Unverified Commit 5d898d4d authored by 7c6f434c's avatar 7c6f434c Committed by GitHub
Browse files

runzip: mark package as insecure (#513544)

parents 111e5111 f654908d
Loading
Loading
Loading
Loading
+5 −0
Original line number Diff line number Diff line
@@ -41,6 +41,11 @@ stdenv.mkDerivation (finalAttrs: {
    description = "Tool to convert filename encoding inside a ZIP archive";
    license = lib.licenses.bsd2;
    maintainers = [ lib.maintainers.raskin ];
    # runzip vendors libzip 0.7.1.
    knownVulnerabilities = [
      "CVE-2015-2331"
      "CVE-2017-14107"
    ];
    platforms = lib.platforms.unix;
    mainProgram = "runzip";
  };