log insign up
nortti

nortti OH1CAU

@nortti

  • they/she (他, sie)
  • ahti.space/~nortti

fi, en, (sv, ja, hu, yi) | avatar by https://twitter.com/udonkimuchikaki

log inask

libera.chat, irc.sortix.org
nortti
microblog (that is, a blog with small entries)
microblog.ahti.space/nortti

posts from @nortti tagged #liblzma

also:
view posts from all pages tagged #liblzma
nortti
nortti OH1CAU@nortti3/29/2024, 5:46 PM

If you are running Debian testing or sid, or Fedora 41 or Rawhide, you may have a backdoored liblzma

Original report: oss-security - backdoor in upstream xz/liblzma leading to ssh server compromise
Red Had advisory: Urgent security alert for Fedora Linux 40 and Fedora Rawhide users
Debian advisory: [SECURITY] [DSA 5649-1] xz-utils security update

If you know any other distributions that use .deb or .rpm packages, and have shipped xz or liblzma versions 5.5.* or 5.6.*, include information in the comments

#linux#security#backdoors#xz#liblzma#ssh#sshd#CVE-2024-3094#CVE#debian#fedora

0 comments
  
  • © 2024 anti software software club llc
  • thanks for using cohost

Legal

  • Terms of Use
  • Privacy Notice
  • Community Guidelines

About

  • install cohost on your phone
  • @staff
  • Support
  • Credits
  • cohost status
  • Careers