!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

692 Members
Coordination and triage of security issues in nixpkgs216 Servers

Load older messages


SenderMessageTime
18 May 2024
@hexa:lossy.networkhexahttps://www.libreoffice.org/about-us/security/advisories/cve-2024-3044/15:39:05
@hexa:lossy.networkhexa * https://www.libreoffice.org/about-us/security/advisories/cve-2024-3044/ CVE-2024-3044: Graphic on-click binding allows unchecked script execution15:39:18
@k900:0upti.meK900Fun fact: our libreoffice is comically out of date15:39:56
@kranzes:matrix.orgkranzes left the room.16:34:27
@dp:anarchyislove.xyzDustin PlattnerYes, I had to move to Onlyoffice.16:49:40
19 May 2024
@conr:mozilla.org@conr:mozilla.org left the room.01:03:33
20 May 2024
@ckie:ckie.devmei 🌒& changed their display name from ckie (they/them) to mei 🌒&.00:09:42
@alina:kescher.at@alina:kescher.at changed their display name from alina to alina (DECT: WUFF/WOOF).14:27:38
21 May 2024
@bumperboat:matrix.org@bumperboat:matrix.org changed their display name from bumperboat (UTC+8) to bumperboat (UTC+7).04:34:22
@hexa:lossy.networkhexa https://github.com/asterisk/asterisk/security/advisories/GHSA-qqxj-v78h-hrf9 yorickvp 11:20:51
@tgerbet:matrix.orgtgerbetTook care of it in https://github.com/NixOS/nixpkgs/pull/31346519:27:30
@yorickvp:matrix.orgyorickvpThanks! 20:16:46
@hexa:lossy.networkhexaplease review 🙂20:18:38
@tgerbet:matrix.orgtgerbethttps://vin01.github.io/piptagole/escape-sequences/iterm2/hyper/url-handlers/code-execution/2024/05/21/arbitrary-url-schemes-terminal-emulators.html Would be nice if someone using macOS/iTerm2 can take a look21:51:47
22 May 2024
@fabaff:matrix.orgFabian Affolterrequests CVE-2024-35195 https://github.com/NixOS/nixpkgs/pull/31359908:29:43
@yorickvp:matrix.orgyorickvp
In reply to @hexa:lossy.network
please review 🙂
merged! in time for the fork, I believ
08:54:26
@yorickvp:matrix.orgyorickvp
In reply to @hexa:lossy.network
please review 🙂
* merged! in time for the fork, I believe
08:54:28
@yorickvp:matrix.orgyorickvp * merged! in time for the branch-off, I believe 08:54:32
@nam3l33ss:matrix.org·☽•Nameless☆•777 · ± changed their display name from ·☽•Nameless☆•777 · to ·☽•Nameless☆•777 · ±.09:22:02
@hexa:lossy.networkhexa https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5148 Jan Tojnar gnome-remote-desktop 46.2 11:23:20
@hexa:lossy.networkhexa * https://vulners.com/redhatcve/RH:CVE-2024-5148 Jan Tojnar gnome-remote-desktop 46.2 11:24:04
@mjolnir:nixos.orgNixOS Moderation Bot banned @5m5z3q888q5prxkg:chat.lightnovel-dungeon.de@5m5z3q888q5prxkg:chat.lightnovel-dungeon.de (Suspended until 2024-05-29).11:45:45
@hexa:lossy.networkhexa https://webkitgtk.org/security/WSA-2024-0003.html Jan Tojnar 12:12:02
@ity:itycodes.org@ity:itycodes.org joined the room.12:38:40
@tgerbet:matrix.orgtgerbetFix was merged for unstable ~1hour ago and a backport PR was created for 23.11 https://github.com/NixOS/nixpkgs/pull/31365012:40:49
@j-k:matrix.orgj-kHello all. I made a backport for tailscale to address https://github.com/NixOS/nixpkgs/issues/313678 https://tailscale.com/security-bulletins#ts-2024-005 LMK if I messed anything up. It involved backporting go 1.22 too https://github.com/NixOS/nixpkgs/pull/31369114:20:16
@vieta:chaos.jetztvieta joined the room.15:17:56
@mjolnir:nixos.orgNixOS Moderation Botchanged room power levels.15:26:09
@mjolnir:nixos.orgNixOS Moderation Botchanged room power levels.15:28:23
23 May 2024
@drewskiwooskie:matrix.org@drewskiwooskie:matrix.org left the room.03:23:20

Show newer messages


Back to Room ListRoom Version: 6