{"id":108095,"date":"2023-04-26T12:48:19","date_gmt":"2023-04-26T10:48:19","guid":{"rendered":"https:\/\/prohoster.info\/?p=108095"},"modified":"2023-04-27T10:34:32","modified_gmt":"2023-04-27T08:34:32","slug":"uyazvimosti-v-git-pozvolyayushhie-perezapisat-fajly-ili-vypolnit-svoj-kod","status":"publish","type":"post","link":"https:\/\/prohoster.info\/de\/blog\/news\/uyazvimosti-v-git-pozvolyayushhie-perezapisat-fajly-ili-vypolnit-svoj-kod","title":{"rendered":"Sicherheitsl\u00fccken in Git, die das \u00dcberschreiben von Dateien oder die Ausf\u00fchrung eigenen Codes erm\u00f6glichen.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Die korrigierenden Versionen des verteilten Versionskontrollsystems Git 2.40.1, 2.39.3, 2.38.5, 2.37.7, 2.36.6, 2.35.8, 2.34.8, 2.33.8, 2.32.7, 2.31.8 und 2.30.9 wurden ver\u00f6ffentlicht, in denen f\u00fcnf Sicherheitsanf\u00e4lligkeiten behoben wurden. Die Aktualisierungen der Pakete in den Distributionen k\u00f6nnen auf den Seiten von Debian, Ubuntu, RHEL, SUSE\/openSUSE, Fedora, Arch, FreeBSD verfolgt werden. Als Umgehungsl\u00f6sungen zum Schutz vor Sicherheitsanf\u00e4lligkeiten wird empfohlen, die Ausf\u00fchrung des Befehls \u201egit apply \u2014reject\u201c beim Arbeiten mit nicht verifiziertem externen Patches zu vermeiden und den Inhalt von $GIT_DIR\/config vor der Ausf\u00fchrung der Befehle \u201egit submodule deinit\u201c, \u201egit config \u2014rename-section\u201c und \u201egit config \u2014remove-section\u201c bei der Arbeit mit unsicheren Repositories zu \u00fcberpr\u00fcfen.    <\/p>\n<p>Die Schwachstelle CVE-2023-29007 erm\u00f6glicht das Einf\u00fcgen von Einstellungen in die Konfigurationsdatei $GIT_DIR\/config, die zum Ausf\u00fchren von Code im System verwendet werden k\u00f6nnen, indem Pfade zu ausf\u00fchrbaren Dateien in den Direktiven core.pager, core.editor und core.sshCommand angegeben werden. Die Schwachstelle wird durch einen logischen Fehler verursacht, der dazu f\u00fchrt, dass sehr lange Konfigurationswerte als Beginn eines neuen Abschnitts verarbeitet werden, wenn Abschnitte im Konfigurationsfile umbenannt oder gel\u00f6scht werden. In der Praxis k\u00f6nnen die ausnutzbaren Werte durch die Angabe sehr langer URLs von Submodulen erreicht werden, die w\u00e4hrend der Initialisierung in die Datei $GIT_DIR\/config gespeichert werden. Diese URLs k\u00f6nnen als neue Einstellungen interpretiert werden, wenn versucht wird, sie \u00fcber \u201egit submodule deinit\u201c zu l\u00f6schen.      <\/p>\n<p>Die Schwachstelle CVE-2023-25652 erm\u00f6glicht es, Inhalte von Dateien au\u00dferhalb des Arbeitsverzeichnisses zu \u00fcberschreiben, wenn sie mit dem Befehl \u201egit apply \u2014reject\u201c speziell gestaltete Patches verarbeitet werden. Bei dem Versuch, mit dem Befehl \u201egit apply\u201c einen b\u00f6sartigen Patch auszuf\u00fchren, der versucht, \u00fcber symbolische Links in eine Datei zu schreiben, wird der Vorgang abgelehnt. In Git 2.39.1 wurde der Schutz vor Manipulationen \u00fcber symbolische Links um eine Sperre f\u00fcr Patches erg\u00e4nzt, die symbolische Links erstellen und versuchen, \u00fcber diese zu schreiben. Das Wesentliche an der betrachteten Schwachstelle ist, dass Git nicht ber\u00fccksichtigt hat, dass ein Benutzer den Befehl \u201egit apply \u2014reject\u201c ausf\u00fchren kann, um abgelehnte Teile des Patches als Dateien mit der Erweiterung \u201e.rej\u201c zu speichern, und ein Angreifer diese M\u00f6glichkeit nutzen kann, um Inhalte in ein beliebiges Verzeichnis zu schreiben, soweit es die aktuellen Zugriffsrechte erlauben.      <\/p>\n<p>Dar\u00fcber hinaus wurden drei Schwachstellen behoben, die nur auf der Plattform Windows auftreten: CVE-2023-29012 (Suche nach der ausf\u00fchrbaren Datei doskey.exe im Arbeitsverzeichnis des Repositories beim Ausf\u00fchren des Befehls \u201eGit CMD\u201c, was es erm\u00f6glicht, eigenen Code im System des Benutzers auszuf\u00fchren), CVE-2023-25815 (Puffer\u00fcberlauf bei der Verarbeitung speziell gestalteter Lokalisierungsdateien in gettext) und CVE-2023-29011 (M\u00f6glichkeit der Manipulation der Datei connect.exe bei der Arbeit \u00fcber SOCKS5).<br \/>\n<br \/>Quelle: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=59033\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d\u044b \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u0438\u0440\u0443\u044e\u0449\u0438\u0435 \u0432\u044b\u043f\u0443\u0441\u043a\u0438 \u0440\u0430\u0441\u043f\u0440\u0435\u0434\u0435\u043b\u0451\u043d\u043d\u043e\u0439 \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u0443\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u044f \u0438\u0441\u0445\u043e\u0434\u043d\u044b\u043c\u0438 \u0442\u0435\u043a\u0441\u0442\u0430\u043c\u0438 Git 2.40.1, 2.39.3, 2.38.5, 2.37.7, 2.36.6, 2.35.8, 2.34.8, 2.33.8, 2.32.7, 2.31.8 \u0438 2.30.9, \u0432 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u043e \u043f\u044f\u0442\u044c \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439. \u041f\u0440\u043e\u0441\u043b\u0435\u0434\u0438\u0442\u044c \u0437\u0430 \u0432\u044b\u043f\u0443\u0441\u043a\u043e\u043c \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u0439 \u043f\u0430\u043a\u0435\u0442\u043e\u0432 \u0432 \u0434\u0438\u0441\u0442\u0440\u0438\u0431\u0443\u0442\u0438\u0432\u0430\u0445 \u043c\u043e\u0436\u043d\u043e \u043d\u0430 \u0441\u0442\u0440\u0430\u043d\u0438\u0446\u0430\u0445 Debian, Ubuntu, RHEL, SUSE\/openSUSE, Fedora, Arch, FreeBSD. \u0412 \u043a\u0430\u0447\u0435\u0441\u0442\u0432\u0435 \u043e\u0431\u0445\u043e\u0434\u043d\u044b\u0445 \u043f\u0443\u0442\u0435\u0439 \u0434\u043b\u044f \u0437\u0430\u0449\u0438\u0442\u044b \u043e\u0442 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0440\u0435\u043a\u043e\u043c\u0435\u043d\u0434\u0443\u0435\u0442\u0441\u044f \u0438\u0437\u0431\u0435\u0433\u0430\u0442\u044c \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u043a\u043e\u043c\u0430\u043d\u0434\u044b [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-108095","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d\u044b \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u0438\u0440\u0443\u044e\u0449\u0438\u0435 \u0432\u044b\u043f\u0443\u0441\u043a\u0438 \u0440\u0430\u0441\u043f\u0440\u0435\u0434\u0435\u043b\u0451\u043d\u043d\u043e\u0439 \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u0443\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u044f \u0438\u0441\u0445\u043e\u0434\u043d\u044b\u043c\u0438 \u0442\u0435\u043a\u0441\u0442\u0430\u043c\u0438 Git 2.40.1, 2.39.3, 2.38.5, 2.37.7, 2.36.6, 2.35.8, 2.34.8, 2.33.8, 2.32.7, 2.31.8 \u0438 2.30.9, \u0432 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u043e \u043f\u044f\u0442\u044c.