{"id":106630,"date":"2023-02-03T12:48:25","date_gmt":"2023-02-03T10:48:25","guid":{"rendered":"https:\/\/prohoster.info\/?p=106630"},"modified":"2023-02-03T21:50:37","modified_gmt":"2023-02-03T19:50:37","slug":"vypusk-openssh-9-2-s-ustraneniem-uyazvimosti-proyavlyayushhejsya-na-etape-do-autentifikaczii","status":"publish","type":"post","link":"https:\/\/prohoster.info\/it\/blog\/news\/vypusk-openssh-9-2-s-ustraneniem-uyazvimosti-proyavlyayushhejsya-na-etape-do-autentifikaczii","title":{"rendered":"Rilascio di OpenSSH 9.2 con risoluzione di una vulnerabilit\u00e0 che si manifesta nella fase pre-autenticazione","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>\u00c8 stato pubblicato il rilascio di OpenSSH 9.2, un'implementazione open source per client e server che opera sui protocolli SSH 2.0 e SFTP. Nella nuova versione \u00e8 stata risolta una vulnerabilit\u00e0 che portava al doppio rilascio della memoria durante la fase precedente all'autenticazione. Solo la versione OpenSSH 9.1 \u00e8 suscettibile a questa vulnerabilit\u00e0; nelle versioni precedenti il problema non si manifesta.       <\/p>\n<p>Per creare le condizioni per l'emergere della vulnerabilit\u00e0, \u00e8 sufficiente cambiare il banner del client SSH in &lt;strong&gt;SSH-2.0-FuTTYSH_9.1p1&lt;\/strong&gt; affinch\u00e9 vengano impostati i flag &lt;strong&gt;SSH_BUG_CURVE25519PAD&lt;\/strong&gt; e &lt;strong&gt;SSH_OLD_DHGEX&lt;\/strong&gt;, dipendenti dalla versione del client SSH. Dopo aver impostato questi flag, la memoria per il buffer &lt;strong&gt;options.kex_algorithms&lt;\/strong&gt; viene liberata due volte &amp;mdash; durante l'esecuzione della funzione do_ssh2_kex(), che chiama compat_kex_proposal(), e durante l'esecuzione della funzione do_authentication2(), che chiama in cascata input_userauth_request(), mm_getpwnamallow(), copy_set_server_options(), assemble_algorithms() e kex_assemble_names().    <\/p>\n<p>La creazione di un exploit funzionante per la vulnerabilit\u00e0 \u00e8 considerata improbabile, poich\u00e9 il processo di sfruttamento \u00e8 troppo complesso &amp;mdash; le moderne librerie di gestione della memoria offrono protezione contro la doppia liberazione della memoria, e il processo di pre-auth, in cui si verifica l'errore, viene eseguito con privilegi ridotti in un ambiente sandbox isolato.    <\/p>\n<p>Oltre alla vulnerabilit\u00e0 menzionata, nella nuova versione sono state risolte anche altre due problematiche di sicurezza:  <\/p>\n<ul>\n<li class=\"l\"> Errore nell'elaborazione della configurazione &lt;strong&gt;PermitRemoteOpen&lt;\/strong&gt;, che porta all'ignorare il primo argomento se diverso dai valori &lt;strong&gt;any&lt;\/strong&gt; e &lt;strong&gt;none&lt;\/strong&gt;. Il problema si manifesta in versioni successive a OpenSSH 8.7 e porta a una verifica saltata specificando solo un'autorit\u00e0.\n<li class=\"l\"> Un attaccante che controlla un server DNS utilizzato per la risoluzione dei nomi pu\u00f2 ottenere l'inserimento di caratteri speciali (ad esempio, &lt;strong&gt;*&lt;\/strong&gt;) nei file known_hosts, se nella configurazione sono abilitate le opzioni CanonicalizeHostname e CanonicalizePermittedCNAMEs, e il risolutore di sistema non verifica la correttezza delle risposte dal server DNS. Lo svolgimento di un attacco \u00e8 considerato improbabile, poich\u00e9 i nomi restituiti devono soddisfare le condizioni specificate tramite CanonicalizePermittedCNAMEs.    <\/ul>\n<p>Altre modifiche:  <\/p>\n<ul>\n<li class=\"l\"> Nel ssh_config per ssh \u00e8 stata aggiunta la configurazione EnableEscapeCommandline, che controlla l'attivazione della gestione delle sequenze di escape da parte del client per la sequenza &lt;strong&gt;~C&lt;\/strong&gt;, che offre una linea di comando. Per impostazione predefinita, la gestione di &lt;strong&gt;~C&lt;\/strong&gt; \u00e8 ora disattivata per utilizzare un'isolamento sandbox pi\u00f9 rigoroso, il che potrebbe potenzialmente causare malfunzionamenti nei sistemi in cui &lt;strong&gt;~C&lt;\/strong&gt; viene utilizzato per il reindirizzamento delle porte durante il funzionamento.