xz是一个应用软件。用于支持读取和写入xz压缩流。 XZ Utils 5.6.0版本和5.6.1版本存在安全漏洞,该漏洞源于允许攻击者嵌入恶意代码。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| None | None | 5.6.0 |
affected |
5.6.1 |
affected | ||
| Red Hat | Red Hat Enterprise Linux 10 | any |
unaffected |
| Red Hat | Red Hat Enterprise Linux 6 | any |
unaffected |
| Red Hat | Red Hat Enterprise Linux 7 | any |
unaffected |
| Red Hat | Red Hat Enterprise Linux 8 | any |
unaffected |
| Red Hat | Red Hat Enterprise Linux 9 | any |
unaffected |
| Red Hat | Red Hat JBoss Enterprise Application Platform 8 | any |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | - | 5.6.0 | - |
|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| Red Hat | Red Hat JBoss Enterprise Application Platform 8 | - |
cpe:/a:redhat:jboss_enterprise_application_platform:8
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Information for CVE-2024-3094 | https://github.com/byinarie/CVE-2024-3094-info | POC Details |
| 2 | Quick and dirty PoC for checking whether a vulnerable version of xz-utils is installed (CVE-2024-3094) | https://github.com/FabioBaroni/CVE-2024-3094-checker | POC Details |
| 3 | Verify that your XZ Utils version is not vulnerable to CVE-2024-3094 | https://github.com/lypd0/CVE-2024-3094-Vulnerabity-Checker | POC Details |
| 4 | None | https://github.com/OpensourceICTSolutions/xz_utils-CVE-2024-3094 | POC Details |
| 5 | Script to detect CVE-2024-3094. | https://github.com/bioless/xz_cve-2024-3094_detection | POC Details |
| 6 | This repository contains a Bash script and a one-liner command to verify if a system is running a vulnerable version of the "xz" utility, as specified by CVE-2024-3094. | https://github.com/Hacker-Hermanos/CVE-2024-3094_xz_check | POC Details |
| 7 | None | https://github.com/Fractal-Tess/CVE-2024-3094 | POC Details |
| 8 | None | https://github.com/wgetnz/CVE-2024-3094-check | POC Details |
| 9 | History of commits related to the xz backdoor Discovered On March 29, 2024: CVE-2024-3094. | https://github.com/emirkmo/xz-backdoor-github | POC Details |
| 10 | xz exploit to privilege escalation in Linux | https://github.com/Jooose001/CVE-2024-3094-EXPLOIT | POC Details |
| 11 | None | https://github.com/ashwani95/CVE-2024-3094 | POC Details |
| 12 | Checker for CVE-2024-3094 where malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. Through a series of complex obfuscations, the liblzma build process extracts a prebuilt object file from a disguised test file existing in the source code, which is then used to modify specific functions in the liblzma code. | https://github.com/harekrishnarai/xz-utils-vuln-checker | POC Details |
| 13 | K8S and Docker Vulnerability Check for CVE-2024-3094 | https://github.com/teyhouse/CVE-2024-3094 | POC Details |
| 14 | This project contains a shell script designed to help users identify and fix installations of xz-utils affected by the CVE-2024-3094 vulnerability. Versions 5.6.0 and 5.6.1 of xz-utils are known to be vulnerable, and this script aids in detecting them and optionally downgrading to a stable, un-compromised version (5.4.6). | https://github.com/alokemajumder/CVE-2024-3094-Vulnerability-Checker-Fixer | POC Details |
| 15 | None | https://github.com/Horizon-Software-Development/CVE-2024-3094 | POC Details |
| 16 | None | https://github.com/hazemkya/CVE-2024-3094-checker | POC Details |
| 17 | An ssh honeypot with the XZ backdoor. CVE-2024-3094 | https://github.com/lockness-Ko/xz-vulnerable-honeypot | POC Details |
| 18 | None | https://github.com/brinhosa/CVE-2024-3094-One-Liner | POC Details |
| 19 | CVE-2024-3094 | https://github.com/isuruwa/CVE-2024-3094 | POC Details |
| 20 | None | https://github.com/k4t3pr0/Check-CVE-2024-3094 | POC Details |
| 21 | A script to detect if xz is vulnerable - CVE-2024-3094 | https://github.com/Yuma-Tsushima07/CVE-2024-3094 | POC Details |
| 22 | None | https://github.com/jfrog/cve-2024-3094-tools | POC Details |
| 23 | None | https://github.com/krascovict/OSINT---CVE-2024-3094- | POC Details |
| 24 | Ansible playbook for patching CVE-2024-3094 | https://github.com/Simplifi-ED/CVE-2024-3094-patcher | POC Details |
| 25 | None | https://github.com/gayatriracha/CVE-2024-3094-Nmap-NSE-script | POC Details |
| 26 | None | https://github.com/Mustafa1986/CVE-2024-3094 | POC Details |
| 27 | XZ-Utils工具库恶意后门植入漏洞(CVE-2024-3094) | https://github.com/MrBUGLF/XZ-Utils_CVE-2024-3094 | POC Details |
| 28 | None | https://github.com/galacticquest/cve-2024-3094-detect | POC Details |
| 29 | None | https://github.com/zgimszhd61/cve-2024-3094-detect-tool | POC Details |
| 30 | None | https://github.com/mightysai1997/CVE-2024-3094-info | POC Details |
No comments yet