Remix.run Logo
Security Researchers Find XZ Utils Backdoored Debian Images on Docker Hub(news.itsfoss.com)
13 points by 6581 a day ago | 2 comments
notherhack a day ago | parent [-]

"The Debian development team put it like this: So, given the wafer thin vectors of attack here, the extreme age of the images in question, and the fact that even at the time that they were fresh, they were images that shouldn't be used in production anyhow (Debian's "development" repositories), we've opted to leave them in place.

Binarly kind of agrees ... "

daymanstep a day ago | parent [-]

Good to know that the Debian team's attitude towards security has not materially changed since the OpenSSL fiasco.