Page 1 of 1

Malicious Code in XZ Utils for Linux Systems Enables Remote Code Execution

Posted: Mon Nov 18, 2024 5:16 am
by Shane1145
The malicious code inserted into the open-source library XZ Utils, a widely used package present in major Linux distributions, is also capable of facilitating remote code execution, a new analysis has revealed.

The audacious supply chain compromise, tracked as CVE-2024-3094 (CVSS score: 10.0), came to light last week when Microsoft engineer and PostgreSQL developer Andres Freund alerted to the presence of a backdoor in the data compression utility that gives remote attackers a way to sidestep secure shell authentication and gain complete access to an affected system.

https://thehackernews.com/2024/04/malic ... linux.html