From f68011c51b935a5313a8280800fe0028199da8cc Mon Sep 17 00:00:00 2001 From: wk333 <13474090681@163.com> Date: Tue, 16 Jan 2024 09:28:47 +0800 Subject: [PATCH] Fix CVE-2023-0437 --- CVE-2023-0437.patch | 27 +++++++++++++++++++++++++++ mongo-c-driver.spec | 6 +++++- 2 files changed, 32 insertions(+), 1 deletion(-) create mode 100644 CVE-2023-0437.patch diff --git a/CVE-2023-0437.patch b/CVE-2023-0437.patch new file mode 100644 index 0000000..a980dcc --- /dev/null +++ b/CVE-2023-0437.patch @@ -0,0 +1,27 @@ +From be865dd759a28aa268232766f304d1bc11f1e8f7 Mon Sep 17 00:00:00 2001 +From: Kevin Albertson +Date: Mon, 30 Oct 2023 18:01:30 +0000 +Subject: [PATCH] CDRIVER-4747 use `size_t` consistently in + `bson_utf8_validate` (#1458) + +Origin: https://github.com/mongodb/mongo-c-driver/commit/be865dd759a28aa268232766f304d1bc11f1e8f7 + +--- + src/libbson/src/bson/bson-utf8.c | 4 ++-- + 1 file changed, 2 insertions(+), 2 deletions(-) + +diff --git a/src/libbson/src/bson/bson-utf8.c b/src/libbson/src/bson/bson-utf8.c +index e122ac31f7..1cebd27069 100644 +--- a/src/libbson/src/bson/bson-utf8.c ++++ b/src/libbson/src/bson/bson-utf8.c +@@ -118,8 +118,8 @@ bson_utf8_validate (const char *utf8, /* IN */ + bson_unichar_t c; + uint8_t first_mask; + uint8_t seq_length; +- unsigned i; +- unsigned j; ++ size_t i; ++ size_t j; + + BSON_ASSERT (utf8); + diff --git a/mongo-c-driver.spec b/mongo-c-driver.spec index c19757a..a9a02a5 100644 --- a/mongo-c-driver.spec +++ b/mongo-c-driver.spec @@ -2,10 +2,11 @@ Name: mongo-c-driver Summary: Client library written in C for MongoDB Version: 1.13.1 -Release: 6 +Release: 7 License: ASL 2.0 and ISC and MIT and zlib URL: https://github.com/mongodb/mongo-c-driver Source0: https://github.com/mongodb/mongo-c-driver/releases/download/1.13.1/mongo-c-driver-1.13.1.tar.gz +Patch0: CVE-2023-0437.patch BuildRequires: cmake >= 3.1 openssl-devel pkgconfig(libsasl2) pkgconfig(zlib) gcc BuildRequires: pkgconfig(snappy) pkgconfig(icu-uc) perl-interpreter python3 python3-sphinx BuildRequires: chrpath @@ -121,6 +122,9 @@ exit $ret %doc NEWS %changelog +* Tue Jan 16 2024 wangkai <13474090681@163.com> - 1.13.1-7 +- Fix CVE-2023-0437 + * Thu Aug 25 2022 wangkai - 1.13.1-6 - Remove rpath -- Gitee