Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security warning: xz-utils had a supply chain attack, please check if/how your app is affected #1425

Open
porg opened this issue Mar 31, 2024 · 2 comments

Comments

@porg
Copy link

porg commented Mar 31, 2024

I wanted to inform you asap as my favorite compression utility about this recent supply chain attack on xz:
https://en.wikipedia.org/wiki/XZ_Utils#Supply_chain_attack

  • I'm not sure whether you integrate xz or its library or make calls to the system wide installed library
  • Better inform than not to inform.

Regards, porg

@porg porg added the bug label Mar 31, 2024
@aonez
Copy link
Owner

aonez commented Mar 31, 2024

Thanks a lot for the info @porg! Keka currently is using 5.4.5 xz and liblzma versions, so it should not be affected. I’ll wait to update the version until this is fixed, hopefully very soon.

Anyway no system resources use the bundled liblzma in Keka, that is also sandboxed without network capabilities. Let’s see how this evolves.

@aonez aonez added xz CVE and removed bug labels Apr 1, 2024
@aonez aonez added this to the Look at milestone Apr 1, 2024
@aonez aonez modified the milestones: Look at, macOS-1.4.0 Jun 11, 2024
@aonez
Copy link
Owner

aonez commented Jun 11, 2024

Will be updating to the latest v5.6.2 in the next revision. Glad the issue did not escalated further.

@aonez aonez added the fixed label Jun 11, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants