glibc: patch 2.23 for CVE-2016-3075, CVE-2016-1234, CVE-2016-3706

This addresses the following security advisories:

+ CVE-2016-3075: Stack overflow in _nss_dns_getnetbyname_r
+ CVE-2016-1234: glob: buffer overflow with GLOB_ALTDIRFUNC due to incorrect
                 NAME_MAX limit assumption
+ CVE-2016-3706: getaddrinfo: stack overflow in hostent conversion

Patches cherry-picked from glibc's release/2.23/master branch.

The "glob-simplify-interface.patch" was a dependency for
"cve-2016-1234.patch".
This commit is contained in:
Scott R. Parish
2016-05-13 23:47:17 -07:00
parent 3f0518ac4d
commit 64f5845418
5 changed files with 809 additions and 0 deletions
@@ -49,6 +49,11 @@ stdenv.mkDerivation ({
"/bin:/usr/bin", which is inappropriate on NixOS machines. This
patch extends the search path by "/run/current-system/sw/bin". */
./fix_path_attribute_in_getconf.patch
./cve-2016-3075.patch
./glob-simplify-interface.patch
./cve-2016-1234.patch
./cve-2016-3706.patch
];
postPatch =