pkgsrc-Bugs archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]
Re: pkg/60648 (editors/emacs20: LP64 Lisp_Object truncation breaks Japanese input, plus two unbackported CVEs)
The following reply was made to PR pkg/60648; it has been noted by GNATS.
From: Showta Ishizaki <zakinko%snowrabbit.org@localhost>
To: gnats-bugs%NetBSD.org@localhost
Cc: zakinko%snowrabbit.org@localhost
Subject: Re: pkg/60648 (editors/emacs20: LP64 Lisp_Object truncation breaks Japanese input, plus two unbackported CVEs)
Date: Sun, 27 Sep 2026 00:35:46 +0900 (JST)
A follow-up, with three additions that belong with this PR.
rcs2log kept its scratch files under $TMPDIR with predictable names,
so a planted symlink had the rlog output written over the caller's
file (CVE-2001-1301, fixed in Emacs 21). patch-lib-src_rcs2log moves
them into a mktemp -d directory. I planted the symlinks and ran it
before and after: the victim file was overwritten before and is intact
after.
browse-url-mosaic wrote /tmp/Mosaic.<pid> by visiting it, so a symlink
at that name had the URL written through it (CVE-2014-3423, fixed in
24.4). Emacs 20 has no O_EXCL write-region, so
patch-lisp_browse-url.el writes the file in a private directory and
renames it into place, which replaces a symlink instead of following
it. The distfile ships browse-url.elc and Emacs prefers it, so the
Makefile gains a post-build step that recompiles that one file. Tested
the same way: the victim was overwritten before, and after the fix it
is intact and the name holds a fresh 0600 file.
Neither CVE had an emacs20 line in doc/pkg-vulnerabilities, and the
two CVEs this PR already fixes are listed there as emacs20-[0-9]*. The
second diff below bounds those at 20.7nb27 and adds the three missing
entries.
Both diffs go on top of the PR and apply to pkgsrc trunk as of
2026-09-27 (editors/emacs20/Makefile 1.69, pkg-vulnerabilities 1.799);
with them emacs20-20.7nb27 builds on NetBSD/amd64. The two new patch
files need a cvs add.
Please let me know if you would rather have these as a separate PR; I
am happy to split them out.
--- editors/emacs20/Makefile
+++ editors/emacs20/Makefile
@@ -104,6 +104,12 @@
${CP} ${FILESDIR}/amd64.h ${WRKSRC}/src/m
${CP} ${FILESDIR}/dragonfly.h ${WRKSRC}/src/s
+# The distfile ships byte-compiled lisp, and the dump and load-path both
+# prefer it, so a patched .el has no effect until it is recompiled.
+post-build:
+ cd ${WRKSRC}/lisp && EMACSLOADPATH=${WRKSRC}/lisp \
+ ../src/emacs -batch -q -no-site-file -f batch-byte-compile browse-url.el
+
pre-install:
@${FIND} ${WRKSRC} -type f -name "*.orig*" -print | ${XARGS} ${RM} -f
--- editors/emacs20/distinfo
+++ editors/emacs20/distinfo
@@ -56,6 +56,8 @@
SHA1 (patch-ce) = df4d2a5639a72d2c719662496f17db35686f4ac2
SHA1 (patch-cf) = 1b5b83eb02872414fd7ca29c344c0560feaf1b7e
SHA1 (patch-cg) = b2bd4cbff399922e44ad54459255ffb1d61e1bd4
+SHA1 (patch-lib-src_rcs2log) = df71b903017e6b6c39937bb8c926c1a55c0b0565
+SHA1 (patch-lisp_browse-url.el) = 735de4ec11079582f551754faa1e96a1a4b3736d
SHA1 (patch-src_coding.h) = 25e759b5484fdf21076807fb47ebfacb6906d97c
SHA1 (patch-src_m_aarch64.h) = 861757ce6568303ea55cb9c9f290abc6100d3dc2
SHA1 (patch-src_xrdb.c) = 34b87fca7d84f286a283a6defea62954eafca2d0
--- editors/emacs20/patches/patch-lib-src_rcs2log
+++ editors/emacs20/patches/patch-lib-src_rcs2log
@@ -0,0 +1,34 @@
+$NetBSD$
+
+rcs2log kept its two scratch files under $TMPDIR with predictable names
+(rcs2log<pid>l, rcs2log<pid>r), so a local user could plant symlinks and
+have the rlog output written over the caller's files (CVE-2001-1301,
+fixed in Emacs 21). A private directory from mktemp -d holds them now,
+and is removed on every exit path.
+
+--- lib-src/rcs2log.orig
++++ lib-src/rcs2log
+@@ -300,10 +300,11 @@
+ esac
+ esac
+
+-llogout=$TMPDIR/rcs2log$$l
+-rlogout=$TMPDIR/rcs2log$$r
++tmpdir=`mktemp -d "${TMPDIR}/rcs2logXXXXXX"` || exit
++llogout=$tmpdir/l
++rlogout=$tmpdir/r
+ trap exit 1 2 13 15
+-trap "rm -f $llogout $rlogout; exit 1" 0
++trap "rm -fr $tmpdir; exit 1" 0
+
+ case $datearg in
+ ?*) $rlog $rlog_options "$datearg" ${1+"$@"} >$rlogout;;
+@@ -670,7 +671,7 @@
+
+ # Exit successfully.
+
+-exec rm -f $llogout $rlogout
++exec rm -fr $tmpdir
+
+ # Local Variables:
+ # tab-width:4
--- editors/emacs20/patches/patch-lisp_browse-url.el
+++ editors/emacs20/patches/patch-lisp_browse-url.el
@@ -0,0 +1,46 @@
+$NetBSD$
+
+browse-url-mosaic wrote the remote-control file /tmp/Mosaic.<pid> by
+visiting it, so a symlink planted at that name had the URL written over
+its target (CVE-2014-3423, fixed in Emacs 24.4). Mosaic dictates the
+name; write the file in a private directory and rename it into place,
+which replaces a symlink rather than following it. Emacs 20 has no
+O_EXCL write-region, which is what upstream uses.
+
+--- lisp/browse-url.el.orig
++++ lisp/browse-url.el
+@@ -792,15 +792,25 @@
+ (setq pid (read (current-buffer)))
+ (kill-buffer nil)))
+ (if (and pid (zerop (signal-process pid 0))) ; Mosaic running
+- (save-excursion
+- (find-file (format "/tmp/Mosaic.%d" pid))
+- (erase-buffer)
+- (insert (if new-window
+- "newwin\n"
+- "goto\n")
+- url "\n")
+- (save-buffer)
+- (kill-buffer nil)
++ (let ((dir (make-temp-name "/tmp/browse-url"))
++ (umask (default-file-modes)))
++ ;; Mosaic reads /tmp/Mosaic.<pid>, so the name is fixed. Write it
++ ;; in a directory only we can enter and rename it into place:
++ ;; rename replaces whatever sits at the name, a symlink included,
++ ;; and never writes through it.
++ (unwind-protect
++ (let ((tmp (expand-file-name "Mosaic" dir)))
++ (set-default-file-modes ?\700)
++ (make-directory dir)
++ (with-temp-buffer
++ (insert (if new-window
++ "newwin\n"
++ "goto\n")
++ url "\n")
++ (write-region (point-min) (point-max) tmp nil 'silent))
++ (rename-file tmp (format "/tmp/Mosaic.%d" pid) t))
++ (set-default-file-modes umask)
++ (condition-case nil (delete-directory dir) (error nil)))
+ ;; Send signal SIGUSR to Mosaic
+ (message "Signalling Mosaic...")
+ (signal-process pid browse-url-usr1-signal)
--- doc/pkg-vulnerabilities.orig
+++ doc/pkg-vulnerabilities
@@ -13791,7 +13791,7 @@
evince<3.25.91 command-injection https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-1000159
vim<8.0.1345 insecure-temporary-files https://nvd.nist.gov/vuln/detail/CVE-2017-1000382
bzr<2.6.0nb1 arbitrary-command-execution https://nvd.nist.gov/vuln/detail/CVE-2017-14176
-emacs20-[0-9]* insecure-temporary-files https://nvd.nist.gov/vuln/detail/CVE-2017-1000383
+emacs20<20.7nb27 insecure-temporary-files https://nvd.nist.gov/vuln/detail/CVE-2017-1000383
emacs21-[0-9]* insecure-temporary-files https://nvd.nist.gov/vuln/detail/CVE-2017-1000383
emacs21-nox11-[0-9]* insecure-temporary-files https://nvd.nist.gov/vuln/detail/CVE-2017-1000383
emacs25-[0-9]* insecure-temporary-files https://nvd.nist.gov/vuln/detail/CVE-2017-1000383
@@ -23950,7 +23950,7 @@
xterm<375 remote-code-execution https://nvd.nist.gov/vuln/detail/CVE-2022-45063
postgresql10-* eol https://ftp.NetBSD.org/pub/NetBSD/packages/vulns/eol-packages
py{27,36,37,38,39,310}-sip<5 eol https://ftp.NetBSD.org/pub/NetBSD/packages/vulns/eol-packages
-emacs20-[0-9]* arbitrary-code-execution https://nvd.nist.gov/vuln/detail/CVE-2022-45939
+emacs20<20.7nb27 arbitrary-code-execution https://nvd.nist.gov/vuln/detail/CVE-2022-45939
emacs21-[0-9]* arbitrary-code-execution https://nvd.nist.gov/vuln/detail/CVE-2022-45939
emacs21-nox11-[0-9]* arbitrary-code-execution https://nvd.nist.gov/vuln/detail/CVE-2022-45939
emacs25-[0-9]* arbitrary-code-execution https://nvd.nist.gov/vuln/detail/CVE-2022-45939
@@ -30454,3 +30454,6 @@
ruby{33,34,40}-zip<3.4.0 path-traversal https://www.cve.org/CVERecord?id=CVE-2026-85396
ruby{33,34,40}-zip24-[0-9]* path-traversal https://www.cve.org/CVERecord?id=CVE-2026-85396
ruby{33,34}-faraday1<1.10.5 server-side-request-forgery https://nvd.nist.gov/vuln/detail/CVE-2026-25765
+emacs20<20.7nb27 shell-command-injection https://nvd.nist.gov/vuln/detail/CVE-2022-48337
+emacs20<20.7nb27 symlink-attack https://nvd.nist.gov/vuln/detail/CVE-2001-1301
+emacs20<20.7nb27 temporary-file-race https://nvd.nist.gov/vuln/detail/CVE-2014-3423
Home |
Main Index |
Thread Index |
Old Index