Package: coreutils
Version: 9.10-1
Severity: wishlist

Dear Maintainer,

=============================================================================

   * What led up to the situation?
   A malware program named sedex (or sedexp) avoids detection by
   manipulating dynamic memory and shared libs so that utils like ls
   will not display its files.

   It would be helpful to have a version of coreutils package built only
   with static libraries so the presence of this malware could be found
   without having to boot from a live CD and search the system.

   In the interim, one can download the coreutils source and add flags
   to ./configure LDFLAGS="..." to build with only static libraries  but
   this is clumsy and does not keep up with new coreutils versions.

=============================================================================


-- System Information:
Debian Release: forky/sid
  APT prefers testing
  APT policy: (500, 'testing')
Architecture: amd64 (x86_64)

Kernel: Linux 6.16.12+deb14+1-amd64 (SMP w/12 CPU threads; PREEMPT)
Kernel taint flags: TAINT_PROPRIETARY_MODULE, TAINT_FIRMWARE_WORKAROUND, 
TAINT_OOT_MODULE, TAINT_UNSIGNED_MODULE
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8) (ignored: LC_ALL 
set to C.UTF-8), LANGUAGE not set
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)

Versions of packages coreutils depends on:
ii  libacl1      2.4.0-1
ii  libattr1     1:2.6.0-1
ii  libc6        2.43-3
ii  libgmp10     2:6.3.0+dfsg-5
ii  libselinux1  3.11-2
ii  libssl3t64   3.6.3-1
ii  libsystemd0  261.2-1

coreutils recommends no packages.

coreutils suggests no packages.

-- no debconf information

Reply via email to