Vulnerability Bulletins

CVE-2024-3094


System information

   
Affected software AmazonWS

Description

Publication Date: 2024/03/29 12:30 PM PST CVE Identifier: CVE-2024-3094 AWS is aware of CVE-2024-3094, which affects versions 5.6.0 and 5.6.1 of the xz-utils package. This issue may attempt to introduce security issues in openssh through the use of liblzma within some operating system environments. Amazon Linux customers are not affected by this issue, and no action is required. AWS infrastructure and services do not utilize the affected software and are not impacted. Users of Bottlerocket are

More info:

https://aws.amazon.com/security/security-bulletins/AWS-2024-002/

Standar resources

Property Value
CVE CVE-2024-3094.

Version history

Version Comments Date
Ministerio de Defensa
CNI
CCN
CCN-CERT