From 7b9fd9aa62aa7dc97c5d09ab0d4945cb4af1ca9f Mon Sep 17 00:00:00 2001 From: Joas Schilling Date: Wed, 15 May 2024 10:28:18 +0200 Subject: [PATCH] fix: Correctly check result of function Signed-off-by: Joas Schilling --- index.php | 4 ++-- lib/Updater.php | 4 ++-- updater.phar | Bin 760151 -> 760148 bytes 3 files changed, 4 insertions(+), 4 deletions(-) diff --git a/index.php b/index.php index 69c1d161..62d7606c 100644 --- a/index.php +++ b/index.php @@ -708,12 +708,12 @@ public function verifyIntegrity(): void { -----END CERTIFICATE----- EOF; - $validSignature = (bool)openssl_verify( + $validSignature = openssl_verify( file_get_contents($this->getDownloadedFilePath()), base64_decode($response['signature']), $certificate, OPENSSL_ALGO_SHA512 - ); + ) === 1; if ($validSignature === false) { throw new \Exception('Signature of update is not valid'); diff --git a/lib/Updater.php b/lib/Updater.php index 37d112d1..f1725aa1 100644 --- a/lib/Updater.php +++ b/lib/Updater.php @@ -670,12 +670,12 @@ public function verifyIntegrity(): void { -----END CERTIFICATE----- EOF; - $validSignature = (bool)openssl_verify( + $validSignature = openssl_verify( file_get_contents($this->getDownloadedFilePath()), base64_decode($response['signature']), $certificate, OPENSSL_ALGO_SHA512 - ); + ) === 1; if ($validSignature === false) { throw new \Exception('Signature of update is not valid'); diff --git a/updater.phar b/updater.phar index d3eb6c6cedbf94aa7299826568432e4f8b65f67a..bfb802eb60ce9c5433d97477881839096c661696 100755 GIT binary patch delta 5382 zcma)9cT`l@*1u)iy)!U(hR%#I)S*aIP`ZeU7!?ttCWwkC8oNe~(O6Jpea~k((PIZq zUNknaaflU-DQX03j7Ea`VoPF=J?h)%+|lIy@vZgUwP161`R#tr<=pnzGuvYqmK&Q7 zjPKvSv|0bs(iV$0CjQUs&2E2xMeX?>CJvqp@KbQ+S~c1iV`Gegz&P?{L@rt=+EJY7 z&6s9^<63k-@CnM)*zwsdvX^3RMXfoGQb)6mU!$&KbEdi`o8wOIv9(2YVi} zPE18Bg*e7|2L796*~cNH#>p750O>eu5K+1|#EbeC!Ci~kD}U_d=^Mu-qppG-)$tOl zulH7JR3=AhpXSY&YbTz*Ta$rN5&^4kv2VdNSq%P%k^BOhQ$GHk1)!MK|}Fl!no&e@e%kxVRgA z7ozqh#TUFyn%EHy3u%Q0hgulKPklM=?0>!=0L*;GI0fChVaLHiqyjxEd*JRj0s^8BrDGSg-SfId3}Q6Z@V-T|6pm|65Enrx>6 zcXUG5nPNx1H!223l0FE_YRMBplb`H&ADwhT{Qf{zc3V^}N=*e1`a-r5=)n?yMKr1c zN{dE^rJ*#xsKx%iY9;Odd1@sg+`73P1Q2F3#v+O1j#;0-gfOE}g})l22h=-!-bOd5 zw++Snnn9pNC)OL3ub}Sqp)|X?Aq-vChoDP0?1r=eRe*|oo1ywo-IUJ(mp+tEIN;e2 z@Uxi1(QP>H`}8iQ=r?b5*!w`dZ_O^vVcp69)r7LXkd*JzRdY(m+pX3A6Umo8CI;0V z!t@CJ;T5aor5iGOdEMRcG229_VrQG`@P?k_qMa)SLKTyl*%+w7nKMsPp=GVr>Qs2E zi`Zu*Y(m0gcaTJ(KI=S`%d#2k};~s-Ed-*f=#bl0ax~5_enrsO{s}(;~Y_YIh za$)v9H&oqwJ)zksNC{nB9;BqZxGYWkkZ@77MRdcMIDqE(6?Dpm8(&?9D-_fMpXETx3b=)O=;-q zoM3?Jz_4e4!~6?{k6<3!Fh)QK$3?d65rSfaY^X}_frjb>nBcfO$Bk~)aFvBtt5ZX} z6VGwW$~UcHOhvCU3t=7n0>9F*1u8q|g^ueD3}P3Qc6io-5pWN9pfooHt*kaFvt7$W zX`%PYIna=Frk!eoQT^!B5;W2ySMBy5kGGiQ7^rT%?z0tkI+HPI&dYuxbK;4qcQ!0ku!>leK`uB-KfKl4ffB4;nD!ZHch;sk=U`Ae zs~Oc<)XSg(4vgL3KC+@I0WFy7pOqZ9_s)({4ERrjoiXd+IPAWw!Gj$ul~ymt%mPrK ze?MN%2D!qnL*;kP$_&@|Q<}TXw-xJ8h24mjZn7$=&~y4wy3OI-Nmq2S9gedmR))9{ zvRxzIn9i!HZ1z(O(W(KZ>$mrO>2hU6^P9Lci{o$+otYLh4Wd=|5kZI6*DUVIPF?EP z9zgF(*sS;f_4s-YSifvsb%YHy4SU%ZyD}KcKp#pU`YgW%x@itIw}m1cztHVr)Ydff~j?5B#^M zU#vqXtZy^MFc|Xeo}CidD(9JGwAD?Iirmy@?}v-;_Bh92HU(5z?C#A5WFrW=b?&s_ z^`6t4C=?C2Xqn~oyWkzY&ql41G%!clUSrehxXgindO_b#KDSer6L1>h*<+kKskcEqY*cB3G)oTeEm=$Dub790;PzPhMG z08^svzu%_!DWJ&0q*igo(f_(mnF0VyvBUQ!`U`Hmm?tyTG zTB8rZ?e4IsT=a*t88bNqZhMw|*9whxnH+}jXGiwTL<1vKw>9up5!Pew6=aAERLd6~ znacY247zhWD7pFT>G4G`oIdKrLm>1S4z#u`dpB2YzC5Skq2 zt|BjpYKGFH)T@?*6Y$`K!9{37Q}wJI2Rc$q|3vgrbe^hyJX$^H<^t-!_KolQ8Z`w_ zebK6DZ(LO=o6X^BFixNse=NR&&PS=AxQC&jCwopbq32D5K--A=HdRlBkD>Qpo~zsn zf>hO0N{qUXO8{!