Nixpkgs security tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Automatically generated suggestions

to slate a suggestion for refinement.

to mark a suggestion as irrelevant and log the reason.

View:
Compact
Detailed
Permalink CVE-2026-48850
3.7 LOW
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): Low (L)
created 6 days, 23 hours ago Activity log
  • Created suggestion
PuTTY 0.72 before 0.84 has a double free in RSA …

PuTTY 0.72 before 0.84 has a double free in RSA KEX.

Affected products

PuTTY
  • <0.84

Matching in nixpkgs

pkgs.putty

Free Telnet/SSH Client

  • nixos-unstable 0.83
    • nixpkgs-unstable 0.83
    • nixos-unstable-small 0.83
  • nixos-25.11 0.83
    • nixos-25.11-small 0.83
    • nixpkgs-25.11-darwin 0.83

Package maintainers

Permalink CVE-2026-48844
7.5 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 6 days, 23 hours ago Activity log
  • Created suggestion
Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has …

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has insecure code evaluation logic in LDAP the autovalues option that could lead to code injection. (Support for code evaluation has been removed in 1.6.16 and 1.7.1.)

Affected products

Webmail
  • <1.6.16
  • <1.7.1

Matching in nixpkgs

Package maintainers

Permalink CVE-2026-48848
7.2 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
created 6 days, 23 hours ago Activity log
  • Created suggestion
Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7 has …

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7 has insufficient HTML sanitization that could lead to Cascading Style Sheets (CSS) injection via an SVG document that has an animate element with the attributeName attribute.

Affected products

Webmail
  • <1.6.16
  • <1.7.1

Matching in nixpkgs

Package maintainers

Permalink CVE-2026-9504
1.9 LOW
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): Low (L)
  • Vulnerable System Impact Integrity (VI): None (N)
  • Vulnerable System Impact Availability (VA): None (N)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Exploit Maturity (E): POC (P)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
  • Modified Vulnerable System Impact Integrity (MVI): None (N)
  • Modified Vulnerable System Impact Availability (MVA): None (N)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
created 6 days, 23 hours ago Activity log
  • Created suggestion
GNU LibreDWG Dwggrep Utility dwggrep.c bit_convert_TU out-of-bounds

A weakness has been identified in GNU LibreDWG up to 0.14. Affected is the function bit_convert_TU of the file programs/dwggrep.c of the component Dwggrep Utility. This manipulation causes out-of-bounds read. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. Patch name: be996bf2178a40e98720f18c2414815d244413db. Applying a patch is the recommended action to fix this issue.

Affected products

LibreDWG
  • ==0.14
  • ==0.9
  • ==0.3
  • ==0.13
  • ==0.6
  • ==0.7
  • ==0.1
  • ==0.8
  • ==0.12
  • ==0.4
  • ==0.2
  • ==0.10
  • ==0.5
  • ==0.11

Matching in nixpkgs

Package maintainers

Permalink CVE-2026-9358
2.1 LOW
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Passive (P)
  • Vulnerable System Impact Confidentiality (VC): None (N)
  • Vulnerable System Impact Integrity (VI): None (N)
  • Vulnerable System Impact Availability (VA): Low (L)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Exploit Maturity (E): POC (P)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Passive (P)
  • Modified Vulnerable System Impact Confidentiality (MVC): None (N)
  • Modified Vulnerable System Impact Integrity (MVI): None (N)
  • Modified Vulnerable System Impact Availability (MVA): Low (L)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
created 1 week ago Activity log
  • Created suggestion
postcss AST Serialization container.js toString recursion

A vulnerability was determined in postcss up to 7.1.1. Affected is the function toString of the file src/selectors/container.js of the component AST Serialization. Executing a manipulation can lead to uncontrolled recursion. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor explains, that according to his definition "DoS on server-side on user-generated CSS is low risk for us (since most users compile own CSS with PostCSS)."

Affected products

postcss
  • ==7.1.1
  • ==7.1.0

Matching in nixpkgs

Permalink CVE-2026-48831
7.3 HIGH
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): Present (P)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Passive (P)
  • Vulnerable System Impact Confidentiality (VC): High (H)
  • Vulnerable System Impact Integrity (VI): High (H)
  • Vulnerable System Impact Availability (VA): High (H)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Automatable (AU): No (N)
  • Value Density (V): Diffuse (D)
  • Provider Urgency (U): Clear (Clear)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): Present (P)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Passive (P)
  • Modified Vulnerable System Impact Confidentiality (MVC): High (H)
  • Modified Vulnerable System Impact Integrity (MVI): High (H)
  • Modified Vulnerable System Impact Availability (MVA): High (H)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 1 week ago Activity log
  • Created suggestion
Wine ships a .desktop file that registers itself as a …

Wine ships a .desktop file that registers itself as a MIME handler for EXE files and several other Windows executable file types. In some configurations, handling of an EXE file causes that file to be blindly executed with the permissions of the invoker. This allows escaping Flatpak and Snap sandboxes, because MIME handlers are not intended for use by code interpreters and loaders. NOTE: some parties feel that this is not a bug to be addressed in Wine, because there is no known solution that avoids a severe loss of usability (Wine could be a binfmt-misc handler, but binfmt-misc does not exist on all platforms supported by Wine).

