andir / nix-vulnerability-scanner

19 stars 4 forks source link

fails to properly understand ntp version scheme #2

Open aanderse opened 5 years ago

aanderse commented 5 years ago

See https://broken.sh/issues/CVE-2014-9750. Reporting versions before 4.2.8p1 are vulnerable but we're shipping 4.2.8p13.