It is known to be in version 5.6.0 and 5.6.1, and the obfuscated code is found in the test directory.
Backdoor in upstream xz/liblzma leading to SSH server compromise
11–20 of 1001 posts
Re: Backdoor in upstream xz/liblzma leading to SSH server compromise
#12Also super weird a contributor thought they could slip this in and not have it be noticed at some point. It may point to burning that person (aka, they go to jail) for whatever they achieved with this. (And whoever they are…)
Re: Backdoor in upstream xz/liblzma leading to SSH server compromise
#13Homebrew is currently shipping 5.6.1 (and was shipping 5.6.0 as well). Hopefully not affected on mac?
Re: Backdoor in upstream xz/liblzma leading to SSH server compromise
#14Re: Backdoor in upstream xz/liblzma leading to SSH server compromise
#15Very strange behavior from the upstream developers. Possible government involvement? I have a feeling LANG is checked to target servers from particular countries
Re: Backdoor in upstream xz/liblzma leading to SSH server compromise
#16Safety through obscurity and weirdness! If you disable ifunc, like any sensible person, this backdoor disables itself.
Re: Backdoor in upstream xz/liblzma leading to SSH server compromise
#17That's completely crazy, the backdoor is introduced through a very cryptic addition to the configure script. Just looking at the diff, it doesn't look malicious at all, it looks like build script gibberish.
Can we even be sure no such successful attempt has already been made?
Re: Backdoor in upstream xz/liblzma leading to SSH server compromise
#18That's completely crazy, the backdoor is introduced through a very cryptic addition to the configure script. Just looking at the diff, it doesn't look malicious at all, it looks like build script gibberish.
Re: Backdoor in upstream xz/liblzma leading to SSH server compromise
#19Does that mean this affects RHEL and Fedora?
Re: Backdoor in upstream xz/liblzma leading to SSH server compromise
#20I worked in the software supply chain field and cannot resist feeling the entire point of that industry is to make companies pay for a security certificate so you can shift the blame onto someone else when things go wrong.