gchristensen changed the topic of #nixos-security to: Vulnerability Roundup Issues: https://github.com/NixOS/nixpkgs/issues?utf8=%E2%9C%93&q=is%3Aissue+is%3Aopen+Vulnerability+roundup + https://broken.sh
<hexa-> If someone else could test and decide between #95583 and #95873 that'd be appreciated. It segfaults for me, but I'm not a user and the package is not maintained anyway.
<{^_^}> https://github.com/NixOS/nixpkgs/pull/95583 (by risicle, 4 days ago, open): [r20.03] sigil: 0.9.14 -> 0.9.16, addressing CVE-2019-14452
<{^_^}> https://github.com/NixOS/nixpkgs/pull/95873 (by risicle, 31 minutes ago, open): [20.03] sigil: add patches for CVE-2019-14452
<ris> does 0.9.14 segfault for you if you ensure you've built it yourself?
<ris> (unpatched 0.9.14 that is)