Affected products

Wine
  • =<11.0

Matching in nixpkgs

pkgs.twine

Collection of utilities for interacting with PyPI

pkgs.q4wine

Qt GUI for Wine to manage prefixes and applications

pkgs.wine64

Open Source implementation of the Windows API on top of X, OpenGL, and Unix

  • nixos-unstable 11.0
    • nixpkgs-unstable 11.0
    • nixos-unstable-small 11.0
  • nixos-25.11 10.0
    • nixos-25.11-small 10.0
    • nixpkgs-25.11-darwin 10.0

pkgs.entwine

Point cloud organization for massive datasets

pkgs.twinejs

Open-source tool for telling interactive, nonlinear stories

pkgs.wine.x86_64-linux

Open Source implementation of the Windows API on top of X, OpenGL, and Unix

  • nixos-unstable 11.0
    • nixpkgs-unstable 11.0
    • nixos-unstable-small 11.0
  • nixos-25.11 10.0
    • nixos-25.11-small 10.0
    • nixpkgs-25.11-darwin 10.0

pkgs.wine64Packages.base

Open Source implementation of the Windows API on top of X, OpenGL, and Unix

  • nixos-unstable 11.0
    • nixpkgs-unstable 11.0
    • nixos-unstable-small 11.0
  • nixos-25.11 10.0
    • nixos-25.11-small 10.0
    • nixpkgs-25.11-darwin 10.0

pkgs.wine64Packages.full

Open Source implementation of the Windows API on top of X, OpenGL, and Unix

  • nixos-unstable 11.0
    • nixpkgs-unstable 11.0
    • nixos-unstable-small 11.0
  • nixos-25.11 10.0
    • nixos-25.11-small 10.0
    • nixpkgs-25.11-darwin 10.0

pkgs.wineWowPackages.base

Open Source implementation of the Windows API on top of X, OpenGL, and Unix

  • nixos-25.11 10.0
    • nixos-25.11-small 10.0
    • nixpkgs-25.11-darwin 10.0

pkgs.wineWowPackages.full

Open Source implementation of the Windows API on top of X, OpenGL, and Unix

  • nixos-25.11 10.0
    • nixos-25.11-small 10.0
    • nixpkgs-25.11-darwin 10.0

pkgs.wine64Packages.stable

Open Source implementation of the Windows API on top of X, OpenGL, and Unix

  • nixos-unstable 11.0
    • nixpkgs-unstable 11.0
    • nixos-unstable-small 11.0
  • nixos-25.11 10.0
    • nixos-25.11-small 10.0
    • nixpkgs-25.11-darwin 10.0

pkgs.wine64Packages.minimal

Open Source implementation of the Windows API on top of X, OpenGL, and Unix

  • nixos-unstable 11.0
    • nixpkgs-unstable 11.0
    • nixos-unstable-small 11.0
  • nixos-25.11 10.0
    • nixos-25.11-small 10.0
    • nixpkgs-25.11-darwin 10.0

pkgs.wine64Packages.staging

Open Source implementation of the Windows API on top of X, OpenGL, and Unix (with staging patches)

  • nixos-unstable 11.8
    • nixpkgs-unstable 11.8
    • nixos-unstable-small 11.8
  • nixos-25.11 10.20
    • nixos-25.11-small 10.20
    • nixpkgs-25.11-darwin 10.20

pkgs.wine64Packages.wayland

Open Source implementation of the Windows API on top of X, OpenGL, and Unix

  • nixos-unstable 11.0
    • nixpkgs-unstable 11.0
    • nixos-unstable-small 11.0
  • nixos-25.11 10.0
    • nixos-25.11-small 10.0
    • nixpkgs-25.11-darwin 10.0

pkgs.wineWowPackages.stable

Open Source implementation of the Windows API on top of X, OpenGL, and Unix

  • nixos-25.11 10.0
    • nixos-25.11-small 10.0
    • nixpkgs-25.11-darwin 10.0

pkgs.wineWowPackages.staging

Open Source implementation of the Windows API on top of X, OpenGL, and Unix (with staging patches)

pkgs.wineWowPackages.yabridge

Open Source implementation of the Windows API on top of X, OpenGL, and Unix (with staging patches)

  • nixos-25.11 9.21
    • nixos-25.11-small 9.21
    • nixpkgs-25.11-darwin 9.21

pkgs.wine-staging.x86_64-linux

Open Source implementation of the Windows API on top of X, OpenGL, and Unix (with staging patches)

  • nixos-unstable 11.8
    • nixpkgs-unstable 11.8
    • nixos-unstable-small 11.8
  • nixos-25.11 10.20
    • nixos-25.11-small 10.20
    • nixpkgs-25.11-darwin 10.20

pkgs.wine64Packages.staging_11

Open Source implementation of the Windows API on top of X, OpenGL, and Unix (with staging patches)

  • nixos-25.11 11.1
    • nixos-25.11-small 11.1
    • nixpkgs-25.11-darwin 11.1

pkgs.wine64Packages.stagingFull

Open Source implementation of the Windows API on top of X, OpenGL, and Unix (with staging patches)

