olegos2 / mobox

2.5k stars 109 forks source link

xz-utils 5.6.0 is backdoored #347

Open NotNite opened 3 months ago

NotNite commented 3 months ago

In use in the components folder. See https://en.wikipedia.org/wiki/XZ_Utils_backdoor.

lvonasek commented 3 months ago

@olegos2, could you prioritize this? It is the vulnerability where hacker could take control over the device: https://github.com/advisories/GHSA-rxwq-x6h5-x525

Added by: https://github.com/olegos2/mobox/commit/9a13f53dd9dd14925c53de67310e25fb45516a29

olegos2 commented 3 months ago

It's not used by the mobox, I will just delete these pkgs from components