summary refs log tree commit diff
path: root/pkgs/development/libraries/qt-5
diff options
context:
space:
mode:
authorMilan Pässler <mil@nyantec.com>2019-11-04 22:50:00 +0100
committerMilan Pässler <mil@nyantec.com>2019-11-04 22:50:00 +0100
commit00ac18cdea8bbe9bc4c7f68b7de4e99ed27fdb54 (patch)
tree4407337891ea472d605e198a5e0f198902dd14b7 /pkgs/development/libraries/qt-5
parentc4821a82f880df90987ff56a4e781fc42ed914b5 (diff)
downloadnixpkgs-00ac18cdea8bbe9bc4c7f68b7de4e99ed27fdb54.tar
nixpkgs-00ac18cdea8bbe9bc4c7f68b7de4e99ed27fdb54.tar.gz
nixpkgs-00ac18cdea8bbe9bc4c7f68b7de4e99ed27fdb54.tar.bz2
nixpkgs-00ac18cdea8bbe9bc4c7f68b7de4e99ed27fdb54.tar.lz
nixpkgs-00ac18cdea8bbe9bc4c7f68b7de4e99ed27fdb54.tar.xz
nixpkgs-00ac18cdea8bbe9bc4c7f68b7de4e99ed27fdb54.tar.zst
nixpkgs-00ac18cdea8bbe9bc4c7f68b7de4e99ed27fdb54.zip
qtwebengine: add patch for CVE-2019-13720
Diffstat (limited to 'pkgs/development/libraries/qt-5')
-rw-r--r--pkgs/development/libraries/qt-5/5.12/default.nix9
1 files changed, 9 insertions, 0 deletions
diff --git a/pkgs/development/libraries/qt-5/5.12/default.nix b/pkgs/development/libraries/qt-5/5.12/default.nix
index 2800f2d7797..9b6534c01b2 100644
--- a/pkgs/development/libraries/qt-5/5.12/default.nix
+++ b/pkgs/development/libraries/qt-5/5.12/default.nix
@@ -79,6 +79,15 @@ let
         url = "https://git.archlinux.org/svntogit/packages.git/plain/trunk/qtbug-77037-workaround.patch?h=packages/qt5-webengine&id=fc77d6b3d5ec74e421b58f199efceb2593cbf951";
         sha256 = "1gv733qfdn9746nbqqxzyjx4ijjqkkb7zb71nxax49nna5bri3am";
       })
+      # patch for CVE-2019-13720, can be removed when it is included in the next upstream release
+      # https://bugreports.qt.io/browse/QTBUG-1019226
+      (fetchpatch {
+        name = "qtwebengine-CVE-2019-13720.patch";
+        url = "https://code.qt.io/cgit/qt/qtwebengine-chromium.git/patch/?id=d6e5fc10";
+        sha256 = "0ywc12m196pr6xn7l5xbascihygkjj4pbcgcn9wxvi5ssdr6z46z";
+        extraPrefix = "src/3rdparty/";
+        stripLen = 1;
+      })
     ]
       ++ optional stdenv.isDarwin ./qtwebengine-darwin-no-platform-check.patch;
     qtwebkit = [ ./qtwebkit.patch ]