{"id":55016,"date":"2020-01-10T00:00:00","date_gmt":"2020-01-09T21:00:00","guid":{"rendered":"https:\/\/prohoster.info\/blog\/blog_prohoster\/uyazvimost-v-e2fsck-proyavlyayushhayasya-pri-obrabotke-spetsialno-oformlennyh-katalogov"},"modified":"2020-02-18T14:03:05","modified_gmt":"2020-02-18T11:03:05","slug":"uyazvimost-v-e2fsck-proyavlyayushhayasya-pri-obrabotke-spetsialno-oformlennyh-katalogov","status":"publish","type":"post","link":"https:\/\/prohoster.info\/fr\/blog\/news\/uyazvimost-v-e2fsck-proyavlyayushhayasya-pri-obrabotke-spetsialno-oformlennyh-katalogov","title":{"rendered":"Vuln\u00e9rabilit\u00e9 dans e2fsck, se manifestant lors du traitement de r\u00e9pertoires sp\u00e9cialement con\u00e7us","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Dans l'outil e2fsck, fourni avec le package <noindex><a rel=\"nofollow\" href=\"http:\/\/e2fsprogs.sourceforge.net\/\">e2fsprogs<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/blog.talosintelligence.com\/2020\/01\/e2fsprogs-remote-code-execution-vuln-jan-2020.html\">une vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 identifi\u00e9e<\/a><\/noindex> <noindex><a rel=\"nofollow\" href=\"https:\/\/talosintelligence.com\/vulnerability_reports\/TALOS-2019-0973\">CVE-2020-10174<\/a><\/noindex> (<noindex><a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2019-5188\">CVE-2019-5188<\/a><\/noindex>), permettant l'ex\u00e9cution de code par un attaquant lors de la v\u00e9rification d'un syst\u00e8me de fichiers contenant des r\u00e9pertoires sp\u00e9cialement format\u00e9s. La vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 confirm\u00e9e dans les versions de 1.43.3 \u00e0 1.45.4. La vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 corrig\u00e9e dans la mise \u00e0 jour <noindex><a rel=\"nofollow\" href=\"https:\/\/git.kernel.org\/pub\/scm\/fs\/ext2\/e2fsprogs.git\/tag\/?h=v1.45.5\">e2fsck 1.45.5<\/a><\/noindex>. Dans les distributions, le probl\u00e8me reste pour l'instant non corrig\u00e9 (<noindex><a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2019-5188\">Debian<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/security.archlinux.org\/package\/e2fsprogs\">Arch Linux<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/bugzilla.suse.com\/show_bug.cgi?id=CVE-2019-5188\">SUSE\/openSUSE<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/people.canonical.com\/~ubuntu-security\/cve\/2019\/CVE-2019-5188.html\">Ubuntu<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=CVE-2019-5188\">RHEL<\/a><\/noindex>).<\/p>\n<p>La vuln\u00e9rabilit\u00e9 est caus\u00e9e par une erreur dans la fonction mutate_name() du fichier rehash.c, utilis\u00e9e lors de la reconstruction des tables de hachage li\u00e9es au r\u00e9pertoire, assurant la correspondance avec tous les fichiers qu'il contient. La corruption de la structure hash_entry li\u00e9e au r\u00e9pertoire peut conduire \u00e0 l'\u00e9criture de donn\u00e9es de l'attaquant dans une zone en dehors du tampon allou\u00e9. Si plusieurs fichiers avec le m\u00eame nom sont trouv\u00e9s dans la table de hachage li\u00e9e au r\u00e9pertoire, l'outil e2fsck renomme les fichiers en doublon en ajoutant ~0, ~1, etc. au nom. Pour stocker temporairement le nouveau nom lors de ce renommage, un tampon de 256 octets est allou\u00e9 sur la pile. <\/p>\n<p>La taille des donn\u00e9es copi\u00e9es est d\u00e9termin\u00e9e par l'expression &#171;entry-&gt;name_len &#038; 0xff&#187;, mais la valeur de entry-&gt;name_len est charg\u00e9e \u00e0 partir de la structure sur le disque, et non calcul\u00e9e en fonction de la taille r\u00e9elle du nom. Si la taille est nulle, l'indice du tableau prend la valeur -1 et cr\u00e9e des conditions pour un d\u00e9bordement d'entier via la limite inf\u00e9rieure du tampon (integer underflow) et l'\u00e9crasement d'autres donn\u00e9es sur la pile par la valeur &#171;~0&#187;. Pour les syst\u00e8mes 64 bits, l'exploitation de la vuln\u00e9rabilit\u00e9 est jug\u00e9e peu probable et n\u00e9cessite l'absence de restrictions sur la taille de la pile (ulimit -s unlimited). Pour les syst\u00e8mes 32 bits, l'exploitation est consid\u00e9r\u00e9e comme possible, mais le r\u00e9sultat d\u00e9pend fortement de la mani\u00e8re dont le fichier ex\u00e9cutable a \u00e9t\u00e9 compil\u00e9.<\/p>\n<p>Pour r\u00e9aliser une attaque, l'attaquant doit alt\u00e9rer de mani\u00e8re sp\u00e9cifique les donn\u00e9es dans une partition avec un FS ext2, ext3 ou ext4. \u00c9tant donn\u00e9 que cette op\u00e9ration n\u00e9cessite des privil\u00e8ges de superutilisateur, la vuln\u00e9rabilit\u00e9 repr\u00e9sente une menace lors de la v\u00e9rification par l'outil e2fsck de p\u00e9riph\u00e9riques externes ou d'images de FS obtenues de l'ext\u00e9rieur.