{"id":37361,"date":"2019-10-31T22:17:12","date_gmt":"2019-10-31T19:17:12","guid":{"rendered":"https:\/\/prohoster.info\/blog\/udalyonnaya-dos-uyazvimost-v-ipv6-steke-freebsd\/"},"modified":"2019-10-31T22:17:12","modified_gmt":"2019-10-31T19:17:12","slug":"udalyonnaya-dos-uyazvimost-v-ipv6-steke-freebsd","status":"publish","type":"post","link":"https:\/\/prohoster.info\/it\/blog\/news\/udalyonnaya-dos-uyazvimost-v-ipv6-steke-freebsd","title":{"rendered":"Vulnerabilit\u00e0 DoS remota nello stack IPv6 di FreeBSD","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>In FreeBSD <noindex><a rel=\"nofollow\" href=\"https:\/\/lists.freebsd.org\/pipermail\/freebsd-announce\/2019-August\/001908.html\">\u00e8 stato risolto<\/a><\/noindex> una vulnerabilit\u00e0 (CVE-2019-5611) che consente di causare un crash del kernel (packet-of-death) inviando pacchetti ICMPv6 MLD appositamente frammentati (<noindex><a rel=\"nofollow\" href=\"https:\/\/tools.ietf.org\/html\/rfc2710\">Multicast Listener Discovery<\/a><\/noindex>). Il problema <noindex><a rel=\"nofollow\" href=\"https:\/\/www.reddit.com\/r\/BSD\/comments\/c4krwr\/freebsd_ipv6_remote_dingdong_attack_kernel_panic\/\">causato<\/a><\/noindex> \u00e8 l'assenza di un'adeguata verifica nella chiamata a m_pulldown(), il che pu\u00f2 portare al ritorno di catene mbufs non continue, contrariamente alle aspettative della parte chiamante.<\/p>\n<p>Vulnerabilit\u00e0 <noindex><a rel=\"nofollow\" href=\"https:\/\/svnweb.freebsd.org\/base?view=revision&#038;revision=350815\">\u00e8 stato risolto<\/a><\/noindex> nelle versioni 12.0-RELEASE-p10, 11.3-RELEASE-p3 e 11.2-RELEASE-p14. Come soluzione alternativa per la protezione, \u00e8 possibile disattivare il supporto per la frammentazione di IPv6 o filtrare tramite firewall le opzioni nell'intestazione <noindex><a rel=\"nofollow\" href=\"https:\/\/tools.ietf.org\/html\/draft-ietf-6man-hbh-header-handling-03\">HBH<\/a><\/noindex> (Hop-by-Hop). \u00c8 interessante notare che l'errore che porta alla vulnerabilit\u00e0 \u00e8 stato identificato gi\u00e0 nel 2006 ed \u00e8 stato corretto in OpenBSD, NetBSD e macOS, ma \u00e8 rimasto non risolto in FreeBSD, nonostante gli sviluppatori di FreeBSD siano stati avvisati del problema.<\/p>\n<p>Si possono inoltre notare la risoluzione di altre due vulnerabilit\u00e0 in FreeBSD:<\/p>\n<ul>\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/lists.freebsd.org\/pipermail\/freebsd-announce\/2019-August\/001910.html\">CVE-2019-5603<\/a><\/noindex> \u2014 overflow of the link counter in data structures in mqueuefs when using 32-bit libraries in a 64-bit environment (32-bit compat). The issue arises when mqueuefs is enabled, which is not active by default, and can lead to access to files, directories, and sockets opened by processes belonging to other users, or to organize access to external files from a jail environment. If the user has root access in the jail, the vulnerability allows obtaining root access on the host environment.\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/lists.freebsd.org\/pipermail\/freebsd-announce\/2019-August\/001909.html\">CVE-2019-5612<\/a><\/noindex> \u2014 issue with multithreaded access to the device \/dev\/midistat in the event of a race condition may lead to reading kernel memory areas outside the bounds allocated for the midistat buffer. On 32-bit systems, attempts to exploit the vulnerability lead to kernel crashes, while on 64-bit systems it allows reading the contents of arbitrary kernel memory areas.\n<\/ul>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Fonte: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51332\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412\u043e FreeBSD \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2019-5611), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0432\u044b\u0437\u0432\u0430\u0442\u044c \u043a\u0440\u0430\u0445 \u044f\u0434\u0440\u0430 (packet-of-death) \u0447\u0435\u0440\u0435\u0437 \u043e\u0442\u043f\u0440\u0430\u0432\u043a\u0443 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u0444\u0440\u0430\u0433\u043c\u0435\u043d\u0442\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u0445 \u043f\u0430\u043a\u0435\u0442\u043e\u0432 ICMPv6 MLD (Multicast Listener Discovery). \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u0432\u044b\u0437\u0432\u0430\u043d\u0430 \u043e\u0442\u0441\u0443\u0442\u0441\u0442\u0432\u0438\u0435\u043c \u043d\u0435\u043e\u0431\u0445\u043e\u0434\u0438\u043c\u043e\u0439 \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0438 \u0432 \u0432\u044b\u0437\u043e\u0432\u0435 m_pulldown(), \u0447\u0442\u043e \u043c\u043e\u0436\u0435\u0442 \u043f\u0440\u0438\u0432\u0435\u0441\u0442\u0438 \u043a \u0432\u043e\u0437\u0432\u0440\u0430\u0442\u0443 \u043d\u0435 \u043d\u0435\u043f\u0440\u0435\u0440\u044b\u0432\u043d\u044b\u0445 \u0446\u0435\u043f\u043e\u0447\u0435\u043a mbufs, \u0432\u043e\u043f\u0440\u0435\u043a\u0438 \u043e\u0436\u0438\u0434\u0430\u043d\u0438\u044f \u0432\u044b\u0437\u044b\u0432\u0430\u044e\u0449\u0435\u0439 \u0441\u0442\u043e\u0440\u043e\u043d\u044b. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0430 \u0432 \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u044f\u0445 12.0-RELEASE-p10, 11.3-RELEASE-p3 \u0438 11.2-RELEASE-p14. \u0412 \u043a\u0430\u0447\u0435\u0441\u0442\u0432\u0435 \u043e\u0431\u0445\u043e\u0434\u043d\u043e\u0433\u043e \u043f\u0443\u0442\u0438 \u0437\u0430\u0449\u0438\u0442\u044b \u043c\u043e\u0436\u043d\u043e [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-37361","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412\u043e FreeBSD \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2019-5611), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0432\u044b\u0437\u0432\u0430\u0442\u044c \u043a\u0440\u0430\u0445 \u044f\u0434\u0440\u0430.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/it\/blog\/news\/udalyonnaya-dos-uyazvimost-v-ipv6-steke-freebsd\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"it_IT\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u0434\u0430\u043b\u0451\u043d\u043d\u0430\u044f DoS-\u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 IPv6-\u0441\u0442\u0435\u043a\u0435 FreeBSD | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412\u043e FreeBSD \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2019-5611), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0432\u044b\u0437\u0432\u0430\u0442\u044c \u043a\u0440\u0430\u0445 \u044f\u0434\u0440\u0430.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/it\/blog\/news\/udalyonnaya-dos-uyazvimost-v-ipv6-steke-freebsd\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:17:12+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T19:17:12+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47 Vulnerabilit\u00e0 DoS remota nello stack IPv6 di FreeBSD | ProHoster","description":"In FreeBSD \u00e8 stata corretta la vulnerabilit\u00e0 (CVE-2019-5611) che permette di causare un crash del kernel.","canonical_url":"https:\/\/prohoster.info\/it\/blog\/news\/udalyonnaya-dos-uyazvimost-v-ipv6-steke-freebsd","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"it_IT","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u0434\u0430\u043b\u0451\u043d\u043d\u0430\u044f DoS-\u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 IPv6-\u0441\u0442\u0435\u043a\u0435 FreeBSD | ProHoster","og:description":"\u0412\u043e FreeBSD \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2019-5611), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0432\u044b\u0437\u0432\u0430\u0442\u044c \u043a\u0440\u0430\u0445 \u044f\u0434\u0440\u0430.","og:url":"https:\/\/prohoster.info\/it\/blog\/news\/udalyonnaya-dos-uyazvimost-v-ipv6-steke-freebsd","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:17:12+00:00","article:modified_time":"2019-10-31T19:17:12+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"37361","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-23 17:29:49","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 01:28:27","updated":"2026-01-23 17:29:49","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/37361","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/comments?post=37361"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/37361\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media?parent=37361"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/categories?post=37361"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/tags?post=37361"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}