GeistHaus
log in · sign up

xz/liblzma Compromise Link Roundup

shellsharks.com

Links to analysis, discussion and more related to the xz/liblzma compromise (CVE-2024-3094).

2 pages link to this URL
The xz backdoor from a Security Engineer persepective

As you probably already heard, the xz package got compromised. The package was used as entrypoint to inject malicious code in sshd, altering the authentication flow. This forged vulnerability is now known as CVE-2024-3094.

1 inbound link article en posts backdoorCVE-2024-3094xzliblzmasupply-chainsecurity-engineering