@PeJF9B`V5y)R^}Z>3+8W_w->@h(C=^Mkcas4`*`RH%T2QypGFG z$X}V6+p^XX+LHiMiq>GV)6q4VTXmirZxT~5m0>#qfg%iX)Ts&9s zCc95*FW8}EPBl}{8=6Qn`7uPJA45)$(|#i}YP)15n3!YwTj^L-eP@b8l5rIgOt@^jU?Jttg=ignC-9!GWn2tgJ2_b|2*GLHHWfo1U0Z&{nILW0sLZO!m1tJ|D zxkgAJ;s#-~%;apysF99<#OR7C&|B1zt+M!ycBx*B`>SjuR1hZ_NadHh7nS7rEB?4b z#wucKEd|ixK2BXb0yExPCZGB1CJE|(K>`+H7^>UjMFQ?>XGP(k?YjTFZn(Zo=S~I| z=vMk-m@GJb(sXX*SEp{Q2c6NsR~R%eCF9~H5PF|H-47zuC!l}R$`%se8lzvub^uq@ z>b%JOiTcMH%G^pej@0L9$j-s~M_RIStUg>zc6o_I-Er|cjf^vA3NoFKblm14OvXnr zDfspTA%)nd3r?O%NT1n4FCNFw5IhKIZslpueMzqw!Y!U$oGN_bVieC54)FwJjT)+9 zB*VrFwLFP`UplQJIo+fN5o#+1kXxD3yPiZGFYVIPv+_Bv&6La}q^D%@$B_lbP!f4a zp3n_%@G`E{IWjUb90{b2xA9sU9{QPV#H+d+J+N-S+|-m5lMpk=b!(8;`{flPsqAhv z^CYjp*iR(G_sSpfczF+F2XeQsv11BBJ&Y-mD#Sk>l%udzA!U=ugVG!m?z=+vU3ySz zg1fDeJ|M&9NOc-gx=pGvla&jl8aL9aLJGIwmwA$&w4N^&iWnGfWD^=P z^I3oOZ_;pd6k?^&VD9qHRQr{Imr(j zX2_o8VUg?+PGzb1`CM5d#Ub*v6aw$P4a^0BtF~4qaK}aSc1Lrf~aFDLbYg1qtXUtgpO^-63bAkX1;T7sOevmKl0u8Ex+$O-*!&h_Neyl zQMGG~B?&#pmzKnhPfQxOY-9KT`FVZVi$766O}^>!yG^BMIgT6Jc4a5Z@O4H8p&Mf= zI*yxk`C1fO8$_8_lsnH&*#(-^g3{6P@xP*N3Kd$=^)Gysx-KE5skK)YAYK>EpdP1j zTwJ#>r>|~Ux3t^g35WM{dkw=bN8(PClD2i8fR1;LErH|WL<6&nbEh$yikj~jv*d* z=DCW`vZdADDu^GY6oSMK;AJK#hvhu%!F|bdve@SKjJMDy4a6M?8QA zcm1Qsqbsw>0ztOXk_-WX zz~s%C{UIabUkaa~6W$P%(UUQ!h#WV)rte;K(2Ft+sL15P1d5sCO1@tBvFdc4hZqS- zU_~u-$YUDa0Z;R$=Uu2r24fUDaGZzk`XlsrCl#yuQ@wXo#h)tnIH{(TnugvR^Q`I# z=%9liGMlW-JR176CL!KKOfcA*^qLCo`hVBDHvpNJ;OR#X%a z!8CM(MCYIW@@FB>+WPRYxOSInM1& zT{g>Ml+}QaTh;nZkT~v*oAGuAHD#ksc`U0iln#$td;=YH8Oofd2pqR&U+V~HnEs4$ z4VvNBH#H{Y>zc1-XO?RYo2d+6j$07pB0bAUDynpeM=i@`G}%pLw!eYfh2c%B;ot$t zcUiEK4JoJ5Q`#VIy~6}8M+_)^z5%`Vm4}!F?x_O$(54PgJrsSx#)TCH~NWQ zU6G+0&jHNp8&KMK)qM-=-r7b9`K&i7$yPNyN;BtltYC?5a@HedgGC87sX|Jd66|-F zWs|eo_fKI$(YAH-pkBQh{<$6;*R8I8FWM(smwPFw!OP6}UO61+HP1hdjZ(`I38fuX zl)A3yC_T67$a0vTRHi)yGJK$=Xdy5nkmBXcm^AGl{6tQ`padZMM+Q`DaaT*X$&$u2 zMwi2`jeY0{t=dmzKzIY*F3nt^sO}>NWq8*Tq0~9> z$Nxb7!@-H(g$~~|7-U*PO556gNrs;5!+iAe;W*n%zkKiau=qe?pnLE!1v3{lj zlsT)13GK&mhf+z|b1U$J1}jDe*#IYXmp3+ zj~}4Hj+tsM{^~fGNjf3U6YuobvZL3oazOS~CdIkygp>v^-sqrq!75kfXo`9|N?*5G z=&h>ec%PH2iulNCPKo-4HZo$VUXqpL9;%Siw)v6sXLOz z+p^I-;j8BQS2)W*Hm*7b!9WVU)p9*);<(RmH&?I&7QO3$=J~1neIOKg^_f-6&=Y$W z3;hl()ScxkEvU{<#XAEUFE2QEg0%pcdcHKXbjozvQv17_gwiD*l|A78Q89RE+rrAA zUNA(-4D=niUR*|vzXPZ0#TZY(Ud{v*5u%lIt`r9^TPuFco>E^Om4#8ShgE4+~<9U6Asi{C6&)eqpM{On9&D2@20fBwT%W&IHhqn8xpsS9sS^dWWlB@fakx z{CdQr-C=@b||?XZGWG%p?>{{E$zCqk7bsh&Xt~nwYyp@Xu*uPN9?C)R)WQp6~!Jm~BFH zyY**aA;GZNPZwQ!2A0bFr*(6~|LJRV7U#hw%x2H6+X#mE4j?Yw_xcdz6R95Y&yefg z?M++I?1)r`I0G^&C3$s!hG=7mBXsKGeEx*?iS%Pn=%tZePv~`#eVK<95c2e&{Mymq zqSSnE2gbCfPwLSIjrx9q2Ih|K4$VeMq3V^Up<}wNe=Ir^VpYmON<*f!W8t*x=xV5% z`>jyf`w?qe(3TKi<|(iifIkfwjC7&u`@RA~&+68@C)ySo&NLiht2f?Dmr!-6+6*5; z{w`Sm^(q<^eVv>iq6ydGv>}>0oIGEaar6+4f(`kaH6$s=I8q=LX3d+)xX_&!apxzp z5ohg?d*j=A8aqmxDmEY6F;I{8RZ7k4V{}?P!k{tYUq6vwMYYZL=CrA{%x0Ip4Lm6| zXqIZp&HkEn9gayi_Cgn8Qk&xrxFv*^6vve&#Ec)8G`=J;v9!22Zd^if;@E_-rAe{H zrHL^;$0hcN85=*oq`BgLoF@4H(?%7KhBaFs>`;hzj?rDy{6##UiboAFrhwa?IM<+Y zC6R+Qzi82>I4h1BtN9jpJk{#R%mU2~9v|4DbtOJUnnyf&bEM`y9j*=K1M!-L`oCa% zJMZ~^J8#Fe4ZI$AP7y+Ir=ow09PXo^)CWh-G=$^U8-g3|y-1%#YP#!l9C6DWgN$q2 z1TS1($NNzAIe5xLA(i+p(s!3}`U7Dh0p?+U+>$T&lLSZoUhV(F&mo{c+l`cjiN_UO zl*Q-Z!BqhDdkkYL1q*TWTNe|;+7s-_*{)8iWwSXV&rm}Zr z@fHVCQO0j`!maIal(I73?~kFZ~emj6(oVhP{wF3EUq56MWz_m)~TxVnK?ewPrC zT+rd%nFf&zj+GiTfsKM$Pu&^t@fqNW6%I=3Pp(%O z=8CvQ(Th~#K)#z~I3SSdWHCb^V|=C89LccddgM&(2lZz?ar6=WAhp&Mf#fylzx2Y@ zRR)3FC>HvgSP$Xq6}m9BfZpXoH(GW+QQ*BDD2T1A6)oy`Oq? z7FGTnL&^(1#r#y<&`%hs1`VIVxZ<*2BClN5m+F}xaz4orAiaRbx(Ar$xT=pn0awj4 z6u%Hb);aw)ks2zE{>yaJaQX_J4{cBn662+FHarxTA@lsPy-*6qt12Wbt}Bx)M4v77 zb0LrVNauNCDwUkPaNa553GV14S*TVp8J#A5q$7h0rOyl)aGl7>8sh{BUm31(!qt^> z1i3z0J^>2#axqWJ=gYes@U+SDOtR%;IYWb+_RAi4X{8)S;%j6tCqgRaU1kh26WKXN zUSz@@p9)rbVXaF=D`K1pTvGQ1a{Cjxz>MMYNyM+E8?$l6K;z%=td9ZeM7wOpN0W@n zB=xDhxFiyZ@Sg9bkI2YV(v@D=<_X}ST%jXTg|ZuuPuOH1btB|? z%WfnuUxwKMQ6S!0C3%wto^n)A+ryD7Q;T