26 Sep 2024 |
| Fabián Heredia set a profile picture. | 01:15:50 |
Alyssa Ross | https://github.com/NixOS/nix/compare/2.24.7...2.24.8 | 08:11:54 |
Alyssa Ross |
builtin:fetchurl: Enable TLS verification
| 08:12:22 |
Alyssa Ross |
Ensure error messages don't leak private key
| 08:12:30 |
Alyssa Ross | https://github.com/NixOS/nixpkgs/pull/344601 | 08:26:33 |
| Arian joined the room. | 12:33:00 |
Arian | This affects all nix versions. We need to make PRs for all the backports too no? | 12:34:17 |
Arian | Not just 2.24-specific afaics | 12:34:25 |
emily | yes. looks like 2.18 is out, someone should open a PR. no other versions yet, waiting for Eelco to cut the tags I assume. (further discussion should probably go in #security-discuss:nixos.org) | 12:35:40 |
Mic92 | In reply to @qyliss:fairydust.space
builtin:fetchurl: Enable TLS verification
I would argue the "information leak" should not affect many people. <nix/fetchurl.nix> is manly used by bootstrap tarballs. | 18:48:48 |
Mic92 | In reply to @qyliss:fairydust.space
builtin:fetchurl: Enable TLS verification
* I would argue the "information leak" should not affect many people. <nix/fetchurl.nix> is manly used by bootstrap tarballs that do not suffer from this. So low impact for most people. | 18:49:22 |
hexa | it probably doesn't, but that is for #security-discuss:nixos.org | 18:52:36 |
vcunat | In reply to @fabianhjr:matrix.org https://x.com/evilsocket/status/1838169889330135132
Claims 9.9 RCE unauthenticated over network affecting all GNU/Linux Systems CUPS? Much earlier than expected, though: https://www.evilsocket.net/2024/09/26/Attacking-UNIX-systems-via-CUPS-Part-I/ | 20:21:55 |
Fabián Heredia | yeah, and also underwhelming for the original hype | 20:25:19 |
void | I recall another one in hplip last year, somebody is getting efficient at it it seems. | 23:52:39 |
27 Sep 2024 |
| SigmaSquadron joined the room. | 00:18:22 |
| @vengmark2:matrix.org joined the room. | 02:26:49 |
| @vengmark2:matrix.org left the room. | 02:29:26 |
Fabián Heredia | The following PR wasn't triaged and was going stale around 2x High (7.5 CVSS) CVEs on libtiff.
https://github.com/NixOS/nixpkgs/pull/340569 | 06:26:33 |
hexa | https://github.com/OpenPrinting/cups-filters/security/advisories/GHSA-rq86-c7g6-r2h8 | 13:11:40 |
| elikoga set a profile picture. | 16:27:28 |
28 Sep 2024 |
| ghpzin joined the room. | 11:00:47 |
| Scrumplex joined the room. | 11:04:11 |
30 Sep 2024 |
| @entheogenesis:matrix.org left the room. | 18:32:15 |
1 Oct 2024 |
| -_o joined the room. | 21:00:31 |
2 Oct 2024 |
| tlaurion aka Insurgo [UTC-4] changed their display name from tlaurion aka Insurgo [UTC-4] (🛫🗺️🛬: Back 2024-10-01) to tlaurion aka Insurgo [UTC-4]. | 12:42:28 |
4 Oct 2024 |
| @ajcxz0:matrix.org left the room. | 01:00:45 |
5 Oct 2024 |
| magic_rb changed their profile picture. | 22:16:56 |
| gvelim joined the room. | 22:54:48 |
6 Oct 2024 |
| Sofie joined the room. | 15:22:25 |