NixOS Security Triage | 707 Members | |
| Coordination and triage of security issues in nixpkgs | 218 Servers |
| Sender | Message | Time |
|---|---|---|
| 9 Apr 2024 | ||
| 12:26:57 | ||
| * The security researchers at exploit.org claimed they've found an RCE in Telegram Desktop's latest version (seems 4.16.1 at least), and updated a demonstration video targeting Windows build. Someone in the comment claimed they could not trigger the PoC in 4.16.4. Currently 23.11 and unstable branch has 4.16.1, and master was updated to 4.16.4 yesterday. Original message: Link: https://t.me/exploitorg/30 Edit: telegram official said they could not find the vulnerability and the demonstration video is likely staged. https://twitter.com/telegram/status/1777677055837995151 | 12:50:10 | |
| 13:24:35 | ||
| 23:12:29 | ||
| 23:22:53 | ||
| Alas, I am travelling and don't really have time rn | 23:49:14 | |
| 10 Apr 2024 | ||
| Redacted or Malformed Event | 04:55:35 | |
| 05:15:59 | ||
| 20:29:23 | ||
| https://github.com/YuriiCrimson/ExploitGSM/ anyone aware of this security vulnerability? | 20:29:46 | |
| That repo looks extremely sus and the behavior of the author is also very weird | 20:33:21 | |
| * That repo looks extremely sus and the behavior of the author is also very weird, lets follow up in #security-discuss:nixos.org if need be | 20:33:52 | |
| Alright | 20:34:11 | |
| 11 Apr 2024 | ||
| 20:44:07 | ||
| 12 Apr 2024 | ||
| 08:07:21 | ||
| * The security researchers at exploit.org claimed they've found an RCE in Telegram Desktop's latest version (seems 4.16.1 at least), and updated a demonstration video targeting Windows build. Someone in the comment claimed they could not trigger the PoC in 4.16.4. Currently 23.11 and unstable branch has 4.16.1, and master was updated to 4.16.4 yesterday. Original message: Link: https://t.me/exploitorg/30 Edit: telegram official said they could not find the vulnerability and the demonstration video is likely staged. https://twitter.com/telegram/status/1777677055837995151 Edit again: RCE confirmed but not zero-click. The user have to click a file that appear to be video files. Affected versions are 4.16.0 to 4.16.6. | 11:24:06 | |
| https://www.openwall.com/lists/oss-security/2024/04/12/11 | 20:46:12 | |
| * https://www.openwall.com/lists/oss-security/2024/04/12/11 php | 20:46:32 | |
| ma27 | 20:48:00 | |
| huh, nobody was faster? fine, on it. | 20:48:50 | |
| https://github.com/NixOS/nixpkgs/pull/303711 | 21:05:00 | |
| 13 Apr 2024 | ||
| 08:27:37 | ||
| https://chromereleases.googleblog.com/2024/04/stable-channel-update-for-desktop_10.html cc emily | 11:06:14 | |
| Done in https://github.com/NixOS/nixpkgs/pull/303377 https://github.com/NixOS/nixpkgs/pull/303471 Somehow missed it in GH search, sorry for the noise | 12:55:11 | |
| 15 Apr 2024 | ||
| Botan 3.4.0 was released: https://github.com/NixOS/nixpkgs/pull/304220 | 09:44:54 | |
| 16:17:25 | ||
| https://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-p521-bias.html | 19:22:28 | |
| * https://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-p521-bias.html ( https://hachyderm.io/@simontatham/112276855758487211 ) | 19:22:46 | |
| https://github.com/NixOS/nixpkgs/pull/304354 | 19:55:11 | |
| 16 Apr 2024 | ||
| 01:01:36 | ||