Atemu@lemmy.ml to Linux@lemmy.ml · 2 years agobackdoor in upstream xz/liblzma leading to ssh server compromisewww.openwall.comexternal-linkmessage-square93linkfedilinkarrow-up1521arrow-down10cross-posted to: selfhosted@lemmy.worldnetsec@lemmy.worldprogramming@programming.devcybersecurity@sh.itjust.works
arrow-up1521arrow-down1external-linkbackdoor in upstream xz/liblzma leading to ssh server compromisewww.openwall.comAtemu@lemmy.ml to Linux@lemmy.ml · 2 years agomessage-square93linkfedilinkcross-posted to: selfhosted@lemmy.worldnetsec@lemmy.worldprogramming@programming.devcybersecurity@sh.itjust.works
minus-squareflying_sheep@lemmy.mlBannedlinkfedilinkarrow-up9·2 years agoBackdoor only gets inserted when building RPM or DEB. So while updating frequently is a good idea, it won’t change anything for Arch users today.
minus-squareSavvyBeardedFish@reddthat.comlinkfedilinkEnglisharrow-up22·2 years agoArchlinux’s XZ was compromised as well. News post Git change for not using tarballs from source
minus-squareflying_sheep@lemmy.mlBannedlinkfedilinkarrow-up13·2 years agoNo, read the link you posted: Arch does not directly link openssh to liblzma, and thus this attack vector is not possible. You can confirm this by issuing the following command: ldd "$(command -v sshd)" However, out of an abundance of caution, we advise users to remove the malicious code from their system by upgrading either way.
minus-squareprogandy@feddit.delinkfedilinkarrow-up5·edit-22 years agoI think that was a precaution. The malicious build script ran during the build, but the backdoor itself was most likely not included in the resuling package as it checked for specific packaging systems. https://www.openwall.com/lists/oss-security/2024/03/29/22
Backdoor only gets inserted when building RPM or DEB. So while updating frequently is a good idea, it won’t change anything for Arch users today.
Archlinux’s XZ was compromised as well.
News post
Git change for not using tarballs from source
No, read the link you posted:
I think that was a precaution. The malicious build script ran during the build, but the backdoor itself was most likely not included in the resuling package as it checked for specific packaging systems.
https://www.openwall.com/lists/oss-security/2024/03/29/22