summary refs log tree commit diff
path: root/pkgs
diff options
context:
space:
mode:
authorRobert Scott <code@humanleg.org.uk>2021-07-25 14:23:36 +0100
committerRobert Scott <code@humanleg.org.uk>2021-07-25 14:23:36 +0100
commitb50d7d0683d61bf00a101ce7b67c7b0f065d7ff6 (patch)
treebf4d52c78073e202a7cf2e593e3c31c3b09ee303 /pkgs
parent4d62c8942fb1598dd0593e55f9c4c1a6119aae76 (diff)
downloadnixpkgs-b50d7d0683d61bf00a101ce7b67c7b0f065d7ff6.tar
nixpkgs-b50d7d0683d61bf00a101ce7b67c7b0f065d7ff6.tar.gz
nixpkgs-b50d7d0683d61bf00a101ce7b67c7b0f065d7ff6.tar.bz2
nixpkgs-b50d7d0683d61bf00a101ce7b67c7b0f065d7ff6.tar.lz
nixpkgs-b50d7d0683d61bf00a101ce7b67c7b0f065d7ff6.tar.xz
nixpkgs-b50d7d0683d61bf00a101ce7b67c7b0f065d7ff6.tar.zst
nixpkgs-b50d7d0683d61bf00a101ce7b67c7b0f065d7ff6.zip
libgrss: add patch for CVE-2016-20011
Diffstat (limited to 'pkgs')
-rw-r--r--pkgs/development/libraries/libgrss/default.nix11
1 files changed, 10 insertions, 1 deletions
diff --git a/pkgs/development/libraries/libgrss/default.nix b/pkgs/development/libraries/libgrss/default.nix
index 8c5ea73af0b..5e1c2b17858 100644
--- a/pkgs/development/libraries/libgrss/default.nix
+++ b/pkgs/development/libraries/libgrss/default.nix
@@ -1,4 +1,4 @@
-{ lib, stdenv, fetchurl, pkg-config, vala, gobject-introspection, gtk-doc, docbook_xsl, docbook_xml_dtd_412, glib, libxml2, libsoup, gnome }:
+{ lib, stdenv, fetchurl, fetchpatch, pkg-config, vala, gobject-introspection, gtk-doc, docbook_xsl, docbook_xml_dtd_412, glib, libxml2, libsoup, gnome }:
 
 let
   version = "0.7.0";
@@ -14,6 +14,15 @@ stdenv.mkDerivation {
     sha256 = "1nalslgyglvhpva3px06fj6lv5zgfg0qmj0sbxyyl5d963vc02b7";
   };
 
+  patches = [
+    (fetchpatch {
+      name = "CVE-2016-20011.patch";
+      # https://gitlab.gnome.org/GNOME/libgrss/-/merge_requests/7, not yet merged!
+      url = "https://gitlab.gnome.org/GNOME/libgrss/-/commit/2c6ea642663e2a44efc8583fae7c54b7b98f72b3.patch";
+      sha256 = "1ijvq2jl97vphcvrbrqxvszdmv6yyjfygdca9vyaijpafwyzzb18";
+    })
+  ];
+
   nativeBuildInputs = [ pkg-config vala gobject-introspection gtk-doc docbook_xsl docbook_xml_dtd_412 ];
   buildInputs = [ glib libxml2 libsoup ];