{"id":37361,"date":"2019-10-31T22:17:12","date_gmt":"2019-10-31T19:17:12","guid":{"rendered":"https:\/\/prohoster.info\/blog\/udalyonnaya-dos-uyazvimost-v-ipv6-steke-freebsd\/"},"modified":"2019-10-31T22:17:12","modified_gmt":"2019-10-31T19:17:12","slug":"udalyonnaya-dos-uyazvimost-v-ipv6-steke-freebsd","status":"publish","type":"post","link":"https:\/\/prohoster.info\/fr\/blog\/news\/udalyonnaya-dos-uyazvimost-v-ipv6-steke-freebsd","title":{"rendered":"Vuln\u00e9rabilit\u00e9 DoS \u00e0 distance dans la pile IPv6 de FreeBSD","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Dans FreeBSD <noindex><a rel=\"nofollow\" href=\"https:\/\/lists.freebsd.org\/pipermail\/freebsd-announce\/2019-August\/001908.html\">a \u00e9t\u00e9 corrig\u00e9e<\/a><\/noindex> vuln\u00e9rabilit\u00e9 (CVE-2019-5611) permettant de provoquer un crash du noyau (packet-of-death) via l'envoi de paquets ICMPv6 MLD sp\u00e9cialement fragment\u00e9s (<noindex><a rel=\"nofollow\" href=\"https:\/\/tools.ietf.org\/html\/rfc2710\">Multicast Listener Discovery<\/a><\/noindex>). Le probl\u00e8me <noindex><a rel=\"nofollow\" href=\"https:\/\/www.reddit.com\/r\/BSD\/comments\/c4krwr\/freebsd_ipv6_remote_dingdong_attack_kernel_panic\/\">est caus\u00e9e<\/a><\/noindex> r\u00e9side dans l'absence de v\u00e9rification n\u00e9cessaire dans l'appel \u00e0 m_pulldown(), ce qui peut entra\u00eener le retour de cha\u00eenes mbufs non continues, contrairement aux attentes de l'appelant.<\/p>\n<p>Vuln\u00e9rabilit\u00e9 <noindex><a rel=\"nofollow\" href=\"https:\/\/svnweb.freebsd.org\/base?view=revision&#038;revision=350815\">a \u00e9t\u00e9 corrig\u00e9e<\/a><\/noindex> dans les mises \u00e0 jour 12.0-RELEASE-p10, 11.3-RELEASE-p3 et 11.2-RELEASE-p14. En tant que solution de contournement, il est possible de d\u00e9sactiver la prise en charge de la fragmentation pour IPv6 ou de filtrer au niveau du pare-feu les options dans l'en-t\u00eate <noindex><a rel=\"nofollow\" href=\"https:\/\/tools.ietf.org\/html\/draft-ietf-6man-hbh-header-handling-03\">HBH<\/a><\/noindex> (Hop-by-Hop). Il est int\u00e9ressant de noter que l'erreur \u00e0 l'origine de la vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 identifi\u00e9e d\u00e8s 2006 et corrig\u00e9e dans OpenBSD, NetBSD et macOS, mais reste non r\u00e9solue dans FreeBSD, malgr\u00e9 le fait que les d\u00e9veloppeurs de FreeBSD aient \u00e9t\u00e9 inform\u00e9s du probl\u00e8me.<\/p>\n<p>On peut \u00e9galement noter la correction de deux autres vuln\u00e9rabilit\u00e9s dans FreeBSD :<\/p>\n<ul>\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/lists.freebsd.org\/pipermail\/freebsd-announce\/2019-August\/001910.html\">CVE-2019-5603<\/a><\/noindex> \u2014 D\u00e9bordement du compteur de liens sur les structures de donn\u00e9es dans mqueuefs lors de l'utilisation de biblioth\u00e8ques 32 bits dans un environnement 64 bits (compatibilit\u00e9 32 bits). Le probl\u00e8me se manifeste lors de l'activation de mqueuefs, qui n'est pas activ\u00e9e par d\u00e9faut, et peut entra\u00eener un acc\u00e8s \u00e0 des fichiers, des r\u00e9pertoires et des sockets ouverts par des processus appartenant \u00e0 d'autres utilisateurs, ou pour organiser l'acc\u00e8s \u00e0 des fichiers externes depuis un environnement jail. En cas d'acc\u00e8s root dans le jail, la vuln\u00e9rabilit\u00e9 permet d'obtenir un acc\u00e8s root c\u00f4t\u00e9 h\u00f4te.\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/lists.freebsd.org\/pipermail\/freebsd-announce\/2019-August\/001909.html\">CVE-2019-5612<\/a><\/noindex> \u2014 Probl\u00e8me d'acc\u00e8s multithread \u00e0 l'appareil \/dev\/midistat en raison d'une condition de concurrence pouvant entra\u00eener la lecture de zones de m\u00e9moire du noyau en dehors des limites du tampon allou\u00e9 pour midistat. Sur les syst\u00e8mes 32 bits, une tentative d'exploitation de la vuln\u00e9rabilit\u00e9 entra\u00eene un plantage du noyau, tandis que sur les syst\u00e8mes 64 bits, elle permet de r\u00e9v\u00e9ler le contenu d'zones de m\u00e9moire arbitraires du noyau.\n<\/ul>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Source : <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51332\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412\u043e FreeBSD \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2019-5611), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0432\u044b\u0437\u0432\u0430\u0442\u044c \u043a\u0440\u0430\u0445 \u044f\u0434\u0440\u0430 (packet-of-death) \u0447\u0435\u0440\u0435\u0437 \u043e\u0442\u043f\u0440\u0430\u0432\u043a\u0443 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u0444\u0440\u0430\u0433\u043c\u0435\u043d\u0442\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u0445 \u043f\u0430\u043a\u0435\u0442\u043e\u0432 ICMPv6 MLD (Multicast Listener Discovery). \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u0432\u044b\u0437\u0432\u0430\u043d\u0430 \u043e\u0442\u0441\u0443\u0442\u0441\u0442\u0432\u0438\u0435\u043c \u043d\u0435\u043e\u0431\u0445\u043e\u0434\u0438\u043c\u043e\u0439 \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0438 \u0432 \u0432\u044b\u0437\u043e\u0432\u0435 m_pulldown(), \u0447\u0442\u043e \u043c\u043e\u0436\u0435\u0442 \u043f\u0440\u0438\u0432\u0435\u0441\u0442\u0438 \u043a \u0432\u043e\u0437\u0432\u0440\u0430\u0442\u0443 \u043d\u0435 \u043d\u0435\u043f\u0440\u0435\u0440\u044b\u0432\u043d\u044b\u0445 \u0446\u0435\u043f\u043e\u0447\u0435\u043a mbufs, \u0432\u043e\u043f\u0440\u0435\u043a\u0438 \u043e\u0436\u0438\u0434\u0430\u043d\u0438\u044f \u0432\u044b\u0437\u044b\u0432\u0430\u044e\u0449\u0435\u0439 \u0441\u0442\u043e\u0440\u043e\u043d\u044b. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0430 \u0432 \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u044f\u0445 12.0-RELEASE-p10, 11.3-RELEASE-p3 \u0438 11.2-RELEASE-p14. \u0412 \u043a\u0430\u0447\u0435\u0441\u0442\u0432\u0435 \u043e\u0431\u0445\u043e\u0434\u043d\u043e\u0433\u043e \u043f\u0443\u0442\u0438 \u0437\u0430\u0449\u0438\u0442\u044b \u043c\u043e\u0436\u043d\u043e [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-37361","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412\u043e FreeBSD \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2019-5611), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0432\u044b\u0437\u0432\u0430\u0442\u044c \u043a\u0440\u0430\u0445 \u044f\u0434\u0440\u0430.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/fr\/blog\/news\/udalyonnaya-dos-uyazvimost-v-ipv6-steke-freebsd\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"fr_FR\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u0434\u0430\u043b\u0451\u043d\u043d\u0430\u044f DoS-\u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 IPv6-\u0441\u0442\u0435\u043a\u0435 FreeBSD | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412\u043e FreeBSD \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2019-5611), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0432\u044b\u0437\u0432\u0430\u0442\u044c \u043a\u0440\u0430\u0445 \u044f\u0434\u0440\u0430.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/fr\/blog\/news\/udalyonnaya-dos-uyazvimost-v-ipv6-steke-freebsd\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:17:12+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T19:17:12+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47 Vuln\u00e9rabilit\u00e9 DoS \u00e0 distance dans la pile IPv6 de FreeBSD | ProHoster","description":"La vuln\u00e9rabilit\u00e9 (CVE-2019-5611) a \u00e9t\u00e9 corrig\u00e9e dans FreeBSD, permettant de provoquer un crash du noyau.","canonical_url":"https:\/\/prohoster.info\/fr\/blog\/news\/udalyonnaya-dos-uyazvimost-v-ipv6-steke-freebsd","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"fr_FR","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u0434\u0430\u043b\u0451\u043d\u043d\u0430\u044f DoS-\u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 IPv6-\u0441\u0442\u0435\u043a\u0435 FreeBSD | ProHoster","og:description":"\u0412\u043e FreeBSD \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2019-5611), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0432\u044b\u0437\u0432\u0430\u0442\u044c \u043a\u0440\u0430\u0445 \u044f\u0434\u0440\u0430.","og:url":"https:\/\/prohoster.info\/fr\/blog\/news\/udalyonnaya-dos-uyazvimost-v-ipv6-steke-freebsd","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:17:12+00:00","article:modified_time":"2019-10-31T19:17:12+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"37361","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-23 17:29:49","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 01:28:27","updated":"2026-01-23 17:29:49","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/37361","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/comments?post=37361"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/37361\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/media?parent=37361"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/categories?post=37361"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/tags?post=37361"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}