Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

xz backdoor is included in 0.3.2 #106

Closed
louislang opened this issue Apr 9, 2024 · 1 comment · Fixed by #107
Closed

xz backdoor is included in 0.3.2 #106

louislang opened this issue Apr 9, 2024 · 1 comment · Fixed by #107

Comments

@louislang
Copy link

The current distribution (v0.3.2) on Crates.io contains the test files for xz that contain the backdoor. The test files themselves are not included in either the .tar.gz nor the .zip tags here on Github and are only present in liblzma-sys_0.3.2.crate that is installed from Crates.io.

The hashes for these files are as follows:

  • liblzma-sys-0.3.2/xz/tests/files/bad-3-corrupt_lzma2.xz ecda10d8877d555dbda4a4eba329e146b2be8ac4b7915fb723eaacc9f89d16bd
  • liblzma-sys-0.3.2/xz/tests/files/good-large_compressed.lzma 9aef898229de60f94cdea42f19268e6e3047f7136f2ff97510390a2deeda7032

It remains to be seen if these are executed in any way. Still, it seems prudent to not ship these files if it can be avoided.

@ChanTsune
Copy link

Thank you for your report @louislang !
I'll release a version without them as soon as possible.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants