{"id":"openSUSE-SU-2022:10101-1","summary":"Security update for nim","details":"This update for nim fixes the following issues:\n\nIncludes upstream security fixes for:\n\n* (boo#1175333, CVE-2020-15693) httpClient is vulnerable to a \n  CR-LF injection\n* (boo#1175334, CVE-2020-15692) mishandle of argument to \n  browsers.openDefaultBrowser\n* (boo#1175332, CVE-2020-15694) httpClient.get().contentLength()\n  fails to properly validate the server response\n* (boo#1192712, CVE-2021-41259) null byte accepted in getContent\n  function, leading to URI validation bypass\n* (boo#1185948, CVE-2021-29495) stdlib httpClient does not\n  validate peer certificates by default\n* (boo#1185085, CVE-2021-21374) Improper verification of the \n  SSL/TLS certificate\n* (boo#1185084, CVE-2021-21373) 'nimble refresh' falls back to a \n  non-TLS URL in case of error\n* (boo#1185083, CVE-2021-21372) doCmd can be leveraged to execute\n  arbitrary commands\n* (boo#1181705, CVE-2020-15690) Standard library asyncftpclient \n  lacks a check for newline character\n\nUpdate to 1.6.6\n\n* standard library use consistent styles for variable names so it\n  can be used in projects which force a consistent style with \n  --styleCheck:usages option. \n* ARC/ORC are now considerably faster at method dispatching, \n  bringing its performance back on the level of the refc memory \n  management.\n* Full changelog:\n  https://nim-lang.org/blog/2022/05/05/version-166-released.html\n- Previous updates and changelogs:\n* 1.6.4: \n  https://nim-lang.org/blog/2022/02/08/version-164-released.html\n* 1.6.2: \n  https://nim-lang.org/blog/2021/12/17/version-162-released.html\n* 1.6.0: \n  https://nim-lang.org/blog/2021/10/19/version-160-released.html\n* 1.4.8: \n  https://nim-lang.org/blog/2021/05/25/version-148-released.html\n* 1.4.6: \n  https://nim-lang.org/blog/2021/04/15/versions-146-and-1212-released.html\n* 1.4.4: \n  https://nim-lang.org/blog/2021/02/23/versions-144-and-1210-released.html\n* 1.4.2: \n  https://nim-lang.org/blog/2020/12/01/version-142-released.html\n* 1.4.0: \n  https://nim-lang.org/blog/2020/10/16/version-140-released.html\n\nupdate to 1.2.16\n\n* oids: switch from PRNG to random module\n* nimc.rst: fix table markup\n* nimRawSetjmp: support Windows\n* correctly enable chronos\n* bigints are not supposed to work on 1.2.x\n* disable nimpy\n* misc bugfixes\n* fixes a 'mixin' statement handling regression [backport:1.2 \n","modified":"2026-03-11T07:33:28.416532Z","published":"2022-08-27T12:33:24Z","related":["CVE-2020-15690","CVE-2020-15692","CVE-2020-15693","CVE-2020-15694","CVE-2021-21372","CVE-2021-21373","CVE-2021-21374","CVE-2021-29495","CVE-2021-41259"],"upstream":["CVE-2020-15690","CVE-2020-15692","CVE-2020-15693","CVE-2020-15694","CVE-2021-21372","CVE-2021-21373","CVE-2021-21374","CVE-2021-29495","CVE-2021-41259"],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SNDISR45BBTIWW5MDTIQOSRHOEV3XUKF/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1175332"},{"type":"REPORT","url":"https://bugzilla.suse.com/1175333"},{"type":"REPORT","url":"https://bugzilla.suse.com/1175334"},{"type":"REPORT","url":"https://bugzilla.suse.com/1181705"},{"type":"REPORT","url":"https://bugzilla.suse.com/1185083"},{"type":"REPORT","url":"https://bugzilla.suse.com/1185084"},{"type":"REPORT","url":"https://bugzilla.suse.com/1185085"},{"type":"REPORT","url":"https://bugzilla.suse.com/1185948"},{"type":"REPORT","url":"https://bugzilla.suse.com/1192712"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-15690"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-15692"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-15693"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-15694"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-21372"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-21373"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-21374"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-29495"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-41259"}],"affected":[{"package":{"name":"nim","ecosystem":"SUSE:Package Hub 15 SP4","purl":"pkg:rpm/suse/nim&distro=SUSE%20Package%20Hub%2015%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.6.6-bp154.2.3.1"}]}],"ecosystem_specific":{"binaries":[{"nim":"1.6.6-bp154.2.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2022:10101-1.json"}},{"package":{"name":"nim","ecosystem":"openSUSE:Leap 15.4","purl":"pkg:rpm/opensuse/nim&distro=openSUSE%20Leap%2015.4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.6.6-bp154.2.3.1"}]}],"ecosystem_specific":{"binaries":[{"nim":"1.6.6-bp154.2.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2022:10101-1.json"}}],"schema_version":"1.7.5"}