From 926a76fac7db55a544b6674dd50c34416b940025 Mon Sep 17 00:00:00 2001 From: Tomo Date: Sun, 27 Oct 2024 07:07:21 +0000 Subject: [PATCH] minidjvu: mark as vulnerable See https://github.com/NixOS/nixpkgs/issues/90896 (cherry picked from commit a0c6ffc324133b4b8b0012ec4e5cec37e375f998) --- pkgs/applications/graphics/minidjvu/default.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/applications/graphics/minidjvu/default.nix b/pkgs/applications/graphics/minidjvu/default.nix index ca9e77391eb3..e9e441f77afa 100644 --- a/pkgs/applications/graphics/minidjvu/default.nix +++ b/pkgs/applications/graphics/minidjvu/default.nix @@ -26,5 +26,8 @@ stdenv.mkDerivation rec { maintainers = [ lib.maintainers.viric ]; platforms = lib.platforms.unix; mainProgram = "minidjvu"; + knownVulnerabilities = [ + "minidjvu is vulnerable to a number of out-of-bound read vulnerabilities, potentially causing denials of service (CVE-2017-12441, CVE-2017-12442, CVE-2017-12443, CVE-2017-12444, CVE-2017-12445)" + ]; }; }