xz/liblzma Backdoored

Discussion in 'News Aggregator' started by Packet Storm, 30 Mar 2024.

  1. Packet Storm

    Packet Storm Guest

    It has been discovered that the upstream source tarballs for xz-utils, the XZ-format compression utilities, are compromised and inject malicious code, at build time, into the resulting liblzma5 library. Included in this archive are not only the advisory but additional data and a testing script to see if you're affected.

    Continue reading...
     

Share This Page

Loading...