{"id":120285,"date":"2024-10-25T13:09:16","date_gmt":"2024-10-25T11:09:16","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimost-v-networkmanager-libreswan-i-guix-daemon-pozvolyayushhie-povysit-privilegii-v-sisteme"},"modified":"2024-10-25T13:09:16","modified_gmt":"2024-10-25T11:09:16","slug":"uyazvimost-v-networkmanager-libreswan-i-guix-daemon-pozvolyayushhie-povysit-privilegii-v-sisteme","status":"publish","type":"post","link":"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimost-v-networkmanager-libreswan-i-guix-daemon-pozvolyayushhie-povysit-privilegii-v-sisteme","title":{"rendered":"Vulnerabilidad en NetworkManager-libreswan y guix-daemon, que permite elevar privilegios en el sistema","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>En el plugin NetworkManager-libreswan, que a\u00f1ade funcionalidad al NetworkManager para conectarse a VPNs compatibles con servidores basados en Libreswan y Cisco IPsec, se ha detectado una vulnerabilidad (CVE-2024-9050) que puede ser utilizada por un usuario local para elevar sus privilegios. Esta vulnerabilidad se ha corregido en la actualizaci\u00f3n de NetworkManager-libreswan 1.2.24. Se puede seguir la aparici\u00f3n de actualizaciones en las distribuciones en las siguientes p\u00e1ginas: Debian, Ubuntu, RHEL, SUSE\/openSUSE, Fedora.       <\/p>\n<p>El problema es causado por una verificaci\u00f3n incorrecta de la configuraci\u00f3n <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/es\/vpn\/\"   title=\"VPN\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"258\">VPN<\/a>, definido por un usuario no privilegiado local y transmitido directamente a Libreswan al intentar activar la conexi\u00f3n. En particular, el complemento no realizaba la verificaci\u00f3n del uso de caracteres de escape, como el salto de l\u00ednea &#171;&#092;n&#187;, que podr\u00edan utilizarse para separar configuraciones espec\u00edficas dadas en una misma l\u00ednea.     <\/p>\n<p>Por lo tanto, el atacante pod\u00eda incluir, en uno de los par\u00e1metros permitidos, el par\u00e1metro &#171;leftupdown&#187;, prohibido para usuarios no privilegiados y que asigna un script que se ejecuta con privilegios de root durante el proceso de establecimiento de la conexi\u00f3n. Por ejemplo, para iniciar el programa \/bin\/true se pueden agregar las siguientes configuraciones al par\u00e1metro permitido &#171;hostaddrfamily&#187;: hostaddrfamily=ipv4&#092;n leftupdown=\/bin\/true&#092;n ikev2=never&#092;n leftxauthclient=yes&#092;n leftusername=username&#092;n phase2alg=aes256-sha1&#092;n authby=secret&#092;n left=faultroute&#092;n leftmodecfgclient=yes&#092;n right=172.31.79.2&#092;nconn ign          <\/p>\n<p>Otra vulnerabilidad ha sido detectada en el proceso en segundo plano guix-daemon, utilizado en distribuciones basadas en el gestor de paquetes GNU Guix. La vulnerabilidad representa un riesgo para sistemas multiusuario y permite que un usuario local obtenga privilegios de cualquier usuario que realice la construcci\u00f3n de paquetes (build user) y modifique el resultado de la construcci\u00f3n. La esencia de la vulnerabilidad es que un atacante puede iniciar una construcci\u00f3n derivada y, si el proceso de construcci\u00f3n se interrumpe, los archivos suid creados permanecen accesibles para los dem\u00e1s usuarios del sistema. Despu\u00e9s de esto, el atacante puede aprovechar el archivo suid creado para interrumpir el proceso de construcci\u00f3n, abrir cualquier archivo a trav\u00e9s de \/proc\/$PID\/fd con los derechos del usuario que est\u00e1 realizando la construcci\u00f3n y sobrescribir archivos con los resultados de la construcci\u00f3n).<br \/>\n<br \/>Fuente: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=62109\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u043f\u043b\u0430\u0433\u0438\u043d\u0435 NetworkManager-libreswan, \u0434\u043e\u0431\u0430\u0432\u043b\u044f\u044e\u0449\u0435\u043c \u0432 NetworkManager \u0444\u0443\u043d\u043a\u0446\u0438\u043e\u043d\u0430\u043b\u044c\u043d\u043e\u0441\u0442\u044c \u0434\u043b\u044f \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u044f \u043a VPN, \u0441\u043e\u0432\u043c\u0435\u0441\u0442\u0438\u043c\u044b\u043c \u0441 \u0441\u0435\u0440\u0432\u0435\u0440\u0430\u043c\u0438 \u043d\u0430 \u0431\u0430\u0437\u0435 Libreswan \u0438 Cisco IPsec, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2024-9050), \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u043c\u043e\u0436\u0435\u0442 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c\u0441\u044f \u0434\u043b\u044f \u043f\u043e\u0432\u044b\u0448\u0435\u043d\u0438\u044f \u043b\u043e\u043a\u0430\u043b\u044c\u043d\u044b\u043c \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u043c \u0441\u0432\u043e\u0438\u0445 \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0439. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0430 \u0432 \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u0438 NetworkManager-libreswan 1.2.24. \u041f\u0440\u043e\u0441\u043b\u0435\u0434\u0438\u0442\u044c \u0437\u0430 \u043f\u043e\u044f\u0432\u043b\u0435\u043d\u0438\u0435\u043c \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u0439 \u0432 \u0434\u0438\u0441\u0442\u0440\u0438\u0431\u0443\u0442\u0438\u0432\u0430\u0445 \u043c\u043e\u0436\u043d\u043e \u043d\u0430 \u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0438\u0445 \u0441\u0442\u0440\u0430\u043d\u0438\u0446\u0430\u0445: Debian, Ubuntu, RHEL, SUSE\/openSUSE, Fedora. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u0432\u044b\u0437\u0432\u0430\u043d\u0430 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-120285","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u043f\u043b\u0430\u0433\u0438\u043d\u0435 NetworkManager-libreswan, \u0434\u043e\u0431\u0430\u0432\u043b\u044f\u044e\u0449\u0435\u043c \u0432 NetworkManager \u0444\u0443\u043d\u043a\u0446\u0438\u043e\u043d\u0430\u043b\u044c\u043d\u043e\u0441\u0442\u044c \u0434\u043b\u044f \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u044f \u043a VPN, \u0441\u043e\u0432\u043c\u0435\u0441\u0442\u0438\u043c\u044b\u043c \u0441 \u0441\u0435\u0440\u0432\u0435\u0440\u0430\u043c\u0438 \u043d\u0430 \u0431\u0430\u0437\u0435 Libreswan \u0438 Cisco IPsec, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2024-9050), \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u043c\u043e\u0436\u0435\u0442.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimost-v-networkmanager-libreswan-i-guix-daemon-pozvolyayushhie-povysit-privilegii-v-sisteme\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"es_ES\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 NetworkManager-libreswan \u0438 guix-daemon, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0435 \u043f\u043e\u0432\u044b\u0441\u0438\u0442\u044c \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0438 \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u043f\u043b\u0430\u0433\u0438\u043d\u0435 NetworkManager-libreswan, \u0434\u043e\u0431\u0430\u0432\u043b\u044f\u044e\u0449\u0435\u043c \u0432 NetworkManager \u0444\u0443\u043d\u043a\u0446\u0438\u043e\u043d\u0430\u043b\u044c\u043d\u043e\u0441\u0442\u044c \u0434\u043b\u044f \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u044f \u043a VPN, \u0441\u043e\u0432\u043c\u0435\u0441\u0442\u0438\u043c\u044b\u043c \u0441 \u0441\u0435\u0440\u0432\u0435\u0440\u0430\u043c\u0438 \u043d\u0430 \u0431\u0430\u0437\u0435 Libreswan \u0438 Cisco IPsec, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2024-9050), \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u043c\u043e\u0436\u0435\u0442.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimost-v-networkmanager-libreswan-i-guix-daemon-pozvolyayushhie-povysit-privilegii-v-sisteme\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2024-10-25T11:09:16+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2024-10-25T11:09:16+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vulnerabilidad en NetworkManager-libreswan y guix-daemon que permite aumentar los privilegios en el sistema | ProHoster","description":"Se ha detectado una vulnerabilidad (CVE-2024-9050) en el plugin NetworkManager-libreswan, que a\u00f1ade a NetworkManager la funcionalidad para conectarse a VPN compatibles con servidores basados en Libreswan y Cisco IPsec.","canonical_url":"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimost-v-networkmanager-libreswan-i-guix-daemon-pozvolyayushhie-povysit-privilegii-v-sisteme","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"es_ES","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 NetworkManager-libreswan \u0438 guix-daemon, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0435 \u043f\u043e\u0432\u044b\u0441\u0438\u0442\u044c \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0438 \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435 | ProHoster","og:description":"\u0412 \u043f\u043b\u0430\u0433\u0438\u043d\u0435 NetworkManager-libreswan, \u0434\u043e\u0431\u0430\u0432\u043b\u044f\u044e\u0449\u0435\u043c \u0432 NetworkManager \u0444\u0443\u043d\u043a\u0446\u0438\u043e\u043d\u0430\u043b\u044c\u043d\u043e\u0441\u0442\u044c \u0434\u043b\u044f \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u044f \u043a VPN, \u0441\u043e\u0432\u043c\u0435\u0441\u0442\u0438\u043c\u044b\u043c \u0441 \u0441\u0435\u0440\u0432\u0435\u0440\u0430\u043c\u0438 \u043d\u0430 \u0431\u0430\u0437\u0435 Libreswan \u0438 Cisco IPsec, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2024-9050), \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u043c\u043e\u0436\u0435\u0442.","og:url":"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimost-v-networkmanager-libreswan-i-guix-daemon-pozvolyayushhie-povysit-privilegii-v-sisteme","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2024-10-25T11:09:16+00:00","article:modified_time":"2024-10-25T11:09:16+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"120285","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-02-04 15:02:21","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2026-01-23 07:28:20","updated":"2026-02-04 15:02:21","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/120285","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/comments?post=120285"}],"version-history":[{"count":1,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/120285\/revisions"}],"predecessor-version":[{"id":156887,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/120285\/revisions\/156887"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/media?parent=120285"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/categories?post=120285"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/tags?post=120285"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}