summary refs log tree commit diff
path: root/pkgs
diff options
context:
space:
mode:
authorWout Mertens <Wout.Mertens@gmail.com>2014-06-30 16:10:50 +0200
committerWout Mertens <Wout.Mertens@gmail.com>2014-06-30 16:10:50 +0200
commit8e7fded9c963ba00b49188b6e5c13a90936530df (patch)
tree2e1f2a88446071054e49b7acd0968bfa1442969f /pkgs
parentea4207f7a35dd350ae122344665d1a858e581e32 (diff)
downloadnixlib-8e7fded9c963ba00b49188b6e5c13a90936530df.tar
nixlib-8e7fded9c963ba00b49188b6e5c13a90936530df.tar.gz
nixlib-8e7fded9c963ba00b49188b6e5c13a90936530df.tar.bz2
nixlib-8e7fded9c963ba00b49188b6e5c13a90936530df.tar.lz
nixlib-8e7fded9c963ba00b49188b6e5c13a90936530df.tar.xz
nixlib-8e7fded9c963ba00b49188b6e5c13a90936530df.tar.zst
nixlib-8e7fded9c963ba00b49188b6e5c13a90936530df.zip
vte: store patch in repo, source offline
Diffstat (limited to 'pkgs')
-rw-r--r--pkgs/desktops/gnome-2/desktop/vte/default.nix7
-rw-r--r--pkgs/desktops/gnome-2/desktop/vte/vte-0.28.2-limit-arguments.patch40
2 files changed, 42 insertions, 5 deletions
diff --git a/pkgs/desktops/gnome-2/desktop/vte/default.nix b/pkgs/desktops/gnome-2/desktop/vte/default.nix
index aca30f87dfc4..30c8bf07d418 100644
--- a/pkgs/desktops/gnome-2/desktop/vte/default.nix
+++ b/pkgs/desktops/gnome-2/desktop/vte/default.nix
@@ -11,11 +11,8 @@ stdenv.mkDerivation rec {
 
   patches = [
     ./alt.patch
-    ( fetchurl { # CVE-2012-2738
-      url = "http://sources.gentoo.org/cgi-bin/viewvc.cgi/gentoo-x86/x11-libs/"
-        + "vte/files/vte-0.28.2-limit-arguments.patch?revision=1.1";
-      sha256 = "1s8agx74wa7wlv9ybd5h3dp4hzf4ddg7piyan37g2ab3fnvg4jhn";
-    } )
+    # CVE-2012-2738
+    ./vte-0.28.2-limit-arguments.patch
   ];
 
   buildInputs = [ intltool pkgconfig glib gtk ncurses ] ++
diff --git a/pkgs/desktops/gnome-2/desktop/vte/vte-0.28.2-limit-arguments.patch b/pkgs/desktops/gnome-2/desktop/vte/vte-0.28.2-limit-arguments.patch
new file mode 100644
index 000000000000..fd454079390f
--- /dev/null
+++ b/pkgs/desktops/gnome-2/desktop/vte/vte-0.28.2-limit-arguments.patch
@@ -0,0 +1,40 @@
+From feeee4b5832b17641e505b7083e0d299fdae318e Mon Sep 17 00:00:00 2001
+From: Christian Persch <chpe@gnome.org>
+Date: Sat, 19 May 2012 17:36:09 +0000
+Subject: emulation: Limit integer arguments to 65535
+
+To guard against malicious sequences containing excessively big numbers,
+limit all parsed numbers to 16 bit range. Doing this here in the parsing
+routine is a catch-all guard; this doesn't preclude enforcing
+more stringent limits in the handlers themselves.
+
+https://bugzilla.gnome.org/show_bug.cgi?id=676090
+---
+diff --git a/src/table.c b/src/table.c
+index 140e8c8..85cf631 100644
+--- a/src/table.c
++++ b/src/table.c
+@@ -550,7 +550,7 @@ _vte_table_extract_numbers(GValueArray **array,
+ 		if (G_UNLIKELY (*array == NULL)) {
+ 			*array = g_value_array_new(1);
+ 		}
+-		g_value_set_long(&value, total);
++		g_value_set_long(&value, CLAMP (total, 0, G_MAXUSHORT));
+ 		g_value_array_append(*array, &value);
+ 	} while (i++ < arginfo->length);
+ 	g_value_unset(&value);
+diff --git a/src/vteseq.c b/src/vteseq.c
+index 457c06a..46def5b 100644
+--- a/src/vteseq.c
++++ b/src/vteseq.c
+@@ -557,7 +557,7 @@ vte_sequence_handler_multiple(VteTerminal *terminal,
+                               GValueArray *params,
+                               VteTerminalSequenceHandler handler)
+ {
+-        vte_sequence_handler_multiple_limited(terminal, params, handler, G_MAXLONG);
++        vte_sequence_handler_multiple_limited(terminal, params, handler, G_MAXUSHORT);
+ }
+ 
+ static void
+--
+cgit v0.9.0.2