arizvisa dice
7 months ago @Edit 7 months ago
oss-security - backdoor in upstream xz/liblzma leadi...

wow, pretty neat. xz/liblzma was backdoor'd, which included specific code to tamper with ssh. to clarify, it was caught due to valgrind and the backdoor affecting performance.

these are the commits here: https://github.com/tukaa...

#debian #security #lzma #xz #backdoor #cve-2024-3094
latest #16
arizvisa
7 months ago
if you're not familiar w/ GH, the record of that user's commits can be listed at: https://github.com/tukaa...
arizvisa
7 months ago
other than the tests, these are the commits containing code contributed by just that one guy:
arizvisa
7 months ago
e446ab7a18abfde18f8d1cf02a914df72b1370e3
立即下載
arizvisa
7 months ago
de5c5e417645ad8906ef914bc059d08c1462fc29
arizvisa
7 months ago
d0f33d672a4da7985ebb5ba8d829f885de49c171
arizvisa
7 months ago
8f236574986e7c414c0ea059f441982d1387e6a4
arizvisa
7 months ago
3d5a99ca373a4e86faf671226ca6487febb9eeac
arizvisa
7 months ago
18d7facd3802b55c287581405c4d49c98708c136
arizvisa
7 months ago
ae5c07b22a6b3766b84f409f1b6b5c100469068a
arizvisa
7 months ago
455a08609caa3223066a717fb01bfa42c5dba47d
arizvisa
7 months ago
82ecc538193b380a21622aea02b0ba078e7ade92
arizvisa
7 months ago
96b663f67c0e738a99ba8f35d9f4ced9add74544
arizvisa
7 months ago
761f5b69a4c778c8bcb09279b845b07c28790575
arizvisa
7 months ago
other than the crc work, the illegitimate tests, and the broken landlock option, they also did some work on xz's filter chains. they also committed two patches in regards to integer overflow checks during encoding. i haven't really verified the details of these thoroughly, tho.
arizvisa
7 months ago
seems absurd to just revert the commits of the entire project by 2 years tho (whee, debian). fortunately, i'm not "smart" enough to care about security policies and all that other higher-level crap.
arizvisa
7 months ago
Oh, probably worth noting that Jia has used these accounts to contribute.
Jia Cheong Tan <[email protected]>
jiat75 <[email protected]>
Jia Tan <[email protected]>
Jia Tan <[email protected]>
back to top