Package Details: android-x86-xz 5.6.1-3

Git Clone URL: https://aur.archlinux.org/android-x86-xz.git (read-only, click to copy)
Package Base: android-x86-xz
Description: Library and command line tools for XZ and LZMA compressed files (Android x86)
Upstream URL: https://tukaani.org/xz
Licenses: GPL, custom, LGPL
Submitter: hipersayan_x
Maintainer: hipersayan_x
Last Packager: hipersayan_x
Votes: 0
Popularity: 0.000000
First Submitted: 2019-05-06 01:14 (UTC)
Last Updated: 2024-04-21 21:48 (UTC)

Latest Comments

hipersayan_x commented on 2024-03-30 12:52 (UTC)

https://www.bleepingcomputer.com/news/security/red-hat-warns-of-backdoor-in-xz-tools-used-by-most-linux-distros/

The malicious code is obfuscated and can only be found in the complete download package, not in the Git distribution, which lacks the M4 macro, which triggers the backdoor build process.

Ok if that's the case, we must be safe, the code was downloaded directly from the github tag. But xz repository is now disabled, so there is no stable repository for downloading the source code.

reaperx7 commented on 2024-03-30 00:37 (UTC)

Please update to 5.6.1-2 ASAP

https://security.archlinux.org/ASA-202403-1