@[email protected] to [email protected]English • 1 year agolove is in the air?lemy.lolimagemessage-square46fedilinkarrow-up1342
arrow-up1342imagelove is in the air?lemy.lol@[email protected] to [email protected]English • 1 year agomessage-square46fedilink
minus-square@[email protected]linkfedilink7•1 year agohttps://archlinux.org/news/the-xz-package-has-been-backdoored/
minus-square@[email protected]linkfedilink7•1 year agoAnd as https://www.openwall.com/lists/oss-security/2024/03/29/4 says: “These conditions include targeting only x86-64 linux: […] Building with gcc and the gnu linker […] Running as part of a debian or RPM package build:” I’m not an expert of course.
minus-squarebrvslvrnstlinkfedilink2•1 year agoHoly shit that was a hell of a dive. And no wonder the dude got it working, he was just pounding those “test and translation” commits
minus-square@[email protected]linkfedilink8•1 year agoYeah but the backdoor does not work on Arch (as far as we currently know). It relies on a linking of libraries that Arch doesnt do by default.
https://archlinux.org/news/the-xz-package-has-been-backdoored/
And as https://www.openwall.com/lists/oss-security/2024/03/29/4 says:
“These conditions include targeting only x86-64 linux: […] Building with gcc and the gnu linker […] Running as part of a debian or RPM package build:”
I’m not an expert of course.
Holy shit that was a hell of a dive. And no wonder the dude got it working, he was just pounding those “test and translation” commits
Yeah but the backdoor does not work on Arch (as far as we currently know). It relies on a linking of libraries that Arch doesnt do by default.