[prev in list] [next in list] [prev in thread] [next in thread] 

List:       haiku-bugs
Subject:    [haiku-bugs] Re: [Haiku] #18872: URGENT ? Revert to xz 5.4x (backdoor in 5.6)
From:       Haiku <trac () haiku-os ! org>
Date:       2024-03-31 18:20:55
Message-ID: 056.f934f1c3e5687a8a47cc13d4b27a0e55 () haiku-os ! org
[Download RAW message or body]

--==============P00911566261817035=MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable

#18872: URGENT ? Revert to xz 5.4x (backdoor in 5.6)
---------------------------------+----------------------------
  Reporter:  slema               |      Owner:  axeld
      Type:  bug                 |     Status:  closed
  Priority:  critical            |  Milestone:  Unscheduled
 Component:  Servers/net_server  |    Version:  R1/Development
Resolution:  invalid             |   Keywords:  ssh xz
Blocked By:                      |   Blocking:
  Platform:  All                 |
---------------------------------+----------------------------
Changes (by waddlesplash):

 * resolution:   => invalid
 * status:  new => closed

Comment:

 We already switched to a 5.6.1 from the Git repository instead of the
 source tarball. The backdoor would not have affected us anyway as we (1)
 are not Linux, (2) do not use glibc's runtime linker, (3) don't use glibc
 ifuncs.

 Ultimately the question of whether to revert back to 5.4.x is still an
 open one. I don't know that a decision has been reached about that yet.
 But this ticket would belong at HaikuPorts anyway, I think.
-- 
Ticket URL: <https://dev.haiku-os.org/ticket/18872#comment:1>
Haiku <https://dev.haiku-os.org>
The Haiku operating system.

--==============P00911566261817035==--

[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic