pkgsrc-Bugs archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: pkg/60648 (editors/emacs20: LP64 Lisp_Object truncation breaks Japanese input, plus two unbackported CVEs)



The following reply was made to PR pkg/60648; it has been noted by GNATS.

From: Showta Ishizaki <zakinko%snowrabbit.org@localhost>
To: gnats-bugs%NetBSD.org@localhost
Cc: zakinko%snowrabbit.org@localhost
Subject: Re: pkg/60648 (editors/emacs20: LP64 Lisp_Object truncation breaks Japanese input, plus two unbackported CVEs)
Date: Sun, 27 Sep 2026 00:35:46 +0900 (JST)

 A follow-up, with three additions that belong with this PR.
 
 rcs2log kept its scratch files under $TMPDIR with predictable names,
 so a planted symlink had the rlog output written over the caller's
 file (CVE-2001-1301, fixed in Emacs 21).  patch-lib-src_rcs2log moves
 them into a mktemp -d directory.  I planted the symlinks and ran it
 before and after: the victim file was overwritten before and is intact
 after.
 
 browse-url-mosaic wrote /tmp/Mosaic.<pid> by visiting it, so a symlink
 at that name had the URL written through it (CVE-2014-3423, fixed in
 24.4).  Emacs 20 has no O_EXCL write-region, so
 patch-lisp_browse-url.el writes the file in a private directory and
 renames it into place, which replaces a symlink instead of following
 it.  The distfile ships browse-url.elc and Emacs prefers it, so the
 Makefile gains a post-build step that recompiles that one file.  Tested
 the same way: the victim was overwritten before, and after the fix it
 is intact and the name holds a fresh 0600 file.
 
 Neither CVE had an emacs20 line in doc/pkg-vulnerabilities, and the
 two CVEs this PR already fixes are listed there as emacs20-[0-9]*.  The
 second diff below bounds those at 20.7nb27 and adds the three missing
 entries.
 
 Both diffs go on top of the PR and apply to pkgsrc trunk as of
 2026-09-27 (editors/emacs20/Makefile 1.69, pkg-vulnerabilities 1.799);
 with them emacs20-20.7nb27 builds on NetBSD/amd64.  The two new patch
 files need a cvs add.
 
 Please let me know if you would rather have these as a separate PR; I
 am happy to split them out.
 
 --- editors/emacs20/Makefile
 +++ editors/emacs20/Makefile
 @@ -104,6 +104,12 @@
  	${CP} ${FILESDIR}/amd64.h ${WRKSRC}/src/m
  	${CP} ${FILESDIR}/dragonfly.h ${WRKSRC}/src/s
  
 +# The distfile ships byte-compiled lisp, and the dump and load-path both
 +# prefer it, so a patched .el has no effect until it is recompiled.
 +post-build:
 +	cd ${WRKSRC}/lisp && EMACSLOADPATH=${WRKSRC}/lisp \
 +		../src/emacs -batch -q -no-site-file -f batch-byte-compile browse-url.el
 +
  pre-install:
  	@${FIND} ${WRKSRC} -type f -name "*.orig*" -print | ${XARGS} ${RM} -f
  
 --- editors/emacs20/distinfo
 +++ editors/emacs20/distinfo
 @@ -56,6 +56,8 @@
  SHA1 (patch-ce) = df4d2a5639a72d2c719662496f17db35686f4ac2
  SHA1 (patch-cf) = 1b5b83eb02872414fd7ca29c344c0560feaf1b7e
  SHA1 (patch-cg) = b2bd4cbff399922e44ad54459255ffb1d61e1bd4
 +SHA1 (patch-lib-src_rcs2log) = df71b903017e6b6c39937bb8c926c1a55c0b0565
 +SHA1 (patch-lisp_browse-url.el) = 735de4ec11079582f551754faa1e96a1a4b3736d
  SHA1 (patch-src_coding.h) = 25e759b5484fdf21076807fb47ebfacb6906d97c
  SHA1 (patch-src_m_aarch64.h) = 861757ce6568303ea55cb9c9f290abc6100d3dc2
  SHA1 (patch-src_xrdb.c) = 34b87fca7d84f286a283a6defea62954eafca2d0
 --- editors/emacs20/patches/patch-lib-src_rcs2log
 +++ editors/emacs20/patches/patch-lib-src_rcs2log
 @@ -0,0 +1,34 @@
 +$NetBSD$
 +
 +rcs2log kept its two scratch files under $TMPDIR with predictable names
 +(rcs2log<pid>l, rcs2log<pid>r), so a local user could plant symlinks and
 +have the rlog output written over the caller's files (CVE-2001-1301,
 +fixed in Emacs 21).  A private directory from mktemp -d holds them now,
 +and is removed on every exit path.
 +
 +--- lib-src/rcs2log.orig
 ++++ lib-src/rcs2log
 +@@ -300,10 +300,11 @@
 + 	esac
 + esac
 + 
 +-llogout=$TMPDIR/rcs2log$$l
 +-rlogout=$TMPDIR/rcs2log$$r
 ++tmpdir=`mktemp -d "${TMPDIR}/rcs2logXXXXXX"` || exit
 ++llogout=$tmpdir/l
 ++rlogout=$tmpdir/r
 + trap exit 1 2 13 15
 +-trap "rm -f $llogout $rlogout; exit 1" 0
 ++trap "rm -fr $tmpdir; exit 1" 0
 + 
 + case $datearg in
 + ?*) $rlog $rlog_options "$datearg" ${1+"$@"} >$rlogout;;
 +@@ -670,7 +671,7 @@
 + 
 + # Exit successfully.
 + 
 +-exec rm -f $llogout $rlogout
 ++exec rm -fr $tmpdir
 + 
 + # Local Variables:
 + # tab-width:4
 --- editors/emacs20/patches/patch-lisp_browse-url.el
 +++ editors/emacs20/patches/patch-lisp_browse-url.el
 @@ -0,0 +1,46 @@
 +$NetBSD$
 +
 +browse-url-mosaic wrote the remote-control file /tmp/Mosaic.<pid> by
 +visiting it, so a symlink planted at that name had the URL written over
 +its target (CVE-2014-3423, fixed in Emacs 24.4).  Mosaic dictates the
 +name; write the file in a private directory and rename it into place,
 +which replaces a symlink rather than following it.  Emacs 20 has no
 +O_EXCL write-region, which is what upstream uses.
 +
 +--- lisp/browse-url.el.orig
 ++++ lisp/browse-url.el
 +@@ -792,15 +792,25 @@
 + 	  (setq pid (read (current-buffer)))
 + 	  (kill-buffer nil)))
 +     (if (and pid (zerop (signal-process pid 0))) ; Mosaic running
 +-	(save-excursion
 +-	  (find-file (format "/tmp/Mosaic.%d" pid))
 +-	  (erase-buffer)
 +-	  (insert (if new-window
 +-		      "newwin\n"
 +-		    "goto\n")
 +-		  url "\n")
 +-	  (save-buffer)
 +-	  (kill-buffer nil)
 ++	(let ((dir (make-temp-name "/tmp/browse-url"))
 ++	      (umask (default-file-modes)))
 ++	  ;; Mosaic reads /tmp/Mosaic.<pid>, so the name is fixed.  Write it
 ++	  ;; in a directory only we can enter and rename it into place:
 ++	  ;; rename replaces whatever sits at the name, a symlink included,
 ++	  ;; and never writes through it.
 ++	  (unwind-protect
 ++	      (let ((tmp (expand-file-name "Mosaic" dir)))
 ++		(set-default-file-modes ?\700)
 ++		(make-directory dir)
 ++		(with-temp-buffer
 ++		  (insert (if new-window
 ++			      "newwin\n"
 ++			    "goto\n")
 ++			  url "\n")
 ++		  (write-region (point-min) (point-max) tmp nil 'silent))
 ++		(rename-file tmp (format "/tmp/Mosaic.%d" pid) t))
 ++	    (set-default-file-modes umask)
 ++	    (condition-case nil (delete-directory dir) (error nil)))
 + 	  ;; Send signal SIGUSR to Mosaic
 + 	  (message "Signalling Mosaic...")
 + 	  (signal-process pid browse-url-usr1-signal)
 
 --- doc/pkg-vulnerabilities.orig
 +++ doc/pkg-vulnerabilities
 @@ -13791,7 +13791,7 @@
  evince<3.25.91		command-injection		https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-1000159
  vim<8.0.1345		insecure-temporary-files	https://nvd.nist.gov/vuln/detail/CVE-2017-1000382
  bzr<2.6.0nb1		arbitrary-command-execution	https://nvd.nist.gov/vuln/detail/CVE-2017-14176
 -emacs20-[0-9]*		insecure-temporary-files	https://nvd.nist.gov/vuln/detail/CVE-2017-1000383
 +emacs20<20.7nb27		insecure-temporary-files	https://nvd.nist.gov/vuln/detail/CVE-2017-1000383
  emacs21-[0-9]*		insecure-temporary-files	https://nvd.nist.gov/vuln/detail/CVE-2017-1000383
  emacs21-nox11-[0-9]*		insecure-temporary-files	https://nvd.nist.gov/vuln/detail/CVE-2017-1000383
  emacs25-[0-9]*		insecure-temporary-files	https://nvd.nist.gov/vuln/detail/CVE-2017-1000383
 @@ -23950,7 +23950,7 @@
  xterm<375	remote-code-execution	https://nvd.nist.gov/vuln/detail/CVE-2022-45063
  postgresql10-*	eol    	https://ftp.NetBSD.org/pub/NetBSD/packages/vulns/eol-packages
  py{27,36,37,38,39,310}-sip<5	eol	https://ftp.NetBSD.org/pub/NetBSD/packages/vulns/eol-packages
 -emacs20-[0-9]*		arbitrary-code-execution	https://nvd.nist.gov/vuln/detail/CVE-2022-45939
 +emacs20<20.7nb27		arbitrary-code-execution	https://nvd.nist.gov/vuln/detail/CVE-2022-45939
  emacs21-[0-9]*		arbitrary-code-execution	https://nvd.nist.gov/vuln/detail/CVE-2022-45939
  emacs21-nox11-[0-9]*		arbitrary-code-execution	https://nvd.nist.gov/vuln/detail/CVE-2022-45939
  emacs25-[0-9]*		arbitrary-code-execution	https://nvd.nist.gov/vuln/detail/CVE-2022-45939
 @@ -30454,3 +30454,6 @@
  ruby{33,34,40}-zip<3.4.0	path-traversal	https://www.cve.org/CVERecord?id=CVE-2026-85396
  ruby{33,34,40}-zip24-[0-9]*		path-traversal	https://www.cve.org/CVERecord?id=CVE-2026-85396
  ruby{33,34}-faraday1<1.10.5	server-side-request-forgery	https://nvd.nist.gov/vuln/detail/CVE-2026-25765
 +emacs20<20.7nb27		shell-command-injection	https://nvd.nist.gov/vuln/detail/CVE-2022-48337
 +emacs20<20.7nb27		symlink-attack		https://nvd.nist.gov/vuln/detail/CVE-2001-1301
 +emacs20<20.7nb27		temporary-file-race	https://nvd.nist.gov/vuln/detail/CVE-2014-3423
 



Home | Main Index | Thread Index | Old Index