Nixpkgs Security Tracker

Login with GitHub

Suggestions search

With package: lxqt.lxqt-archiver

Found 6 matching suggestions

View:
Compact
Detailed
created 1 month, 1 week ago
GFI Archiver MArc.Store Missing Authorization Authentication Bypass Vulnerability

GFI Archiver MArc.Store Missing Authorization Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of GFI Archiver. Authentication is not required to exploit this vulnerability. The specific flaw exists within the configuration of the MArc.Store.Remoting.exe process, which listens on port 8018. The issue results from the lack of authorization prior to allowing access to functionality. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of SYSTEM. Was ZDI-CAN-28597.

References

Affected products

Archiver
  • ==15.10

Matching in nixpkgs

pkgs.archiver

Easily create & extract archives, and compress & decompress files of various formats

Package maintainers

created 1 month, 1 week ago
GFI Archiver MArc.Store Deserialization of Untrusted Data Remote Code Execution Vulnerability

GFI Archiver MArc.Store Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GFI Archiver. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the configuration of the MArc.Store.Remoting.exe process. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-27936.

References

Affected products

Archiver
  • ==15.10

Matching in nixpkgs

pkgs.archiver

Easily create & extract archives, and compress & decompress files of various formats

Package maintainers

created 1 month, 1 week ago
GFI Archiver MArc.Core Missing Authorization Authentication Bypass Vulnerability

GFI Archiver MArc.Core Missing Authorization Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of GFI Archiver. Authentication is not required to exploit this vulnerability. The specific flaw exists within the configuration of the MArc.Core.Remoting.exe process, which listens on port 8017. The issue results from the lack of authorization prior to allowing access to functionality. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of SYSTEM. Was ZDI-CAN-27934.

References

Affected products

Archiver
  • ==15.10

Matching in nixpkgs

pkgs.archiver

Easily create & extract archives, and compress & decompress files of various formats

Package maintainers

Permalink CVE-2025-2241
8.2 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): HIGH
  • Privileges required (PR): LOW
  • User interaction (UI): NONE
  • Scope (S): CHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): HIGH
  • Availability impact (A): NONE
created 6 months, 1 week ago
Hive: exposure of vcenter credentials via clusterprovision in hive / mce / acm

A flaw was found in Hive, a component of Multicluster Engine (MCE) and Advanced Cluster Management (ACM). This vulnerability causes VCenter credentials to be exposed in the ClusterProvision object after provisioning a VSphere cluster. Users with read access to ClusterProvision objects can extract sensitive credentials even if they do not have direct access to Kubernetes Secrets. This issue can lead to unauthorized VCenter access, cluster management, and privilege escalation.

References

Affected products

hive
  • =<1.1.16
rhacm2/cluster-backup-rhel8-operator
rhacm2/cluster-backup-rhel9-operator
multicluster-engine/multicloud-manager-rhel8
multicluster-engine/multicloud-manager-rhel9

Matching in nixpkgs

pkgs.hivex

Windows registry hive extraction library

  • nixos-unstable -

pkgs.enchive

Encrypted personal archives

  • nixos-unstable -

pkgs.archiver

Easily create & extract archives, and compress & decompress files of various formats

  • nixos-unstable -

pkgs.hivemind

Process manager for Procfile-based applications

  • nixos-unstable -

pkgs.zarchive

File archive format supporting random-access reads

  • nixos-unstable -

pkgs.xarchiver

GTK frontend to 7z,zip,rar,tar,bzip2, gzip,arj, lha, rpm and deb (open and extract only)

pkgs.ytarchive

Garbage Youtube livestream downloader

  • nixos-unstable -

pkgs.disarchive

Disassemble software into data and metadata

  • nixos-unstable -

pkgs.fsarchiver

File system archiver for linux

  • nixos-unstable -

pkgs.libarchive

Multi-format archive and compression library

  • nixos-unstable -

pkgs.tg-archive

Tool for exporting Telegram group chats into static websites like mailing list archives

  • nixos-unstable -

pkgs.archivemount

Gateway between FUSE and libarchive: allows mounting of cpio, .tar.gz, .tar.bz2 archives

  • nixos-unstable -
    • nixpkgs-unstable 1b

pkgs.fuse-archive

Serve an archive or a compressed file as a read-only FUSE file system

  • nixos-unstable -

pkgs.jpeg-archive

Utilities for archiving photos for saving to long term storage or serving over the web

  • nixos-unstable -

pkgs.web-archives

Web archives reader offering the ability to browse offline millions of articles

  • nixos-unstable -

pkgs.hivelytracker

Chip music tracker based upon the AHX format

  • nixos-unstable -

pkgs.libarchive-qt

Qt based archiving solution with libarchive backend

  • nixos-unstable -

pkgs.lparchive2epub

Transform any LP from lparchive into an epub document

  • nixos-unstable -

pkgs.internetarchive

Python and Command-Line Interface to Archive.org

  • nixos-unstable -

pkgs.kodiPackages.archive_tool

Set of common python functions to work with the Kodi archive virtual file system (vfs) binary addons

  • nixos-unstable -

Package maintainers

Permalink CVE-2024-25132
4.3 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): NONE
  • Integrity impact (I): NONE
  • Availability impact (A): LOW
created 6 months, 1 week ago
Openshift-dedicated: hive: hibernation controller denial of service

A flaw was found in the Hive hibernation controller component of OpenShift Dedicated. The ClusterDeployment.hive.openshift.io/v1 resource can be created with the spec.installed field set to true, regardless of the installation status, and a positive timespan for the spec.hibernateAfter value. If a ClusterSync.hiveinternal.openshift.io/v1alpha1 resource is also created, the hive hibernation controller will enter the reconciliation loop leading to a panic when accessing a non-existing field in the ClusterDeployment’s status section, resulting in a denial of service.

References

Affected products

hive
  • <126c7eb43aa55a008b8f0cf594e7bd18086841eb

Matching in nixpkgs

pkgs.hivex

Windows registry hive extraction library

  • nixos-unstable -

pkgs.enchive

Encrypted personal archives

  • nixos-unstable -

pkgs.archiver

Easily create & extract archives, and compress & decompress files of various formats

  • nixos-unstable -

pkgs.hivemind

Process manager for Procfile-based applications

  • nixos-unstable -

pkgs.zarchive

File archive format supporting random-access reads

  • nixos-unstable -

pkgs.xarchiver

GTK frontend to 7z,zip,rar,tar,bzip2, gzip,arj, lha, rpm and deb (open and extract only)

pkgs.ytarchive

Garbage Youtube livestream downloader

  • nixos-unstable -

pkgs.disarchive

Disassemble software into data and metadata

  • nixos-unstable -

pkgs.fsarchiver

File system archiver for linux

  • nixos-unstable -

pkgs.libarchive

Multi-format archive and compression library

  • nixos-unstable -

pkgs.tg-archive

Tool for exporting Telegram group chats into static websites like mailing list archives

  • nixos-unstable -

pkgs.archivemount

Gateway between FUSE and libarchive: allows mounting of cpio, .tar.gz, .tar.bz2 archives

  • nixos-unstable -
    • nixpkgs-unstable 1b

pkgs.fuse-archive

Serve an archive or a compressed file as a read-only FUSE file system

  • nixos-unstable -

pkgs.jpeg-archive

Utilities for archiving photos for saving to long term storage or serving over the web

  • nixos-unstable -

pkgs.web-archives

Web archives reader offering the ability to browse offline millions of articles

  • nixos-unstable -

pkgs.hivelytracker

Chip music tracker based upon the AHX format

  • nixos-unstable -

pkgs.libarchive-qt

Qt based archiving solution with libarchive backend

  • nixos-unstable -

pkgs.lparchive2epub

Transform any LP from lparchive into an epub document

  • nixos-unstable -

pkgs.internetarchive

Python and Command-Line Interface to Archive.org

  • nixos-unstable -

pkgs.kodiPackages.archive_tool

Set of common python functions to work with the Kodi archive virtual file system (vfs) binary addons

  • nixos-unstable -

Package maintainers

Permalink CVE-2024-0406
6.1 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): LOCAL
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): REQUIRED
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): LOW
  • Integrity impact (I): HIGH
  • Availability impact (A): NONE
created 6 months, 1 week ago
Mholt/archiver: path traversal vulnerability

A flaw was discovered in the mholt/archiver package. This flaw allows an attacker to create a specially crafted tar file, which, when unpacked, may allow access to restricted files or directories. This issue can allow the creation or overwriting of files with the user's or application's privileges using the library.

References

Affected products

mholt
  • ==4
archiver
  • *
  • *
openshift4/oc-mirror-plugin-rhel8
openshift4/oc-mirror-plugin-rhel9
  • *
advanced-cluster-security/rhacs-main-rhel8
advanced-cluster-security/rhacs-roxctl-rhel8
advanced-cluster-security/rhacs-scanner-rhel8

Matching in nixpkgs

pkgs.archiver

Easily create & extract archives, and compress & decompress files of various formats

  • nixos-unstable -

pkgs.xarchiver

GTK frontend to 7z,zip,rar,tar,bzip2, gzip,arj, lha, rpm and deb (open and extract only)

pkgs.fsarchiver

File system archiver for linux

  • nixos-unstable -

Package maintainers