Elektrine lite

← Feed

@noahm@chaos.social

Post #2095329

2024-03-29 20:57 UTC

@corbet This concern was even called out during the ingestion process for the backdoored version. https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1067708#27 The fact that the upload was being performed by one of the upstream contributors no doubt went a long way toward assuaging those concerns at the time.

Replies (1)

  • @noahm@chaos.social @corbet@social.kernel.org The vulnerable version was already present in debian test/unstable before that, it was just 5.6.0 instead of 5.6.1. And it was uploaded by the in-fact maintainer of the debian package for ~5 years.

    Open ##4241053