Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2024-3094 PoC — Xz: malicious code in distributed source

Source
Associated Vulnerability
Title: Xz: malicious code in distributed source (CVE-2024-3094)
Description:Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. Through a series of complex obfuscations, the liblzma build process extracts a prebuilt object file from a disguised test file existing in the source code, which is then used to modify specific functions in the liblzma code. This results in a modified liblzma library that can be used by any software linked against this library, intercepting and modifying the data interaction with this library.
Description
XZ-Utils工具库恶意后门植入漏洞(CVE-2024-3094)
Readme
# 漏洞概述

XZ是一种数据压缩格式,几乎存在每个Linux发行版中。liblzma是一个处理XZ压缩格式的开源软件库。3月29日开发人员发现XZ包的供应链攻击,溯源发现SSH上游liblzma库被植入后门木马,当满足一定条件时,会解密流量里的C2命令执行。

* 漏洞编号: CVE-2024-3094
* CVSS 3.1评分:10.0
* 威胁类型:供应链攻击、后门
* POC状态:已公开
* EXP状态:已公开

# 影响版本

* xz == 5.6.0、5.6.1
* liblzma == 5.6.0、5.6.1

| OS                                   | Package name | Package version(s) | Fix package version | Reference |
| ------------------------------------ | ------------ | ------------------ | ------------------- | --------- |
| Fedora 40, Rawhide                   | xz           | 5.6.0, 5.6.1       | Revert to 5.4.x     | Details   |
| Debian unstable (Sid)                | xz-utils     | 5.6.1              | Revert to 5.4.5     | Details   |
| Alpine edge                          | xz           | 5.6.1-r2           | Revert to 5.4.x     | Details   |
| Arch Linux                           | xz           | 5.6.0-1, 5.6.1-1   | Upgrade to 5.6.1-2  | Details   |
| openSUSE Tumbleweed openSUSE MicroOS | xz           | 5.6.0              | Revert to 5.4.x     | Details   |

# 自查脚本

:bulb: [XZ-Utils-POC.sh](./XZ-Utils-POC.sh)

![image-20240401095227113](./images/image-20240401095227113.png)

# 修复建议

目前暂无最新版本,需要对XZ版本进行降级到5.4.x
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →