From db8434a6945561fc94284f1e8fc5c2baac298f9b Mon Sep 17 00:00:00 2001 From: Robert Scott Date: Sun, 9 Feb 2020 17:43:32 +0000 Subject: [PATCH] libexif: add patch for CVE-2019-9278 no upstream release with this yet --- pkgs/development/libraries/libexif/default.nix | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/pkgs/development/libraries/libexif/default.nix b/pkgs/development/libraries/libexif/default.nix index 833ccf5dca5d..cd35dc4c1db6 100644 --- a/pkgs/development/libraries/libexif/default.nix +++ b/pkgs/development/libraries/libexif/default.nix @@ -25,6 +25,11 @@ stdenv.mkDerivation rec { sha256 = "01aqvz63glwq6wg0wr7ykqqghb4abgq77ghvhizbzadg1k4h7drx"; excludes = [ "NEWS" ]; }) + (fetchpatch { + name = "CVE-2019-9278.patch"; + url = "https://github.com/libexif/libexif/commit/75aa73267fdb1e0ebfbc00369e7312bac43d0566.patch"; + sha256 = "10ikg33mips5zq9as7l9xqnyzbg1wwr4sw17517nzf4hafjpasrj"; + }) ]; buildInputs = [ gettext ];