andi- changed the topic of #nixos-security to: Vulnerability Roundup Issues: https://github.com/NixOS/nixpkgs/issues?utf8=%E2%9C%93&q=is%3Aissue+is%3Aopen+Vulnerability+roundup + https://broken.sh | Currently supported releases: unstable (master), 20.09, 20.03 (until 27th of November)
supersandro2000 has quit [Quit: Ping timeout (120 seconds)]
supersandro2000 has joined #nixos-security
supersandro20006 has joined #nixos-security
supersandro2000 has quit [Ping timeout: 264 seconds]
supersandro20006 is now known as supersandro2000
supersandro20004 has joined #nixos-security
supersandro2000 has quit [Ping timeout: 265 seconds]
supersandro20004 is now known as supersandro2000
tilpner_ has joined #nixos-security
tilpner has quit [Ping timeout: 260 seconds]
tilpner_ is now known as tilpner
rajivr has joined #nixos-security
eyJhb has joined #nixos-security
eyJhb has joined #nixos-security
eyJhb has quit [Ping timeout: 240 seconds]
feepo has quit [Ping timeout: 242 seconds]
star_cloud has quit [Ping timeout: 246 seconds]
feepo has joined #nixos-security
eyJhb has quit [Ping timeout: 240 seconds]
eyJhb has joined #nixos-security
eyJhb has joined #nixos-security
ajs124 has quit [Ping timeout: 240 seconds]
ajs124 has joined #nixos-security
fabian_a has joined #nixos-security
cole-h has quit [Ping timeout: 260 seconds]
supersandro2000 has quit [Quit: The Lounge - https://thelounge.chat]
supersandro2000 has joined #nixos-security
rajivr has quit [Quit: Connection closed for inactivity]
<stigo> hexa-++
<{^_^}> hexa-'s karma got increased to 22
supersandro2000 has quit [Read error: Connection reset by peer]
supersandro2000 has joined #nixos-security
rajivr has joined #nixos-security
qyliss has quit [Quit: bye]
qyliss has joined #nixos-security
cryptm0d has joined #nixos-security
cryptm0d has quit [Remote host closed the connection]
cryptm0d has joined #nixos-security
cryptm0d has quit [Remote host closed the connection]
fabian_a is now known as faffolter
cryptm0d has joined #nixos-security
julm has quit [Ping timeout: 240 seconds]
cole-h has joined #nixos-security
justanotheruser has quit [Ping timeout: 264 seconds]
justanotheruser has joined #nixos-security
cryptm0d has quit [Remote host closed the connection]
supersandro2000 has quit [Read error: Connection reset by peer]
supersandro2000 has joined #nixos-security
rajivr has quit [Quit: Connection closed for inactivity]
supersandro2000 has quit [Quit: The Lounge - https://thelounge.chat]
supersandro2000 has joined #nixos-security
supersandro2000 has quit [Quit: The Lounge - https://thelounge.chat]
supersandro2000 has joined #nixos-security
supersandro2000 has quit [Quit: The Lounge - https://thelounge.chat]
supersandro2000 has joined #nixos-security
cryptm0d has joined #nixos-security
cryptm0d has quit [Remote host closed the connection]
justanotheruser has quit [Ping timeout: 240 seconds]
justanotheruser has joined #nixos-security
<hexa-> Python 3.x through 3.9.1 has a buffer overflow in PyCArg_repr in _ctypes/callproc.c, which may lead to remote code execution in certain Python applications that accept floating-point numbers as untrusted input, as demonstrated by a 1e300 argument to c_double.from_param. This occurs because sprintf is used unsafely.
justan0theruser has joined #nixos-security
justanotheruser has quit [Ping timeout: 272 seconds]
supersandro2000 has quit [Quit: The Lounge - https://thelounge.chat]
supersandro2000 has joined #nixos-security
cryptm0d has joined #nixos-security
<ajs124> oof. time to patch all the python releases?
<gchristensen> ow
<flokli> wonder if python 2 is affected too, but noone cares due to it being EOL
<flokli> hah, according to gentoo, yes: https://security.gentoo.org/glsa/202101-18
<simpson> Only affects CPython, though. (Cold comfort for most users, but it's nice that it's not a stdlib patch, since that would have to be copied and applied multiple times.)
<ajs124> gentoo seems to be maintaining a python 2.7 fork here: https://gitweb.gentoo.org/fork/cpython.git/log/?h=gentoo-2.7-vanilla
cryptm0d has quit [Remote host closed the connection]
<hexa-> I'm on it
<hexa-> flokli: fck python2
faffolter has quit [Remote host closed the connection]