lemmy.dexlit
  • Communities
  • Create Post
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
@ngn@lemy.lol to Memes@lemmy.mlEnglish • 1 year ago

love is in the air?

lemy.lol

message-square
45
fedilink
309

love is in the air?

lemy.lol

@ngn@lemy.lol to Memes@lemmy.mlEnglish • 1 year ago
message-square
45
fedilink
  • @30p87@feddit.de
    link
    fedilink
    22•1 year ago

    Arch isn’t affected afaik, as it specifically targeted Debian and RPM. Also, sshd isn’t linked against liblzma (or something along those lines). And I hope that’s true, because otherwise, I had a backdoor on a public system for over a month.

    • @ReversalHatchery@beehaw.org
      link
      fedilink
      English
      16•
      edit-2
      1 year ago

      Also, sshd isn’t linked against liblzma

      Not directly, but it’s loaded through libsystemd. It is there.

      Edit: except on arch, if you use that. That doesn’t use libsystemd

    • u/lukmly013 💾 (lemmy.sdf.org)
      link
      fedilink
      English
      12•
      edit-2
      1 year ago

      And the packages on most distros should be long updated by now.

      Even Termux updated to 5.6.1+really5.4.5 just 2 hours after Arch Linux.

      • @30p87@feddit.de
        link
        fedilink
        4•1 year ago

        I just updated all packages in Termux actually lol

      • @Pantherina@feddit.de
        link
        fedilink
        1•1 year ago

        very nice!

        • u/lukmly013 💾 (lemmy.sdf.org)
          link
          fedilink
          English
          1•1 year ago

          What package manager is that?

          • @ngn@lemy.lolOP
            link
            fedilink
            English
            1•1 year ago

            I think it’s nala, which is a wrapper for (lib)apt

          • @Pantherina@feddit.de
            link
            fedilink
            1•1 year ago

            Nala, Termux is Debian based and its pkg is basically apt

    • @wildbus8979@sh.itjust.works
      link
      fedilink
      6•1 year ago

      https://archlinux.org/news/the-xz-package-has-been-backdoored/

      • @HopFlop@discuss.tchncs.de
        link
        fedilink
        8•1 year ago

        Yeah but the backdoor does not work on Arch (as far as we currently know). It relies on a linking of libraries that Arch doesnt do by default.

      • @30p87@feddit.de
        link
        fedilink
        7•1 year ago

        And as https://www.openwall.com/lists/oss-security/2024/03/29/4 says:

        “These conditions include targeting only x86-64 linux: […] Building with gcc and the gnu linker […] Running as part of a debian or RPM package build:”

        I’m not an expert of course.

        • brvslvrnst
          link
          fedilink
          2•1 year ago

          Holy shit that was a hell of a dive. And no wonder the dude got it working, he was just pounding those “test and translation” commits

Memes@lemmy.ml

!memes@lemmy.ml

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !memes@lemmy.ml

Rules:

  1. Be civil and nice.
  2. Try not to excessively repost, as a rule of thumb, wait at least 2 months to do it if you have to.
  • 1.06K users / day
  • 4.08K users / week
  • 7.34K users / month
  • 22.5K users / 6 months
  • 51.3K subscribers
  • 13.2K Posts
  • 253K Comments
  • Modlog
  • mods:
  • ghost_laptop
  • @sexy_peach@feddit.de
  • Cyclohexane
  • Arthur Besse
  • BE: 0.19.3
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org