{"id":90288,"date":"2020-07-30T13:42:19","date_gmt":"2020-07-30T11:42:19","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/kriticheskaya-uyazvimost-v-zagruzchike-grub2-pozvolyayushhaya-obojti-uefi-secure-boot"},"modified":"2020-07-30T13:42:19","modified_gmt":"2020-07-30T11:42:19","slug":"kriticheskaya-uyazvimost-v-zagruzchike-grub2-pozvolyayushhaya-obojti-uefi-secure-boot","status":"publish","type":"post","link":"https:\/\/prohoster.info\/de\/blog\/novosti-interneta\/kriticheskaya-uyazvimost-v-zagruzchike-grub2-pozvolyayushhaya-obojti-uefi-secure-boot","title":{"rendered":"Kritische Schwachstelle im GRUB2-Bootloader, die UEFI Secure Boot umgehen kann","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Im GRUB2-Bootloader <noindex><a rel=\"nofollow\" href=\"https:\/\/www.openwall.com\/lists\/oss-security\/2020\/07\/29\/3\">35 Schwachstellen identifiziert, auf deren Grundlage mehrere Angriffsszenarien entwickelt wurden, die es erm\u00f6glichen, AES-Schl\u00fcssel aus der Enklave zu extrahieren oder die Ausf\u00fchrung eigenen Codes durch das Schaffen von Bedingungen f\u00fcr die Besch\u00e4digung des Speicherinhalts zu organisieren.<\/a><\/noindex> 8 Schwachstellen. Die gef\u00e4hrlichste <noindex><a rel=\"nofollow\" href=\"https:\/\/kb.cert.org\/vuls\/id\/174059\">ein Problem<\/a><\/noindex> (<noindex><a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2020-10713\">CVE-2020-10713<\/a><\/noindex>), die den Codenamen BootHole tr\u00e4gt, <noindex><a rel=\"nofollow\" href=\"https:\/\/eclypsium.com\/2020\/07\/29\/theres-a-hole-in-the-boot\/\">erm\u00f6glicht es,<\/a><\/noindex> den UEFI Secure Boot-Mechanismus zu umgehen und nicht verifiziertes Malware zu installieren. Ein besonderes Merkmal dieser Schwachstelle ist, dass ein einfaches Update von GRUB2 nicht ausreicht, da ein Angreifer ein bootf\u00e4higes Medium mit einer alten, verwundbaren Version verwenden kann, die durch eine digitale Signatur verifiziert wurde. Der Angreifer kann den Verifizierungsprozess nicht nur von Linux, sondern auch von anderen Betriebssystemen kompromittieren, einschlie\u00dflich <noindex><a rel=\"nofollow\" href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/ADV200011\">Windows<\/a><\/noindex>. <\/p>\n<p>Das Problem kann nur durch ein Update des <noindex><a rel=\"nofollow\" href=\"https:\/\/uefi.org\/revocationlistfile\">Widerrufslisten<\/a><\/noindex> (dbx, UEFI Widerrufsliste) gel\u00f6st werden, aber in diesem Fall wird die M\u00f6glichkeit zur Verwendung \u00e4lterer Installationsmedien mit Linux verloren gehen. Einige Hardwarehersteller haben bereits aktualisierte Widerrufslisten in ihre Firmware integriert; auf solchen Systemen wird im UEFI Secure Boot-Modus nur der Zugang zu aktualisierten Versionen von Linux-Distributionen m\u00f6glich sein. <\/p>\n<p>Um die Sicherheitsanf\u00e4lligkeit in den Distributionen zu beheben, m\u00fcssen auch die Installer, Bootloader, Kernel-Pakete, fwupd-Firmware und die shim-Schicht aktualisiert werden, wobei neue digitale Signaturen erstellt werden. Nutzer m\u00fcssen die Installationsabbilder und andere bootf\u00e4hige Medien aktualisieren und die Liste der widerrufenen Zertifikate (dbx) in die UEFI-Firmware laden. Bis dbx in der UEFI aktualisiert wird, bleibt das System anf\u00e4llig, unabh\u00e4ngig von installierten Updates im Betriebssystem. <\/p>\n<p>Sicherheitsanf\u00e4lligkeit <noindex><a rel=\"nofollow\" href=\"https:\/\/access.redhat.com\/security\/vulnerabilities\/grub2bootloader\">durch<\/a><\/noindex> einem Puffer\u00fcberlauf, der ausgenutzt werden kann, um beliebigen Code im Bootprozess auszuf\u00fchren.<br \/>\nDie Anf\u00e4lligkeit tritt beim Parsen des Inhalts der Konfigurationsdatei grub.cfg auf, die normalerweise im ESP (EFI System Partition) abgelegt ist und von einem Angreifer mit Administratorrechten bearbeitet werden kann, ohne die Integrit\u00e4t der signierten ausf\u00fchrbaren Dateien von shim und GRUB2 zu beeintr\u00e4chtigen. Aufgrund von <noindex><a rel=\"nofollow\" href=\"https:\/\/lists.gnu.org\/archive\/html\/grub-devel\/2020-07\/msg00019.html\">Fehlers<\/a><\/noindex> Im Code des Konfigurationsparsers gab der Handler f\u00fcr fatale Parsierungsfehler YY_FATAL_ERROR lediglich eine Warnung aus und beendete das Programm nicht. Das Risiko der Verwundbarkeit wird durch die Notwendigkeit eines privilegierten Zugangs zum System gemindert. Dennoch k\u00f6nnte das Problem f\u00fcr die Implementierung versteckter Rootkits relevant werden, falls physischer Zugang zur Hardware besteht (insbesondere wenn das Booten von einem eigenen Tr\u00e4ger m\u00f6glich ist).<\/p>\n<p>In den meisten Linux-Distributionen wird zur verifizierten Boot-Prozess eine kleine <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=36077\">shim-Schicht<\/a><\/noindex>, die digital von Microsoft signiert ist, verwendet. Diese Schicht verifiziert GRUB2 mit ihrem eigenen Zertifikat, was es den Entwicklern der Distributionen erm\u00f6glicht, nicht jedes Kernel- oder GRUB-Update bei Microsoft zu signieren. Die Verwundbarkeit erlaubt es, durch \u00c4nderung des Inhalts von grub.cfg eigenen Code nach erfolgreicher Verifizierung des Shim auszuf\u00fchren, jedoch vor dem Booten des Betriebssystems. Dadurch wird in die Vertrauenskette eingegriffen, w\u00e4hrend der Secure Boot aktiv ist, und vollst\u00e4ndige Kontrolle \u00fcber den weiteren Bootprozess erlangt, einschlie\u00dflich des Bootens eines anderen Betriebssystems, der Modifikation von Betriebssystemkomponenten und der Umgehung von Schutzma\u00dfnahmen. <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51591\">Lockdown.<\/a><\/noindex>. <\/p>\n<p><center><noindex><a rel=\"nofollow\" href=\"https:\/\/lh6.googleusercontent.com\/EWWksJQKlwJyur1cBV5lCanfbF5m36DxRDQs8Ax6K9jn0Au5yWdmK5tQAtULQm-qQw9zOafCD1Pvny5vMJWdbhTr4FV9Qlnk_FQpXI6GbeiuKOjJ5uFMy9pnasLRsfR-Ll58p2Gr\"><img decoding=\"async\" alt=\"Kritische Schwachstelle im GRUB2-Bootloader, die UEFI Secure Boot umgehen kann\" src=\"\/wp-content\/uploads\/2020\/07\/d8def940f6d08206bdf1261d57288fba.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/center><\/p>\n<p>Weitere Schwachstellen in GRUB2:<\/p>\n<ul>\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2020-14308\">CVE-2020-14308<\/a><\/noindex> &#8212; Buffer\u00fcberlauf aufgrund fehlender \u00dcberpr\u00fcfung der Gr\u00f6\u00dfe des zugewiesenen Speicherbereichs in grub_malloc;\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2020-14309\">CVE-2020-14309<\/a><\/noindex> &#8212; Ganzzahl\u00fcberlauf in grub_squash_read_symlink, der dazu f\u00fchren kann, dass Daten au\u00dferhalb des zugewiesenen Puffers geschrieben werden;\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2020-14310\">CVE-2020-14310<\/a><\/noindex> &#8212; Ganzzahl\u00fcberlauf in read_section_from_string, der dazu f\u00fchren kann, dass Daten au\u00dferhalb des zugewiesenen Puffers geschrieben werden;\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2020-14311\">CVE-2020-14311<\/a><\/noindex> &#8212; Ganzzahl\u00fcberlauf in grub_ext2_read_link, der dazu f\u00fchren kann, dass Daten au\u00dferhalb des zugewiesenen Puffers geschrieben werden;\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2020-15705\">CVE-2020-15705<\/a><\/noindex> &#8212; Erm\u00f6glicht das Laden von unsignierten Kernen beim direkten Booten im Secure-Boot-Modus ohne shim-Schicht;\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2020-15706\">CVE-2020-15706<\/a><\/noindex> &#8212; Zugriff auf bereits freigegebenen Speicherbereich (use-after-free) bei der \u00dcberschreibung einer Funktion zur Laufzeit;\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2020-15707\">CVE-2020-15707<\/a><\/noindex> &#8212; Ganzzahl\u00fcberlauf im Handler f\u00fcr die Gr\u00f6\u00dfe von initrd.\n<\/ul>\n<p>Paketupdates mit Fixes wurden ver\u00f6ffentlicht f\u00fcr <noindex><a rel=\"nofollow\" href=\"https:\/\/www.debian.org\/security\/2020-GRUB-UEFI-SecureBoot\/#package_updates\">Debian<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/ubuntu.com\/\/blog\/mitigating-boothole-theres-a-hole-in-the-boot-cve-2020-10713-and-related-vulnerabilities\">Ubuntu<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/access.redhat.com\/security\/cve\/cve-2020-10713\">RHEL<\/a><\/noindex> und <noindex><a rel=\"nofollow\" href=\"https:\/\/www.suse.com\/c\/suse-addresses-grub2-secure-boot-issue\/\">SUSE<\/a><\/noindex>. F\u00fcr GRUB2 <noindex><a rel=\"nofollow\" href=\"https:\/\/lists.gnu.org\/archive\/html\/grub-devel\/2020-07\/msg00034.html\">wurde angeboten<\/a><\/noindex> Patch-Satz.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Quelle: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=53454\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u0437\u0430\u0433\u0440\u0443\u0437\u0447\u0438\u043a\u0435 GRUB2 \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e 8 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439. \u041d\u0430\u0438\u0431\u043e\u043b\u0435\u0435 \u043e\u043f\u0430\u0441\u043d\u0430\u044f \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 (CVE-2020-10713), \u043a\u043e\u0442\u043e\u0440\u043e\u0439 \u043f\u0440\u0438\u0441\u0432\u043e\u0435\u043d\u043e \u043a\u043e\u0434\u043e\u0432\u043e\u0435 \u0438\u043c\u044f BootHole, \u0434\u0430\u0451\u0442 \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u044c \u043e\u0431\u043e\u0439\u0442\u0438 \u043c\u0435\u0445\u0430\u043d\u0438\u0437\u043c UEFI Secure Boot \u0438 \u0434\u043e\u0431\u0438\u0442\u044c\u0441\u044f \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0438 \u043d\u0435\u0432\u0435\u0440\u0438\u0444\u0438\u0446\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u0433\u043e \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u0433\u043e \u041f\u041e. \u041e\u0441\u043e\u0431\u0435\u043d\u043d\u043e\u0441\u0442\u044c\u044e \u0434\u0430\u043d\u043d\u043e\u0439 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u0442\u043e, \u0447\u0442\u043e \u0434\u043b\u044f \u0435\u0451 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u044f \u043d\u0435 \u0434\u043e\u0441\u0442\u0430\u0442\u043e\u0447\u043d\u043e \u043e\u0431\u043d\u043e\u0432\u0438\u0442\u044c GRUB2, \u0442\u0430\u043a \u043a\u0430\u043a \u0430\u0442\u0430\u043a\u0443\u044e\u0449\u0438\u0439 \u043c\u043e\u0436\u0435\u0442 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c \u0437\u0430\u0433\u0440\u0443\u0437\u043e\u0447\u043d\u044b\u0439 \u043d\u043e\u0441\u0438\u0442\u0435\u043b\u044c \u0441\u043e \u0441\u0442\u0430\u0440\u043e\u0439 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0439 \u0432\u0435\u0440\u0441\u0438\u0435\u0439, \u0437\u0430\u0432\u0435\u0440\u0435\u043d\u043d\u043e\u0439 \u0446\u0438\u0444\u0440\u043e\u0432\u043e\u0439 \u043f\u043e\u0434\u043f\u0438\u0441\u044c\u044e. [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":90289,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-90288","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-novosti-interneta"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 4.9.10 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u0437\u0430\u0433\u0440\u0443\u0437\u0447\u0438\u043a\u0435 GRUB2 \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e 8 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439. \u041d\u0430\u0438\u0431\u043e\u043b\u0435\u0435 \u043e\u043f\u0430\u0441\u043d\u0430\u044f \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 (CVE-2020-10713), \u043a\u043e\u0442\u043e\u0440\u043e\u0439 \u043f\u0440\u0438\u0441\u0432\u043e\u0435\u043d\u043e \u043a\u043e\u0434\u043e\u0432\u043e\u0435 \u0438\u043c\u044f BootHole, \u0434\u0430\u0451\u0442 \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u044c \u043e\u0431\u043e\u0439\u0442\u0438 \u043c\u0435\u0445\u0430\u043d\u0438\u0437\u043c UEFI Secure Boot \u0438 \u0434\u043e\u0431\u0438\u0442\u044c\u0441\u044f \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0438 \u043d\u0435\u0432\u0435\u0440\u0438\u0444\u0438\u0446\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u0433\u043e \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u0433\u043e \u041f\u041e. \u041e\u0441\u043e\u0431\u0435\u043d\u043d\u043e\u0441\u0442\u044c\u044e \u0434\u0430\u043d\u043d\u043e\u0439 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u0442\u043e, \u0447\u0442\u043e \u0434\u043b\u044f \u0435\u0451 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u044f \u043d\u0435 \u0434\u043e\u0441\u0442\u0430\u0442\u043e\u0447\u043d\u043e \u043e\u0431\u043d\u043e\u0432\u0438\u0442\u044c GRUB2, \u0442\u0430\u043a \u043a\u0430\u043a \u0430\u0442\u0430\u043a\u0443\u044e\u0449\u0438\u0439 \u043c\u043e\u0436\u0435\u0442 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c \u0437\u0430\u0433\u0440\u0443\u0437\u043e\u0447\u043d\u044b\u0439 \u043d\u043e\u0441\u0438\u0442\u0435\u043b\u044c \u0441\u043e \u0441\u0442\u0430\u0440\u043e\u0439 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0439 \u0432\u0435\u0440\u0441\u0438\u0435\u0439, \u0437\u0430\u0432\u0435\u0440\u0435\u043d\u043d\u043e\u0439 \u0446\u0438\u0444\u0440\u043e\u0432\u043e\u0439 \u043f\u043e\u0434\u043f\u0438\u0441\u044c\u044e.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/de\/blog\/novosti-interneta\/kriticheskaya-uyazvimost-v-zagruzchike-grub2-pozvolyayushhaya-obojti-uefi-secure-boot\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 4.9.10\" \/>\n\t\t<meta property=\"og:locale\" content=\"de_DE\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0430\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 \u0437\u0430\u0433\u0440\u0443\u0437\u0447\u0438\u043a\u0435 GRUB2, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043e\u0431\u043e\u0439\u0442\u0438 UEFI Secure Boot | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u0437\u0430\u0433\u0440\u0443\u0437\u0447\u0438\u043a\u0435 GRUB2 \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e 8 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439. \u041d\u0430\u0438\u0431\u043e\u043b\u0435\u0435 \u043e\u043f\u0430\u0441\u043d\u0430\u044f \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 (CVE-2020-10713), \u043a\u043e\u0442\u043e\u0440\u043e\u0439 \u043f\u0440\u0438\u0441\u0432\u043e\u0435\u043d\u043e \u043a\u043e\u0434\u043e\u0432\u043e\u0435 \u0438\u043c\u044f BootHole, \u0434\u0430\u0451\u0442 \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u044c \u043e\u0431\u043e\u0439\u0442\u0438 \u043c\u0435\u0445\u0430\u043d\u0438\u0437\u043c UEFI Secure Boot \u0438 \u0434\u043e\u0431\u0438\u0442\u044c\u0441\u044f \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0438 \u043d\u0435\u0432\u0435\u0440\u0438\u0444\u0438\u0446\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u0433\u043e \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u0433\u043e \u041f\u041e. \u041e\u0441\u043e\u0431\u0435\u043d\u043d\u043e\u0441\u0442\u044c\u044e \u0434\u0430\u043d\u043d\u043e\u0439 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u0442\u043e, \u0447\u0442\u043e \u0434\u043b\u044f \u0435\u0451 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u044f \u043d\u0435 \u0434\u043e\u0441\u0442\u0430\u0442\u043e\u0447\u043d\u043e \u043e\u0431\u043d\u043e\u0432\u0438\u0442\u044c GRUB2, \u0442\u0430\u043a \u043a\u0430\u043a \u0430\u0442\u0430\u043a\u0443\u044e\u0449\u0438\u0439 \u043c\u043e\u0436\u0435\u0442 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c \u0437\u0430\u0433\u0440\u0443\u0437\u043e\u0447\u043d\u044b\u0439 \u043d\u043e\u0441\u0438\u0442\u0435\u043b\u044c \u0441\u043e \u0441\u0442\u0430\u0440\u043e\u0439 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0439 \u0432\u0435\u0440\u0441\u0438\u0435\u0439, \u0437\u0430\u0432\u0435\u0440\u0435\u043d\u043d\u043e\u0439 \u0446\u0438\u0444\u0440\u043e\u0432\u043e\u0439 \u043f\u043e\u0434\u043f\u0438\u0441\u044c\u044e.