andi- changed the topic of #nixos-security to: Vulnerability Roundup Issues: https://github.com/NixOS/nixpkgs/issues?utf8=%E2%9C%93&q=is%3Aissue+is%3Aopen+Vulnerability+roundup + https://broken.sh | Currently supported releases: unstable (master), 20.09, 20.03 (until 27th of November)
star_cloud has quit [Ping timeout: 240 seconds]
<supersandro2000> NVD rates it a 9.8 but gnutls has a low severity https://nvd.nist.gov/vuln/detail/CVE-2021-20231
star_cloud has joined #nixos-security
<lukegb> or just bump to 3.7.1, I guess
<lukegb> which we're... already at?
jpo has quit [Ping timeout: 268 seconds]
jpo has joined #nixos-security
<supersandro2000> yeah. Didn't check that. I thought when the CVE is from today it surely isn't fixed yet.
supersandro2000 has quit [Remote host closed the connection]
supersandro2000 has joined #nixos-security
rajivr has joined #nixos-security
cole-h has quit [Ping timeout: 252 seconds]
cjb has quit []
Synthetica has joined #nixos-security
<hexa-> openssh 8.6 is out
<hexa-> supersandro2000: NVD Published Date:
<hexa-> 03/12/2021
<hexa-> not sure how it is "from today"
<hexa-> Subject: Announce: OpenSSH 8.6 released
<hexa-> > A flaw was found in NetworkManager. Setting match.path and activating a profile crashes NetworkManager. The highest threat from this vulnerability is to system availability.
<{^_^}> error: syntax error, unexpected IN, expecting ')', at (string):494:18
<hexa-> updating to 1.30.4 on master
star_cloud has quit [Ping timeout: 246 seconds]
<hexa-> and 1.26.8 on release-20.09
star_cloud has joined #nixos-security
<supersandro2000> hexa-: 🤦 read the wrong date. derp
rajivr has quit [Quit: Connection closed for inactivity]
cole-h has joined #nixos-security
star_cloud has quit [Ping timeout: 260 seconds]
star_cloud has joined #nixos-security
midchildan has quit [Ping timeout: 250 seconds]
nh2 has quit [Ping timeout: 245 seconds]
midchildan has joined #nixos-security
nh2 has joined #nixos-security
<{^_^}> #119909 (by mweinelt, 1 minute ago, open): [20.09] clamav: 0.102.4 -> 0.103.2
Synthetica has quit [Quit: Connection closed for inactivity]
cjb has joined #nixos-security
supersandro2000 is now known as Guest61649
Guest61649 has quit [Killed (hitchcock.freenode.net (Nickname regained by services))]
supersandro2000 has joined #nixos-security