mac)
  ++            {
  ++            /* A separate 'decryption_failed' alert was introduced with TLS 1.0,
  ++             * SSL 3.0 only has 'bad_record_mac'.  But unless a decryption
  ++             * failure is directly visible from the ciphertext anyway,
  ++             * we should not reveal which kind of error occured -- this
  ++             * might become visible to an attacker (e.g. via a logfile) */
  ++            al=SSL_AD_BAD_RECORD_MAC;
  ++            
SSLerr(SSL_F_SSL3_GET_RECORD,SSL_R_DECRYPTION_FAILED_OR_BAD_RECORD_MAC);
  ++            goto f_err;
  ++            }
  ++
  +     /* r->length is now just compressed */
  +     if (s->expand != NULL)
  +             {
  +@@ -443,14 +466,6 @@
  + 
  +     return(1);
  + 
  +-decryption_failed_or_bad_record_mac:
  +-    /* Separate 'decryption_failed' alert was introduced with TLS 1.0,
  +-     * SSL 3.0 only has 'bad_record_mac'.  But unless a decryption
  +-     * failure is directly visible from the ciphertext anyway,
  +-     * we should not reveal which kind of error occured -- this
  +-     * might become visible to an attacker (e.g. via logfile) */
  +-    al=SSL_AD_BAD_RECORD_MAC;
  +-    SSLerr(SSL_F_SSL3_GET_RECORD,SSL_R_DECRYPTION_FAILED_OR_BAD_RECORD_MAC);
  + f_err:
  +     ssl3_send_alert(s,SSL3_AL_FATAL,al);
  + err:
  @@ .
  patch -p0 <<'@@ .'
  Index: openpkg-src/openssl/openssl.spec
  ============================================================================
  $ cvs diff -u -r1.37.2.1.2.1 -r1.37.2.1.2.2 openssl.spec
  --- openpkg-src/openssl/openssl.spec  18 Jan 2003 17:21:22 -0000      1.37.2.1.2.1
  +++ openpkg-src/openssl/openssl.spec  19 Feb 2003 15:15:18 -0000      1.37.2.1.2.2
  @@ -37,6 +37,7 @@
   
   #   list of sources
   Source0:      ftp://ftp.openssl.org/source/openssl-%{version}.tar.gz
  +Patch0:       openssl.patch
   
   #   build information
   Prefix:       %{l_prefix}
  @@ -57,6 +58,7 @@
   
   %prep
       %setup -q
  +    %patch -p0
       %{l_shtool} subst -e 's;-m486;-march=i486;g' Configure
       %{l_shtool} subst -e 's;test "$OSTYPE" = msdosdjgpp;true;' util/point.sh
   
  @@ .
______________________________________________________________________
The OpenPKG Project                                    www.openpkg.org
CVS Repository Commit List                     [EMAIL PROTECTED]

Reply via email to