XZ Utils backdoor
Backdoor discovered in 2024
Nº Q125219823 ★★★
Rare · Literature
XZ Utils backdoor
Backdoor discovered in 2024
On 29 March 2024, a malicious backdoor was discovered in the compression software XZ Utils. The backdoor gives an attacker who possesses a specific private key the ability to remotely execute code on an affected system through OpenSSH, a set of networking utilities.
Last price
—
Floor price
—
7-day median
—
30-day sales
0
30-day range
—
In circulation
0
Price history
median
low – high
sales
No sales in this period
Show table
| Date | median | Low | High | sales |
|---|
Sales history
- Last sale
- —
- 30-day average
- —
- 30-day low
- —
- 30-day high
- —
- Sales 7d
- 0
- Sales 30d
- 0
No sales yet.
Anonymous sales: no buyer or seller shown. Figures count player-to-player sales only.
From Wikipedia
On 29 March 2024, a malicious backdoor was discovered in the compression software XZ Utils. The backdoor gives an attacker who possesses a specific private key the ability to remotely execute code on an affected system through OpenSSH, a set of networking utilities. The backdoor was discovered by software developer Andres Freund. It was later discovered that the exploit was deliberately included into the software in February 2024 by a user going by the name of "Jia Tan", affecting both version 5.6.0 and 5.6.1. The issue was given the CVE exploit number CVE-2024-3094 and was assigned a CVSS score of 10.0, the highest possible score, indicating that the exploit was extremely severe. While XZ Utils is commonly present in most Linux distributions, at the time of discovery the affected versions had not yet been widely deployed to production systems, but were present in development versions of major distributions, resulting in distribution maintainers rebuilding their packages to mitigate the exploit. A patch for this backdoor was released on 29 May 2024, with version number 5.6.2. The exploit was noted for its high level of obfuscation, being the result of a campaign lasting years.
Text: Wikipédia, CC BY-SA 4.0. · Image: Jia Tan (CC BY-SA 4.0) ·