From ffdc459cc145ad9a280219a84b4b49a8f3ac7d99 Mon Sep 17 00:00:00 2001 From: Florian Smeets Date: Sat, 21 Mar 2015 19:41:29 +0000 Subject: Add patches for the following CVEs CVE-2015-2301 CVE-2014-9705 CVE-2015-0273 MFH: 2015Q1 --- archivers/php53-phar/files/patch-CVE-2015-2301 | 12 ++++++++++++ 1 file changed, 12 insertions(+) create mode 100644 archivers/php53-phar/files/patch-CVE-2015-2301 (limited to 'archivers/php53-phar/files/patch-CVE-2015-2301') diff --git a/archivers/php53-phar/files/patch-CVE-2015-2301 b/archivers/php53-phar/files/patch-CVE-2015-2301 new file mode 100644 index 000000000000..896408a16ffc --- /dev/null +++ b/archivers/php53-phar/files/patch-CVE-2015-2301 @@ -0,0 +1,12 @@ +--- phar_object.c 2015-03-16 13:56:47.878348393 -0400 ++++ phar_object.c 2015-03-16 13:56:47.826347993 -0400 +@@ -2320,8 +2320,8 @@ + } + its_ok: + if (SUCCESS == php_stream_stat_path(newpath, &ssb)) { +- efree(oldpath); + zend_throw_exception_ex(spl_ce_BadMethodCallException, 0 TSRMLS_CC, "phar \"%s\" exists and must be unlinked prior to conversion", newpath); ++ efree(oldpath); + return NULL; + } + if (!phar->is_data) { -- cgit v1.2.3