Skip to content

[liblzma] port uses compromised version #37839

@marekr

Description

@marekr

Describe the bug
vcpkg updated liblzma to 5.6.0. This version is known as compromised and backdoored

https://nvd.nist.gov/vuln/detail/CVE-2024-3094
https://www.redhat.com/en/blog/urgent-security-alert-fedora-41-and-rawhide-users

This is a solid 10.0 CVE score vulnerability

vcpkg should immediately revert from 5.6.0

Metadata

Metadata

Assignees

No one assigned

    Labels

    category:port-bugThe issue is with a library, which is something the port should already support

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions