mox@lemmy.sdf.org to Selfhosted@lemmy.worldEnglish · edit-22 years agoBackdoor in upstream xz/liblzma leading to ssh server compromisewww.openwall.comexternal-linkmessage-square9fedilinkarrow-up1176file-textcross-posted to: opensource@lemmit.onlinenetsec@links.hackliberty.orglinux_gaming@lemmit.onlinelinux@lemmy.worldnetsec@lemmy.worldprogramming@programming.devcybersecurity@sh.itjust.workshackernews@lemmy.smeargle.fanssecurity@lemmy.ml
arrow-up1176external-linkBackdoor in upstream xz/liblzma leading to ssh server compromisewww.openwall.commox@lemmy.sdf.org to Selfhosted@lemmy.worldEnglish · edit-22 years agomessage-square9fedilinkfile-textcross-posted to: opensource@lemmit.onlinenetsec@links.hackliberty.orglinux_gaming@lemmit.onlinelinux@lemmy.worldnetsec@lemmy.worldprogramming@programming.devcybersecurity@sh.itjust.workshackernews@lemmy.smeargle.fanssecurity@lemmy.ml
Related discussion: https://news.ycombinator.com/item?id=39865810 https://news.ycombinator.com/item?id=39877267 Advisories: CVE-2024-3094 Arch Debian openSUSE Red Hat
minus-squareMoonrise2473@feddit.itlinkfedilinkEnglisharrow-up6·2 years agoWow And for a state sponsored attacker is cheaper to bribe (or threaten to kill, even cheaper) the single developer to add a backdoor than all the research to find a zero day
Wow
And for a state sponsored attacker is cheaper to bribe (or threaten to kill, even cheaper) the single developer to add a backdoor than all the research to find a zero day