{"id":112924,"date":"2024-01-15T17:28:03","date_gmt":"2024-01-15T15:28:03","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimost-v-patchah-red-hat-k-zagruzchiku-grub2-pozvolyayushhaya-obojti-proverku-parolya"},"modified":"2024-01-15T17:28:03","modified_gmt":"2024-01-15T15:28:03","slug":"uyazvimost-v-patchah-red-hat-k-zagruzchiku-grub2-pozvolyayushhaya-obojti-proverku-parolya","status":"publish","type":"post","link":"https:\/\/prohoster.info\/fr\/blog\/news\/uyazvimost-v-patchah-red-hat-k-zagruzchiku-grub2-pozvolyayushhaya-obojti-proverku-parolya","title":{"rendered":"Vuln\u00e9rabilit\u00e9 dans les correctifs de Red Hat pour le chargeur GRUB2, permettant de contourner la v\u00e9rification du mot de passe","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Des informations ont \u00e9t\u00e9 r\u00e9v\u00e9l\u00e9es concernant une vuln\u00e9rabilit\u00e9 (CVE-2023-4001) dans les correctifs du chargeur GRUB2, pr\u00e9par\u00e9s par Red Hat. Cette vuln\u00e9rabilit\u00e9 permet, sur de nombreux syst\u00e8mes avec UEFI, de contourner la v\u00e9rification du mot de passe d\u00e9finie dans GRUB2 pour restreindre l'acc\u00e8s au menu de d\u00e9marrage ou \u00e0 l'invite de commande du chargeur. Elle est caus\u00e9e par une modification apport\u00e9e par Red Hat dans le paquet GRUB2 fourni dans RHEL et Fedora Linux. Ce probl\u00e8me ne se manifeste pas dans le projet principal de GRUB2 et affecte uniquement les distributions ayant appliqu\u00e9 des correctifs suppl\u00e9mentaires de Red Hat.      <\/p>\n<p>Le probl\u00e8me est caus\u00e9 par une erreur dans la logique d'utilisation de l'UUID pour rechercher le chargeur de d\u00e9marrage d'un appareil avec un fichier de configuration (par exemple, \"\/boot\/efi\/EFI\/fedora\/grub.cfg\"), contenant un hachage de mot de passe. Pour contourner l'authentification, un utilisateur ayant un acc\u00e8s physique \u00e0 l'ordinateur peut connecter un p\u00e9riph\u00e9rique externe, tel qu'une cl\u00e9 USB, en lui attribuant un UUID qui r\u00e9p\u00e8te l'identifiant de la partition de d\u00e9marrage \/boot du syst\u00e8me cibl\u00e9.       <\/p>\n<p>De nombreux syst\u00e8mes UEFI traitent d'abord les p\u00e9riph\u00e9riques externes et les placent en t\u00eate de la liste des appareils d\u00e9tect\u00e9s avant les disques durs internes, ce qui fait que la partition \/boot pr\u00e9par\u00e9e par l'attaquant sera prioritaire lors du traitement. Ainsi, GRUB2 tentera de charger le fichier de configuration depuis cette partition. Au cours de la recherche de partition utilisant la commande \"search\" dans GRUB2, seule la premi\u00e8re correspondance de l'UUID est d\u00e9termin\u00e9e, apr\u00e8s quoi la recherche s'arr\u00eate. Si le fichier de configuration principal n'est pas trouv\u00e9 dans une partition donn\u00e9e, GRUB2 affichera un invite de commande permettant un contr\u00f4le total du processus de d\u00e9marrage ult\u00e9rieur.      <\/p>\n<p>Pour d\u00e9terminer l'UUID d'une partition, un utilisateur local non privil\u00e9gi\u00e9 peut utiliser l'utilitaire \"lsblk\", mais un utilisateur externe n'ayant pas acc\u00e8s au syst\u00e8me, mais capable d'observer le processus de d\u00e9marrage, peut dans certaines distributions d\u00e9terminer l'UUID \u00e0 partir des messages de diagnostic affich\u00e9s lors du d\u00e9marrage. Cette vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 corrig\u00e9e par Red Hat en ajoutant un nouvel argument \u00e0 la commande \"search\" pour restreindre l'op\u00e9ration de scan d'UUID uniquement aux p\u00e9riph\u00e9riques de bloc utilis\u00e9s pour d\u00e9marrer le gestionnaire de d\u00e9marrage (c'est-\u00e0-dire que la partition \/boot doit \u00eatre sur le m\u00eame disque que la partition syst\u00e8me EFI).<br \/>\n<br \/>Source : <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=60439\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0420\u0430\u0441\u043a\u0440\u044b\u0442\u0430 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044f \u043e\u0431 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 (CVE-2023-4001) \u0432 \u043f\u0430\u0442\u0447\u0430\u0445 \u043a \u0437\u0430\u0433\u0440\u0443\u0437\u0447\u0438\u043a\u0443 GRUB2, \u043f\u043e\u0434\u0433\u043e\u0442\u043e\u0432\u043b\u0435\u043d\u043d\u044b\u0445 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0435\u0439 Red Hat. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u043d\u0430 \u043c\u043d\u043e\u0433\u0438\u0445 \u0441\u0438\u0441\u0442\u0435\u043c\u0430\u0445 \u0441 UEFI \u043e\u0431\u043e\u0439\u0442\u0438 \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0443 \u043f\u0430\u0440\u043e\u043b\u044f, \u0432\u044b\u0441\u0442\u0430\u0432\u043b\u0435\u043d\u043d\u043e\u0433\u043e \u0432 GRUB2 \u0434\u043b\u044f \u043e\u0433\u0440\u0430\u043d\u0438\u0447\u0435\u043d\u0438\u044f \u0434\u043e\u0441\u0442\u0443\u043f\u0430 \u043a \u0437\u0430\u0433\u0440\u0443\u0437\u043e\u0447\u043d\u043e\u043c\u0443 \u043c\u0435\u043d\u044e \u0438\u043b\u0438 \u043a\u043e\u043c\u0430\u043d\u0434\u043d\u043e\u0439 \u0441\u0442\u0440\u043e\u043a\u0435 \u0437\u0430\u0433\u0440\u0443\u0437\u0447\u0438\u043a\u0430. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432\u044b\u0437\u0432\u0430\u043d\u0430 \u0438\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u0435\u043c, \u0434\u043e\u0431\u0430\u0432\u043b\u0435\u043d\u043d\u044b\u043c \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0435\u0439 Red Hat \u0432 \u043f\u0430\u043a\u0435\u0442 \u0441 GRUB2, \u043f\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u0435\u043c\u044b\u0439 \u0432 RHEL \u0438 Fedora Linux. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-112924","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0420\u0430\u0441\u043a\u0440\u044b\u0442\u0430 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044f \u043e\u0431 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 (CVE-2023-4001) \u0432 \u043f\u0430\u0442\u0447\u0430\u0445 \u043a \u0437\u0430\u0433\u0440\u0443\u0437\u0447\u0438\u043a\u0443 GRUB2, \u043f\u043e\u0434\u0433\u043e\u0442\u043e\u0432\u043b\u0435\u043d\u043d\u044b\u0445 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0435\u0439 Red Hat.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/fr\/blog\/news\/uyazvimost-v-patchah-red-hat-k-zagruzchiku-grub2-pozvolyayushhaya-obojti-proverku-parolya\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"fr_FR\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 \u043f\u0430\u0442\u0447\u0430\u0445 Red Hat \u043a \u0437\u0430\u0433\u0440\u0443\u0437\u0447\u0438\u043a\u0443 GRUB2, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043e\u0431\u043e\u0439\u0442\u0438 \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0443 \u043f\u0430\u0440\u043e\u043b\u044f | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0420\u0430\u0441\u043a\u0440\u044b\u0442\u0430 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044f \u043e\u0431 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 (CVE-2023-4001) \u0432 \u043f\u0430\u0442\u0447\u0430\u0445 \u043a \u0437\u0430\u0433\u0440\u0443\u0437\u0447\u0438\u043a\u0443 GRUB2, \u043f\u043e\u0434\u0433\u043e\u0442\u043e\u0432\u043b\u0435\u043d\u043d\u044b\u0445 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0435\u0439 Red Hat.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/fr\/blog\/news\/uyazvimost-v-patchah-red-hat-k-zagruzchiku-grub2-pozvolyayushhaya-obojti-proverku-parolya\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2024-01-15T15:28:03+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2024-01-15T15:28:03+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47 Vuln\u00e9rabilit\u00e9 dans les correctifs Red Hat du chargeur GRUB2, permettant de contourner la v\u00e9rification du mot de passe | ProHoster","description":"Des informations sur une vuln\u00e9rabilit\u00e9 (CVE-2023-4001) ont \u00e9t\u00e9 divulgu\u00e9es dans les correctifs du chargeur GRUB2, pr\u00e9par\u00e9s par Red Hat.","canonical_url":"https:\/\/prohoster.info\/fr\/blog\/news\/uyazvimost-v-patchah-red-hat-k-zagruzchiku-grub2-pozvolyayushhaya-obojti-proverku-parolya","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"fr_FR","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 \u043f\u0430\u0442\u0447\u0430\u0445 Red Hat \u043a \u0437\u0430\u0433\u0440\u0443\u0437\u0447\u0438\u043a\u0443 GRUB2, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043e\u0431\u043e\u0439\u0442\u0438 \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0443 \u043f\u0430\u0440\u043e\u043b\u044f | ProHoster","og:description":"\u0420\u0430\u0441\u043a\u0440\u044b\u0442\u0430 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044f \u043e\u0431 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 (CVE-2023-4001) \u0432 \u043f\u0430\u0442\u0447\u0430\u0445 \u043a \u0437\u0430\u0433\u0440\u0443\u0437\u0447\u0438\u043a\u0443 GRUB2, \u043f\u043e\u0434\u0433\u043e\u0442\u043e\u0432\u043b\u0435\u043d\u043d\u044b\u0445 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0435\u0439 Red Hat.","og:url":"https:\/\/prohoster.info\/fr\/blog\/news\/uyazvimost-v-patchah-red-hat-k-zagruzchiku-grub2-pozvolyayushhaya-obojti-proverku-parolya","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2024-01-15T15:28:03+00:00","article:modified_time":"2024-01-15T15:28:03+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":[],"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/112924","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/comments?post=112924"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/112924\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/media?parent=112924"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/categories?post=112924"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/tags?post=112924"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}