about summary refs log tree commit diff
path: root/pkgs/development/libraries/avahi
diff options
context:
space:
mode:
authorArnout Engelen <arnout@bzzt.net>2023-11-26 16:05:00 +0100
committerArnout Engelen <arnout@bzzt.net>2023-11-26 16:10:09 +0100
commitf65b41f13dc33338d287d9d8637d63fd2ae6978b (patch)
tree7d73c8cf032b967c8dfa4e9b1ba4f6e76802680c /pkgs/development/libraries/avahi
parent38b85cb4449a90f66cee5339064a6a3fee709302 (diff)
avahi: apply patch for CVE-2023-38470
Diffstat (limited to 'pkgs/development/libraries/avahi')
-rw-r--r--pkgs/development/libraries/avahi/default.nix9
1 files changed, 8 insertions, 1 deletions
diff --git a/pkgs/development/libraries/avahi/default.nix b/pkgs/development/libraries/avahi/default.nix
index a51d104228ad3..ca742975e91b2 100644
--- a/pkgs/development/libraries/avahi/default.nix
+++ b/pkgs/development/libraries/avahi/default.nix
@@ -51,8 +51,15 @@ stdenv.mkDerivation rec {
       url = "https://github.com/lathiat/avahi/commit/a2696da2f2c50ac43b6c4903f72290d5c3fa9f6f.patch";
       sha256 = "sha256-BEYFGCnQngp+OpiKIY/oaKygX7isAnxJpUPCUvg+efc=";
     })
+    # CVE-2023-38470
+    # https://github.com/lathiat/avahi/pull/457 merged Sep 19
+    (fetchpatch {
+      name = "CVE-2023-38470.patch";
+      url = "https://github.com/lathiat/avahi/commit/94cb6489114636940ac683515417990b55b5d66c.patch";
+      sha256 = "sha256-Fanh9bvz+uknr5pAmltqijuUAZIG39JR2Lyq5zGKJ58=";
+    })
     # CVE-2023-38473
-    # https://github.com/lathiat/avahi/pull/486
+    # https://github.com/lathiat/avahi/pull/486 merged Oct 18
     (fetchpatch {
       name = "CVE-2023-38473.patch";
       url = "https://github.com/lathiat/avahi/commit/b448c9f771bada14ae8de175695a9729f8646797.patch";