{"id":84053,"date":"2020-06-05T01:42:08","date_gmt":"2020-06-04T23:42:08","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/opasnye-uyazvimosti-v-qemu-node-js-grafana-i-android"},"modified":"2020-06-05T01:42:08","modified_gmt":"2020-06-04T23:42:08","slug":"opasnye-uyazvimosti-v-qemu-node-js-grafana-i-android","status":"publish","type":"post","link":"https:\/\/prohoster.info\/fr\/blog\/news\/opasnye-uyazvimosti-v-qemu-node-js-grafana-i-android","title":{"rendered":"Vuln\u00e9rabilit\u00e9s dangereuses dans QEMU, Node.js, Grafana et Android","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Plusieurs vuln\u00e9rabilit\u00e9s r\u00e9cemment d\u00e9couvertes :<\/p>\n<ul>\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/www.openwall.com\/lists\/oss-security\/2020\/06\/03\/6\">Vuln\u00e9rabilit\u00e9<\/a><\/noindex> (<noindex><a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2020-13765\">CVE-2020-13765<\/a><\/noindex>) dans QEMU, qui peut potentiellement conduire \u00e0 l'ex\u00e9cution de code avec les privil\u00e8ges du processus QEMU sur le syst\u00e8me h\u00f4te lors du chargement d'une image de noyau sp\u00e9cialement con\u00e7ue dans le syst\u00e8me invit\u00e9. Le probl\u00e8me est d\u00fb \u00e0 un d\u00e9bordement de tampon dans le code de copie du contenu du ROM au moment du chargement du syst\u00e8me, et se manifeste lors du chargement du contenu d'une image de noyau 32 bits en m\u00e9moire. Un correctif est pour l'instant disponible uniquement sous forme de <noindex><a rel=\"nofollow\" href=\"https:\/\/git.qemu.org\/?p=qemu.git;a=commitdiff;h=e423455c4f23a1a828901c78fe6d03b7dde79319\">d'un correctif<\/a><\/noindex>.\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/nodejs.org\/en\/blog\/vulnerability\/june-2020-security-releases\/\">Quatre vuln\u00e9rabilit\u00e9s<\/a><\/noindex> dans Node.js. Les vuln\u00e9rabilit\u00e9s <noindex><a rel=\"nofollow\" href=\"https:\/\/nodejs.org\/en\/blog\/release\/v14.4.0\/\">r\u00e9solus<\/a><\/noindex> sont pr\u00e9sentes dans les versions 14.4.0, 10.21.0 et 12.18.0.\n<ul>\n<li class=\"l\"> CVE-2020-8172 \u2014 permet de contourner la v\u00e9rification du certificat de l'h\u00f4te lors de la r\u00e9utilisation d'une session TLS.\n<li class=\"l\"> CVE-2020-8174 \u2014 permet potentiellement l'ex\u00e9cution de code sur le syst\u00e8me en raison d'un d\u00e9bordement de tampon dans les fonctions napi_get_value_string_*(), qui se produit lors de certains appels. <noindex><a rel=\"nofollow\" href=\"https:\/\/www.npmjs.com\/package\/node-addon-api\">N-API<\/a><\/noindex> (API C pour \u00e9crire des modules natifs).\n<li class=\"l\"> CVE-2020-10531 \u2014 d\u00e9bordement d'entier dans ICU (International Components for Unicode) pour C\/C++, pouvant entra\u00eener un d\u00e9bordement de tampon lors de l'utilisation de la fonction UnicodeString::doAppend().\n<li class=\"l\"> CVE-2020-11080 \u2014 permet de provoquer un d\u00e9ni de service (100 % d'utilisation CPU) en envoyant de grandes trames \u00ab SETTINGS \u00bb lors d'une connexion HTTP\/2.\n<\/ul>\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/www.openwall.com\/lists\/oss-security\/2020\/06\/03\/4\">Vuln\u00e9rabilit\u00e9<\/a><\/noindex> dans la plateforme d'affichage interactif de m\u00e9triques Grafana, utilis\u00e9e pour cr\u00e9er des graphiques de surveillance visuelle bas\u00e9s sur diverses sources de donn\u00e9es. Une erreur dans le code de gestion des avatars permet d'initier l'envoi d'une requ\u00eate HTTP depuis Grafana vers n'importe quelle URL sans authentification et de voir le r\u00e9sultat de cette requ\u00eate. Cette fonctionnalit\u00e9 peut \u00eatre utilis\u00e9e, par exemple, pour explorer le r\u00e9seau interne des entreprises utilisant Grafana. Le probl\u00e8me <noindex><a rel=\"nofollow\" href=\"https:\/\/grafana.com\/blog\/2020\/06\/03\/grafana-6.7.4-and-7.0.2-released-with-important-security-fix\/\">a \u00e9t\u00e9 corrig\u00e9e<\/a><\/noindex> se trouve dans les versions<br \/>\nGrafana 6.7.4 et 7.0.2. En tant que solution de contournement pour la protection, il est recommand\u00e9 de restreindre l'acc\u00e8s \u00e0 l'URL \u00ab \/avatar\/* \u00bb sur le serveur avec Grafana.<\/p>\n<li class=\"l\">  <noindex><a rel=\"nofollow\" href=\"https:\/\/source.android.com\/security\/bulletin\/2020-06-01\">Publi\u00e9<\/a><\/noindex> Le lot de correctifs de s\u00e9curit\u00e9 de juin pour Android, qui corrige 34 vuln\u00e9rabilit\u00e9s. Quatre probl\u00e8mes ont \u00e9t\u00e9 class\u00e9s comme critiques : deux vuln\u00e9rabilit\u00e9s (CVE-2019-14073, CVE-2019-14080) dans des composants propri\u00e9taires de Qualcomm et deux vuln\u00e9rabilit\u00e9s dans le syst\u00e8me permettant l'ex\u00e9cution de code lors du traitement de donn\u00e9es externes sp\u00e9cialement con\u00e7ues (CVE-2020-0117 \u2014 d\u00e9bordement d'entier. <noindex><a rel=\"nofollow\" href=\"https:\/\/android.googlesource.com\/platform\/system\/bt\/+\/1570b62c88d7c5b9c6bfe43da8cc16ea30d3e8df\">dans la pile Bluetooth,<\/a><\/noindex> CVE-2020-8597 \u2014 d\u00e9bordement EAP dans pppd <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=52498\">CVE-2020-8597 \u2014 d\u00e9bordement EAP dans pppd.<\/a><\/noindex>).\n<\/ul>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Source : <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=53085\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u043d\u0435\u0434\u0430\u0432\u043d\u043e \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043d\u044b\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439: \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2020-13765) \u0432 QEMU, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u043f\u043e\u0442\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043c\u043e\u0436\u0435\u0442 \u043f\u0440\u0438\u0432\u0435\u0441\u0442\u0438 \u043a \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044e \u043a\u043e\u0434\u0430 \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430 QEMU \u043d\u0430 \u0441\u0442\u043e\u0440\u043e\u043d\u0435 \u0445\u043e\u0441\u0442-\u0441\u0438\u0441\u0442\u0435\u043c\u044b \u043f\u0440\u0438 \u0437\u0430\u0433\u0440\u0443\u0437\u043a\u0435 \u0432 \u0433\u043e\u0441\u0442\u0435\u0432\u043e\u0439 \u0441\u0438\u0441\u0442\u0435\u043c\u0435 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043e\u0444\u043e\u0440\u043c\u043b\u0435\u043d\u043d\u043e\u0433\u043e \u043e\u0431\u0440\u0430\u0437\u0430 \u044f\u0434\u0440\u0430. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u0432\u044b\u0437\u0432\u0430\u043d\u0430 \u043f\u0435\u0440\u0435\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0435\u043c \u0431\u0443\u0444\u0435\u0440\u0430 \u0432 \u043a\u043e\u0434\u0435 \u043a\u043e\u043f\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u0441\u043e\u0434\u0435\u0440\u0436\u0438\u043c\u043e\u0433\u043e \u041f\u0417\u0423 \u043d\u0430 \u044d\u0442\u0430\u043f\u0435 \u0437\u0430\u0433\u0440\u0443\u0437\u043a\u0438 \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u0438 \u043f\u0440\u043e\u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u043f\u0440\u0438 \u0437\u0430\u0433\u0440\u0443\u0437\u043a\u0435 \u0441\u043e\u0434\u0435\u0440\u0436\u0438\u043c\u043e\u0433\u043e 32-\u0440\u0430\u0437\u0440\u044f\u0434\u043d\u043e\u0433\u043e \u043e\u0431\u0440\u0430\u0437\u0430 \u044f\u0434\u0440\u0430 \u0432 \u043f\u0430\u043c\u044f\u0442\u044c. \u0418\u0441\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u0435 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-84053","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u043d\u0435\u0434\u0430\u0432\u043d\u043e \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043d\u044b\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439: \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/fr\/blog\/news\/opasnye-uyazvimosti-v-qemu-node-js-grafana-i-android\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"fr_FR\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041e\u043f\u0430\u0441\u043d\u044b\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 QEMU, Node.js, Grafana \u0438 Android | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u043d\u0435\u0434\u0430\u0432\u043d\u043e \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043d\u044b\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439: \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/fr\/blog\/news\/opasnye-uyazvimosti-v-qemu-node-js-grafana-i-android\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-06-04T23:42:08+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-06-04T23:42:08+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vuln\u00e9rabilit\u00e9s dangereuses dans QEMU, Node.js, Grafana et Android | ProHoster","description":"\ud83e\udd47Vuln\u00e9rabilit\u00e9s critiques dans QEMU, Node.js, Grafana et Android | ProHoster","canonical_url":"https:\/\/prohoster.info\/fr\/blog\/news\/opasnye-uyazvimosti-v-qemu-node-js-grafana-i-android","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"fr_FR","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041e\u043f\u0430\u0441\u043d\u044b\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 QEMU, Node.js, Grafana \u0438 Android | ProHoster","og:description":"\u041d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u043d\u0435\u0434\u0430\u0432\u043d\u043e \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043d\u044b\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439: \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (","og:url":"https:\/\/prohoster.info\/fr\/blog\/news\/opasnye-uyazvimosti-v-qemu-node-js-grafana-i-android","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-06-04T23:42:08+00:00","article:modified_time":"2020-06-04T23:42:08+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"84053","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 15:05:33","updated":"2022-09-28 11:57:16","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/84053","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/comments?post=84053"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/84053\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/media?parent=84053"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/categories?post=84053"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/tags?post=84053"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}