diff options
| author | Vojtěch Káně <vojtech.kane@gmail.com> | 2025-05-22 10:42:20 +0200 |
|---|---|---|
| committer | Vojtěch Káně <vojtech.kane@gmail.com> | 2025-06-05 10:57:27 +0200 |
| commit | a8b64551c5f11f7fe4700c94d50758b4c1baf5d3 (patch) | |
| tree | aa7c16212857435b000f7725c6c6fb5815214514 /pkgs/development/python-modules/python-etherscan-api | |
| parent | ee761a56b1f398b767cefa40dcce5cefd90499e7 (diff) | |
aerc: backport an upstream patch for handling of attachments' filenames
The patch is not part of a tagged release yet so we apply it selectively
instead of upgrading whole aerc. While it is originally presented as
a usability problem only for attachments with absolutes filepaths (they
fail to open), there is nothing stopping you from putting a relative
path in there therefore forcing aerc to overwriting any path on the host
system with sender chosen data. It's been marked as CVE-2025-49466
I decided to inline the patches into nixpkgs as they are very short and
the current bot protection of git.sr.ht complicates patch fetching.
Diffstat (limited to 'pkgs/development/python-modules/python-etherscan-api')
0 files changed, 0 insertions, 0 deletions
