Nixpkgs Security Tracker

Login with GitHub

Suggestion detail

Dismissed
updated 3 weeks ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed
    2 packages
    • malcontent
    • malcontent-ui
  • @LeSuisse dismissed
malcontent's nested archive extraction failure can drop content from scan inputs

malcontent is software for discovering supply-chain compromises through context, differential analysis, and YARA. Prior to version 1.21.0, malcontent would remove nested archives which failed to extract which could potentially leave malicious content. A better approach is to preserve these archives so that malcontent can attempt a best-effort scan of the archive bytes. Version 1.21.0 fixes the issue.

Affected products

malcontent
  • ==< 1.21.0
Ignored packages (2)
Not present in nixpkgs