From 8bea5bfe119466a596e69284157e46d089c81aaa Mon Sep 17 00:00:00 2001 From: Joas Schilling Date: Wed, 15 May 2024 10:28:18 +0200 Subject: [PATCH] fix: Correctly check result of function Signed-off-by: Joas Schilling [skip ci] --- index.php | 4 ++-- lib/Updater.php | 4 ++-- updater.phar | Bin 763202 -> 763202 bytes 3 files changed, 4 insertions(+), 4 deletions(-) diff --git a/index.php b/index.php index 31142c90..24aad88c 100644 --- a/index.php +++ b/index.php @@ -688,12 +688,12 @@ public function verifyIntegrity() { -----END CERTIFICATE----- EOF; - $validSignature = (bool)openssl_verify( + $validSignature = openssl_verify( file_get_contents($this->getDownloadedFilePath()), base64_decode($response['signature']), $certificate, OPENSSL_ALGO_SHA512 - ); + ) === 1; if ($validSignature === false) { throw new \Exception('Signature of update is not valid'); diff --git a/lib/Updater.php b/lib/Updater.php index 8e5825a8..06f65e8b 100644 --- a/lib/Updater.php +++ b/lib/Updater.php @@ -652,12 +652,12 @@ public function verifyIntegrity() { -----END CERTIFICATE----- EOF; - $validSignature = (bool)openssl_verify( + $validSignature = openssl_verify( file_get_contents($this->getDownloadedFilePath()), base64_decode($response['signature']), $certificate, OPENSSL_ALGO_SHA512 - ); + ) === 1; if ($validSignature === false) { throw new \Exception('Signature of update is not valid'); diff --git a/updater.phar b/updater.phar index ed4428dfdea8469963d18ec996b790efcc9426a5..53a9e46af79b3334c7f690902b5ca30fa2deaa59 100755 GIT binary patch delta 5594 zcmZ`+c~}%zwy*B$rK+o&E;hSqw#H^(ML`f15H}Pe?nEUDL_`fBE@6kZA#M1iIXQ6CnXh^B(L9@^uJ#JHR_MAC|i>itO$ZoRXMq6PRXqJ%BhvD@S1NQ zHigoW7r)zsMka)tDdTOUAY`0cya1)eB{0Sh8bR=yc(M)|;vyO2Q!trb|KT=tHmWCM z2nIp;>a}SFXjoLNFZB_x69nhClK3H*(!WsD5MxKTV!fI4aJnEIP0o3(QyR;pO`?n% zqP&>HjbJn9O2{RY9-F444$;EcbSCLZJ!-pMKx%XBks{ zdkMn%{P|||Ui1*ghzJ*itA8(SM?+#pGRA6fR(){Z2=sIGFqYZtHbF?9aI2&>2**PVI)4br?5lG+1>B!n@>UW*`v zja}UiCca3U;LVtGA;cG9(b?!mTw)LEcrKVlbld(-XATqqb4zB;o;IU`#-9SORE^RT z`y#W^`;o!SQ3){oV~$Tl4D@9jMhcC7()b&p7HJXkyD$^7<(b^#2!5!qop=) zbX((v_KgaXYTa3)Gn&CnONCZXzj-?z6`0)6c+ZrxUf{9!cS%O7>q^8?iZh0ZFydmSzH@JCLg7y8kt zG7oi&1Yv3zGQ|#u>*m zX%V#eyM^tIC@_$lwHs_q(913e=?mxQps#{E1IZ{|k{IU41`5L7JLP>kVG@BnC4W?K z&gxeTiBp77I#hh`xkd)p$cs=1LJz10rKzLd`H}a+jM~yv^`6_B(k0)h3sFB`7uxxi zT|KLEBTC17e$5*#3L3`Jd;cgDvCHuy7af{ZL^L7i7bl`bcW{1*YRd&3lX}eY&@F z-Nds&!~8jnCeDCnCI0Gx%3NIQsm+gP<8L3xf=3P(ghT1193^;gjpnI#wZna!DLuP- zh!(Z^r}ErkpTs#ydCc&2=fBG_PD(nQQ>|IYVp@G;nz@k)}Cu&04Sc=JN7P2FtfiPobHoXg05S* zU|4{i3D!gKQ(ljsK6kgoUypV<%)H=(j!dRC8)~|E@!x6B&Ev{^)F0djgHoRZTWs#G zT2MN%sFm*FQ@XzGmx|{ZQUBf!J`ZoO41a5f1r9tv+Y@0$4Slm@5YrB>^F>yd#1i-% z1m&4c6>KI61q#Z0$x{t-@g7kcl`__a%7a}fp&&%v4rrmBr8M-ypswg#pbG`pbyb(U zQ>Juy>-dKNG-{!s`Z_Olyf?R^)GzpJ9c%^;Evm3DB#0$)#zPQhW?Z}Z-11m~m-=%z zZb|98TX)v7Hq`{1P~}li>6F_oDhVFWTsQ!Q8CCa>!$@7ICRj%0$INP)KX*ZC)`GT; zXm~^qb~@h#^YLBIuj)LV87RcZfjYW)px7}Eb(_1*lzwsSp%;UEN0(?mz93s~bY_fQ zy$GJ^+P%AZ~G%G(h5fJS{^}fEW zicIij`>$U&!BTUf7OR6Xucit@Z0)xFth5%Z0ks~pN>3pGb%VxR`IIB!Zmdss{(@S3 z`RBv$^@4EV=f+CNYY@-;H4lE$zJw@i?K4wZyW1vOQ16|pn&U2q(k+)auZMQ?FM!Ly z7`^Q3Sq7gb)reG24*wz09%)6v@9ctN#IJe$nP$ooquH%z^!A~egBAchia}lY*N4Q!G}H63iyhlLQ3bX8?c}47@mL;ee$)ZI>@~}Da}^A(x6y= zNNd5})t$#Sz{SXM+w7E3-wzelk;`3D>Uh0t1{4~D+VZU`-M2IrrSD!LXF?Q4R-z(^c&}6hA+{uvoPq_KFjBL5z ziBx_RsL8pot}M+~Fw4r_pN&R@a;SX_jP|m7d*NKfL1cbOe+kSxRnBQJ6ppgpz_9I! zE{1P}q0G-6V2n6f+8efFZ^qaGmDGy2mjPtq%=#!O&X+HyasZFtroY!S$aT#2Q>7T* zQ%bjgn*Wraav#N!S2@T1;dKUXW7>8~FD{K+%D`RYV@C64d#Y*fwov+4XT)a=l{G#b zl?wrDpUlnEvxQdUV?eJ~1*p^9JAl#$woN}hpFdUj%$u*;$B@o{@7R0-2FPzY1c`6o zyCL75p8-9svZ~A7cOj+O@7gm^iY1TLe*(~WJ!^YUwi9<*yioO7e`#&!!Ty_>e-V8F z1KL&o;vv}Q{)lQVK4tP5Su(R~+N_ev^vYZBE)LC8USxiqkn>084R-+{IgGIm&fT@e z{m;X><1VbrZ0Z5`BBE3?zsLemp+f$(d<$HBKG*ge^4A5R4xJx^iZug%e{|n*q!TKE zC{gsr+XiSXYK;5XQ+oWtYHt)N1|a&|y`-^|md(m? zBbKHp$z8=QX|qgD^7#x?jh-x<&wQ27(vd7$(Y)UA zxWh;3kN(lyf}XX=q}rt9D`;YG1q~fE4xd|Ya^m8bG+oH8D$@iTsXT2u+zU@@H2ILR zYfT~HoyF+G*V$ud~~?^q{)t*Q;=N`?lnOE6h*+H_Mk_E~H4q_3Hl9&w3r zr71;4NySqVBky z<7g$2)NhbmwRqeZML`R@sc2aeX1T$Ot?^32S{?o&M)wG}*hD8OwTi>LkOs3jPD3V3 zVu1$3vx~GD#AzDREQ@|3v3ZC=8eDKg>x+k5MLjtmCbsLTnhx8>X}ri^Mrm3_?93Fs zNM*LRX%Xk*8`_Mnc)%r4$eN@%F^RxqQYA4rX;SU@vLxQ39-~OYQEglxGp6~N$%O*V zOIq9#3UY|hg`j**k{)L+0_W#O%4b#F;ir?y?OVqCGJC{(PZ;yb*&Rl03VFQUxL6C_ zHhN;~Nuz;${DE<#p0r#yS`E0_tT${dG=xwiKXS!l96BFA>n4pQ&F%VAlX37?qe80A z8%!!baNQ7r3#yGK^7~q2gAsR>i3vFKmKcivQL2+j)fz*NjKRvdvDwgEAfB*iB6Mj-YrFIGD)Q1lL5eH?;ALwE)lGDzX&?