Hello community, here is the log from the commit of package slf4j for openSUSE:Factory checked in at 2018-05-18 14:28:32 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/slf4j (Old) and /work/SRC/openSUSE:Factory/.slf4j.new (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "slf4j" Fri May 18 14:28:32 2018 rev:15 rq:610260 version:1.7.12 Changes: -------- --- /work/SRC/openSUSE:Factory/slf4j/slf4j.changes 2017-10-21 20:20:30.406565945 +0200 +++ /work/SRC/openSUSE:Factory/.slf4j.new/slf4j.changes 2018-05-18 14:28:36.924801961 +0200 @@ -1,0 +2,10 @@ +Fri May 18 09:17:44 UTC 2018 - [email protected] + +- Security fix: [bsc#1085970, CVE-2018-8088] + * Disallow EventData deserialization by default + * Added slf4j-Disallow-EventData-deserialization-by-default.patch + refreshed from Fedora [ https://src.fedoraproject.org/rpms/slf4j/ + blob/d7cd96bc7a8e8d8d62c8bc62baa7df02cef56c63/f/ + 0001-Disallow-EventData-deserialization-by-default.patch ] + +------------------------------------------------------------------- New: ---- slf4j-Disallow-EventData-deserialization-by-default.patch ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ slf4j.spec ++++++ --- /var/tmp/diff_new_pack.pYXUPc/_old 2018-05-18 14:28:37.768770990 +0200 +++ /var/tmp/diff_new_pack.pYXUPc/_new 2018-05-18 14:28:37.772770843 +0200 @@ -1,7 +1,7 @@ # # spec file for package slf4j # -# Copyright (c) 2017 SUSE LINUX GmbH, Nuernberg, Germany. +# Copyright (c) 2018 SUSE LINUX GmbH, Nuernberg, Germany. # Copyright (c) 2000-2009, JPackage Project # # All modifications and additions to the file contributed by third parties @@ -28,6 +28,7 @@ Source1: build.xml.tar.bz2 Patch1: build-remove-slf4j_api-binder.patch Patch2: slf4j-commons-lang3.patch +Patch3: slf4j-Disallow-EventData-deserialization-by-default.patch BuildRequires: ant >= 1.6.5 BuildRequires: ant-junit >= 1.6.5 BuildRequires: apache-commons-lang3 @@ -77,6 +78,7 @@ tar xjf %{SOURCE1} %patch1 -p1 %patch2 -p1 +%patch3 -p1 find . -name "*.jar" | xargs rm sed -i -e "s|ant<|org.apache.ant<|g" integration/pom.xml ++++++ slf4j-Disallow-EventData-deserialization-by-default.patch ++++++ Index: slf4j-1.7.12/slf4j-ext/src/main/java/org/slf4j/ext/EventData.java =================================================================== --- slf4j-1.7.12.orig/slf4j-ext/src/main/java/org/slf4j/ext/EventData.java +++ slf4j-1.7.12/slf4j-ext/src/main/java/org/slf4j/ext/EventData.java @@ -76,12 +76,21 @@ public class EventData implements Serial */ @SuppressWarnings("unchecked") public EventData(String xml) { - ByteArrayInputStream bais = new ByteArrayInputStream(xml.getBytes()); - try { - XMLDecoder decoder = new XMLDecoder(bais); - this.eventData = (Map<String, Object>) decoder.readObject(); - } catch (Exception e) { - throw new EventException("Error decoding " + xml, e); + if ("1".equals(System.getProperty("org.slf4j.ext.allowInsecureDeserialization"))) { + ByteArrayInputStream bais = new ByteArrayInputStream(xml.getBytes()); + try { + XMLDecoder decoder = new XMLDecoder(bais); + this.eventData = (Map<String, Object>) decoder.readObject(); + } catch (Exception e) { + throw new EventException("Error decoding " + xml, e); + } + } else { + throw new UnsupportedOperationException( + "Constructing EventData from XML is vulnerable to remote " + + "excution and is not allowed by default. If you're " + + "completely sure the source data is trusted, you can enable " + + "it by setting org.slf4j.ext.allowInsecureDeserialization " + + "JVM property to 1"); } } @@ -302,4 +311,4 @@ public class EventData implements Serial public int hashCode() { return this.eventData.hashCode(); } -} \ No newline at end of file +}
