From 68fe9dfc71ea99d125f8c62d581f816a5bdbfa5f Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Vladim=C3=ADr=20=C4=8Cun=C3=A1t?= Date: Wed, 30 Nov 2016 14:34:36 +0100 Subject: [PATCH] vim*: apply upstream patch to fix CVE-2016-1248 /cc #20814. Our version in master was past the last vulnerable one. --- pkgs/applications/editors/vim/common.nix | 10 +++++++++- 1 file changed, 9 insertions(+), 1 deletion(-) diff --git a/pkgs/applications/editors/vim/common.nix b/pkgs/applications/editors/vim/common.nix index a028555b25e3..dd1a4f4de90d 100644 --- a/pkgs/applications/editors/vim/common.nix +++ b/pkgs/applications/editors/vim/common.nix @@ -1,4 +1,4 @@ -{ lib, fetchFromGitHub }: +{ lib, fetchFromGitHub, fetchpatch }: rec { version = "7.4.2367"; @@ -18,6 +18,14 @@ rec { '' substituteInPlace runtime/ftplugin/man.vim \ --replace "/usr/bin/man " "man " + + patch -p1 < '${ + fetchpatch { + name = "cve-2016-1248.diff"; + url = "https://github.com/vim/vim/commit/d0b5138b.diff"; + sha256 = "057kg95ipjdirbkr082wbwrbz5l79mwxir8ymkxhma6l6wbxidif"; + } + }' ''; meta = with lib; {