Backdoor in xz/liblzma (CVE-2024-3094)
On March 29th, Andres Freund, a Postgres developer, working at Microsoft, identified a response time while authenticating to openSSH on a Debian Sid installation that was about 500 ms longer as usual. He investigated the behaviour and concluded that liblzma, part of the xz library, was compromised by a complex backdoor injected into distribution packages […]
Backdoor in xz/liblzma (CVE-2024-3094) Read More »