Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerability roundup 87: kitty-0.18.1: 1 advisory [9.8] #92038

Closed
1 task
ckauhaus opened this issue Jul 2, 2020 · 3 comments
Closed
1 task

Vulnerability roundup 87: kitty-0.18.1: 1 advisory [9.8] #92038

ckauhaus opened this issue Jul 2, 2020 · 3 comments
Labels
1.severity: security Issues which raise a security issue, or PRs that fix one

Comments

@ckauhaus
Copy link
Contributor

ckauhaus commented Jul 2, 2020

search, files

Scanned versions: nixos-unstable: b3251e0. May contain false positives.

Cc @Luflosi
Cc @Ma27
Cc @rvolosatovs
Cc @tex

@ckauhaus ckauhaus added the 1.severity: security Issues which raise a security issue, or PRs that fix one label Jul 2, 2020
@Luflosi
Copy link
Contributor

Luflosi commented Jul 2, 2020

That CVE mentions KiTTY, which is a Windows program, while the kitty in nixpkgs is a different program.

@Ma27
Copy link
Member

Ma27 commented Jul 2, 2020

@ckauhaus IIRC we had such a false-positive in the past already. Any chance to blacklist this?

@Ma27 Ma27 closed this as completed Jul 2, 2020
@ckauhaus
Copy link
Contributor Author

ckauhaus commented Jul 3, 2020

@Ma27 Yeah, working on it. I've been collecting data in nix-community/vulnix#62. I think now I'm seeing the patterns clearly enough to be able to come up with some easy to use code.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
1.severity: security Issues which raise a security issue, or PRs that fix one
Projects
None yet
Development

No branches or pull requests

3 participants