social.sour.is
  • Communities
  • Create Post
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
@ngn@lemy.lol to Memes@lemmy.mlEnglish • 1 year ago

love is in the air?

lemy.lol

message-square
42
fedilink
0

love is in the air?

lemy.lol

@ngn@lemy.lol to Memes@lemmy.mlEnglish • 1 year ago
message-square
42
fedilink
  • @30p87@feddit.de
    link
    fedilink
    0•1 year ago

    Arch isn’t affected afaik, as it specifically targeted Debian and RPM. Also, sshd isn’t linked against liblzma (or something along those lines). And I hope that’s true, because otherwise, I had a backdoor on a public system for over a month.

    • u/lukmly013 💾 (lemmy.sdf.org)
      link
      fedilink
      English
      0•
      edit-2
      1 year ago

      And the packages on most distros should be long updated by now.

      Even Termux updated to 5.6.1+really5.4.5 just 2 hours after Arch Linux.

      • @30p87@feddit.de
        link
        fedilink
        0•1 year ago

        I just updated all packages in Termux actually lol

      • @Pantherina@feddit.de
        link
        fedilink
        0•1 year ago

        very nice!

        • u/lukmly013 💾 (lemmy.sdf.org)
          link
          fedilink
          English
          0•1 year ago

          What package manager is that?

    • @ReversalHatchery@beehaw.org
      link
      fedilink
      English
      0•1 year ago

      Also, sshd isn’t linked against liblzma

      Not directly, but it’s loaded through systemd’s lib. It is there.

    • @wildbus8979@sh.itjust.works
      link
      fedilink
      0•1 year ago

      https://archlinux.org/news/the-xz-package-has-been-backdoored/

      • @30p87@feddit.de
        link
        fedilink
        0•1 year ago

        And as https://www.openwall.com/lists/oss-security/2024/03/29/4 says:

        “These conditions include targeting only x86-64 linux: […] Building with gcc and the gnu linker […] Running as part of a debian or RPM package build:”

        I’m not an expert of course.

        • brvslvrnst
          link
          fedilink
          0•1 year ago

          Holy shit that was a hell of a dive. And no wonder the dude got it working, he was just pounding those “test and translation” commits

      • @HopFlop@discuss.tchncs.de
        link
        fedilink
        0•1 year ago

        Yeah but the backdoor does not work on Arch (as far as we currently know). It relies on a linking of libraries that Arch doesnt do by default.

Memes@lemmy.ml

!memes@lemmy.ml

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !memes@lemmy.ml

Rules:

  1. Be civil and nice.
  2. Try not to excessively repost, as a rule of thumb, wait at least 2 months to do it if you have to.
  • 121 users / day
  • 353 users / week
  • 932 users / month
  • 5.19K users / 6 months
  • 51K subscribers
  • 15.3K Posts
  • 307K Comments
  • Modlog
  • mods:
  • ghost_laptop
  • @sexy_peach@feddit.de
  • Cyclohexane
  • Arthur Besse
  • BE: 0.19.3
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org