From a9cd13546b0bfea319ce71f359a12710946b84a1 Mon Sep 17 00:00:00 2001 From: Yorick van Pelt Date: Mon, 10 Oct 2022 07:59:49 +0200 Subject: [PATCH] proxysql: switch libmicrohttpd from 0.9.70 to 0.9.69 0.9.70 is vulnerable to CVE-2021-3466, but 0.9.69 is fine. proxysql is not yet compatible with 0.9.71 --- pkgs/servers/sql/proxysql/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/servers/sql/proxysql/default.nix b/pkgs/servers/sql/proxysql/default.nix index b8748368c50d..97b0591cbff7 100644 --- a/pkgs/servers/sql/proxysql/default.nix +++ b/pkgs/servers/sql/proxysql/default.nix @@ -16,7 +16,7 @@ , libev , libgcrypt , libinjection -, libmicrohttpd_0_9_70 +, libmicrohttpd_0_9_69 , libuuid , lz4 , nlohmann_json @@ -100,7 +100,7 @@ stdenv.mkDerivation rec { { f = "libdaemon"; p = libdaemon; } { f = "libev"; p = libev; } { f = "libinjection"; p = libinjection; } - { f = "libmicrohttpd"; p = libmicrohttpd_0_9_70; } + { f = "libmicrohttpd"; p = libmicrohttpd_0_9_69; } { f = "libssl"; p = openssl; } { f = "lz4"; p = lz4; } { f = "pcre"; p = pcre; }