タグ

ブックマーク / gist.github.com/thesamesam (1)

  • xz-utils backdoor situation (CVE-2024-3094)

    xz-backdoor.md FAQ on the xz-utils backdoor (CVE-2024-3094) This is a living document. Everything in this document is made in good faith of being accurate, but like I just said; we don't yet know everything about what's going on. Background On March 29th, 2024, a backdoor was discovered in xz-utils, a suite of software that gives developers lossless compression. This package is commonly used for c

    xz-utils backdoor situation (CVE-2024-3094)
    sonots
    sonots 2024/03/30
    テストデータとして入れたバイナリを、ビルド時に展開してビルドプロセス改変してた、のかな。巧妙
  • 1