CVE-2024-3094#

Statement on CVE-2024-3094 Leaky Vessels Vulnerability#

April 23, 2024

Information#

Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. Through a series of complex obfuscations, the liblzma build process extracts a prebuilt object file from a disguised test file existing in the source code, which is then used to modify specific functions in the liblzma code. This results in a modified liblzma library that can be used by any software linked against this library, intercepting and modifying the data interaction with this library.

Severity#

Low

Response#

Melissa Data Corporation (“Melissa”) was not impacted by the xz-utils vulnerability as we do not utilize the affected version of liblzma for any Melissa commercial web services or products.

Melissa will continue to follow all guidance provided for this vulnerability as necessary to prevent any future risks.

If you have any additional questions, please contact Melissa’s Compliance department at Compliance@melissa.com.