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/de\/blog\/news\/uyazvimosti-v-git-pozvolyayushhie-perezapisat-fajly-ili-vypolnit-svoj-kod\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"de_DE\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 Git, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0435 \u043f\u0435\u0440\u0435\u0437\u0430\u043f\u0438\u0441\u0430\u0442\u044c \u0444\u0430\u0439\u043b\u044b \u0438\u043b\u0438 \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u0441\u0432\u043e\u0439 \u043a\u043e\u0434 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d\u044b \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u0438\u0440\u0443\u044e\u0449\u0438\u0435 \u0432\u044b\u043f\u0443\u0441\u043a\u0438 \u0440\u0430\u0441\u043f\u0440\u0435\u0434\u0435\u043b\u0451\u043d\u043d\u043e\u0439 \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u0443\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u044f \u0438\u0441\u0445\u043e\u0434\u043d\u044b\u043c\u0438 \u0442\u0435\u043a\u0441\u0442\u0430\u043c\u0438 Git 2.40.1, 2.39.3, 2.38.5, 2.37.7, 2.36.6, 2.35.8, 2.34.8, 2.33.8, 2.32.7, 2.31.8 \u0438 2.30.9, \u0432 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u043e \u043f\u044f\u0442\u044c.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/de\/blog\/news\/uyazvimosti-v-git-pozvolyayushhie-perezapisat-fajly-ili-vypolnit-svoj-kod\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2023-04-26T10:48:19+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2023-04-27T08:34:32+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Schwachstellen in Git, die das \u00dcberschreiben von Dateien oder die Ausf\u00fchrung eigenen Codes erm\u00f6glichen | ProHoster","description":"Es wurden Korrekturversionen des verteilten Quelltextverwaltungssystems Git 2.40.1, 2.39.3, 2.38.5, 2.37.7, 2.36.6, 2.35.8, 2.34.8, 2.33.8, 2.32.7, 2.31.8 und 2.30.9 ver\u00f6ffentlicht, in denen f\u00fcnf Schwachstellen behoben wurden.","canonical_url":"https:\/\/prohoster.info\/de\/blog\/news\/uyazvimosti-v-git-pozvolyayushhie-perezapisat-fajly-ili-vypolnit-svoj-kod","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"de_DE","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 Git, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0435 \u043f\u0435\u0440\u0435\u0437\u0430\u043f\u0438\u0441\u0430\u0442\u044c \u0444\u0430\u0439\u043b\u044b \u0438\u043b\u0438 \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u0441\u0432\u043e\u0439 \u043a\u043e\u0434 | ProHoster","og:description":"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d\u044b \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u0438\u0440\u0443\u044e\u0449\u0438\u0435 \u0432\u044b\u043f\u0443\u0441\u043a\u0438 \u0440\u0430\u0441\u043f\u0440\u0435\u0434\u0435\u043b\u0451\u043d\u043d\u043e\u0439 \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u0443\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u044f \u0438\u0441\u0445\u043e\u0434\u043d\u044b\u043c\u0438 \u0442\u0435\u043a\u0441\u0442\u0430\u043c\u0438 Git 2.40.1, 2.39.3, 2.38.5, 2.37.7, 2.36.6, 2.35.8, 2.34.8, 2.33.8, 2.32.7, 2.31.8 \u0438 2.30.9, \u0432 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u043e \u043f\u044f\u0442\u044c.","og:url":"https:\/\/prohoster.info\/de\/blog\/news\/uyazvimosti-v-git-pozvolyayushhie-perezapisat-fajly-ili-vypolnit-svoj-kod","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2023-04-26T10:48:19+00:00","article:modified_time":"2023-04-27T08:34:32+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":[],"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/108095","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/comments?post=108095"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/108095\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/media?parent=108095"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/categories?post=108095"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/tags?post=108095"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}