diff options
author | Pascal Wittmann <mail@pascal-wittmann.de> | 2015-06-08 13:55:20 +0200 |
---|---|---|
committer | Pascal Wittmann <mail@pascal-wittmann.de> | 2015-06-08 13:56:42 +0200 |
commit | c46889ea4227418fb31a0562626ffcab20d90890 (patch) | |
tree | 35a7ac6b1e9cc2667e7c5da78e4f9f6ee177dc18 /pkgs | |
parent | cc96e474d3d21969b999865c817a41c44aab3dc3 (diff) |
ipsec-tools: apply debians patch to fix CVE-2015-4047
Diffstat (limited to 'pkgs')
-rw-r--r-- | pkgs/os-specific/linux/ipsec-tools/CVE-2015-4047.patch | 16 | ||||
-rw-r--r-- | pkgs/os-specific/linux/ipsec-tools/default.nix | 3 |
2 files changed, 18 insertions, 1 deletions
diff --git a/pkgs/os-specific/linux/ipsec-tools/CVE-2015-4047.patch b/pkgs/os-specific/linux/ipsec-tools/CVE-2015-4047.patch new file mode 100644 index 0000000000000..00c23c6cac14c --- /dev/null +++ b/pkgs/os-specific/linux/ipsec-tools/CVE-2015-4047.patch @@ -0,0 +1,16 @@ +Index: pkg-ipsec-tools/src/racoon/gssapi.c +=================================================================== +--- pkg-ipsec-tools.orig/src/racoon/gssapi.c ++++ pkg-ipsec-tools/src/racoon/gssapi.c +@@ -192,6 +192,11 @@ gssapi_init(struct ph1handle *iph1) + gss_name_t princ, canon_princ; + OM_uint32 maj_stat, min_stat; + ++ if (iph1->rmconf == NULL) { ++ plog(LLV_ERROR, LOCATION, NULL, "no remote config\n"); ++ return -1; ++ } ++ + gps = racoon_calloc(1, sizeof (struct gssapi_ph1_state)); + if (gps == NULL) { + plog(LLV_ERROR, LOCATION, NULL, "racoon_calloc failed\n"); diff --git a/pkgs/os-specific/linux/ipsec-tools/default.nix b/pkgs/os-specific/linux/ipsec-tools/default.nix index a6042b1e33b8a..fc3b0500fed90 100644 --- a/pkgs/os-specific/linux/ipsec-tools/default.nix +++ b/pkgs/os-specific/linux/ipsec-tools/default.nix @@ -16,7 +16,8 @@ stdenv.mkDerivation rec { buildInputs = [ readline openssl flex kerberos pam ]; - patches = [ ./dont-create-localstatedir-during-install.patch ]; + patches = [ ./dont-create-localstatedir-during-install.patch + ./CVE-2015-4047.patch ]; # fix build with newer gcc versions preConfigure = ''substituteInPlace configure --replace "-Werror" "" ''; |