There have been multiple accounts created with the sole purpose of posting advertisement posts or replies containing unsolicited advertising.

Accounts which solely post advertisements, or persistently post them may be terminated.

SpaceCadet ,
@SpaceCadet@feddit.nl avatar

In the case of Arch the backdoor also wasn’t inserted into liblzma at all, because at build time there was a check to see if it’s being built on a deb or rpm based system, and only inserts it in those two cases.

See gist.github.com/…/223949d5a074ebc3dce9ee78baad9e2… for an analysis of the situation.

So even if Arch built their xz binaries off the backdoored tarball, it was never actually vulnerable.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • [email protected]
  • random
  • lifeLocal
  • goranko
  • All magazines