[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
01/01: gnu: unzip: Mitigate CVE-2018-1000035.
From: |
Leo Famulari |
Subject: |
01/01: gnu: unzip: Mitigate CVE-2018-1000035. |
Date: |
Tue, 13 Feb 2018 09:51:17 -0500 (EST) |
lfam pushed a commit to branch master
in repository guix.
commit 77737e035491112a1e9c7d9a0e6f1e0397a4f930
Author: Leo Famulari <address@hidden>
Date: Mon Feb 12 13:49:49 2018 -0500
gnu: unzip: Mitigate CVE-2018-1000035.
* gnu/packages/compression.scm (unzip)[replacement]: New field.
(unzip/fixed): New variable.
---
gnu/packages/compression.scm | 17 ++++++++++++++++-
1 file changed, 16 insertions(+), 1 deletion(-)
diff --git a/gnu/packages/compression.scm b/gnu/packages/compression.scm
index 3a0e279..9983ee1 100644
--- a/gnu/packages/compression.scm
+++ b/gnu/packages/compression.scm
@@ -5,7 +5,7 @@
;;; Copyright © 2015 Taylan Ulrich Bayırlı/Kammer <address@hidden>
;;; Copyright © 2015, 2016 Eric Bavier <address@hidden>
;;; Copyright © 2015, 2016, 2017 Ricardo Wurmus <address@hidden>
-;;; Copyright © 2015, 2017 Leo Famulari <address@hidden>
+;;; Copyright © 2015, 2017, 2018 Leo Famulari <address@hidden>
;;; Copyright © 2015 Jeff Mickey <address@hidden>
;;; Copyright © 2015, 2016, 2017 Efraim Flashner <address@hidden>
;;; Copyright © 2016 Ben Woodcroft <address@hidden>
@@ -1719,6 +1719,7 @@ Compression ratios of 2:1 to 3:1 are common for text
files.")
(define-public unzip
(package (inherit zip)
(name "unzip")
+ (replacement unzip/fixed)
(version "6.0")
(source
(origin
@@ -1769,6 +1770,20 @@ recreates the stored directory structure by default.")
(license (license:non-copyleft "file://LICENSE"
"See LICENSE in the distribution."))))
+(define unzip/fixed
+ (package/inherit unzip
+ (arguments
+ (substitute-keyword-arguments (package-arguments unzip)
+ ((#:phases phases)
+ `(modify-phases ,phases
+ (add-after 'unpack 'fortify
+ (lambda _
+ ;; Mitigate CVE-2018-1000035, an exploitable buffer overflow.
+ ;; This environment variable is recommended in 'unix/Makefile'
+ ;; for passing flags to the C compiler.
+ (setenv "LOCAL_UNZIP" "-D_FORTIFY_SOURCE=1")
+ #t))))))))
+
(define-public zziplib
(package
(name "zziplib")