Nixpkgs security tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Automatically generated suggestions

to slate a suggestion for refinement.

to mark a suggestion as irrelevant and log the reason.

View:
Compact
Detailed
created 2 months ago Activity log
  • Created suggestion
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor …

vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.

Affected products

vsftpd
  • ==2.3.4 downloaded between 20110630 and 20110703

Matching in nixpkgs

Package maintainers

created 2 months ago Activity log
  • Created suggestion
WebKit in Google Chrome before Blink M11 and M12 does …

WebKit in Google Chrome before Blink M11 and M12 does not properly handle counter nodes, which allows remote attackers to cause a denial of service (memory corruption).

References

Affected products

Chrome
  • ==before Blink M11 and M12

Matching in nixpkgs

pkgs.netflix

Open Netflix in Google Chrome app mode

  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small
  • nixos-25.11 -
    • nixos-25.11-small
    • nixpkgs-25.11-darwin

pkgs.chrome-export

Scripts to save Google Chrome's bookmarks and history as HTML bookmarks files

pkgs.go-chromecast

CLI for Google Chromecast, Home devices and Cast Groups

created 2 months ago Activity log
  • Created suggestion
pithos before 0.3.5 allows overwrite of arbitrary files via symlinks.

pithos before 0.3.5 allows overwrite of arbitrary files via symlinks.

Affected products

pithos
  • ==before 0.3.5

Matching in nixpkgs

pkgs.pithos

Pandora Internet Radio player for GNOME

Package maintainers

created 2 months ago Activity log
  • Created suggestion
A denial of service flaw was found in the way …

A denial of service flaw was found in the way the server component of Freeciv before 2.3.4 processed certain packets. A remote attacker could send a specially-crafted packet that, when processed would lead to memory exhaustion or excessive CPU consumption.

Affected products

freeciv
  • ==before 2.3.4

Matching in nixpkgs

pkgs.freeciv

Multiplayer (or single player), turn-based strategy game

pkgs.freeciv_qt

Multiplayer (or single player), turn-based strategy game

pkgs.freeciv_gtk

Multiplayer (or single player), turn-based strategy game

pkgs.freeciv_sdl2

Multiplayer (or single player), turn-based strategy game

Package maintainers

created 2 months ago Activity log
  • Created suggestion
In klibc 1.5.20 and 1.5.21, the DHCP options written by …

In klibc 1.5.20 and 1.5.21, the DHCP options written by ipconfig to /tmp/net-$DEVICE.conf are not properly escaped. This may allow a remote attacker to send a specially crafted DHCP reply which could execute arbitrary code with the privileges of any process which sources DHCP options.

Affected products

klibc
  • ==1.5.21
  • ==1.5.20

Matching in nixpkgs

Package maintainers

created 2 months ago Activity log
  • Created suggestion
surf: cookie jar has read access from other local user

surf: cookie jar has read access from other local user

Affected products

surf
  • ==Fixed in 0.6

Matching in nixpkgs

pkgs.surf

Simple web browser based on WebKitGTK

pkgs.glsurf

Program to draw implicit surfaces and curves

pkgs.surfer

Extensible and Snappy Waveform Viewer

pkgs.surfraw

Provides a fast unix command line interface to a variety of popular WWW search engines and other artifacts of power

pkgs.surf-display

Kiosk browser session manager based on the surf browser

pkgs.netsurf.libcss

Cascading Style Sheets library for netsurf browser

pkgs.netsurf.libdom

Document Object Model library for netsurf browser

Package maintainers

created 2 months ago Activity log
  • Created suggestion
NetworkManager 0.9 and earlier allows local users to use other …

NetworkManager 0.9 and earlier allows local users to use other users' certificates or private keys when making a connection via the file path when adding a new connection.

Affected products

NetworkManager
  • ==0.9 and earlier

Matching in nixpkgs

created 2 months ago Activity log
  • Created suggestion
Heap-based buffer overflow in Xchat-WDK before 1499-4 (2012-01-18) xchat 2.8.6 …

Heap-based buffer overflow in Xchat-WDK before 1499-4 (2012-01-18) xchat 2.8.6 on Maemo architecture could allow remote attackers to cause a denial of service (xchat client crash) or execute arbitrary code via a UTF-8 line from server containing characters outside of the Basic Multilingual Plane (BMP).

Affected products

xchat
  • ==2.8.6 on Maemo architecture
Xchat-WDK
  • ==before 1499-4 (2012-01-18)

Matching in nixpkgs

Package maintainers

created 2 months ago Activity log
  • Created suggestion
The GTK version of ettercap uses a global settings file …

The GTK version of ettercap uses a global settings file at /tmp/.ettercap_gtk and does not verify ownership of this file. When parsing this file for settings in gtkui_conf_read() (src/interfacesgtk/ec_gtk_conf.c), an unchecked sscanf() call allows a maliciously placed settings file to overflow a statically-sized buffer on the stack.

Affected products

ettercap
  • ==ettercap 0.7.5

Matching in nixpkgs

Package maintainers

created 2 months ago Activity log
  • Created suggestion
Information-disclosure vulnerability in Netsurf through 2.8 due to a world-readable …

Information-disclosure vulnerability in Netsurf through 2.8 due to a world-readable cookie jar.

References

Affected products

netsurf
  • ==through 2.8

Matching in nixpkgs

pkgs.netsurf.libcss

Cascading Style Sheets library for netsurf browser

pkgs.netsurf.libdom

Document Object Model library for netsurf browser

Package maintainers