From nobody Sat Mar 30 21:53:48 2024 X-Original-To: freebsd-stable@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4V6WJ36dtMz5G5lF for ; Sat, 30 Mar 2024 21:53:55 +0000 (UTC) (envelope-from jon@xyinn.org) Received: from mail-4323.proton.ch (mail-4323.proton.ch [185.70.43.23]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "protonmail.com", Issuer "R3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4V6WJ33k2Zz4tZp for ; Sat, 30 Mar 2024 21:53:55 +0000 (UTC) (envelope-from jon@xyinn.org) Authentication-Results: mx1.freebsd.org; none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=xyinn.org; s=protonmail3; t=1711835633; x=1712094833; bh=vaLSO/Q568R790d3NtCdzmDA+MvhgDV5Dm4odOiG3B8=; h=Date:To:From:Cc:Subject:Message-ID:In-Reply-To:References: Feedback-ID:From:To:Cc:Date:Subject:Reply-To:Feedback-ID: Message-ID:BIMI-Selector; b=Zmf8phhkhesi95ZdEz2b5HKrPaY1JVcNxP9QkA6rryJFo5Rcbe/iMTzLpBQlr0Nba CqSb3XaeYUQWGFJScPX8kjIoipJdFAu20KrfJis+m3w0neYR/SSAcP+QzbAG2fBJCB H00ttCRIoC7KLG13XRgpC0ZKayyJNgnP80TliD1ypuWYD9I31GUuMhW9zJJmPchXJG MQF185Zw02HZYBvyJFt/9OBwonC6bJA8iw7cBJ0qMCFWqHycGGUKe0VsSVDRy23CN9 K5uttI9SQbQwvbXeYvbFpLYF8jnlLBqZGYy880JMaAejc7Ab/LOdUGScnSB+mit3hT LJh+CQrx0GMWg== Date: Sat, 30 Mar 2024 21:53:48 +0000 To: "henrichhartzer@tuta.io" From: Jonathan Vasquez Cc: Freebsd Stable Subject: Re: xz 5.6.0/5.6.1 backdoored, possibly in src/contrib as well Message-ID: In-Reply-To: References: Feedback-ID: 12351801:user:proton List-Id: Production branch of FreeBSD source code List-Archive: https://lists.freebsd.org/archives/freebsd-stable List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-freebsd-stable@freebsd.org X-BeenThere: freebsd-stable@freebsd.org MIME-Version: 1.0 Content-Type: multipart/alternative; boundary="b1_kuKzhbe2XkkrOvQ7aGZlzYNG8luhnTGXhYDGMoOAtrU" X-Spamd-Bar: ---- X-Rspamd-Pre-Result: action=no action; module=replies; Message is reply to one we originated X-Spamd-Result: default: False [-4.00 / 15.00]; REPLY(-4.00)[]; ASN(0.00)[asn:62371, ipnet:185.70.43.0/24, country:CH] X-Rspamd-Queue-Id: 4V6WJ33k2Zz4tZp This is a multi-part message in MIME format. --b1_kuKzhbe2XkkrOvQ7aGZlzYNG8luhnTGXhYDGMoOAtrU Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: base64 VGhhbmtzIGZvciBzZW5kaW5nIHRoaXMgSGVucmljaC4gRm9yIHdoYXRldmVyIHJlYXNvbiBJIHRo b3VnaHQgSSB3YXMgYWxyZWFkeSBzdWJzY3JpYmVkIHRvIEBzZWN1cml0eSBidXQgSSB3YXNu4oCZ dOKApiB0aGlzIGhhcyBiZWVuIHJlc29sdmVkIDopLgoKT24gRnJpLCBNYXIgMjksIDIwMjQgYXQg MjE6MTUsIDxbaGVucmljaGhhcnR6ZXJAdHV0YS5pb10obWFpbHRvOk9uIEZyaSwgTWFyIDI5LCAy MDI0IGF0IDIxOjE1LCAgPDxhIGhyZWY9KT4gd3JvdGU6Cgo+IEhpIGV2ZXJ5b25lLAo+Cj4gSSBy ZWNlbnRseSByZWFkIHRocm91Z2ggdGhpczogaHR0cHM6Ly93d3cub3BlbndhbGwuY29tL2xpc3Rz L29zcy1zZWN1cml0eS8yMDI0LzAzLzI5LzQKPgo+IEl0IHNvdW5kcyBsaWtlIHh6IDUuNi4wIGFu ZCA1LjYuMSBhcmUgYmFja2Rvb3JlZC4gTm90IHN1cmUgaWYgRnJlZUJTRCBpcyBvciBub3QsIGJ1 dCBpdCBsb29rcyBsaWtlIDE0LXN0YWJsZSBhbmQgbWFpbiBoYXZlIHh6IDUuNi4wLiBJbiBteSBv cGluaW9uLCBlYXJsaWVyIHZlcnNpb25zIG1heSBhbHNvIGJlIHN1c3BlY3QgZ2l2ZW4gdGhhdCB0 aGlzIG1heSBoYXZlIGJlZW4gYSBkZWxpYmVyYXRlIGJhY2tkb29yIGZyb20gYSBtYWludGFpbmVy Lgo+Cj4gSSBwcm9wb3NlIHRoYXQgd2UgZ28gYmFjayB0byBhICJrbm93biBzYWZlIiB2ZXJzaW9u LiBJdCB3b3VsZCBwcm9iYWJseSBiZSB1bndpc2UgdG8gcHVzaCAxNC4xIGFzLWlzLCBhcyB3ZWxs Lgo+Cj4gVGhlIEdpdGh1YiByZXBvc2l0b3J5IGhhcyBjdXJyZW50bHkgYmVlbiBsb2NrZWQgb3V0 Lgo+Cj4gSG9waW5nIHRoYXQgc29tZW9uZSBtb3JlIGF3YXJlIG9mIHdoYXQncyBnb2luZyBvbiBj YW4gb2ZmZXIgbW9yZSBpbnNpZ2h0Lgo+Cj4gVGhhbmtzIQo+Cj4gLUhlbnJpY2g= --b1_kuKzhbe2XkkrOvQ7aGZlzYNG8luhnTGXhYDGMoOAtrU Content-Type: text/html; charset=utf-8 Content-Transfer-Encoding: base64 PGh0bWw+PGhlYWQ+PC9oZWFkPjxib2R5PiAgIDxkaXYgZGlyPSJhdXRvIj5UaGFua3MgZm9yIHNl bmRpbmcgdGhpcyBIZW5yaWNoLiBGb3Igd2hhdGV2ZXIgcmVhc29uIEkgdGhvdWdodCBJIHdhcyBh bHJlYWR5IHN1YnNjcmliZWQgdG8gQHNlY3VyaXR5IGJ1dCBJIHdhc27igJl04oCmIHRoaXMgaGFz IGJlZW4gcmVzb2x2ZWQgOikuPC9kaXY+PGRpdj48YnI+PC9kaXY+ICA8ZGl2Pjxicj48L2Rpdj48 ZGl2Pjxicj48L2Rpdj5PbiBGcmksIE1hciAyOSwgMjAyNCBhdCAyMToxNSwgICZsdDs8YSBjbGFz cz0iIiBocmVmPSJtYWlsdG86T24gRnJpLCBNYXIgMjksIDIwMjQgYXQgMjE6MTUsICA8PGEgaHJl Zj0iPmhlbnJpY2hoYXJ0emVyQHR1dGEuaW88L2E+Jmd0OyB3cm90ZTo8YmxvY2txdW90ZSB0eXBl PSJjaXRlIiBjbGFzcz0icHJvdG9ubWFpbF9xdW90ZSI+ICBIaSBldmVyeW9uZSw8YnI+PGJyPkkg cmVjZW50bHkgcmVhZCB0aHJvdWdoIHRoaXM6IGh0dHBzOi8vd3d3Lm9wZW53YWxsLmNvbS9saXN0 cy9vc3Mtc2VjdXJpdHkvMjAyNC8wMy8yOS80PGJyPjxicj5JdCBzb3VuZHMgbGlrZSB4eiA1LjYu MCBhbmQgNS42LjEgYXJlIGJhY2tkb29yZWQuIE5vdCBzdXJlIGlmIEZyZWVCU0QgaXMgb3Igbm90 LCBidXQgaXQgbG9va3MgbGlrZSAxNC1zdGFibGUgYW5kIG1haW4gaGF2ZSB4eiA1LjYuMC4gSW4g bXkgb3BpbmlvbiwgZWFybGllciB2ZXJzaW9ucyBtYXkgYWxzbyBiZSBzdXNwZWN0IGdpdmVuIHRo YXQgdGhpcyBtYXkgaGF2ZSBiZWVuIGEgZGVsaWJlcmF0ZSBiYWNrZG9vciBmcm9tIGEgbWFpbnRh aW5lci48YnI+PGJyPkkgcHJvcG9zZSB0aGF0IHdlIGdvIGJhY2sgdG8gYSAia25vd24gc2FmZSIg dmVyc2lvbi4gSXQgd291bGQgcHJvYmFibHkgYmUgdW53aXNlIHRvIHB1c2ggMTQuMSBhcy1pcywg YXMgd2VsbC48YnI+PGJyPlRoZSBHaXRodWIgcmVwb3NpdG9yeSBoYXMgY3VycmVudGx5IGJlZW4g bG9ja2VkIG91dC48YnI+PGJyPkhvcGluZyB0aGF0IHNvbWVvbmUgbW9yZSBhd2FyZSBvZiB3aGF0 J3MgZ29pbmcgb24gY2FuIG9mZmVyIG1vcmUgaW5zaWdodC48YnI+PGJyPlRoYW5rcyE8YnI+PGJy Pi1IZW5yaWNoPGJyPjxicj48L2Jsb2NrcXVvdGU+PC9ib2R5PjwvaHRtbD4= --b1_kuKzhbe2XkkrOvQ7aGZlzYNG8luhnTGXhYDGMoOAtrU--