{"id":116883,"date":"2024-07-01T18:05:44","date_gmt":"2024-07-01T16:05:44","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimost-v-openssh-pozvolyayushhaya-udalyonno-vypolnit-kod-s-pravami-root-na-serverah-s-glibc"},"modified":"2024-07-01T18:05:44","modified_gmt":"2024-07-01T16:05:44","slug":"uyazvimost-v-openssh-pozvolyayushhaya-udalyonno-vypolnit-kod-s-pravami-root-na-serverah-s-glibc","status":"publish","type":"post","link":"https:\/\/prohoster.info\/de\/blog\/news\/uyazvimost-v-openssh-pozvolyayushhaya-udalyonno-vypolnit-kod-s-pravami-root-na-serverah-s-glibc","title":{"rendered":"Eine Schwachstelle in OpenSSH erm\u00f6glicht die Ausf\u00fchrung von Code mit Root-Rechten auf Servern mit Glibc.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Das Unternehmen Qualys hat eine kritische Sicherheitsanf\u00e4lligkeit (CVE-2024-6387) in OpenSSH aufgedeckt, die eine Remote-Codeausf\u00fchrung mit Root-Rechten ohne Authentifizierung erm\u00f6glicht. Die Schwachstelle, die den Codenamen regreSSHion tr\u00e4gt, tritt in der Standardkonfiguration ab Version OpenSSH 8.5 auf Systemen mit der Standardbibliothek Glibc auf. <\/p>\n<p>Die M\u00f6glichkeit, einen Angriff durchzuf\u00fchren, wurde auf einem 32-Bit-System mit Glibc und aktivem ASLR-Schutz (Address Space Layout Randomization) demonstriert. F\u00fcr einen erfolgreichen Angriff im Laborumfeld waren 6-8 Stunden erforderlich, in denen <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/de\/server\/dts-prohoster\/\"   title=\"Server\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"3083\">Server<\/a> st\u00e4ndig Verbindungen mit der maximal zul\u00e4ssigen Intensit\u00e4t gem\u00e4\u00df der sshd-Konfiguration hergestellt wurden. Die Durchf\u00fchrung eines Angriffs wird auf Systemen ohne ASLR oder in Distributionen, die eine modifizierte Version von OpenSSH verwenden, bei der die erneute ASLR-Randomisierung f\u00fcr jede Verbindung deaktiviert ist, erleichtert und ben\u00f6tigt weniger Zeit. Ein funktionierender Exploit-Prototyp wird nicht \u00f6ffentlich ver\u00f6ffentlicht, bis die Schwachstelle umfassend beseitigt wurde, jedoch ist eine ausreichend detaillierte Beschreibung der Schwachstelle verf\u00fcgbar, die das Auftauchen von Drittanbieter-Exploits nur noch eine Frage der Zeit ist.<\/p>\n<p>Ein Angriff auf 64-Bit-Systeme ist ebenfalls m\u00f6glich, aber ein funktionierender Exploit f\u00fcr solche Systeme steht derzeit noch nicht zur Verf\u00fcgung. Es wird angenommen, dass die Durchf\u00fchrung eines Angriffs auf 64-Bit-Systeme wesentlich mehr Zeit in Anspruch nehmen wird, aber nicht l\u00e4nger als eine Woche. OpenSSH in OpenBSD ist nicht betroffen, da in diesem System seit 2001 ein Schutzmechanismus eingesetzt wird, der solche Angriffe blockiert. In anderen Systemen, die auf anderen Standardbibliotheken als Glibc basieren, k\u00f6nnte die Methode theoretisch angepasst werden, um einen Angriff durchzuf\u00fchren (dieses Thema wurde bei Qualys bisher nicht untersucht). <\/p>\n<p>Die Schwachstelle wurde in der heute ver\u00f6ffentlichten Version von OpenSSH 9.8 (Patch) behoben. Die Aktualisierungen der Pakete in den Distributionen k\u00f6nnen auf den folgenden Seiten verfolgt werden: Debian, Ubuntu, RHEL, SUSE\/openSUSE, Fedora, ROSA, Gentoo, ALT Linux, Arch und FreeBSD. Als Umgehungsl\u00f6sung zur Blockierung der Schwachstelle kann im sshd_config-Parameter \u201eLoginGraceTime=0\u201c eingestellt werden, wobei das Deaktivieren des Timeouts das Initiieren eines Denial-of-Service-Angriffs bei einer gro\u00dfen Anzahl von Verbindungen, die die \u00fcber den Parameter MaxStartups festgelegten Grenzen \u00fcberschreiten, erleichtert.<br \/>\nEin Anzeichen f\u00fcr den Versuch eines Angriffs ist das Auftreten einer gro\u00dfen Anzahl von Eintr\u00e4gen im Protokoll \u201eTimeout before authentication\u201c.<\/p>\n<p>Die Schwachstelle entstand durch eine regressiven \u00c4nderung, die in die Version OpenSSH 8.5 aufgenommen wurde und zu einem Race Condition im Code der Signalverarbeitung in sshd f\u00fchrt. Die Regression f\u00fchrte dazu, dass der Schutz gegen die alte Schwachstelle CVE-2006-5051, die bis zur Version OpenSSH 4.4 (2006) auftrat und theoretischer Natur war, nicht mehr wirksam war.