Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerability roundup 85: zoom-1.1.5: 4 advisories [9.8] #91034

Closed
4 tasks
ckauhaus opened this issue Jun 18, 2020 · 9 comments
Closed
4 tasks

Vulnerability roundup 85: zoom-1.1.5: 4 advisories [9.8] #91034

ckauhaus opened this issue Jun 18, 2020 · 9 comments
Labels
1.severity: security Issues which raise a security issue, or PRs that fix one

Comments

@ckauhaus
Copy link
Contributor

ckauhaus commented Jun 18, 2020

*Note this is zoom the game, not zoom-us!

search, files

Scanned versions: nixos-20.03: a84b797; nixos-unstable: 22c9881. May contain false positives.

@ckauhaus ckauhaus added the 1.severity: security Issues which raise a security issue, or PRs that fix one label Jun 18, 2020
@flokli
Copy link
Contributor

flokli commented Jun 18, 2020

cc @glittershark

@glittershark
Copy link
Member

@flokli thanks for the heads up.

@glittershark
Copy link
Member

Looked at each and it looks like all of these are in a version older than what's in master, which has 5.0.408598.0517.

@glittershark
Copy link
Member

also both 20.03 and unstable have versions >5.0, so all four of these seem to be false positives

@glittershark
Copy link
Member

oh also looking at the files linked in the description this appears to be referencing pkgs/games/zoom, which is different from the messaging client zoom-us

@flokli
Copy link
Contributor

flokli commented Jun 18, 2020

Ooops, then sorry for the noise 🤦

@glittershark
Copy link
Member

np! worth having a quick trigger finger on security stuff 😄

@puzzlewolf
Copy link
Contributor

@ckauhaus: this is a false positive, the CVEs are for zoom-us, not for zoom, the game, as the title and linked files suggest.

@ckauhaus
Copy link
Contributor Author

Thanks for investigating. I'm currently collecting data in to improve on CPE matching nix-community/vulnix#62 and will come up with an improved vulnix.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
1.severity: security Issues which raise a security issue, or PRs that fix one
Projects
None yet
Development

No branches or pull requests

4 participants