UBUNTU-CVE-2024-3094
Dashboard / Vulnerabilities / UBUNTU-CVE-2024-3094
Summary:
Details: Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. Through a series of complex obfuscations, the liblzma build process extracts a prebuilt object file from a disguised test file existing in the source code, which is then used to modify specific functions in the liblzma code. This results in a modified liblzma library that can be used by any software linked against this library, intercepting and modifying the data interaction with this library.
References: https://ubuntu.com/security/CVE-2024-3094, https://www.openwall.com/lists/oss-security/2024/03/29/4, https://discourse.ubuntu.com/t/xz-liblzma-security-update/43714, https://www.cve.org/CVERecord?id=CVE-2024-3094
Affected packages
Package
Name: xz-utils
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=focal
Affected ranges
Type: ECOSYSTEM
Events:
