Cookie Consent by Free Privacy Policy Generator Aktuallisiere deine Cookie Einstellungen ๐Ÿ“Œ All about the xz-utils backdoor


๐Ÿ“š All about the xz-utils backdoor


๐Ÿ’ก Newskategorie: Tools
๐Ÿ”— Quelle: kali.org

As of 5:00 pm ET on March 29, 2024 the following information is accurate. Should there be updates to this situation, they will be edited onto this blog post.

The xz-utils package, starting from versions 5.6.0 to 5.6.1, was found to contain a backdoor (CVE-2024-3094). This backdoor could potentially allow a malicious actor to compromise sshd authentication, granting unauthorized access to the entire system remotely.

With a library this widely used, the severity of this vulnerability poses a threat to the entire Linux ecosystem. Luckily, this issue was caught quickly so the impact was significantly less than it could have been. It has already been patched in Debian, and therefore, Kali Linux.

The impact of this vulnerability affected Kali between March 26th to March 29th, during which time xz-utils 5.6.0-0.2 was available. If you updated your Kali installation on or after March 26th, but before March 29th, it is crucial to apply the latest updates today to address this issue. However, if you did not update your Kali installation before the 26th, you are not affected by this backdoor vulnerability.

Should you wish to check if you have the vulnerable version installed, we can perform the following command:

kali@kali:~$ apt-cache policy liblzma5
liblzma5:
ย Installed: 5.4.5-0.3
ย Candidate: 5.6.1+really5.4.5-1
ย Version table:
ย ย ย ย 5.6.1+really5.4.5-1 500
ย ย ย ย ย ย ย 500 http://kali.download/kali kali-rolling/main amd64 Packages
*** 5.4.5-0.3 100
ย ย ย ย ย ย ย 100 /var/lib/dpkg/status

If we see the version 5.6.0-0.2 next to Installed: then we must upgrade to the latest version, 5.6.1+really5.4.5-1. We can do this with the following commands:

kali@kali:~$ sudo apt update && sudo apt install -y --only-upgrade liblzma5
...
kali@kali:~$

More information can be found at Help Net Security for a summarized post on the details of the vulnerability, Openwall for the initial disclosure, and NISTโ€™s NVD entry for this vulnerability.

...



๐Ÿ“Œ No backdoor, no backdoor... you're a backdoor! Huawei won't spy for China or anyone else, exec tells MPs


๐Ÿ“ˆ 23.7 Punkte

๐Ÿ“Œ Bugtraq: Multiple vulnerabilities found in the Dlink DWR-932B (backdoor, backdoor accounts, weak WPS, RCE ...)


๐Ÿ“ˆ 15.8 Punkte

๐Ÿ“Œ Why WhatsAppโ€™s โ€˜Backdoorโ€™ Isnโ€™t a Backdoor


๐Ÿ“ˆ 15.8 Punkte

๐Ÿ“Œ Bugtraq: Multiple vulnerabilities found in the Dlink DWR-932B (backdoor, backdoor accounts, weak WPS, RCE ...)


๐Ÿ“ˆ 15.8 Punkte

๐Ÿ“Œ Why WhatsAppโ€™s โ€˜Backdoorโ€™ Isnโ€™t a Backdoor


๐Ÿ“ˆ 15.8 Punkte

๐Ÿ“Œ Hacking the hackers โ€“ IOT botnet author adds his own backdoor on top of a ZTE router backdoor


๐Ÿ“ˆ 15.8 Punkte

๐Ÿ“Œ SolarWinds Hack โ€“ Multiple Similarities Found Between Sunburst Backdoor and Turlaโ€™s Backdoor


๐Ÿ“ˆ 15.8 Punkte

๐Ÿ“Œ Shell Backdoor List - PHP / ASP Shell Backdoor List


๐Ÿ“ˆ 15.8 Punkte

๐Ÿ“Œ Backdoor.Win32.Wollf.c Hardcoded Backdoor Password


๐Ÿ“ˆ 15.8 Punkte

๐Ÿ“Œ Powershell-Backdoor-Generator - Obfuscated Powershell Reverse Backdoor With Flipper Zero And USB Rubber Ducky Payloads


๐Ÿ“ˆ 15.8 Punkte

๐Ÿ“Œ l+f: Webshop all inclusive (mit Backdoor)


๐Ÿ“ˆ 12.79 Punkte

๐Ÿ“Œ l+f: Webshop all inclusive (mit Backdoor)


๐Ÿ“ˆ 12.79 Punkte

๐Ÿ“Œ l+f: Webshop all inclusive (mit Backdoor)


๐Ÿ“ˆ 12.79 Punkte

๐Ÿ“Œ l+f: Webshop all inclusive (mit Backdoor)


๐Ÿ“ˆ 12.79 Punkte

๐Ÿ“Œ New Plurox malware is a backdoor, cryptominer, and worm, all packed into one


๐Ÿ“ˆ 12.79 Punkte

๐Ÿ“Œ Renewed calls for backdoor access to encryption have all the same flaws


๐Ÿ“ˆ 12.79 Punkte

๐Ÿ“Œ Backdoor Could Allow Company To Shut Down 70% of All Bitcoin Mining Operations


๐Ÿ“ˆ 12.79 Punkte

๐Ÿ“Œ 88 New Satellites Will Watch Earth, All the Time, All the Places


๐Ÿ“ˆ 9.78 Punkte

๐Ÿ“Œ Ask Slashdot: What Would Happen If All Software Ran On All Platforms?


๐Ÿ“ˆ 9.78 Punkte

๐Ÿ“Œ In detail: How we are all pushed, filed, stamped, indexed, briefed, debriefed or numbered โ€“ by online biz all day


๐Ÿ“ˆ 9.78 Punkte

๐Ÿ“Œ Privacy In An Era Where All Things Know All Things


๐Ÿ“ˆ 9.78 Punkte

๐Ÿ“Œ IBM bans all removable storage, for all staff, everywhere


๐Ÿ“ˆ 9.78 Punkte

๐Ÿ“Œ Is the "either all GTK or all Qt" mentality still relevant today?


๐Ÿ“ˆ 9.78 Punkte

๐Ÿ“Œ All I wanna do is copy a DVD. But all Ubuntu wants to do is infuriate me.


๐Ÿ“ˆ 9.78 Punkte

๐Ÿ“Œ Is Data Science For All the New Computer Science For All?


๐Ÿ“ˆ 9.78 Punkte

๐Ÿ“Œ All-time Heat Records Are Being Set All Over the World


๐Ÿ“ˆ 9.78 Punkte

๐Ÿ“Œ For all the contributors and all the supporters of Linux, THANK YOU!


๐Ÿ“ˆ 9.78 Punkte

๐Ÿ“Œ DGAP-News: All for One Steeb AG: Hauptversammlung beschlieรŸt Umfirmierung in All for One ...


๐Ÿ“ˆ 9.78 Punkte

๐Ÿ“Œ All for One Steeb AG: Hauptversammlung beschlieรŸt Umfirmierung in All for One Group AG ...


๐Ÿ“ˆ 9.78 Punkte











matomo