<!DOCTYPE html>
<html>
<head>
<meta http-equiv="content-type" content="text/html; charset=UTF-8">
</head>
<body>
<p
style="box-sizing: border-box; margin: 0px 0px 10px; color: rgb(85, 85, 85); font-family: "Helvetica Neue", Helvetica, Arial, sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; white-space: normal; background-color: rgb(255, 255, 255); text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;">There
is an xz vulnerability in 5.6.0 and 5.6.1 that was caused by a
malicious payload added via a commit. <a
href="https://boehs.org/node/everything-i-know-about-the-xz-backdoor"
style="box-sizing: border-box; background-color: transparent; color: rgb(47, 164, 231); text-decoration: none;"
class="moz-txt-link-freetext">https://boehs.org/node/everything-i-know-about-the-xz-backdoor</a></p>
<p
style="box-sizing: border-box; margin: 0px 0px 10px; color: rgb(85, 85, 85); font-family: "Helvetica Neue", Helvetica, Arial, sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; white-space: normal; background-color: rgb(255, 255, 255); text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;">At
this time, I am unaware of anything in libarchive that is
considered dangerous as mentioned on that website. MidnightBSD
does not use the affected versions of xz in base. We have 5.2.9
right now.</p>
<p></p>
<pre class="moz-signature" cols="72">--
Lucas Holt
<a class="moz-txt-link-abbreviated" href="mailto:Luke@FoolishGames.com">Luke@FoolishGames.com</a>
________________________________________________________
MidnightBSD.org (Free OS)
JustJournal.com (Free blogging)</pre>
</body>
</html>