  • nixos-unstable 11.8
    • nixpkgs-unstable 11.8
    • nixos-unstable-small 11.8
  • nixos-25.11 10.20
    • nixos-25.11-small 10.20
    • nixpkgs-25.11-darwin 10.20

pkgs.wineWowPackages.staging_11

Open Source implementation of the Windows API on top of X, OpenGL, and Unix (with staging patches)

  • nixos-25.11 11.1
    • nixos-25.11-small 11.1
    • nixpkgs-25.11-darwin 11.1

Package maintainers

Permalink CVE-2026-48832
3.5 LOW
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): None (N)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
created 1 week ago Activity log
  • Created suggestion
action/cookie.php in ecrire in SPIP before 4.4.15 is prone to …

action/cookie.php in ecrire in SPIP before 4.4.15 is prone to an open redirect vulnerability.

Affected products

SPIP
  • <4.4.15

Matching in nixpkgs

pkgs.spiped

Utility for secure encrypted channels between sockets

pkgs.aespipe

AES encrypting or decrypting pipe

  • nixos-unstable 2.4j
    • nixpkgs-unstable 2.4j
    • nixos-unstable-small 2.4j
  • nixos-25.11 2.4j
    • nixos-25.11-small 2.4j
    • nixpkgs-25.11-darwin 2.4j

pkgs.lesspipe

Preprocessor for less

  • nixos-unstable 2.20
    • nixpkgs-unstable 2.20
    • nixos-unstable-small 2.20
  • nixos-25.11 2.20
    • nixos-25.11-small 2.20
    • nixpkgs-25.11-darwin 2.20

pkgs.crosspipe

PipeWire graph GTK4/Libadwaita GUI

Package maintainers

Permalink CVE-2026-9365
2.9 LOW
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): Low (L)
  • Vulnerable System Impact Integrity (VI): Low (L)
  • Vulnerable System Impact Availability (VA): Low (L)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Exploit Maturity (E): POC (P)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
  • Modified Vulnerable System Impact Integrity (MVI): Low (L)
  • Modified Vulnerable System Impact Availability (MVA): Low (L)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
created 1 week ago Activity log
  • Created suggestion
Ettercap GG Dissector ec_gg.c FUNC_DECODER heap-based overflow

A vulnerability has been found in Ettercap up to 0.8.3. The affected element is the function FUNC_DECODER of the file src/dissectors/ec_gg.c of the component GG Dissector. The manipulation of the argument gg leads to heap-based buffer overflow. The attack is possible to be carried out remotely. The complexity of an attack is rather high. The exploitability is described as difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 0.8.4 is sufficient to fix this issue. The identifier of the patch is feeae6fa366e01a3dd9f1857ec6aae847b2ae00c. It is suggested to upgrade the affected component.

Affected products

Ettercap
  • ==0.8.1
  • ==0.8.2
  • ==0.8.0
  • ==0.8.4
  • ==0.8.3

Matching in nixpkgs

Package maintainers

Permalink CVE-2026-9300
2.1 LOW
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): Low (L)
  • Vulnerable System Impact Integrity (VI): Low (L)
  • Vulnerable System Impact Availability (VA): Low (L)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Exploit Maturity (E): POC (P)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
  • Modified Vulnerable System Impact Integrity (MVI): Low (L)
  • Modified Vulnerable System Impact Availability (MVA): Low (L)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
created 1 week, 1 day ago Activity log
  • Created suggestion
omec-project amf NGSetupRequest memory corruption

A vulnerability has been found in omec-project amf up to 2.1.1. This affects an unknown part of the component NGSetupRequest Handler. Such manipulation leads to memory corruption. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. It is best practice to apply a patch to resolve this issue.

Affected products

amf
  • ==2.1.0
  • ==2.1.1

Matching in nixpkgs

pkgs.bamf

Application matching framework

pkgs.ramfetch

Tool which displays memory information

  • nixos-unstable 1.1.0a
  • nixos-25.11 -
    • nixos-25.11-small
    • nixpkgs-25.11-darwin

pkgs.cramfsswap

Swap endianess of a cram filesystem (cramfs)

Permalink CVE-2018-25356
8.6 HIGH
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): High (H)
  • Vulnerable System Impact Integrity (VI): High (H)
  • Vulnerable System Impact Availability (VA): High (H)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): High (H)
  • Modified Vulnerable System Impact Integrity (MVI): High (H)
  • Modified Vulnerable System Impact Availability (MVA): High (H)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 1 week, 1 day ago Activity log
  • Created suggestion
SIPp 3.6 Local Buffer Overflow via Command-line Arguments

SIPp 3.6 and earlier contains a local buffer overflow vulnerability in command-line argument handling that allows local attackers to crash the application or execute arbitrary code. Attackers can trigger the vulnerability by supplying oversized input to the -3pcc, -i, or -log_file parameters, causing strcpy to write beyond buffer boundaries in sipp.cpp.

Affected products

SIPp
  • =<3.6

Matching in nixpkgs