andi- changed the topic of #nixos-security to: Vulnerability Roundup Issues: https://github.com/NixOS/nixpkgs/issues?utf8=%E2%9C%93&q=is%3Aissue+is%3Aopen+Vulnerability+roundup + https://broken.sh | Currently supported releases: unstable (master), 20.09, 20.03 (until 27th of November)
dstzd has quit [Quit: ZNC - https://znc.in]
dstzd has joined #nixos-security
supersandro2000 has quit [Disconnected by services]
supersandro2000 has joined #nixos-security
kalbasit has quit [Remote host closed the connection]
kalbasit has joined #nixos-security
cole-h has quit [Ping timeout: 240 seconds]
ris has quit [Ping timeout: 246 seconds]
rajivr has joined #nixos-security
lassulus has quit [Ping timeout: 256 seconds]
lassulus has joined #nixos-security
lassulus has quit [Ping timeout: 256 seconds]
lassulus has joined #nixos-security
lassulus has quit [Ping timeout: 246 seconds]
lassulus has joined #nixos-security
lassulus has quit [Ping timeout: 256 seconds]
lassulus has joined #nixos-security
kalbasit has quit [Ping timeout: 256 seconds]
justanotheruser has quit [Ping timeout: 244 seconds]
justanotheruser has joined #nixos-security
sgo has quit [Ping timeout: 260 seconds]
sgo has joined #nixos-security
star_cloud has quit [Ping timeout: 246 seconds]
cole-h has joined #nixos-security
lassulus has quit [Quit: WeeChat 2.7.1]
FRidh has joined #nixos-security
sgo is now known as stigo
lassulus has joined #nixos-security
FRidh has quit [Ping timeout: 260 seconds]
star_cloud has joined #nixos-security
lassulus has quit [Ping timeout: 240 seconds]
lassulus has joined #nixos-security
cole-h has quit [Ping timeout: 256 seconds]
lassulus has quit [Read error: error:1408F10B:SSL routines:ssl3_get_record:wrong version number]
lassulus has joined #nixos-security
FRidh has joined #nixos-security
lassulus has quit [Ping timeout: 246 seconds]
star_cloud has quit [Ping timeout: 246 seconds]
star_cloud has joined #nixos-security
star_cloud has quit [Ping timeout: 260 seconds]
lassulus has joined #nixos-security
supersandro2000 has quit [Quit: The Lounge - https://thelounge.chat]
supersandro2000 has joined #nixos-security
justanotheruser has quit [Ping timeout: 264 seconds]
star_cloud has joined #nixos-security
justanotheruser has joined #nixos-security
lassulus has quit [Quit: WeeChat 2.9]
lassulus has joined #nixos-security
supersandro2000 has quit [Quit: The Lounge - https://thelounge.chat]
supersandro2000 has joined #nixos-security
arianvp has joined #nixos-security
<arianvp> are there bugs in the vulnix CPE matcher?
<arianvp> wire-desktop is on version 3.21 in nixpkgs and that is not in the CPE for https://nvd.nist.gov/vuln/detail/CVE-2020-27853/cpes but yet vulnix marks it as vulnerable
<supersandro2000> maybe it matches https://nvd.nist.gov/products/cpe/detail/826253?keyword=cpe%3A2.3%3Aa%3Awire%3Awire%3A-%3A*%3A*%3A*%3A*%3A*%3A*%3A*&status=FINAL,DEPRECATED&orderBy=CPEURI&namingFormat=2.3 ?
<arianvp> hmm what should I change in the naming format to make it not match? I'm not very familiar with the format
<arianvp> I'll see if I can get it updated
<arianvp> ah it is because the package is named `wire-desktop` on nixos
<arianvp> instead of `wire` like on Ubuntu
<arianvp> can I create some alias rule for this in vulnix?
<arianvp> no wait.. if that was the problem it wouldn't match at all. confused face
<supersandro2000> I have no clue. Just trying to do an educated guess here.
<arianvp> hm I thin it's because the reporter added a date on which the issue was fixed instead of a version number
<arianvp> I'll see if I can get the exact version number on the page
<arianvp> thanks for rubber ducking with me =)
kalbasit has joined #nixos-security
<supersandro2000> I am a big rubber ducker, too
ehmry has quit [Ping timeout: 272 seconds]
rajivr has quit [Quit: Connection closed for inactivity]
kalbasit_ has joined #nixos-security
kalbasit has quit [Ping timeout: 240 seconds]
kalbasit_ has quit [Remote host closed the connection]
kalbasit has joined #nixos-security
cole-h has joined #nixos-security
ris has joined #nixos-security
Rostand has joined #nixos-security
red[evilred] has joined #nixos-security
<red[evilred]> Yes there are issues
<red[evilred]> and you'll find a lot of misidentified / mis-vendored stuff
<red[evilred]> short of maintaining translation tables it's a hard problem
<red[evilred]> tables, plural
<red[evilred]> because sometimes repology != nvd != nixos
FRidh has quit [Quit: Konversation terminated!]
ehmry has joined #nixos-security
KREYREEN has quit [Ping timeout: 240 seconds]
KREYREEN has joined #nixos-security
star_cloud has quit [Remote host closed the connection]
star_cloud has joined #nixos-security
red[evilred] has quit [Quit: Idle timeout reached: 10800s]
star_cloud has quit [Excess Flood]
star_cloud has joined #nixos-security
dstzd has quit [Quit: ZNC - https://znc.in]
dstzd has joined #nixos-security