82 points

no real-world use found for staying more than one version behind

The ssh vulnerability didn’t affect Debian because the packages were too many versions behind

permalink
report
reply
44 points

AFAIK, the xz vulnerability was designed for Debian based on its workaround fixing systemd service status detection. Even if it shipped to something like Arch, the malicious code wouldn’t load.

permalink
report
parent
reply
22 points

Security through Geriatricity

permalink
report
parent
reply
21 points

Except this isn’t true at all.

https://security-tracker.debian.org/tracker/CVE-2024-6387

Regresshion impacted bookworm and trixie both. Buster was too old.

With the downside of me doing an apt update and seeing that openssh-server was on 1:9.2p1-2+deb12u3 and I had no idea at a glance if this included the fix or not (qualys’s page states version 8.5p1-9.8p1 were vulnerable).

If you are running debian bookworm or trixie, you absolutely should update your openssh-server package.

permalink
report
parent
reply
19 points

Isn’t this meme format completely written in sarcasm?

permalink
report
parent
reply
1 point

We’re on a meme page. There is little difference between sarcasm and being serious here. It doesn’t matter whether OP is being fully sarcastic or fully serious, people in the comments may hold the same opinion seriously, sarcastically, or with a mixture of both. The format is irrelevant

permalink
report
parent
reply
28 points

The “install lib-blah-blah-blah” bit doesn’t bother me 'cause whenever I need to make something work, I just copy and paste the “sudo apt install …” commands straight from the internet :)

permalink
report
reply
7 points

I also never used version pinning in debian

permalink
report
parent
reply
27 points

Don’t

Erupt

Before

I

Am

Nevada

permalink
report
reply
25 points

well at least they aren’t trying to make me install snaps, and patching apt so if I sudo apt install firefox it installs the snap version.

permalink
report
reply
12 points

This should be a jailable crime.

permalink
report
parent
reply
2 points
*

especially as the hack flows downriver to distros with actual dignity like mint. Like this is pollution of the water supply dog!

permalink
report
parent
reply
25 points
*

This is great! No better way to demonstrate how perfect Debian is! Debian for the win!

permalink
report
reply

linuxmemes

!linuxmemes@lemmy.world

Create post

I use Arch btw


Sister communities:
Community rules
  1. Follow the site-wide rules and code of conduct
  2. Be civil
  3. Post Linux-related content
  4. No recent reposts

Please report posts and comments that break these rules!

Community stats

  • 8.4K

    Monthly active users

  • 1.1K

    Posts

  • 61K

    Comments