enhanced-ctorrent: fix CVE-2009-1759 (#39311)

Patches from Debian.

authored by Corbin Simpson and committed by Jörg Thalheim 69f23d9e 3aea9a4c

+14 -1
+14 -1
pkgs/applications/networking/enhanced-ctorrent/default.nix
··· 1 - { stdenv, fetchurl }: 1 + { stdenv, fetchurl, fetchpatch }: 2 2 3 3 stdenv.mkDerivation rec { 4 4 version = "dnh3.3.2"; 5 5 name = "enhanced-ctorrent"; 6 + 6 7 src = fetchurl { 7 8 url = "http://www.rahul.net/dholmes/ctorrent/ctorrent-dnh3.3.2.tar.gz"; 8 9 sha256 = "0qs8waqwllk56i3yy3zhncy7nsnhmf09a494p5siz4vm2k4ncwy8"; 9 10 }; 11 + 12 + # These patches come from Debian and fix CVE-2009-1759. 13 + patches = [ 14 + (fetchpatch { 15 + url = "https://sources.debian.org/data/main/c/ctorrent/1.3.4.dnh3.3.2-5/debian/patches/cve-security-fix.diff"; 16 + sha256 = "1qkzzm8sfspbcs10azmmif4qcr7pr8r38dsa2py84lsjm1yi3kls"; 17 + }) 18 + (fetchpatch { 19 + url = "https://sources.debian.org/data/main/c/ctorrent/1.3.4.dnh3.3.2-5/debian/patches/FTBFS-fix.diff"; 20 + sha256 = "1m3zh96xwqjjzsbg62f7kx0miams58nys1f484qhdn870b5x9p06"; 21 + }) 22 + ]; 10 23 11 24 meta = { 12 25 description = "BitTorrent client written in C++";