{1U^dHk`u z{~MN^{YhG%K&zEVkVU%Y#~v{}4#YEv?gcXUu5qh_n3l+|dy%%&`c%#H!I}Ou`sw5P zXl!kVwtja(e+4ow6OB0VxZXmZp3$f1N%V1jvmUpZ^m<~clAoB!$NThU9;95S&(!11 z%ftu_qt3-`*K}TZbD9oj0GM*m#hrN^HZK=rSpSG_v-o}r*|JOwvy)x2{z*M^jn9>d zyUEzu;$SNe1@9Ljss`ZQ{h_!-grAHu&WO{QNPt79@g^|XM;@g9f;dCOd(w7SkSeV%+(4c_5@m_XLP^ji@v)T^O3D{XO$NS3C@gWUqVI!;x9cl; zwgrh&_Z&X>=m@C-PdX$e(^V5i2b)SyhbLb;!{3np3f^h&z-0)x29vHbsYsWLd@%fn z%-ox*8=MvkPPXbJ_yNltVz837D7o4PcTADJas71JPU2_FS2Q@&B1t5#ME*>}xp@`x zKXv5Tbor2mG`uX|)R2r)d6|YINhy_+$dNL6k%pX}D!0JYJ@nAU4qZ8|$w=1J>U#O& z;90sz`kqB#XyxA6ywPAMSJQMWqo0dL;?1=>3D*;ygA6>POSF^X65T>A0dS>R$l*ra zdXY}tL5gPST(R^qn3VkjgTdPl>v9O}hA0yrJ^}VrK%sb4BH!eRgH>D_FIvcr81axE zFPZ@B+BsYdB5!4i*;YJhf*6F-x_RLSMQy#Phz+y(@^^P z^u{%ty;B;$?_DQ04jr^6i{7&Fx`5bc3p8x;= delta 5409 zcmZ8ld0CaO`B%v6E37YSl?G zh0#5WCq+k3DB8HY*Z=!@=jA{DL|J?WACCqrez;|->MzxB9QW-6xfu0U`djFSX5zRh zw{AzF8aazG_JhXwo;{zU+1*1KBMLO^Ur9#vG|CUvcJp9Nn}OrvMl`*FlA_`n<8?55 zt-Et2X!T%>ZAOkuefympbR;U+YkF~EX_VtHjst>zJf&sB7Z;$!?md}yO$NuEJ>>fm z%I?;UF(OcceKAg1Y)f4Yte{d|#K>!mv$t!27X^@ku`{G~SkA3Wp&e?rl} ztiITBMG??ln-gCgRbJ_1J`5gDvx1Uc$KRQ!~GFoi)MI&sUOql2e2+W_G zU2RQ6TdmIeVGY(iCM=XW?mzQyG@_|ay&2=31spfeCn^Wk+B;my_(Hzwq>b#Pr$g!f z`(-KUV8C+?blu5S_ZP@<2P2Pvj~c?M(1OxcSDag_TD3Kh4o#2J%5h^aqY8B(Gnoa9 z-tof|kQVve1dXvcGhrK`JSe**C8A_>OHF@W{haD*OWhk`&FNgUZ*d zB8+H*lB8#SMoD9mU!6E^Le}B^s6Y!ve^}fY^EWfcJvK&tf(j%0>+0`CjAjx$z`fH_ z{S&$am^i|{(bh=a8n5PCM#TyNvJtBW$vLby51M|H#qCO8P)`_Hn`$5_c7 z;k_91gv4>zGwR|{YasROf^J9ZZT%e_xOb-K6J+%aMA!Vxct}rGMt3{wm|TKDhc9h8 zgPQ&O>4Exm?#mn=0m)jgiUhPa?75wUwszK|%?9bVOK)vN_JBa-@9(YKCj09X7-r$P z`dIsq&8?Qy{iit4?lok`FrT_LN$NJc})_ra(?0K%7;eG+uw`}WWe8EVnt-i*0Sf%G&%Q+B5hs(HTt?I3nwC7Ig z&z@WE0ak(4UG?6b4?(^+bBLLpN`rLtR~79vj50-w((_BYEkW!2Sqcn_GDwsPDfQlR zv7SOf^FwW2^}azMsM}vX3J^?SVWmSuc<%UR3%H46jNj@x?(l;~2eNh=&KRZ8;2EQG zVxVn@FvfW>N#DKd0(##i5HH4e_ddne39lA z$(Z9+*j%p`_k)%X#I=1?5jU?;-KAvzb_ds8^=gOp=eT33q>Qx-(+leZ?NX7c>rwi7 z%8+6}xZO>Dsw#NCTwF<;Vkay$8V;p%n%oL0hb|H@NLkiXI2j|0DAhaSPr!-zMZs`MM9n6vP`J8E3^eYgVK=Kb~(YQX0Qx@0EXM) zZJsPNs_!+deAWya)`)f!N?n7#e#SbPNHJkybQ?HbsKmRxhnzlW^1-(^Q={mF> z!+D6S9^CkH*zGaDSUV1L(>`u51*IALt_HJ1AVX*Ewx}CZ8WH;DB#1a1<$HLss5b&s zr(B-?@!~*;$<^BdHKYepy0P`gX&u`(1D$pAK~2v7c+WzUjO~k5la|tcGNs!;YR-ep zXe9If9^_kaJUf+brE=#k`rdiNc_@?K_T;$xr`B7bqXx0fo&|%xQ)>9JPWy|j4)g3N9wLgcx`3gD12EjgERq?nOD3X7m?upW_@goE2#=uP6 z9HlC#+*=>zWdLdJ<-Gs0YmvqRD#6-mm{wXXN-NT?-hyS_Zal6Mc6l8jO~sT3o$D7s z>(TCe2FzAoJ06sJcmCM)Li|lMh#y4j)|77EzPpCaLq}v*Z7&QqbxvtndegLyYXofz z@?lWq!5n#9s>y9%3bkJyVwk6nSF{Fy^Dl&*X6x>8s@VfbQ<>Z2Lkp`&zcMQ}2j=BvL(UxiBK zd7NE^%H=?2YlJb3i@Na$CCcH9VFl>w9;VBvND9?KT`Tp~Kfadqck{cia@^`~XB8kp z>db74;Z1ouasA6kmUToM!0V%k?MG3J6wEYM$8lWG?0&K6ny4?uNnmo~Kv))9V~Auk z+VL3gn9)eo#pDIAav9}ES+&1{I>mv~$}3$ipn--sX2!ud{A*6h*bcL>=VpHxt$Ns+ zNnfMO;r>5xp?(kAZ5qIW3Jrl#x>#@njW-WwjD^s~v9EkrTx}kvM-BB@_tC7OXuL_k z=s!t>$NZ?d7PQ~2zd@>?E^@q2FO*|!e-OTAOl5(^fh}i!K zr?J^{kcT0R9rpoP%&7lIExN+%@Bbgbhs*er@1SRb{!fo5z_{Nfp(k<(I?yNJiPbfs z&q(yP7{h$b1dY(>x-ZcwL3dgPr8v4cV=b7tBTvDmV-hYTG4*2*|EQwR(on6Sm(mW` z#Fke|VabcS{Y(hzU~qUA>MiP}+z;=F;E}6upm+I@WLlFqVEdSe}FSq2LkBS-oxCnOAiE9Crg<-P$olt_>9 zor%&Gd}OmI;WrB;h158t5HqfwB1tbK1SCUk>5TL>l8+4^9VJV+?OnkGUqgZyUev=R z5N)Q^+lcq%i*~$yjmaBt*d@uh^AU(?$R`r0!NnEFY|1TBs<}Bhh!#AJ7qNj4|*btq~?xXWx!gBNh0fdD_s=aoFiyV3xie!ZbGsT zdHlN^7>V1kStNc71ckDDa;pXJULa4wZQn{79%mHYalt*=iA?%Z zj`3m=0S^bTfHWFaBOn`e%z%typsa_O&sh6J9w{;%|4rY zhykQ6NgQs*jwI2I42l)w&E%gk;u<4`J(Q-Ih|>oHl!J;Tf4rd_hUE1Ya~%GrP%Or_ zePDAoL$E1Sd)cO&paRNac-v$p7&oK<_=A5l&7O!ioHvJ&d6&(TGwC@Z*5-o};2xxd z<2lEiEz{o<$-vF#ektVB0<*h@9h=3$^jr^eda3!T8=0LZ#26@iDz5!dOx#q?tE|CD zb)vAqK*oj&*I2cD$+#t^thvlL&YdPpgPdh_! zwiKbjNK=+cZI!9iOoC>Z78$VZ71MAMkYX~#6U#i4P0%&Y#F!q*6cCBD8pIf1ytu^- zIT*ygB>j6~v$vk;!WOBE-oWF!%jFR9bUotCBsod?lgiQ2LIiHOY*z5C_r(-i{9*fU zN~5xM9+W)AZ632YOfv;{7B(iOc&?kUqYbQI9@Da=- zIEGS(6PS!GRy`gzS`7Phxp{Ikk3r3q{TET38nHCp7c!@d6hW(iwj+lTT&=l zk!HATz+qGQ0VM5h{wD)jooF~`Cii#nD~%+62j6G75LQ%PUfLDU{*~WKyr1wZ5^zZ( zG|-tTe7aLix7cozqvIyT6ctVkB^!Gf1QTAho9{%{P2~gQo+~=xswsTd^9zDr4Jqi^ zvN0GghTdp>lD#o1d4m~MtaHV1L5xA0YV0T~S!zt)P~wT#i@ddQ=Jn7J5+d^sPXfPJ z^T@tEsqve-*An3)gIu)p789Di&Vu1if&YG6mf85#^2-XnTdK^BB?HGKBLAd1T##W< z@cke@qH$cpKAzrOvE=8`{1cvRPvpP0knj>dm8S~vcu*|Bw0#6W68bukw~*jqex)0! z?8m#=aNS?{ndCtpzs!l=I?jzdqL+#2VE1!=%FP3g?P$46(E;D=nhUqySS6Kz2v0k% Jf5xDU{{xS32Z{gy