about summary refs log tree commit diff
diff options
context:
space:
mode:
authorMarek Mahut <marek.mahut@satoshilabs.com>2019-07-16 16:14:35 +0200
committerMarek Mahut <marek.mahut@satoshilabs.com>2019-07-16 22:35:36 +0200
commit38ec5055494ec88883e0033b7078ae6d45ced85a (patch)
treea41a0c0e97639ce98e4391103c68a8c784e3e0c3
parent00ef72610c82dd0ea69f2bc3f70445483acca0d0 (diff)
downloadnixlib-38ec5055494ec88883e0033b7078ae6d45ced85a.tar
nixlib-38ec5055494ec88883e0033b7078ae6d45ced85a.tar.gz
nixlib-38ec5055494ec88883e0033b7078ae6d45ced85a.tar.bz2
nixlib-38ec5055494ec88883e0033b7078ae6d45ced85a.tar.lz
nixlib-38ec5055494ec88883e0033b7078ae6d45ced85a.tar.xz
nixlib-38ec5055494ec88883e0033b7078ae6d45ced85a.tar.zst
nixlib-38ec5055494ec88883e0033b7078ae6d45ced85a.zip
libosinfo: CVE-2019-13313
Fixes #64660
-rw-r--r--pkgs/development/libraries/libosinfo/default.nix13
1 files changed, 12 insertions, 1 deletions
diff --git a/pkgs/development/libraries/libosinfo/default.nix b/pkgs/development/libraries/libosinfo/default.nix
index 04f0db030bb0..b971c8924f36 100644
--- a/pkgs/development/libraries/libosinfo/default.nix
+++ b/pkgs/development/libraries/libosinfo/default.nix
@@ -1,4 +1,4 @@
-{ stdenv, fetchurl, pkgconfig, intltool, gobject-introspection, gtk-doc, docbook_xsl
+{ stdenv, fetchurl, fetchpatch, pkgconfig, intltool, gobject-introspection, gtk-doc, docbook_xsl
 , glib, libsoup, libxml2, libxslt, check, curl, perl, hwdata, osinfo-db, vala ? null
 }:
 
@@ -21,6 +21,17 @@ stdenv.mkDerivation rec {
 
   patches = [
     ./osinfo-db-data-dir.patch
+    # https://nvd.nist.gov/vuln/detail/CVE-2019-13313
+    (fetchpatch {
+      url = "https://gitlab.com/libosinfo/libosinfo/commit/3654abee6ead9f11f8bb9ba8fc71efd6fa4dabbc.patch";
+      name = "CVE-2019-13313-1.patch";
+      sha256 = "1lybywfj6b41zfjk33ap90bab5l84lf5y3kif7vd2b6wq5r91rcn";
+    })
+    (fetchpatch {
+      url = "https://gitlab.com/libosinfo/libosinfo/commit/08fb8316b4ac42fe74c1fa5ca0ac593222cdf81a.patch";
+      name = "CVE-2019-13313-2.patch";
+      sha256 = "1f6rhkrgy3j8nmidk97wnz6p35zs1dsd63d3np76q7qs7ra74w9z";
+    })
   ];
 
   postPatch = ''