Re: Check If Your Distro Is Vulnerable To XZ Backdoor

Liste des GroupesRevenir à ol advocacy 
Sujet : Re: Check If Your Distro Is Vulnerable To XZ Backdoor
De : Rockinghorse (at) *nospam* amgen.com (Rockinghorse Winner)
Groupes : comp.os.linux.advocacy
Date : 02. Apr 2024, 06:20:38
Autres entêtes
Organisation : Borscht Belt Babes
Message-ID : <uug12m$306oq$2@dont-email.me>
References : 1 2
User-Agent : slrn/1.0.3 (Linux)
On 2024-03-31, Physfitfreak <physfitfreak@gmail.com> opined as follows:
On 3/31/24 08:01, Farley Flud wrote:
Run this command to check if liblzma is linked to ssh:
 
ldd "$(command -v sshd)"
 
For example, on Gentoo (the best distro) I get:
 
linux-vdso.so.1 (0x00007ffff7fcb000)
         libcrypt.so.2 => /usr/lib64/libcrypt.so.2 (0x00007ffff7f6e000)
         libcrypto.so.3 => /usr/lib64/libcrypto.so.3 (0x00007ffff7a00000)
         libz.so.1 => /usr/lib64/libz.so.1 (0x00007ffff7f54000)
         libc.so.6 => /lib64/libc.so.6 (0x00007ffff783c000)
         /lib64/ld-linux-x86-64.so.2 (0x00007ffff7fcc000)
 
Nope.  There ain't no linking to liblzma, thus Gentoo is NOT affected
regardless of what version of xz-utils is installed.
 
Systemd is ultimately responsible and more and more hackers will be
looking for more and better ways of exploiting that 3 million loc
pile of junk.
 
Don't say we didn't tell you so.
 
To save your systems, downgrade xz-utils AND eliminate systemd.
 
 
>
>
I get:
>
ldd: ./: not regular file
>
>

You don't have a sshd server installed most likely.


--
'Many have sought in vain to tell joyously of the Most Joyous. Now at last It declares
Itself to me, now in this misery.'    - Holderlin
             ____
            /.   \
___________<     |___________
\___________     ___________/
 \___________   ___________/
  \___________ ___________/
           |     |
          ^^^   ^^^
          _________
         |  R   W  |
         |   (*)   |
         |____U____|
         

Date Sujet#  Auteur
31 Mar 24 * Re: Check If Your Distro Is Vulnerable To XZ Backdoor42Physfitfreak
1 Apr 24 +* Re: Check If Your Distro Is Vulnerable To XZ Backdoor40candycanearter07
1 Apr 24 i+* Re: Check If Your Distro Is Vulnerable To XZ Backdoor2rbowman
1 Apr 24 ii`- Re: Check If Your Distro Is Vulnerable To XZ Backdoor1candycanearter07
1 Apr 24 i`* Re: Check If Your Distro Is Vulnerable To XZ Backdoor37Physfitfreak
1 Apr 24 i `* Re: Check If Your Distro Is Vulnerable To XZ Backdoor36candycanearter07
1 Apr 24 i  `* Re: Check If Your Distro Is Vulnerable To XZ Backdoor35Physfitfreak
1 Apr 24 i   +* Re: Check If Your Distro Is Vulnerable To XZ Backdoor33candycanearter07
1 Apr 24 i   i+* Re: Check If Your Distro Is Vulnerable To XZ Backdoor28Physfitfreak
1 Apr 24 i   ii+* Re: Check If Your Distro Is Vulnerable To XZ Backdoor22Physfitfreak
1 Apr 24 i   iii+* Re: Check If Your Distro Is Vulnerable To XZ Backdoor20Physfitfreak
1 Apr 24 i   iiii`* Re: Check If Your Distro Is Vulnerable To XZ Backdoor19candycanearter07
1 Apr 24 i   iiii +* Re: Check If Your Distro Is Vulnerable To XZ Backdoor8Physfitfreak
1 Apr 24 i   iiii i`* Re: Check If Your Distro Is Vulnerable To XZ Backdoor7candycanearter07
1 Apr 24 i   iiii i `* Re: Check If Your Distro Is Vulnerable To XZ Backdoor6Physfitfreak
2 Apr 24 i   iiii i  `* Re: Check If Your Distro Is Vulnerable To XZ Backdoor5candycanearter07
2 Apr 24 i   iiii i   `* Re: Check If Your Distro Is Vulnerable To XZ Backdoor4Lawrence D'Oliveiro
2 Apr 24 i   iiii i    +* Re: Check If Your Distro Is Vulnerable To XZ Backdoor2Physfitfreak
2 Apr 24 i   iiii i    i`- Re: Check If Your Distro Is Vulnerable To XZ Backdoor1Lawrence D'Oliveiro
2 Apr 24 i   iiii i    `- Re: Check If Your Distro Is Vulnerable To XZ Backdoor1candycanearter07
2 Apr 24 i   iiii `* Re: Check If Your Distro Is Vulnerable To XZ Backdoor10Lawrence D'Oliveiro
2 Apr 24 i   iiii  `* Re: Check If Your Distro Is Vulnerable To XZ Backdoor9Farley Flud
2 Apr 24 i   iiii   `* Re: Check If Your Distro Is Vulnerable To XZ Backdoor8Chris Ahlstrom
2 Apr 24 i   iiii    `* Re: Check If Your Distro Is Vulnerable To XZ Backdoor7Farley Flud
3 Apr 24 i   iiii     `* Re: Check If Your Distro Is Vulnerable To XZ Backdoor6rbowman
3 Apr 24 i   iiii      +* Re: Check If Your Distro Is Vulnerable To XZ Backdoor4rbowman
4 Apr 24 i   iiii      i`* Re: Check If Your Distro Is Vulnerable To XZ Backdoor3Lawrence D'Oliveiro
4 Apr 24 i   iiii      i +- Re: Check If Your Distro Is Vulnerable To XZ Backdoor1rbowman
5 Apr 24 i   iiii      i `- Re: Check If Your Distro Is Vulnerable To XZ Backdoor1Simon
3 Apr 24 i   iiii      `- Re: Check If Your Distro Is Vulnerable To XZ Backdoor1rbowman
2 Apr 24 i   iii`- Re: Check If Your Distro Is Vulnerable To XZ Backdoor1Lawrence D'Oliveiro
1 Apr 24 i   ii`* Re: Check If Your Distro Is Vulnerable To XZ Backdoor5candycanearter07
1 Apr 24 i   ii +* Re: Check If Your Distro Is Vulnerable To XZ Backdoor2Physfitfreak
2 Apr 24 i   ii i`- Re: Check If Your Distro Is Vulnerable To XZ Backdoor1rbowman
6 Apr 24 i   ii `* Re: Check If Your Distro Is Vulnerable To XZ Backdoor2Stéphane CARPENTIER
7 Apr 24 i   ii  `- Re: Check If Your Distro Is Vulnerable To XZ Backdoor1candycanearter07
2 Apr 24 i   i`* Re: Check If Your Distro Is Vulnerable To XZ Backdoor4Lawrence D'Oliveiro
2 Apr 24 i   i `* Re: Check If Your Distro Is Vulnerable To XZ Backdoor3candycanearter07
3 Apr 24 i   i  `* Re: Check If Your Distro Is Vulnerable To XZ Backdoor2cr0c0d1le
3 Apr 24 i   i   `- Re: Check If Your Distro Is Vulnerable To XZ Backdoor1Lawrence D'Oliveiro
2 Apr 24 i   `- Re: Check If Your Distro Is Vulnerable To XZ Backdoor1rbowman
2 Apr 24 `- Re: Check If Your Distro Is Vulnerable To XZ Backdoor1Rockinghorse Winner

Haut de la page

Les messages affichés proviennent d'usenet.

NewsPortal