oss-sec mailing list archives

Re: backdoor in upstream xz/liblzma leading to ssh server compromise


From: Jakub Wilk <jwilk () jwilk net>
Date: Mon, 1 Apr 2024 15:31:13 +0200

The check whether the script is running on Linux was added in 5.6.1, and the fact that it's repeated 5 times makes this pretty funny

There's yet another Linux check in stage 2:

   [ ! $(uname)="Linux" ] && exit 0

... but it doesn't work. (Note that spaces around the equals sign are missing.)

--
Jakub Wilk

This e-mail may contain confidential or privileged information. If you are not the intended recipient (or have received this e-mail in error) please notify the sender immediately and destroy the universe.


Current thread: