79 points

no real-world use found for staying more than one version behind

The ssh vulnerability didn’t affect Debian because the packages were too many versions behind

permalink
report
reply
40 points

AFAIK, the xz vulnerability was designed for Debian based on its workaround fixing systemd service status detection. Even if it shipped to something like Arch, the malicious code wouldn’t load.

permalink
report
parent
reply
21 points

Security through Geriatricity

permalink
report
parent
reply
14 points

Isn’t this meme format completely written in sarcasm?

permalink
report
parent
reply
0 points

We’re on a meme page. There is little difference between sarcasm and being serious here. It doesn’t matter whether OP is being fully sarcastic or fully serious, people in the comments may hold the same opinion seriously, sarcastically, or with a mixture of both. The format is irrelevant

permalink
report
parent
reply
12 points

Except this isn’t true at all.

https://security-tracker.debian.org/tracker/CVE-2024-6387

Regresshion impacted bookworm and trixie both. Buster was too old.

With the downside of me doing an apt update and seeing that openssh-server was on 1:9.2p1-2+deb12u3 and I had no idea at a glance if this included the fix or not (qualys’s page states version 8.5p1-9.8p1 were vulnerable).

If you are running debian bookworm or trixie, you absolutely should update your openssh-server package.

permalink
report
parent
reply
1 point

The xz/ssh back door made it into Debian testing, So I felt I should wipe and reinstall.

Debian has had a rolling release for ages.

permalink
report
parent
reply
24 points

The “install lib-blah-blah-blah” bit doesn’t bother me 'cause whenever I need to make something work, I just copy and paste the “sudo apt install …” commands straight from the internet :)

permalink
report
reply
5 points

I also never used version pinning in debian

permalink
report
parent
reply
23 points

Don’t

Erupt

Before

I

Am

Nevada

permalink
report
reply
21 points
*

This is great! No better way to demonstrate how perfect Debian is! Debian for the win!

permalink
report
reply
19 points

well at least they aren’t trying to make me install snaps, and patching apt so if I sudo apt install firefox it installs the snap version.

permalink
report
reply
8 points

This should be a jailable crime.

permalink
report
parent
reply
1 point
*

especially as the hack flows downriver to distros with actual dignity like mint. Like this is pollution of the water supply dog!

permalink
report
parent
reply

linuxmemes

!linuxmemes@lemmy.world

Create post

Hint: :q!


Sister communities:

Community rules (click to expand)

1. Follow the site-wide rules
2. Be civil
  • Understand the difference between a joke and an insult.
  • Do not harrass or attack members of the community for any reason.
  • Leave remarks of “peasantry” to the PCMR community. If you dislike an OS/service/application, attack the thing you dislike, not the individuals who use it. Some people may not have a choice.
  • Bigotry will not be tolerated.
  • These rules are somewhat loosened when the subject is a public figure. Still, do not attack their person or incite harrassment.
3. Post Linux-related content
  • Including Unix and BSD.
  • Non-Linux content is acceptable as long as it makes a reference to Linux. For example, the poorly made mockery of sudo in Windows.
  • No porn. Even if you watch it on a Linux machine.
4. No recent reposts
  • Everybody uses Arch btw, can’t quit Vim, and wants to interject for a moment. You can stop now.

Please report posts and comments that break these rules!

Community stats

  • 6.6K

    Monthly active users

  • 1.3K

    Posts

  • 69K

    Comments