gchristensen changed the topic of #nixos-security to: Vulnerability Roundup Issues: https://github.com/NixOS/nixpkgs/issues?utf8=%E2%9C%93&q=is%3Aissue+is%3Aopen+Vulnerability+roundup + https://broken.sh
pie_ has quit [Remote host closed the connection]
kgz has joined #nixos-security
pie_ has joined #nixos-security
pie_ has quit [Ping timeout: 252 seconds]
<{^_^}> #67637 (by andir, 23 minutes ago, open): dovecot-pigeonhole: 0.5.7.1 -> 0.5.7.2 (CVE-2019-11500)
<{^_^}> #67639 (by andir, 4 minutes ago, open): [19.03] dovecot apply CVE-2019-11500 patches
pie_ has joined #nixos-security
pie_ has quit [Ping timeout: 248 seconds]
tokudan has joined #nixos-security
pie_ has joined #nixos-security
pie_ has quit [Ping timeout: 245 seconds]
pie_ has joined #nixos-security
<samueldr> >> RDoc documentations generated with previous versions have to be re-generated with newer RDoc
<samueldr> good thing this is a non-issue with nix :)
<andi-> how is that to be exploited?
<samueldr> (though this looks like it is a really low priority issue)
<andi-> Someone must host the static page and then others can pass in (search?) strings that get evaled?
<samueldr> not sure, it looks like they basically upgraded jQuery in RDoc because of the CVEs
<andi-> also from 2012 o.O
<samueldr> so it's possible it's not relevant to their use of jQuery
<andi-> but I guess that is what happens if you vendor dependencies once without tooling?
<samueldr> sounds like it
<samueldr> looks like they removed it
<andi-> I had a chat with a nodejs maintainer about our nix expression for it... They really want us to use all the vendored dependencies for it. Still wanted to report the failing tests to him since we should be able to make all of them pass or report to upstream why they fail.
<andi-> they just removed it without removing references to it?
<samueldr> I know about as much as you do as of now
tokudan has quit [Quit: ZNC 1.7.3 - https://znc.in]
tokudan has joined #nixos-security
pie_ has quit [Ping timeout: 245 seconds]