Malicious Code in XZ Utils for Linux Systems Enables Remote Code Execution

Post Reply
Shane1145
Posts: 1729
Joined: Wed Sep 25, 2024 2:31 pm

Malicious Code in XZ Utils for Linux Systems Enables Remote Code Execution

Post by Shane1145 »

The malicious code inserted into the open-source library XZ Utils, a widely used package present in major Linux distributions, is also capable of facilitating remote code execution, a new analysis has revealed.

The audacious supply chain compromise, tracked as CVE-2024-3094 (CVSS score: 10.0), came to light last week when Microsoft engineer and PostgreSQL developer Andres Freund alerted to the presence of a backdoor in the data compression utility that gives remote attackers a way to sidestep secure shell authentication and gain complete access to an affected system.

https://thehackernews.com/2024/04/malic ... linux.html
Post Reply