Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

>OpenSSH runs...

Not every OpenSSH build it's linked against xz. OpenBSD's one isn't.



Correct. OpenSSH doesn't care about linux or systemd. Makes me want to switch to BSD now


Arch Linux uses systemd, but does not patch sshd, so its not vulnerable to the known backdoor either.

However, to my knowledge nobody has fully analyzed the malware binary yet. So we don't know whether it only contains a single mechanism to attack sshd or whether it also has other harmful components.


Well there is always Slackware, no systemd and unpatched sshd. win-win :)

And correct, this was not an issue for Slackware Current (which has xz 5.6.1). Slackware 15 has xz 5.2.5




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: