Statement on backdoor in xz package

2024-04-02 Thread Ihsan Dogan via users
Recently, a backdoor [1] was discovered in the xz compression library. xz/liblzma [2] are packaged by the OpenCSW project and various other packages are depending on the liblzma library [3]. I have released today the version 5.6.0r529 to the repository, which is based on the 5.2.9. This is

Re: CSWxz and CVE-2024-3094

2024-04-02 Thread Ihsan Dogan via users
Hi > Am 02.04.2024 um 14:37 schrieb Jeffrey Walton via users > : what about CVE-2024-3094 and current version CSWxz? https://nvd.nist.gov/vuln/detail/CVE-2024-3094 >>> >>> Ihsan already prepared an updated package which should show up soon. >> >> Yes, I am on it. I am

Re: CSWxz and CVE-2024-3094

2024-04-02 Thread Jeffrey Walton via users
On Tue, Apr 2, 2024 at 8:23 AM Ihsan Dogan via users wrote: > > > Am 02.04.2024 um 14:03 schrieb Dagobert Michelsen : > > > >> what about CVE-2024-3094 and current version CSWxz? > >> > >> https://nvd.nist.gov/vuln/detail/CVE-2024-3094 > > > > Ihsan already prepared an updated package which

Re: CSWxz and CVE-2024-3094

2024-04-02 Thread Ihsan Dogan via users
Hi Yuri > Am 02.04.2024 um 14:03 schrieb Dagobert Michelsen : > >> what about CVE-2024-3094 and current version CSWxz? >> >> https://nvd.nist.gov/vuln/detail/CVE-2024-3094 > > Ihsan already prepared an updated package which should show up soon. Yes, I am on it. I am preparing a rollback to

Re: CSWxz and CVE-2024-3094

2024-04-02 Thread Yuri via users
Well, waiting for. Thank you. 02.04.2024 17:03, Dagobert Michelsen пишет: Hi Yuri, Am 02.04.2024 um 13:37 schrieb Yuri via users : what about CVE-2024-3094 and current version CSWxz? https://nvd.nist.gov/vuln/detail/CVE-2024-3094 Ihsan already prepared an updated package which should show

Re: CSWxz and CVE-2024-3094

2024-04-02 Thread Dagobert Michelsen via users
Hi Yuri, > Am 02.04.2024 um 13:37 schrieb Yuri via users : > what about CVE-2024-3094 and current version CSWxz? > > https://nvd.nist.gov/vuln/detail/CVE-2024-3094 Ihsan already prepared an updated package which should show up soon. Best regards — Dago -- "You don't become great by

CSWxz and CVE-2024-3094

2024-04-02 Thread Yuri via users
Hi there, what about CVE-2024-3094 and current version CSWxz? https://nvd.nist.gov/vuln/detail/CVE-2024-3094 Just FYI. WBR, Yuri OpenPGP_0x4BEE94A33E3743A7.asc Description: OpenPGP public key OpenPGP_signature.asc Description: OpenPGP digital signature