gchristensen changed the topic of #nixos-security to: Vulnerability Roundup Issues: https://github.com/NixOS/nixpkgs/issues?utf8=%E2%9C%93&q=is%3Aissue+is%3Aopen+Vulnerability+roundup + https://broken.sh
timokau[m] has quit [*.net *.split]
timokau[m] has joined #nixos-security
ris has quit [Ping timeout: 258 seconds]
<pie_> wowee
<ivan> the output is ${XDG_DATA_DIRS:+:}$XDG_DATA_DIRS
<ivan> but how does that work while inside a ''
<ivan> oops I meant to put this in #nixos-dev
<ivan> wow world\''${stuff} works but world\''stuff does not
hmpffff has quit [Quit: nchrrrr…]
qyliss has quit [Quit: bye]
<ivan> https://github.com/NixOS/nixpkgs/pulls/ivan cc gchristensen since you've been taking my chromium PRs
qyliss has joined #nixos-security
<ivan> we might need to get a CVE issued for that since it seems not that unlikely that someone would start chromium from a downloads directory with all kinds of untrusted .so files
<ivan> it got into 19.09 unfortunately
<ivan> wonder how much would break if we got rid of this https://sourceware.org/git/?p=glibc.git;a=blob;f=elf/dl-load.c;h=c1b6d4ba0f133409c749944fea989ea89822560d;hb=HEAD#l446
filemon has joined #nixos-security
filemon has quit [Ping timeout: 240 seconds]
__Sander__ has joined #nixos-security
<pie_> ivan: im somewhat speechless
hmpffff has joined #nixos-security
prusnak has joined #nixos-security
<prusnak> hi! does broken.sh have a json output?
hmpffff has quit [Quit: nchrrrr…]
__Sander__ has quit [Quit: Konversation terminated!]
<andi-> prusnak: yes
<andi-> just set `Accept: application/json`
<andi-> should work on all views
LnL has joined #nixos-security
LnL has joined #nixos-security
LnL has quit [Changing host]
<prusnak> andi-: thanks
ris has joined #nixos-security
hmpffff has joined #nixos-security
hmpffff has quit [Quit: nchrrrr…]
hmpffff has joined #nixos-security
hmpffff has quit [Quit: nchrrrr…]
<ris> #72387
<{^_^}> https://github.com/NixOS/nixpkgs/pull/72387 (by risicle, 14 seconds ago, open): jhead: add patches for CVE-2019-1010301, CVE-2019-1010302
<ris> #72397
<{^_^}> https://github.com/NixOS/nixpkgs/pull/72397 (by risicle, 18 seconds ago, open): jack2: 1.9.12 -> 1.9.13, addressing CVE-2019-13351