<br \/>\nW\u00e4hrend der Entwicklung von OpenSSH 8.5 wurde versehentlich der Block \u201e#ifdef DO_LOG_SAFE_IN_SIGHAND\u201c aus der Funktion sigdie() entfernt, die direkt vom SIGALRM-Handler aufgerufen wird.<\/p>\n<p>Der SIGALRM-Handler wird im sshd asynchron aufgerufen, wenn der Client die Authentifizierung innerhalb der durch den Verbindungszeit\u00fcberschreitung (LoginGraceTime, standardm\u00e4\u00dfig 120 Sek.) festgelegten Zeit nicht durchgef\u00fchrt hat. Der Angriff basiert darauf, dass der Signalhandler Funktionen aufruft, die bei der asynchronen Signalverarbeitung unsicher sind, wie syslog(). Die Funktion syslog() in Glibc ist nicht f\u00fcr die Verwendung in asynchron ausgef\u00fchrten Signalhandlern vorgesehen, da sie Funktionen wie malloc() und free() aufruft. Das Ausl\u00f6sen des SIGALRM-Signals, das die Ausf\u00fchrung bestimmter Codes in sshd unterbricht, kann zu einer Beeintr\u00e4chtigung des Ausf\u00fchrungszustands f\u00fchren, und das Ziel des Exploits besteht darin, Bedingungen zu schaffen, um den gew\u00fcnschten Code zum richtigen Zeitpunkt seiner Ausf\u00fchrung zu unterbrechen. Die Schwachstelle betrifft OpenBSD nicht, da anstelle von syslog() aus dem SIGALRM-Signalhandler die Funktion syslog_r() aufgerufen wird, die speziell f\u00fcr den asynchronen Betrieb entwickelt wurde.<br \/>\n<br \/>Quelle: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=61470\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f Qualys \u0432\u044b\u044f\u0432\u0438\u043b\u0430 \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0443\u044e \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2024-6387) \u0432 OpenSSH, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0443\u044e \u0434\u043e\u0431\u0438\u0442\u044c\u0441\u044f \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e\u0433\u043e \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u043a\u043e\u0434\u0430 \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 root \u0431\u0435\u0437 \u043f\u0440\u043e\u0445\u043e\u0436\u0434\u0435\u043d\u0438\u044f \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u043f\u043e\u043b\u0443\u0447\u0438\u043b\u0430 \u043a\u043e\u0434\u043e\u0432\u043e\u0435 \u0438\u043c\u044f regreSSHion, \u043f\u0440\u043e\u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u0432 \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u0438 \u043f\u043e \u0443\u043c\u043e\u043b\u0447\u0430\u043d\u0438\u044e \u043d\u0430\u0447\u0438\u043d\u0430\u044f \u0441 \u0432\u0435\u0440\u0441\u0438\u0438 OpenSSH 8.5 \u043d\u0430 \u0441\u0438\u0441\u0442\u0435\u043c\u0430\u0445 \u0441\u043e \u0441\u0442\u0430\u043d\u0434\u0430\u0440\u0442\u043d\u043e\u0439 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u043e\u0439 Glibc. \u0412\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u044c \u0441\u043e\u0432\u0435\u0440\u0448\u0435\u043d\u0438\u044f \u0430\u0442\u0430\u043a\u0438 \u043f\u0440\u043e\u0434\u0435\u043c\u043e\u043d\u0441\u0442\u0440\u0438\u0440\u043e\u0432\u0430\u043d\u0430 \u043d\u0430 32-\u0440\u0430\u0437\u0440\u044f\u0434\u043d\u043e\u0439 \u0441\u0438\u0441\u0442\u0435\u043c\u0435 \u0441 Glibc \u0441 \u0432\u043a\u043b\u044e\u0447\u0451\u043d\u043d\u043e\u0439 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 ASLR (\u0440\u0430\u043d\u0434\u043e\u043c\u0438\u0437\u0430\u0446\u0438\u044f [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-116883","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f Qualys \u0432\u044b\u044f\u0432\u0438\u043b\u0430 \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0443\u044e \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2024-6387) \u0432 OpenSSH, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0443\u044e \u0434\u043e\u0431\u0438\u0442\u044c\u0441\u044f \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e\u0433\u043e \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u043a\u043e\u0434\u0430 \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 root \u0431\u0435\u0437 \u043f\u0440\u043e\u0445\u043e\u0436\u0434\u0435\u043d\u0438\u044f \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/de\/blog\/news\/uyazvimost-v-openssh-pozvolyayushhaya-udalyonno-vypolnit-kod-s-pravami-root-na-serverah-s-glibc\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"de_DE\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 OpenSSH, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 root \u043d\u0430 \u0441\u0435\u0440\u0432\u0435\u0440\u0430\u0445 \u0441 Glibc | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f Qualys \u0432\u044b\u044f\u0432\u0438\u043b\u0430 \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0443\u044e \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2024-6387) \u0432 OpenSSH, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0443\u044e \u0434\u043e\u0431\u0438\u0442\u044c\u0441\u044f \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e\u0433\u043e \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u043a\u043e\u0434\u0430 \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 root \u0431\u0435\u0437 \u043f\u0440\u043e\u0445\u043e\u0436\u0434\u0435\u043d\u0438\u044f \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/de\/blog\/news\/uyazvimost-v-openssh-pozvolyayushhaya-udalyonno-vypolnit-kod-s-pravami-root-na-serverah-s-glibc\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2024-07-01T16:05:44+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2024-07-01T16:05:44+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Eine Schwachstelle in OpenSSH, die es erm\u00f6glicht, Root-Code auf Servern mit Glibc aus der Ferne auszuf\u00fchren | ProHoster","description":"Das Unternehmen Qualys hat eine kritische Schwachstelle (CVE-2024-6387) in OpenSSH identifiziert, die es erm\u00f6glicht, Root-Code ausf\u00fchrend ohne Authentifizierung aus der Ferne auszuf\u00fchren.","canonical_url":"https:\/\/prohoster.info\/de\/blog\/news\/uyazvimost-v-openssh-pozvolyayushhaya-udalyonno-vypolnit-kod-s-pravami-root-na-serverah-s-glibc","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"de_DE","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 OpenSSH, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 root \u043d\u0430 \u0441\u0435\u0440\u0432\u0435\u0440\u0430\u0445 \u0441 Glibc | ProHoster","og:description":"\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f Qualys \u0432\u044b\u044f\u0432\u0438\u043b\u0430 \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0443\u044e \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2024-6387) \u0432 OpenSSH, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0443\u044e \u0434\u043e\u0431\u0438\u0442\u044c\u0441\u044f \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e\u0433\u043e \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u043a\u043e\u0434\u0430 \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 root \u0431\u0435\u0437 \u043f\u0440\u043e\u0445\u043e\u0436\u0434\u0435\u043d\u0438\u044f \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438.","og:url":"https:\/\/prohoster.info\/de\/blog\/news\/uyazvimost-v-openssh-pozvolyayushhaya-udalyonno-vypolnit-kod-s-pravami-root-na-serverah-s-glibc","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2024-07-01T16:05:44+00:00","article:modified_time":"2024-07-01T16:05:44+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"116883","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-02-09 21:59:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2026-01-23 03:18:19","updated":"2026-02-09 21:59:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/116883","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/comments?post=116883"}],"version-history":[{"count":1,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/116883\/revisions"}],"predecessor-version":[{"id":160364,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/116883\/revisions\/160364"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/media?parent=116883"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/categories?post=116883"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/tags?post=116883"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}