irfan,

As far as I can tell, you're only impacted by this vulnerability only if:

  • Your distro sources/packages xz from their release tarballs rather than through the Git source directly.

  • The payload was only included for the or packaging, so unless your distro uses these - you're probably safe.

  • As far as I can tell, it also only affects x86 systems so based systems should be fine.

  • As far as I can tell, your system needs to be running to be impacted by this, so / should mostly if not entirely be fine....? maybe.


In other news, people are currently investigating and evaluating other projects also actively contributed by the compromised developer, Jia Tan, including .

People are also analysing the dev's commit history to deduce their background from their activity lol. They've been found to push commits during office hours Mon-Fri, every other Saturdays, presumably Public Holidays that seem to align with China's PH, and seems to be on GMT +8 locale.

🔗 https://github.com/libarchive/libarchive

🔗 https://twitter.com/hackerfantastic/status/1773864354439417983

  • All
  • Subscribed
  • Moderated
  • Favorites
  • linux
  • DreamBathrooms
  • ngwrru68w68
  • modclub
  • magazineikmin
  • thenastyranch
  • rosin
  • khanakhh
  • InstantRegret
  • Youngstown
  • slotface
  • Durango
  • kavyap
  • mdbf
  • GTA5RPClips
  • JUstTest
  • tacticalgear
  • normalnudes
  • tester
  • osvaldo12
  • everett
  • cubers
  • ethstaker
  • anitta
  • provamag3
  • Leos
  • cisconetworking
  • megavids
  • lostlight
  • All magazines