[tcpdump-workers] Re: openwrt Conclusions from CVE-2024-3094 (libxz disaster)

2024-04-02 Thread Francois-Xavier Le Bail via tcpdump-workers
--- Begin Message --- On 01/04/2024 20:18, Guy Harris wrote: > On Apr 1, 2024, at 6:53 AM, Michael Richardson wrote: > >> I wonder if we should nuke our own make tarball system. > > I.e., replace: > > to get {libpcap,tcpdump,tcpslice} version X.Y.Z, download > {libpcap,tcpdump,tcpslice}-

[tcpdump-workers] Re: openwrt Conclusions from CVE-2024-3094 (libxz disaster)

2024-04-02 Thread Denis Ovsienko
On Tue, 2 Apr 2024 14:06:28 +0200 Francois-Xavier Le Bail via tcpdump-workers wrote: > Even if we keep the tarball archive, we could have a host compromise > (bad autoconf, etc.) and if the "configure" script is generated on > it, we risk to open a door to an attack. > > Thus, don't deliver "con