{"id":105776,"date":"2022-12-01T15:37:11","date_gmt":"2022-12-01T13:37:11","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/udalyonno-ekspluatiruemaya-root-uyazvimost-v-utilite-ping-postavlyaemoj-vo-freebsd"},"modified":"2022-12-01T15:37:11","modified_gmt":"2022-12-01T13:37:11","slug":"udalyonno-ekspluatiruemaya-root-uyazvimost-v-utilite-ping-postavlyaemoj-vo-freebsd","status":"publish","type":"post","link":"https:\/\/prohoster.info\/de\/blog\/news\/udalyonno-ekspluatiruemaya-root-uyazvimost-v-utilite-ping-postavlyaemoj-vo-freebsd","title":{"rendered":"Remote ausnutzbare Root-Sicherheitsl\u00fccke in der Ping-Utility, die mit FreeBSD ausgeliefert wird","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>In FreeBSD wurde eine Sicherheitsanf\u00e4lligkeit (CVE-2022-23093) in der Ping-Utility entdeckt, die Teil der Standardauslieferung ist. Das Problem k\u00f6nnte potenziell zur Remote-Ausf\u00fchrung von Code mit Root-Rechten f\u00fchren, wenn ein Ping an einen externen, vom Angreifer kontrollierten Host gesendet wird. Ein Patch wurde in den Updates FreeBSD 13.1-RELEASE-p5, 12.4-RC2-p2 und 12.3-RELEASE-p10 bereitgestellt. Ob andere BSD-Systeme von der entdeckten Anf\u00e4lligkeit betroffen sind, ist noch unklar (Berichte \u00fcber Anf\u00e4lligkeiten in NetBSD, DragonFlyBSD und OpenBSD liegen bislang nicht vor).      <\/p>\n<p>Die Sicherheitsanf\u00e4lligkeit wird durch einen Buffer Overflow im Code zur Analyse von ICMP-Nachrichten verursacht, die als Antwort auf den Ping-Anfrage kommen. Der Code f\u00fcr das Senden und Empfangen von ICMP-Nachrichten in Ping verwendet Raw-Sockets und l\u00e4uft mit erh\u00f6hten Rechten (das Utility wird mit dem Setuid-Root-Flag ausgeliefert). Die Verarbeitung der Antwort erfolgt von Ping aus, indem die IP- und ICMP-Header der Pakete, die aus dem Raw-Socket empfangen werden, rekonstruiert werden. Die extrahierten IP- und ICMP-Header werden von der Funktion pr_pack() in Puffer kopiert, ohne zu ber\u00fccksichtigen, dass im Paket nach dem IP-Header zus\u00e4tzliche erweiterte Header vorhanden sein k\u00f6nnen.     <\/p>\n<p>Solche Header werden aus dem Paket extrahiert und in den Headerblock aufgenommen, jedoch nicht bei der Berechnung der Pufferspeichergr\u00f6\u00dfe ber\u00fccksichtigt. Falls der Host als Antwort auf die gesendete ICMP-Anfrage ein Paket mit zus\u00e4tzlichen Headern zur\u00fccksendet, wird deren Inhalt in den Bereich au\u00dferhalb des Puffers im Stack geschrieben. Infolgedessen kann der Angreifer bis zu 40 Bytes Daten im Stack \u00fcberschreiben, was potenziell zur Ausf\u00fchrung eigenen Codes f\u00fchren kann. Die Gef\u00e4hrlichkeit des Problems wird durch die Tatsache gemildert, dass der Prozess zum Zeitpunkt des Auftretens des Fehlers im Zustand isolierter Systemaufrufe (Capability Mode) ist, was den Zugriff auf den Rest des Systems nach der Ausnutzung der Anf\u00e4lligkeit erschwert.<br \/>\n<br \/>Quelle: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=58232\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412\u043e FreeBSD \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2022-23093) \u0432 \u0443\u0442\u0438\u043b\u0438\u0442\u0435 ping, \u0432\u0445\u043e\u0434\u044f\u0449\u0435\u0439 \u0432 \u0431\u0430\u0437\u043e\u0432\u0443\u044e \u043f\u043e\u0441\u0442\u0430\u0432\u043a\u0443. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u043f\u043e\u0442\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043c\u043e\u0436\u0435\u0442 \u043f\u0440\u0438\u0432\u0435\u0441\u0442\u0438 \u043a \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e\u043c\u0443 \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044e \u043a\u043e\u0434\u0430 \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 root \u043f\u0440\u0438 \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0435 \u043f\u0440\u0438 \u043f\u043e\u043c\u043e\u0449\u0438 ping \u0432\u043d\u0435\u0448\u043d\u0435\u0433\u043e \u0445\u043e\u0441\u0442\u0430, \u043f\u043e\u0434\u043a\u043e\u043d\u0442\u0440\u043e\u043b\u044c\u043d\u043e\u0433\u043e \u0437\u043b\u043e\u0443\u043c\u044b\u0448\u043b\u0435\u043d\u043d\u0438\u043a\u0443. \u0418\u0441\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u0435 \u043f\u0440\u0435\u0434\u043b\u043e\u0436\u0435\u043d\u043e \u0432 \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u044f\u0445 FreeBSD 13.1-RELEASE-p5, 12.4-RC2-p2 \u0438 12.3-RELEASE-p10. \u041f\u043e\u0434\u0432\u0435\u0440\u0436\u0435\u043d\u044b \u043b\u0438 \u0434\u0440\u0443\u0433\u0438\u0435 BSD-\u0441\u0438\u0441\u0442\u0435\u043c\u044b \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043d\u043e\u0439 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u043f\u043e\u043a\u0430 \u043d\u0435 \u044f\u0441\u043d\u043e (\u043e\u0442\u0447\u0451\u0442\u043e\u0432 \u043e\u0431 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 NetBSD, [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-105776","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412\u043e FreeBSD \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2022-23093) \u0432 \u0443\u0442\u0438\u043b\u0438\u0442\u0435 ping, \u0432\u0445\u043e\u0434\u044f\u0449\u0435\u0439 \u0432 \u0431\u0430\u0437\u043e\u0432\u0443\u044e \u043f\u043e\u0441\u0442\u0430\u0432\u043a\u0443.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/de\/blog\/news\/udalyonno-ekspluatiruemaya-root-uyazvimost-v-utilite-ping-postavlyaemoj-vo-freebsd\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"de_DE\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0438\u0440\u0443\u0435\u043c\u0430\u044f root-\u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 \u0443\u0442\u0438\u043b\u0438\u0442\u0435 ping, \u043f\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u0435\u043c\u043e\u0439 \u0432\u043e FreeBSD | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412\u043e FreeBSD \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2022-23093) \u0432 \u0443\u0442\u0438\u043b\u0438\u0442\u0435 ping, \u0432\u0445\u043e\u0434\u044f\u0449\u0435\u0439 \u0432 \u0431\u0430\u0437\u043e\u0432\u0443\u044e \u043f\u043e\u0441\u0442\u0430\u0432\u043a\u0443.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/de\/blog\/news\/udalyonno-ekspluatiruemaya-root-uyazvimost-v-utilite-ping-postavlyaemoj-vo-freebsd\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2022-12-01T13:37:11+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2022-12-01T13:37:11+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Remote ausnutzbare Root-Sicherheitsl\u00fccke in der Ping-Utility, die mit FreeBSD ausgeliefert wird | ProHoster","description":"In FreeBSD wurde eine Sicherheitsanf\u00e4lligkeit (CVE-2022-23093) in der Ping-Utility entdeckt, die Teil der Standardauslieferung ist.","canonical_url":"https:\/\/prohoster.info\/de\/blog\/news\/udalyonno-ekspluatiruemaya-root-uyazvimost-v-utilite-ping-postavlyaemoj-vo-freebsd","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"de_DE","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0438\u0440\u0443\u0435\u043c\u0430\u044f root-\u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 \u0443\u0442\u0438\u043b\u0438\u0442\u0435 ping, \u043f\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u0435\u043c\u043e\u0439 \u0432\u043e FreeBSD | ProHoster","og:description":"\u0412\u043e FreeBSD \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2022-23093) \u0432 \u0443\u0442\u0438\u043b\u0438\u0442\u0435 ping, \u0432\u0445\u043e\u0434\u044f\u0449\u0435\u0439 \u0432 \u0431\u0430\u0437\u043e\u0432\u0443\u044e \u043f\u043e\u0441\u0442\u0430\u0432\u043a\u0443.","og:url":"https:\/\/prohoster.info\/de\/blog\/news\/udalyonno-ekspluatiruemaya-root-uyazvimost-v-utilite-ping-postavlyaemoj-vo-freebsd","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2022-12-01T13:37:11+00:00","article:modified_time":"2022-12-01T13:37:11+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":[],"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/105776","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/comments?post=105776"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/105776\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/media?parent=105776"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/categories?post=105776"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/tags?post=105776"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}