▲ 1218 ▼ XZ backdoor in a nutshell (lemmy.zip) submitted 2 years ago by possiblylinux127@lemmy.zip to c/linux@lemmy.ml 155 comments fedilink hide all child comments
[–] fluxion@lemmy.world 9 points 2 years ago (1 child) Tukaani main website permalink fedilink source parent hideshow 2 child comments replies: [–] TheFadingOne@feddit.de 6 points 2 years ago* (last edited 2 years ago) Though unfortunately (or I guess for most use-cases fortunately) you can't find the malicious m4/build-to-host.m4 file on there afaik. The best way to find that now, should you really want to, is by looking through the commit history of the salsa.debian.org/debian/xz-utils repository which is, as far as I understand it, the repository that the debian packages are built from and consequently also what the compromised packages were built from. permalink fedilink source parent
[–] TheFadingOne@feddit.de 6 points 2 years ago* (last edited 2 years ago) Though unfortunately (or I guess for most use-cases fortunately) you can't find the malicious m4/build-to-host.m4 file on there afaik. The best way to find that now, should you really want to, is by looking through the commit history of the salsa.debian.org/debian/xz-utils repository which is, as far as I understand it, the repository that the debian packages are built from and consequently also what the compromised packages were built from. permalink fedilink source parent