xz是一个应用软件。用于支持读取和写入xz压缩流。 XZ Utils 5.6.0版本和5.6.1版本存在安全漏洞,该漏洞源于允许攻击者嵌入恶意代码。
| 厂商 | 产品 | 版本范围 | 状态 |
|---|---|---|---|
| None | None | 5.6.0 |
affected |
5.6.1 |
affected | ||
| Red Hat | Red Hat Enterprise Linux 10 | 全部 |
unaffected |
| Red Hat | Red Hat Enterprise Linux 6 | 全部 |
unaffected |
| Red Hat | Red Hat Enterprise Linux 7 | 全部 |
unaffected |
| Red Hat | Red Hat Enterprise Linux 8 | 全部 |
unaffected |
| Red Hat | Red Hat Enterprise Linux 9 | 全部 |
unaffected |
| Red Hat | Red Hat JBoss Enterprise Application Platform 8 | 全部 |
unaffected |
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| 厂商 | 产品 | 影响版本 | CPE | 订阅 |
|---|---|---|---|---|
| - | - | 5.6.0 | - |
|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| Red Hat | Red Hat JBoss Enterprise Application Platform 8 | - |
cpe:/a:redhat:jboss_enterprise_application_platform:8
|
|
| # | POC 描述 | 源链接 | 神龙链接 |
|---|---|---|---|
| 1 | Information for CVE-2024-3094 | https://github.com/byinarie/CVE-2024-3094-info | POC详情 |
| 2 | Quick and dirty PoC for checking whether a vulnerable version of xz-utils is installed (CVE-2024-3094) | https://github.com/FabioBaroni/CVE-2024-3094-checker | POC详情 |
| 3 | Verify that your XZ Utils version is not vulnerable to CVE-2024-3094 | https://github.com/lypd0/CVE-2024-3094-Vulnerabity-Checker | POC详情 |
| 4 | None | https://github.com/OpensourceICTSolutions/xz_utils-CVE-2024-3094 | POC详情 |
| 5 | Script to detect CVE-2024-3094. | https://github.com/bioless/xz_cve-2024-3094_detection | POC详情 |
| 6 | This repository contains a Bash script and a one-liner command to verify if a system is running a vulnerable version of the "xz" utility, as specified by CVE-2024-3094. | https://github.com/Hacker-Hermanos/CVE-2024-3094_xz_check | POC详情 |
| 7 | None | https://github.com/Fractal-Tess/CVE-2024-3094 | POC详情 |
| 8 | None | https://github.com/wgetnz/CVE-2024-3094-check | POC详情 |
| 9 | History of commits related to the xz backdoor Discovered On March 29, 2024: CVE-2024-3094. | https://github.com/emirkmo/xz-backdoor-github | POC详情 |
| 10 | xz exploit to privilege escalation in Linux | https://github.com/Jooose001/CVE-2024-3094-EXPLOIT | POC详情 |
| 11 | None | https://github.com/ashwani95/CVE-2024-3094 | POC详情 |
| 12 | Checker for CVE-2024-3094 where malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. Through a series of complex obfuscations, the liblzma build process extracts a prebuilt object file from a disguised test file existing in the source code, which is then used to modify specific functions in the liblzma code. | https://github.com/harekrishnarai/xz-utils-vuln-checker | POC详情 |
| 13 | K8S and Docker Vulnerability Check for CVE-2024-3094 | https://github.com/teyhouse/CVE-2024-3094 | POC详情 |
| 14 | This project contains a shell script designed to help users identify and fix installations of xz-utils affected by the CVE-2024-3094 vulnerability. Versions 5.6.0 and 5.6.1 of xz-utils are known to be vulnerable, and this script aids in detecting them and optionally downgrading to a stable, un-compromised version (5.4.6). | https://github.com/alokemajumder/CVE-2024-3094-Vulnerability-Checker-Fixer | POC详情 |
| 15 | None | https://github.com/Horizon-Software-Development/CVE-2024-3094 | POC详情 |
| 16 | None | https://github.com/hazemkya/CVE-2024-3094-checker | POC详情 |
| 17 | An ssh honeypot with the XZ backdoor. CVE-2024-3094 | https://github.com/lockness-Ko/xz-vulnerable-honeypot | POC详情 |
| 18 | None | https://github.com/brinhosa/CVE-2024-3094-One-Liner | POC详情 |
| 19 | CVE-2024-3094 | https://github.com/isuruwa/CVE-2024-3094 | POC详情 |
| 20 | None | https://github.com/k4t3pr0/Check-CVE-2024-3094 | POC详情 |
| 21 | A script to detect if xz is vulnerable - CVE-2024-3094 | https://github.com/Yuma-Tsushima07/CVE-2024-3094 | POC详情 |
| 22 | None | https://github.com/jfrog/cve-2024-3094-tools | POC详情 |
| 23 | None | https://github.com/krascovict/OSINT---CVE-2024-3094- | POC详情 |
| 24 | Ansible playbook for patching CVE-2024-3094 | https://github.com/Simplifi-ED/CVE-2024-3094-patcher | POC详情 |
| 25 | None | https://github.com/gayatriracha/CVE-2024-3094-Nmap-NSE-script | POC详情 |
| 26 | None | https://github.com/Mustafa1986/CVE-2024-3094 | POC详情 |
| 27 | XZ-Utils工具库恶意后门植入漏洞(CVE-2024-3094) | https://github.com/MrBUGLF/XZ-Utils_CVE-2024-3094 | POC详情 |
| 28 | None | https://github.com/galacticquest/cve-2024-3094-detect | POC详情 |
| 29 | None | https://github.com/zgimszhd61/cve-2024-3094-detect-tool | POC详情 |
| 30 | None | https://github.com/mightysai1997/CVE-2024-3094-info | POC详情 |
暂无评论