Nixpkgs Security Tracker

Login with GitHub

Automatically generated suggestions

to queue a suggestion for refinement.

to remove a suggestion from the queue.

created 4 months ago
AngularJS improper sanitization in 'srcset' attribute

Improper sanitization of the value of the 'srcset' attribute in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing . This issue affects AngularJS versions 1.3.0-rc.4 and greater. Note: The AngularJS project is End-of-Life and will not receive any updates to address this issue. For more information see here https://docs.angularjs.org/misc/version-support-status .

Affected products

angular
  • ==>=1.3.0-rc.4

Matching in nixpkgs

pkgs.angular-language-server

LSP for angular completions, AOT diagnostic, quick info and go to definitions

  • nixos-unstable -

pkgs.nodePackages.@angular/cli

CLI tool for Angular

  • nixos-unstable -

pkgs.nodePackages_latest.@angular/cli

CLI tool for Angular

  • nixos-unstable -

pkgs.vimPlugins.nvim-treesitter-parsers.angular

  • nixos-unstable -
    • nixpkgs-unstable

Package maintainers: 1

created 4 months ago
Vuetify XSS through 'eventMoreText' prop of VCalendar

Improper neutralization of the value of the 'eventMoreText' property of the 'VCalendar' component in Vuetify allows unsanitized HTML to be inserted into the page. This can lead to a  Cross-Site Scripting (XSS) https://owasp.org/www-community/attacks/xss  attack. The vulnerability occurs because the default Vuetify translator will return the translation key as the translation, if it can't find an actual translation. This issue affects Vuetify versions greater than or equal to 2.0.0 and less than 3.0.0. Note: Version 2.x of Vuetify is End-of-Life and will not receive any updates to address this issue. For more information see here https://v2.vuetifyjs.com/en/about/eol/ .

Affected products

vuetify
  • ==>=2.0.0 <3.0.0

Matching in nixpkgs

pkgs.python312Packages.ipyvuetify

Jupyter widgets based on Vuetify UI Components

  • nixos-unstable -

pkgs.python313Packages.ipyvuetify

Jupyter widgets based on Vuetify UI Components

  • nixos-unstable -

Package maintainers: 1

created 4 months ago
AngularJS improper sanitization in '<source>' element

Improper sanitization of the value of the [srcset] attribute in <source> HTML elements in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing . This issue affects all versions of AngularJS. Note: The AngularJS project is End-of-Life and will not receive any updates to address this issue. For more information see here https://docs.angularjs.org/misc/version-support-status .

Affected products

angular
  • ==>=0.0.0

Matching in nixpkgs

pkgs.angular-language-server

LSP for angular completions, AOT diagnostic, quick info and go to definitions

  • nixos-unstable -

pkgs.nodePackages.@angular/cli

CLI tool for Angular

  • nixos-unstable -

pkgs.nodePackages_latest.@angular/cli

CLI tool for Angular

  • nixos-unstable -

pkgs.vimPlugins.nvim-treesitter-parsers.angular

  • nixos-unstable -
    • nixpkgs-unstable

Package maintainers: 1

created 4 months ago
AngularJS improper sanitization in SVG '<image>' element

Improper sanitization of the value of the 'href' and 'xlink:href' attributes in '<image>' SVG elements in AngularJS allows attackers to bypass common image source restrictions. This can lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing  and also negatively affect the application's performance and behavior by using too large or slow-to-load images. This issue affects all versions of AngularJS. Note: The AngularJS project is End-of-Life and will not receive any updates to address this issue. For more information see here https://docs.angularjs.org/misc/version-support-status .

Affected products

angular
  • ==>=0.0.0

Matching in nixpkgs

pkgs.angular-language-server

LSP for angular completions, AOT diagnostic, quick info and go to definitions

  • nixos-unstable -

pkgs.nodePackages.@angular/cli

CLI tool for Angular

  • nixos-unstable -

pkgs.nodePackages_latest.@angular/cli

CLI tool for Angular

  • nixos-unstable -

pkgs.vimPlugins.nvim-treesitter-parsers.angular

  • nixos-unstable -
    • nixpkgs-unstable

Package maintainers: 1

created 4 months ago
Coreutils: heap buffer under-read in gnu coreutils sort via key specification

A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key format. A malicious input could lead to a crash or leak sensitive data.

Affected products

rhcos
coreutils
  • <9.8

Matching in nixpkgs

pkgs.coreutils

GNU Core Utilities

  • nixos-unstable -

pkgs.coreutils-full

GNU Core Utilities

  • nixos-unstable -

pkgs.policycoreutils

SELinux policy core utilities

  • nixos-unstable -

pkgs.uutils-coreutils

Cross-platform Rust rewrite of the GNU coreutils

  • nixos-unstable -

pkgs.coreutils-prefixed

GNU Core Utilities

  • nixos-unstable -

pkgs.uutils-coreutils-noprefix

Cross-platform Rust rewrite of the GNU coreutils

  • nixos-unstable -

Package maintainers: 5

created 4 months ago
Gimp: stack-based buffer overflows in file-ico

A flaw was found in GIMP. The GIMP ani_load_image() function is vulnerable to a stack-based overflow. If a user opens.ANI files, GIMP may be used to store more information than the capacity allows. This flaw allows a malicious ANI file to trigger arbitrary code execution.

Affected products

gimp
  • <2.99.16
gimp:2.8/gimp

Matching in nixpkgs

pkgs.zigimports

Automatically remove unused imports and globals from Zig files

  • nixos-unstable -

pkgs.gimpPlugins.bimp

Batch Image Manipulation Plugin for GIMP

  • nixos-unstable -

pkgs.gimpPlugins.gimp

GNU Image Manipulation Program

pkgs.gimpPlugins.gmic

GIMP plugin for the G'MIC image processing framework

  • nixos-unstable -

pkgs.gimp-with-plugins

GNU Image Manipulation Program

pkgs.gimp3Plugins.gimp

GNU Image Manipulation Program

  • nixos-unstable -

pkgs.gimp3Plugins.gmic

GIMP plugin for the G'MIC image processing framework

  • nixos-unstable -

pkgs.gimp3-with-plugins

GNU Image Manipulation Program

  • nixos-unstable -

pkgs.gimpPlugins.fourier

GIMP plug-in to do the fourier transform

  • nixos-unstable -

pkgs.gimpPlugins.farbfeld

Gimp plug-in for the farbfeld image format

pkgs.gimpPlugins.lightning

  • nixos-unstable -
    • nixpkgs-unstable

pkgs.gimpPlugins.lqrPlugin

  • nixos-unstable -

pkgs.gimp3Plugins.lightning

  • nixos-unstable -
    • nixpkgs-unstable

pkgs.gimpPlugins.gimplensfun

GIMP plugin to correct lens distortion using the lensfun library and database

pkgs.gimpPlugins.resynthesizer

  • nixos-unstable -

pkgs.gimpPlugins.waveletSharpen

  • nixos-unstable -

Package maintainers: 3

created 4 months ago
Gimp: multiple heap buffer overflows in tga parser

A flaw was found in GIMP when processing certain TGA image files. If a user opens one of these image files that has been specially crafted by an attacker, GIMP can be tricked into making serious memory errors, potentially leading to crashes and causing a heap buffer overflow.

Affected products

gimp
  • <3.0.0
  • *
gimp:2.8
  • *
gimp:2.8/gimp

Matching in nixpkgs

pkgs.zigimports

Automatically remove unused imports and globals from Zig files

  • nixos-unstable -

pkgs.gimpPlugins.bimp

Batch Image Manipulation Plugin for GIMP

  • nixos-unstable -

pkgs.gimpPlugins.gimp

GNU Image Manipulation Program

pkgs.gimpPlugins.gmic

GIMP plugin for the G'MIC image processing framework

  • nixos-unstable -

pkgs.gimp-with-plugins

GNU Image Manipulation Program

pkgs.gimp3Plugins.gimp

GNU Image Manipulation Program

  • nixos-unstable -

pkgs.gimp3Plugins.gmic

GIMP plugin for the G'MIC image processing framework

  • nixos-unstable -

pkgs.gimp3-with-plugins

GNU Image Manipulation Program

  • nixos-unstable -

pkgs.gimpPlugins.fourier

GIMP plug-in to do the fourier transform

  • nixos-unstable -

pkgs.gimpPlugins.farbfeld

Gimp plug-in for the farbfeld image format

pkgs.gimpPlugins.lightning

  • nixos-unstable -
    • nixpkgs-unstable

pkgs.gimpPlugins.lqrPlugin

  • nixos-unstable -

pkgs.gimp3Plugins.lightning

  • nixos-unstable -
    • nixpkgs-unstable

pkgs.gimpPlugins.gimplensfun

GIMP plugin to correct lens distortion using the lensfun library and database

pkgs.gimpPlugins.resynthesizer

  • nixos-unstable -

pkgs.gimpPlugins.waveletSharpen

  • nixos-unstable -

Package maintainers: 3

created 4 months ago
Gimp: multiple use after free in xcf parser

A flaw was found in GIMP when processing XCF image files. If a user opens one of these image files that has been specially crafted by an attacker, GIMP can be tricked into making serious memory errors, potentially leading to crashes and causing use-after-free issues.

Affected products

gimp
  • <3.0.0
  • *
gimp:2.8
  • *
gimp:2.8/gimp

Matching in nixpkgs

pkgs.zigimports

Automatically remove unused imports and globals from Zig files

  • nixos-unstable -

pkgs.gimpPlugins.bimp

Batch Image Manipulation Plugin for GIMP

  • nixos-unstable -

pkgs.gimpPlugins.gimp

GNU Image Manipulation Program

pkgs.gimpPlugins.gmic

GIMP plugin for the G'MIC image processing framework

  • nixos-unstable -

pkgs.gimp-with-plugins

GNU Image Manipulation Program

pkgs.gimp3Plugins.gimp

GNU Image Manipulation Program

  • nixos-unstable -

pkgs.gimp3Plugins.gmic

GIMP plugin for the G'MIC image processing framework

  • nixos-unstable -

pkgs.gimp3-with-plugins

GNU Image Manipulation Program

  • nixos-unstable -

pkgs.gimpPlugins.fourier

GIMP plug-in to do the fourier transform

  • nixos-unstable -

pkgs.gimpPlugins.farbfeld

Gimp plug-in for the farbfeld image format

pkgs.gimpPlugins.lightning

  • nixos-unstable -
    • nixpkgs-unstable

pkgs.gimpPlugins.lqrPlugin

  • nixos-unstable -

pkgs.gimp3Plugins.lightning

  • nixos-unstable -
    • nixpkgs-unstable

pkgs.gimpPlugins.gimplensfun

GIMP plugin to correct lens distortion using the lensfun library and database

pkgs.gimpPlugins.resynthesizer

  • nixos-unstable -

pkgs.gimpPlugins.waveletSharpen

  • nixos-unstable -

Package maintainers: 3

created 4 months ago
Icu: stack buffer overflow in the srbroot::addtag function

A stack buffer overflow was found in Internationl components for unicode (ICU ). While running the genrb binary, the 'subtag' struct overflowed at the SRBRoot::addTag function. This issue may lead to memory corruption and local arbitrary code execution.

Affected products

icu
  • *
  • <78.1
rhcos
mingw-icu

Matching in nixpkgs

pkgs.icu60

Unicode and globalization support library

  • nixos-unstable -

pkgs.icu63

Unicode and globalization support library

  • nixos-unstable -

pkgs.icu64

Unicode and globalization support library

  • nixos-unstable -

pkgs.icu66

Unicode and globalization support library

  • nixos-unstable -

pkgs.icu67

Unicode and globalization support library

  • nixos-unstable -

pkgs.icu69

Unicode and globalization support library

  • nixos-unstable -

pkgs.icu70

Unicode and globalization support library

  • nixos-unstable -

pkgs.icu71

Unicode and globalization support library

  • nixos-unstable -

pkgs.icu72

Unicode and globalization support library

  • nixos-unstable -

pkgs.icu73

Unicode and globalization support library

  • nixos-unstable -

pkgs.icu74

Unicode and globalization support library

  • nixos-unstable -

pkgs.icu75

Unicode and globalization support library

  • nixos-unstable -

pkgs.icu76

Unicode and globalization support library

  • nixos-unstable -

pkgs.icu77

Unicode and globalization support library

  • nixos-unstable -

pkgs.cunicu

Zeroconf peer-to-peer mesh VPN using Wireguard® and Interactive Connectivity Establishment (ICE)

  • nixos-unstable -

pkgs.musicus

Classical music player and organizer

  • nixos-unstable -

pkgs.ploticus

Non-interactive software package for producing plots and charts

  • nixos-unstable -

pkgs.moolticute

GUI app and daemon to work with Mooltipass device via USB

  • nixos-unstable -

pkgs.solicurses

Version of Solitaire written in C++ using the ncurses library

pkgs.wikicurses

Simple curses interface for MediaWiki sites such as Wikipedia

  • nixos-unstable -

pkgs.harfbuzzFull

OpenType text shaping engine

  • nixos-unstable -

pkgs.python312Packages.pyicu

Python extension wrapping the ICU C++ API

  • nixos-unstable -

pkgs.python313Packages.pyicu

Python extension wrapping the ICU C++ API

  • nixos-unstable -

pkgs.haskellPackages.text-icu

Bindings to the ICU library

pkgs.python312Packages.unicurses

Unified Curses Wrapper for Python

  • nixos-unstable -

pkgs.python313Packages.unicurses

Unified Curses Wrapper for Python

  • nixos-unstable -

pkgs.typstPackages.icu-datetime_0_1_0

Date and time formatting using ICU4X via WASM

  • nixos-unstable -

pkgs.typstPackages.icu-datetime_0_1_1

Date and time formatting using ICU4X via WASM

  • nixos-unstable -

pkgs.typstPackages.icu-datetime_0_1_2

Date and time formatting using ICU4X via WASM

  • nixos-unstable -

pkgs.chickenPackages_5.chickenEggs.icu

Chicken bindings to the ICU unicode library

  • nixos-unstable -

pkgs.elasticsearchPlugins.analysis-icu

ICU Analysis plugin integrates the Lucene ICU module into elasticsearch

pkgs.haskellPackages.music-articulation

Abstract representation of musical articulation

  • nixos-unstable -

pkgs.typstPackages.curriculo-acad_0_1_0

Creating a CV from your LATTES entries

  • nixos-unstable -

pkgs.python312Packages.pyicumessageformat

Unopinionated Python3 parser for ICU MessageFormat

  • nixos-unstable -

pkgs.python313Packages.pyicumessageformat

Unopinionated Python3 parser for ICU MessageFormat

  • nixos-unstable -

pkgs.rubyPackages.cocoapods-expert-difficulty

  • nixos-unstable -

pkgs.rubyPackages_3_1.cocoapods-expert-difficulty

  • nixos-unstable -

pkgs.rubyPackages_3_2.cocoapods-expert-difficulty

  • nixos-unstable -

pkgs.rubyPackages_3_3.cocoapods-expert-difficulty

  • nixos-unstable -

pkgs.rubyPackages_3_4.cocoapods-expert-difficulty

  • nixos-unstable -

pkgs.tests.pkg-config.defaultPkgConfigPackages.icu-io

Test whether icu4c-76.1 exposes pkg-config modules icu-io

  • nixos-unstable -

pkgs.tests.pkg-config.defaultPkgConfigPackages.icu-uc

Test whether icu4c-76.1 exposes pkg-config modules icu-uc

  • nixos-unstable -

pkgs.tests.pkg-config.defaultPkgConfigPackages.icu-i18n

Test whether icu4c-76.1 exposes pkg-config modules icu-i18n

  • nixos-unstable -

Package maintainers: 10

created 4 months ago
daily-backup.sh script in cyrus-imapd allows escalation from cyrus to root

A UNIX Symbolic Link (Symlink) Following vulnerability in openSUSE Tumbleweed cyrus-imapd allows escalation from cyrus to root.This issue affects openSUSE Tumbleweed cyrus-imapd before 3.8.4-2.1.

Affected products

cyrus-imapd
  • <3.8.4-2.1

Matching in nixpkgs

pkgs.cyrus-imapd

Email, contacts and calendar server

  • nixos-unstable -

Package maintainers: 2