···19 # remaps /etc/passwd to a trivial file, but we can't do that on Darwin so I do this
20 # instead. In this case, I pass in the very imaginative "submitter" as the submitter name
2122- patchPhase = let
0000000023 # This evaluates to a string containing:
24 #
25 # substituteInPlace tests/shar-2 --replace '${SHAR}' '${SHAR} -s submitter'
···19 # remaps /etc/passwd to a trivial file, but we can't do that on Darwin so I do this
20 # instead. In this case, I pass in the very imaginative "submitter" as the submitter name
2122+ patches = [
23+ # CVE-2018-1000097
24+ (fetchurl {
25+ url = "https://sources.debian.org/data/main/s/sharutils/1:4.15.2-2+deb9u1/debian/patches/01-fix-heap-buffer-overflow-cve-2018-1000097.patch";
26+ sha256 = "19g0sxc8g79aj5gd5idz5409311253jf2q8wqkasf0handdvsbxx";
27+ })
28+ ];
29+30+ postPatch = let
31 # This evaluates to a string containing:
32 #
33 # substituteInPlace tests/shar-2 --replace '${SHAR}' '${SHAR} -s submitter'