From 0b34b58688ac0d9bc0e2700acf82269e67ccdfa3 Mon Sep 17 00:00:00 2001 From: Leo Famulari Date: Tue, 8 Nov 2016 17:12:01 -0500 Subject: gnu: libxslt: Fix CVE-2016-4738. * gnu/packages/patches/libxslt-CVE-2016-4738.patch: New file. * gnu/local.mk (dist_patch_DATA): Add it. * gnu/packages/xml.scm (libxslt)[replacement]: New field. (libxslt/fixed): New variable. --- gnu/packages/xml.scm | 9 +++++++++ 1 file changed, 9 insertions(+) (limited to 'gnu/packages/xml.scm') diff --git a/gnu/packages/xml.scm b/gnu/packages/xml.scm index 879b37a33..d6c034bc2 100644 --- a/gnu/packages/xml.scm +++ b/gnu/packages/xml.scm @@ -147,6 +147,7 @@ project (but it is usable outside of the Gnome platform).") (define-public libxslt (package (name "libxslt") + (replacement libxslt/fixed) (version "1.1.29") (source (origin (method url-fetch) @@ -168,6 +169,14 @@ project (but it is usable outside of the Gnome platform).") based on libxml for XML parsing, tree manipulation and XPath support.") (license license:x11))) +(define libxslt/fixed + (package + (inherit libxslt) + (name "libxslt") + (source (origin + (inherit (package-source libxslt)) + (patches (search-patches "libxslt-CVE-2016-4738.patch")))))) + (define-public perl-graph-readwrite (package (name "perl-graph-readwrite") -- cgit v1.3