[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248364

 
 

909

 
 

195388

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Supply-chain backdooor vulnerability in XZ - CVE-2024-3094 (linux)

ID: oval:org.secpod.oval:def:98828Date: (C)2024-04-04   (M)2024-04-17
Class: VULNERABILITYFamily: unix




The host is installed with XZ version 5.6.0, or 5.6.1 and is prone to a supply-chain backdooor vulnerability. A flaw is present in the application, which fails to handle a malicious code in the upstream tarballs of xz. Successful exploitation allows attackers to use any software linked against the modified liblzma library, intercepting and modifying the data interaction with this library.

Platform:
Linux
Product:
XZ
Reference:
CVE-2024-3094
CVE    1
CVE-2024-3094

© SecPod Technologies