TEMP-0000000-39AEFA

NameTEMP-0000000-39AEFA
DescriptionGuix build user takeover vulnerability
SourceAutomatically generated temporary name. Not for external reference.

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
guix (PTS)bullseye (security), bullseye1.2.0-4+deb11u2vulnerable
bookworm (security), bookworm1.4.0-3+deb12u1vulnerable
sid1.4.0-8fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
guixsource(unstable)1.4.0-8

Notes

https://guix.gnu.org/en/blog/2024/build-user-takeover-vulnerability/
Fixed by: https://git.savannah.gnu.org/cgit/guix.git/commit/?id=558224140dab669cabdaebabff18504a066c48d4
Fixed by: https://git.savannah.gnu.org/cgit/guix.git/commit/?id=5ab3c4c1e43ebb637551223791db0ea3519986e1

Search for package or bug name: Reporting problems