A backdoor in xz
A backdoor in xz
Posted Mar 29, 2024 21:57 UTC (Fri) by pbonzini (subscriber, #60935)In reply to: A backdoor in xz by Cyberax
Parent article: A backdoor in xz
The most horrible parts are introduced by the xz maintainer and are obfuscated (for example they use a variable containing "." to invoke the shell's source builtin). The actual code has some ugly sed substitutions but it's not even comparable to this abomination. You can find it at https://fossies.org/linux/NetworkManager/m4/build-to-host.m4
