nixpkgs/pkgs/applications
aszlig 9e476fe740
synergy: Add patch to fix CVE-2020-15117
From the description of CVE-2020-15117:

> In Synergy before version 1.12.0, a Synergy server can be crashed by
> receiving a kMsgHelloBack packet with a client name length set to
> 0xffffffff (4294967295) if the servers memory is less than 4 GB. It
> was verified that this issue does not cause a crash through the
> exception handler if the available memory of the Server is more than
> 4GB.

While I personally would consider this a pretty low-priority issue since
Synergy usually is only used in local environment, it's nevertheless
better to patch known issues.

Since the fix is part of version 1.12, which doesn't have a stable
release yet, I'm including the fix as a patch cherry-picked from the
upstream commit.

I originally had the CVE number as a comment prior to the fetchpatch
call in question, but since @mweinelt mentioned that https://broken.sh/
uses the patch file name[1] to match whether the software in question
has been patched, I've removed my initial comment as it would be
redundant.

[1]: https://github.com/andir/nix-vulnerability-scanner/blob/fb63998885462/src/report/nix_patches.rs#L83-L95

Signed-off-by: aszlig <aszlig@nix.build>
Fixes: https://github.com/NixOS/nixpkgs/issues/94007
2020-08-04 16:35:18 +02:00
..
accessibility
audio Unmaintain packages I don't use anymore 2020-07-28 02:08:36 +02:00
backup vorta: 0.6.24 -> 0.6.26 2020-05-27 15:03:28 +02:00
blockchains electron: point electron alias to the latest stable version 2020-07-20 17:58:55 +02:00
display-managers
editors Merge branch 'staging-next' 2020-07-25 16:18:40 +02:00
gis qgis: 3.10.4 -> 3.10.7 2020-06-22 13:47:53 +01:00
graphics Merge pull request #93800 from danieldk/drawio-13.5.1 2020-07-26 08:33:37 +02:00
kde Merge pull request #93152 from ttuegel/kde-applications-20.04.3 2020-07-22 09:49:47 -05:00
misc synergy: Add patch to fix CVE-2020-15117 2020-08-04 16:35:18 +02:00
networking Unmaintain packages I don't use anymore 2020-07-28 02:08:36 +02:00
office Merge pull request #93577 from danieldk/freeoffice-version 2020-07-24 12:25:11 +02:00
qubes/qubes-core-vchan-xen
radio Merge branch 'master' into staging-next 2020-07-22 08:37:19 +02:00
science finalfrontier: 0.9.3 -> 0.9.4 2020-07-27 11:02:09 +02:00
search
system monitor: 0.7.2 -> 0.8.1 2020-07-22 14:31:25 +02:00
version-management gitAndTools.git-workspace: 0.6.0 -> 0.7.0 2020-07-26 11:32:41 +02:00
video makemkv: add danieldk as a maintainer 2020-07-25 12:08:33 +02:00
virtualization Merge pull request #93625 from NixOS/f/qemu 2020-07-27 21:36:09 +08:00
window-managers Merge pull request #93737 from r-ryantm/auto-update/i3lock-color 2020-07-26 23:59:31 +02:00