3 ms·
"As verified by running find / -name 'lzma' in our built containers, we depend only on version 5.4.3 and not on the vulnerable versions 5.6.0 or 5.6.1." Yet De
by macrolime 3y ago
"As verified by running find / -name 'lzma' in our built containers, we depend only on version 5.4.3 and not on the vulnerable versions 5.6.0 or 5.6.1."
Yet Debian is looking into reverting to 5.3.1, as all newer versions contain many commits by Jia Tan.
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1068024 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1068024
- LegitShady 3y agothat sounds like a Debian problem, not a RubyGems problem, then.
- pilif 3y agono. We have to assume any commit of the threat actor to have been malicious. Given that 5.4 contains code by the threat actor, it's not safe to claim to not be vulnerable. Not vulnerable to this specific backdoor, sure. But I don't feel like 5.4 is safe either.
- nextaccountic 3y agoAre there any other distros that may do this? I see that debian did the funny 5.6.1+really5.4.5-1 thing but Arch for example is currently at 5.6.1-3. Don't Arch Linux also want to get rid of those suspicious commits?
- vvillena 3y agoArch has a policy to keep package patching to a minimum. If the newer xz version doesn't have a backdoor, they will probably follow upstream. Also, Arch doesn't appear to be affected by the vulnerability: >> openssh does not directly use liblzma. However debian and several other distributions patch openssh to support systemd notification, and libsystemd does depend on lzma. > Arch does not directly link openssh to liblzma, and thus this attack vector is not possible.
- nextaccountic 3y agoThe issue here is that the malware developer may have hid other malware in xz's codebase. This one specifically was targeted at deb and rpm distros
- uticus 3y agoTo find answer to your question I recommend looking through relevant discussions, ref https://bbs.archlinux.org/viewtopic.php?id=294363 https://bbs.archlinux.org/viewtopic.php?id=294363 and elsewhere
- nextaccountic 3y ago> This thread had been meant to call attention to the official announcement. I think it is clear systems should be updated out of caution. This thread has diverged from that point. > I am going to go ahead and close the thread at this point. It seems that discussing further mitigation steps is off topic in that thread. Unlike Debian and NixOS, Arch Linux devs don't appear to want to downgrade to 5.4 to get rid of code authored by the malicious developer.