Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

On arch, `ldd $(which sshd)` doesn't list lzma or xz, so I think it's unaffected? Obviously still not great to be shipping malicious code that just happens to not trigger.


Deleted per below


This is what the `detect_sh.bin` attached to the email does. I can only assume that the pesron who reported the vulnerability checked that this succeeds in detecting it.

Note that I'm not looking for the vulnerable symbols, I'm looking for the library that does the patching in the first place.


Deleted, thanks.


My Arch setup is the same, they must not patch openssh.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: