[MacPorts] #69619: xz @5.6.1 reportedly backdoored

MacPorts noreply at macports.org
Sat Mar 30 01:16:24 UTC 2024


#69619: xz @5.6.1 reportedly backdoored
---------------------+------------------------
  Reporter:  jmroot  |      Owner:  ryandesign
      Type:  defect  |     Status:  assigned
  Priority:  High    |  Milestone:
 Component:  ports   |    Version:
Resolution:          |   Keywords:  security
      Port:  xz      |
---------------------+------------------------

Comment (by woolsweater):

 If possible -- I have no idea what breakages would result -- it seems most
 prudent to roll even further back. The account responsible for the
 backdoor has been involved in the xz project for quite some time and has
 many, many commits. See this discussion on the Debian bug list:
 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1068024

-- 
Ticket URL: <https://trac.macports.org/ticket/69619#comment:4>
MacPorts <https://www.macports.org/>
Ports system for macOS


More information about the macports-tickets mailing list