Security alert for xz/xz-utils for Jammy/Fossapup64-95

Issues and / or general discussion relating to Puppy

Moderator: Forum moderators

Post Reply
User avatar
Jasper
Posts: 1654
Joined: Wed Sep 07, 2022 1:20 pm
Has thanked: 712 times
Been thanked: 378 times

Security alert for xz/xz-utils for Jammy/Fossapup64-95

Post by Jasper »

Hi all

I read an article today on this website regarding a security alert for an application (xz / xz-utils):
https://www.phoronix.com/news/GitHub-Disables-XZ-Repo

I know that I have compiled/uploaded/shared this application on the forum in the JammyPup section:
viewtopic.php?p=115050#p115050

I have removed the link and posted in that section for members to uninstall the update as it has been flagged up that it contains malicious code.

I have checked the Fossapup64-95 applications thread to see if I also included this update in that section too. I did find an older build 5.4.x but not the affected version builds ie 5.60 and 5.61

@rockedge or members of the Moderators, please can you check again for links for xz v5.60 / v5.61 ?

The search facility is difficult to get results for small terms eg "xz"

@sonny , I do not know if you have also added this to the forum as you too continue to support Fossapup64-95 with application updates.

On my part this was not done intentionally nor did I have any prior knowledge of the altered code available on GitHub.

sonny
Posts: 606
Joined: Mon Feb 15, 2021 4:50 pm
Has thanked: 442 times
Been thanked: 141 times

Re: Security alert for xz/xz-utils for Jammy/Fossapup64-95

Post by sonny »

Thanks, @Jasper!
Fortunately the last version of xz I posted was 5.4.6.
I will downgrade it from DARKPUPPY asap.

Post Reply

Return to “Users”