From 5268c6cc51fbda1202369ceee1e35ef0c103a116 Mon Sep 17 00:00:00 2001 From: wk333 <13474090681@163.com> Date: Tue, 16 Jan 2024 09:37:51 +0800 Subject: [PATCH] Fix CVE-2023-0437 --- CVE-2023-0437.patch | 27 +++++++++++++++++++++++++++ mongo-c-driver.spec | 6 +++++- 2 files changed, 32 insertions(+), 1 deletion(-) create mode 100644 CVE-2023-0437.patch diff --git a/CVE-2023-0437.patch b/CVE-2023-0437.patch new file mode 100644 index 0000000..a980dcc --- /dev/null +++ b/CVE-2023-0437.patch @@ -0,0 +1,27 @@ +From be865dd759a28aa268232766f304d1bc11f1e8f7 Mon Sep 17 00:00:00 2001 +From: Kevin Albertson +Date: Mon, 30 Oct 2023 18:01:30 +0000 +Subject: [PATCH] CDRIVER-4747 use `size_t` consistently in + `bson_utf8_validate` (#1458) + +Origin: https://github.com/mongodb/mongo-c-driver/commit/be865dd759a28aa268232766f304d1bc11f1e8f7 + +--- + src/libbson/src/bson/bson-utf8.c | 4 ++-- + 1 file changed, 2 insertions(+), 2 deletions(-) + +diff --git a/src/libbson/src/bson/bson-utf8.c b/src/libbson/src/bson/bson-utf8.c +index e122ac31f7..1cebd27069 100644 +--- a/src/libbson/src/bson/bson-utf8.c ++++ b/src/libbson/src/bson/bson-utf8.c +@@ -118,8 +118,8 @@ bson_utf8_validate (const char *utf8, /* IN */ + bson_unichar_t c; + uint8_t first_mask; + uint8_t seq_length; +- unsigned i; +- unsigned j; ++ size_t i; ++ size_t j; + + BSON_ASSERT (utf8); + diff --git a/mongo-c-driver.spec b/mongo-c-driver.spec index 8427fe2..e6edd4b 100644 --- a/mongo-c-driver.spec +++ b/mongo-c-driver.spec @@ -2,10 +2,11 @@ Name: mongo-c-driver Summary: Client library written in C for MongoDB Version: 1.13.1 -Release: 3 +Release: 4 License: ASL 2.0 and ISC and MIT and zlib URL: https://github.com/mongodb/mongo-c-driver Source0: https://github.com/mongodb/mongo-c-driver/releases/download/1.13.1/mongo-c-driver-1.13.1.tar.gz +Patch0: CVE-2023-0437.patch BuildRequires: cmake >= 3.1 openssl-devel pkgconfig(libsasl2) pkgconfig(zlib) BuildRequires: pkgconfig(snappy) pkgconfig(icu-uc) perl-interpreter python python3-sphinx %if %{with_tests} @@ -109,6 +110,9 @@ exit $ret %doc NEWS %changelog +* Tue Jan 16 2024 wangkai <13474090681@163.com> - 1.13.1-4 +- Fix CVE-2023-0437 + * Fri Feb 21 2020 gulining - 1.13.1-3 - fix build error -- Gitee