liblzma
CompromisedThe open-source application xz
was recently discovered to have been compromised by a backdoor in its liblzma
library which potentially allows attackers to take control of a system. The exploit, which affects versions 5.6.0 and 5.6.1 of xz
, appears to target only certain Linux distros.
The MacOS build of osabe v0.10.0 is packaged with a version of the liblzma
library, but the version of xz
this was taken from is 5.4.5, so installs of osabe should be unaffected by this exploit.
Windows builds do not use this library so are unaffected.
I will continue to keep an eye on this and will update this notice if anything changes.