Nixpkgs Security Tracker

Login with GitHub

Suggestion detail

Dismissed
updated 1 month ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed
    5 packages
    • runzip
    • ripunzip
    • unzipNLS
    • haskellPackages.unzip-traversable
    • haskellPackages.wai-middleware-gunzip
  • @LeSuisse dismissed
The NEEDBITS macro in the inflate_dynamic function in inflate.c for …

The NEEDBITS macro in the inflate_dynamic function in inflate.c for unzip can be invoked using invalid buffers, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors that trigger a free of uninitialized or previously-freed data.

References

Affected products

n/a
  • ==n/a
unzip
  • <6.0

Matching in nixpkgs

pkgs.unzip

Extraction utility for archives compressed in .zip format

  • nixos-unstable -
Ignored packages (5)

pkgs.runzip

Tool to convert filename encoding inside a ZIP archive

  • nixos-unstable -

pkgs.ripunzip

Tool to unzip files in parallel

  • nixos-unstable -

pkgs.unzipNLS

Extraction utility for archives compressed in .zip format

  • nixos-unstable -

Package maintainers

Current stable branch was never impacted

https://github.com/NixOS/nixpkgs/commit/672d3856df5d0e0e5bd5053e59cd5925b85e9f4a