nixpkgs/pkgs/development
Anders Kaseorg e12f4db556 treewide: Fix unsafe concatenation of $LD_LIBRARY_PATH, round 2
Naive concatenation of $LD_LIBRARY_PATH can result in an empty
colon-delimited segment; this tells glibc to load libraries from the
current directory, which is definitely wrong, and may be a security
vulnerability if the current directory is untrusted.  (See #67234, for
example.)  Fix this throughout the tree.

Followup to #76804.  Fixes #144646.

Signed-off-by: Anders Kaseorg <andersk@mit.edu>
2021-11-04 16:15:05 -07:00
..
androidndk-pkgs
beam-modules
bower-modules/generic
chez-modules
compilers treewide: Fix unsafe concatenation of $LD_LIBRARY_PATH, round 2 2021-11-04 16:15:05 -07:00
coq-modules coqPackages.dpdgraph: 0.6.9 → 1.0 2021-10-31 07:06:14 +01:00
dhall-modules
dotnet-modules
em-modules/generic
embedded openocd: libgpiod is supported only on linux (#143652) 2021-10-29 16:12:53 +02:00
gnuradio-modules
go-modules
go-packages
guile-modules
haskell-modules
idris-modules
interpreters Merge master into staging-next 2021-11-01 00:01:32 +00:00
java-modules
libraries treewide: Fix unsafe concatenation of $LD_LIBRARY_PATH, round 2 2021-11-04 16:15:05 -07:00
lisp-modules
lua-modules
misc
mobile
nim-packages
node-packages lua-fmt: init at 2.6.0 2021-10-27 20:05:16 +11:00
ocaml-modules ocamlPackages.awa: 0.0.3 -> 0.0.4 2021-10-30 22:46:44 +02:00
octave-modules
perl-modules
pharo
php-packages
pure-modules
python-modules treewide: Fix unsafe concatenation of $LD_LIBRARY_PATH, round 2 2021-11-04 16:15:05 -07:00
quickemu quickemu: 2.2.6 -> 2.2.7 2021-10-27 08:45:41 -06:00
r-modules rPackages: fix builds requiring gsl 2021-11-01 19:39:52 +11:00
ruby-modules rbenv: 1.1.2 -> 1.2.0 2021-10-29 01:13:11 +00:00
scheme-modules/scheme-bytestructures
tools treewide: Fix unsafe concatenation of $LD_LIBRARY_PATH, round 2 2021-11-04 16:15:05 -07:00
web Merge master into staging-next 2021-10-31 00:01:33 +00:00