nixpkgs/pkgs
aszlig 9e476fe740
synergy: Add patch to fix CVE-2020-15117
From the description of CVE-2020-15117:

> In Synergy before version 1.12.0, a Synergy server can be crashed by
> receiving a kMsgHelloBack packet with a client name length set to
> 0xffffffff (4294967295) if the servers memory is less than 4 GB. It
> was verified that this issue does not cause a crash through the
> exception handler if the available memory of the Server is more than
> 4GB.

While I personally would consider this a pretty low-priority issue since
Synergy usually is only used in local environment, it's nevertheless
better to patch known issues.

Since the fix is part of version 1.12, which doesn't have a stable
release yet, I'm including the fix as a patch cherry-picked from the
upstream commit.

I originally had the CVE number as a comment prior to the fetchpatch
call in question, but since @mweinelt mentioned that https://broken.sh/
uses the patch file name[1] to match whether the software in question
has been patched, I've removed my initial comment as it would be
redundant.

[1]: https://github.com/andir/nix-vulnerability-scanner/blob/fb63998885462/src/report/nix_patches.rs#L83-L95

Signed-off-by: aszlig <aszlig@nix.build>
Fixes: https://github.com/NixOS/nixpkgs/issues/94007
2020-08-04 16:35:18 +02:00
..
applications synergy: Add patch to fix CVE-2020-15117 2020-08-04 16:35:18 +02:00
build-support Merge branch 'staging-next' 2020-07-25 16:18:40 +02:00
common-updater
data all-cabal-hashes: update to Hackage at 2020-07-24T00:16:27Z 2020-07-24 21:38:22 +02:00
desktops Merge pull request #93851 from dawidsowa/atril 2020-07-26 23:42:50 -03:00
development Unmaintain packages I don't use anymore 2020-07-28 02:08:36 +02:00
games minecraft: 2.1.15852 -> 2.1.16102 2020-07-26 22:35:02 +02:00
misc snes9x-gtk: use wrapGAppsHook 2020-07-27 11:59:54 +02:00
os-specific linux_latest-libre: 17570 -> 17583 2020-07-27 08:54:52 -04:00
servers Merge pull request #93807 from r-ryantm/auto-update/metabase 2020-07-27 00:31:30 +02:00
shells Merge pull request #93585 from adrian-gierakowski/fix-dash-on-darwin 2020-07-27 22:02:41 +02:00
stdenv
test
tools Merge pull request #93965 from jojosch/mycli-1.22.1 2020-07-28 01:50:46 +02:00
top-level Merge pull request #93774 from Ma27/riot-removal 2020-07-28 00:54:58 +02:00