From 7e6201fc0304bc1122bdef5884b741c42d097998 Mon Sep 17 00:00:00 2001 From: Michael Vogt Date: Tue, 27 Sep 2011 09:41:18 +0200 Subject: [PATCH] fix apt-key net-update by erroring out if there are any duplicated keys in master-keyring and add-keyring (see lp #857472) and add regression test --- cmdline/apt-key | 11 ++++ .../exploid-keyring-with-dupe-keys.pub | Bin 0 -> 3986 bytes test/integration/test-apt-key-net-update | 47 ++++++++++++++++++ 3 files changed, 58 insertions(+) create mode 100644 test/integration/exploid-keyring-with-dupe-keys.pub create mode 100755 test/integration/test-apt-key-net-update diff --git a/cmdline/apt-key b/cmdline/apt-key index 4d2b7c49f..8a3f5ba54 100755 --- a/cmdline/apt-key +++ b/cmdline/apt-key @@ -50,6 +50,17 @@ add_keys_with_verify_against_master_keyring() { # from a key in the $distro-master-keyring add_keys=`$GPG_CMD --keyring $ADD_KEYRING --with-colons --list-keys | grep ^pub | cut -d: -f5` master_keys=`$GPG_CMD --keyring $MASTER --with-colons --list-keys | grep ^pub | cut -d: -f5` + # verify to ensure that there are no key id duplications that may be + # used to attack the system, see LP: #857472 + for add_key in $add_keys; do + for master_key in $master_keys; do + if [ "$add_key" = "$master_key" ]; then + echo >&2 "Keyid collision for '$add_key' detected, operation aborted" + return 1 + fi + done + done + # add all keys signed with any of the master key(s) for add_key in $add_keys; do ADDED=0 for master_key in $master_keys; do diff --git a/test/integration/exploid-keyring-with-dupe-keys.pub b/test/integration/exploid-keyring-with-dupe-keys.pub new file mode 100644 index 0000000000000000000000000000000000000000..642952a403cb33ab2e1a07aa7e98dd1c944f5927 GIT binary patch literal 3986 zcmai$WmHt{7J#Q{hK>OQgdqeGr9rwo1O!2l7#gIzrAq~bAtZ(oP-&!*k`x3<>6A_> z38@Qsy`SH&d;Yv@owe6__j>lT&)z9OG(^p-2Sp44pakg1CpP@gqJCM9rl5$+CJDat z@Q6;fJ&y6UsOnI8WXGl33k~&=3lvHOaBX1$8ZtVn{34G(^hPG8p>|TT$|-nJ7T&EX zaF!u>pvqvfV>XYHx^BVV3Hu0I<~;W3k^Z;*Bij|W+0k*sHSRkrC~J0eKUJ4ey>ar; zn+C?D0Ms0uklKZ@pnS;fwXDoJ3MTq#*bM?mc}RPBVzh%zyJ}d_o0coWmXyTBl*I(Cx#+yJa#%gMf3NFneFlYh267{a`XYIB7&f27tM!4V+#*F*E{t3H+}uRqsm4k2g}RJ-Avu=xo(PF9}*_NAF&8i2q`fLz=#35 zsvw94jERSXjRgi_l4FB#aPc4%ATSU_2Lw?D0&sDNqIEWtCm=S1+mirPjiDK_UFWM0 zb}0V|@l>>HN#fz<+vo!6Po5SU3G8vzc}CD$(Gujl%n}d)Tmyt&J3<5jEOf;*bSDhO z(u_@#cQ%ccLy2ZqdX&YpcNoh_kU!YCofYCdir^Ib%DHDr*703oOl@_JwN-)MunW>HUQ_7Vp{~}EiASpDKiw7Nil8_ElDYaCc zu1IM-WINHGufb8ajn-EOfHArwFi@LJ#Ft5C6x;TDF?!rV5W6%Yowxgq9H^^zDI7{!x zMw?oFu}I>x;Vb~RPNB1hB2^o%nQ3n`hc4iTU2JMe&DnSE2t^3&k~_{H z?)ZP>#Rma0jo6bxu(x!{QhmC+zm(E8+G?y^0BLye$HEkyN@S4moP5>n!R{{llgcZ+ z$WE?PC(fzf+8dfh=3%i5ImD;y z>pEKgtdYIiKdPO|?)UD^Znh-)M-%GQQ&FmVTglyv266$2fdF7R#g%2;zh&e8Bb$j> zL^XsI_}jM2Z2zBa2rV6_x{B97;C2u|V6%O{JK={P!TNAl1>^^5pK&55GUxi+KB*e1 z`O07PXMXL|aW7Aoqb88ziz&ad&f6x9zvhuY;qZoMEFiQJ?8BFoO1z`fpVw5rv@*`8 zWq7>MsbWB8hQH>mx8oFEknW+AW?nI+F<`v}X z|3Myj&Kc?$KxZM)NrERWOtKDZ4V$xI(7D!65t^azrKsb_w%Jp=+4e3jJX=;{!g$A8~=7 z0HFPR?7>wJ%kv59$u_0w10buwUX9SOi{g{puy!)~ipg+UU;H3K)o=pjs&Ml9by{B7srv2W}TBFuIVY`JhoMQ;o3%0#W zpNLE{F_MpU$q%WBOzbK?jsebJi}@0)=G}b@0Ju~$4a9`px#K=xWq$E-t*~MH0YfY& z(HlH6PZPmI1~#qcS?&yAFAp63Vys$4=nPvXRuENs{7x{stYM??KB* zKy4yFT^sioy*gB>ZQ(g9O$-H(&;EB>4zcEZjb8Ah(82+S(^1(Fy?0BNbYHEh9@K>< zd%*2Oz??%GP7BXS?L}i0`^MMP-SCEZ{Ip9=FN{*TCqyGD1fr(b@RY&z^IZ)RX2__{ z!?9RQO?%A^-O`vvrOl%!Cd99{b{{iD;p-|I>{wG!cwN)Gh6VdKtVkX38FBl336@^5 z%BWzZL-Y*~&wSF6vOW1#*Kcf$Kl|^yRjpVZrVSXpRxTZ46^x9J+KY<{mDi$bH=HQo z@DtWX(>0YkuDwVR*5-YW#dVz3f36hl5n6Me5Ik*B^o9qu5C8|zJ6Rre3j}>9Jpw;? zzvrRMxh7lXw{fA^&1r#HHMv$z;8L}5l}put5*dKvRO23}f+O9}6A~Ux4H2k{2J;r^ zXaB&#Tmm|+qkvo%7V|)CpTCq4`mKb}wGyJ&N{p-gi30**5+Q04W)+v*rLkdgnPScP1ps0wjyDnEGZbhCOygv3)}cA#zcX*Xo| z_?GJdNwri3Gu}x^fH>>j$G=hFTeu-?xi0_Q7JqSAh5QKu0`b2B#a(ip7c)QSstt4O zop_M%D{e5nP>G_W6g^y8*Eh_{VpN^RlaCmm^SkDtep!|4R6u}MSbC}|LXXB1rD=br zD81Vj)*fmsDLIRZvRpt)?pJTS0-3QY(Y&E&e*E7l{b;dE{D`myKNOqiR2g}fo7Vq} z&)-QYoB+i*)AwS%Qf}5eI3UIB-Q`-hNr*!z)M5)e(<25p51$?wYi43)o>G!tC6#iu zjd-sS0=7(7LErRF@9EflAs8$KDGUO&T)quVR8>TLARSb}H$n z&7T53bUgL#>o}<|us@Kn7RLk9EN&c2GpP8I_)-;)Ga@6GHcroFaJ>-ga0w>c$PJ zHozy$o;q!pkF9P-@>|xm78Vn_xbxF*;Ia(JO5sUHPcAAo*0Ad??HxZlwEw!43`a)Q zt#G{jZwHv#nOI#ehu6nd<$;3#OzJhl|2L^0R*Xz$-rqEhB*X?}0p2(^C{%$E?<*g& zr|$Qa2gkEd=r{-2V(0R2SB;f=BFx|MnVEMEV$vf)Q;Ewn3# zXiwS+aA;k=t8dimG}cdyDYukHoQuT4dCr|ktN%{YR#teF5%LM1PS~(m+V}uvJN0Ry zNbS!op@_YU%%7i%!4$6Pr2S{ql@J5`q}gU}>bny?aJfE(4GK$Xkt$L79%EQ?SdN<5 zHpuZ_r^fEHvX3?^xX>j1gU{cm){~;-O>K|Tu^suIlG5%6yBfSxBHu74tnOi*Gk2~{6}~!3F~eA_x%$%e z-u&Ctwn!@k#_=`VJ^e3xihMekF-QcwwcK{^L7+*O1qsNRhV zX_8JW^uc`F$QDxvs|GBvhK~vfKg{kviV%BUPEUsxix%fiiWBB!D>W7>6wOjJ2==(; zpVzIMbB9EqK1XQCHo6hPV)`wmL$Xn-?`4SM)YjXSeKIqON5|X