tangled
alpha
login
or
join now
tjh.dev
/
nixpkgs
Clone of https://github.com/NixOS/nixpkgs.git (to stress-test knotserver)
0
fork
atom
overview
issues
pulls
pipelines
Merge branch 'staging-19.03' into release-19.03
Vladimír Čunát
6 years ago
47d7882b
d5a3e5f4
+14
2 changed files
expand all
collapse all
unified
split
pkgs
tools
compression
bzip2
cve-2019-12900.patch
default.nix
+13
pkgs/tools/compression/bzip2/cve-2019-12900.patch
···
1
1
+
https://gitlab.com/federicomenaquintero/bzip2/commit/74de1e2e6ffc9d
2
2
+
diff --git a/decompress.c b/decompress.c
3
3
+
--- a/decompress.c
4
4
+
+++ b/decompress.c
5
5
+
@@ -287,7 +287,7 @@
6
6
+
GET_BITS(BZ_X_SELECTOR_1, nGroups, 3);
7
7
+
if (nGroups < 2 || nGroups > 6) RETURN(BZ_DATA_ERROR);
8
8
+
GET_BITS(BZ_X_SELECTOR_2, nSelectors, 15);
9
9
+
- if (nSelectors < 1) RETURN(BZ_DATA_ERROR);
10
10
+
+ if (nSelectors < 1 || nSelectors > BZ_MAX_SELECTORS) RETURN(BZ_DATA_ERROR);
11
11
+
for (i = 0; i < nSelectors; i++) {
12
12
+
j = 0;
13
13
+
while (True) {
+1
pkgs/tools/compression/bzip2/default.nix
···
22
22
23
23
patches = [
24
24
./CVE-2016-3189.patch
25
25
+
./cve-2019-12900.patch
25
26
];
26
27
27
28