未验证 提交 90d15ab3 编写于 作者: O openharmony_ci 提交者: Gitee

!57 fix CVE-2022-2068(3.1release)

Merge pull request !57 from HaixiangW/cherry-pick-1656070700
#!{- $config{HASHBANGPERL} -} #!{- $config{HASHBANGPERL} -}
# {- join("\n# ", @autowarntext) -} # {- join("\n# ", @autowarntext) -}
# Copyright 1999-2021 The OpenSSL Project Authors. All Rights Reserved. # Copyright 1999-2022 The OpenSSL Project Authors. All Rights Reserved.
# #
# Licensed under the OpenSSL license (the "License"). You may not use # Licensed under the OpenSSL license (the "License"). You may not use
# this file except in compliance with the License. You can obtain a copy # this file except in compliance with the License. You can obtain a copy
...@@ -104,52 +104,78 @@ foreach (@dirlist) { ...@@ -104,52 +104,78 @@ foreach (@dirlist) {
} }
exit($errorcount); exit($errorcount);
sub copy_file {
my ($src_fname, $dst_fname) = @_;
if (open(my $in, "<", $src_fname)) {
if (open(my $out, ">", $dst_fname)) {
print $out $_ while (<$in>);
close $out;
} else {
warn "Cannot open $dst_fname for write, $!";
}
close $in;
} else {
warn "Cannot open $src_fname for read, $!";
}
}
sub hash_dir { sub hash_dir {
my %hashlist; my $dir = shift;
print "Doing $_[0]\n"; my %hashlist;
chdir $_[0];
opendir(DIR, "."); print "Doing $dir\n";
my @flist = sort readdir(DIR);
closedir DIR; if (!chdir $dir) {
if ( $removelinks ) { print STDERR "WARNING: Cannot chdir to '$dir', $!\n";
# Delete any existing symbolic links return;
foreach (grep {/^[\da-f]+\.r{0,1}\d+$/} @flist) { }
if (-l $_) {
print "unlink $_" if $verbose; opendir(DIR, ".") || print STDERR "WARNING: Cannot opendir '.', $!\n";
unlink $_ || warn "Can't unlink $_, $!\n"; my @flist = sort readdir(DIR);
} closedir DIR;
} if ( $removelinks ) {
} # Delete any existing symbolic links
FILE: foreach $fname (grep {/\.(pem)|(crt)|(cer)|(crl)$/} @flist) { foreach (grep {/^[\da-f]+\.r{0,1}\d+$/} @flist) {
# Check to see if certificates and/or CRLs present. if (-l $_) {
my ($cert, $crl) = check_file($fname); print "unlink $_\n" if $verbose;
if (!$cert && !$crl) { unlink $_ || warn "Can't unlink $_, $!\n";
print STDERR "WARNING: $fname does not contain a certificate or CRL: skipping\n"; }
next; }
} }
link_hash_cert($fname) if ($cert); FILE: foreach $fname (grep {/\.(pem)|(crt)|(cer)|(crl)$/} @flist) {
link_hash_crl($fname) if ($crl); # Check to see if certificates and/or CRLs present.
