Texonom
Texonom
/
Computing
Computing
/Computing Theory/Information Theory/Cryptography/Encoding/Data Compression/File Archiving/
xz
Search

xz

Creator
Creator
Seonglae Cho
Created
Created
2024 Apr 2 13:13
Editor
Editor
Seonglae Cho
Edited
Edited
2024 Apr 3 12:21
Refs
Refs

CVE-2024-3094

LZMA/LZMA2 압축 알고리즘을 사용
CPU 사용량이 더 높고 압축 및 압축 해제 속도가 느릴 수 있습니다. xz는 주로 높은 압축률이 필요한 상황에 사용
 
 
 
 
research!rsc: Timeline of the xz open source attack
Over a period of over two years, an attacker using the name “Jia Tan” worked as a diligent, effective contributor to the xz compression library, eventually being granted commit access and maintainership. Using that access, they installed a very subtle, carefully hidden backdoor into liblzma, a part of xz that also happens to be a dependency of OpenSSH sshd on Debian, Ubuntu, Fedora, and other systemd-based Linux systems. That backdoor watches for the attacker sending hidden commands at the start of an SSH session, giving the attacker the ability to run an arbitrary command on the target system without logging in: unauthenticated, targeted remote code execution.
research!rsc: Timeline of the xz open source attack
https://research.swtch.com/xz-timeline
 
 
 

 

Recommendations

Texonom
Texonom
/
Computing
Computing
/Computing Theory/Information Theory/Cryptography/Encoding/Data Compression/File Archiving/
xz
Copyright Seonglae Cho