XZ Utils Backdoor (CVE-2024-3094) : 개인 λ…ΈνŠΈ

XZ Utils Backdoor (CVE-2024-3094) : 개인 λ…ΈνŠΈ

Tech WorldλŠ” XZ Utils λΌμ΄λΈŒλŸ¬λ¦¬μ—μ„œ μˆ¨κ²¨μ§„ 백도어λ₯Ό λ°œκ²¬ν•˜λ©΄μ„œ ν₯λ―Έλ₯Ό λͺ¨μœΌκ³  μžˆμŠ΅λ‹ˆλ‹€. 이 λ°±λ„μ–΄λŠ” SSH RSA ν‚€μ˜ μ•”ν˜Έ 해독 곡정을 μ‘°μž‘ν•˜μ—¬ κ³΅κ²©μžκ°€ μ‹œμŠ€ν…œμ— μž„μ˜μ˜ μ½”λ“œλ₯Ό μ‹€ν–‰ν•  수 있게 ν•©λ‹ˆλ‹€. XZ Utils 버전 5.6.0 및 5.6.1μ—μ„œ λ¬Έμ œκ°€ λ°œκ²¬λ˜μ—ˆμœΌλ©°, μ•½ ν•œ 달 λ™μ•ˆ μˆœν™˜λ˜μ—ˆμŠ΅λ‹ˆλ‹€.

XZ Utils Backdoor (CVE-2024-3094): Personal Notes

Tech World is interested in discovering hidden backdoores in the XZ UTILS library.This backdoor manipulates the password detoxification process of the SSH RSA key, allowing the attacker to run any code on the system.Problems were found in the XZ UTILS version 5.6.0 and 5.6.1 and circulated for about a month.

https://marcoramilli.com/2024/04/03/xz-utils-backdoor-cve-2024-3094-personal-notes/