{"id":109367,"date":"2023-07-12T21:10:19","date_gmt":"2023-07-12T19:10:19","guid":{"rendered":"https:\/\/prohoster.info\/?p=109367"},"modified":"2023-07-13T09:57:04","modified_gmt":"2023-07-13T07:57:04","slug":"uyazvimosti-v-redis-ghostscript-asterisk-i-parse-server","status":"publish","type":"post","link":"https:\/\/prohoster.info\/it\/blog\/news\/uyazvimosti-v-redis-ghostscript-asterisk-i-parse-server","title":{"rendered":"Vulnerabilit\u00e0 in Redis, Ghostscript, Asterisk e Parse Server","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Alcune vulnerabilit\u00e0 pericolose recentemente scoperte:  <\/p>\n<ul>\n<li class=\"l\"> CVE-2022-24834 \u2014 vulnerabilit\u00e0 nel DBMS Redis, che consente di provocare un overflow del buffer nelle librerie cjson e cmsgpack durante l'esecuzione di uno script appositamente formattato in linguaggio Lua. Potenzialmente, la vulnerabilit\u00e0 pu\u00f2 portare all'esecuzione remota di codice su <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/it\/server\/dts-newyork\/\"   title=\"server\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"2763\">server<\/a>. Il problema si manifesta a partire da Redis 2.6 ed \u00e8 stato risolto nelle versioni 7.0.12, 6.2.13 e 6.0.20. Come soluzione alternativa, \u00e8 possibile vietare agli utenti Redis di eseguire i comandi EVAL e EVALSHA tramite ACL.\n<li class=\"l\"> CVE-2023-36824 \u2014 vulnerabilit\u00e0 nel database Redis che provoca un overflow del buffer durante l'elaborazione dei nomi delle chiavi, fornite tramite il comando COMMAND GETKEYS o COMMAND GETKEYSANDFLAGS, cos\u00ec come le liste di chiavi nelle regole ACL. Questa vulnerabilit\u00e0 potrebbe potenzialmente portare all'esecuzione remota di codice sul server. Il problema si manifesta solo nella branch 7.0.x ed \u00e8 stato risolto nella versione 7.0.12.\n<li class=\"l\"> CVE-2022-23537 \u2014 vulnerabilit\u00e0 nella piattaforma di comunicazione Asterisk, che porta a un overflow del buffer durante l'analisi <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/it\/server\/dts-prohoster\/\"   title=\"server\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"3076\">server<\/a> di messaggi STUN appositamente formattati, in cui \u00e8 specificato un attributo sconosciuto. Il problema si manifesta quando Asterisk utilizza i protocolli ICE o WebRTC. La vulnerabilit\u00e0 \u00e8 stata risolta nelle versioni 16.30.1, 18.18.1, 19.8.1 e 20.3.1.\n<li class=\"l\"> CVE-2023-36664 \u2014 vulnerabilit\u00e0 in Ghostscript, un insieme di strumenti per la gestione, trasformazione e generazione di documenti nei formati PostScript e PDF, che consente di eseguire codice arbitrario all'apertura di documenti appositamente formati in PostScript. Il problema \u00e8 causato da un'elaborazione errata dei nomi dei file che iniziano con il simbolo \u00ab|\u00bb o il prefisso %pipe%. La vulnerabilit\u00e0 \u00e8 stata corretta nella versione Ghostscript 10.01.2.\n<p>In molti ambienti, Ghostscript viene chiamato durante la creazione di miniature sul desktop o durante l'indicizzazione in background dei dati, quindi per un attacco \u00e8 a volte sufficiente caricare un file con un exploit o visualizzare la cartella contenente esso in Nautilus. Un attacco ai sistemi server pu\u00f2 essere organizzato tramite i gestori di immagini basati su ImageMagick e GraphicsMagick, che chiamano Ghostscript quando vengono passati file JPEG o PNG in cui invece dell'immagine c'\u00e8 codice PostScript (questo file sar\u00e0 elaborato in Ghostscript, poich\u00e9 il MIME-type viene riconosciuto dal contenuto e non si basa sull'estensione).    <\/p>\n<li class=\"l\"> CVE-2023-36475 \u2014 vulnerabilit\u00e0 nel Parse Server, backend per Node.js, che lavora con il framework web Express, che consente di eseguire il proprio codice sul server da remoto. La vulnerabilit\u00e0 consente di utilizzare il metodo di inquinamento del prototipo degli oggetti JavaScript (\u00abprototype pollution\u00bb) per eseguire il proprio codice tramite il parser BSON di MongoDB. La vulnerabilit\u00e0 ha ricevuto un punteggio di pericolo di 9.8 su 10. Il problema \u00e8 stato corretto negli aggiornamenti parse-server 5.5.2 e 6.2.1.      <\/ul>\n<p>Fonte: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=59430\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u043d\u0435\u0434\u0430\u0432\u043d\u043e \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043d\u044b\u0445 \u043e\u043f\u0430\u0441\u043d\u044b\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439: CVE-2022-24834 &#8212; \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 \u0421\u0423\u0411\u0414 Redis, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0432\u044b\u0437\u0432\u0430\u0442\u044c \u043f\u0435\u0440\u0435\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0435 \u0431\u0443\u0444\u0435\u0440\u0430 \u0432 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0430\u0445 cjson \u0438 cmsgpack \u043f\u0440\u0438 \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0438 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043e\u0444\u043e\u0440\u043c\u043b\u0435\u043d\u043d\u043e\u0433\u043e \u0441\u0446\u0435\u043d\u0430\u0440\u0438\u044f \u043d\u0430 \u044f\u0437\u044b\u043a\u0435 Lua. \u041f\u043e\u0442\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u043c\u043e\u0436\u0435\u0442 \u043f\u0440\u0438\u0432\u0435\u0441\u0442\u0438 \u043a \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e\u043c\u0443 \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044e \u043a\u043e\u0434\u0430 \u043d\u0430 \u0441\u0435\u0440\u0432\u0435\u0440\u0435. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u043f\u0440\u043e\u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u043d\u0430\u0447\u0438\u043d\u0430\u044f \u0441 Redis 2.6 \u0438 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0430 \u0432 \u0432\u044b\u043f\u0443\u0441\u043a\u0430\u0445 7.0.12, 6.2.13 \u0438 6.0.20. \u0412 \u043a\u0430\u0447\u0435\u0441\u0442\u0432\u0435 \u043e\u0431\u0445\u043e\u0434\u043d\u043e\u0433\u043e [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-109367","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u043d\u0435\u0434\u0430\u0432\u043d\u043e \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043d\u044b\u0445 \u043e\u043f\u0430\u0441\u043d\u044b\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439: CVE-2022-24834 - \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 \u0421\u0423\u0411\u0414 Redis, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0432\u044b\u0437\u0432\u0430\u0442\u044c \u043f\u0435\u0440\u0435\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0435 \u0431\u0443\u0444\u0435\u0440\u0430 \u0432 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0430\u0445 cjson \u0438 cmsgpack \u043f\u0440\u0438 \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0438 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/it\/blog\/news\/uyazvimosti-v-redis-ghostscript-asterisk-i-parse-server\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"it_IT\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 Redis, Ghostscript, Asterisk \u0438 Parse Server | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u043d\u0435\u0434\u0430\u0432\u043d\u043e \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043d\u044b\u0445 \u043e\u043f\u0430\u0441\u043d\u044b\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439: CVE-2022-24834 - \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 \u0421\u0423\u0411\u0414 Redis, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0432\u044b\u0437\u0432\u0430\u0442\u044c \u043f\u0435\u0440\u0435\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0435 \u0431\u0443\u0444\u0435\u0440\u0430 \u0432 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0430\u0445 cjson \u0438 cmsgpack \u043f\u0440\u0438 \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0438 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/it\/blog\/news\/uyazvimosti-v-redis-ghostscript-asterisk-i-parse-server\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2023-07-12T19:10:19+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2023-07-13T07:57:04+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47 Vulnerabilit\u00e0 in Redis, Ghostscript, Asterisk e Parse Server | ProHoster","description":"Alcune vulnerabilit\u00e0 pericolose recentemente scoperte: CVE-2022-24834 - vulnerabilit\u00e0 nel database Redis, che consente di provocare un overflow del buffer nelle librerie cjson e cmsgpack durante l'esecuzione di codice specifico.","canonical_url":"https:\/\/prohoster.info\/it\/blog\/news\/uyazvimosti-v-redis-ghostscript-asterisk-i-parse-server","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"it_IT","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 Redis, Ghostscript, Asterisk \u0438 Parse Server | ProHoster","og:description":"\u041d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u043d\u0435\u0434\u0430\u0432\u043d\u043e \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043d\u044b\u0445 \u043e\u043f\u0430\u0441\u043d\u044b\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439: CVE-2022-24834 - \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 \u0421\u0423\u0411\u0414 Redis, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0432\u044b\u0437\u0432\u0430\u0442\u044c \u043f\u0435\u0440\u0435\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0435 \u0431\u0443\u0444\u0435\u0440\u0430 \u0432 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0430\u0445 cjson \u0438 cmsgpack \u043f\u0440\u0438 \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0438 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e.","og:url":"https:\/\/prohoster.info\/it\/blog\/news\/uyazvimosti-v-redis-ghostscript-asterisk-i-parse-server","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2023-07-12T19:10:19+00:00","article:modified_time":"2023-07-13T07:57:04+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"109367","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2026-02-09 21:40:03","updated":"2026-02-09 21:46:52","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/109367","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/comments?post=109367"}],"version-history":[{"count":2,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/109367\/revisions"}],"predecessor-version":[{"id":160357,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/109367\/revisions\/160357"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media?parent=109367"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/categories?post=109367"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/tags?post=109367"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}