From 8f53bcbb05e22697d64989cec8187a866353f510 Mon Sep 17 00:00:00 2001 From: Mark Stemm Date: Tue, 3 Jan 2017 16:22:51 -0800 Subject: [PATCH] Patch jq 1.5 with a fix for security vulns. After downloading jq 1.5, apply the changes in stedolan/jq@8eb1367 by downloading the commit as a patch and applying it. This fixes CVE-2015-8863. --- CMakeLists.txt | 1 + 1 file changed, 1 insertion(+) diff --git a/CMakeLists.txt b/CMakeLists.txt index b0a122e7..5d54005c 100644 --- a/CMakeLists.txt +++ b/CMakeLists.txt @@ -99,6 +99,7 @@ else() CONFIGURE_COMMAND ./configure --disable-maintainer-mode --enable-all-static --disable-dependency-tracking BUILD_COMMAND ${CMD_MAKE} LDFLAGS=-all-static BUILD_IN_SOURCE 1 + PATCH_COMMAND wget -O jq-1.5-fix-tokenadd.patch https://github.com/stedolan/jq/commit/8eb1367ca44e772963e704a700ef72ae2e12babd.patch && patch -i jq-1.5-fix-tokenadd.patch INSTALL_COMMAND "") endif()