Re: backdoor in upstream xz/liblzma leading to ssh server compromise

Related Vulnerabilities: CVE-2024-3094  
                I would not trust any content from tukanni.org including older tarballs.

The malicious individual has access to the signing key clearly and could
modify older tarballs easily.

Regards,

Anthony Liguori

On Fri, Mar 29, 2024, 9:18 AM Alex Gaynor <alex.gaynor () gmail com> wrote: