nixpkgs/pkgs
Red Davies 93b523d030 botan2: update 2.7.0 -> 2.9.0
Fixes:
CVE-2018-12435: requires >= 2.7.0 (NVD extry is incorrect)
"Bug introduced in 2.5.0, fixed in 2.7.0. The 1.10 branch is not affected."
A side channel in the ECDSA signature operation could allow a local attacker to recover the secret key.

CVE-2018-20187: requires >= 2.9.0
"Introduced in 1.11.20, fixed in 2.8.0."
A timing side channel during ECC key generation could leak information about the high bits of the secret scalar. Such information allows an attacker to perform a brute force attack on the key somewhat more efficiently than they would otherwise.
2020-11-24 14:11:14 -05:00
..
applications chromiumDev: Unmark the build as broken 2020-11-21 00:27:27 +01:00
build-support dockerTools: Always cross compile for another arch in the cross example 2020-11-20 12:57:58 +01:00
common-updater
data libsForQt5.qtcurve: fix build with Qt5.15 2020-11-20 22:24:27 +01:00
desktops gnomeExtensions.workspace-matrix: 4.0.1 -> 4.0.2 2020-11-19 22:36:43 -08:00
development botan2: update 2.7.0 -> 2.9.0 2020-11-24 14:11:14 -05:00
games pentobi: 18.1 -> 18.3 2020-11-20 22:24:20 +01:00
misc calaos_installer: 3.1 -> 3.5 2020-11-20 22:24:18 +01:00
os-specific s6-linux-utils: 2.5.1.2 -> 2.5.1.3 2020-11-20 18:15:17 +01:00
pkgs-lib
servers Merge pull request #88822 from mweinelt/pim6sd 2020-11-21 03:08:28 +01:00
shells oh-my-zsh: 2020-11-12 → 2020-11-20 2020-11-20 16:27:42 +00:00
stdenv Merge #98541 into staging-next 2020-11-14 09:19:31 +01:00
test haskell: Add documentationTarball to lib 2020-11-13 21:37:56 +01:00
tools Merge pull request #100257 from priegger/feature/update-bees 2020-11-21 03:49:11 +01:00
top-level Merge pull request #88822 from mweinelt/pim6sd 2020-11-21 03:08:28 +01:00