Nixpkgs Security Tracker

Login with GitHub

Automatically generated suggestions

to slate a suggestion for refinement.

to mark a suggestion as irrelevant and log the reason.

View:
Compact
Detailed
created 1 month, 1 week ago
trytond 2.4: ModelView.button fails to validate authorization

trytond 2.4: ModelView.button fails to validate authorization

References

Affected products

trytond
  • ==≤ 2.4

Matching in nixpkgs

Package maintainers

created 1 month, 1 week ago
foomatic-rip filter v4.0.12 and prior used insecurely creates temporary files …

foomatic-rip filter v4.0.12 and prior used insecurely creates temporary files for storage of PostScript data by rendering the data when the debug mode was enabled. This flaw may be exploited by a local attacker to conduct symlink attacks by overwriting arbitrary files accessible with the privileges of the user running the foomatic-rip universal print filter.

References

Affected products

foomatic-filters
  • ==4.0.12 and prior

Matching in nixpkgs

Package maintainers

Permalink CVE-2010-3872
7.5 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): NONE
  • Integrity impact (I): NONE
  • Availability impact (A): HIGH
created 1 month, 1 week ago
Httpd: mod_fcgid: stack-based buffer overflow in fcgid_header_bucket_read() in modules/fcgid/fcgid_bucket.c

A flaw was found in the mod_fcgid module of httpd. A malformed FastCGI response may result in a stack-based buffer overflow in the modules/fcgid/fcgid_bucket.c file in the fcgid_header_bucket_read() function, resulting in an application crash.

References

Affected products

mod_fcgid
  • ==2.3.6

Matching in nixpkgs

Package maintainers

created 1 month, 1 week ago
nginx http proxy module does not verify peer identity of …

nginx http proxy module does not verify peer identity of https origin server which could facilitate man-in-the-middle attack (MITM)

References

Affected products

nginx
  • ==through 1.6.2

Matching in nixpkgs

pkgs.nginxQuic

Reverse proxy and lightweight webserver

created 1 month, 1 week ago
An unchecked sscanf() call in ettercap before 0.7.5 allows an …

An unchecked sscanf() call in ettercap before 0.7.5 allows an insecure temporary settings file to overflow a static-sized buffer on the stack.

Affected products

ettercap
  • ==0.7.3

Matching in nixpkgs

Package maintainers

created 1 month, 1 week ago
Yubico PAM Module before 2.10 performed user authentication when 'use_first_pass' …

Yubico PAM Module before 2.10 performed user authentication when 'use_first_pass' PAM configuration option was not used and the module was configured as 'sufficient' in the PAM configuration. A remote attacker could use this flaw to circumvent common authentication process and obtain access to the account in question by providing a NULL value (pressing Ctrl-D keyboard sequence) as the password string.

Affected products

yubico-pam
  • ==before 2.10

Matching in nixpkgs

created 1 month, 1 week ago
Transmission before 1.92 allows an attacker to cause a denial …

Transmission before 1.92 allows an attacker to cause a denial of service (crash) or possibly have other unspecified impact via a large number of tr arguments in a magnet link.

References

Affected products

transmission
  • ==before 1.92

Matching in nixpkgs

pkgs.transmission_3

Fast, easy and free BitTorrent client (deprecated version 3)

pkgs.libtransmission_3

Fast, easy and free BitTorrent client (deprecated version 3)

pkgs.transmission_3-qt

Fast, easy and free BitTorrent client (deprecated version 3)

Package maintainers

created 1 month, 1 week ago
NetworkManager 0.9 and earlier allows local users to use other …

NetworkManager 0.9 and earlier allows local users to use other users' certificates or private keys when making a connection via the file path when adding a new connection.

References

Affected products

NetworkManager
  • ==0.9 and earlier

Matching in nixpkgs

created 1 month, 1 week ago
In ConsoleKit before 0.4.2, an intended security policy restriction bypass …

In ConsoleKit before 0.4.2, an intended security policy restriction bypass was found. This flaw allows an authenticated system user to escalate their privileges by initiating a remote VNC session.

Affected products

consolekit
  • ==before 0.4.2

Matching in nixpkgs

Package maintainers

created 1 month, 1 week ago
PostfixAdmin 2.3.4 has multiple XSS vulnerabilities

PostfixAdmin 2.3.4 has multiple XSS vulnerabilities

References

Affected products

postfixadmin
  • ==2.3.4

Matching in nixpkgs

Package maintainers