Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Sat, 30 Mar 2024 20:06:06 +0100
From: Axel Beckert <abe@...xchevaux.org>
To: oss-security@...ts.openwall.com
Subject: Re: backdoor in upstream xz/liblzma leading to ssh
 server compromise

Hi,

On Sat, Mar 30, 2024 at 07:00:42PM +0800, Alexander E. Patrakov wrote:
> As GitHub has disabled the repository, the commit links in the
> original message no longer work. One of the remaining mirrors is
> https://git.rootprojects.org/root/xz

Note that this is not a mirror of the adversary controlled git repo on
Github but a mirror of https://git.tukaani.org/xz.git which is
controlled by the original maintainer according to
https://tukaani.org/xz-backdoor/. (And that repo is still there, too,
even if it gives a 403 Forbidden when accessed with a web browser. You
can still "git clone" from it.)

BTW, both repos miss that most recent commit on Github by the adversary
with the now infamous "simplification of SECURITY.md".

		Kind regards, Axel
-- 
PGP: 2FF9CD59612616B5      /~\  Plain Text Ribbon Campaign, http://arc.pasp.de/
Mail: abe@...xchevaux.org  \ /  Say No to HTML in E-Mail and Usenet
Mail+Jabber: abe@...ne.org  X
https://axel.beckert.ch/   / \  I love long mails: https://email.is-not-s.ms/

Download attachment "signature.asc" of type "application/pgp-signature" (834 bytes)

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.