Xterm'i haavatavus, mis võimaldab koodi täitmist teatud ridade töötlemisel

Xterm terminal emulator has a vulnerability (CVE-2022-45063) that allows for the execution of shell commands when processing certain escape sequences in the terminal. For the attack, it is sufficient to display the contents of a specially formatted file on the screen, for example, using the cat utility, or to paste a line from the clipboard. printf "\e]50;i\$(touch /tmp/hack-like-its-1999)\a\e]50;?\a" > cve-2022-45063 cat cve-2022-45063

The issue is caused by an error in processing the escape sequence with code 50, used to set or get font parameters. If the requested font does not exist, the operation returns the font name specified in the request. Control characters cannot be directly inserted into the name, but the returned string may be terminated by a sequence "^G", which in zsh, when line editing mode in vi style is active, leads to the execution of the list expansion operation, which can be used to run commands without explicitly pressing the Enter key.

Turvaliseks haavatavuse kasutamiseks peab kasutaja kasutama Zsh käsureade, mis on seadistatud 'vi' režiimiks (vi-cmd-mode), mida vaikimisi ei kasutata distributsioonides. Probleem ei ilmne ka siis, kui xterm'i seaded on seatud allowWindowOps=false või allowFontOps=false. Näiteks seadistatakse allowFontOps=false OpenBSD, Debian ja RHEL'is, kuid Arch Linux'is ei rakendata seda vaikimisi.

Muudatuste loendi ja probleemile viitava teadlase avalduse kohaselt on haavatavus kõrvaldatud xterm versioonis 375, kuid teiste andmete kohaselt jätkab haavatavus xterm 375 Arch Linux'i versioonis esinemist. Paranduste avaldamise jälgimiseks distributsioonide kaudu võib vaadata järgmisi lehti: Debian, RHEL, Fedora, SUSE, Ubuntu, Arch Linux, OpenBSD, FreeBSD, NetBSD.

Allikas: opennet.ru

Osta usaldusväärne veebihosting DDoS kaitsega, VPS VDS serverid 🔥 Osta usaldusväärne veebihosting DDoS kaitsega, VPS VDS serverid | ProHoster