{"id":106239,"date":"2022-12-22T15:36:49","date_gmt":"2022-12-22T13:36:49","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimost-v-systemd-coredump-pozvolyayushhaya-opredelit-soderzhimoe-pamyati-suid-programm"},"modified":"2022-12-22T15:36:49","modified_gmt":"2022-12-22T13:36:49","slug":"uyazvimost-v-systemd-coredump-pozvolyayushhaya-opredelit-soderzhimoe-pamyati-suid-programm","status":"publish","type":"post","link":"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimost-v-systemd-coredump-pozvolyayushhaya-opredelit-soderzhimoe-pamyati-suid-programm","title":{"rendered":"Vulnerabilitate \u00een systemd-coredump, care permite determinarea con\u021binutului memoriei programelor suid","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>\u00cen componenta systemd-coredump, care asigur\u0103 procesarea fi\u0219ierelor core generate dup\u0103 \u00eencheierea anormal\u0103 a proceselor, a fost descoperit\u0103 o vulnerabilitate (CVE-2022-4415) care permite unui utilizator local f\u0103r\u0103 privilegii s\u0103 determine con\u021binutul memoriei proceselor privilegiate, lansate cu flag-ul suid root. Prezen\u021ba problemei \u00een configura\u021bia implicit\u0103 a fost confirmat\u0103 \u00een distribu\u021biile openSUSE, Arch, Debian, Fedora \u0219i SLES.        <\/p>\n<p>Vulnerabilitatea este cauzat\u0103 de absen\u021ba unei prelucr\u0103ri corecte a parametrului sysctl fs.suid_dumpable \u00een systemd-coredump, care, \u00een cazul \u00een care este setat la valoarea implicit\u0103 2, permite generarea de core-dumps pentru celelalte procese cu flag-ul suid. Se presupune c\u0103 fi\u0219ierele core scrise de kernel pentru procesele suid ar trebui s\u0103 aib\u0103 permisiuni de acces care permit citirea doar utilizatorului root. Utilitarul systemd-coredump, care este invocat de kernel pentru a salva fi\u0219ierele core, salveaz\u0103 fi\u0219ierul core sub identificatorul root, dar \u00een plus ofer\u0103 acces la fi\u0219ierele core pe baza ACL, permi\u021b\u00e2nd citirea pe baza identificatorului proprietar care a lansat ini\u021bial procesul.      <\/p>\n<p>Aceast\u0103 caracteristic\u0103 permite \u00eenc\u0103rcarea fi\u0219ierelor core f\u0103r\u0103 a \u021bine cont de faptul c\u0103 programul poate schimba identificatorul utilizatorului \u0219i s\u0103 ruleze cu privilegii ridicate. Atacul const\u0103 \u00een faptul c\u0103 utilizatorul poate lansa o aplica\u021bie suid \u0219i s\u0103-i trimit\u0103 un semnal SIGSEGV, dup\u0103 care poate \u00eenc\u0103rca con\u021binutul fi\u0219ierului core, care include un e\u0219antion al memoriei procesului \u00een timpul \u00eencheierii sale anormale.     <\/p>\n<p>De exemplu, utilizatorul poate rula &#171;\\\/usr\\\/bin\\\/su&#187; \u0219i \u00een alt terminal poate termina execu\u021bia cu comanda &#171;kill -s SIGSEGV `pidof su`&#187;, dup\u0103 care systemd-coredump va salva fi\u0219ierul core \u00een directorul \\\/var\\\/lib\\\/systemd\\\/coredump, stabilind un ACL care permite citirea utilizatorului curent. Deoarece utilitarul suid &#8216;su&#8217; cite\u0219te \u00een memorie con\u021binutul \\\/etc\\\/shadow, atacatorul poate ob\u021bine acces la informa\u021biile despre hash-urile parolelor tuturor utilizatorilor din sistem. Utilitarul sudo nu este vulnerabil la atac, deoarece interzice generarea fi\u0219ierelor core prin ulimit.            <\/p>\n<p>Potrivit dezvoltatorilor systemd, vulnerabilitatea apare \u00eencep\u00e2nd cu versiunea systemd 247 (noiembrie 2020), dar, conform cercet\u0103torului care a descoperit problema, versiunea 246 este de asemenea afectat\u0103. Vulnerabilitatea se manifest\u0103 dac\u0103 systemd este compilat cu biblioteca libacl (care este implicit \u00een toate distribu\u021biile populare). Ocorectare este disponibil\u0103 momentan sub form\u0103 de patch. Pute\u021bi urm\u0103ri corect\u0103rile \u00een distribu\u021bii pe urm\u0103toarele pagini: Debian, Ubuntu, Gentoo, RHEL, SUSE, Fedora, Gentoo, Arch. Ca m\u0103sur\u0103 temporar\u0103 de protec\u021bie, se poate seta sysctl fs.suid_dumpable la valoarea 0, dezactiv\u00e2nd transmiterea dump-urilor c\u0103tre handler-ul systemd-coredump.<br \/>\n<br \/>Sursa: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=58373\">opennet.ro<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u043a\u043e\u043c\u043f\u043e\u043d\u0435\u043d\u0442\u0435 systemd-coredump, \u043e\u0431\u0435\u0441\u043f\u0435\u0447\u0438\u0432\u0430\u044e\u0449\u0435\u043c \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0443 core-\u0444\u0430\u0439\u043b\u043e\u0432, \u0433\u0435\u043d\u0435\u0440\u0438\u0440\u0443\u0435\u043c\u044b\u0445 \u043f\u043e\u0441\u043b\u0435 \u0430\u0432\u0430\u0440\u0438\u0439\u043d\u043e\u0433\u043e \u0437\u0430\u0432\u0435\u0440\u0448\u0435\u043d\u0438\u044f \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u043e\u0432, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2022-4415), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043d\u0435\u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u043c\u0443 \u043b\u043e\u043a\u0430\u043b\u044c\u043d\u043e\u043c\u0443 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e \u043e\u043f\u0440\u0435\u0434\u0435\u043b\u0438\u0442\u044c \u0441\u043e\u0434\u0435\u0440\u0436\u0438\u043c\u043e\u0435 \u043f\u0430\u043c\u044f\u0442\u0438 \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u0445 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u043e\u0432, \u0437\u0430\u043f\u0443\u0449\u0435\u043d\u043d\u044b\u0445 \u0441 \u0444\u043b\u0430\u0433\u043e\u043c suid root. \u041d\u0430\u043b\u0438\u0447\u0438\u0435 \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u044b \u0432 \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u0438 \u043f\u043e \u0443\u043c\u043e\u043b\u0447\u0430\u043d\u0438\u044e \u043f\u043e\u0434\u0442\u0432\u0435\u0440\u0436\u0434\u0435\u043d\u043e \u0432 \u0434\u0438\u0441\u0442\u0440\u0438\u0431\u0443\u0442\u0438\u0432\u0430\u0445 openSUSE, Arch, Debian, Fedora \u0438 SLES. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432\u044b\u0437\u0432\u0430\u043d\u0430 \u043e\u0442\u0441\u0443\u0442\u0441\u0442\u0432\u0438\u0435\u043c \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u043d\u043e\u0439 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0438 sysctl-\u043f\u0430\u0440\u0430\u043c\u0435\u0442\u0440\u0430 fs.suid_dumpable \u0432 systemd-coredump, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u043f\u0440\u0438 \u0432\u044b\u0441\u0442\u0430\u0432\u043b\u0435\u043d\u043d\u043e\u043c [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-106239","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u043a\u043e\u043c\u043f\u043e\u043d\u0435\u043d\u0442\u0435 systemd-coredump, \u043e\u0431\u0435\u0441\u043f\u0435\u0447\u0438\u0432\u0430\u044e\u0449\u0435\u043c \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0443 core-\u0444\u0430\u0439\u043b\u043e\u0432, \u0433\u0435\u043d\u0435\u0440\u0438\u0440\u0443\u0435\u043c\u044b\u0445 \u043f\u043e\u0441\u043b\u0435 \u0430\u0432\u0430\u0440\u0438\u0439\u043d\u043e\u0433\u043e \u0437\u0430\u0432\u0435\u0440\u0448\u0435\u043d\u0438\u044f \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u043e\u0432, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2022-4415), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043d\u0435\u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u043c\u0443 \u043b\u043e\u043a\u0430\u043b\u044c\u043d\u043e\u043c\u0443 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimost-v-systemd-coredump-pozvolyayushhaya-opredelit-soderzhimoe-pamyati-suid-programm\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"ro_RO\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 systemd-coredump, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043e\u043f\u0440\u0435\u0434\u0435\u043b\u0438\u0442\u044c \u0441\u043e\u0434\u0435\u0440\u0436\u0438\u043c\u043e\u0435 \u043f\u0430\u043c\u044f\u0442\u0438 suid-\u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u043a\u043e\u043c\u043f\u043e\u043d\u0435\u043d\u0442\u0435 systemd-coredump, \u043e\u0431\u0435\u0441\u043f\u0435\u0447\u0438\u0432\u0430\u044e\u0449\u0435\u043c \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0443 core-\u0444\u0430\u0439\u043b\u043e\u0432, \u0433\u0435\u043d\u0435\u0440\u0438\u0440\u0443\u0435\u043c\u044b\u0445 \u043f\u043e\u0441\u043b\u0435 \u0430\u0432\u0430\u0440\u0438\u0439\u043d\u043e\u0433\u043e \u0437\u0430\u0432\u0435\u0440\u0448\u0435\u043d\u0438\u044f \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u043e\u0432, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2022-4415), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043d\u0435\u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u043c\u0443 \u043b\u043e\u043a\u0430\u043b\u044c\u043d\u043e\u043c\u0443 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimost-v-systemd-coredump-pozvolyayushhaya-opredelit-soderzhimoe-pamyati-suid-programm\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2022-12-22T13:36:49+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2022-12-22T13:36:49+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vulnerabilitate \u00een systemd-coredump, care permite accesarea con\u021binutului memoriei programelor suid | ProHoster","description":"\u00cen componenta systemd-coredump, responsabil\u0103 pentru gestionarea fi\u0219ierelor core generate dup\u0103 finalizarea necontrolat\u0103 a proceselor, a fost identificat\u0103 o vulnerabilitate (CVE-2022-4415) care permite unui utilizator local neprivilegiat.","canonical_url":"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimost-v-systemd-coredump-pozvolyayushhaya-opredelit-soderzhimoe-pamyati-suid-programm","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"ro_RO","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 systemd-coredump, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043e\u043f\u0440\u0435\u0434\u0435\u043b\u0438\u0442\u044c \u0441\u043e\u0434\u0435\u0440\u0436\u0438\u043c\u043e\u0435 \u043f\u0430\u043c\u044f\u0442\u0438 suid-\u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c | ProHoster","og:description":"\u0412 \u043a\u043e\u043c\u043f\u043e\u043d\u0435\u043d\u0442\u0435 systemd-coredump, \u043e\u0431\u0435\u0441\u043f\u0435\u0447\u0438\u0432\u0430\u044e\u0449\u0435\u043c \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0443 core-\u0444\u0430\u0439\u043b\u043e\u0432, \u0433\u0435\u043d\u0435\u0440\u0438\u0440\u0443\u0435\u043c\u044b\u0445 \u043f\u043e\u0441\u043b\u0435 \u0430\u0432\u0430\u0440\u0438\u0439\u043d\u043e\u0433\u043e \u0437\u0430\u0432\u0435\u0440\u0448\u0435\u043d\u0438\u044f \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u043e\u0432, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2022-4415), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043d\u0435\u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u043c\u0443 \u043b\u043e\u043a\u0430\u043b\u044c\u043d\u043e\u043c\u0443 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e.","og:url":"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimost-v-systemd-coredump-pozvolyayushhaya-opredelit-soderzhimoe-pamyati-suid-programm","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2022-12-22T13:36:49+00:00","article:modified_time":"2022-12-22T13:36:49+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":[],"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/106239","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/comments?post=106239"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/106239\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/media?parent=106239"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/categories?post=106239"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/tags?post=106239"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}