aboutsummaryrefslogtreecommitdiff
path: root/mail
diff options
context:
space:
mode:
authorRodrigo Osorio <rodrigo@FreeBSD.org>2014-12-10 09:58:25 +0000
committerRodrigo Osorio <rodrigo@FreeBSD.org>2014-12-10 09:58:25 +0000
commitf951023d0ea794a6cee3aba25f59f876a1b980a2 (patch)
treefcf618a5b62450d39ff0c3febe38956d298b71d0 /mail
parentb3fc172a8e8952a6377ed94e0711f2a2e2b43200 (diff)
downloadports-f951023d0ea794a6cee3aba25f59f876a1b980a2.tar.gz
ports-f951023d0ea794a6cee3aba25f59f876a1b980a2.zip
Notes
Diffstat (limited to 'mail')
-rw-r--r--mail/mutt/Makefile2
-rw-r--r--mail/mutt/files/patch-CVE-2014-911643
2 files changed, 44 insertions, 1 deletions
diff --git a/mail/mutt/Makefile b/mail/mutt/Makefile
index b41625e2d530..1156fb8f8bc2 100644
--- a/mail/mutt/Makefile
+++ b/mail/mutt/Makefile
@@ -3,7 +3,7 @@
PORTNAME= mutt
PORTVERSION= 1.5.23
-PORTREVISION?= 6
+PORTREVISION?= 7
CATEGORIES+= mail ipv6
MASTER_SITES= ftp://ftp.mutt.org/mutt/ \
ftp://ftp.mutt.org/mutt/devel/ \
diff --git a/mail/mutt/files/patch-CVE-2014-9116 b/mail/mutt/files/patch-CVE-2014-9116
new file mode 100644
index 000000000000..830d606bfbe6
--- /dev/null
+++ b/mail/mutt/files/patch-CVE-2014-9116
@@ -0,0 +1,43 @@
+# HG changeset patch
+# User Kevin McCarthy <kevin@8t8.us>
+# Date 1417472364 28800
+# Mon Dec 01 14:19:24 2014 -0800
+# Branch stable
+# Node ID 54c59aaf88b9f6b50f1078fc6f7551fa9315ac3e
+# Parent 1b583341d5ad677c8a1935eb4110eba27606878a
+Revert write_one_header() to skip space and tab. (closes #3716)
+
+This patch fixes CVE-2014-9116 in the stable branch. It reverts
+write_one_header() to the pre [f251d523ca5a] code for skipping
+whitespace.
+
+Thanks to Antonio Radici and Tomas Hoger for their analysis and patches
+to mutt, which this patch is based off of.
+
+diff --git a/sendlib.c b/sendlib.c
+--- sendlib.c
++++ sendlib.c
+@@ -1809,17 +1809,22 @@
+ {
+ tagbuf = NULL;
+ valbuf = mutt_substrdup (start, end);
+ }
+ else
+ {
+ tagbuf = mutt_substrdup (start, t);
+ /* skip over the colon separating the header field name and value */
+- t = skip_email_wsp(t + 1);
++ ++t;
++
++ /* skip over any leading whitespace (WSP, as defined in RFC5322) */
++ while (*t == ' ' || *t == '\t')
++ t++;
++
+ valbuf = mutt_substrdup (t, end);
+ }
+ dprint(4,(debugfile,"mwoh: buf[%s%s] too long, "
+ "max width = %d > %d\n",
+ NONULL(pfx), valbuf, max, wraplen));
+ if (fold_one_header (fp, tagbuf, valbuf, pfx, wraplen, flags) < 0)
+ return -1;
+ FREE (&tagbuf);