logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2024-3094

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2024-3094

Description:
Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. Through a series of complex obfuscations, the liblzma build process extracts a prebuilt object file from a disguised test file existing in the source code, which is then used to modify specific functions in the liblzma code. This results in a modified liblzma library that can be used by any software linked against this library, intercepting and modifying the data interaction with this library.
Last updated date:
05/01/2024
Type:
exploit
Confidence:
HIGH
Date of publishing:
03/29/2024
Reference url to background

https://github.com/byinarie/CVE-2024-3094-info

Type:
exploit
Confidence:
HIGH
Date of publishing:
03/29/2024
Type:
exploit
Confidence:
HIGH
Date of publishing:
03/29/2024
Type:
exploit
Confidence:
HIGH
Date of publishing:
03/29/2024
Type:
exploit
Confidence:
HIGH
Date of publishing:
03/30/2024
Type:
exploit
Confidence:
HIGH
Date of publishing:
03/30/2024
Type:
exploit
Confidence:
HIGH
Date of publishing:
03/30/2024
Type:
exploit
Confidence:
HIGH
Date of publishing:
03/30/2024
Type:
exploit
Confidence:
HIGH
Date of publishing:
03/30/2024
Type:
exploit
Confidence:
HIGH
Date of publishing:
03/31/2024
Type:
exploit
Confidence:
HIGH
Date of publishing:
03/31/2024
Type:
exploit
Confidence:
HIGH
Date of publishing:
04/01/2024
Reference url to background

https://github.com/amlweems/xzbot

Type:
exploit
Confidence:
HIGH
Date of publishing:
04/01/2024
Type:
exploit
Confidence:
HIGH
Date of publishing:
04/01/2024
Type:
exploit
Confidence:
HIGH
Date of publishing:
04/02/2024
Reference url to background

https://github.com/r0binak/xzk8s

Type:
exploit
Confidence:
HIGH
Date of publishing:
04/04/2024
Type:
exploit
Confidence:
HIGH
Date of publishing:
04/04/2024
Type:
exploit
Confidence:
HIGH
Date of publishing:
04/05/2024
Vulnerability FeedContributorsAboutBlog

@inTheWild

©2024

Privacy Policy