!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

660 Members
Coordination and triage of security issues in nixpkgs | Discussions in #security-discuss:nixos.org | Open PRs: https://github.com/NixOS/nixpkgs/pulls?q=is%3Apr+is%3Aopen+sort%3Aupdated-desc+label%3A%221.severity%3A+security%22205 Servers

Load older messages


SenderMessageTime
31 Oct 2024
@scrumplex:duckhub.ioScrumplex

Buffer overflow in libmpg123:

https://www.openwall.com/lists/oss-security/2024/10/30/2

00:37:32
@scrumplex:duckhub.ioScrumplex *

Buffer overflow in libmpg123:

https://www.openwall.com/lists/oss-security/2024/10/30/2

CVE-2024-10573

00:37:59
@hexa:lossy.networkhexa https://www.openwall.com/lists/oss-security/2024/10/31/1 webkitgtk 2.46.3 Jan Tojnar 01:04:50
@vcunat:matrix.orgvcunat
In reply to @scrumplex:duckhub.io

Buffer overflow in libmpg123:

https://www.openwall.com/lists/oss-security/2024/10/30/2

CVE-2024-10573

https://github.com/NixOS/nixpkgs/pull/351584
06:39:26
@jtojnar:matrix.orgJan Tojnarsorry, not sure if I will be able to get to it this week09:27:35
1 Nov 2024
@tomodachi94:matrix.orgTomodachi94 (they/them) joined the room.19:18:47
2 Nov 2024
@matrix:03j.de@matrix:03j.de joined the room.00:16:13
4 Nov 2024
@aleksana:mozilla.orgaleksana 🏳️‍⚧️ (force me to bed after 18:00 UTC)Someone reported on hacker news that yt-dlp 2024.10.22 (which we are also using) has malicious behavior: https://news.ycombinator.com/item?id=4204060012:03:10
@aleksana:mozilla.orgaleksana 🏳️‍⚧️ (force me to bed after 18:00 UTC)No conclusion has been drawn yet12:04:27
@sandro:supersandro.deSandro 🐧we are not using the prebuilt binaries in the first place and the actual content is also being disputed 15:52:07
@martijn:plebian.nlmartijn joined the room.18:41:25
@frontraffle:transfem.devNeco Arc left the room.19:58:37
@fifteenconcierge:matrix.org@fifteenconcierge:matrix.org joined the room.20:26:13
@fifteenconcierge:matrix.org@fifteenconcierge:matrix.org left the room.20:31:32
@fifteenconcierge:matrix.org@fifteenconcierge:matrix.org joined the room.20:35:42
@a1ois:matrix.orgAlois set a profile picture.21:12:08
@alois:kemono.sualois 🌱 joined the room.21:17:03
@a10is:matrix.orga10is joined the room.21:31:12
5 Nov 2024
@a1ois:matrix.orgAlois
In reply to @aleksana:mozilla.org
Someone reported on hacker news that yt-dlp 2024.10.22 (which we are also using) has malicious behavior: https://news.ycombinator.com/item?id=42040600
complete nonsense; can be safely ignored + we compile from source
00:17:59
@a1ois:matrix.orgAlois
In reply to @aleksana:mozilla.org
Someone reported on hacker news that yt-dlp 2024.10.22 (which we are also using) has malicious behavior: https://news.ycombinator.com/item?id=42040600
*
00:18:09
@grossmap:in.tum.de@grossmap:in.tum.de left the room.14:15:08
6 Nov 2024
@scrumplex:duckhub.ioScrumplexhttps://github.com/NixOS/nixpkgs/pull/35396808:12:13
7 Nov 2024
@emilazy:matrix.orgemilyhttps://github.com/NixOS/nixpkgs/pull/354139 https://github.com/NixOS/nixpkgs/pull/35414005:22:44
@vcunat:matrix.orgvcunatMissing expat triage for 24.05: https://github.com/NixOS/nixpkgs/pull/354155#issuecomment-246179524510:29:35
@vcunat:matrix.orgvcunatThough it's only a NULL dereference and 24.05 won't live very long anyway.10:34:08
@leona:leona.isleonait seems quite trivial to backport, so I'd do it 11:13:18
@teutat3s:pub.solarteutat3shttps://github.com/NixOS/nixpkgs/pull/35268917:26:39
8 Nov 2024
@jschvz:matrix.orgjschvz joined the room.02:57:52
10 Nov 2024
@chrisoboe:one.ems.hostChrisOboe removed their profile picture.11:56:25
11 Nov 2024
@k900:0upti.meK900 https://github.com/dani-garcia/vaultwarden/releases/tag/1.32.4 uh oh 04:11:39

Show newer messages


Back to Room ListRoom Version: 6