3 ms·
Debian have reverted xz-utils (in unstable) to 5.4.5 – actual version string is “5.6.1+really5.4.5-1”. So presumably that version's safe; we shall see…
by smeehee 3y ago
Debian have reverted xz-utils (in unstable) to 5.4.5 – actual version string is “5.6.1+really5.4.5-1”. So presumably that version's safe; we shall see…
- xorcist 3y agoIs that version truly vetted? "Jia Tan" has been the official maintainer since 5.4.3, could have pushed code under any other pseudonym, and controls the signing keys. I would have felt better about reverting farther back, xz hasn't had any breaking changes for a long time.
- rnmkr 3y agoIt's not only that account, other maintainer has been pushing the same promotion all over the place.
- tobias2014 3y agoIt looks like this is being discussed, with a complication of additional symbols that were introduced https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1068024 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1068024
- binkHN 3y agoThanks for this! I found this URL in the thread very interesting! https://www.nongnu.org/lzip/xz_inadequate.html https://www.nongnu.org/lzip/xz_inadequate.html
- deleted 3y ago[deleted]
- mehdix 3y agoIt is an excellent technical write-up and yet again another testimonial to the importance of keeping things simple.
- userbinator 3y agoThe other comments here showing that the backdoor was a long-term effort now make me wonder just how long of an effort it was...
- kzrdude 3y agoThere are suggestions to roll back further
- sgarland 3y agoTIL that +really is a canonical string. [0] [0]: https://www.debian.org/doc/debian-policy/ch-controlfields.html#epochs-should-be-used-sparingly https://www.debian.org/doc/debian-policy/ch-controlfields.ht...