bug-standards
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: GNU Coding Standards, automake, and the recent xz-utils backdoor


From: Jose E. Marchesi
Subject: Re: GNU Coding Standards, automake, and the recent xz-utils backdoor
Date: Sun, 31 Mar 2024 17:34:10 +0200
User-agent: Gnus/5.13 (Gnus v5.13)

> [...]
>> I agree that distcheck is good but not a cure all.  Any static
>> system can be attacked when there is motive, and unit tests are
>> easily gamed.
>
> The issue seems to be releases containing binary data for unit tests,
> instead of source or scripts to generate that data.  In this case,
> that binary data was used to smuggle in heavily obfuscated object
> code.

As a side note, GNU poke (https://jemarch.net/poke) is good for
generating arbitrarily complex binary data from clear textual
descriptions.



reply via email to

[Prev in Thread] Current Thread [Next in Thread]