Nixpkgs Security Tracker

Login with GitHub

Suggestions search

With package: python312Packages.mock-open

Found 2 matching suggestions

Untriaged
created 4 months, 3 weeks ago
Uninitialized memory access in Motoko incremental garbage collector

Motoko's incremental garbage collector is impacted by an uninitialized memory access bug, caused by incorrect use of write barriers in a few locations. This vulnerability could potentially allow unauthorized read or write access to a Canister's memory. However, exploiting this bug requires the Canister to enable the incremental garbage collector or enhanced orthogonal persistence, which are non-default features in Motoko.

Affected products

moc
  • =<0.13.3

Matching in nixpkgs

pkgs.amoco

Tool for analysing binaries

  • nixos-unstable -

pkgs.mochi

Simple markdown-powered SRS app

pkgs.umoci

Modifies Open Container images

  • nixos-unstable -

pkgs.cmocka

Lightweight library to simplify and generalize unit tests for C

  • nixos-unstable -

pkgs.emocli

Emoji picker for your command line

  • nixos-unstable -

pkgs.cosmocc

Compilers for Cosmopolitan C/C++ programs

  • nixos-unstable -

pkgs.mockgen

Mocking framework for the Go programming language

  • nixos-unstable -

pkgs.mockoon

Easiest and quickest way to run mock APIs locally

  • nixos-unstable -

pkgs.teamocil

Simple tool used to automatically create windows and panes in tmux with YAML files

  • nixos-unstable -

pkgs.umockdev

Mock hardware devices for creating unit tests

  • nixos-unstable -

pkgs.wiremock

Flexible tool for building mock APIs

  • nixos-unstable -

pkgs.uhttpmock

Project for mocking web service APIs which use HTTP or HTTPS

  • nixos-unstable -

pkgs.go-mockery

Mock code autogenerator for Golang

  • nixos-unstable -

pkgs.go-minimock

Golang mock generator from interfaces

  • nixos-unstable -

pkgs.mockobjects

Generic unit testing framework and methodology for testing any kind of code

  • nixos-unstable -

pkgs.libqtdbusmock

Library for mocking DBus interactions using Qt

  • nixos-unstable -

pkgs.uhttpmock_1_0

Project for mocking web service APIs which use HTTP or HTTPS

  • nixos-unstable -

pkgs.rtl-sdr-osmocom

Software to turn the RTL2832U into a SDR receiver

  • nixos-unstable -

pkgs.gnomeExtensions.mock-tray

Creates an invisible system tray (TopIcons) for apps (like MEGAsync) that won't run properly without one.

  • nixos-unstable -
    • nixpkgs-unstable 4

pkgs.python312Packages.pymochad

Python library for sending commands to the mochad TCP gateway daemon for the X10 CMA15A controller

  • nixos-unstable -

pkgs.python313Packages.pymochad

Python library for sending commands to the mochad TCP gateway daemon for the X10 CMA15A controller

  • nixos-unstable -

Package maintainers

Untriaged
created 4 months, 3 weeks ago
Mock: privilege escalation for users that can access mock configuration

The Mock software contains a vulnerability wherein an attacker could potentially exploit privilege escalation, enabling the execution of arbitrary code with root user privileges. This weakness stems from the absence of proper sandboxing during the expansion and execution of Jinja2 templates, which may be included in certain configuration parameters. While the Mock documentation advises treating users added to the mock group as privileged, certain build systems invoking mock on behalf of users might inadvertently permit less privileged users to define configuration tags. These tags could then be passed as parameters to mock during execution, potentially leading to the utilization of Jinja2 templates for remote privilege escalation and the execution of arbitrary code as the root user on the build server.

Affected products

mock

Matching in nixpkgs

pkgs.cmocka

Lightweight library to simplify and generalize unit tests for C

  • nixos-unstable -

pkgs.mockgen

Mocking framework for the Go programming language

  • nixos-unstable -

pkgs.mockoon

Easiest and quickest way to run mock APIs locally

  • nixos-unstable -

pkgs.umockdev

Mock hardware devices for creating unit tests

  • nixos-unstable -

pkgs.wiremock

Flexible tool for building mock APIs

  • nixos-unstable -

pkgs.uhttpmock

Project for mocking web service APIs which use HTTP or HTTPS

  • nixos-unstable -

pkgs.go-mockery

Mock code autogenerator for Golang

  • nixos-unstable -

pkgs.go-minimock

Golang mock generator from interfaces

  • nixos-unstable -

pkgs.mockobjects

Generic unit testing framework and methodology for testing any kind of code

  • nixos-unstable -

pkgs.libqtdbusmock

Library for mocking DBus interactions using Qt

  • nixos-unstable -

pkgs.uhttpmock_1_0

Project for mocking web service APIs which use HTTP or HTTPS

  • nixos-unstable -

pkgs.gnomeExtensions.mock-tray

Creates an invisible system tray (TopIcons) for apps (like MEGAsync) that won't run properly without one.

  • nixos-unstable -
    • nixpkgs-unstable 4

Package maintainers