On Fri, 26 Apr 2024, Patrick O'Callaghan wrote:
On Fri, 2024-04-26 at 08:22 +0930, Tim via users wrote:
>> as far as xz, for F40, the affected version was only in updates-
>> testing
> Thanks. Also wondering how far back the breach went. I
remember
> reading that the person had being playing the long game about doing
> this.
They spent a long time setting it up, but the actual breach wasn't
introduced until very recently, and IIRC was caught before it made it
to a stable release.
How was it caught?
If it's what I read about recently, 'twas a bit of a fluke.
--
Michael hennebry(a)mail.cs.ndsu.NoDak.edu
"SCSI is NOT magic. There are *fundamental technical
reasons* why it is necessary to sacrifice a young
goat to your SCSI chain now and then." -- John Woods