Nixpkgs Security Tracker

Login with GitHub

Automatically generated suggestions

to slate a suggestion for refinement.

to mark a suggestion as irrelevant and log the reason.

View:
Compact
Detailed
created 1 month ago
tuned 2.10.0 creates its PID file with insecure permissions which …

tuned 2.10.0 creates its PID file with insecure permissions which allows local users to kill arbitrary processes.

Affected products

tuned
  • ==2.10.0-1

Matching in nixpkgs

Package maintainers

created 1 month ago
WebKit in Google Chrome before Blink M11 and M12 does …

WebKit in Google Chrome before Blink M11 and M12 does not properly handle counter nodes, which allows remote attackers to cause a denial of service (memory corruption).

Affected products

Chrome
  • ==before Blink M11 and M12

Matching in nixpkgs

pkgs.netflix

Open Netflix in Google Chrome app mode

  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small
  • nixos-25.11 -
    • nixos-25.11-small
    • nixpkgs-25.11-darwin
created 1 month ago
The AX.25 daemon (ax25d) in ax25-tools before 0.0.8-13 does not …

The AX.25 daemon (ax25d) in ax25-tools before 0.0.8-13 does not check the return value of a setuid call. The setuid call is responsible for dropping privileges but if the call fails the daemon would continue to run with root privileges which can allow possible privilege escalation.

Affected products

ax25-tools
  • ==before 0.0.8-13

Matching in nixpkgs

Package maintainers

created 1 month ago
mom creates world-writable pid files in /var/run

mom creates world-writable pid files in /var/run

References

Affected products

mom
  • ==through 2012-10-05

Matching in nixpkgs

Package maintainers

created 1 month ago
simplesamlphp before 1.6.3 (squeeze) and before 1.8.2 (sid) incorrectly handles …

simplesamlphp before 1.6.3 (squeeze) and before 1.8.2 (sid) incorrectly handles XML encryption which could allow remote attackers to decrypt or forge messages.

Affected products

simplesamlphp
  • ==1.13.1-2

Matching in nixpkgs

pkgs.simplesamlphp

SimpleSAMLphp is an application written in native PHP that deals with authentication (SQL, .htpasswd, YubiKey, LDAP, PAPI, Radius)

Package maintainers

created 1 month ago
MediaWiki before 1.18.5, and 1.19.x before 1.19.2 saves passwords in …

MediaWiki before 1.18.5, and 1.19.x before 1.19.2 saves passwords in the local database, (1) which could make it easier for context-dependent attackers to obtain cleartext passwords via a brute-force attack or, (2) when an authentication plugin returns a false in the strict function, could allow remote attackers to use old passwords for non-existing accounts in an external authentication system via unspecified vectors.

References

Affected products

MediaWiki
  • ==before 1.18.5
  • ==1.19.x before 1.19.2

Matching in nixpkgs

Package maintainers

created 1 month ago
Use after free vulnerability exists in WebKit in Google Chrome …

Use after free vulnerability exists in WebKit in Google Chrome before Blink M12 in RenderLayerwhen removing elements with reflections.

Affected products

Chrome
  • ==before Blink M12

Matching in nixpkgs

pkgs.netflix

Open Netflix in Google Chrome app mode

  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small
  • nixos-25.11 -
    • nixos-25.11-small
    • nixpkgs-25.11-darwin
created 1 month ago
NULL pointer dereference vulnerability in ZNC before 0.092 caused by …

NULL pointer dereference vulnerability in ZNC before 0.092 caused by traffic stats when there are unauthenticated connections.

Affected products

znc
  • ==before 0.092

Matching in nixpkgs

Package maintainers

updated 1 month ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed
    10 packages
    • jenkins-job-builder
    • python312Packages.jenkinsapi
    • python313Packages.jenkinsapi
    • python314Packages.jenkinsapi
    • python312Packages.python-jenkins
    • python313Packages.python-jenkins
    • python314Packages.python-jenkins
    • python312Packages.jenkins-job-builder
    • python313Packages.jenkins-job-builder
    • python314Packages.jenkins-job-builder
Jenkins main before 1.482 and LTS before 1.466.2 allows remote …

Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers with read access and HTTP access to Jenkins master to insert data and execute arbitrary code.

Affected products

jenkins
  • ==1.447.2

Matching in nixpkgs

Ignored packages (10)

Package maintainers

created 1 month ago
Google Chrome before 3.0 does not properly handle XML documents, …

Google Chrome before 3.0 does not properly handle XML documents, which allows remote attackers to obtain sensitive information via a crafted web site.

Affected products

Chrome
  • ==before 3.0

Matching in nixpkgs

pkgs.netflix

Open Netflix in Google Chrome app mode

  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small
  • nixos-25.11 -
    • nixos-25.11-small
    • nixpkgs-25.11-darwin