From 6458876597d292ea06f0d41048948fd801cedb8a Mon Sep 17 00:00:00 2001 From: Mark H Weaver Date: Fri, 25 Mar 2016 17:01:52 -0400 Subject: [PATCH] gnu: expat: Replace with 2.1.1 [fixes CVE-2015-1283]. * gnu/packages/xml.scm (expat)[replacement]: New field. (expat-2.1.1): New variable. --- gnu/packages/xml.scm | 17 ++++++++++++++++- 1 file changed, 16 insertions(+), 1 deletion(-) diff --git a/gnu/packages/xml.scm b/gnu/packages/xml.scm index 7419c61d3a..6d3ffe8ea5 100644 --- a/gnu/packages/xml.scm +++ b/gnu/packages/xml.scm @@ -4,7 +4,7 @@ ;;; Copyright © 2015 Eric Bavier ;;; Copyright © 2015 Sou Bunnbu ;;; Copyright © 2015 Ricardo Wurmus -;;; Copyright © 2015 Mark H Weaver +;;; Copyright © 2015, 2016 Mark H Weaver ;;; Copyright © 2015 Efraim Flashner ;;; Copyright © 2015 Raimon Grau ;;; @@ -43,6 +43,7 @@ (define-public expat (package + (replacement expat-2.1.1) (name "expat") (version "2.1.0") (source (origin @@ -62,6 +63,20 @@ stream-oriented parser in which an application registers handlers for things the parser might find in the XML document (like start tags).") (license license:expat))) +(define expat-2.1.1 + (package + (inherit expat) + (replacement #f) + (source + (let ((version "2.1.1")) + (origin + (method url-fetch) + (uri (string-append "mirror://sourceforge/expat/expat/" + version "/expat-" version ".tar.bz2")) + (sha256 + (base32 + "0ryyjgvy7jq0qb7a9mhc1giy3bzn56aiwrs8dpydqngplbjq9xdg"))))))) + (define-public libxml2 (package (name "libxml2")