Latest Slackware current update:
84 updates. Including a (* Security fix *)!
Thu Sep 10 00:16:15 UTC 2026
a/xz-5.8.4-x86_64-1.txz: Upgraded.
This update fixes a security issue:
liblzma: lzma_alone_decoder(), lzma_lzip_decoder(), lzma_auto_decoder(),
Latest Slackware current update:
84 updates. Including a (* Security fix *)!
Thu Sep 10 00:16:15 UTC 2026
a/xz-5.8.4-x86_64-1.txz: Upgraded.
This update fixes a security issue:
liblzma: lzma_alone_decoder(), lzma_lzip_decoder(), lzma_auto_decoder(),
The waitlist is live
morbiz.ai/marketing-engine
The waitlist is live
morbiz.ai/marketing-engine
📊 10.0/10
📝 Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0.
Through a series of complex obfuscations, the liblzma build process ex...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-31700
#cybersecurity #infosec #cve #euvd
📊 10.0/10
📝 Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0.
Through a series of complex obfuscations, the liblzma build process ex...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-31700
#cybersecurity #infosec #cve #euvd
Andres Freund, a Microsoft engineer, noticed SSH logins taking ~500ms longer than they should.
Most people would shrug. He went digging instead.
He traced the delay into liblzma and found a backdoor in XZ Utils, a package shipped with nearly every Linux distribution.
Andres Freund, a Microsoft engineer, noticed SSH logins taking ~500ms longer than they should.
Most people would shrug. He went digging instead.
He traced the delay into liblzma and found a backdoor in XZ Utils, a package shipped with nearly every Linux distribution.
Notices SSH using too much CPU. Profiles it. CPU time in liblzma inside sshd.
"It felt surreal. I wondered if I was having fever dreams."
He publishes. The internet catches fire.
Notices SSH using too much CPU. Profiles it. CPU time in liblzma inside sshd.
"It felt surreal. I wondered if I was having fever dreams."
He publishes. The internet catches fire.
https://www.ssh.com/blog/a-recap-of-the-openssh-and-xz-liblzma-incident
https://www.ssh.com/blog/a-recap-of-the-openssh-and-xz-liblzma-incident
www.ssh.com/blog/a-recap...
www.ssh.com/blog/a-recap...
#threat-intelligence #information-security #linux #cybersecurity #supply-chain
Origin | Interest […]
#threat-intelligence #information-security #linux #cybersecurity #supply-chain
Origin | Interest […]
CVE-2024-3094: хтось намагався додати бекдор у openssh через liblzma. Найцікавіше поки те, що у коді репозиторію немає, а у артефактах (архівах для завантаження) на github є. Принаймні, були до закривання.
CVE-2024-3094: хтось намагався додати бекдор у openssh через liblzma. Найцікавіше поки те, що у коді репозиторію немає, а у артефактах (архівах для завантаження) на github є. Принаймні, були до закривання.
$ fuse-archive --version
fuse-archive version: 1.17
libarchive version: libarchive 3.7.4
bzlib version: 1.0.8, 13-Jul-2019
liblz4 version: 1.10.0
liblzma version: 5.8.1
libzstd version: 1.5.7
zlib version: 1.3.1
FUSE library version 3.17.4
using FUSE kernel interface version 7 […]
$ fuse-archive --version
fuse-archive version: 1.17
libarchive version: libarchive 3.7.4
bzlib version: 1.0.8, 13-Jul-2019
liblz4 version: 1.10.0
liblzma version: 5.8.1
libzstd version: 1.5.7
zlib version: 1.3.1
FUSE library version 3.17.4
using FUSE kernel interface version 7 […]
It provides a Docker container with the vulnerable Debian package and a patched liblzma library to reproduce the SSH authentication bypass exploit
➤ https://ku.bz/4K_lDB_ff
It provides a Docker container with the vulnerable Debian package and a patched liblzma library to reproduce the SSH authentication bypass exploit
➤ https://ku.bz/4K_lDB_ff
It provides a Docker container with the vulnerable Debian package and a patched liblzma library to reproduce the SSH authentication bypass exploit
➜ https://ku.bz/4K_lDB_ff
It provides a Docker container with the vulnerable Debian package and a patched liblzma library to reproduce the SSH authentication bypass exploit
➜ https://ku.bz/4K_lDB_ff
robmensching.com/blog/posts/2...
robmensching.com/blog/posts/2...
➡️ „Poisoning your supply chain - the xz-utils SSH backdoor” – Łukasz Kędziora (Antmicro)
Prezentacja omawia głośny przypadek tylnej furtki w bibliotece liblzma, której celem było przejęcie kontroli nad OpenSSH.
👉 PeerTube […]
[Original post on fosstodon.org]
➡️ „Poisoning your supply chain - the xz-utils SSH backdoor” – Łukasz Kędziora (Antmicro)
Prezentacja omawia głośny przypadek tylnej furtki w bibliotece liblzma, której celem było przejęcie kontroli nad OpenSSH.
👉 PeerTube […]
[Original post on fosstodon.org]