Unveiling the xz Utils Backdoor which deliberately opens our SSH connections for RCEs

Описание к видео Unveiling the xz Utils Backdoor which deliberately opens our SSH connections for RCEs

In the latest liblzma update, a trusted bad actor called 'JiaT75' implemented a backdoor which allows RCE (sending calls to system()) on ssh connections. Here I'm looking into the case and explaining how it works.

Links:
AndresFreundTec on Mastodon: https://mastodon.social/@AndresFreund...
openwall email: https://www.openwall.com/lists/oss-se...
debian repo: https://salsa.debian.org/debian/xz-ut...
Filippo Valsorda on bsky: https://bsky.app/profile/filippo.abys...

Комментарии

Информация по комментариям в разработке