Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Usage of xz #13

Open
quat1024 opened this issue Mar 29, 2024 · 1 comment
Open

Usage of xz #13

quat1024 opened this issue Mar 29, 2024 · 1 comment

Comments

@quat1024
Copy link
Member

quat1024 commented Mar 29, 2024

Voldeloom uses xz-java to unpack the "binpatches.pack.lzma" file present in Forge 1.6 and 1.7. In other news, the xz maintainer has apparently just outed themself as the type to add backdoors into binaries: https://www.openwall.com/lists/oss-security/2024/03/29/4

note that xz-java is a separate project and I don't think it uses the native xz binaries... but still. They're under the same organization and the same author commits to both. Switching to another lzma decompressing solution might be a good idea.

@unascribed
Copy link

unascribed commented Mar 29, 2024

The original LZMA library by the 7zip project is public domain and has a Java port. It's not available in a Maven repo, unfortunately.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants