From b4d51391c5635ddc10a7b29abb9d694bc6889940 Mon Sep 17 00:00:00 2001 From: Joas Schilling Date: Wed, 15 May 2024 10:28:18 +0200 Subject: [PATCH] fix: Correctly check result of function Signed-off-by: Joas Schilling --- index.php | 4 ++-- lib/Updater.php | 4 ++-- updater.phar | Bin 757576 -> 757570 bytes 3 files changed, 4 insertions(+), 4 deletions(-) diff --git a/index.php b/index.php index 31142c90..24aad88c 100644 --- a/index.php +++ b/index.php @@ -688,12 +688,12 @@ public function verifyIntegrity() { -----END CERTIFICATE----- EOF; - $validSignature = (bool)openssl_verify( + $validSignature = openssl_verify( file_get_contents($this->getDownloadedFilePath()), base64_decode($response['signature']), $certificate, OPENSSL_ALGO_SHA512 - ); + ) === 1; if ($validSignature === false) { throw new \Exception('Signature of update is not valid'); diff --git a/lib/Updater.php b/lib/Updater.php index 8e5825a8..06f65e8b 100644 --- a/lib/Updater.php +++ b/lib/Updater.php @@ -652,12 +652,12 @@ public function verifyIntegrity() { -----END CERTIFICATE----- EOF; - $validSignature = (bool)openssl_verify( + $validSignature = openssl_verify( file_get_contents($this->getDownloadedFilePath()), base64_decode($response['signature']), $certificate, OPENSSL_ALGO_SHA512 - ); + ) === 1; if ($validSignature === false) { throw new \Exception('Signature of update is not valid'); diff --git a/updater.phar b/updater.phar index 8ba2ade488dff61f240064a4481e8b31517b6f5a..23fc40ed507cd8d4d300d7fcf4046ae393b5dc7f 100755 GIT binary patch delta 5403 zcmZ`+dwfjS_CGV{%$##(CNn29iAgd^OeAEIkcU?u@{%Y~B=HCpB%xlZB8qsER>h+& zVYfDoMEq_qiZ;1T+1?4R5>%s9iy+)q6(#k&Mcv=p`%K*S_xb$hpYJ*Az1Ci9?K8(K zBM(aj(aBUcJ4`U*B&H`pY}Y(4@6BavV3aXzb`2I>NImi{3$Os>SjTx7MzDLaw z2?BMC0y`#q(}(Whj?+e;{e&X?Tqq_i2sMS7Rk6EaY0SX8636ZNzWQ_2H=?KNBA(;U z44Z30iQ#=2A+!U>HT_U<9o-He#0bm5;>rWF2BOvBnatHfJI8e!@$kfpHE4XV{qIDJZ8?NE8je!NhT4aXp8&TC_j{ zkz=OLj+*|~>rs8PXyKheV+k*f3_v|1jb4;EnOBJv>r2u;K=w|ZnTMwk^WC7hF6c;P zdq&vp!Ex<}F29aeMXIM!3@-Mz56?hLI>j)FVo(W<-tsMKa5)%ZJV-R`ab=(+mqQr` zFVsE7-NLL=w9cg(?iR;!