From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from eggs.gnu.org ([2001:4830:134:3::10]:33539) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1eJjHo-0001VF-1m for guix-patches@gnu.org; Tue, 28 Nov 2017 12:03:13 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1eJjHk-0000HE-Ak for guix-patches@gnu.org; Tue, 28 Nov 2017 12:03:08 -0500 Received: from debbugs.gnu.org ([208.118.235.43]:54413) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_128_CBC_SHA1:16) (Exim 4.71) (envelope-from ) id 1eJjHk-0000HA-6k for guix-patches@gnu.org; Tue, 28 Nov 2017 12:03:04 -0500 Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1eJjHj-0001bd-UX for guix-patches@gnu.org; Tue, 28 Nov 2017 12:03:03 -0500 Subject: [bug#29487] [PATCH] gnu: libxcursor: Replace with 1.1.15 [fixes CVE-2017-16612]. Resent-Message-ID: Received: from eggs.gnu.org ([2001:4830:134:3::10]:32811) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1eJjGs-0000CT-Jr for guix-patches@gnu.org; Tue, 28 Nov 2017 12:02:16 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1eJjGr-0008FC-Il for guix-patches@gnu.org; Tue, 28 Nov 2017 12:02:10 -0500 Received: from out4-smtp.messagingengine.com ([66.111.4.28]:52045) by eggs.gnu.org with esmtps (TLS1.0:DHE_RSA_AES_256_CBC_SHA1:32) (Exim 4.71) (envelope-from ) id 1eJjGr-0008Eo-DX for guix-patches@gnu.org; Tue, 28 Nov 2017 12:02:09 -0500 From: Marius Bakke Date: Tue, 28 Nov 2017 18:02:05 +0100 Message-Id: <20171128170205.30002-1-mbakke@fastmail.com> List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-patches-bounces+kyle=kyleam.com@gnu.org Sender: "Guix-patches" To: 29487@debbugs.gnu.org * gnu/packages/xorg.scm (libxcursor-1.1.15): New public variable. (libxcursor)[replacement]: New field. --- gnu/packages/xorg.scm | 13 +++++++++++++ 1 file changed, 13 insertions(+) diff --git a/gnu/packages/xorg.scm b/gnu/packages/xorg.scm index 994476ed6..1c1ddd4bf 100644 --- a/gnu/packages/xorg.scm +++ b/gnu/packages/xorg.scm @@ -5307,6 +5307,7 @@ draggable titlebars and borders.") (package (name "libxcursor") (version "1.1.14") + (replacement libxcursor-1.1.15) (source (origin (method url-fetch) @@ -5339,6 +5340,18 @@ draggable titlebars and borders.") (description "Xorg Cursor management library.") (license license:x11))) +;; For CVE-2017-16612. +(define-public libxcursor-1.1.15 + (package + (inherit libxcursor) + (version "1.1.15") + (source (origin + (method url-fetch) + (uri (string-append "mirror://xorg/individual/lib/libXcursor-" + version ".tar.bz2")) + (sha256 + (base32 + "0syzlfvh29037p0vnlc8f3jxz8nl55k65blswsakklkwsc6nfki9")))))) (define-public libxt (package -- 2.15.0