aboutsummaryrefslogtreecommitdiff
path: root/pkgs/development/libraries/cairo
diff options
context:
space:
mode:
authorworldofpeace <worldofpeace@users.noreply.github.com>2019-02-17 03:52:37 +0000
committerVladimír Čunát <vcunat@gmail.com>2019-02-17 08:25:53 +0100
commit21531d353b2b1ccd4ac5719db677b1baa7894600 (patch)
treee0e7fd3d8193247462cc373e70260f61423da725 /pkgs/development/libraries/cairo
parentf7f1a2f54ef2b744a26e37418dd6354bc46aa20a (diff)
Merge #55894: cairo: apply patch for CVE-2018-19876
(cherry picked from commit bad2db31b7b256e7b26f60e18dd2301cd277880c) Forward-picked from staging to staging-next; it's a trivial patch and we now rebuild anyway due to unzip.
Diffstat (limited to 'pkgs/development/libraries/cairo')
-rw-r--r--pkgs/development/libraries/cairo/default.nix15
1 files changed, 14 insertions, 1 deletions
diff --git a/pkgs/development/libraries/cairo/default.nix b/pkgs/development/libraries/cairo/default.nix
index 8f7a04cbb68f..f161e0f511a9 100644
--- a/pkgs/development/libraries/cairo/default.nix
+++ b/pkgs/development/libraries/cairo/default.nix
@@ -1,4 +1,4 @@
-{ stdenv, fetchurl, pkgconfig, libiconv
+{ stdenv, fetchurl, fetchpatch, pkgconfig, libiconv
, libintl, expat, zlib, libpng, pixman, fontconfig, freetype, xorg
, gobjectSupport ? true, glib
, xcbSupport ? true # no longer experimental since 1.12
@@ -20,6 +20,19 @@ in stdenv.mkDerivation rec {
sha256 = "0c930mk5xr2bshbdljv005j3j8zr47gqmkry3q6qgvqky6rjjysy";
};
+ patches = [
+ # Fixes CVE-2018-19876; see Nixpkgs issue #55384
+ # CVE information: https://nvd.nist.gov/vuln/detail/CVE-2018-19876
+ # Upstream PR: https://gitlab.freedesktop.org/cairo/cairo/merge_requests/5
+ #
+ # This patch is the merged commit from the above PR.
+ (fetchpatch {
+ name = "CVE-2018-19876.patch";
+ url = "https://gitlab.freedesktop.org/cairo/cairo/commit/6edf572ebb27b00d3c371ba5ae267e39d27d5b6d.patch";
+ sha256 = "112hgrrsmcwxh1r52brhi5lksq4pvrz4xhkzcf2iqp55jl2pb7n1";
+ })
+ ];
+
outputs = [ "out" "dev" "devdoc" ];
outputBin = "dev"; # very small