aboutsummaryrefslogtreecommitdiff
path: root/gnu
diff options
context:
space:
mode:
authorLeo Famulari <leo@famulari.name>2017-01-15 13:38:48 -0500
committerLeo Famulari <leo@famulari.name>2017-01-15 20:24:34 -0500
commit8afabb2eca954af6fbba8c6ae37e8f0bc3047840 (patch)
treee80c1923c42b62d259b40be057356d06aa7cc9ee /gnu
parentaf8c7e10147acd105fe33f60baab2d1d21f38f7b (diff)
downloadguix-8afabb2eca954af6fbba8c6ae37e8f0bc3047840.tar
guix-8afabb2eca954af6fbba8c6ae37e8f0bc3047840.tar.gz
gnu: cups-filters: Fix CVE-2016-{10132,10133} in statically linked mupdf.
The vulnerabilities are in the MuJS that is bundled with MuPDF. * gnu/packages/cups.scm (cups-filters)[replacement]: New field. (mupdf/fixed-instead-of-mupdf), (cups-filters/fixed): New variables.
Diffstat (limited to 'gnu')
-rw-r--r--gnu/packages/cups.scm9
1 files changed, 9 insertions, 0 deletions
diff --git a/gnu/packages/cups.scm b/gnu/packages/cups.scm
index ca16958352..39ab41c192 100644
--- a/gnu/packages/cups.scm
+++ b/gnu/packages/cups.scm
@@ -3,6 +3,7 @@
;;; Copyright © 2015, 2016 Ludovic Courtès <ludo@gnu.org>
;;; Copyright © 2015, 2016 Efraim Flashner <efraim@flashner.co.il>
;;; Copyright © 2016 Danny Milosavljevic <dannym@scratchpost.org>
+;;; Copyright © 2017 Leo Famulari <leo@famulari.name>
;;;
;;; This file is part of GNU Guix.
;;;
@@ -51,6 +52,7 @@
(define-public cups-filters
(package
(name "cups-filters")
+ (replacement cups-filters/fixed)
(version "1.13.1")
(source(origin
(method url-fetch)
@@ -133,6 +135,13 @@ filters for the PDF-centric printing workflow introduced by OpenPrinting.")
license:lgpl2.0+
license:expat))))
+(define mupdf/fixed-instead-of-mupdf
+ (package-input-rewriting `((,mupdf . ,(@@ (gnu packages pdf) mupdf/fixed)))))
+
+;;; Fix CVE-2016-10132 and CVE-2016-10133. See mupdf/fixed for more information.
+(define cups-filters/fixed
+ (mupdf/fixed-instead-of-mupdf cups-filters))
+
;; CUPS on non-MacOS systems requires cups-filters. Since cups-filters also
;; depends on CUPS libraries and binaries, cups-minimal has been added to
;; satisfy this dependency.