Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Commit 77446d2

Browse files
authored
bpo-46948: Fix CVE-2022-26488 by ensuring the Windows Installer correctly uses the install path during repair (pythonGH-31726)
1 parent ca9689f commit 77446d2

File tree

12 files changed

+27
-4
lines changed

12 files changed

+27
-4
lines changed
Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,2 @@
1+
Prevent CVE-2022-26488 by ensuring the Add to PATH option in the Windows
2+
installer uses the correct path when being repaired.

Tools/msi/appendpath/appendpath.wxs

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,7 @@
33
<Product Id="*" Language="!(loc.LCID)" Name="!(loc.Title)" Version="$(var.Version)" Manufacturer="!(loc.Manufacturer)" UpgradeCode="$(var.UpgradeCode)">
44
<Package InstallerVersion="500" Compressed="yes" InstallScope="perUser" />
55

6+
<PropertyRef Id="DetectTargetDir" />
67
<PropertyRef Id="UpgradeTable" />
78
<PropertyRef Id="REGISTRYKEY" />
89

Tools/msi/bundle/bundle.wxs

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -108,8 +108,8 @@
108108
<PackageGroupRef Id="crt" />
109109
<?endif ?>
110110
<PackageGroupRef Id="core" />
111-
<PackageGroupRef Id="dev" />
112111
<PackageGroupRef Id="exe" />
112+
<PackageGroupRef Id="dev" />
113113
<PackageGroupRef Id="lib" />
114114
<PackageGroupRef Id="test" />
115115
<PackageGroupRef Id="doc" />

Tools/msi/common.wxs

Lines changed: 14 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -53,11 +53,23 @@
5353
</Fragment>
5454

5555
<Fragment>
56-
<?ifdef InstallDirectoryGuidSeed ?>
5756
<Directory Id="TARGETDIR" Name="SourceDir">
57+
<?ifdef InstallDirectoryGuidSeed ?>
5858
<Directory Id="InstallDirectory" ComponentGuidGenerationSeed="$(var.InstallDirectoryGuidSeed)" />
59+
<?endif ?>
5960
</Directory>
60-
<?endif ?>
61+
</Fragment>
62+
63+
<Fragment>
64+
<!-- Locate TARGETDIR automatically assuming we have executables installed -->
65+
<Property Id="TARGETDIR">
66+
<ComponentSearch Id="PythonExe_Directory" Guid="$(var.PythonExeComponentGuid)">
67+
<DirectorySearch Id="PythonExe_Directory" AssignToProperty="yes" Path=".">
68+
<FileSearch Id="PythonExe_DirectoryFile" Name="python.exe" />
69+
</DirectorySearch>
70+
</ComponentSearch>
71+
</Property>
72+
<Property Id="DetectTargetDir" Value="1" />
6173
</Fragment>
6274

6375
<!-- Top-level directories -->

Tools/msi/dev/dev.wxs

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,7 @@
44
<Package InstallerVersion="500" Compressed="yes" InstallScope="perUser" />
55
<MediaTemplate EmbedCab="yes" CompressionLevel="high" />
66

7+
<PropertyRef Id="DetectTargetDir" />
78
<PropertyRef Id="UpgradeTable" />
89

910
<Feature Id="DefaultFeature" AllowAdvertise="no" Title="!(loc.Title)" Description="!(loc.Description)">

Tools/msi/doc/doc.wxs

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,7 @@
44
<Package InstallerVersion="500" Compressed="yes" InstallScope="perUser" />
55
<MediaTemplate EmbedCab="yes" CompressionLevel="high" />
66

7+
<PropertyRef Id="DetectTargetDir" />
78
<PropertyRef Id="UpgradeTable" />
89
<PropertyRef Id="REGISTRYKEY" />
910

Tools/msi/lib/lib.wxs

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,7 @@
44
<Package InstallerVersion="500" Compressed="yes" InstallScope="perUser" />
55
<MediaTemplate EmbedCab="yes" CompressionLevel="high" />
66

7+
<PropertyRef Id="DetectTargetDir" />
78
<PropertyRef Id="UpgradeTable" />
89
<PropertyRef Id="REGISTRYKEY" />
910

Tools/msi/path/path.wxs

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,8 @@
22
<Wix xmlns="http://schemas.microsoft.com/wix/2006/wi">
33
<Product Id="*" Language="!(loc.LCID)" Name="!(loc.Title)" Version="$(var.Version)" Manufacturer="!(loc.Manufacturer)" UpgradeCode="$(var.UpgradeCode)">
44
<Package InstallerVersion="500" Compressed="yes" InstallScope="perUser" />
5-
5+
6+
<PropertyRef Id="DetectTargetDir" />
67
<PropertyRef Id="UpgradeTable" />
78
<PropertyRef Id="REGISTRYKEY" />
89

Tools/msi/tcltk/tcltk.wxs

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,7 @@
44
<Package InstallerVersion="500" Compressed="yes" InstallScope="perUser" />
55
<MediaTemplate EmbedCab="yes" CompressionLevel="high" />
66

7+
<PropertyRef Id="DetectTargetDir" />
78
<PropertyRef Id="UpgradeTable" />
89
<PropertyRef Id="REGISTRYKEY" />
910

Tools/msi/test/test.wxs

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,7 @@
44
<Package InstallerVersion="500" Compressed="yes" InstallScope="perUser" />
55
<MediaTemplate EmbedCab="yes" CompressionLevel="high" />
66

7+
<PropertyRef Id="DetectTargetDir" />
78
<PropertyRef Id="UpgradeTable" />
89
<PropertyRef Id="REGISTRYKEY" />
910

Tools/msi/tools/tools.wxs

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,7 @@
44
<Package InstallerVersion="500" Compressed="yes" InstallScope="perUser" />
55
<MediaTemplate EmbedCab="yes" CompressionLevel="high" />
66

7+
<PropertyRef Id="DetectTargetDir" />
78
<PropertyRef Id="UpgradeTable" />
89

910
<Feature Id="DefaultFeature" AllowAdvertise="no" Title="!(loc.Title)" Description="!(loc.Description)">

Tools/msi/ucrt/ucrt.wxs

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,7 @@
44
<Package InstallerVersion="500" Compressed="yes" InstallScope="perUser" />
55
<MediaTemplate EmbedCab="yes" CompressionLevel="high" />
66

7+
<PropertyRef Id="DetectTargetDir" />
78
<PropertyRef Id="UpgradeTable" />
89
<PropertyRef Id="REGISTRYKEY" />
910

0 commit comments

Comments
 (0)