summary refs log tree commit diff
path: root/pkgs/servers/sip
diff options
context:
space:
mode:
authorThomas Gerbet <thomas@gerbet.me>2021-01-20 23:24:04 +0100
committerThomas Gerbet <thomas@gerbet.me>2021-01-22 11:58:00 +0100
commitfdafac8b00c859cdaeaefcfe453aec68b62bd79b (patch)
tree578fdce883b7e5ff3f9be4a820e09d1300752106 /pkgs/servers/sip
parent59863dc3d7d549e853d9cfe705fe0ea975284eaa (diff)
downloadnixpkgs-fdafac8b00c859cdaeaefcfe453aec68b62bd79b.tar
nixpkgs-fdafac8b00c859cdaeaefcfe453aec68b62bd79b.tar.gz
nixpkgs-fdafac8b00c859cdaeaefcfe453aec68b62bd79b.tar.bz2
nixpkgs-fdafac8b00c859cdaeaefcfe453aec68b62bd79b.tar.lz
nixpkgs-fdafac8b00c859cdaeaefcfe453aec68b62bd79b.tar.xz
nixpkgs-fdafac8b00c859cdaeaefcfe453aec68b62bd79b.tar.zst
nixpkgs-fdafac8b00c859cdaeaefcfe453aec68b62bd79b.zip
libexosip: 4.1.0 -> 5.2.0
Fix CVE-2014-10375.

sipwitch is marked as broken as it does compile with libexosip > 5.0.0
and the upstream project appears to be stalled/abandoned.
Diffstat (limited to 'pkgs/servers/sip')
-rw-r--r--pkgs/servers/sip/sipwitch/default.nix1
1 files changed, 1 insertions, 0 deletions
diff --git a/pkgs/servers/sip/sipwitch/default.nix b/pkgs/servers/sip/sipwitch/default.nix
index 3e69602170f..f5b3288c60c 100644
--- a/pkgs/servers/sip/sipwitch/default.nix
+++ b/pkgs/servers/sip/sipwitch/default.nix
@@ -23,5 +23,6 @@ stdenv.mkDerivation rec {
     license = lib.licenses.gpl3Plus;
     maintainers = with lib.maintainers; [ ];
     platforms = with lib.platforms; linux;
+    broken = true; # Require libexosip2 < 5.0.0 which is vulnerable to CVE-2014-10375.
   };
 }