▲ 173 ▼ Backdoor in upstream xz/liblzma leading to ssh server compromise (www.openwall.com) submitted 2 years ago* (last edited 2 years ago) by mox@lemmy.sdf.org to c/selfhosted@lemmy.world 9 comments fedilink hide all child comments Related discussion: https://news.ycombinator.com/item?id=39865810 https://news.ycombinator.com/item?id=39877267 Advisories: CVE-2024-3094 Arch Debian openSUSE Red Hat
▲ 12 ▼ The xz package (used by SSHD) has been backdoored (www.openwall.com) submitted 2 years ago by c0mmando@links.hackliberty.org [M] to c/netsec@links.hackliberty.org comment fedilink hide all child comments The upstream release tarballs for xz version 5.6.0 and 5.6.1 contain malicious code which adds a backdoor. ArchLinux and most rolling release distro are affected. Debian Testing/Sid/Experimental are affected, Debian Stable ISN'T AFFECTED. Short summary by the ArchLinux team: https://archlinux.org/news/the-xz-package-has-been-backdoored/ Your distro should have a blog post/message to tell you what to do, either update (if they provide an updated version) or downgrade to a known-good version. Analysis: https://www.openwall.com/lists/oss-security/2024/03/29/4 More Infos: https://archlinux.org/news/the-xz-package-has-been-backdoored/ https://lists.debian.org/debian-security-announce/2024/msg00057.html https://github.com/tukaani-project/xz/issues/92
▲ 65 ▼ Backdoor in upstream xz/liblzma leading to ssh server compromise (www.openwall.com) submitted 2 years ago* (last edited 2 years ago) by mox@lemmy.sdf.org to c/linux@lemmy.world comment fedilink hide all child comments Related discussion: https://news.ycombinator.com/item?id=39865810 https://news.ycombinator.com/item?id=39877267 Advisories: CVE-2024-3094 Arch Debian openSUSE Red Hat
▲ 1 ▼ oss-security - Backdoor in upstream xz/liblzma leading to ssh server compromise (www.openwall.com) submitted 2 years ago by repostbot33@lemmy.world [B] to c/netsec@lemmy.world comment fedilink hide all child comments
▲ 143 ▼ Backdoor in upstream xz/liblzma leading to ssh server compromise (www.openwall.com) submitted 2 years ago by e0qdk@reddthat.com to c/programming@programming.dev 11 comments fedilink hide all child comments
▲ 39 ▼ Backdoor in upstream xz/liblzma leading to ssh server compromise (www.openwall.com) submitted 2 years ago by thomask@lemmy.sdf.org to c/cybersecurity@sh.itjust.works 2 comments fedilink hide all child comments
▲ 3 ▼ Backdoor in upstream xz/liblzma leading to SSH server compromise (www.openwall.com) submitted 2 years ago by bot@lemmy.smeargle.fans [M, B] to c/hackernews@lemmy.smeargle.fans comment fedilink hide all child comments HN Discussion
▲ 1 ▼ backdoor in upstream xz/liblzma leading to ssh server compromise (www.openwall.com) submitted 2 years ago by Atemu@lemmy.ml to c/security@lemmy.ml comment fedilink hide all child comments
▲ 520 ▼ backdoor in upstream xz/liblzma leading to ssh server compromise (www.openwall.com) submitted 2 years ago by Atemu@lemmy.ml to c/linux@lemmy.ml 96 comments fedilink hide all child comments