From d95603039c642c926d7e9dddea48d447506e044c Mon Sep 17 00:00:00 2001 From: Ingo Blechschmidt Date: Fri, 17 Dec 2021 21:32:54 +0100 Subject: [PATCH] tightvnc: mark as insecure (fixes #150704) (cherry picked from commit 034d277c6e32133163d2fd5d7ead0b4b70f478a2) --- pkgs/tools/admin/tightvnc/default.nix | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/pkgs/tools/admin/tightvnc/default.nix b/pkgs/tools/admin/tightvnc/default.nix index 1bfb3be113da..872192fc97fd 100644 --- a/pkgs/tools/admin/tightvnc/default.nix +++ b/pkgs/tools/admin/tightvnc/default.nix @@ -81,5 +81,9 @@ stdenv.mkDerivation { maintainers = []; platforms = lib.platforms.unix; + + knownVulnerabilities = [ "CVE-2021-42785" ]; + # Unfortunately, upstream doesn't maintain the 1.3 branch anymore, and the + # new 2.x branch is substantially different (requiring either Windows or Java) }; }