• caglararli@hotmail.com
  • 05386281520

XZ compromise and consequences for people having used it

Çağlar Arlı      -    9 Views

XZ compromise and consequences for people having used it

Here's a hot topic:

I'm not an expert in reverse engineering, so my questions are:

Is only SSHD affected? Does merely having the sshd daemon run is enough to get your system compromised or the attacker must have actually accessed the compromised system? Many more packages depend on (are linked to) liblzma including: RPM, GRUB, KMOD, systemd, etc.

Systemd is run by default, RPM is run whenever you do anything with your packages.