Re: backdoor in upstream xz/liblzma leading to ssh server compromise

Related Vulnerabilities: CVE-2024-3094  
                Hi Andres,

Thanks for writing this up. Just to make sure I understand the action
item here: folks who are building their own xz, should switch to a
release prior to 5.6.0, as those are the only ones known to be
unaffected?

Alex

On Fri, Mar 29, 2024 at 12:10 PM Andres Freund <andres () anarazel de> wrote:

-- 
All that is necessary for evil to succeed is for good people to do nothing.