A backdoor in xz
A backdoor in xz
Posted Mar 29, 2024 21:45 UTC (Fri) by zblaxell (subscriber, #26385)In reply to: A backdoor in xz by daroc
Parent article: A backdoor in xz
Wow...so today I get to add to my collection of "mail filtering/transformation worst-case outcomes" examples! In the LWN version, the text reads:
== Detecting if installation is vulnerable == Vegard Nossum wrote a script to detect if it's likely that the ssh binary on a system is vulnerable, attached here. Thanks! Greetings, Andres Freund P="-fPIC -DPIC -fno-lto -ffunction-sections -fdata-sections" C="pic_flag=\" $P\"" O="^pic_flag=\" -fPIC -DPIC\"$" R="is_arch_extension_supported" [...]so I'm thinking "OK, so it's attached here", not "this mailing list archive software dumps random text from a bunch of extremely heterogenous MIME parts into the message body without any markup indicating boundaries between sections."
Given the sensitivity, can that be fixed on the LWN archive before someone else makes the same mistake?
