{"id":120608,"date":"2024-11-20T01:09:18","date_gmt":"2024-11-19T23:09:18","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimosti-v-utilite-needrestart-pozvolyayushhie-poluchit-root-dostup-v-ubuntu-server"},"modified":"2024-11-20T01:09:18","modified_gmt":"2024-11-19T23:09:18","slug":"uyazvimosti-v-utilite-needrestart-pozvolyayushhie-poluchit-root-dostup-v-ubuntu-server","status":"publish","type":"post","link":"https:\/\/prohoster.info\/it\/blog\/news\/uyazvimosti-v-utilite-needrestart-pozvolyayushhie-poluchit-root-dostup-v-ubuntu-server","title":{"rendered":"Vulnerabilit\u00e0 nell'utility needrestart, che consentono di ottenere accesso root su Ubuntu Server.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>L'azienda Qualys ha identificato tre vulnerabilit\u00e0 nell'utilit\u00e0 needrestart, progettata per riavviare i processi in background dopo l'aggiornamento delle librerie utilizzate dai processi interessati. A partire da Ubuntu 21.04, l'utilit\u00e0 needrestart \u00e8 inclusa nell'ambiente di base di Ubuntu Server, dove viene eseguita con diritti di root alla fine di ogni transazione del gestore pacchetti APT, esamina i processi in esecuzione e riavvia quelli correlati ai file che sono stati modificati dopo l'aggiornamento dei pacchetti. Le vulnerabilit\u00e0 identificate consentono a un utente locale non privilegiato di ottenere diritti di root in Ubuntu Server nella configurazione predefinita.      <\/p>\n<p>Le vulnerabilit\u00e0 sono presenti in needrestart a partire dalla versione 0.8 (2014) e sono state risolte nella versione 3.8 di needrestart. I problemi sono gi\u00e0 stati corretti anche nelle distribuzioni Debian e Ubuntu. Come soluzione alternativa per bloccare l'esploitazione della vulnerabilit\u00e0, \u00e8 possibile disabilitare la scansione degli interpreti specificando nel file di configurazione \/etc\/needrestart\/needrestart.conf il parametro '$nrconf{interpscan} = 0'.      <\/p>\n<p>Le vulnerabilit\u00e0 sono presenti nel codice che implementa la modalit\u00e0 di rilevamento dell'aggiornamento degli script eseguiti con interpreti. Problemi identificati:  <\/p>\n<ul>\n<li class=\"l\"> CVE-2024-48990 \u2014 un utente locale pu\u00f2 ottenere l'esecuzione di codice con diritti di root creando le condizioni per eseguire l'interprete Python con la variabile d'ambiente PYTHONPATH impostata dall'attaccante. Oltre all'uso di Python, l'attacco pu\u00f2 essere effettuato (CVE-2024-48992) tramite l'esecuzione dell'interprete Ruby con la variabile d'ambiente RUBYLIB.\n<p>Le vulnerabilit\u00e0 sono causate dal fatto che durante il riavvio di uno script modificato, lo strumento needrestart imposta la variabile d'ambiente PYTHONPATH in base al contenuto del file \/proc\/pid\/environ, che poi utilizza anche per eseguire il proprio codice Python. Di conseguenza, l'attaccante pu\u00f2 attendere un'attivit\u00e0 associata all'utilizzo del gestore pacchetti APT, simulare la modifica del proprio script e impostare la variabile d'ambiente PYTHONPATH, che verr\u00e0 applicata anche durante l'esecuzione del codice Python integrato in needrestart ('import sys\n print(sys.path)'), eseguito con diritti di root.    <\/p>\n<p>Ad esempio, per sfruttare la vulnerabilit\u00e0, \u00e8 possibile avviare un processo Python sempre in memoria impostando per esso la variabile d'ambiente 'PYTHONPATH=\/home\/test', e posizionare una libreria condivisa '\/home\/test\/importlib\/__init__.so' che verr\u00e0 eseguita durante l'esecuzione del codice Python privilegiato in needrestart.           <\/p>\n<li class=\"l\"> CVE-2024-48991 \u2014 un utente locale pu\u00f2 ottenere l'esecuzione di codice con diritti di root avviando una condizione di corsa (race condition), a seguito della quale needrestart avvier\u00e0 un interprete Python fittizio fornito dall'attaccante, invece dell'interprete Python di sistema. La natura della vulnerabilit\u00e0 \u00e8 simile al problema sopra menzionato, l'unica differenza \u00e8 che needrestart determina il nome del processo Python (ad esempio, \/usr\/bin\/python3) leggendo '\/proc\/pid\/exe'.\n<p>Per sfruttare la vulnerabilit\u00e0, \u00e8 possibile creare un processo \/home\/test\/race, che attender\u00e0 l'arrivo del momento in cui needrestart inizia a leggere il contenuto di \/proc\/pid\/exe tramite il meccanismo inotify, e lancer\u00e0 immediatamente tramite la funzione execve l'interprete Python di sistema. Poich\u00e9 needrestart non verifica se questo sia realmente Python, considerer\u00e0 che \/home\/test\/race sia l'interprete Python e lo avvier\u00e0 per il proprio codice.         <\/p>\n<li class=\"l\"> CVE-2024-11003 \u2014 un utente locale pu\u00f2 ottenere l'esecuzione di comandi shell arbitrari con privilegi di root creando condizioni per il trattamento in needrestart di nomi di file nel formato \u00abcomando|\u00bb, la cui trasmissione alla funzione Perl open() porter\u00e0 all'esecuzione del comando. Infatti, la vulnerabilit\u00e0 si manifesta nel modulo Perl ScanDeps (CVE-2024-10224), ma \u00e8 causata dalla trasmissione di parametri esterni a questo modulo senza adeguati controlli.\n<p>L'attacco pu\u00f2 essere realizzato avviando uno script Perl con il simbolo \u00ab|\u00bb nel nome, ad esempio \u00ab\/home\/test\/perl|\u00bb. Durante l'esecuzione della funzione scan_deps() in needrestart, questo file verr\u00e0 aperto tramite la funzione open(), che tratter\u00e0 il simbolo \u00ab|\u00bb come un flag per avviare il programma \u00ab\/home\/test\/perl\u00bb e utilizzare il flusso di uscita generato da questo programma.                 <\/ul>\n<p>Fonte: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=62261\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f Qualys \u0432\u044b\u044f\u0432\u0438\u043b\u0430 \u0442\u0440\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 \u0443\u0442\u0438\u043b\u0438\u0442\u0435 needrestart, \u043f\u0440\u0435\u0434\u043d\u0430\u0437\u043d\u0430\u0447\u0435\u043d\u043d\u043e\u0439 \u0434\u043b\u044f \u043f\u0435\u0440\u0435\u0437\u0430\u043f\u0443\u0441\u043a\u0430 \u0444\u043e\u043d\u043e\u0432\u044b\u0445 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u043e\u0432 \u043f\u043e\u0441\u043b\u0435 \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u044f \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u044b\u0445 \u0434\u0430\u043d\u043d\u044b\u043c\u0438 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430\u043c\u0438 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a. \u041d\u0430\u0447\u0438\u043d\u0430\u044f \u0441 Ubuntu 21.04 \u0443\u0442\u0438\u043b\u0438\u0442\u0430 needrestart \u0432\u043a\u043b\u044e\u0447\u0435\u043d\u0430 \u0432 \u0441\u043e\u0441\u0442\u0430\u0432 \u0431\u0430\u0437\u043e\u0432\u043e\u0433\u043e \u043e\u043a\u0440\u0443\u0436\u0435\u043d\u0438\u044f Ubuntu Server, \u0432 \u043a\u043e\u0442\u043e\u0440\u043e\u043c \u0437\u0430\u043f\u0443\u0441\u043a\u0430\u0435\u0442\u0441\u044f \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 root \u0432 \u043a\u043e\u043d\u0446\u0435 \u043a\u0430\u0436\u0434\u043e\u0439 \u0442\u0440\u0430\u043d\u0437\u0430\u043a\u0446\u0438\u0438 \u043f\u0430\u043a\u0435\u0442\u043d\u043e\u0433\u043e \u043c\u0435\u043d\u0435\u0434\u0436\u0435\u0440\u0430 APT, \u0441\u043a\u0430\u043d\u0438\u0440\u0443\u0435\u0442 \u0437\u0430\u043f\u0443\u0449\u0435\u043d\u043d\u044b\u0435 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u044b \u0438 \u043f\u0435\u0440\u0435\u0437\u0430\u043f\u0443\u0441\u043a\u0430\u0435\u0442 \u0442\u0435 \u0438\u0445 \u043d\u0438\u0445, \u0447\u0442\u043e \u0441\u0432\u044f\u0437\u0430\u043d\u043d\u044b [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-120608","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f Qualys \u0432\u044b\u044f\u0432\u0438\u043b\u0430 \u0442\u0440\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 \u0443\u0442\u0438\u043b\u0438\u0442\u0435 needrestart, \u043f\u0440\u0435\u0434\u043d\u0430\u0437\u043d\u0430\u0447\u0435\u043d\u043d\u043e\u0439 \u0434\u043b\u044f \u043f\u0435\u0440\u0435\u0437\u0430\u043f\u0443\u0441\u043a\u0430 \u0444\u043e\u043d\u043e\u0432\u044b\u0445 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u043e\u0432 \u043f\u043e\u0441\u043b\u0435 \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u044f \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u044b\u0445 \u0434\u0430\u043d\u043d\u044b\u043c\u0438 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430\u043c\u0438 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/it\/blog\/news\/uyazvimosti-v-utilite-needrestart-pozvolyayushhie-poluchit-root-dostup-v-ubuntu-server\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"it_IT\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 \u0443\u0442\u0438\u043b\u0438\u0442\u0435 needrestart, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0435 \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c root-\u0434\u043e\u0441\u0442\u0443\u043f \u0432 Ubuntu Server | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f Qualys \u0432\u044b\u044f\u0432\u0438\u043b\u0430 \u0442\u0440\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 \u0443\u0442\u0438\u043b\u0438\u0442\u0435 needrestart, \u043f\u0440\u0435\u0434\u043d\u0430\u0437\u043d\u0430\u0447\u0435\u043d\u043d\u043e\u0439 \u0434\u043b\u044f \u043f\u0435\u0440\u0435\u0437\u0430\u043f\u0443\u0441\u043a\u0430 \u0444\u043e\u043d\u043e\u0432\u044b\u0445 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u043e\u0432 \u043f\u043e\u0441\u043b\u0435 \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u044f \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u044b\u0445 \u0434\u0430\u043d\u043d\u044b\u043c\u0438 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430\u043c\u0438 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/it\/blog\/news\/uyazvimosti-v-utilite-needrestart-pozvolyayushhie-poluchit-root-dostup-v-ubuntu-server\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2024-11-19T23:09:18+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2024-11-19T23:09:18+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vulnerabilit\u00e0 nell'utility needrestart, che consentono di ottenere accesso root su Ubuntu Server | ProHoster","description":"L'azienda Qualys ha identificato tre vulnerabilit\u00e0 nell'utility needrestart, progettata per riavviare i processi in background dopo l'aggiornamento delle librerie utilizzate dai processi.","canonical_url":"https:\/\/prohoster.info\/it\/blog\/news\/uyazvimosti-v-utilite-needrestart-pozvolyayushhie-poluchit-root-dostup-v-ubuntu-server","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"it_IT","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 \u0443\u0442\u0438\u043b\u0438\u0442\u0435 needrestart, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0435 \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c root-\u0434\u043e\u0441\u0442\u0443\u043f \u0432 Ubuntu Server | ProHoster","og:description":"\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f Qualys \u0432\u044b\u044f\u0432\u0438\u043b\u0430 \u0442\u0440\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 \u0443\u0442\u0438\u043b\u0438\u0442\u0435 needrestart, \u043f\u0440\u0435\u0434\u043d\u0430\u0437\u043d\u0430\u0447\u0435\u043d\u043d\u043e\u0439 \u0434\u043b\u044f \u043f\u0435\u0440\u0435\u0437\u0430\u043f\u0443\u0441\u043a\u0430 \u0444\u043e\u043d\u043e\u0432\u044b\u0445 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u043e\u0432 \u043f\u043e\u0441\u043b\u0435 \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u044f \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u044b\u0445 \u0434\u0430\u043d\u043d\u044b\u043c\u0438 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430\u043c\u0438 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a.","og:url":"https:\/\/prohoster.info\/it\/blog\/news\/uyazvimosti-v-utilite-needrestart-pozvolyayushhie-poluchit-root-dostup-v-ubuntu-server","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2024-11-19T23:09:18+00:00","article:modified_time":"2024-11-19T23:09:18+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"120608","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-23 08:09:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2026-01-23 08:09:19","updated":"2026-01-23 08:09:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/120608","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/comments?post=120608"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/120608\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media?parent=120608"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/categories?post=120608"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/tags?post=120608"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}