oss-sec mailing list archives

Re: backdoor in upstream xz/liblzma leading to ssh server compromise


From: Matthias Weckbecker <matthias () weckbecker name>
Date: Fri, 29 Mar 2024 19:44:05 +0100

Hi Andres,

thanks for the nice write-up.

I've attached a yara rule to detect the *.o droplet you attached in the
email (liblzma_la-crc64-fast.o.gz).

I'll look more into this as soon as I return from holidays. Again, nice
write-up. Thanks!

Matthias

Attachment: CVE-2024-3094-o.yara
Description:


Current thread: