Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #268632 > unrolled thread

Re: Fwd: [oss-security] backdoor in upstream xz/liblzma leading to ssh server compromise

Started byAndy Smith <andy@strugglers.net>
First post2024-03-29 21:00 +0100
Last post2024-03-29 21:00 +0100
Articles 1 — 1 participant

Back to article view | Back to linux.debian.user

This discussion starts older than the indexed window; earlier articles aren't shown. The article labeled Started by below is the oldest one visible, not the original post.


Contents

  Re: Fwd: [oss-security] backdoor in upstream xz/liblzma leading to  ssh server compromise Andy Smith <andy@strugglers.net> - 2024-03-29 21:00 +0100

#268632 — Re: Fwd: [oss-security] backdoor in upstream xz/liblzma leading to ssh server compromise

FromAndy Smith <andy@strugglers.net>
Date2024-03-29 21:00 +0100
SubjectRe: Fwd: [oss-security] backdoor in upstream xz/liblzma leading to ssh server compromise
Message-ID<Inqyl-2AVn-21@gated-at.bofh.it>
Hello,

On Fri, Mar 29, 2024 at 01:52:18PM -0400, Jeffrey Walton wrote:
> Seems relevant since Debian adopted xz about 10 years ago.

Though we do not know how or why this developer has come to recently
put apparent exploits in it, so we can't yet draw much of a
conclusion beyond "sometimes people do bad stuff to good software".

Sounds like it'll be an interesting story though. It's going to
drive a lot of conspiracy theories.

Thanks,
Andy

-- 
https://bitfolk.com/ -- No-nonsense VPS hosting

[toc] | [standalone]


Back to top | Article view | linux.debian.user


csiph-web