Merge pull request #111579 from dotlambda/libsixel-insecure

libsixel: mark as insecure
This commit is contained in:
Daniël de Kok 2021-02-01 17:10:16 +01:00 committed by GitHub
commit 73bf313f08
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23

View file

@ -22,5 +22,9 @@ stdenv.mkDerivation rec {
maintainers = with maintainers; [ vrthra ];
license = licenses.mit;
platforms = with platforms; unix;
knownVulnerabilities = [
"CVE-2020-11721" # https://github.com/saitoha/libsixel/issues/134
"CVE-2020-19668" # https://github.com/saitoha/libsixel/issues/136
];
};
}