package/proftpd: add patch for CVE-2026-44331

(alternative to commit 3577d1442e)
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
Signed-off-by: Raphaël Mélotte <raphael.melotte@mind.be>
This commit is contained in:
Titouan Christophe
2026-09-07 12:18:07 +02:00
committed by Raphaël Mélotte
parent 63b29824e5
commit 439c25237a
2 changed files with 109 additions and 0 deletions

View File

@@ -0,0 +1,106 @@
From 07797aba88dca902da7eaf1dfe262c8896943de7 Mon Sep 17 00:00:00 2001
From: TJ Saunders <tj@castaglia.org>
Date: Tue, 5 May 2026 09:56:33 -0700
Subject: [PATCH] Issue #2057: Properly escape the "name" provided when doing
SQL lookups for allowed/denied client IP addresses or DNS names.
CVE: CVE-2026-44331
Upstream: https://github.com/proftpd/proftpd/commit/07797aba88dca902da7eaf1dfe262c8896943de7
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
---
contrib/mod_wrap2_sql.c | 49 +++++++++++++++++++++++++++++++++++++----
1 file changed, 45 insertions(+), 4 deletions(-)
diff --git a/contrib/mod_wrap2_sql.c b/contrib/mod_wrap2_sql.c
index eaf6ea7dc..d4fd56e69 100644
--- a/contrib/mod_wrap2_sql.c
+++ b/contrib/mod_wrap2_sql.c
@@ -1,7 +1,7 @@
/*
* ProFTPD: mod_wrap2_sql -- a mod_wrap2 sub-module for supplying IP-based
* access control data via SQL tables
- * Copyright (c) 2002-2016 TJ Saunders
+ * Copyright (c) 2002-2026 TJ Saunders
*
* This program is free software; you can redistribute it and/or modify
* it under the terms of the GNU General Public License as published by
@@ -25,7 +25,7 @@
#include "mod_wrap2.h"
#include "mod_sql.h"
-#define MOD_WRAP2_SQL_VERSION "mod_wrap2_sql/1.0"
+#define MOD_WRAP2_SQL_VERSION "mod_wrap2_sql/1.1"
#define WRAP2_SQL_NSLOTS 2
#define WRAP2_SQL_CLIENT_QUERY_IDX 0
@@ -62,6 +62,41 @@ static int sqltab_close_cb(wrap2_table_t *sqltab) {
return 0;
}
+static char *sqltab_get_escaped_text(pool *p, wrap2_table_t *sqltab,
+ const char *text) {
+ pool *tmp_pool = NULL;
+ cmdtable *sql_cmdtab = NULL;
+ cmd_rec *sql_cmd = NULL;
+ modret_t *sql_res = NULL;
+
+ /* Find the cmdtable for the sql_escapestr command, as the provided
+ * name needs to be properly escaped for SQL syntax; see Issue #2057.
+ */
+ sql_cmdtab = pr_stash_get_symbol2(PR_SYM_HOOK, "sql_escapestr", NULL, NULL,
+ NULL);
+ if (sql_cmdtab == NULL) {
+ wrap2_log("error: unable to find SQL hook symbol 'sql_escapestr': "
+ "perhaps your proftpd.conf needs 'LoadModule mod_sql.c'?");
+ return NULL;
+ }
+
+ sql_cmd = sql_cmd_create(tmp_pool, 1, text);
+ sql_res = pr_module_call(sql_cmdtab->m, sql_cmdtab->handler, sql_cmd);
+ if (sql_res == NULL) {
+ wrap2_log("sql_escapestr '%s' returned no data; "
+ "see the mod_sql.c SQLLogFile for more details", text);
+ return NULL;
+ }
+
+ if (MODRET_ISERROR(sql_res)) {
+ wrap2_log("error processing sql_escapestr '%s': "
+ "check the mod_sql.c SQLLogFile for more details", text);
+ return NULL;
+ }
+
+ return sql_res->data;
+}
+
static array_header *sqltab_fetch_clients_cb(wrap2_table_t *sqltab,
const char *name) {
register unsigned int i;
@@ -70,12 +105,18 @@ static array_header *sqltab_fetch_clients_cb(wrap2_table_t *sqltab,
cmd_rec *sql_cmd = NULL;
modret_t *sql_res = NULL;
array_header *sql_data = NULL;
- char *query = NULL, **vals = NULL;
+ char *escaped_name = NULL, *query = NULL, **vals = NULL;
array_header *clients_list = NULL;
/* Allocate a temporary pool for the duration of this read. */
tmp_pool = make_sub_pool(sqltab->tab_pool);
+ escaped_name = sqltab_get_escaped_text(tmp_pool, sqltab, name);
+ if (escaped_name == NULL) {
+ destroy_pool(tmp_pool);
+ return NULL;
+ }
+
query = ((char **) sqltab->tab_data)[WRAP2_SQL_CLIENT_QUERY_IDX];
/* Find the cmdtable for the sql_lookup command. */
@@ -89,7 +130,7 @@ static array_header *sqltab_fetch_clients_cb(wrap2_table_t *sqltab,
}
/* Prepare the SELECT query. */
- sql_cmd = sql_cmd_create(tmp_pool, 3, "sql_lookup", query, name);
+ sql_cmd = sql_cmd_create(tmp_pool, 3, "sql_lookup", query, escaped_name);
/* Call the handler. */
sql_res = pr_module_call(sql_cmdtab->m, sql_cmdtab->handler, sql_cmd);

View File

@@ -14,6 +14,9 @@ PROFTPD_SELINUX_MODULES = ftp
# 0001-CVE-2026-42167.patch
PROFTPD_IGNORE_CVES += CVE-2026-42167
# 0001-CVE-2026-44331.patch
PROFTPD_IGNORE_CVES += CVE-2026-44331
PROFTPD_CONF_ENV = \
ac_cv_func_setpgrp_void=yes \
ac_cv_func_setgrent_void=yes