} my ($cert, $crl) = check_file($fname);
if (!$cert && !$crl) {
print STDERR "WARNING: $fname does not contain a certificate or CRL: skipping\n";
next;
}
link_hash_cert($fname) if ($cert);
link_hash_crl($fname) if ($crl);
}
chdir $pwd;
} }
sub check_file { sub check_file {
my ($is_cert, $is_crl) = (0,0); my ($is_cert, $is_crl) = (0,0);
my $fname = $_[0]; my $fname = $_[0];
open IN, $fname;
while(<IN>) { open(my $in, "<", $fname);
if (/^-----BEGIN (.*)-----/) { while(<$in>) {
my $hdr = $1; if (/^-----BEGIN (.*)-----/) {
if ($hdr =~ /^(X509 |TRUSTED |)CERTIFICATE$/) { my $hdr = $1;
$is_cert = 1; if ($hdr =~ /^(X509 |TRUSTED |)CERTIFICATE$/) {
last if ($is_crl); $is_cert = 1;
} elsif ($hdr eq "X509 CRL") { last if ($is_crl);
$is_crl = 1; } elsif ($hdr eq "X509 CRL") {
last if ($is_cert); $is_crl = 1;
} last if ($is_cert);
} }
} }
close IN; }
return ($is_cert, $is_crl); close $in;
return ($is_cert, $is_crl);
} }
sub compute_hash { sub compute_hash {
...@@ -177,76 +203,48 @@ sub compute_hash { ...@@ -177,76 +203,48 @@ sub compute_hash {
# certificate fingerprints # certificate fingerprints
sub link_hash_cert { sub link_hash_cert {
my $fname = $_[0]; link_hash($_[0], 'cert');
my ($hash, $fprint) = compute_hash($openssl, "x509", $x509hash,
"-fingerprint", "-noout",
"-in", $fname);
chomp $hash;
chomp $fprint;
return if !$hash;
$fprint =~ s/^.*=//;
$fprint =~ tr/://d;
my $suffix = 0;
# Search for an unused hash filename
while(exists $hashlist{"$hash.$suffix"}) {
# Hash matches: if fingerprint matches its a duplicate cert
if ($hashlist{"$hash.$suffix"} eq $fprint) {
print STDERR "WARNING: Skipping duplicate certificate $fname\n";
return;
}
$suffix++;
}
$hash .= ".$suffix";
if ($symlink_exists) {
print "link $fname -> $hash\n" if $verbose;
symlink $fname, $hash || warn "Can't symlink, $!";
} else {
print "copy $fname -> $hash\n" if $verbose;
if (open($in, "<", $fname)) {
if (open($out,">", $hash)) {
print $out $_ while (<$in>);
close $out;
} else {
warn "can't open $hash for write, $!";
}
close $in;
} else {
warn "can't open $fname for read, $!";
}
}
$hashlist{$hash} = $fprint;
} }
# Same as above except for a CRL. CRL links are of the form <hash>.r<n> # Same as above except for a CRL. CRL links are of the form <hash>.r<n>
sub link_hash_crl { sub link_hash_crl {
my $fname = $_[0]; link_hash($_[0], 'crl');
my ($hash, $fprint) = compute_hash($openssl, "crl", $crlhash, }
"-fingerprint", "-noout",
"-in", $fname); sub link_hash {
chomp $hash; my ($fname, $type) = @_;
chomp $fprint; my $is_cert = $type eq 'cert';
return if !$hash;
$fprint =~ s/^.*=//; my ($hash, $fprint) = compute_hash($openssl,
$fprint =~ tr/://d; $is_cert ? "x509" : "crl",
my $suffix = 0; $is_cert ? $x509hash : $crlhash,
# Search for an unused hash filename "-fingerprint", "-noout",
while(exists $hashlist{"$hash.r$suffix"}) { "-in", $fname);
# Hash matches: if fingerprint matches its a duplicate cert chomp $hash;
if ($hashlist{"$hash.r$suffix"} eq $fprint) { chomp $fprint;
print STDERR "WARNING: Skipping duplicate CRL $fname\n"; return if !$hash;
return; $fprint =~ s/^.*=//;
} $fprint =~ tr/://d;
$suffix++; my $suffix = 0;
} # Search for an unused hash filename
$hash .= ".r$suffix"; my $crlmark = $is_cert ? "" : "r";
if ($symlink_exists) { while(exists $hashlist{"$hash.$crlmark$suffix"}) {
print "link $fname -> $hash\n" if $verbose; # Hash matches: if fingerprint matches its a duplicate cert
symlink $fname, $hash || warn "Can't symlink, $!"; if ($hashlist{"$hash.$crlmark$suffix"} eq $fprint) {
} else { my $what = $is_cert ? 'certificate' : 'CRL';
print "cp $fname -> $hash\n" if $verbose; print STDERR "WARNING: Skipping duplicate $what $fname\n";
system ("cp", $fname, $hash); return;
warn "Can't copy, $!" if ($? >> 8) != 0; }
} $suffix++;
$hashlist{$hash} = $fprint; }
$hash .= ".$crlmark$suffix";
if ($symlink_exists) {
print "link $fname -> $hash\n" if $verbose;
symlink $fname, $hash || warn "Can't symlink, $!";
} else {
print "copy $fname -> $hash\n" if $verbose;
copy_file($fname, $hash);
}
$hashlist{$hash} = $fprint;
} }
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册