{"id":102953,"date":"2022-01-13T15:37:33","date_gmt":"2022-01-13T13:37:33","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/%d1%83%d1%8f%d0%b7%d0%b2%d0%b8%d0%bc%d0%be%d1%81%d1%82%d0%b8-%d0%b2-systemd-flatpak-samba-freerdp-clamav-node-js"},"modified":"2022-01-13T15:37:33","modified_gmt":"2022-01-13T13:37:33","slug":"uyazvimosti-v-systemd-flatpak-samba-freerdp-clamav-node-js","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimosti-v-systemd-flatpak-samba-freerdp-clamav-node-js","title":{"rendered":"\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432  systemd, Flatpak, Samba, FreeRDP, Clamav, Node.js","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>A vulnerability (CVE-2021-3997) has been identified in the systemd utility systemd-tmpfiles, allowing for uncontrolled recursion. This issue can be exploited to perform a denial of service during system boot by creating a large number of nested subdirectories in the \/tmp directory. A fix is currently available in the form of a patch. Package updates addressing the issue have been proposed in Ubuntu and SUSE, but are not yet available in Debian, RHEL, and Fedora (fixes are in testing).     <\/p>\n<p>When creating thousands of nested directories, executing the operation &#171;systemd-tmpfiles &#8212;remove&#187; results in a crash due to stack exhaustion. Typically, the systemd-tmpfiles utility performs removal and creation operations in a single call (&#171;systemd-tmpfiles &#8212;create &#8212;remove &#8212;boot &#8212;exclude-prefix=\\\/dev&#187;), first removing and then creating; thus, a crash at the removal stage will lead to important operational files, as specified in \\\/usr\\\/lib\\\/tmpfiles.d\\\/*.conf, not being created.      <\/p>\n<p>A more dangerous attack scenario on Ubuntu 21.04 is also mentioned: due to the crash of systemd-tmpfiles, the file \/run\/lock\/subsys is not created, and the \/run\/lock directory is writable by all users. An attacker can create a \/run\/lock\/subsys directory under their identifier and, by creating symbolic links that intersect with lock files from system processes, orchestrate the overwriting of system files.     <\/p>\n<p>Additionally, new releases of the Flatpak, Samba, FreeRDP, Clamav, and Node.js projects have been published, addressing vulnerabilities:    <\/p>\n<ul>\n<li class=\"l\"> In the corrective releases of the self-contained package building tool Flatpak 1.10.6 and 1.12.3, two vulnerabilities have been addressed: The first vulnerability (CVE-2021-43860) allows the concealment of certain extended permissions during the installation process when loading a package from an unverified repository through metadata manipulation. The second vulnerability (without a CVE) enables the creation of directories in the filesystem area outside the build directory when building a package using the command &#171;flatpak-builder &#8212;mirror-screenshots-url&#187;.\n<li class=\"l\">The Samba 4.13.16 update resolves a vulnerability (CVE-2021-43566) that allows a client to exploit symbolic links on SMB1 or NFS partitions to achieve the creation of <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/en\/server\/dts-newyork\/\"   title=\"server\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"2695\">server<\/a> The catalog beyond the exported area of the filesystem (the issue is caused by a race condition and is difficult to exploit in practice, though theoretically possible). The problem affects versions prior to 4.13.16.\n<p>A report has also been published regarding another similar vulnerability (CVE-2021-20316), which allows an authenticated client to read or modify the contents of a file or metadata in the filesystem area through manipulation of symbolic links. <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/en\/server\/dts-los-angeles\/\"   title=\"server\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"3788\">server<\/a> outside the exported section. The issue has been addressed in release 4.15.0, but it also affects previous branches. However, no fixes for older branches will be published since the old Samba VFS architecture does not allow the problem to be resolved due to the binding of metadata operations to file paths (in Samba 4.15, the VFS layer was completely redone). The danger of the problem is mitigated by the fact that it is quite complex to exploit, and user permissions must allow reading or writing to the target file or directory.      <\/p>\n<li class=\"l\"> In the FreeRDP 2.5 project release, which offers a free implementation of the Remote Desktop Protocol (RDP), three security issues have been addressed (CVE identifiers have not been assigned), which may lead to buffer overflow when using an incorrect locale, handling specially crafted registry parameters, and specifying incorrectly formatted extension names. Notable changes in the new version include support for OpenSSL 3.0, implementation of the TcpConnectTimeout setting, improved compatibility with LibreSSL, and resolution of clipboard issues in Wayland-based environments.\n<li class=\"l\"> In the recent releases of the free antivirus package ClamAV 0.103.5 and 0.104.2, the CVE-2022-20698 vulnerability, related to improper pointer reading, has been resolved, which could remotely cause the process to crash if the package is compiled with the libjson-c library and the CL_SCAN_GENERAL_COLLECT_METADATA option is enabled (clamscan &#8212;gen-json).\n<li class=\"l\"> The updates for Node.js versions 16.13.2, 14.18.3, 17.3.1, and 12.22.9 address four vulnerabilities: bypassing certificate checks when verifying network connections due to improper conversion of SAN (Subject Alternative Names) to string format (CVE-2021-44532); improper handling of multiple values in the subject and issuer fields that can be exploited to bypass checks on these fields in certificates (CVE-2021-44533); bypassing restrictions related to SAN-URI type in certificates (CVE-2021-44531); and insufficient input validation in the console.table() function, which could be used to assign empty strings to numeric keys (CVE-2022-21824).          <\/ul>\n<p>Source: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=56498\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412\u043e \u0432\u0445\u043e\u0434\u044f\u0449\u0435\u0439 \u0432 \u0441\u043e\u0441\u0442\u0430\u0432 systemd \u0443\u0442\u0438\u043b\u0438\u0442\u0435 systemd-tmpfiles \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2021-3997), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0432\u044b\u0437\u0432\u0430\u0442\u044c \u043d\u0435\u043a\u043e\u043d\u0442\u0440\u043e\u043b\u0438\u0440\u0443\u0435\u043c\u0443\u044e \u0440\u0435\u043a\u0443\u0440\u0441\u0438\u044e. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0443 \u043c\u043e\u0436\u043d\u043e \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c \u0434\u043b\u044f \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u0438 \u043e\u0442\u043a\u0430\u0437\u0430 \u0432 \u043e\u0431\u0441\u043b\u0443\u0436\u0438\u0432\u0430\u043d\u0438\u0438 \u0432\u043e \u0432\u0440\u0435\u043c\u044f \u0437\u0430\u0433\u0440\u0443\u0437\u043a\u0438 \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u0447\u0435\u0440\u0435\u0437 \u0441\u043e\u0437\u0434\u0430\u043d\u0438\u0435 \u0432 \u043a\u0430\u0442\u0430\u043b\u043e\u0433\u0435 \/tmp \u0431\u043e\u043b\u044c\u0448\u043e\u0433\u043e \u0447\u0438\u0441\u043b\u0430 \u0432\u043b\u043e\u0436\u0435\u043d\u043d\u044b\u0445 \u043f\u043e\u0434\u043a\u0430\u0442\u0430\u043b\u043e\u0433\u043e\u0432. \u0418\u0441\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u0435 \u043f\u043e\u043a\u0430 \u0434\u043e\u0441\u0442\u0443\u043f\u043d\u043e \u0432 \u0444\u043e\u0440\u043c\u0435 \u043f\u0430\u0442\u0447\u0430. \u041e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u044f \u043f\u0430\u043a\u0435\u0442\u043e\u0432 \u0441 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u0435\u043c \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u044b \u043f\u0440\u0435\u0434\u043b\u043e\u0436\u0435\u043d\u044b \u0432 Ubuntu \u0438 SUSE, \u043d\u043e \u043f\u043e\u043a\u0430 \u043d\u0435\u0434\u043e\u0441\u0442\u0443\u043f\u043d\u044b \u0432 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-102953","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412\u043e \u0432\u0445\u043e\u0434\u044f\u0449\u0435\u0439 \u0432 \u0441\u043e\u0441\u0442\u0430\u0432 systemd \u0443\u0442\u0438\u043b\u0438\u0442\u0435 systemd-tmpfiles \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2021-3997), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0432\u044b\u0437\u0432\u0430\u0442\u044c \u043d\u0435\u043a\u043e\u043d\u0442\u0440\u043e\u043b\u0438\u0440\u0443\u0435\u043c\u0443\u044e \u0440\u0435\u043a\u0443\u0440\u0441\u0438\u044e.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimosti-v-systemd-flatpak-samba-freerdp-clamav-node-js\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 systemd, Flatpak, Samba, FreeRDP, Clamav, Node.js | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412\u043e \u0432\u0445\u043e\u0434\u044f\u0449\u0435\u0439 \u0432 \u0441\u043e\u0441\u0442\u0430\u0432 systemd \u0443\u0442\u0438\u043b\u0438\u0442\u0435 systemd-tmpfiles \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2021-3997), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0432\u044b\u0437\u0432\u0430\u0442\u044c \u043d\u0435\u043a\u043e\u043d\u0442\u0440\u043e\u043b\u0438\u0440\u0443\u0435\u043c\u0443\u044e \u0440\u0435\u043a\u0443\u0440\u0441\u0438\u044e.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimosti-v-systemd-flatpak-samba-freerdp-clamav-node-js\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2022-01-13T13:37:33+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2022-01-13T13:37:33+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vulnerabilities in systemd, Flatpak, Samba, FreeRDP, Clamav, Node.js | ProHoster","description":"A vulnerability has been found in the systemd utility systemd-tmpfiles (CVE-2021-3997) that allows for uncontrolled recursion.","canonical_url":"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimosti-v-systemd-flatpak-samba-freerdp-clamav-node-js","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 systemd, Flatpak, Samba, FreeRDP, Clamav, Node.js | ProHoster","og:description":"\u0412\u043e \u0432\u0445\u043e\u0434\u044f\u0449\u0435\u0439 \u0432 \u0441\u043e\u0441\u0442\u0430\u0432 systemd \u0443\u0442\u0438\u043b\u0438\u0442\u0435 systemd-tmpfiles \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2021-3997), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0432\u044b\u0437\u0432\u0430\u0442\u044c \u043d\u0435\u043a\u043e\u043d\u0442\u0440\u043e\u043b\u0438\u0440\u0443\u0435\u043c\u0443\u044e \u0440\u0435\u043a\u0443\u0440\u0441\u0438\u044e.","og:url":"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimosti-v-systemd-flatpak-samba-freerdp-clamav-node-js","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2022-01-13T13:37:33+00:00","article:modified_time":"2022-01-13T13:37:33+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"102953","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2022-01-13 13:38:58","updated":"2026-02-22 15:30:39","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/102953","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=102953"}],"version-history":[{"count":2,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/102953\/revisions"}],"predecessor-version":[{"id":162316,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/102953\/revisions\/162316"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=102953"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=102953"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=102953"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}