summary refs log tree commit diff
path: root/pkgs/development/libraries/zziplib
diff options
context:
space:
mode:
authorMarek Mahut <marek.mahut@satoshilabs.com>2019-06-16 12:14:08 +0200
committerVladimír Čunát <v@cunat.cz>2019-06-16 12:17:30 +0200
commit3aa8f9448cfdf24d6322b31805a969af5b9cfdcd (patch)
tree10729a6d73ac5fc6f47068b77a32c7dbecca64c8 /pkgs/development/libraries/zziplib
parent9e480c5dfa1909c58f80ab855a3d5a267aad83c1 (diff)
downloadnixpkgs-3aa8f9448cfdf24d6322b31805a969af5b9cfdcd.tar
nixpkgs-3aa8f9448cfdf24d6322b31805a969af5b9cfdcd.tar.gz
nixpkgs-3aa8f9448cfdf24d6322b31805a969af5b9cfdcd.tar.bz2
nixpkgs-3aa8f9448cfdf24d6322b31805a969af5b9cfdcd.tar.lz
nixpkgs-3aa8f9448cfdf24d6322b31805a969af5b9cfdcd.tar.xz
nixpkgs-3aa8f9448cfdf24d6322b31805a969af5b9cfdcd.tar.zst
nixpkgs-3aa8f9448cfdf24d6322b31805a969af5b9cfdcd.zip
zziplib: patch CVE-2018-17828
Fixes https://github.com/NixOS/nixpkgs/issues/61961
Close https://github.com/NixOS/nixpkgs/pull/63189
vcunat amended some nitpicks into the original commit.
Diffstat (limited to 'pkgs/development/libraries/zziplib')
-rw-r--r--pkgs/development/libraries/zziplib/default.nix9
1 files changed, 8 insertions, 1 deletions
diff --git a/pkgs/development/libraries/zziplib/default.nix b/pkgs/development/libraries/zziplib/default.nix
index 6aede4e9653..010c73336b9 100644
--- a/pkgs/development/libraries/zziplib/default.nix
+++ b/pkgs/development/libraries/zziplib/default.nix
@@ -1,4 +1,4 @@
-{ docbook_xml_dtd_412, fetchurl, stdenv, perl, python2, zip, xmlto, zlib }:
+{ docbook_xml_dtd_412, fetchurl, stdenv, perl, python2, zip, xmlto, zlib, fetchpatch }:
 
 stdenv.mkDerivation rec {
   name = "zziplib-${version}";
@@ -9,6 +9,13 @@ stdenv.mkDerivation rec {
     sha256 = "0i052a7shww0fzsxrdp3rd7g4mbzx7324a8ysbc0br7frpblcql4";
   };
 
+  patches = [
+    (fetchpatch {
+      name = "CVE-2018-17828.patch";
+      url = "https://github.com/gdraheim/zziplib/commit/f609ae8971f3c0ce6.diff";
+      sha256 = "0jhiz4fgr93wzh6q03avn95b2nsf6402jaki6hxirxyhs5v9ahry";
+    })
+  ];
   postPatch = ''
     sed -i -e s,--export-dynamic,, configure
   '';