Pricefield | Lemmy
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
@[email protected] to [email protected]English • 1 year ago

love is in the air?

lemy.lol

message-square
46
fedilink
342

love is in the air?

lemy.lol

@[email protected] to [email protected]English • 1 year ago
message-square
46
fedilink
  • @[email protected]
    link
    fedilink
    24•1 year ago

    Arch isn’t affected afaik, as it specifically targeted Debian and RPM. Also, sshd isn’t linked against liblzma (or something along those lines). And I hope that’s true, because otherwise, I had a backdoor on a public system for over a month.

    • u/lukmly013 💾 (lemmy.sdf.org)
      link
      fedilink
      English
      12•
      edit-2
      1 year ago

      And the packages on most distros should be long updated by now.

      Even Termux updated to 5.6.1+really5.4.5 just 2 hours after Arch Linux.

      • @[email protected]
        link
        fedilink
        4•1 year ago

        I just updated all packages in Termux actually lol

      • @[email protected]
        link
        fedilink
        1•1 year ago

        very nice!

        • u/lukmly013 💾 (lemmy.sdf.org)
          link
          fedilink
          English
          1•1 year ago

          What package manager is that?

          • @[email protected]OP
            link
            fedilink
            English
            1•1 year ago

            I think it’s nala, which is a wrapper for (lib)apt

          • @[email protected]
            link
            fedilink
            1•1 year ago

            Nala, Termux is Debian based and its pkg is basically apt

    • @[email protected]
      link
      fedilink
      English
      16•
      edit-2
      1 year ago

      Also, sshd isn’t linked against liblzma

      Not directly, but it’s loaded through libsystemd. It is there.

      Edit: except on arch, if you use that. That doesn’t use libsystemd

    • @[email protected]
      link
      fedilink
      7•1 year ago

      https://archlinux.org/news/the-xz-package-has-been-backdoored/

      • @[email protected]
        link
        fedilink
        7•1 year ago

        And as https://www.openwall.com/lists/oss-security/2024/03/29/4 says:

        “These conditions include targeting only x86-64 linux: […] Building with gcc and the gnu linker […] Running as part of a debian or RPM package build:”

        I’m not an expert of course.

        • brvslvrnst
          link
          fedilink
          2•1 year ago

          Holy shit that was a hell of a dive. And no wonder the dude got it working, he was just pounding those “test and translation” commits

      • @[email protected]
        link
        fedilink
        8•1 year ago

        Yeah but the backdoor does not work on Arch (as far as we currently know). It relies on a linking of libraries that Arch doesnt do by default.

[email protected]

[email protected]
Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: [email protected]

Rules:

  1. Be civil and nice.
  2. Try not to excessively repost, as a rule of thumb, wait at least 2 months to do it if you have to.
  • 69 users / day
  • 360 users / week
  • 821 users / month
  • 5.19K users / 6 months
  • 3 subscribers
  • 13.4K Posts
  • 288K Comments
  • Modlog
  • mods:
  • ghost_laptop
  • @[email protected]
  • Cyclohexane
  • Arthur Besse
  • UI: 0.18.4
  • BE: 0.18.2
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org