Hello community,

here is the log from the commit of package slf4j for openSUSE:Factory checked 
in at 2018-05-18 14:28:32
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/slf4j (Old)
 and      /work/SRC/openSUSE:Factory/.slf4j.new (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "slf4j"

Fri May 18 14:28:32 2018 rev:15 rq:610260 version:1.7.12

Changes:
--------
--- /work/SRC/openSUSE:Factory/slf4j/slf4j.changes      2017-10-21 
20:20:30.406565945 +0200
+++ /work/SRC/openSUSE:Factory/.slf4j.new/slf4j.changes 2018-05-18 
14:28:36.924801961 +0200
@@ -1,0 +2,10 @@
+Fri May 18 09:17:44 UTC 2018 - [email protected]
+
+- Security fix:  [bsc#1085970, CVE-2018-8088]
+  * Disallow EventData deserialization by default
+  * Added slf4j-Disallow-EventData-deserialization-by-default.patch
+    refreshed from Fedora [ https://src.fedoraproject.org/rpms/slf4j/
+    blob/d7cd96bc7a8e8d8d62c8bc62baa7df02cef56c63/f/
+    0001-Disallow-EventData-deserialization-by-default.patch ]
+
+-------------------------------------------------------------------

New:
----
  slf4j-Disallow-EventData-deserialization-by-default.patch

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ slf4j.spec ++++++
--- /var/tmp/diff_new_pack.pYXUPc/_old  2018-05-18 14:28:37.768770990 +0200
+++ /var/tmp/diff_new_pack.pYXUPc/_new  2018-05-18 14:28:37.772770843 +0200
@@ -1,7 +1,7 @@
 #
 # spec file for package slf4j
 #
-# Copyright (c) 2017 SUSE LINUX GmbH, Nuernberg, Germany.
+# Copyright (c) 2018 SUSE LINUX GmbH, Nuernberg, Germany.
 # Copyright (c) 2000-2009, JPackage Project
 #
 # All modifications and additions to the file contributed by third parties
@@ -28,6 +28,7 @@
 Source1:        build.xml.tar.bz2
 Patch1:         build-remove-slf4j_api-binder.patch
 Patch2:         slf4j-commons-lang3.patch
+Patch3:         slf4j-Disallow-EventData-deserialization-by-default.patch
 BuildRequires:  ant >= 1.6.5
 BuildRequires:  ant-junit >= 1.6.5
 BuildRequires:  apache-commons-lang3
@@ -77,6 +78,7 @@
 tar xjf %{SOURCE1}
 %patch1 -p1
 %patch2 -p1
+%patch3 -p1
 find . -name "*.jar" | xargs rm
 
 sed -i -e "s|ant<|org.apache.ant<|g" integration/pom.xml

++++++ slf4j-Disallow-EventData-deserialization-by-default.patch ++++++
Index: slf4j-1.7.12/slf4j-ext/src/main/java/org/slf4j/ext/EventData.java
===================================================================
--- slf4j-1.7.12.orig/slf4j-ext/src/main/java/org/slf4j/ext/EventData.java
+++ slf4j-1.7.12/slf4j-ext/src/main/java/org/slf4j/ext/EventData.java
@@ -76,12 +76,21 @@ public class EventData implements Serial
      */
     @SuppressWarnings("unchecked")
     public EventData(String xml) {
-        ByteArrayInputStream bais = new ByteArrayInputStream(xml.getBytes());
-        try {
-            XMLDecoder decoder = new XMLDecoder(bais);
-            this.eventData = (Map<String, Object>) decoder.readObject();
-        } catch (Exception e) {
-            throw new EventException("Error decoding " + xml, e);
+       if 
("1".equals(System.getProperty("org.slf4j.ext.allowInsecureDeserialization"))) {
+           ByteArrayInputStream bais = new 
ByteArrayInputStream(xml.getBytes());
+           try {
+               XMLDecoder decoder = new XMLDecoder(bais);
+               this.eventData = (Map<String, Object>) decoder.readObject();
+           } catch (Exception e) {
+               throw new EventException("Error decoding " + xml, e);
+           }
+       } else {
+           throw new UnsupportedOperationException(
+                   "Constructing EventData from XML is vulnerable to remote " +
+                    "excution and is not allowed by default. If you're " +
+                    "completely sure the source data is trusted, you can 
enable " +
+                    "it by setting org.slf4j.ext.allowInsecureDeserialization 
" +
+                    "JVM property to 1");
         }
     }
 
@@ -302,4 +311,4 @@ public class EventData implements Serial
     public int hashCode() {
         return this.eventData.hashCode();
     }
-}
\ No newline at end of file
+}

Reply via email to