\n<li class=\"l\"> Nel file sshd_config per sshd \u00e8 stata aggiunta la direttiva ChannelTimeout per impostare il timeout di inattivit\u00e0 del canale (i canali in cui non viene rilevato traffico per il tempo specificato nella direttiva verranno automaticamente chiusi). Diversi timeout possono essere impostati per la sessione, X11, l'agente e il reindirizzamento del traffico.\n<li class=\"l\"> Nel file sshd_config per sshd \u00e8 stata aggiunta la direttiva UnusedConnectionTimeout, che consente di impostare un timeout per terminare le connessioni dei client che rimangono inattive per un certo periodo senza canali attivi.\n<li class=\"l\"> Nel sshd \u00e8 stata aggiunta l'opzione &lt;strong&gt;-V&lt;\/strong&gt; per visualizzare la versione, analogamente a una simile opzione nel client ssh.\n<li class=\"l\"> Nel output di &lt;strong&gt;ssh -G&lt;\/strong&gt; \u00e8 stata aggiunta la riga &lt;strong&gt;Host&lt;\/strong&gt;, che riflette il valore dell'argomento con il nome host.\n<li class=\"l\"> In scp e sftp \u00e8 stata aggiunta l'opzione &#171;-X&#187; per gestire parametri del protocollo SFTP, come la dimensione del buffer di copia e il numero di richieste in attesa di completamento.\n<li class=\"l\"> In ssh-keyscan \u00e8 consentita la scansione di interi range di indirizzi CIDR, ad esempio, &#171;ssh-keyscan 192.168.0.0\/24&#187;.      <\/ul>\n<p>Fonte: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=58598\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u0440\u0435\u043b\u0438\u0437 OpenSSH 9.2, \u043e\u0442\u043a\u0440\u044b\u0442\u043e\u0439 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u043a\u043b\u0438\u0435\u043d\u0442\u0430 \u0438 \u0441\u0435\u0440\u0432\u0435\u0440\u0430 \u0434\u043b\u044f \u0440\u0430\u0431\u043e\u0442\u044b \u043f\u043e \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u0430\u043c SSH 2.0 \u0438 SFTP. \u0412 \u043d\u043e\u0432\u043e\u0439 \u0432\u0435\u0440\u0441\u0438\u0438 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c, \u043f\u0440\u0438\u0432\u043e\u0434\u044f\u0449\u0430\u044f \u043a \u0434\u0432\u043e\u0439\u043d\u043e\u043c\u0443 \u043e\u0441\u0432\u043e\u0431\u043e\u0436\u0434\u0435\u043d\u0438\u044e \u043e\u0431\u043b\u0430\u0441\u0442\u0438 \u043f\u0430\u043c\u044f\u0442\u0438 \u043d\u0430 \u0441\u0442\u0430\u0434\u0438\u0438 \u0434\u043e \u043f\u0440\u043e\u0445\u043e\u0436\u0434\u0435\u043d\u0438\u044f \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u043f\u043e\u0434\u0432\u0435\u0440\u0436\u0435\u043d \u0442\u043e\u043b\u044c\u043a\u043e \u0432\u044b\u043f\u0443\u0441\u043a OpenSSH 9.1, \u0432 \u0431\u043e\u043b\u0435\u0435 \u0440\u0430\u043d\u043d\u0438\u0445 \u0432\u0435\u0440\u0441\u0438\u044f\u0445 \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u043d\u0435 \u043f\u0440\u043e\u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f. \u0414\u043b\u044f \u0441\u043e\u0437\u0434\u0430\u043d\u0438\u044f \u0443\u0441\u043b\u043e\u0432\u0438\u0439 \u043f\u0440\u043e\u044f\u0432\u043b\u0435\u043d\u0438\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0434\u043e\u0441\u0442\u0430\u0442\u043e\u0447\u043d\u043e \u0438\u0437\u043c\u0435\u043d\u0438\u0442\u044c \u0431\u0430\u043d\u043d\u0435\u0440 SSH-\u043a\u043b\u0438\u0435\u043d\u0442\u0430 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-106630","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u0440\u0435\u043b\u0438\u0437 OpenSSH 9.2, \u043e\u0442\u043a\u0440\u044b\u0442\u043e\u0439 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u043a\u043b\u0438\u0435\u043d\u0442\u0430 \u0438 \u0441\u0435\u0440\u0432\u0435\u0440\u0430 \u0434\u043b\u044f \u0440\u0430\u0431\u043e\u0442\u044b \u043f\u043e \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u0430\u043c SSH 2.0 \u0438 SFTP.