Search CVE reports
1 – 10 of 30 results
(An issue was discovered in Nix before 2.34.7. Writing to arbitrary fil ...)
1 affected package
nix
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| nix | Needs evaluation | Needs evaluation | Needs evaluation | — | — |
(An issue was discovered in Nix before 2.34.7 and Lix before 2.95.2. Un ...)
1 affected package
nix
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| nix | Needs evaluation | Needs evaluation | Needs evaluation | — | — |
Nix is a package manager for Linux and other Unix systems. A bug in the fix for CVE-2024-27297 allowed for arbitrary overwrites of files writable by the Nix process orchestrating the builds (typically the Nix daemon running as...
1 affected package
nix
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| nix | Needs evaluation | Needs evaluation | Needs evaluation | — | — |
A flaw was found in libtheora. This heap-based out-of-bounds read vulnerability exists within the AVI (Audio Video Interleave) parser, specifically in the avi_parse_input_file() function. A local attacker could exploit this by...
4 affected packages
asc, libtheora, mkvtoolnix, ogmrip
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| asc | Vulnerable | Vulnerable | Vulnerable | Vulnerable | Vulnerable |
| libtheora | Vulnerable | Vulnerable | Vulnerable | Vulnerable | Vulnerable |
| mkvtoolnix | Vulnerable | Vulnerable | Vulnerable | Vulnerable | Vulnerable |
| ogmrip | Vulnerable | Not in release | Vulnerable | Vulnerable | Vulnerable |
Nix is a package manager for Linux and other Unix systems. Builds with Nix 2.30.0 on macOS were executed with elevated privileges (root), instead of the build users. The fix was applied to Nix 2.30.1. No known workarounds are available.
1 affected package
nix
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| nix | — | Not affected | Not affected | — | — |
Some fixes available 2 of 3
Nix is a package manager for Linux and other Unix systems. Starting in version 1.11 and prior to versions 2.18.8 and 2.24.8, `<nix/fetchurl.nix>` did not verify TLS certificates on HTTPS connections. This could lead to connection...
1 affected package
nix
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| nix | Not affected | Fixed | Fixed | Not in release | — |
Some fixes available 2 of 3
Nix is a package manager for Linux and other Unix systems. A bug in Nix 2.24 prior to 2.24.6 allows a substituter or malicious user to craft a NAR that, when unpacked by Nix, causes Nix to write to arbitrary file system locations...
1 affected package
nix
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| nix | Not affected | Fixed | Fixed | Not in release | — |
Rejected reason: DO NOT USE THIS CVE RECORD. Consult IDs: CVE-2024-45593. Reason: This record is a reservation duplicate of CVE-2024-45593. Notes: All CVE users should reference CVE-2024-45593 instead of this record....
1 affected package
nix
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| nix | — | Not affected | Not affected | Not in release | — |
Some fixes available 2 of 4
Nix is a package manager for Linux and other Unix systems that makes package management reliable and reproducible. A build process has access to and can change the permissions of the build directory. After creating a setuid binary...
1 affected package
nix
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| nix | Not affected | Fixed | Fixed | Not in release | — |
Nix through 2.22.1 mishandles certain usage of hash caches, which makes it easier for attackers to replace current source code with attacker-controlled source code by luring a maintainer into accepting a malicious pull request.
1 affected package
nix
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| nix | Vulnerable | Vulnerable | Vulnerable | Not in release | — |