From mboxrd@z Thu Jan 1 00:00:00 1970 From: Leo Famulari Subject: [PATCH 1/1] gnu: curl: Replace with 7.49.1 [fixes CVE-2016-3739]. Date: Sat, 11 Jun 2016 23:38:30 -0400 Message-ID: <7e8126c4a72a6a4bcbd1bf3f49984bd9584cd013.1465702340.git.leo@famulari.name> References: Return-path: Received: from eggs.gnu.org ([2001:4830:134:3::10]:55116) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1bBwEe-0000Z9-Bw for guix-devel@gnu.org; Sat, 11 Jun 2016 23:38:53 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1bBwEa-0004u7-5i for guix-devel@gnu.org; Sat, 11 Jun 2016 23:38:51 -0400 Received: from out2-smtp.messagingengine.com ([66.111.4.26]:47036) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1bBwEX-0004rY-N9 for guix-devel@gnu.org; Sat, 11 Jun 2016 23:38:48 -0400 Received: from localhost.localdomain (unknown [65.210.89.2]) by mail.messagingengine.com (Postfix) with ESMTPA id ADF72F29F3 for ; Sat, 11 Jun 2016 23:38:35 -0400 (EDT) In-Reply-To: In-Reply-To: References: List-Id: "Development of GNU Guix and the GNU System distribution." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-devel-bounces+gcggd-guix-devel=m.gmane.org@gnu.org Sender: "Guix-devel" To: guix-devel@gnu.org * gnu/packages/curl.scm (curl)[replacement]: New field. (curl/fixed): New variable. --- gnu/packages/curl.scm | 15 +++++++++++++++ 1 file changed, 15 insertions(+) diff --git a/gnu/packages/curl.scm b/gnu/packages/curl.scm index 222910b..925602e 100644 --- a/gnu/packages/curl.scm +++ b/gnu/packages/curl.scm @@ -40,6 +40,7 @@ (define-public curl (package (name "curl") + (replacement curl/fixed) (version "7.47.0") (source (origin (method url-fetch) @@ -123,3 +124,17 @@ tunneling, and so on.") (license (license:non-copyleft "file://COPYING" "See COPYING in the distribution.")) (home-page "http://curl.haxx.se/"))) + +(define curl/fixed + (package + (inherit curl) + (source + (let ((name "curl") + (version "7.49.1")) + (origin + (method url-fetch) + (uri (string-append "https://curl.haxx.se/download/curl-" + version ".tar.lzma")) + (sha256 + (base32 + "033w3wyawali0rc5s15ywxpjnf476671m595r49sr4vj07idf3al"))))))) -- 2.8.4