oss-sec mailing list archives

Re: backdoor in upstream xz/liblzma leading to ssh server compromise


From: Axel Beckert <abe () deuxchevaux org>
Date: Sat, 30 Mar 2024 20:06:06 +0100

Hi,

On Sat, Mar 30, 2024 at 07:00:42PM +0800, Alexander E. Patrakov wrote:
As GitHub has disabled the repository, the commit links in the
original message no longer work. One of the remaining mirrors is
https://git.rootprojects.org/root/xz

Note that this is not a mirror of the adversary controlled git repo on
Github but a mirror of https://git.tukaani.org/xz.git which is
controlled by the original maintainer according to
https://tukaani.org/xz-backdoor/. (And that repo is still there, too,
even if it gives a 403 Forbidden when accessed with a web browser. You
can still "git clone" from it.)

BTW, both repos miss that most recent commit on Github by the adversary
with the now infamous "simplification of SECURITY.md".

                Kind regards, Axel
-- 
PGP: 2FF9CD59612616B5      /~\  Plain Text Ribbon Campaign, http://arc.pasp.de/
Mail: abe () deuxchevaux org  \ /  Say No to HTML in E-Mail and Usenet
Mail+Jabber: abe () noone org  X
https://axel.beckert.ch/   / \  I love long mails: https://email.is-not-s.ms/

Attachment: signature.asc
Description:


Current thread: