{"id":73151,"date":"2020-03-07T14:42:03","date_gmt":"2020-03-07T11:42:03","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimost-v-pppd-i-lwip-pozvolyayushhaya-udalyonno-vypolnit-kod-s-pravami-root"},"modified":"2020-03-07T14:42:03","modified_gmt":"2020-03-07T11:42:03","slug":"uyazvimost-v-pppd-i-lwip-pozvolyayushhaya-udalyonno-vypolnit-kod-s-pravami-root","status":"publish","type":"post","link":"https:\/\/prohoster.info\/pl\/blog\/news\/uyazvimost-v-pppd-i-lwip-pozvolyayushhaya-udalyonno-vypolnit-kod-s-pravami-root","title":{"rendered":"Luka w pppd i lwIP, umo\u017cliwiaj\u0105ca zdalne wykonanie kodu z uprawnieniami root","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>W pakiecie pppd <noindex><a rel=\"nofollow\" href=\"https:\/\/seclists.org\/fulldisclosure\/2020\/Mar\/6\">wykryto<\/a><\/noindex> <noindex><a rel=\"nofollow\" href=\"https:\/\/www.kb.cert.org\/vuls\/id\/782301\/\">luka<\/a><\/noindex> (<noindex><a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2020-8597\">CVE-2020-8597<\/a><\/noindex>), co umo\u017cliwia wykonanie w\u0142asnego kodu poprzez wysy\u0142anie specjalnie sformatowanych zapyta\u0144 do system\u00f3w korzystaj\u0105cych z protoko\u0142u PPP (Point-to-Point Protocol) lub PPPoE (PPP over Ethernet). Te protoko\u0142y s\u0105 zazwyczaj wykorzystywane przez dostawc\u00f3w do organizowania po\u0142\u0105cze\u0144 przez Ethernet lub DSL, a tak\u017ce stosowane w niekt\u00f3rych VPN (na przyk\u0142ad, pptpd i <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/adrienverge\/openfortivpn\">openfortivpn<\/a><\/noindex>). Aby sprawdzi\u0107 podatno\u015b\u0107 swoich system\u00f3w na problem <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/marcinguy\/CVE-2020-8597\">przygotowano<\/a><\/noindex>  prototyp exploita.<\/p>\n<p>Vulnerability is caused by a buffer overflow in the implementation of the EAP (Extensible Authentication Protocol) authentication protocol. The attack can be carried out before the authentication stage by sending a packet with the type EAPT_MD5CHAP, which includes a very long hostname that does not fit in the allocated buffer. Due to an error in the size check for the rhostname field, an attacker can overwrite data beyond the buffer on the stack, achieving remote execution of their code with root privileges. The vulnerability manifests on both the server and client side, meaning that not only the server can be attacked, but also the client attempting to connect to a server controlled by the attacker (for example, the attacker may first exploit the server through this vulnerability and then start affecting connecting clients).<\/p>\n<p>Problem dotyczy wersji <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/paulusmack\/ppp\/\">pppd<\/a><\/noindex> od 2.4.2 do 2.4.8 w\u0142\u0105cznie i zosta\u0142a usuni\u0119ta w formie <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/paulusmack\/ppp\/commit\/8d7970b8f3db727fe798b65f3377fe6787575426\">\u0142atki<\/a><\/noindex>. Vulnerability is also <noindex><a rel=\"nofollow\" href=\"http:\/\/git.savannah.nongnu.org\/cgit\/lwip.git\/commit\/?id=2ee3cbe69c6d2805e64e7cac2a1c1706e49ffd86\">rozwi\u0105za\u0144 opartych na otwartym stosie UPnP<\/a><\/noindex> stosowa\u0107 <noindex><a rel=\"nofollow\" href=\"http:\/\/git.savannah.nongnu.org\/cgit\/lwip.git\/tree\/\">lwIP<\/a><\/noindex>, ale w domy\u015blnej konfiguracji lwIP nie ma wsparcia dla EAP.<\/p>\n<p> Status usuni\u0119cia problemu w dystrybucjach mo\u017cna zobaczy\u0107 na stronach: <noindex><a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2020-8597\">Debian<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/people.canonical.com\/~ubuntu-security\/cve\/2020\/CVE-2020-8597.html\">Ubuntu<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=CVE-2020-8597\">RHEL<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=1800734\">Fedora<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/bugzilla.suse.com\/show_bug.cgi?id=CVE-2020-8597\">SUSE<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/openwrt.org\/advisory\/2020-02-21-1\">OpenWRT<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/security.archlinux.org\/CVE-2020-8597\">Arch<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"http:\/\/ftp.netbsd.org\/pub\/NetBSD\/packages\/vulns\/pkg-vulnerabilities\">NetBSD<\/a><\/noindex>. W RHEL, OpenWRT i SUSE pakiet pppd jest skompilowany z w\u0142\u0105czon\u0105 ochron\u0105 \"Stack Smashing Protection\" (tryb \"-fstack-protector\" w gcc), co ogranicza mo\u017cliwo\u015b\u0107 wykorzystania awarii. Poza dystrybucjami, podatno\u015b\u0107 zosta\u0142a r\u00f3wnie\u017c potwierdzona w niekt\u00f3rych produktach <noindex><a rel=\"nofollow\" href=\"https:\/\/quickview.cloudapps.cisco.com\/quickview\/bug\/CSCvs95534\/\">Cisco<\/a><\/noindex> (CallManager), <noindex><a rel=\"nofollow\" href=\"https:\/\/www.tp-link.com\/en\/support\/faq\/2803\/\">TP-LINK<\/a><\/noindex>  i Synology (DiskStation Manager, VisualStation VS960HD i Router Manager), korzystaj\u0105cych z kodu pppd lub lwIP.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>\u0179r\u00f3d\u0142o: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=52498\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u043f\u0430\u043a\u0435\u0442\u0435 pppd \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2020-8597), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u0441\u0432\u043e\u0439 \u043a\u043e\u0434 \u0447\u0435\u0440\u0435\u0437 \u043e\u0442\u043f\u0440\u0430\u0432\u043a\u0443 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043e\u0444\u043e\u0440\u043c\u043b\u0435\u043d\u043d\u044b\u0445 \u0437\u0430\u043f\u0440\u043e\u0441\u043e\u0432 \u043d\u0430 \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u044e \u043a \u0441\u0438\u0441\u0442\u0435\u043c\u0430\u043c, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044e\u0449\u0438\u043c \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b PPP (Point-to-Point Protocol) \u0438\u043b\u0438 PPPoE (PPP over Ethernet). \u0414\u0430\u043d\u043d\u044b\u0435 \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u044b \u043e\u0431\u044b\u0447\u043d\u043e \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u044e\u0442\u0441\u044f \u043f\u0440\u043e\u0432\u0430\u0439\u0434\u0435\u0440\u0430\u043c\u0438 \u0434\u043b\u044f \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u0438 \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u044f \u0447\u0435\u0440\u0435\u0437 Ethernet \u0438\u043b\u0438 DSL, \u0430 \u0442\u0430\u043a\u0436\u0435 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044e\u0442\u0441\u044f \u0432 \u043d\u0435\u043a\u043e\u0442\u043e\u0440\u044b\u0445 VPN (\u043d\u0430\u043f\u0440\u0438\u043c\u0435\u0440, pptpd \u0438 openfortivpn). \u0414\u043b\u044f \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0438 \u043f\u043e\u0434\u0432\u0435\u0440\u0436\u0435\u043d\u043d\u043e\u0441\u0442\u0438 \u0441\u0432\u043e\u0438\u0445 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-73151","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u043f\u0430\u043a\u0435\u0442\u0435 pppd \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/pl\/blog\/news\/uyazvimost-v-pppd-i-lwip-pozvolyayushhaya-udalyonno-vypolnit-kod-s-pravami-root\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"pl_PL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 pppd \u0438 lwIP, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 root | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u043f\u0430\u043a\u0435\u0442\u0435 pppd \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/pl\/blog\/news\/uyazvimost-v-pppd-i-lwip-pozvolyayushhaya-udalyonno-vypolnit-kod-s-pravami-root\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-03-07T11:42:03+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-03-07T11:42:03+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Podatno\u015b\u0107 w pppd i lwIP, umo\u017cliwiaj\u0105ca zdalne wykonanie kodu z uprawnieniami root | ProHoster","description":"W pakiecie pppd zidentyfikowano podatno\u015b\u0107.","canonical_url":"https:\/\/prohoster.info\/pl\/blog\/news\/uyazvimost-v-pppd-i-lwip-pozvolyayushhaya-udalyonno-vypolnit-kod-s-pravami-root","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"pl_PL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 pppd \u0438 lwIP, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 root | ProHoster","og:description":"\u0412 \u043f\u0430\u043a\u0435\u0442\u0435 pppd \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c.","og:url":"https:\/\/prohoster.info\/pl\/blog\/news\/uyazvimost-v-pppd-i-lwip-pozvolyayushhaya-udalyonno-vypolnit-kod-s-pravami-root","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-03-07T11:42:03+00:00","article:modified_time":"2020-03-07T11:42:03+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"73151","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 18:38:40","updated":"2022-09-28 04:48:21","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/posts\/73151","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/comments?post=73151"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/posts\/73151\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/media?parent=73151"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/categories?post=73151"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/tags?post=73151"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}