From 21fcfa3348213aa87f0e3aef62ca4720c6d31cb7 Mon Sep 17 00:00:00 2001 From: Robert Xu Date: Thu, 10 Nov 2011 18:04:39 -0500 Subject: initial commit to suse branch: eclipse integration --- ...delibs-3.5.10-cve-2009-2537-select-length.patch | 30 ---------------------- 1 file changed, 30 deletions(-) delete mode 100644 opensuse/tdelibs/kdelibs-3.5.10-cve-2009-2537-select-length.patch (limited to 'opensuse/tdelibs/kdelibs-3.5.10-cve-2009-2537-select-length.patch') diff --git a/opensuse/tdelibs/kdelibs-3.5.10-cve-2009-2537-select-length.patch b/opensuse/tdelibs/kdelibs-3.5.10-cve-2009-2537-select-length.patch deleted file mode 100644 index 5972b0a38..000000000 --- a/opensuse/tdelibs/kdelibs-3.5.10-cve-2009-2537-select-length.patch +++ /dev/null @@ -1,30 +0,0 @@ -diff -ur kdelibs-3.5.10/khtml/ecma/kjs_html.cpp kdelibs-3.5.10-cve-2009-2537-select-length/khtml/ecma/kjs_html.cpp ---- kdelibs-3.5.10/khtml/ecma/kjs_html.cpp 2008-02-13 10:41:09.000000000 +0100 -+++ kdelibs-3.5.10-cve-2009-2537-select-length/khtml/ecma/kjs_html.cpp 2009-07-26 04:54:52.000000000 +0200 -@@ -62,6 +62,9 @@ - - #include - -+// CVE-2009-2537 (vendors agreed on max 10000 elements) -+#define MAX_SELECT_LENGTH 10000 -+ - namespace KJS { - - KJS_DEFINE_PROTOTYPE_WITH_PROTOTYPE(HTMLDocumentProto, DOMDocumentProto) -@@ -2550,8 +2553,14 @@ - case SelectValue: { select.setValue(str); return; } - case SelectLength: { // read-only according to the NS spec, but webpages need it writeable - Object coll = Object::dynamicCast( getSelectHTMLCollection(exec, select.options(), select) ); -- if ( coll.isValid() ) -- coll.put(exec,"length",value); -+ -+ if ( coll.isValid() ) { -+ if (value.toInteger(exec) >= MAX_SELECT_LENGTH) { -+ Object err = Error::create(exec, RangeError); -+ exec->setException(err); -+ } else -+ coll.put(exec, "length", value); -+ } - return; - } - // read-only: form -- cgit v1.2.1