nixpkgs/pkgs/development
Anders Kaseorg 665dfc26ed libversion: Fix unsafe concatenation of $LD_LIBRARY_PATH
Naive concatenation of $LD_LIBRARY_PATH can result in an empty
colon-delimited segment; this tells glibc to load libraries from the
current directory, which is definitely wrong, and may be a security
vulnerability if the current directory is untrusted.  This particular
case probably has no security relevance, but we should avoid this
unsafe pattern anyway in case it gets copied.  See #76804.

Signed-off-by: Anders Kaseorg <andersk@mit.edu>
2020-05-31 01:42:09 -07:00
..
androidndk-pkgs androidndkPkgs: expose libc in cc.lib (#87737) 2020-05-16 09:22:24 +00:00
arduino treewide: remove the-kenny from maintainers 2020-05-09 10:28:57 +01:00
beam-modules
bower-modules/generic
chez-modules
compilers zz: 2020-03-02 -> 0.1 2020-05-28 04:20:00 -05:00
coq-modules coqPackages.mathcomp-extra: refactor 2020-05-27 09:22:42 +02:00
dhall-modules
dotnet-modules python-language-server: init at 2020-04-24 2020-05-09 09:41:14 +02:00
em-modules/generic
go-modules go-modules: Add in old modsha256 w/ warning 2020-05-14 07:21:52 +01:00
go-packages buildGoPackage: use $out instead of $bin 2020-04-28 20:30:23 +10:00
guile-modules guile-cairo: 1.10.0 -> 1.11.0 2020-05-27 12:16:50 -07:00
haskell-modules haskell/generic-builder.nix: Fix C lib multiple inclusions 2020-05-15 21:02:08 +02:00
idris-modules
interpreters Merge pull request #88761 from r-ryantm/auto-update/rakudo 2020-05-25 07:50:52 -07:00
java-modules
libraries libversion: Fix unsafe concatenation of $LD_LIBRARY_PATH 2020-05-31 01:42:09 -07:00
lisp-modules lisp-modules: fix missing && after test command 2020-05-04 21:55:21 +02:00
lua-modules
misc Merge pull request #86165 from jtojnar/libusb-compat-rename 2020-04-29 08:26:08 +02:00
mobile cocoapods-beta: 1.9.1 -> 1.9.2 2020-05-22 17:15:27 -07:00
node-packages treewide: per RFC45, remove more unquoted URLs 2020-05-08 15:20:47 +02:00
ocaml-modules ocamlPackages.core: remove at 112.24.01 2020-05-28 09:09:53 +02:00
perl-modules
pharo
pure-modules
python-modules pythonPackages.pytest-datadir: init at 1.3.1 2020-05-28 19:21:43 -07:00
r-modules r-statmod: Add libiconv to buildInputs 2020-05-14 20:00:58 -07:00
ruby-modules
tools cmake-language-server: init at 0.1.1 2020-05-28 19:21:43 -07:00
web nodejs-12_x: 12.16.3 -> 12.17.0 2020-05-27 04:20:00 -05:00