Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerability roundup 45 (master) #43846

Closed
10 tasks done
ckauhaus opened this issue Jul 20, 2018 · 4 comments
Closed
10 tasks done

Vulnerability roundup 45 (master) #43846

ckauhaus opened this issue Jul 20, 2018 · 4 comments

Comments

@ckauhaus
Copy link
Contributor

ckauhaus commented Jul 20, 2018

Scanned nixos/release-combined.nix @ dae9cf6. Filtered out previously reported CVEs. May contain false positives.

git-2.17.1 (search, files)

graphviz-2.40.1 (search, files)

libsass-3.5.4 (search, files)

postgresql-9.6.8 (search, files)

Cc: @joepie91, @phanimahesh, @the-kenny, @7c6f434c, @k0001, @peterhoeg, @nh2, @LnL7, @grahamc, @adisbladis, @fpletz, @vcunat

Contact @ckauhaus for any questions.

@infinisil
Copy link
Member

git's one was fixed in 2.17.1 and master already has 2.18, see https://github.com/git/git/blob/master/Documentation/RelNotes/2.17.1.txt

@infinisil
Copy link
Member

libsass CVE-2018-11693 fixed in b5b23b3

benley pushed a commit to benley/nixpkgs that referenced this issue Jul 20, 2018
@infinisil
Copy link
Member

postgresql CVE-2018-1058 was fixed in the last round of updates: https://www.postgresql.org/about/news/1834/ (7e21fd7 and parents)

@danbst
Copy link
Contributor

danbst commented Jul 23, 2019

libasass is 3.5.5 in 19.03
graphviz already has patch applied

@danbst danbst closed this as completed Jul 23, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

4 participants