about summary refs log tree commit diff
diff options
context:
space:
mode:
authorMarek Mahut <marek.mahut@gmail.com>2019-08-25 19:16:38 +0200
committerMarek Mahut <marek.mahut@gmail.com>2019-08-25 19:16:38 +0200
commit302cac35f586d0cc4813ae0cf5d124f1375deecf (patch)
treeb32838a415a94286cc975c206ebd21503a676179
parentcceab5257fc3bca0113b042d7913a408bd5514ac (diff)
downloadnixlib-302cac35f586d0cc4813ae0cf5d124f1375deecf.tar
nixlib-302cac35f586d0cc4813ae0cf5d124f1375deecf.tar.gz
nixlib-302cac35f586d0cc4813ae0cf5d124f1375deecf.tar.bz2
nixlib-302cac35f586d0cc4813ae0cf5d124f1375deecf.tar.lz
nixlib-302cac35f586d0cc4813ae0cf5d124f1375deecf.tar.xz
nixlib-302cac35f586d0cc4813ae0cf5d124f1375deecf.tar.zst
nixlib-302cac35f586d0cc4813ae0cf5d124f1375deecf.zip
python2: CVE-2018-20852
Fixes #67200
-rw-r--r--pkgs/development/interpreters/python/cpython/2.7/default.nix6
1 files changed, 6 insertions, 0 deletions
diff --git a/pkgs/development/interpreters/python/cpython/2.7/default.nix b/pkgs/development/interpreters/python/cpython/2.7/default.nix
index de980f1ca687..4e323898afbf 100644
--- a/pkgs/development/interpreters/python/cpython/2.7/default.nix
+++ b/pkgs/development/interpreters/python/cpython/2.7/default.nix
@@ -79,6 +79,12 @@ let
         sha256 = "0l9rw6r5r90iybdkp3hhl2pf0h0s1izc68h5d3ywrm92pq32wz57";
       })
 
+      (fetchpatch {
+        url = "https://github.com/python/cpython/commit/979daae300916adb399ab5b51410b6ebd0888f13.patch";
+        name = "CVE-2018-20852.patch";
+        sha256 = "0p838ycssd6abxzby69rhngjqqm59cmlp07910mpjx7lmsz049pb";
+      })
+
       # Fix race-condition during pyc creation. Has a slight backwards
       # incompatible effect: pyc symlinks will now be overridden
       # (https://bugs.python.org/issue17222). Included in python >= 3.4,