• kaleissin@sopuli.xyz
    link
    fedilink
    arrow-up
    33
    arrow-down
    34
    ·
    3 months ago

    Bad title. This is CVE-2024-3094. Run “xz --version” to see if you are affected.

    • ryannathans
      link
      fedilink
      arrow-up
      83
      arrow-down
      1
      ·
      3 months ago

      “Run the affected binary to see if you have it”

    • 1henno1@feddit.de
      link
      fedilink
      arrow-up
      64
      ·
      3 months ago

      AFAIK it‘s better to use rpm -q xz xz-libs (copied from the forum replies) to avoid running xz itself just in case the affected version is already installed

    • ara@lemmy.ml
      link
      fedilink
      arrow-up
      55
      ·
      3 months ago

      If you go to the post, on the comments, there is someone that is already telling you to run dnf list xz --installed. So you don’t need to run xz directly.

    • bitwolf@lemmy.one
      link
      fedilink
      arrow-up
      2
      ·
      3 months ago

      If you are checking out the extent of damage on your system do not use ldd to check the links.

      You can inadvertently executed the exploit this way.