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Source : <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=52162\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u0443\u0442\u0438\u043b\u0438\u0442\u0435 e2fsck, \u043f\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u0435\u043c\u043e\u0439 \u0432 \u0441\u043e\u0441\u0442\u0430\u0432\u0435 \u043f\u0430\u043a\u0435\u0442\u0430 e2fsprogs, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2019-5188), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0434\u043e\u0431\u0438\u0442\u044c\u0441\u044f \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u043a\u043e\u0434\u0430 \u0437\u043b\u043e\u0443\u043c\u044b\u0448\u043b\u0435\u043d\u043d\u0438\u043a\u0430 \u043f\u0440\u0438 \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0438 \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0438 \u0444\u0430\u0439\u043b\u043e\u0432\u043e\u0439 \u0441\u0438\u0441\u0442\u0435\u043c\u044b, \u0441\u043e\u0434\u0435\u0440\u0436\u0430\u0449\u0435\u0439 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u044b\u043c \u043e\u0431\u0440\u0430\u0437\u043e\u043c \u043e\u0444\u043e\u0440\u043c\u043b\u0435\u043d\u043d\u044b\u0435 \u043a\u0430\u0442\u0430\u043b\u043e\u0433\u0438. \u041d\u0430\u043b\u0438\u0447\u0438\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u043f\u043e\u0434\u0442\u0432\u0435\u0440\u0436\u0434\u0435\u043d\u043e \u0432 \u0432\u044b\u043f\u0443\u0441\u043a\u0430\u0445 \u0441 1.43.3 \u043f\u043e 1.45.4. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0430 \u0432 \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u0438 e2fsck 1.45.5. \u0412 \u0434\u0438\u0441\u0442\u0440\u0438\u0431\u0443\u0442\u0438\u0432\u0430\u0445 \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u043f\u043e\u043a\u0430 \u043e\u0441\u0442\u0430\u0451\u0442\u0441\u044f \u043d\u0435\u0438\u0441\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u043d\u043e\u0439 (Debian, Arch Linux, SUSE\/openSUSE, Ubuntu, RHEL). \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432\u044b\u0437\u0432\u0430\u043d\u0430 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-55016","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u0443\u0442\u0438\u043b\u0438\u0442\u0435 e2fsck, \u043f\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u0435\u043c\u043e\u0439 \u0432 \u0441\u043e\u0441\u0442\u0430\u0432\u0435 \u043f\u0430\u043a\u0435\u0442\u0430 e2fsprogs,\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/fr\/blog\/news\/uyazvimost-v-e2fsck-proyavlyayushhayasya-pri-obrabotke-spetsialno-oformlennyh-katalogov\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"fr_FR\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 e2fsck, \u043f\u0440\u043e\u044f\u0432\u043b\u044f\u044e\u0449\u0430\u044f\u0441\u044f \u043f\u0440\u0438 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0435 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043e\u0444\u043e\u0440\u043c\u043b\u0435\u043d\u043d\u044b\u0445 \u043a\u0430\u0442\u0430\u043b\u043e\u0433\u043e\u0432 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u0443\u0442\u0438\u043b\u0438\u0442\u0435 e2fsck, \u043f\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u0435\u043c\u043e\u0439 \u0432 \u0441\u043e\u0441\u0442\u0430\u0432\u0435 \u043f\u0430\u043a\u0435\u0442\u0430 e2fsprogs,\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/fr\/blog\/news\/uyazvimost-v-e2fsck-proyavlyayushhayasya-pri-obrabotke-spetsialno-oformlennyh-katalogov\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-01-09T21:00:00+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-02-18T11:03:05+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vuln\u00e9rabilit\u00e9 dans e2fsck, se manifestant lors du traitement de r\u00e9pertoires sp\u00e9cialement format\u00e9s | ProHoster","description":"Dans l'outil e2fsck, fourni avec le package e2fsprogs,","canonical_url":"https:\/\/prohoster.info\/fr\/blog\/news\/uyazvimost-v-e2fsck-proyavlyayushhayasya-pri-obrabotke-spetsialno-oformlennyh-katalogov","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"fr_FR","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 e2fsck, \u043f\u0440\u043e\u044f\u0432\u043b\u044f\u044e\u0449\u0430\u044f\u0441\u044f \u043f\u0440\u0438 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0435 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043e\u0444\u043e\u0440\u043c\u043b\u0435\u043d\u043d\u044b\u0445 \u043a\u0430\u0442\u0430\u043b\u043e\u0433\u043e\u0432 | ProHoster","og:description":"\u0412 \u0443\u0442\u0438\u043b\u0438\u0442\u0435 e2fsck, \u043f\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u0435\u043c\u043e\u0439 \u0432 \u0441\u043e\u0441\u0442\u0430\u0432\u0435 \u043f\u0430\u043a\u0435\u0442\u0430 e2fsprogs,","og:url":"https:\/\/prohoster.info\/fr\/blog\/news\/uyazvimost-v-e2fsck-proyavlyayushhayasya-pri-obrabotke-spetsialno-oformlennyh-katalogov","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-01-09T21:00:00+00:00","article:modified_time":"2020-02-18T11:03:05+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"55016","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-24 13:31:20","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 19:21:08","updated":"2026-01-24 13:31:20","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/55016","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/comments?post=55016"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/55016\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/media?parent=55016"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/categories?post=55016"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/tags?post=55016"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}