Headline
xz/liblzma Backdoored
It has been discovered that the upstream source tarballs for xz-utils, the XZ-format compression utilities, are compromised and inject malicious code, at build time, into the resulting liblzma5 library. Included in this archive are not only the advisory but additional data and a testing script to see if you’re affected.
© 2022 Packet Storm. All rights reserved.