From e77499c7d6762c3cecf5f97fdef416f64d5c885f Mon Sep 17 00:00:00 2001 From: Thomas Gerbet Date: Sun, 30 Mar 2025 19:42:17 +0200 Subject: [PATCH] fig2dev: apply patches for CVE-2025-31162 and CVE-2025-31163 https://sourceforge.net/p/mcj/tickets/185/ https://sourceforge.net/p/mcj/tickets/186/ --- pkgs/by-name/fi/fig2dev/CVE-2025-31162.patch | 27 ++++++ pkgs/by-name/fi/fig2dev/CVE-2025-31163.patch | 91 ++++++++++++++++++++ pkgs/by-name/fi/fig2dev/package.nix | 5 ++ 3 files changed, 123 insertions(+) create mode 100644 pkgs/by-name/fi/fig2dev/CVE-2025-31162.patch create mode 100644 pkgs/by-name/fi/fig2dev/CVE-2025-31163.patch diff --git a/pkgs/by-name/fi/fig2dev/CVE-2025-31162.patch b/pkgs/by-name/fi/fig2dev/CVE-2025-31162.patch new file mode 100644 index 000000000000..4824c9254407 --- /dev/null +++ b/pkgs/by-name/fi/fig2dev/CVE-2025-31162.patch @@ -0,0 +1,27 @@ +commit da8992f44b84a337b4edaa67fc8b36b55eaef696 +Date: Wed Jan 22 23:18:54 2025 +0100 + + Reject huge pattern lengths, ticket #185 + + Reject patterned lines, e.g., dashed lines, where the + pattern length exceeds 80 inches. + +diff --git a/fig2dev/object.h b/fig2dev/object.h +index 29f5a62..7f83939 100644 +--- a/fig2dev/object.h ++++ b/fig2dev/object.h +@@ -57,12 +57,13 @@ typedef struct f_comment { + struct f_comment *next; + } F_comment; + ++#define STYLE_VAL_MAX 6400.0 /* dash length 80 inches, that is enough */ + #define COMMON_PROPERTIES(o) \ + o->style < SOLID_LINE || o->style > DASH_3_DOTS_LINE || \ + o->thickness < 0 || o->depth < 0 || o->depth > 999 || \ + o->fill_style < UNFILLED || \ + o->fill_style >= NUMSHADES + NUMTINTS + NUMPATTERNS || \ +- o->style_val < 0.0 ++ o->style_val < 0.0 || o->style_val > STYLE_VAL_MAX + + typedef struct f_ellipse { + int type; diff --git a/pkgs/by-name/fi/fig2dev/CVE-2025-31163.patch b/pkgs/by-name/fi/fig2dev/CVE-2025-31163.patch new file mode 100644 index 000000000000..ed350b6e88d4 --- /dev/null +++ b/pkgs/by-name/fi/fig2dev/CVE-2025-31163.patch @@ -0,0 +1,91 @@ +commit c8a87d22036e62bac0c6f7836078d8103caa6457 +Author: Thomas Loimer +Date: Wed Jan 22 23:27:43 2025 +0100 + + Reject arcs with co-incident points, ticket #186 + +diff --git a/fig2dev/object.h b/fig2dev/object.h +index 7f83939..50afbf0 100644 +--- a/fig2dev/object.h ++++ b/fig2dev/object.h +@@ -3,7 +3,7 @@ + * Copyright (c) 1991 by Micah Beck + * Parts Copyright (c) 1985-1988 by Supoj Sutanthavibul + * Parts Copyright (c) 1989-2015 by Brian V. Smith +- * Parts Copyright (c) 2015-2023 by Thomas Loimer ++ * Parts Copyright (c) 2015-2025 by Thomas Loimer + * + * Any party obtaining a copy of these files is granted, free of charge, a + * full and unrestricted irrevocable, world-wide, paid up, royalty-free, +@@ -92,10 +92,10 @@ typedef struct f_ellipse { + struct f_ellipse *next; + } F_ellipse; + +-#define INVALID_ELLIPSE(e) \ ++#define INVALID_ELLIPSE(e) \ + e->type < T_ELLIPSE_BY_RAD || e->type > T_CIRCLE_BY_DIA || \ +- COMMON_PROPERTIES(e) || (e->direction != 1 && e->direction != 0) || \ +- e->radiuses.x == 0 || e->radiuses.y == 0 || \ ++ COMMON_PROPERTIES(e) || (e->direction != 1 && e->direction != 0) || \ ++ e->radiuses.x == 0 || e->radiuses.y == 0 || \ + e->angle < -7. || e->angle > 7. + + typedef struct f_arc { +@@ -126,12 +126,16 @@ typedef struct f_arc { + #define CIRCARC 9 + #define CIRCULARARC > 8 + +-#define INVALID_ARC(a) \ ++#define COINCIDENT(a, b) (a.x == b.x && a.y == b.y) ++#define INVALID_ARC(a) \ + a->type < T_OPEN_ARC || a->type > T_PIE_WEDGE_ARC || \ + COMMON_PROPERTIES(a) || a->cap_style < 0 || a->cap_style > 2 || \ + a->center.x < COORD_MIN || a->center.x > COORD_MAX || \ + a->center.y < COORD_MIN || a->center.y > COORD_MAX || \ +- (a->direction != 0 && a->direction != 1) ++ (a->direction != 0 && a->direction != 1) || \ ++ COINCIDENT(a->point[0], a->point[1]) || \ ++ COINCIDENT(a->point[0], a->point[2]) || \ ++ COINCIDENT(a->point[1], a->point[2]) + + typedef struct f_line { + int type; +diff --git a/fig2dev/tests/read.at b/fig2dev/tests/read.at +index 1b4baea..da9ea3e 100644 +--- a/fig2dev/tests/read.at ++++ b/fig2dev/tests/read.at +@@ -2,7 +2,7 @@ dnl Fig2dev: Translate Fig code to various Devices + dnl Copyright (c) 1991 by Micah Beck + dnl Parts Copyright (c) 1985-1988 by Supoj Sutanthavibul + dnl Parts Copyright (c) 1989-2015 by Brian V. Smith +-dnl Parts Copyright (c) 2015-2024 by Thomas Loimer ++dnl Parts Copyright (c) 2015-2025 by Thomas Loimer + dnl + dnl Any party obtaining a copy of these files is granted, free of charge, a + dnl full and unrestricted irrevocable, world-wide, paid up, royalty-free, +@@ -14,7 +14,7 @@ dnl party to do so, with the only requirement being that the above copyright + dnl and this permission notice remain intact. + + dnl read.at +-dnl Author: Thomas Loimer, 2017-2024 ++dnl Author: Thomas Loimer, 2017-2025 + + + AT_BANNER([Sanitize and harden input.]) +@@ -248,6 +248,16 @@ EOF + ]) + AT_CLEANUP + ++AT_SETUP([reject arcs with coincident points, ticket #186]) ++AT_KEYWORDS(read.c arc) ++AT_CHECK([fig2dev -L pict2e <