Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #268632

Re: Fwd: [oss-security] backdoor in upstream xz/liblzma leading to ssh server compromise

From Andy Smith <andy@strugglers.net>
Newsgroups linux.debian.user
Subject Re: Fwd: [oss-security] backdoor in upstream xz/liblzma leading to ssh server compromise
Date 2024-03-29 21:00 +0100
Message-ID <Inqyl-2AVn-21@gated-at.bofh.it> (permalink)
References <InoGd-2zHX-3@gated-at.bofh.it> <InoGd-2zHX-1@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


Hello,

On Fri, Mar 29, 2024 at 01:52:18PM -0400, Jeffrey Walton wrote:
> Seems relevant since Debian adopted xz about 10 years ago.

Though we do not know how or why this developer has come to recently
put apparent exploits in it, so we can't yet draw much of a
conclusion beyond "sometimes people do bad stuff to good software".

Sounds like it'll be an interesting story though. It's going to
drive a lot of conspiracy theories.

Thanks,
Andy

-- 
https://bitfolk.com/ -- No-nonsense VPS hosting

Back to linux.debian.user | Previous | Next | Find similar | Unroll thread


Thread

Re: Fwd: [oss-security] backdoor in upstream xz/liblzma leading to  ssh server compromise Andy Smith <andy@strugglers.net> - 2024-03-29 21:00 +0100

csiph-web