libupnp-1.14.12
This commit is contained in:
@@ -9,8 +9,7 @@ from pisi.actionsapi import pisitools
|
|||||||
from pisi.actionsapi import get
|
from pisi.actionsapi import get
|
||||||
|
|
||||||
def setup():
|
def setup():
|
||||||
autotools.autoreconf("-vif")
|
autotools.configure("--enable-reuseaddr --disable-static")
|
||||||
autotools.configure("--disable-static")
|
|
||||||
|
|
||||||
pisitools.dosed("libtool", " -shared ", " -Wl,-O1,--as-needed -shared ")
|
pisitools.dosed("libtool", " -shared ", " -Wl,-O1,--as-needed -shared ")
|
||||||
|
|
||||||
|
|||||||
@@ -1,65 +0,0 @@
|
|||||||
From be0a01bdb83395d9f3a5ea09c1308a4f1a972cbd Mon Sep 17 00:00:00 2001
|
|
||||||
From: Matthew Garrett <mjg59@srcf.ucam.org>
|
|
||||||
Date: Tue, 23 Feb 2016 13:53:20 -0800
|
|
||||||
Subject: [PATCH] Don't allow unhandled POSTs to write to the filesystem by
|
|
||||||
default
|
|
||||||
|
|
||||||
If there's no registered handler for a POST request, the default behaviour
|
|
||||||
is to write it to the filesystem. Several million deployed devices appear
|
|
||||||
to have this behaviour, making it possible to (at least) store arbitrary
|
|
||||||
data on them. Add a configure option that enables this behaviour, and change
|
|
||||||
the default to just drop POSTs that aren't directly handled.
|
|
||||||
---
|
|
||||||
configure.ac | 4 ++++
|
|
||||||
upnp/inc/upnpconfig.h.in | 5 +++++
|
|
||||||
upnp/src/genlib/net/http/webserver.c | 4 ++++
|
|
||||||
3 files changed, 13 insertions(+)
|
|
||||||
|
|
||||||
diff --git a/configure.ac b/configure.ac
|
|
||||||
index dd88734..ea2bc09 100644
|
|
||||||
--- a/configure.ac
|
|
||||||
+++ b/configure.ac
|
|
||||||
@@ -482,6 +482,10 @@ if test "x$enable_scriptsupport" = xyes ; then
|
|
||||||
AC_DEFINE(IXML_HAVE_SCRIPTSUPPORT, 1, [see upnpconfig.h])
|
|
||||||
fi
|
|
||||||
|
|
||||||
+RT_BOOL_ARG_ENABLE([postwrite], [no], [write to the filesystem on otherwise unhandled POST requests])
|
|
||||||
+if test "x$enable_postwrite" = xyes ; then
|
|
||||||
+ AC_DEFINE(UPNP_ENABLE_POST_WRITE, 1, [see upnpconfig.h])
|
|
||||||
+fi
|
|
||||||
|
|
||||||
RT_BOOL_ARG_ENABLE([samples], [yes], [compilation of upnp/sample/ code])
|
|
||||||
|
|
||||||
diff --git a/upnp/inc/upnpconfig.h.in b/upnp/inc/upnpconfig.h.in
|
|
||||||
index 46ddc6e..5df8c5a 100644
|
|
||||||
--- a/upnp/inc/upnpconfig.h.in
|
|
||||||
+++ b/upnp/inc/upnpconfig.h.in
|
|
||||||
@@ -135,5 +135,10 @@
|
|
||||||
* (i.e. configure --enable-open_ssl) */
|
|
||||||
#undef UPNP_ENABLE_OPEN_SSL
|
|
||||||
|
|
||||||
+/** Defined to 1 if the library has been compiled to support filesystem writes on POST
|
|
||||||
+ * (i.e. configure --enable-postwrite) */
|
|
||||||
+#undef UPNP_ENABLE_POST_WRITE
|
|
||||||
+
|
|
||||||
+
|
|
||||||
#endif /* UPNP_CONFIG_H */
|
|
||||||
|
|
||||||
diff --git a/upnp/src/genlib/net/http/webserver.c b/upnp/src/genlib/net/http/webserver.c
|
|
||||||
index 8991c16..8b2ecf2 100644
|
|
||||||
--- a/upnp/src/genlib/net/http/webserver.c
|
|
||||||
+++ b/upnp/src/genlib/net/http/webserver.c
|
|
||||||
@@ -1369,9 +1369,13 @@ static int http_RecvPostMessage(
|
|
||||||
if (Fp == NULL)
|
|
||||||
return HTTP_INTERNAL_SERVER_ERROR;
|
|
||||||
} else {
|
|
||||||
+#ifdef UPNP_ENABLE_POST_WRITE
|
|
||||||
Fp = fopen(filename, "wb");
|
|
||||||
if (Fp == NULL)
|
|
||||||
return HTTP_UNAUTHORIZED;
|
|
||||||
+#else
|
|
||||||
+ return HTTP_NOT_FOUND;
|
|
||||||
+#endif
|
|
||||||
}
|
|
||||||
parser->position = POS_ENTITY;
|
|
||||||
do {
|
|
||||||
@@ -1,13 +0,0 @@
|
|||||||
Index: libupnp-1.6.6/m4/acx_pthread.m4
|
|
||||||
===================================================================
|
|
||||||
--- libupnp-1.6.6.orig/m4/acx_pthread.m4
|
|
||||||
+++ libupnp-1.6.6/m4/acx_pthread.m4
|
|
||||||
@@ -146,7 +146,7 @@ acx_pthread_flags="pthreads none -Kthrea
|
|
||||||
# pthread-config: use pthread-config program (for GNU Pth library)
|
|
||||||
|
|
||||||
case "${host_cpu}-${host_os}" in
|
|
||||||
- *solaris*)
|
|
||||||
+ *solaris*|*linux*)
|
|
||||||
|
|
||||||
# On Solaris (at least, for some versions), libc contains stubbed
|
|
||||||
# (non-functional) versions of the pthreads routines, so link-based
|
|
||||||
@@ -5,19 +5,19 @@
|
|||||||
<Name>libupnp</Name>
|
<Name>libupnp</Name>
|
||||||
<Homepage>https://github.com/pupnp/pupnp</Homepage>
|
<Homepage>https://github.com/pupnp/pupnp</Homepage>
|
||||||
<Packager>
|
<Packager>
|
||||||
<Name>PisiLinux Community</Name>
|
<Name>Pisilinux Community</Name>
|
||||||
<Email>admins@pisilinux.org</Email>
|
<Email>admins@pisilinux.org</Email>
|
||||||
</Packager>
|
</Packager>
|
||||||
<License>BSD</License>
|
<License>BSD</License>
|
||||||
<IsA>library</IsA>
|
<IsA>library</IsA>
|
||||||
<Summary>Portable UPnP library.</Summary>
|
<Summary>Portable UPnP library.</Summary>
|
||||||
<Description>The Universal Plug and Play (UPnP) SDK for Linux provides support for building UPnP-compliant control points, devices, and bridges on Linux.</Description>
|
<Description>The Universal Plug and Play (UPnP) SDK for Linux provides support for building UPnP-compliant control points, devices, and bridges on Linux.</Description>
|
||||||
<Archive sha1sum="33e2eec13112860c9da8406ae6f60a920a7205cf" type="tarbz2">mirrors://sourceforge/pupnp/libupnp-1.14.7.tar.bz2</Archive>
|
<Archive sha1sum="0c51aad290506989335b619ea3181c7ccf146fe9" type="tarbz2">mirrors://sourceforge/pupnp/libupnp-1.14.12.tar.bz2</Archive>
|
||||||
<BuildDependencies>
|
<BuildDependencies>
|
||||||
<Dependency>kernel-headers</Dependency>
|
<Dependency>kernel-headers</Dependency>
|
||||||
</BuildDependencies>
|
</BuildDependencies>
|
||||||
<Patches>
|
<Patches>
|
||||||
<!-- <Patch level="1">CVE-2020-13848.patch</Patch> -->
|
<!-- <Patch level="1">missing.patch</Patch> -->
|
||||||
</Patches>
|
</Patches>
|
||||||
</Source>
|
</Source>
|
||||||
|
|
||||||
@@ -42,6 +42,13 @@
|
|||||||
</Package>
|
</Package>
|
||||||
|
|
||||||
<History>
|
<History>
|
||||||
|
<Update release="7">
|
||||||
|
<Date>2022-04-16</Date>
|
||||||
|
<Version>1.14.12</Version>
|
||||||
|
<Comment>Version bump.</Comment>
|
||||||
|
<Name>fury</Name>
|
||||||
|
<Email>uglyside@yandex.ru</Email>
|
||||||
|
</Update>
|
||||||
<Update release="6">
|
<Update release="6">
|
||||||
<Date>2021-07-02</Date>
|
<Date>2021-07-02</Date>
|
||||||
<Version>1.14.7</Version>
|
<Version>1.14.7</Version>
|
||||||
|
|||||||
Reference in New Issue
Block a user