{"id":41415,"date":"2020-02-10T20:42:08","date_gmt":"2020-02-10T17:42:08","guid":{"rendered":"https:\/\/prohoster.info\/blog\/blog_prohoster\/uyazvimost-v-android-pozvolyayushhaya-udalyonno-vypolnit-kod-pri-vklyuchyonnom-bluetooth"},"modified":"2020-02-10T20:42:08","modified_gmt":"2020-02-10T17:42:08","slug":"uyazvimost-v-android-pozvolyayushhaya-udalyonno-vypolnit-kod-pri-vklyuchyonnom-bluetooth","status":"publish","type":"post","link":"https:\/\/prohoster.info\/de\/blog\/uyazvimost-v-android-pozvolyayushhaya-udalyonno-vypolnit-kod-pri-vklyuchyonnom-bluetooth","title":{"rendered":"Sicherheitsanf\u00e4lligkeit in Android, die das Ausf\u00fchren von Code aus der Ferne bei aktiviertem Bluetooth erm\u00f6glicht","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Im Februar <noindex><a rel=\"nofollow\" href=\"https:\/\/source.android.com\/security\/bulletin\/2020-02-01.html\">Update<\/a><\/noindex> wurde eine kritische Sicherheitsanf\u00e4lligkeit in der Android-Plattform behoben <noindex><a rel=\"nofollow\" href=\"https:\/\/insinuator.net\/2020\/02\/critical-bluetooth-vulnerability-in-android-cve-2020-0022\/\">eine Schwachstelle<\/a><\/noindex> (CVE-2020-0022) im Bluetooth-Stack, die es erm\u00f6glicht, durch das Senden eines speziell gestalteten Bluetooth-Pakets Code remote auszuf\u00fchren. Das Problem k\u00f6nnte unbemerkt von einem Angreifer ausgenutzt werden, der sich in Reichweite von Bluetooth befindet. Es besteht die M\u00f6glichkeit, dass die Schwachstelle zur Erstellung von W\u00fcrmern verwendet werden kann, die benachbarte Ger\u00e4te infizieren. <\/p>\n<p>F\u00fcr einen Angriff reicht es aus, die MAC-Adresse des Zielger\u00e4ts zu kennen (eine vorherige Kopplung ist nicht erforderlich, aber Bluetooth muss auf dem Ger\u00e4t aktiviert sein). Bei einigen Ger\u00e4ten kann die Bluetooth-MAC-Adresse basierend auf der MAC-Adresse des Wi-Fi berechnet werden. Bei erfolgreicher Ausnutzung der Schwachstelle kann der Angreifer seinen Code mit den Rechten eines Hintergrundprozesses ausf\u00fchren, der die Bluetooth-Arbeit in Android koordiniert.<br \/>\nDas Problem ist spezifisch f\u00fcr den in Android verwendeten Bluetooth-Stack <noindex><a rel=\"nofollow\" href=\"https:\/\/android.googlesource.com\/platform\/system\/bt\/\">Fluoride<\/a><\/noindex> (basierend auf dem Code des BlueDroid-Projekts von Broadcom) und tritt nicht im in Linux verwendeten BlueZ-Stack auf.<\/p>\n<p>Die Forscher, die das Problem entdeckt haben, konnten einen funktionsf\u00e4higen Exploit-Prototyp erstellen, aber die Details der Ausnutzung werden <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/ernw\">sp\u00e4ter<\/a><\/noindex> ver\u00f6ffentlicht, nachdem der Fix an die breite Nutzerschaft verteilt wurde. Bekannt ist nur, dass die Schwachstelle im Code der Paketgliederung und in <noindex><a rel=\"nofollow\" href=\"https:\/\/android.googlesource.com\/platform\/system\/bt\/+\/3cb7149d8fed2d7d77ceaa95bf845224c4db3baf\">wird verursacht<\/a><\/noindex> der fehlerhaften Berechnung der Paketgr\u00f6\u00dfen von L2CAP (Logical Link Control and Adaptation Protocol) besteht, wenn die vom Sender \u00fcbermittelten Daten die erwartete Gr\u00f6\u00dfe \u00fcberschreiten.<\/p>\n<p>In Android 8 and 9, the issue can lead to code execution, but in Android 10, it is limited to crashing the Bluetooth background process. Older versions of Android may also be affected, but the ability to exploit the vulnerability has not been tested. Users are advised to install the firmware update as soon as possible, and if that is not feasible \u2014 to turn off Bluetooth by default, disable device discovery, and activate Bluetooth in public places only when absolutely necessary (including replacing wireless headphones with wired ones).  <\/p>\n<p>Neben dem genannten Problem wurden im <noindex><a rel=\"nofollow\" href=\"https:\/\/source.android.com\/security\/bulletin\/2020-02-01.html\">dem Februar-<\/a><\/noindex> Sicherheitsupdate-Paket f\u00fcr Android 26 Schwachstellen behoben, von denen eine weitere Schwachstelle (CVE-2020-0023) als kritisch eingestuft wurde. Die zweite Schwachstelle ist ebenfalls <noindex><a rel=\"nofollow\" href=\"https:\/\/android.googlesource.com\/platform\/packages\/apps\/Bluetooth\/+\/0d8307f408f166862fbd6efb593c4d65906a46ae\">betroffen<\/a><\/noindex> Der Bluetooth-Stack ist mit einer fehlerhaften Verarbeitung der Berechtigung BLUETOOTH_PRIVILEGED in setPhonebookAccessPermission verbunden. Was die als gef\u00e4hrlich gekennzeichneten Schwachstellen betrifft, so wurden 7 Probleme in Frameworks und Anwendungen behoben, 4 in Systemkomponenten, 2 im Kernel und 10 in offenen und propriet\u00e4ren Komponenten f\u00fcr Qualcomm-Chips.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Quelle: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=52330\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u0444\u0435\u0432\u0440\u0430\u043b\u044c\u0441\u043a\u043e\u043c \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u0438 \u043f\u043b\u0430\u0442\u0444\u043e\u0440\u043c\u044b Android \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0430 \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0430\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2020-0022) \u0432 Bluetooth-\u0441\u0442\u0435\u043a\u0435, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u043e\u0432\u0430\u0442\u044c \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e\u0435 \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0435 \u043a\u043e\u0434\u0430 \u0447\u0435\u0440\u0435\u0437 \u043e\u0442\u043f\u0440\u0430\u0432\u043a\u0443 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043e\u0444\u043e\u0440\u043c\u043b\u0435\u043d\u043d\u043e\u0433\u043e Bluetooth-\u043f\u0430\u043a\u0435\u0442\u0430. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u043c\u043e\u0436\u0435\u0442 \u0431\u044b\u0442\u044c \u043d\u0435\u0437\u0430\u043c\u0435\u0442\u043d\u043e \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0438\u0440\u043e\u0432\u0430\u043d\u0430 \u0430\u0442\u0430\u043a\u0443\u044e\u0449\u0438\u043c, \u043d\u0430\u0445\u043e\u0434\u044f\u0449\u0438\u043c\u0441\u044f \u0432 \u043f\u0440\u0435\u0434\u0435\u043b\u0430\u0445 \u0434\u043e\u0441\u044f\u0433\u0430\u0435\u043c\u043e\u0441\u0442\u0438 Bluetooth. \u041d\u0435 \u0438\u0441\u043a\u043b\u044e\u0447\u0435\u043d\u043e \u0437\u0430\u0434\u0435\u0439\u0441\u0442\u0432\u043e\u0432\u0430\u043d\u0438\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0434\u043b\u044f \u0441\u043e\u0437\u0434\u0430\u043d\u0438\u044f \u0447\u0435\u0440\u0432\u0435\u0439, \u043f\u043e \u0446\u0435\u043f\u043e\u0447\u043a\u0435 \u043f\u043e\u0440\u0430\u0436\u0430\u044e\u0449\u0438\u0445 \u0441\u043e\u0441\u0435\u0434\u043d\u0438\u0435 \u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432\u0430. \u0414\u043b\u044f \u0430\u0442\u0430\u043a\u0438 \u0434\u043e\u0441\u0442\u0430\u0442\u043e\u0447\u043d\u043e \u0437\u043d\u0430\u0442\u044c MAC-\u0430\u0434\u0440\u0435\u0441 \u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432\u0430 \u0436\u0435\u0440\u0442\u0432\u044b (\u043f\u0440\u0435\u0434\u0432\u0430\u0440\u0438\u0442\u0435\u043b\u044c\u043d\u043e\u0433\u043e \u0441\u043e\u043f\u0440\u044f\u0436\u0435\u043d\u0438\u044f \u043d\u0435 \u0442\u0440\u0435\u0431\u0443\u0435\u0442\u0441\u044f, [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[],"tags":[],"class_list":["post-41415","post","type-post","status-publish","format-standard","hentry"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u0444\u0435\u0432\u0440\u0430\u043b\u044c\u0441\u043a\u043e\u043c \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u0438 \u043f\u043b\u0430\u0442\u0444\u043e\u0440\u043c\u044b Android \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0430 \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0430\u044f\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/de\/blog\/uyazvimost-v-android-pozvolyayushhaya-udalyonno-vypolnit-kod-pri-vklyuchyonnom-bluetooth\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"de_DE\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 Android, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u043f\u0440\u0438 \u0432\u043a\u043b\u044e\u0447\u0451\u043d\u043d\u043e\u043c Bluetooth | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u0444\u0435\u0432\u0440\u0430\u043b\u044c\u0441\u043a\u043e\u043c \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u0438 \u043f\u043b\u0430\u0442\u0444\u043e\u0440\u043c\u044b Android \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0430 \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0430\u044f\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/de\/blog\/uyazvimost-v-android-pozvolyayushhaya-udalyonno-vypolnit-kod-pri-vklyuchyonnom-bluetooth\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-02-10T17:42:08+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-02-10T17:42:08+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Schwachstelle in Android, die eine Remote-Codeausf\u00fchrung bei aktiviertem Bluetooth erm\u00f6glicht | ProHoster","description":"Im Februar-Update der Android-Plattform wurde eine kritische Schwachstelle behoben.","canonical_url":"https:\/\/prohoster.info\/de\/blog\/uyazvimost-v-android-pozvolyayushhaya-udalyonno-vypolnit-kod-pri-vklyuchyonnom-bluetooth","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"de_DE","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 Android, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u043f\u0440\u0438 \u0432\u043a\u043b\u044e\u0447\u0451\u043d\u043d\u043e\u043c Bluetooth | ProHoster","og:description":"\u0412 \u0444\u0435\u0432\u0440\u0430\u043b\u044c\u0441\u043a\u043e\u043c \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u0438 \u043f\u043b\u0430\u0442\u0444\u043e\u0440\u043c\u044b Android \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0430 \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0430\u044f","og:url":"https:\/\/prohoster.info\/de\/blog\/uyazvimost-v-android-pozvolyayushhaya-udalyonno-vypolnit-kod-pri-vklyuchyonnom-bluetooth","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-02-10T17:42:08+00:00","article:modified_time":"2020-02-10T17:42:08+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"41415","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 13:26:29","updated":"2022-09-29 21:00:24","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/41415","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/comments?post=41415"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/41415\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/media?parent=41415"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/categories?post=41415"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/tags?post=41415"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}