|
|
Log in / Subscribe / Register

Packages affected

Packages affected

Posted Jul 11, 2018 11:50 UTC (Wed) by jak90 (subscriber, #123821)
In reply to: Packages affected by rengolin
Parent article: Malware found in the Arch Linux AUR repository

It seems "acrored" is a typo for the Adobe Reader package (acroread) that's sitting back at package version 9.5.5-7 (if one even dares to use this native version of the application, which is no longer supported by or officially available from Adobe).
Likewise, submitting "mistyped" packages would seem like a viable compromise vector as well.


to post comments

Packages affected

Posted Jul 12, 2018 11:50 UTC (Thu) by feb (guest, #60129) [Link]

That's a typosquatting attack which LWN talked about a few years ago (https://lwn.net/Articles/694830/). In the case of Arch AUR packages, there's also the idea of targetting orphaned packages.


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds