From 4a5c66135a4b2abb03a788db47601a02a886904b Mon Sep 17 00:00:00 2001 From: Graham Christensen Date: Wed, 23 Nov 2016 19:24:37 -0500 Subject: [PATCH] gnuchess: 6.2.3 -> 6.2.4 for CVEs CVE-2015-8972: stack buffer overflow related to user move input, where 160 characters of input can crash gnuchess --- pkgs/games/gnuchess/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/games/gnuchess/default.nix b/pkgs/games/gnuchess/default.nix index 9aee664a50e..9b0ada3f926 100644 --- a/pkgs/games/gnuchess/default.nix +++ b/pkgs/games/gnuchess/default.nix @@ -3,10 +3,10 @@ let s = # Generated upstream information rec { baseName="gnuchess"; - version="6.2.3"; + version="6.2.4"; name="${baseName}-${version}"; url="mirror://gnu/chess/${name}.tar.gz"; - sha256="10hvnfhj9bkpz80x20jgxyqvgvrcgfdp8sfcbcrf1dgjn9v936bq"; + sha256="1vw2w3jwnmn44d5vsw47f8y70xvxcsz9m5msq9fgqlzjch15qhiw"; }; buildInputs = [ flex