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/it\/blog\/news\/vypusk-openssh-9-2-s-ustraneniem-uyazvimosti-proyavlyayushhejsya-na-etape-do-autentifikaczii\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"it_IT\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0412\u044b\u043f\u0443\u0441\u043a OpenSSH 9.2 \u0441 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u0435\u043c \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438, \u043f\u0440\u043e\u044f\u0432\u043b\u044f\u044e\u0449\u0435\u0439\u0441\u044f \u043d\u0430 \u044d\u0442\u0430\u043f\u0435 \u0434\u043e \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u0440\u0435\u043b\u0438\u0437 OpenSSH 9.2, \u043e\u0442\u043a\u0440\u044b\u0442\u043e\u0439 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u043a\u043b\u0438\u0435\u043d\u0442\u0430 \u0438 \u0441\u0435\u0440\u0432\u0435\u0440\u0430 \u0434\u043b\u044f \u0440\u0430\u0431\u043e\u0442\u044b \u043f\u043e \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u0430\u043c SSH 2.0 \u0438 SFTP.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/it\/blog\/news\/vypusk-openssh-9-2-s-ustraneniem-uyazvimosti-proyavlyayushhejsya-na-etape-do-autentifikaczii\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2023-02-03T10:48:25+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2023-02-03T19:50:37+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47 Rilascio di OpenSSH 9.2 con la correzione di una vulnerabilit\u00e0 che si manifesta prima dell'autenticazione | ProHoster","description":"\u00c8 stata pubblicata la versione di OpenSSH 9.2, un'implementazione open-source del client e del server per funzionare con i protocolli SSH 2.0 e SFTP.","canonical_url":"https:\/\/prohoster.info\/it\/blog\/news\/vypusk-openssh-9-2-s-ustraneniem-uyazvimosti-proyavlyayushhejsya-na-etape-do-autentifikaczii","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"it_IT","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0412\u044b\u043f\u0443\u0441\u043a OpenSSH 9.2 \u0441 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u0435\u043c \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438, \u043f\u0440\u043e\u044f\u0432\u043b\u044f\u044e\u0449\u0435\u0439\u0441\u044f \u043d\u0430 \u044d\u0442\u0430\u043f\u0435 \u0434\u043e \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 | ProHoster","og:description":"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u0440\u0435\u043b\u0438\u0437 OpenSSH 9.2, \u043e\u0442\u043a\u0440\u044b\u0442\u043e\u0439 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u043a\u043b\u0438\u0435\u043d\u0442\u0430 \u0438 \u0441\u0435\u0440\u0432\u0435\u0440\u0430 \u0434\u043b\u044f \u0440\u0430\u0431\u043e\u0442\u044b \u043f\u043e \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u0430\u043c SSH 2.0 \u0438 SFTP.","og:url":"https:\/\/prohoster.info\/it\/blog\/news\/vypusk-openssh-9-2-s-ustraneniem-uyazvimosti-proyavlyayushhejsya-na-etape-do-autentifikaczii","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2023-02-03T10:48:25+00:00","article:modified_time":"2023-02-03T19:50:37+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":[],"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/106630","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/comments?post=106630"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/106630\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media?parent=106630"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/categories?post=106630"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/tags?post=106630"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}