LWN.net Logo

The Fedora-Red Hat Crisis (Datamation)

The Fedora-Red Hat Crisis (Datamation)

Posted Sep 11, 2008 7:25 UTC (Thu) by njs (subscriber, #40338)
In reply to: The Fedora-Red Hat Crisis (Datamation) by BrucePerens
Parent article: The Fedora-Red Hat Crisis (Datamation)

>At least one user I've heard from got compromised ssh packages that were distributed from a corrupt Fedora archive. He doesn't know if they were actually used to penetrate his system.

Wait, what? The official word from Fedora is that there were no compromised packages whatsoever. (And from RH that there are compromised ssh packages, but that they were not distributed.) If there's information otherwise, then shouldn't he (or you) be contacting Fedora, and possibly also media outlets?


(Log in to post comments)

The Fedora-Red Hat Crisis (Datamation)

Posted Sep 11, 2008 7:41 UTC (Thu) by BrucePerens (subscriber, #2510) [Link]

Wait, what? The official word from Fedora is that there were no compromised packages whatsoever. (And from RH that there are compromised ssh packages, but that they were not distributed.)
I've heard from one person who says his system failed the test script that Red Hat distributed. I don'k know him and can't attest to his reliability. I don't know if it's a false positive.

The Fedora-Red Hat Crisis (Datamation)

Posted Sep 11, 2008 7:52 UTC (Thu) by njs (subscriber, #40338) [Link]

Oh, so it was RH? I guess that would be another reason he couldn't get help from Fedora :-). But that's an easy mix-up to make...

If he really did fail the test script, though, then I bet he can get help: presumably the investigators would *love* to figure out how that package got onto his system, since whoever put it there must have contact with the RH attackers... OTOH: random emailer of unknown provenance, making an unverifiable claim that would make news if real but hasn't, and whining about how they can't get help when they would have if they tried? Obviously I don't know him either, but kind of tingles my internet-attention-seeker sense.

The Fedora-Red Hat Crisis (Datamation)

Posted Sep 11, 2008 8:02 UTC (Thu) by mspevack (subscriber, #36977) [Link]

I don'k [sic] know him and can't attest to his reliability.

Then why are you spreading FUD? -1 (Troll)

The Fedora-Red Hat Crisis (Datamation)

Posted Sep 11, 2008 12:58 UTC (Thu) by skvidal (subscriber, #3094) [Link]

If you'd like to pass along his name/email, it'd be handy to know where he obtained this package from.

It wasn't from what is on the master mirror, I can assure you of that.

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds