Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #268653

Re: [oss-security] backdoor in upstream xz/liblzma leading to ssh server compromise

From Andy Smith <andy@strugglers.net>
Newsgroups linux.debian.user
Subject Re: [oss-security] backdoor in upstream xz/liblzma leading to ssh server compromise
Date 2024-03-30 22:50 +0100
Message-ID <InOKl-2SJC-1@gated-at.bofh.it> (permalink)
References <InoGd-2zHX-3@gated-at.bofh.it> <InoGd-2zHX-1@gated-at.bofh.it> <InNbz-2RYK-1@gated-at.bofh.it> <InNXY-2SeM-3@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


Hi,

On Sat, Mar 30, 2024 at 08:57:14PM +0000, fxkl47BF@protonmail.com wrote:
> so is this a threat to us normal debian users

If you have to ask, i.e. you do not know how to check that your
Debian install is secured against extremely well known recent
exploits that have been plastered across the entire Internet,
then yes, your Debian install is at risk - from this gap in your
knowledge.

It's okay to not know things, but let's rectify that.

Every Debian user that manages their own machine(s) should read
this:

    https://www.debian.org/doc/manuals/debian-handbook/

In it there is a chapter on keeping up to date:

    https://www.debian.org/doc/manuals/debian-handbook/sect.regular-upgrades.en.html

That will get you a long way - letting you kn ow when there's
updated packages available for your version of Debian.

But what about known issues that may or may not have been yet
tackled by Debian?

You can find a reference for advisories here:

    https://www.debian.org/security/

And you can be fed info by email by subscribing to:

    https://lists.debian.org/debian-security-announce/

Between those last two links your specific question here is answered
but in case you object to being taught to fish, here is your fish:

    https://lists.debian.org/debian-security-announce/2024/msg00057.html

Bon appetit.
Andy

-- 
https://bitfolk.com/ -- No-nonsense VPS hosting

Back to linux.debian.user | Previous | Next — Previous in thread | Find similar | Unroll thread


Thread

Re: [oss-security] backdoor in upstream xz/liblzma leading to ssh  server compromise Jeffrey Walton <noloader@gmail.com> - 2024-03-30 21:10 +0100
  Re: [oss-security] backdoor in upstream xz/liblzma leading to ssh server compromise fxkl47BF@protonmail.com - 2024-03-30 22:00 +0100
    Re: [oss-security] backdoor in upstream xz/liblzma leading to ssh  server compromise Michel Verdier <mv524@free.fr> - 2024-03-30 22:30 +0100
    Re: [oss-security] backdoor in upstream xz/liblzma leading to ssh  server compromise Andy Smith <andy@strugglers.net> - 2024-03-30 22:50 +0100

csiph-web