Nixpkgs security tracker

Login with GitHub

Dismissed suggestions

These automatic suggestions were dismissed after initial triaging.

to select a suggestion for revision.

View:
Compact
Detailed
Permalink CVE-2003-0063
7.3 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): Low (L)
updated 5 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    3 packages
    • fontxfree86type1
    • font-xfree86-type1
    • xorg.fontxfree86type1
  • @LeSuisse dismissed
The xterm terminal emulator in XFree86 4.2.0 and earlier allows …

The xterm terminal emulator in XFree86 4.2.0 and earlier allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.

References

Affected products

n/a
  • ==n/a
xfree86
  • =<4.2.0
Ignored packages (3)
Old issue. No impact on current stable branch.
Permalink CVE-2026-2531
6.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): Low (L)
  • Exploit Code Maturity (E): Proof-of-Concept (P)
  • Remediation Level (RL): Official Fix (O)
  • Report Confidence (RC): Confirmed (C)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): Low (L)
updated 5 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    3 packages
    • python312Packages.mindsdb-evaluator
    • python313Packages.mindsdb-evaluator
    • python314Packages.mindsdb-evaluator
  • @LeSuisse dismissed
MindsDB File Upload security.py clear_filename server-side request forgery

A security vulnerability has been detected in MindsDB up to 25.14.1. This vulnerability affects the function clear_filename of the file mindsdb/utilities/security.py of the component File Upload. Such manipulation leads to server-side request forgery. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The name of the patch is 74d6f0fd4b630218519a700fbee1c05c7fd4b1ed. It is best practice to apply a patch to resolve this issue.

Affected products

MindsDB
  • ==25.14.0
  • ==25.14.1
Ignored packages (3)
mindsdb/mindsdb is not present in nixpkgs.
updated 5 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    45 packages
    • tests.hardeningFlags.sfa1StdenvUnsupp
    • tests.hardeningFlags.sfa3StdenvUnsupp
    • tests.hardeningFlags.fortifyStdenvUnsupp
    • tests.hardeningFlags.lchFastStdenvUnsupp
    • tests.hardeningFlags-gcc.sfa1StdenvUnsupp
    • tests.hardeningFlags-gcc.sfa3StdenvUnsupp
    • tests.hardeningFlags.fortify3StdenvUnsupp
    • tests.hardeningFlags-clang.sfa1StdenvUnsupp
    • tests.hardeningFlags-clang.sfa3StdenvUnsupp
    • tests.hardeningFlags-gcc.fortifyStdenvUnsupp
    • tests.hardeningFlags-gcc.fortify3StdenvUnsupp
    • tests.hardeningFlags-clang.fortifyStdenvUnsupp
    • tests.hardeningFlags-clang.lchFastStdenvUnsupp
    • tests.hardeningFlags-clang.fortify3StdenvUnsupp
    • tests.hardeningFlags.stackProtectorStdenvUnsupp
    • tests.hardeningFlags.glibcxxassertionsStdenvUnsupp
    • tests.hardeningFlags-gcc.stackProtectorStdenvUnsupp
    • tests.hardeningFlags.sfa1StdenvUnsuppUnsupportsSfa3
    • tests.hardeningFlags-clang.stackProtectorStdenvUnsupp
    • tests.hardeningFlags.sfa3StdenvUnsuppDoesntUnsuppSfa1
    • tests.hardeningFlags.stackClashProtectionStdenvUnsupp
    • tests.hardeningFlags-gcc.glibcxxassertionsStdenvUnsupp
    • tests.hardeningFlags-gcc.sfa1StdenvUnsuppUnsupportsSfa3
    • tests.hardeningFlags-clang.glibcxxassertionsStdenvUnsupp
    • tests.hardeningFlags-clang.sfa1StdenvUnsuppUnsupportsSfa3
    • tests.hardeningFlags-gcc.sfa3StdenvUnsuppDoesntUnsuppSfa1
    • tests.hardeningFlags-gcc.stackClashProtectionStdenvUnsupp
    • tests.hardeningFlags.fortifyStdenvUnsuppUnsupportsFortify3
    • tests.hardeningFlags-clang.sfa3StdenvUnsuppDoesntUnsuppSfa1
    • tests.hardeningFlags-clang.stackClashProtectionStdenvUnsupp
    • tests.hardeningFlags.fortify3StdenvUnsuppDoesntUnsuppFortify1
    • tests.hardeningFlags.sfa3StdenvUnsuppDoesntUnsuppSfa1ExecTest
    • tests.hardeningFlags-gcc.fortifyStdenvUnsuppUnsupportsFortify3
    • tests.hardeningFlags.lchFastStdenvUnsuppUnsupportsLchExtensive
    • tests.hardeningFlags-clang.fortifyStdenvUnsuppUnsupportsFortify3
    • tests.hardeningFlags-gcc.fortify3StdenvUnsuppDoesntUnsuppFortify1
    • tests.hardeningFlags-gcc.sfa3StdenvUnsuppDoesntUnsuppSfa1ExecTest
    • tests.hardeningFlags-clang.fortify3StdenvUnsuppDoesntUnsuppFortify1
    • tests.hardeningFlags-clang.sfa3StdenvUnsuppDoesntUnsuppSfa1ExecTest
    • tests.hardeningFlags.lchExtensiveStdenvUnsuppDoesntUnsupportLchFast
    • tests.hardeningFlags-clang.lchFastStdenvUnsuppUnsupportsLchExtensive
    • tests.hardeningFlags.fortify3StdenvUnsuppDoesntUnsuppFortify1ExecTest
    • tests.hardeningFlags-clang.lchExtensiveStdenvUnsuppDoesntUnsupportLchFast
    • tests.hardeningFlags-gcc.fortify3StdenvUnsuppDoesntUnsuppFortify1ExecTest
    • tests.hardeningFlags-clang.fortify3StdenvUnsuppDoesntUnsuppFortify1ExecTest
  • @LeSuisse dismissed
Nvu 0.99+1.0pre uses an old copy of Mozilla XPCOM which …

Nvu 0.99+1.0pre uses an old copy of Mozilla XPCOM which can result in multiple security issues.

Affected products

Nvu
  • ==0.99+1.0pre
Ignored packages (45)
Old issue, no impact on the current stable branch.
Permalink CVE-1999-0084
8.4 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 5 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    15 packages
    • python312Packages.pynfsclient
    • perl538Packages.FileNFSLock
    • perl5Packages.FileNFSLock
    • perlPackages.FileNFSLock
    • mkinitcpio-nfs-utils
    • nfs-ganesha
    • nfs-utils
    • openfst
    • unfs3
    • libnfs
    • svnfs
    • nfstrace
    • unionfs-fuse
    • coqPackages.InfSeqExt
    • perl540Packages.FileNFSLock
  • @LeSuisse dismissed
Certain NFS servers allow users to use mknod to gain …

Certain NFS servers allow users to use mknod to gain privileges by creating a writable kmem device and setting the UID to 0.

References

Affected products

n/a
  • ==n/a
nfs
  • <4.1.3
Ignored packages (15)

pkgs.svnfs

FUSE filesystem for accessing Subversion repositories

  • nixos-unstable 0.4
    • nixpkgs-unstable 0.4
    • nixos-unstable-small 0.4

pkgs.unfs3

User-space NFSv3 file system server

pkgs.openfst

Library for working with finite-state transducers

pkgs.nfs-ganesha

NFS server that runs in user space

  • nixos-unstable 9.5
    • nixpkgs-unstable 9.5
    • nixos-unstable-small 9.5

pkgs.unionfs-fuse

FUSE UnionFS implementation

  • nixos-unstable 3.7
    • nixpkgs-unstable 3.7
    • nixos-unstable-small 3.7

pkgs.mkinitcpio-nfs-utils

ipconfig and nfsmount tools for root on NFS, ported from klibc

  • nixos-unstable 0.3
    • nixpkgs-unstable 0.3
    • nixos-unstable-small 0.3
Old issue. Unclear what was impacted but it is very unlikely something in the current stable branch is.
Permalink CVE-1999-0038
8.4 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 5 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored package xlockmore
  • @LeSuisse dismissed
Buffer overflow in xlock program allows local users to execute …

Buffer overflow in xlock program allows local users to execute commands as root.

Affected products

n/a
  • ==n/a
xlock
  • *
Ignored packages (1)

pkgs.xlockmore

Screen locker for the X Window System

  • nixos-unstable 5.87
    • nixpkgs-unstable 5.87
    • nixos-unstable-small 5.87
Old issue. Current stable branch was never impacted.
Permalink CVE-1999-0036
8.4 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 5 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored package mairix
  • @LeSuisse dismissed
IRIX login program with a nonzero LOCKOUT parameter allows creation …

IRIX login program with a nonzero LOCKOUT parameter allows creation or damage to files.

References

  • 990 x_refsource_OSVDBvdb-entryx_transferred
  • H-106 third-party-advisoryx_refsource_CIACgovernment-resourcex_transferred
  • 19970508-02-PX x_refsource_SGIvendor-advisoryx_transferred
  • sgi-lockout(557) x_refsource_XFvdb-entryx_transferred

Affected products

n/a
  • ==n/a
irix
  • ==5.1
  • ==6.0.1
  • ==5.0.1
  • ==5.2
  • ==5.3
  • ==6.3
  • ==6.1
  • ==6.2
  • ==5.0
  • ==6.4
  • ==6.0
  • ==5.1.1
Ignored packages (1)
Not present in nixpkgs. Old issue.
Permalink CVE-1999-0029
8.4 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 5 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored package mairix
  • @LeSuisse dismissed
root privileges via buffer overflow in ordist command on SGI …

root privileges via buffer overflow in ordist command on SGI IRIX systems.

Affected products

n/a
  • ==n/a
irix
  • *
Ignored packages (1)
Not present in nixpkgs. Old issue.
updated 5 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    40 packages
    • tests.hardeningFlags-clang.allExplicitDisabledShadowStack
    • tests.hardeningFlags-clang.shadowStackExplicitDisabled
    • tests.hardeningFlags-clang.shadowStackExplicitEnabled
    • tests.hardeningFlags.allExplicitDisabledShadowStack
    • tests.hardeningFlags-gcc.shadowStackExplicitEnabled
    • tests.hardeningFlags.shadowStackExplicitEnabled
    • tests.hardeningFlags-gcc.shadowStackExplicitDisabled
    • tests.hardeningFlags.shadowStackExplicitDisabled
    • tests.hardeningFlags-gcc.allExplicitDisabledShadowStack
    • obs-studio-plugins.obs-stroke-glow-shadow
    • su
    • qsudo
    • sudo-rs
    • psudohash
    • shadowenv
    • shadowfox
    • sudo-font
    • shadow-tls
    • darwin.sudo
    • gnome-sudoku
    • doas-sudo-shim
    • lxqt.lxqt-sudo
    • go-shadowsocks2
    • shadowsocks-rust
    • yaziPlugins.sudo
    • shadowsocks-libev
    • libsForQt5.ksudoku
    • kdePackages.ksudoku
    • typstPackages.shadowed
    • plasma5Packages.ksudoku
    • shadowsocks-v2ray-plugin
    • fishPlugins.plugin-sudope
    • haskellPackages.shadowsocks
    • typstPackages.shadowed_0_1_0
    • shadow
    • haskellPackages.Unixutils-shadow
    • wayfirePlugins.wayfire-shadows
    • typstPackages.shadowed_0_2_0
    • typstPackages.shadowed_0_1_2
    • typstPackages.shadowed_0_1_1
  • @LeSuisse restored package shadow
  • @LeSuisse dismissed
There is a possible tty hijacking in shadow 4.x before …

There is a possible tty hijacking in shadow 4.x before 4.1.5 and sudo 1.x before 1.7.4 via "su - user -c program". The user session can be escaped to the parent session by using the TIOCSTI ioctl to push characters into the input buffer to be read by the next process.

Affected products

sudo
  • ==1.x before 1.7.4
shadow
  • ==4.x before 4.1.5

Matching in nixpkgs

pkgs.shadow

Suite containing authentication-related tools such as passwd and su

Ignored packages (39)

pkgs.su

Suite containing authentication-related tools such as passwd and su

pkgs.sudo-rs

Memory safe implementation of sudo and su

pkgs.psudohash

Password list generator for orchestrating brute force attacks and cracking hashes

pkgs.shadowenv

Reversible directory-local environment variable manipulations

pkgs.shadowfox

Universal dark theme for Firefox while adhering to the modern design principles set by Mozilla

pkgs.sudo-font

Font for programmers and command line users

  • nixos-unstable 3.4
    • nixpkgs-unstable 3.4
    • nixos-unstable-small 3.4

pkgs.shadow-tls

Proxy to expose real tls handshake to the firewall

pkgs.gnome-sudoku

Test your logic skills in this number grid puzzle

  • nixos-unstable 49.4
    • nixpkgs-unstable 49.4
    • nixos-unstable-small 49.4

Package maintainers

Old issue. Never impacted the current stable branch.
Permalink CVE-1999-0039
7.3 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): Low (L)
updated 5 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored package mairix
  • @LeSuisse dismissed
webdist CGI program (webdist.cgi) in SGI IRIX allows remote attackers …

webdist CGI program (webdist.cgi) in SGI IRIX allows remote attackers to execute arbitrary commands via shell metacharacters in the distloc parameter.

References

  • 19970501-02-PX x_refsource_SGIvendor-advisoryx_transferred
  • http-sgi-webdist(333) x_refsource_XFvdb-entryx_transferred
  • CA-1997-12 third-party-advisoryx_refsource_CERTx_transferred
  • 374 x_refsource_BIDvdb-entryx_transferred
  • 235 x_refsource_OSVDBvdb-entryx_transferred

Affected products

n/a
  • ==n/a
irix
  • ==0
Ignored packages (1)
Not present in nixpkgs. Old issue.
Permalink CVE-1999-0059
7.3 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): Low (L)
updated 5 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored package mairix
  • @LeSuisse dismissed
IRIX fam service allows an attacker to obtain a list …

IRIX fam service allows an attacker to obtain a list of all files on the server.

References

  • 164 x_refsource_OSVDBvdb-entryx_transferred
  • 353 x_refsource_BIDvdb-entryx_transferred
  • irix-fam(325) x_refsource_XFvdb-entryx_transferred

Affected products

n/a
  • ==n/a
irix
  • ==5.3
  • ==6.3
  • ==6.1
  • ==6.2
Ignored packages (1)
Not present in nixpkgs. Old issue.