Sujet : Re: Malware find in the news: xz related.
De : gtaylor (at) *nospam* tnetconsulting.net (Grant Taylor)
Groupes : comp.os.linux.miscDate : 31. Mar 2024, 17:05:58
Autres entêtes
Organisation : TNet Consulting
Message-ID : <uuc1l6$lfl$1@tncsrv09.home.tnetconsulting.net>
References : 1 2
User-Agent : Mozilla Thunderbird
On 3/31/24 08:38, John McCue wrote:
Thanks, here is another interesting link that describes how the issue occurred and indicates why *BSD and Distros like Slackware would not be vulnerable.
My understanding is that effectively the differentiating factor of if a distro is impacted or not is if it uses systemd or not.
Purportedly sshd itself doesn't use xz. But sshd built on / for systemd distros end up having xz added as a library / dependency because of systemd compatibility because systemd does use xz for things.
As such, my supposition is that, things like *BSD, Slackware, and Gentoo (OpenRC old default) aren't affected because they don't have -> use systemd.
-- Grant. . . .