pkgsrc-Users archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: Bulk builds after xz downgrade



On Fri, Mar 29, 2024 at 01:33:44PM +0000, Jonathan Perkin wrote:
> Heads up to those performing bulk builds, you'll need to remove xz-5.6.*
> from your PACKAGES directory before starting builds after this change,
> otherwise you'll run into depends failures.

I've renamed the version to "5.6.1nb100" so it's newer than what we
had before. It contains the code of 5.4.6 though. I noted this in
DESCR and COMMENT.

The reason for the downgrade is a backdoor introduced in 5.6.0 that
only seems to affect Linux installations. Here's the full write-up:

https://www.openwall.com/lists/oss-security/2024/03/29/4

 Thomas


Home | Main Index | Thread Index | Old Index