<hexa->
> Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing the malicious image
<{^_^}>
error: syntax error, unexpected IN, expecting ')', at (string):494:38
<hexa->
12.00 in release-20.09
<hexa->
12.16 in unstable
<hexa->
and php-exif can shelv out to exiftool
<hexa->
nice
rajivr has joined #nixos-security
justanotheruser has quit [Ping timeout: 276 seconds]
justanotheruser has joined #nixos-security
justanotheruser has quit [Ping timeout: 260 seconds]
supersandro2000 has quit [Killed (kornbluth.freenode.net (Nickname regained by services))]
<hexa->
if someone more familiar with busybox usage in nixpkgs could answer this
<andi->
a minimal /bin/sh (just the sh part) is used for builds within the sandbox on NixOS systems. The tar and unxz features (and some coreutils-like things) are part of our bootstrap tarball. Not sure what the question in that PR actually is.
cole-h has quit [Quit: Goodbye]
cole-h has joined #nixos-security
justanotheruser has quit [Ping timeout: 260 seconds]
justanotheruser has joined #nixos-security
cole-h has quit [Quit: Goodbye]
cole-h has joined #nixos-security
supersandro2000 has quit [*.net *.split]
aminechikhaoui has joined #nixos-security
julm has joined #nixos-security
dotlambda has joined #nixos-security
supersandro2000 has joined #nixos-security
ajs124 has joined #nixos-security
justanotheruser has quit [Ping timeout: 246 seconds]