Portable-Network-Archive / liblzma-rs

Bindings to liblzma in Rust (xz streams in Rust)
Apache License 2.0
19 stars 5 forks source link

Backdoor in upstream xz/lzma #95

Closed amousset closed 7 months ago

amousset commented 8 months ago

See https://www.openwall.com/lists/oss-security/2024/03/29/4

This library is very likely not impacted as it does not use the tarball which contains the backdoor activation but directly the git repository as a submodule, but it might be worth considering a downgrade to 5.4.6 as a safety measure.

ChanTsune commented 8 months ago

@amousset Thank you for letting us know! We'll be keeping an eye on this matter!