_rpjGS{oXwW_c*|74^a33T1{qUCMC>-VS;nO>~7YLJfrb zFk)jpDhLf{1hdR>TOOp!C?+(R5qOa39(nyCa%wYJ&3A*}ye?gywN@w=UD5cX5rYGz zN_S-FYfT@ft3Y+%_~~XOdLg@eB+-zLDKXpwAX#AL{O!se9^(A^LR zDv;Zv7XwYoEFjW!DJI1Zi35%PO!|Ew%osKDB06JKrL!|VloqWjO>scKrbJXB=P>C$ zAboyW1dp74RN8`E86L`WohnW7-+bgh(Q{7+iq@%P)B=gWHR1j>G+InzCN58dscCH5 zi_AU_N!P3K@f>k3_+!OPsX^E&vD=V>(p2`qZ=cB3#WP0n*9jX z`K!{`^>)UH_u;tY`E&arip64){2LsO;RBG=3SFA24bYeq4+BQ zaU!~4qS={{QW2uO;;tOUxWQ}hxKlTw{e2YWfm@Se$+yaU^bgNqG~kera#~SMQq0+T z*@oH%X0q`9fX*lludYBr0ln0&DhwFNI5%Mm@19&`f{cbT!Vai@!LfeHXtcjNxQS5U zjRzWYQA_(^lvnGEnkRTD8L)I{@Dw*oHNQdigHg#&5j7Xuq-zG1iCX;Bj>($})romx zM&@8us><%GhH=3D3iImf!*Pd`$z*iKgGxwf?U#0?#XYPPPcQGQMUmc=>8ad=ElIso zj0pXBJX9wfWfBi%GvrAb6z9}=jb@dhVI}VNRNnPgnH0y}On3)v@=@2}@kEZBvDVOm{dlXmdh6YGpcIiuX?R-(*sS-@lnpXR}00|?aRK0rgWj>9Ritm9!ffL zTKgWY-g}{IPX9H-Ba}BGMQWd7+OYmH(5-PSiBvFS|NE2mu#6mtMiae2L~|_a{%L~6 z-?6f4AImU$fga62W|3aFj}JXJtIOC0H(PZ#=Wl3}S1?K#Vo{z~tIjCyzgJrXA@)|2 zaG2GJItX4r@R=6JD&Dv)K0wW zrLVhk6s092pTktCbKME*tZcn-7q(t7qS6x;FP5?bO+V&D>EBpur5-V(9kXmoSGO68 zngzc1q3P9+hmmlh_z1uJ&gQ$!)0>&t>&bDZK@alLMp!%4cG*$866Iby6vs?DdW%)9 zX12F71wKe<@hQ$&)oUNyBdJH)D!tt+kz$6?n!plkY%8Har|PE?Of_vkwg&Dw^>iBB zsw3#vpX2-%wo5@N&SVx5U83tQk<&nkKv|zyl!5Nyr&w2CPzqC)&Lp400?dhAaYtQ0 z!TyXm0i)aF8E2D=DrLVVHP(Kb}pLER2I7`3QzE8k?(TU}s4 z#bd0}HuuedJ_zZC0y;REnX7PFR}5-=s5X3v6;-|-s9bbQQcUZ=FN3X(8elp@{Fv6K zz_|YAgWWI*olxdzf90TCgW}zp&O)fY+DxAV!M-be4BYOoGS$0479G1#A+k zv?+|S4HBy4Z^Cl*Qa?{8)0MFPhiY2*H3yBTV!Bz8BGl8OxaEssFW50Q*Lf>n!!=5e zk>a_xJH1Vtcg;Z)@}2IfBtSJNkK#X^p z0=3R!DK|jRT}#{2oh`jA4=aj3?Lb8)L7m6hCiNp`FC5WllV3Xwr_e{`_!?hh`c4RO zvuVwJ=z)HWunMN<@}l%JFg*@L4Zbjn$azXp_PbXMMa|sN9?%$6K>ZZ`8O-b~wm(G< z!5_5<>aMh;z<+_x+m5zws{jf3w9f`Gj3%X{K?qo=+(-#Gj5sI=tcXY z^>0rr7Y|x#yoj%!*Z7e0rN+e~&Zsc>;8lgj0P<0aahC>Pnk&2T`DEh?^l7mM-o2$(2$NwdU&86<>>@o0*q)|xsl}M8*bTg zLW?1R)a){>h{sba3|?g9EJIKS^6X2)JPiTDLOTJ8OaYs-jXg={9Al{$DNQ$?Fp)il zMwnq#_jis>|=dvtua(Q)HK@s(1!Gp;O?dy?V)hHqlY?Na&JFuePU zT&{N}B_%my$l$B;k~kbyCWjEqQh5xI8ytq|WX@9gzLxmBEuYnqi*se3$N4EnBN`v2 zppdSZIjtQZ^@)HlX9~ZQ@+aD&Hn{CDO&j9(NSm%9yIZs)HH?6P;6b|H(-vxo*L|%o zPbNLq25Rv98m%{Rn)#n~BxrXioe zM6xL~;OGl5WE)!~|>f|UgKkWVYP>Y*T$ z#76O<%pS4n3vn1}heT~G$tn{UY4MW=(UUw`A-<-=2}n%BnVEu#Og-4PzzPy2(lA}$PsSx9coEk;5yq0(6Z&UfID5K2uvIXf6fDr^ zCH{q`D&rUXbP`!!B(BmiVWN-LPfXvnP@F51*dO&*J+bmcFp??P^bJ}vcd1ywLn^Ww zVEk2mxRz!WPo4YV=wh)AZqA2PqA!XPKCy(aAldc0V8hylqG4^hv;^m0fV8PWT(V92 z9B(O?a>z1KZkF8=^IkHGNKUcTw;e8-Ddpm_I=+({2dH`5sW&G%xK28t{geC~ho!4l zmIJPSAUJT@E}f)iS6wcxH`6#%agDE}C#$}bLZWGm1JwG}Jrc`&3B1QUNZv$wp_LR= z>!7`!&e!|>x8DD?N}y(T9#{EDB0hLu(35_Y zOb*=?(Sec_L4 zW*PsQ&u?JuLaIja11S$u_G%ww=(#7*hEM2fV6#?~4~JoE7< zuC|eX&rJCJ{8U~QukaRNMNmsP+gnJ$tD^Psf0Dn~!smGYKh_N7=RVSnexziQ^c_qdm50Zf zcwr77rgnu>kxC@IKSmB!m6XSVMEpZ#(Mu&l$91Jyu=()7%by6L>Ri=N;w_}BRbJ^u z9Yv6LM#z^mxMVT3aKQ-Kz}g4rXUSd3F9YN$8ocN;!GtY?WfS?^Q2DAr9E0V<8Y1+U zf70N4BV>_$oF&iG{7KC>M_!;I&Vh2H1}hr`3AbbkX{4r9nCQ(O=^}99@?61>WPT+K zwqcl49}*obl!m|LrxI}6&xh<9Ak5cNg;W}c9|@=unoY!KgRq(>U?HiaYG>aCL2tv( z7`+}Bqx_a?Pb+|B&444(PFsdl4^@mrs;92m*7{Md$u_RH_ep| zaKkOG-BJEwZ0&nJw(=M*wc+SWx)YV9NVSuD8`9ujj1>Go{>7NOb8ne-&7Sw(uRIg5 RS-dfR6x`rkpR@sK{|kHex*Pxi delta 5462 zcmZ8kd0OP_Sgwmun+minG`^RDb^Nn)(96kjNHaqa;5o(}Z$8lU+vRsCGnFm1Lv>0nW9$Zvu}MjfP(XYHW5j`m^Ix(NZH#lE+E@kU$GS0r)xdGdBM!WY zF2|-Y#_M4ETD-?B(Cp3_8;u;7`M389P)S@E9@57kYafexd`hPduPs4saY;*uJ$X-8>p;f#3)5}H|Y_Zu|CZbyr(R=mz#4VL@yE>Ip?`!Kb8pjP{Z zHXr?FqiPPuECpts@$HPY?uG2TZ5+q_>)TTk(QfyVjFILC)y|)nzt%kqZE*Ksyf4Z* z?uM=K7vu=Fqcd(cd~>;K(b{L|0V#dH_3|FHD3VI;sL(1ivwjYa+g)PahQ@TIf-uG` z?8QZfANthYjyv2`AJk;AGur_my6{T05v?|->nGA;&SH|^ z+&FGR?%v&KvX`FO9~Lhrcr0+-17qA_bRf)*0;6Mev%%4$nbZl0Zn3Pri&nr91xDMj zGgFmNuNd8SuRF)_^TxYD?z%J~OAXLgS#{_rZC}*qEGq|R5$IotgBG^O-@5HDvr^+;d@APXN~Ve)Z`O_ zYJ>DJUqNNVmt1Z^V;zxrNEcPcqvIua)D$S|HSP`U$I{skdMo{Aq@wu95R?!U%$WJW z-1yZyYfxji5OlDMzi!grMIXsX3&%C~aQ+NEL!}~G&_ze&aw^Bg)YX3icJI?0FSAL97XHu~@lVJugE5wxq0DuDSZz{EDfM6fWh2AnNuhN$(09nCLTSV9wW9#bROU4sy2SS%zpe+b z$&B&1k>mFMySW-QIfgSv6^uyEsDec3<|KS)lAbf;&d3?x@Y~ z(A(^hy(j+66LjlcHB!3g=znZ5q|heOs#6=Q>Ru?