https://github.com/tukaani-project/xz/releases
這次 backdoor 被放進 5.6.1(2024/03/09),在大多數的 LTS distribution 都還沒跟上,但很多 testing/prerelease 版本就慘了...
另外一方面是 xz 團隊被迫要回頭仔細的 audit 之前的 commit 了...
https://github.com/tukaani-project/xz/releases
這次 backdoor 被放進 5.6.1(2024/03/09),在大多數的 LTS distribution 都還沒跟上,但很多 testing/prerelease 版本就慘了...
另外一方面是 xz 團隊被迫要回頭仔細的 audit 之前的 commit 了...
https://www.openwall.com/lists/oss-security/2024/03/29/4
https://news.ycombinator.com/item?id=39865810
睡醒打開電腦就發現 xz 被下蠱的消息,而且是埋了兩年的 social engineering (這麼刺激?):
He has been part of the xz project for 2 years, adding all sorts of binary test files, and to be honest with this level of sophistication I would be suspicious of even older versions of xz until proven otherwise.
GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.
All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.