Nixpkgs security tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Automatically generated suggestions

to slate a suggestion for refinement.

to mark a suggestion as irrelevant and log the reason.

View:
Compact
Detailed
created 2 months ago Activity log
  • Created suggestion
Missing verification of host key for kdump server

The kdump implementation is missing the host key verification in the kdump and mkdumprd OpenSSH integration of kdump prior to version 2012-01-20. This is similar to CVE-2011-3588, but different in that the kdump implementation is specific to SUSE. A remote malicious kdump server could use this flaw to impersonate the correct kdump server to obtain security sensitive information (kdump core files).

References

Affected products

kdump
  • <2012-01-20

Matching in nixpkgs

pkgs.slackdump

Tools for saving Slack's data without admin privileges

Package maintainers

created 2 months ago Activity log
  • Created suggestion
An issue exists in WebKit in Google Chrome before Blink …

An issue exists in WebKit in Google Chrome before Blink M12. when clearing lists in AnimationControllerPrivate that signal when a hardware animation starts.

References

Affected products

Chrome
  • ==before Blink M12

Matching in nixpkgs

pkgs.netflix

Open Netflix in Google Chrome app mode

  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small
  • nixos-25.11 -
    • nixos-25.11-small
    • nixpkgs-25.11-darwin

pkgs.chrome-export

Scripts to save Google Chrome's bookmarks and history as HTML bookmarks files

pkgs.go-chromecast

CLI for Google Chromecast, Home devices and Cast Groups

created 2 months ago Activity log
  • Created suggestion
Cross-site scripting (XSS) vulnerability in the Smiley module 6.x-1.x versions …

Cross-site scripting (XSS) vulnerability in the Smiley module 6.x-1.x versions prior to 6.x-1.1 and Smileys module 6.x-1.x versions prior to 6.x-1.1 for Drupal allows remote authenticated users with the "administer smiley" permission to inject arbitrary web script or HTML via a smiley acronym.

References

Affected products

Smiley
  • ==6.x-1.x versions prior to 6.x-1.1
Smileys
  • ==6.x-1.x versions prior to 6.x-1.1

Matching in nixpkgs

pkgs.smiley-sans

Condensed and oblique Chinese typeface seeking a visual balance between the humanist and the geometric

created 2 months ago Activity log
  • Created suggestion
PostfixAdmin 2.3.4 has multiple XSS vulnerabilities

PostfixAdmin 2.3.4 has multiple XSS vulnerabilities

Affected products

postfixadmin
  • ==2.3.4

Matching in nixpkgs

pkgs.postfixadmin

Web based virtual user administration interface for Postfix mail servers

Package maintainers

created 2 months ago Activity log
  • Created suggestion
OverlayFS in the Linux kernel before 3.0.0-16.28, as used in …

OverlayFS in the Linux kernel before 3.0.0-16.28, as used in Ubuntu 10.0.4 LTS and 11.10, is missing inode security checks which could allow attackers to bypass security restrictions and perform unauthorized actions.

References

Affected products

OverlayFS
  • ==as used in Ubuntu 10.0.4 LTS and 11.10
  • ==before 3.0.0-16.28

Matching in nixpkgs

Package maintainers

created 2 months ago Activity log
  • Created suggestion
Polipo before 1.0.4.1 suffers from a DoD vulnerability via specially-crafted …

Polipo before 1.0.4.1 suffers from a DoD vulnerability via specially-crafted HTTP POST / PUT request.

Affected products

polipo
  • ==before 1.0.4.1

Matching in nixpkgs

pkgs.polipo

Small and fast caching web proxy

Package maintainers

created 2 months ago Activity log
  • Created suggestion
xscreensaver before 5.14 crashes during activation and leaves the screen …

xscreensaver before 5.14 crashes during activation and leaves the screen unlocked when in Blank Only Mode and when DPMS is disabled, which allows local attackers to access resources without authentication.

Affected products

xscreensaver
  • ==before 5.14

Matching in nixpkgs

Package maintainers

created 2 months ago Activity log
  • Created suggestion
Tahoe-LAFS v1.3.0 through v1.8.2 could allow unauthorized users to delete …

Tahoe-LAFS v1.3.0 through v1.8.2 could allow unauthorized users to delete immutable files in some cases.

Affected products

Tahoe-LAFS
  • ==v1.3.0 through v1.8.2

Matching in nixpkgs

Package maintainers

created 2 months ago Activity log
  • Created suggestion
In ConsoleKit before 0.4.2, an intended security policy restriction bypass …

In ConsoleKit before 0.4.2, an intended security policy restriction bypass was found. This flaw allows an authenticated system user to escalate their privileges by initiating a remote VNC session.

Affected products

consolekit
  • ==before 0.4.2

Matching in nixpkgs

Package maintainers

created 2 months ago Activity log
  • Created suggestion
Moodle before 2.2.2: Course information leak via hidden courses being …

Moodle before 2.2.2: Course information leak via hidden courses being displayed in tag search results

Affected products

Moodle
  • ==2.1 to 2.1.4+
  • ==2.2 to 2.2.1+

Matching in nixpkgs

pkgs.moodle

Free and open-source learning management system (LMS) written in PHP

pkgs.moodle-dl

Moodle downloader that downloads course content fast from Moodle

Package maintainers