gchristensen changed the topic of #nixos-security to: Vulnerability Roundup Issues: https://github.com/NixOS/nixpkgs/issues?utf8=%E2%9C%93&q=is%3Aissue+is%3Aopen+Vulnerability+roundup + https://broken.sh
anselmolsm has quit [Quit: Konversation terminated!]
ajs124 has quit [Quit: killed]
ajs124 has joined #nixos-security
pie_[bnc] has quit [Changing host]
pie_[bnc] has joined #nixos-security
aminechikhaoui has quit [Quit: Ping timeout (120 seconds)]
aminechikhaoui has joined #nixos-security
FRidh has joined #nixos-security
hax404 has quit [Ping timeout: 272 seconds]
hax404 has joined #nixos-security
hax404 has quit [Ping timeout: 240 seconds]
hax404 has joined #nixos-security
hax404 has quit [Ping timeout: 240 seconds]
hax404 has joined #nixos-security
hax404 has quit [Ping timeout: 240 seconds]
hax404 has joined #nixos-security
hax404 has quit [Remote host closed the connection]
hax404 has joined #nixos-security
globin_ has joined #nixos-security
globin has quit [Ping timeout: 246 seconds]
hax404 has quit [Ping timeout: 240 seconds]
hax404 has joined #nixos-security
hax404 has quit [Ping timeout: 240 seconds]
hax404 has joined #nixos-security
hax404 has quit [Ping timeout: 240 seconds]
hax404 has joined #nixos-security
ajs124 has quit [Ping timeout: 260 seconds]
WilliButz has quit [Ping timeout: 264 seconds]
WilliButz has joined #nixos-security
ajs124 has joined #nixos-security
vesper11 has quit [Ping timeout: 256 seconds]
vesper has joined #nixos-security
anselmolsm has joined #nixos-security
primeos has quit [Quit: WeeChat 2.4]
primeos has joined #nixos-security
andi- has quit [Ping timeout: 244 seconds]
primeos has quit [Client Quit]
justanotheruser has quit [Ping timeout: 240 seconds]
primeos has joined #nixos-security
andi- has joined #nixos-security
justanotheruser has joined #nixos-security
zarel has quit [Ping timeout: 256 seconds]
zarel has joined #nixos-security
BrilliantRose has joined #nixos-security
BrilliantRose has quit [Client Quit]
stigo has quit [Remote host closed the connection]
stigo has joined #nixos-security
FRidh has quit [Ping timeout: 244 seconds]
murphy has joined #nixos-security
murphy has quit [Changing host]
murphy has joined #nixos-security
<hexa-> looking into openldap update
qyliss has quit [Quit: bye]
qyliss has joined #nixos-security
<hexa-> #86246
<{^_^}> https://github.com/NixOS/nixpkgs/pull/86246 (by mweinelt, 28 seconds ago, open): openldap: 2.4.49 → 2.4.50
<hexa-> #86247
<{^_^}> https://github.com/NixOS/nixpkgs/pull/86247 (by mweinelt, 9 seconds ago, open): [20.03] openldap: 2.4.49 → 2.4.50
zarel has quit [Quit: ZNC 1.7.4 - https://znc.in]
zarel has joined #nixos-security
<flokli> Thanks hexa- :-)
<flokli> I'm not sure about the size of these rebuilds. I doubt 19.09 will go through another staging cycle
<hexa-> i can rebase that if need be :)
<flokli> I'd prefer it to go to staging for 20.03 and master
<hexa-> staging for 20.03, staging-next for master
<flokli> yeah, staging-next should be fine too
infinisil is now known as infi
infi is now known as infinisil
justanotheruser has quit [Ping timeout: 246 seconds]
<hexa-> #86268 #86270 #86271
<{^_^}> https://github.com/NixOS/nixpkgs/pull/86268 (by mweinelt, 14 minutes ago, open): coturn: apply patch for CVE-2020-6061/6062
<{^_^}> https://github.com/NixOS/nixpkgs/pull/86270 (by mweinelt, 9 minutes ago, open): [20.03] coturn: apply patch for CVE-2020-6061/6062
<{^_^}> https://github.com/NixOS/nixpkgs/pull/86271 (by mweinelt, 3 minutes ago, open): [19.09] coturn: apply patch for CVE-2020-6061/6062
justanotheruser has joined #nixos-security
<ajs124> hexa-: thanks! coturn is such a shitshow. Looking at their commit history, you should probably just run master.
<ajs124> But I was so happy that I managed to get that POS working properly, that I just stopped looking at anything related to it in any way, so now I just have an insecure version deployed -.-
<hexa-> yeah, their release fu is not that great
<hexa-> describe on master has an older version than the newest tag
<hexa-> the commits didn't really apply, so I fetched the debian patch against 4.5.1.1 instead
<ajs124> their fu is not that great, release or otherwise. The only reason why anyone deploys it is because there is literally no alternative. But I shouldn't use this channel to rant... thanks that you're looking into it!
<hexa-> yeah, stacks like matrix and jabber use coturn … so we're SOL