wdormann ,
@wdormann@infosec.exchange avatar

Just a backdoor in XZ.
Nothing important.
https://www.openwall.com/lists/oss-security/2024/03/29/4

wdormann OP ,
@wdormann@infosec.exchange avatar

Interesting how this backdoor can lead to an sshd compromise.

"openssh does not directly use liblzma. However debian and several other distributions patch openssh to support systemd notification, and libsystemd does depend on lzma."

wdormann OP ,
@wdormann@infosec.exchange avatar

Presumably somebody is going back through all of this actor's commits back to 2021 to check for shenanigans?
On the other hand, that seems like a lot of work.
It's probably all good. 😬

wdormann OP ,
@wdormann@infosec.exchange avatar

More about this actor:
https://boehs.org/node/everything-i-know-about-the-xz-backdoor
"libarchive should also be considered compromised until proven otherwise."

Good times...

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • test
  • worldmews
  • mews
  • All magazines