about summary refs log tree commit diff
path: root/pkgs/development/interpreters/python
diff options
context:
space:
mode:
authorFranz Pletz <fpletz@fnordicwalking.de>2018-11-02 02:09:41 +0100
committerFrederik Rietdijk <fridh@fridh.nl>2018-11-11 09:00:31 +0100
commitae3e9b5a27e61a5590d1dd4e1fd402b061550b4e (patch)
tree80d1705cad9afe7f9f459a46631bec66495b55c8 /pkgs/development/interpreters/python
parent7863aae5b2eeb8c7af241a0f0ee0c5a15a8fabc8 (diff)
downloadnixlib-ae3e9b5a27e61a5590d1dd4e1fd402b061550b4e.tar
nixlib-ae3e9b5a27e61a5590d1dd4e1fd402b061550b4e.tar.gz
nixlib-ae3e9b5a27e61a5590d1dd4e1fd402b061550b4e.tar.bz2
nixlib-ae3e9b5a27e61a5590d1dd4e1fd402b061550b4e.tar.lz
nixlib-ae3e9b5a27e61a5590d1dd4e1fd402b061550b4e.tar.xz
nixlib-ae3e9b5a27e61a5590d1dd4e1fd402b061550b4e.tar.zst
nixlib-ae3e9b5a27e61a5590d1dd4e1fd402b061550b4e.zip
python27: add patch to fix CVE-2018-1000802
Diffstat (limited to 'pkgs/development/interpreters/python')
-rw-r--r--pkgs/development/interpreters/python/cpython/2.7/default.nix6
1 files changed, 6 insertions, 0 deletions
diff --git a/pkgs/development/interpreters/python/cpython/2.7/default.nix b/pkgs/development/interpreters/python/cpython/2.7/default.nix
index 2609c053d95b..00a1cfc5bd0e 100644
--- a/pkgs/development/interpreters/python/cpython/2.7/default.nix
+++ b/pkgs/development/interpreters/python/cpython/2.7/default.nix
@@ -74,6 +74,12 @@ let
         url = "file://${./type_getattro.patch}";
         sha256 = "11v9yx20hs3jmw0wggzvmw39qs4mxay4kb8iq2qjydwy9ya61nrd";
       })
+
+      (fetchpatch {
+        name = "CVE-2018-1000802.patch";
+        url = "https://github.com/python/cpython/pull/8985.patch";
+        sha256 = "1c8nq2c9sjqa8ipl62hiandg6a7lzrwwfhi3ky6jd3pxgyalrh97";
+      })
     ] ++ optionals (x11Support && stdenv.isDarwin) [
       ./use-correct-tcl-tk-on-darwin.patch
     ] ++ optionals stdenv.isLinux [