On Sat, 2024-03-30 21:02:12 +1100, Brian May via luv-main wrote:
> Aníbal Monsalve Salazar via luv-main <[email protected]> writes:
>> On Sat, 2024-03-30 19:47:23 +1100, Aníbal Monsalve Salazar wrote:
>>
>> This is very urgent.
>>
>> Debian version 5.6.1+really5.4.5-1 is now available at
> 
> Question is: is downgrading to 5.4.5 really sufficient? Some people are
> saying 5.3.1 was the last trusted
> version. https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1068024
> 
> (although that has at least one security vulnerability that needs to be
> patched)
> 
> And there might be other projects affected too.

Andrew Ruthven via linux-aus <[email protected]>, wrote:
        
 Not just Debian. If you run Fedora 41 (not released yet) or Fedora
 Rawhide, please see:
 
https://www.redhat.com/en/blog/urgent-security-alert-fedora-41-and-rawhide-users

> Terrible situation. More references:
> 
> * https://www.openwall.com/lists/oss-security/2024/03/29/4
> * https://www.youtube.com/watch?v=jqjtNDtbDNI
> * 
> https://hackaday.com/2024/03/29/security-alert-potential-ssh-backdoor-via-liblzma/
_______________________________________________
luv-main mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to