andi- changed the topic of #nixos-security to: Vulnerability Roundup Issues: https://github.com/NixOS/nixpkgs/issues?utf8=%E2%9C%93&q=is%3Aissue+is%3Aopen+Vulnerability+roundup + https://broken.sh | Currently supported releases: unstable (master), 20.09, 20.03 (until 27th of November)
ehmry has quit [Quit: No Ping reply in 180 seconds.]
ehmry has joined #nixos-security
justanotheruser has quit [Ping timeout: 272 seconds]
stigo has quit [Ping timeout: 246 seconds]
stigo has joined #nixos-security
rajivr has joined #nixos-security
stigo has quit [Ping timeout: 256 seconds]
stigo has joined #nixos-security
ris has quit [Ping timeout: 264 seconds]
tilpner_ has joined #nixos-security
tilpner has quit [Ping timeout: 256 seconds]
tilpner_ is now known as tilpner
LnL has quit [Quit: exit 1]
LnL has joined #nixos-security
LnL has joined #nixos-security
LnL- has joined #nixos-security
LnL- has joined #nixos-security
LnL- has quit [Changing host]
LnL has quit [Ping timeout: 260 seconds]
star_cloud has quit [Remote host closed the connection]
star_cloud has joined #nixos-security
LnL has joined #nixos-security
LnL has joined #nixos-security
LnL has quit [Changing host]
prusnak has quit [Ping timeout: 272 seconds]
prusnak has joined #nixos-security
prusnak has quit [Ping timeout: 272 seconds]
prusnak has joined #nixos-security
prusnak has quit [Ping timeout: 272 seconds]
red[evilred] has quit [Quit: Idle timeout reached: 10800s]
prusnak has joined #nixos-security
star_cloud has quit [Remote host closed the connection]
star_cloud has joined #nixos-security
star_cloud has quit [Remote host closed the connection]
star_cloud has joined #nixos-security
midchildan has quit [Ping timeout: 272 seconds]
midchildan has joined #nixos-security
kalbasit has quit [Ping timeout: 240 seconds]
FRidh has joined #nixos-security
sphalerite is now known as LinuxHackerman
LinuxHackerman is now known as sphalerite
ddima has joined #nixos-security
tilpner has quit [Remote host closed the connection]
tilpner has joined #nixos-security
<stigo> #104049 #104050
<{^_^}> https://github.com/NixOS/nixpkgs/pull/104049 (by stigtsp, 6 minutes ago, open): firefox-bin: 82.0.3 -> 83.0
<{^_^}> https://github.com/NixOS/nixpkgs/pull/104050 (by stigtsp, 5 minutes ago, open): [20.09] firefox-bin: 82.0.3 -> 83.0
<stigo> #104051 #104053
<{^_^}> https://github.com/NixOS/nixpkgs/pull/104051 (by stigtsp, 5 minutes ago, open): firefox: 82.0.3 -> 83.0
<{^_^}> https://github.com/NixOS/nixpkgs/pull/104053 (by stigtsp, 3 minutes ago, open): [20.09] firefox: 82.0.3 -> 83.0
kalbasit has joined #nixos-security
<hexa-> taking care of openldap today
<hexa-> stigo: fwiw: we do still support 20.03 until the 28th
<hexa-> not sure what that means for firefox
<hexa-> 27th even
<hexa-> #104064 #104068
<{^_^}> https://github.com/NixOS/nixpkgs/pull/104064 (by mweinelt, 25 minutes ago, open): openldap: 2.4.51 -> 2.4.56
<{^_^}> https://github.com/NixOS/nixpkgs/pull/104068 (by mweinelt, 21 seconds ago, open): [20.03] openldap: apply security patches
justanotheruser has joined #nixos-security
<hexa-> poked srhb to handle CVE-2020-25660
<hexa-> >> ceph: CEPHX_V2 replay attack protection lost
rajivr has quit [Quit: Connection closed for inactivity]
ris has joined #nixos-security
<andi-> ugh, pipewire an Firefox.. As feared it is really a mess...
<hexa-> -v?
<andi-> It will bite us again and again with updating firefox. If there is a security fix that is urgent (most releases) I'd just drop pipewire support the moment the patches fail.
<hexa-> fair
red[evilred] has joined #nixos-security
<red[evilred]> CVE-2020-25677 - ceph (from redhat) - vulnerable to replay attacks
<red[evilred]> (auth)
<andi-> red[evilred]: hexa- just posted that a few minutes ago
<red[evilred]> okay - didn't see it - thx
<red[evilred]> (I saw it on oss-security list - which is probably whhere he saw it)
<red[evilred]> still - better to have it twice than not at all
<hexa-> yes, srhb is handling it
justanotheruser has quit [Ping timeout: 272 seconds]
<stigo> #104093 <-- hexa- :)
<{^_^}> https://github.com/NixOS/nixpkgs/pull/104093 (by stigtsp, 36 minutes ago, open): [20.03] firefox-bin: 82.0 -> 83.0
<hexa-> stigo++
<{^_^}> stigo's karma got increased to 4
ninjin has quit [Remote host closed the connection]
ninjin has joined #nixos-security