CVE-2024-3094

CVSS v3 10 (Critical)
EPSS 10.08 % (95th)
Affected Products 1
Advisories 3

Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0.
Through a series of complex obfuscations, the liblzma build process extracts a prebuilt object file from a disguised test file existing in the source code, which is then used to modify specific functions in the liblzma code. This results in a modified liblzma library that can be used by any software linked against this library, intercepting and modifying the data interaction with this library.

Weaknesses
CWE-506
Embedded Malicious Code
CNA
Red Hat, Inc.
secalert@redhat.com
Published Date
2024-03-29 17:15:21
(3 weeks ago)
Updated Date
2024-04-12 07:15:08
(12 days ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Tukaani Xz 5.6.0 cpe:2.3:a:tukaani:xz:5.6.0
  Tukaani Xz 5.6.1 cpe:2.3:a:tukaani:xz:5.6.1
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...