From e5dd29c8f4298d5efe9f8b8698b82e2c56892e62 Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" <41898282+github-actions[bot]@users.noreply.github.com> Date: Wed, 22 May 2024 13:32:52 +0000 Subject: tinyproxy: 1.11.1 -> 1.11.2 (#313675) Fixes CVE-2023-49606 and CVE-2023-40533. https://github.com/tinyproxy/tinyproxy/releases/tag/1.11.2 Reporter advisories: https://talosintelligence.com/vulnerability_reports/TALOS-2023-1889 https://talosintelligence.com/vulnerability_reports/TALOS-2023-1902 (cherry picked from commit bcd0c6a3ca932310ba35ecacc14d9c56b803ff3f) Co-authored-by: Thomas Gerbet --- pkgs/tools/networking/tinyproxy/default.nix | 13 ++----------- 1 file changed, 2 insertions(+), 11 deletions(-) diff --git a/pkgs/tools/networking/tinyproxy/default.nix b/pkgs/tools/networking/tinyproxy/default.nix index 8778b90b2b026..03def9023b15a 100644 --- a/pkgs/tools/networking/tinyproxy/default.nix +++ b/pkgs/tools/networking/tinyproxy/default.nix @@ -1,7 +1,6 @@ { lib , stdenv , fetchFromGitHub -, fetchpatch , autoreconfHook , perl , nixosTests @@ -10,23 +9,15 @@ stdenv.mkDerivation rec { pname = "tinyproxy"; - version = "1.11.1"; + version = "1.11.2"; src = fetchFromGitHub { - sha256 = "sha256-tipFXh9VG5auWTI2/IC5rwMQFls7aZr6dkzhYTZZkXM="; + hash = "sha256-bpr/O723FmW2gb+85aJrwW5/U7R2HwbePTx15i3rpsE="; rev = version; repo = "tinyproxy"; owner = "tinyproxy"; }; - patches = [ - (fetchpatch { - name = "CVE-2022-40468.patch"; - url = "https://github.com/tinyproxy/tinyproxy/commit/3764b8551463b900b5b4e3ec0cd9bb9182191cb7.patch"; - sha256 = "sha256-P0c4mUK227ld3703ss5MQhi8Vo2QVTCVXhKmc9fcufk="; - }) - ]; - # perl is needed for man page generation. nativeBuildInputs = [ autoreconfHook perl ]; -- cgit 1.4.1