oss-sec mailing list archives
Re: backdoor in upstream xz/liblzma leading to ssh server compromise
From: Axel Beckert <abe () deuxchevaux org>
Date: Sat, 30 Mar 2024 20:06:06 +0100
Hi, On Sat, Mar 30, 2024 at 07:00:42PM +0800, Alexander E. Patrakov wrote:
As GitHub has disabled the repository, the commit links in the original message no longer work. One of the remaining mirrors is https://git.rootprojects.org/root/xz
Note that this is not a mirror of the adversary controlled git repo on Github but a mirror of https://git.tukaani.org/xz.git which is controlled by the original maintainer according to https://tukaani.org/xz-backdoor/. (And that repo is still there, too, even if it gives a 403 Forbidden when accessed with a web browser. You can still "git clone" from it.) BTW, both repos miss that most recent commit on Github by the adversary with the now infamous "simplification of SECURITY.md". Kind regards, Axel -- PGP: 2FF9CD59612616B5 /~\ Plain Text Ribbon Campaign, http://arc.pasp.de/ Mail: abe () deuxchevaux org \ / Say No to HTML in E-Mail and Usenet Mail+Jabber: abe () noone org X https://axel.beckert.ch/ / \ I love long mails: https://email.is-not-s.ms/
Attachment:
signature.asc
Description:
Current thread:
- Re: Re: backdoor in upstream xz/liblzma leading to ssh server compromise, (continued)
- Re: Re: backdoor in upstream xz/liblzma leading to ssh server compromise Jan Engelhardt (Mar 30)
- Re: Re: backdoor in upstream xz/liblzma leading to ssh server compromise Pat Gunn (Mar 30)
- SV: Re: backdoor in upstream xz/liblzma leading to ssh server compromise Markus Klyver (Mar 31)
- Re: Re: backdoor in upstream xz/liblzma leading to ssh server compromise Loganaden Velvindron (Mar 31)
- Re: Re: backdoor in upstream xz/liblzma leading to ssh server compromise Russ Allbery (Mar 30)
- Re: Re: backdoor in upstream xz/liblzma leading to ssh server compromise Mike O'Connor (Mar 30)
- Re: Re: backdoor in upstream xz/liblzma leading to ssh server compromise Florian Weimer (Mar 30)
- Re: backdoor in upstream xz/liblzma leading to ssh server compromise Axel Beckert (Mar 30)
- Re: backdoor in upstream xz/liblzma leading to ssh server compromise Salvatore Bonaccorso (Mar 30)
- Re: Re: backdoor in upstream xz/liblzma leading to ssh server compromise Rein Fernhout (Levitating) (Mar 30)
- Re: Re: backdoor in upstream xz/liblzma leading to ssh server compromise Jonathan Schleifer (Mar 30)
- Re: Re: backdoor in upstream xz/liblzma leading to ssh server compromise Rein Fernhout (Levitating) (Mar 30)
- Re: Re: backdoor in upstream xz/liblzma leading to ssh server compromise Fay Stegerman (Mar 30)
- RE: backdoor in upstream xz/liblzma leading to ssh server compromise Thomas Ward (Mar 30)