3 ms·
That's my second point. Just checking for version <= 5.6.0 is not safe either and is exactly what the original article has done. But if all you use as the basi
by pilif 3y ago
That's my second point. Just checking for version <= 5.6.0 is not safe either and is exactly what the original article has done.
But if all you use as the basis of the vulnerability analysis is the version constraint and what we currently know about the backdoor, then, unless you are a distro building a liblzma distro package, you will not be vulnerable no matter the version (which was my point 1)