Nixpkgs security tracker

Login with GitHub

Dismissed suggestions

These automatic suggestions were dismissed after initial triaging.

to select a suggestion for revision.

View:
Compact
Detailed
updated 5 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    6 packages
    • python312Packages.openshift
    • python313Packages.openshift
    • python314Packages.openshift
    • python312Packages.azure-mgmt-redhatopenshift
    • python313Packages.azure-mgmt-redhatopenshift
    • python314Packages.azure-mgmt-redhatopenshift
  • @LeSuisse dismissed
OpenShift: Install script has temporary file creation vulnerability which can …

OpenShift: Install script has temporary file creation vulnerability which can result in arbitrary code execution

References

Affected products

OpenShift
  • ==through 2014-01-21

Matching in nixpkgs

Ignored packages (6)

Package maintainers

Current stable branch was never impacted.

https://github.com/NixOS/nixpkgs/commit/ce3dd652234318508da37f8cbc7d69ace7b098ef
Permalink CVE-2024-9453
6.5 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
updated 5 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    8 packages
    • jenkins
    • jenkins-job-builder
    • python312Packages.jenkinsapi
    • python313Packages.jenkinsapi
    • python312Packages.python-jenkins
    • python313Packages.python-jenkins
    • python312Packages.jenkins-job-builder
    • python313Packages.jenkins-job-builder
  • @LeSuisse dismissed
Jenkins-image: sensitive data disclosure when using openshift jenkins image

A vulnerability was found in Red Hat OpenShift Jenkins. The bearer token is not obfuscated in the logs and potentially carries a high risk if those logs are centralized when collected. The token is typically valid for one year. This flaw allows a malicious user to jeopardize the environment if they have access to sensitive information.

References

Affected products

jenkins
openshift-sync-plugin
  • <1.1.0.818.v3883b_3b_df89a_
Ignored packages (8)

pkgs.jenkins

Extendable open source continuous integration server

  • nixos-unstable -

pkgs.jenkins-job-builder

Jenkins Job Builder is a system for configuring Jenkins jobs using simple YAML files stored in Git

  • nixos-unstable -
Not present in nixpkgs
updated 5 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored package owncloud-client
  • @LeSuisse dismissed
Cross-site scripting (XSS) vulnerability in ownCloud 4.5.5, 4.0.10, and earlier …

Cross-site scripting (XSS) vulnerability in ownCloud 4.5.5, 4.0.10, and earlier allows remote attackers to inject arbitrary web script or HTML via the action parameter to core/ajax/sharing.php.

Affected products

ownCloud
  • ==4.5.5
  • ==4.0.10
  • ==and earlier
Ignored packages (1)

pkgs.owncloud-client

Synchronise your ownCloud with your computer using this desktop client

Not present in nixpkgs
updated 5 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    5 packages
    • runzip
    • ripunzip
    • unzipNLS
    • haskellPackages.unzip-traversable
    • haskellPackages.wai-middleware-gunzip
  • @LeSuisse dismissed
The NEEDBITS macro in the inflate_dynamic function in inflate.c for …

The NEEDBITS macro in the inflate_dynamic function in inflate.c for unzip can be invoked using invalid buffers, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors that trigger a free of uninitialized or previously-freed data.

References

Affected products

n/a
  • ==n/a
unzip
  • <6.0

Matching in nixpkgs

pkgs.unzip

Extraction utility for archives compressed in .zip format

  • nixos-unstable -
    • nixpkgs-unstable 6.0
Ignored packages (5)

pkgs.runzip

Tool to convert filename encoding inside a ZIP archive

  • nixos-unstable -
    • nixpkgs-unstable 1.4

pkgs.ripunzip

Tool to unzip files in parallel

  • nixos-unstable -

pkgs.unzipNLS

Extraction utility for archives compressed in .zip format

  • nixos-unstable -
    • nixpkgs-unstable 6.0

Package maintainers

Current stable branch was never impacted

https://github.com/NixOS/nixpkgs/commit/672d3856df5d0e0e5bd5053e59cd5925b85e9f4a
updated 5 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    5 packages
    • ripunzip
    • unzipNLS
    • haskellPackages.unzip-traversable
    • haskellPackages.wai-middleware-gunzip
    • runzip
  • @LeSuisse dismissed
Heap-based buffer overflow in the test_compr_eb function in Info-ZIP UnZip …

Heap-based buffer overflow in the test_compr_eb function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command.

References

Affected products

UnZip
  • ==6.0 and earlier

Matching in nixpkgs

pkgs.unzip

Extraction utility for archives compressed in .zip format

  • nixos-unstable 6.0
    • nixpkgs-unstable 6.0
    • nixos-unstable-small 6.0
Ignored packages (5)

pkgs.runzip

Tool to convert filename encoding inside a ZIP archive

  • nixos-unstable 1.4
    • nixpkgs-unstable 1.4
    • nixos-unstable-small 1.4

pkgs.ripunzip

Tool to unzip files in parallel

pkgs.unzipNLS

Extraction utility for archives compressed in .zip format

  • nixos-unstable 6.0
    • nixpkgs-unstable 6.0
    • nixos-unstable-small 6.0

Package maintainers

Current stable branch was never impacted

https://github.com/NixOS/nixpkgs/commit/173f41cf0bc618f0b2c313b1915fee8d8a6d0ee2
updated 5 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    5 packages
    • runzip
    • ripunzip
    • unzipNLS
    • haskellPackages.unzip-traversable
    • haskellPackages.wai-middleware-gunzip
  • @LeSuisse dismissed
Heap-based buffer overflow in the getZip64Data function in Info-ZIP UnZip …

Heap-based buffer overflow in the getZip64Data function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command.

References

Affected products

UnZip
  • ==6.0 and earlier

Matching in nixpkgs

pkgs.unzip

Extraction utility for archives compressed in .zip format

  • nixos-unstable 6.0
    • nixpkgs-unstable 6.0
    • nixos-unstable-small 6.0
Ignored packages (5)

pkgs.runzip

Tool to convert filename encoding inside a ZIP archive

  • nixos-unstable 1.4
    • nixpkgs-unstable 1.4
    • nixos-unstable-small 1.4

pkgs.ripunzip

Tool to unzip files in parallel

pkgs.unzipNLS

Extraction utility for archives compressed in .zip format

  • nixos-unstable 6.0
    • nixpkgs-unstable 6.0
    • nixos-unstable-small 6.0

Package maintainers

Current stable branch was never impacted

https://github.com/NixOS/nixpkgs/commit/173f41cf0bc618f0b2c313b1915fee8d8a6d0ee2
updated 5 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    5 packages
    • runzip
    • ripunzip
    • unzipNLS
    • haskellPackages.unzip-traversable
    • haskellPackages.wai-middleware-gunzip
  • @LeSuisse dismissed
Heap-based buffer overflow in the CRC32 verification in Info-ZIP UnZip …

Heap-based buffer overflow in the CRC32 verification in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command.

References

Affected products

UnZip
  • ==6.0 and earlier

Matching in nixpkgs

pkgs.unzip

Extraction utility for archives compressed in .zip format

  • nixos-unstable 6.0
    • nixpkgs-unstable 6.0
    • nixos-unstable-small 6.0
Ignored packages (5)

pkgs.runzip

Tool to convert filename encoding inside a ZIP archive

  • nixos-unstable 1.4
    • nixpkgs-unstable 1.4
    • nixos-unstable-small 1.4

pkgs.ripunzip

Tool to unzip files in parallel

pkgs.unzipNLS

Extraction utility for archives compressed in .zip format

  • nixos-unstable 6.0
    • nixpkgs-unstable 6.0
    • nixos-unstable-small 6.0

Package maintainers

Current stable branch was never impacted

https://github.com/NixOS/nixpkgs/commit/173f41cf0bc618f0b2c313b1915fee8d8a6d0ee2
Permalink CVE-1999-0022
7.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 5 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    3 packages
    • aixlog
    • mairix
    • tests.fetchgit.describe-tag
  • @LeSuisse dismissed
Local user gains root privileges via buffer overflow in rdist, …

Local user gains root privileges via buffer overflow in rdist, via expstr() function.

References

  • 00179 x_refsource_SUNvendor-advisoryx_transferred

Affected products

aix
  • ==3.2.4
  • ==4.1.4
  • ==3.1
  • ==4.1.5
  • ==4.2
  • ==4.1.3
  • ==3.2
  • ==4.1
  • ==4.1.2
  • ==4.1.1
  • ==3.2.5
n/a
  • ==n/a
irix
  • ==5.1
  • ==6.0.1
  • ==5.0.1
  • ==5.2
  • ==5.3
  • ==6.3
  • ==6.1
  • ==6.2
  • ==5.0
  • ==6.4
  • ==6.0
  • ==5.1.1
hp-ux
  • ==10.00
sunos
  • ==5.1
  • ==5.4
  • ==5.2
  • ==5.3
  • ==4.1.2
  • ==5.0
  • ==4.1.1
  • ==4.1.3u1
bsd_os
  • ==1.1
freebsd
  • ==2.0.5
  • ==2.0
  • ==2.1.0
solaris
  • ==4.1.3
Ignored packages (3)

pkgs.aixlog

Header-only C++ logging library

Old issue. Impacted packages not present in nixpkgs.
updated 5 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    12 packages
    • mutter
    • neomutt
    • mutt-ics
    • mutter46
    • mutter48
    • mutt-wizard
    • fontmuttmisc
    • notmuch-mutt
    • font-mutt-misc
    • pantheon.mutter
    • xorg.fontmuttmisc
    • vimPlugins.nvim-treesitter-parsers.muttrc
  • @LeSuisse dismissed
Mutt before 1.5.20 patch 7 allows an attacker to cause …

Mutt before 1.5.20 patch 7 allows an attacker to cause a denial of service via a series of requests to mutt temporary files.

Affected products

mutt
  • ==before 1.5.20-7

Matching in nixpkgs

pkgs.mutt

Small but very powerful text-based mail client

Ignored packages (12)

pkgs.mutter

Window manager for GNOME

  • nixos-unstable 49.3
    • nixpkgs-unstable 49.4
    • nixos-unstable-small 49.4

pkgs.mutt-ics

Tool to show calendar event details in Mutt

pkgs.mutter48

Window manager for GNOME

  • nixos-unstable 48.7
    • nixpkgs-unstable 48.7
    • nixos-unstable-small 48.7

pkgs.mutt-wizard

System for automatically configuring mutt and isync

Package maintainers

Old issue. No impact on current stable branch.
Permalink CVE-2004-2154
9.8 CRITICAL
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 5 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    68 packages
    • apcupsd
    • cups-bjnp
    • cups-dymo
    • carps-cups
    • cups-zj-58
    • cups-browsed
    • cups-filters
    • cups-kyocera
    • cups-printers
    • gutenprintBin
    • cups-kyodialog
    • cups-pk-helper
    • gutenprint-bin
    • libcupsfilters
    • canon-cups-ufr2
    • cups-idprt-tspl
    • cups-pdf-to-pdf
    • cups-idprt-mt888
    • cups-idprt-mt890
    • cups-idprt-sp900
    • cups-idprt-barcode
    • brgenml1cupswrapper
    • mfc465cncupswrapper
    • cups-brother-dcpt310
    • cups-toshiba-estudio
    • dcp375cw-cupswrapper
    • mfc5890cncupswrapper
    • mfcj880dwcupswrapper
    • perlPackages.NetCUPS
    • mfc9140cdncupswrapper
    • mfcj470dw-cupswrapper
    • mfcl2700dncupswrapper
    • mfcl2720dwcupswrapper
    • mfcl2740dwcupswrapper
    • perl5Packages.NetCUPS
    • magicard-cups-driver
    • cups-brother-dcpt725dw
    • cups-brother-hl3170cdw
    • cups-brother-hll2350dw
    • cups-brother-hll2375dw
    • cups-kyocera-3500-4500
    • dcp9020cdw-cupswrapper
    • mfcj6510dw-cupswrapper
    • mfcl3770cdwcupswrapper
    • mfcl8690cdwcupswrapper
    • cups-brother-mfcl2710dw
    • cups-brother-mfcl2750dw
    • cups-brother-mfcl2800dw
    • perl538Packages.NetCUPS
    • perl540Packages.NetCUPS
    • cups-brother-dcp1610wlpr
    • cups-brother-dcpl3550cdw
    • python312Packages.pycups
    • python313Packages.pycups
    • python314Packages.pycups
    • mfcj470dwlpr.x86_64-linux
    • prometheus-apcupsd-exporter
    • cups-kyocera-ecosys-m552x-p502x
    • cups-brother-hl1110.x86_64-linux
    • cups-brother-hl1210w.x86_64-linux
    • cups-brother-hl2260d.x86_64-linux
    • cups-brother-hl3140cw.x86_64-linux
    • cups-brother-hll2340dw.x86_64-linux
    • home-assistant-component-tests.cups
    • cups-brother-hll3230cdw.x86_64-linux
    • home-assistant-component-tests.apcupsd
    • cups-kyocera-ecosys-m2x35-40-p2x35-40dnw
    • tests.home-assistant-component-tests.apcupsd
  • @LeSuisse dismissed
CUPS before 1.1.21rc1 treats a Location directive in cupsd.conf as …

CUPS before 1.1.21rc1 treats a Location directive in cupsd.conf as case sensitive, which allows attackers to bypass intended ACLs via a printer name containing uppercase or lowercase letters that are different from what is specified in the directive.

References

Affected products

n/a
  • ==n/a
cups
  • <1.1.21
ubuntu_linux
  • ==4.10

Matching in nixpkgs

pkgs.cups

Standards-based printing system for UNIX

Ignored packages (68)

pkgs.cups-bjnp

CUPS back-end for Canon printers

pkgs.cups-browsed

Daemon for browsing the Bonjour broadcasts of shared, remote CUPS printers

pkgs.cups-filters

Backends, filters, and other software that was once part of the core CUPS distribution but is no longer maintained by Apple Inc

pkgs.cups-kyocera

CUPS drivers for several Kyocera FS-{1020,1025,1040,1060,1120,1125} printers

pkgs.gutenprintBin

Some additional CUPS drivers including Canon drivers

pkgs.cups-pk-helper

PolicyKit helper to configure cups with fine-grained privileges

pkgs.gutenprint-bin

Some additional CUPS drivers including Canon drivers

pkgs.libcupsfilters

Backends, filters, and other software that was once part of the core CUPS distribution but is no longer maintained by Apple Inc

pkgs.cups-idprt-tspl

CUPS drivers for TSPL-based iDPRT thermal label printers (SP210, SP310, SP320, SP320E, SP410, SP410BT, SP420, SP450, SP460BT)

pkgs.cups-idprt-barcode

CUPS drivers for iDPRT barcode printers (iD2P, iD2X, iD4P, iD4S, iE2P, iE2X, iE4P, iE4S, iT4B, iT4E, iT4P, iT4S, iT4X, iX4E, iX4L, iX4P, iX4E, iX6P)

Old issue. No impact on current stable branch.