https://seclists.org/oss-sec/2024/q1/350: backdoor in upstream xz/liblzma leading to ssh server compromise
Published Mar 31, 2024
·Updated
Affected Software
2 affected components
XZ Utils xz
XZ Utils liblzma
Frequently Asked Questions
1
What is the severity of CVE-2024-12345?
CVE-2024-12345 is rated as critical due to its potential to allow unauthorized access to the SSH server.
2
How do I fix CVE-2024-12345?
To fix CVE-2024-12345, upgrade to the latest version of XZ Utils that addresses this vulnerability.
3
What is the impact of CVE-2024-12345 on systems using XZ Utils?
The impact of CVE-2024-12345 includes the risk of a backdoor being created in systems using affected versions of XZ Utils, leading to potential SSH server compromise.
4
Are there any workarounds for CVE-2024-12345 until I can update XZ Utils?
Temporary workarounds include disabling the use of affected features in XZ Utils until an update can be applied.
5
When was CVE-2024-12345 first published?
CVE-2024-12345 was first published on March 31, 2024.