The following issues have been resolved in NixOS in unstable and
release-16.09. They remain potentially vulnerable on older major
releases.
These patches will be released to the unstable and
release-16.09 channels when Hydra finishes building the "tested" job
for each channel:
-
https://hydra.nixos.org/job/nixos/release-16.09/tested
-
https://hydra.nixos.org/job/nixos/trunk-combined/tested
Please consider helping with the next security roundup by commenting on
https://github.com/NixOS/nixpkgs/issues/20647.
master 16.09 Message Notes
--- --- --- ---
9118702 5f69faa libarchive: 3.2.1 -> 3.2.2 for unspecified vuln... n/a
4a5c661 1980c26 gnuchess: 6.2.3 -> 6.2.4 for CVEs n/a
a3b7468 27c390f w3m: 0.5.3-2015-12-20 -> 0.5.3+git20161120 for ... n/a
336bacf 386c980 qemu: add patch to fix CVE-2016-7907 n/a
c823eae 2292d85 graphicsmagick: Update URLs for patches n/a
9de6029 ee38d13 libtiff: 4.0.6 -> 4.0.7 for many CVEs n/a
Thank you,
Graham Christensen