Get Mystery Box with random crypto!

The xz package, starting from version 5.6.0 to 5.6.1, was foun | Kali Linux

The xz package, starting from version 5.6.0 to 5.6.1, was found to contain a backdoor. The impact of this vulnerability affected Kali between March 26th to March 29th. If you updated your Kali installation on or after March 26th, it is crucial to apply the latest updates today.

This backdoor could potentially allow a malicious actor to compromise sshd authentication. If you did not update your Kali installation before the 26th, you are not affected by this backdoor vulnerability.

More information can be found at:

https://www.helpnetsecurity.com/2024/03/29/cve-2024-3094-linux-backdoor/

And

https://www.openwall.com/lists/oss-security/2024/03/29/4

If you would like to be sure that you are up to date and not affected by this vulnerability, you can do the following to upgrade your local version of the package:
sudo apt update && sudo apt install —only-upgrade liblzma5

Full blog post:
https://www.kali.org/blog/about-the-xz-backdoor/

@kalilinux