#d%3JXjDj6y`&e=7bk$qy8K_Gs zb@Y3%j`k_Flc-om`#e>aT;u?bJCsSLva@C4$Y^M?8GUqXN>61BDT5>F$@I4<95?rX z*Ld1>xHd+$plEOXqB)kqadRBDU98PJra+88J@u7z2l}|>)qw_pRo_G}!Eu(|NMFK& zQYUz7EMV*jJwsukH2k%#ZZOI@Ea*?b@Y=i47qW;#Lwxk5Jp!1Xp%?z7U9A^3E)rVv z9Upx;KMz6ApMQ`JUF;Gsh)_M{Z=eln4D_>2&t>d%xDOJ4b$9s|@QN5!);@Ec5T!Z0 z+QV27D9S^-A?Xe%jgEM`9FmN}RZ~LH)(9G|KH{ay}$Kv}czA7fiD+Xq&` z@@G}6Hq?b7r3Vg{EPt{sn2Ou8uq^@#^lB&#SlBfSnkbuvt^=2sw;f&E>C#uDY0?v+ zbX^;1VG~mC=ZTB$aFT%`x|GsxDI-JJa&eAPRov=s??eRxD%t-80HIjjw}p&vqh^u1&Z>w&Vu zohwWgds0~eEOaV?LzU+-ESU3F{!w9I1nGx0# zX?Fdw`Z9oApBZpRb%gjgHq8U{O^{yT?hJk)nh$_e~J*e)Oh;C{fnm zhCSeEaJL&tL{}tzGnRwN@sA^O(F#Kho4?Lyd}p{A6m0Ti@A){RK6-xzlUZ%S7g3%e znVE3V_MgtJ9MfqM*=e#i-Yn-szBD(aneg0J!viC1 zWSlLmCd9*atS`E8l}U|f48esjg0GS*l9u= z>dd&huR+7d`WSF?Np`Xc6)jcCt18%gaOUTi_>J}q;{JD9Dh_`1O%%mz;U6Df? zo6MP>B;8GYJ%wyNWqz223$K|1P*dOE$$^>XUwYxDfx-{?+iM0NB2713GU6Q-@bg2# z^o)Sr@(dO-%3vxskOWlZzK@Y_bb%8j3vV{=#W0aa7Tlo%3tJZOSJ#`Prz zkzA}W1oHS!SJ6hmd9@Gq=ttZt4c7$9^}>aN%ns6)XFep5m=g15ckJ8W9FA`m3GR5@ zW=X>(gUkv!Q)tezl9$uX12nQf(R^IS@V}XypJu*oz)gRVAK)Jc%j@y}C6bKa&Xdig zu1F3SaQ$#uekvg#8EPeG7E57%xMi^vfjd?!1$cUmsS+PpEQq*%mmJ~xwNWw=Ax}Dy zg0&-pND7z9bB$#FF8PsFXJpsN0akplw<6;^Nc6#17Kna$k;5bstwinx&<~WHcvFqZ zAFqB>R&daJkkgPIGN?n$oTm~3k^~X=JR@7l?6>6p9#2KOQON|E_x%6Nv#-dC8+P_I z2;{(OMUBRTt|=0!JFm<(U@hDvlQ$yF!Dif=ENV;(gH|*?us{hQ558AIV(^{Cf!*w@=7H@v*ioPg^O3juFAq^{&ns5D%_)uECX z85AU?2;>91w8BVXkDz6y;p|j^^2#(m5D$qF&G_{rLNfk3Un;}adayYgBU;T=d+A#( zav)WX#2bg2!*EkLfIs*<(+d;v>it3_dGWAN(TB#7uvQLAfP1J8j_(8^U!mUm30_d8zL?+kTD+O6?R;9 zQar_!JC8ZXg`*XjT-`6M5}p*|gR7ns%*67X&?I4}EW)fy;&g>r!^ILKtyv-U<4jco z2`x4)GGJ>z({R!?++;{0mNJu7)HPb{ruzy-L?#_K#Y8)9?w9;WO11eN_DwdjoWJ>p^bgS-d$Bs(b0vY5_z0dr+xHz6b+?^`^u1sm=VM!^T z^xHzNk5yW9RWfp-vVbQ-k#f^SCX7_tc+xLQ;#J}yOABoTRx)qIeYW$V7N10?a z@XL*4*%rR{a51uU`t+)9_{c+k1F3k#FH6O08n5E&$$XYqa%^H!Y(-gl_muHvY0in2 zGiS|>AXkzMq6uHv&UYaRQ}{C}PxRfe?_@r=^Ma_ya3Az)Zc1+w@VnUt8-_cf2&L9J zQER%~+`g*P7u{-5o4vn@3Ma>8zM6fK42fUJ<5VY~-dx-8S{i|0gH3o_wn1(FZRu#0 zUL&)GW;O5GG;}bn0q^KzFyqyse01}lDZ6;Msr+zVC?tkQ^ACA^U=nX3gVOjD7IJD5 zpUG3r6p}oG9}nY8Wk*B#z*p1#a9?b(1mP%+${5c0_ gyW6|?1z#a#a83N_m$o(6ZGHVic;j&cat7u6AFUz9s{jB1