openSUSE-SU-2022:10101-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2022:10101-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2022:10101-1
Upstream
CVE (9)
Related
Published
2022-08-27T12:33:24Z
Modified
2026-02-04T04:03:16Z
Summary
Security update for nim
Details

This update for nim fixes the following issues:

Includes upstream security fixes for:

  • (boo#1175333, CVE-2020-15693) httpClient is vulnerable to a CR-LF injection
  • (boo#1175334, CVE-2020-15692) mishandle of argument to browsers.openDefaultBrowser
  • (boo#1175332, CVE-2020-15694) httpClient.get().contentLength() fails to properly validate the server response
  • (boo#1192712, CVE-2021-41259) null byte accepted in getContent function, leading to URI validation bypass
  • (boo#1185948, CVE-2021-29495) stdlib httpClient does not validate peer certificates by default
  • (boo#1185085, CVE-2021-21374) Improper verification of the SSL/TLS certificate
  • (boo#1185084, CVE-2021-21373) 'nimble refresh' falls back to a non-TLS URL in case of error
  • (boo#1185083, CVE-2021-21372) doCmd can be leveraged to execute arbitrary commands
  • (boo#1181705, CVE-2020-15690) Standard library asyncftpclient lacks a check for newline character

Update to 1.6.6

  • standard library use consistent styles for variable names so it can be used in projects which force a consistent style with --styleCheck:usages option.
  • ARC/ORC are now considerably faster at method dispatching, bringing its performance back on the level of the refc memory management.
  • Full changelog: https://nim-lang.org/blog/2022/05/05/version-166-released.html
  • Previous updates and changelogs:

update to 1.2.16

  • oids: switch from PRNG to random module
  • nimc.rst: fix table markup
  • nimRawSetjmp: support Windows
  • correctly enable chronos
  • bigints are not supposed to work on 1.2.x
  • disable nimpy
  • misc bugfixes
  • fixes a 'mixin' statement handling regression [backport:1.2
References

Affected packages

SUSE:Package Hub 15 SP4 / nim

Package

Name
nim
Purl
pkg:rpm/suse/nim&distro=SUSE%20Package%20Hub%2015%20SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.6.6-bp154.2.3.1

Ecosystem specific

{
    "binaries":  [
        {
            "nim":  "1.6.6-bp154.2.3.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2022:10101-1.json"

openSUSE:Leap 15.4 / nim

Package

Name
nim
Purl
pkg:rpm/opensuse/nim&distro=openSUSE%20Leap%2015.4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.6.6-bp154.2.3.1

Ecosystem specific

{
    "binaries":  [
        {
            "nim":  "1.6.6-bp154.2.3.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2022:10101-1.json"