4 ms·
That's my first point though. If you only take into account what is currently known about the backdoor, unless you are a linux distro building a liblzma debian
by pilif 3y ago
That's my first point though. If you only take into account what is currently known about the backdoor, unless you are a linux distro building a liblzma debian or RPM package, you are not vulnerable to the backdoor.
So I believe, given the current state of knowledge, that all the projects that are not about building liblzma packages are not vulnerable and thus their postings about them not being vulnerable is noise.
- woodruffw 3y agoMuch like PyPI, there are a large number of gems on RubyGems that either vendor library builds or provide source redistributions for local builds. That’s why these kinds of indices need to perform these scans; it’s not sufficient to assume that the host distribution or OS is the only source of runtime libraries.
- ncallaway 3y agoSure, I wasn't disagreeing with your first point. I was disagreeing with your second point.