@ngn@lemy.lol to Memes@lemmy.mlEnglish • 3 months agolove is in the air?lemy.lolimagemessage-square46fedilinkarrow-up1350arrow-down140
arrow-up1310arrow-down1imagelove is in the air?lemy.lol@ngn@lemy.lol to Memes@lemmy.mlEnglish • 3 months agomessage-square46fedilink
minus-square@wildbus8979@sh.itjust.workslinkfedilink6•3 months agohttps://archlinux.org/news/the-xz-package-has-been-backdoored/
minus-square@HopFlop@discuss.tchncs.delinkfedilink8•3 months agoYeah but the backdoor does not work on Arch (as far as we currently know). It relies on a linking of libraries that Arch doesnt do by default.
minus-square@30p87@feddit.delinkfedilink7•3 months agoAnd as https://www.openwall.com/lists/oss-security/2024/03/29/4 says: “These conditions include targeting only x86-64 linux: […] Building with gcc and the gnu linker […] Running as part of a debian or RPM package build:” I’m not an expert of course.
minus-squarebrvslvrnstlinkfedilink2•3 months agoHoly shit that was a hell of a dive. And no wonder the dude got it working, he was just pounding those “test and translation” commits
https://archlinux.org/news/the-xz-package-has-been-backdoored/
Yeah but the backdoor does not work on Arch (as far as we currently know). It relies on a linking of libraries that Arch doesnt do by default.
And as https://www.openwall.com/lists/oss-security/2024/03/29/4 says:
“These conditions include targeting only x86-64 linux: […] Building with gcc and the gnu linker […] Running as part of a debian or RPM package build:”
I’m not an expert of course.
Holy shit that was a hell of a dive. And no wonder the dude got it working, he was just pounding those “test and translation” commits