@TheBlueMatt (Matt Corallo) on Twitter: "Looks like someone managed to get a backdoor into ssh in Fedora and Debian testing. Patch systems ASAP."

https://openwall.com/lists/oss-security/2024/03/29/4

Reply to this note

Please Login to reply.

Discussion

Also nostr:npub185h9z5yxn8uc7retm0n6gkm88358lejzparxms5kmy9epr236k2qcswrdp on nostr

nostr:note1mqvnsk7me3wt3xd2pqyu04chlvygdphkt5p8sm56wxa28agxtc5stt2l5q

LOL, I tried to search for him but it couldn't find any profiles (on Nostrudel). I also checked his Twitter bio for a pubkey but didn't find anything. Thanks nostr:npub1zafcms4xya5ap9zr7xxr0jlrtrattwlesytn2s42030lzu0dwlzqpd26k5!

Add purplepag.es relay for pabloverse’s profile index

Pablo runs a profile indexer?

To me it reads like it's just another strfry relay but he only allows kind 0 events? Or did you fork the strfry software and made changes to it nostr:npub1l2vyh47mk2p0qlsku7hg0vn29faehy9hy34ygaclpn66ukqp3afqutajft?

It’a for profiles only. No notes.

Look for profile X on relay Y.

Pablo. Runs. Everything.

He holds all the keys. He knows all the doors.

Pablo is nostr's fundamental centralisation problem.

Pablo has access to way too much brazilian dance powder for his dev sessions 😂

BRAZILIAN DANCE POWDER!

hahahhahah

latest release is affeced 5.6.1, there is not release with fix available. idk if master brannch has fix or not.

https://github.com/tukaani-project/xz/releases

Brew (package manager on Macs) downgrades xz to 5.4.6. Haven't seen any news of a patch yet.

older package xz-5.4.6 is available from arch archives

https://archive.archlinux.org/packages/x/xz/

🤣 Why run testing branch software... Seriously...

bleeding edge features I guess

Not really worth it on a production or primary system is it? Oh well.

Nothing more fun than testing in production 😂