Files
main/network/download/wget/files/wget-1.12-CVE-2010-2252.diff
2016-03-25 17:44:44 +02:00

156 lines
6.9 KiB
Diff

diff -Naurp wget-1.12/doc/wget.texi wget-1.12.oden/doc/wget.texi
--- wget-1.12/doc/wget.texi 2010-09-02 12:21:40.000000000 -0400
+++ wget-1.12.oden/doc/wget.texi 2010-09-02 12:22:13.000000000 -0400
@@ -1487,6 +1487,13 @@ This option is useful for some file-down
@code{Content-Disposition} headers to describe what the name of a
downloaded file should be.
+@cindex Trust server names
+@item --trust-server-names
+
+If this is set to on, on a redirect the last component of the
+redirection URL will be used as the local file name. By default it is
+used the last component in the original URL.
+
@cindex authentication
@item --auth-no-challenge
@@ -2799,6 +2806,10 @@ Set the connect timeout---the same as @s
Turn on recognition of the (non-standard) @samp{Content-Disposition}
HTTP header---if set to @samp{on}, the same as @samp{--content-disposition}.
+@item trust_server_names = on/off
+If set to on, use the last component of a redirection URL for the local
+file name.
+
@item continue = on/off
If set to on, force continuation of preexistent partially retrieved
files. See @samp{-c} before setting it.
diff -Naurp wget-1.12/src/http.c wget-1.12.oden/src/http.c
--- wget-1.12/src/http.c 2010-09-02 12:21:40.000000000 -0400
+++ wget-1.12.oden/src/http.c 2010-09-02 12:22:13.000000000 -0400
@@ -2410,8 +2410,9 @@ File %s already there; not retrieving.\n
/* The genuine HTTP loop! This is the part where the retrieval is
retried, and retried, and retried, and... */
uerr_t
-http_loop (struct url *u, char **newloc, char **local_file, const char *referer,
- int *dt, struct url *proxy, struct iri *iri)
+http_loop (struct url *u, struct url *original_url, char **newloc,
+ char **local_file, const char *referer, int *dt, struct url *proxy,
+ struct iri *iri)
{
int count;
bool got_head = false; /* used for time-stamping and filename detection */
@@ -2457,7 +2458,8 @@ http_loop (struct url *u, char **newloc,
}
else if (!opt.content_disposition)
{
- hstat.local_file = url_file_name (u);
+ hstat.local_file =
+ url_file_name (opt.trustservernames ? u : original_url);
got_name = true;
}
@@ -2497,7 +2499,7 @@ File %s already there; not retrieving.\n
/* Send preliminary HEAD request if -N is given and we have an existing
* destination file. */
- file_name = url_file_name (u);
+ file_name = url_file_name (opt.trustservernames ? u : original_url);
if (opt.timestamping
&& !opt.content_disposition
&& file_exists_p (file_name))
@@ -2852,9 +2854,9 @@ Remote file exists.\n\n"));
/* Remember that we downloaded the file for later ".orig" code. */
if (*dt & ADDED_HTML_EXTENSION)
- downloaded_file(FILE_DOWNLOADED_AND_HTML_EXTENSION_ADDED, hstat.local_file);
+ downloaded_file (FILE_DOWNLOADED_AND_HTML_EXTENSION_ADDED, hstat.local_file);
else
- downloaded_file(FILE_DOWNLOADED_NORMALLY, hstat.local_file);
+ downloaded_file (FILE_DOWNLOADED_NORMALLY, hstat.local_file);
ret = RETROK;
goto exit;
@@ -2885,9 +2887,9 @@ Remote file exists.\n\n"));
/* Remember that we downloaded the file for later ".orig" code. */
if (*dt & ADDED_HTML_EXTENSION)
- downloaded_file(FILE_DOWNLOADED_AND_HTML_EXTENSION_ADDED, hstat.local_file);
+ downloaded_file (FILE_DOWNLOADED_AND_HTML_EXTENSION_ADDED, hstat.local_file);
else
- downloaded_file(FILE_DOWNLOADED_NORMALLY, hstat.local_file);
+ downloaded_file (FILE_DOWNLOADED_NORMALLY, hstat.local_file);
ret = RETROK;
goto exit;
diff -Naurp wget-1.12/src/http.h wget-1.12.oden/src/http.h
--- wget-1.12/src/http.h 2009-09-04 12:31:54.000000000 -0400
+++ wget-1.12.oden/src/http.h 2010-09-02 12:22:13.000000000 -0400
@@ -33,8 +33,8 @@ as that of the covered work. */
struct url;
-uerr_t http_loop (struct url *, char **, char **, const char *, int *,
- struct url *, struct iri *);
+uerr_t http_loop (struct url *, struct url *, char **, char **, const char *,
+ int *, struct url *, struct iri *);
void save_cookies (void);
void http_cleanup (void);
time_t http_atotm (const char *);
diff -Naurp wget-1.12/src/init.c wget-1.12.oden/src/init.c
--- wget-1.12/src/init.c 2010-09-02 12:21:40.000000000 -0400
+++ wget-1.12.oden/src/init.c 2010-09-02 12:22:13.000000000 -0400
@@ -244,6 +244,7 @@ static const struct {
{ "timeout", NULL, cmd_spec_timeout },
{ "timestamping", &opt.timestamping, cmd_boolean },
{ "tries", &opt.ntry, cmd_number_inf },
+ { "trustservernames", &opt.trustservernames, cmd_boolean },
{ "useproxy", &opt.use_proxy, cmd_boolean },
{ "user", &opt.user, cmd_string },
{ "useragent", NULL, cmd_spec_useragent },
diff -Naurp wget-1.12/src/main.c wget-1.12.oden/src/main.c
--- wget-1.12/src/main.c 2010-09-02 12:21:40.000000000 -0400
+++ wget-1.12.oden/src/main.c 2010-09-02 12:22:13.000000000 -0400
@@ -268,6 +268,7 @@ static struct cmdline_option option_data
{ "timeout", 'T', OPT_VALUE, "timeout", -1 },
{ "timestamping", 'N', OPT_BOOLEAN, "timestamping", -1 },
{ "tries", 't', OPT_VALUE, "tries", -1 },
+ { "trust-server-names", 0, OPT_BOOLEAN, "trustservernames", -1 },
{ "user", 0, OPT_VALUE, "user", -1 },
{ "user-agent", 'U', OPT_VALUE, "useragent", -1 },
{ "verbose", 'v', OPT_BOOLEAN, "verbose", -1 },
@@ -679,6 +680,8 @@ Recursive accept/reject:\n"),
N_("\
-I, --include-directories=LIST list of allowed directories.\n"),
N_("\
+ --trust-server-names use the name specified by the redirection url last component.\n"),
+ N_("\
-X, --exclude-directories=LIST list of excluded directories.\n"),
N_("\
-np, --no-parent don't ascend to the parent directory.\n"),
diff -Naurp wget-1.12/src/options.h wget-1.12.oden/src/options.h
--- wget-1.12/src/options.h 2010-09-02 12:21:40.000000000 -0400
+++ wget-1.12.oden/src/options.h 2010-09-02 12:22:13.000000000 -0400
@@ -243,6 +243,7 @@ struct options
char *encoding_remote;
char *locale;
+ bool trustservernames;
#ifdef __VMS
int ftp_stmlf; /* Force Stream_LF format for binary FTP. */
#endif /* def __VMS */
diff -Naurp wget-1.12/src/retr.c wget-1.12.oden/src/retr.c
--- wget-1.12/src/retr.c 2009-09-04 12:31:54.000000000 -0400
+++ wget-1.12.oden/src/retr.c 2010-09-02 12:22:13.000000000 -0400
@@ -689,7 +689,8 @@ retrieve_url (struct url * orig_parsed,
#endif
|| (proxy_url && proxy_url->scheme == SCHEME_HTTP))
{
- result = http_loop (u, &mynewloc, &local_file, refurl, dt, proxy_url, iri);
+ result = http_loop (u, orig_parsed, &mynewloc, &local_file, refurl, dt,
+ proxy_url, iri);
}
else if (u->scheme == SCHEME_FTP)
{