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/de\/blog\/novosti-interneta\/kriticheskaya-uyazvimost-v-zagruzchike-grub2-pozvolyayushhaya-obojti-uefi-secure-boot\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-07-30T11:42:19+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-07-30T11:42:19+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47 Kritische Schwachstelle im GRUB2-Bootloader, die das Umgehen von UEFI Secure Boot erm\u00f6glicht | ProHoster","description":"Im GRUB2-Bootloader wurden 8 Schwachstellen festgestellt. Das gef\u00e4hrlichste Problem (CVE-2020-10713), auch bekannt als BootHole, erm\u00f6glicht das Umgehen des UEFI Secure Boot-Mechanismus und die Installation von nicht verifiziertem Schadcode. Ein besonderes Merkmal dieser Schwachstelle ist, dass es nicht ausreicht, GRUB2 zu aktualisieren, da Angreifer ein startf\u00e4higes Medium mit einer alten, anf\u00e4lligen Version verwenden k\u00f6nnten, die durch eine digitale Signatur beglaubigt ist.","canonical_url":"https:\/\/prohoster.info\/de\/blog\/novosti-interneta\/kriticheskaya-uyazvimost-v-zagruzchike-grub2-pozvolyayushhaya-obojti-uefi-secure-boot","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"de_DE","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0430\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 \u0437\u0430\u0433\u0440\u0443\u0437\u0447\u0438\u043a\u0435 GRUB2, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043e\u0431\u043e\u0439\u0442\u0438 UEFI Secure Boot | ProHoster","og:description":"\u0412 \u0437\u0430\u0433\u0440\u0443\u0437\u0447\u0438\u043a\u0435 GRUB2 \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e 8 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439. \u041d\u0430\u0438\u0431\u043e\u043b\u0435\u0435 \u043e\u043f\u0430\u0441\u043d\u0430\u044f \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 (CVE-2020-10713), \u043a\u043e\u0442\u043e\u0440\u043e\u0439 \u043f\u0440\u0438\u0441\u0432\u043e\u0435\u043d\u043e \u043a\u043e\u0434\u043e\u0432\u043e\u0435 \u0438\u043c\u044f BootHole, \u0434\u0430\u0451\u0442 \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u044c \u043e\u0431\u043e\u0439\u0442\u0438 \u043c\u0435\u0445\u0430\u043d\u0438\u0437\u043c UEFI Secure Boot \u0438 \u0434\u043e\u0431\u0438\u0442\u044c\u0441\u044f \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0438 \u043d\u0435\u0432\u0435\u0440\u0438\u0444\u0438\u0446\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u0433\u043e \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u0433\u043e \u041f\u041e. \u041e\u0441\u043e\u0431\u0435\u043d\u043d\u043e\u0441\u0442\u044c\u044e \u0434\u0430\u043d\u043d\u043e\u0439 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u0442\u043e, \u0447\u0442\u043e \u0434\u043b\u044f \u0435\u0451 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u044f \u043d\u0435 \u0434\u043e\u0441\u0442\u0430\u0442\u043e\u0447\u043d\u043e \u043e\u0431\u043d\u043e\u0432\u0438\u0442\u044c GRUB2, \u0442\u0430\u043a \u043a\u0430\u043a \u0430\u0442\u0430\u043a\u0443\u044e\u0449\u0438\u0439 \u043c\u043e\u0436\u0435\u0442 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c \u0437\u0430\u0433\u0440\u0443\u0437\u043e\u0447\u043d\u044b\u0439 \u043d\u043e\u0441\u0438\u0442\u0435\u043b\u044c \u0441\u043e \u0441\u0442\u0430\u0440\u043e\u0439 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0439 \u0432\u0435\u0440\u0441\u0438\u0435\u0439, \u0437\u0430\u0432\u0435\u0440\u0435\u043d\u043d\u043e\u0439 \u0446\u0438\u0444\u0440\u043e\u0432\u043e\u0439 \u043f\u043e\u0434\u043f\u0438\u0441\u044c\u044e.","og:url":"https:\/\/prohoster.info\/de\/blog\/novosti-interneta\/kriticheskaya-uyazvimost-v-zagruzchike-grub2-pozvolyayushhaya-obojti-uefi-secure-boot","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-07-30T11:42:19+00:00","article:modified_time":"2020-07-30T11:42:19+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"90288","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 12:54:27","updated":"2022-09-27 23:35:06"},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/90288","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/comments?post=90288"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/90288\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/media\/90289"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/media?parent=90288"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/categories?post=90288"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/tags?post=90288"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}