Project

General

Profile

Actions

Bug #376

closed

Assess whether CVE-2024-3094 liblzma backdoor affects distributed binaries

Added by Alina Lenk 10 months ago. Updated 3 months ago.

Status:
Closed
Priority:
High
Category:
-
Target version:
-
Start date:
03/29/2024
Due date:
% Done:

0%

Estimated time:

Description

https://nvd.nist.gov/vuln/detail/CVE-2024-3094
Malicious code was discovered in the upstream tarballs of xz/liblzma, starting with version 5.6.0. (released Feb 24th, i.e. before Freeciv 3.1.0). The compromised maintainer has been making commits since early 2023 at least, so even older versions might already contain backdoors. We should assess whether compromised versions might have been linked into distributed Freeciv binaries, and what to do about it.

Actions

Also available in: Atom PDF