summary refs log tree commit diff
path: root/pkgs/tools/graphics/netpbm
diff options
context:
space:
mode:
authorVladimír Čunát <vcunat@gmail.com>2013-12-25 11:08:19 +0100
committerVladimír Čunát <vcunat@gmail.com>2013-12-25 11:11:59 +0100
commit15a5894ab3ed1e8ebafb72dc903052b091b6155f (patch)
treec529b5078f7be8397be2d29fbb999bf6558bbe87 /pkgs/tools/graphics/netpbm
parentc744a7e106aba084a56deb28db96ae644ae4736a (diff)
downloadnixpkgs-15a5894ab3ed1e8ebafb72dc903052b091b6155f.tar
nixpkgs-15a5894ab3ed1e8ebafb72dc903052b091b6155f.tar.gz
nixpkgs-15a5894ab3ed1e8ebafb72dc903052b091b6155f.tar.bz2
nixpkgs-15a5894ab3ed1e8ebafb72dc903052b091b6155f.tar.lz
nixpkgs-15a5894ab3ed1e8ebafb72dc903052b091b6155f.tar.xz
nixpkgs-15a5894ab3ed1e8ebafb72dc903052b091b6155f.tar.zst
nixpkgs-15a5894ab3ed1e8ebafb72dc903052b091b6155f.zip
netpbm: fix CVE-2005-2471
Diffstat (limited to 'pkgs/tools/graphics/netpbm')
-rw-r--r--pkgs/tools/graphics/netpbm/default.nix5
1 files changed, 5 insertions, 0 deletions
diff --git a/pkgs/tools/graphics/netpbm/default.nix b/pkgs/tools/graphics/netpbm/default.nix
index dc16f4887d9..2e3274ca0ff 100644
--- a/pkgs/tools/graphics/netpbm/default.nix
+++ b/pkgs/tools/graphics/netpbm/default.nix
@@ -10,6 +10,11 @@ stdenv.mkDerivation {
     sha256 = "0csx6g0ci66nx1a6z0a9dkpfp66mdvcpp5r7g6zrx4jp18r9hzb2";
   };
 
+  postPatch = /* CVE-2005-2471, from Arch */ ''
+    substituteInPlace converter/other/pstopnm.c \
+      --replace '"-DSAFER"' '"-DPARANOIDSAFER"'
+  '';
+
   NIX_CFLAGS_COMPILE = "-fPIC"; # Gentoo adds this on every platform
 
   buildInputs = [ pkgconfig flex zlib perl libpng libjpeg libxml2 makeWrapper libX11 libtiff ];