{"id":106404,"date":"2023-01-19T06:48:10","date_gmt":"2023-01-19T04:48:10","guid":{"rendered":"https:\/\/prohoster.info\/?p=106404"},"modified":"2023-01-19T14:02:40","modified_gmt":"2023-01-19T12:02:40","slug":"dve-uyazvimosti-v-git-sposobnye-privesti-k-udalyonnomu-vypolneniyu-koda","status":"publish","type":"post","link":"https:\/\/prohoster.info\/ro\/blog\/news\/dve-uyazvimosti-v-git-sposobnye-privesti-k-udalyonnomu-vypolneniyu-koda","title":{"rendered":"Dou\u0103 vulnerabilit\u0103\u021bi \u00een Git care ar putea duce la executarea de cod de la distan\u021b\u0103","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Au fost publicate versiunile corective ale sistemului distribuit de gestionare a codului surs\u0103 Git 2.39.1, 2.38.3, 2.37.5, 2.36.4, 2.35.6, 2.34.6, 2.33.6, 2.32.5, 2.31.6 \u0219i 2.30.7, \u00een care au fost rezolvate dou\u0103 vulnerabilit\u0103\u021bi ce permit executarea de cod neautorizat pe sistemul utilizatorului prin utilizarea comenzii &#171;git archive&#187; \u0219i \u00een lucrul cu repozitorii externe necontrolate. Vulnerabilit\u0103\u021bile sunt cauzate de erori \u00een codul de formatare al commit-urilor \u0219i \u00een analiza fi\u0219ierului &#171;.gitattributes&#187;, care, atunci c\u00e2nd sunt procesate \u00een repozitorii externe, pot duce la scrierea \u00een zona de memorie dincolo de heap \u0219i citirea datelor aleatorii din memorie.       <\/p>\n<p>Ambele vulnerabilit\u0103\u021bi au fost identificate \u00een cadrul unui audit de securitate al codului surs\u0103 Git, efectuat de compania X41 la cererea Funda\u021biei OSTIF (Open Source Technology Improvement Fund), creat\u0103 pentru a \u00eent\u0103ri securitatea proiectelor deschise. Pe l\u00e2ng\u0103 cele dou\u0103 probleme critice discutate mai jos, auditul a identificat de asemenea o vulnerabilitate periculoas\u0103, una cu un risc mediu \u0219i patru probleme minore. Au fost de asemenea f\u0103cute 27 de recomand\u0103ri pentru \u00eembun\u0103t\u0103\u021birea securit\u0103\u021bii codului.    <\/p>\n<ul>\n<li class=\"l\"> CVE-2022-41903: overflow de numere \u00eentregi \u00een codul de formatare a informa\u021biilor despre commit, care apare atunci c\u00e2nd se proceseaz\u0103 valori mari de offset \u00een operatorii de completare, cum ar fi &#171;%&lt;(&#171;, &#171;%&lt;|(&#171;, &#171;%&gt;(&#171;, &#171;%&gt;&gt;(&#187; \u0219i &#171;%&gt;&lt;( )&#187;. Overflow-ul de numere \u00eentregi apare \u00een func\u021bia format_and_pad_commit() din cauza utiliz\u0103rii tipului int pentru variabila size_t, care particip\u0103 la definirea dimensiunii blocului copiat \u00een apelul memcpy().\n<p>Vulnerabilitatea se manifest\u0103 at\u00e2t \u00een cazul apelurilor directe cu parametrii de formatare special preg\u0103ti\u021bi (de exemplu, atunci c\u00e2nd se ruleaz\u0103 &#171;git log &#8212;format=&#8230;&#187;), c\u00e2t \u0219i \u00een cazul utiliz\u0103rii indirecte a formatarea \u00een timpul execut\u0103rii comenzii &#171;git archive&#187; \u00eentr-un repozitoriu controlat de atacator. \u00cen acest din urm\u0103 caz, modificatorii de formatare sunt defini\u021bi prin parametrul export-subst din fi\u0219ierul &#171;.gitattributes&#187;, care poate fi plasat de atacator \u00een propriul s\u0103u repozitoriu. Problema poate fi utilizat\u0103 pentru a citi \u0219i scrie \u00een zone aleatorii \u00een heap \u0219i poate duce la executarea codului atacatorului atunci c\u00e2nd se lucreaz\u0103 cu repozitorii neverificate.    <\/p>\n<li class=\"l\"> CVE-2022-23521: overflow de numere \u00eentregi \u00een analiza con\u021binutului fi\u0219ierelor &#171;.gitattributes&#187; din repozitoriu, manifest\u00e2ndu-se atunci c\u00e2nd se proceseaz\u0103 un num\u0103r foarte mare de modele de c\u0103i de fi\u0219iere sau un num\u0103r mare de atribute cu un singur model, precum \u0219i \u00een analiza unor nume de atribute foarte mari. Problema poate fi utilizat\u0103 pentru a citi \u0219i scrie \u00een zone aleatorii \u00een heap \u0219i poate duce la executarea codului atacatorului c\u00e2nd se lucreaz\u0103 cu un repozitoriu necontrolat, \u00een care atacatorul poate plasa un fi\u0219ier .gitattributes special preg\u0103tit \u0219i asigura c\u0103 acesta este inclus \u00een index.  <\/ul>\n<p>Urm\u0103rirea public\u0103rii actualiz\u0103rilor pachetelor \u00een distribu\u021biile poate fi realizat\u0103 pe paginile: Debian, Ubuntu, Gentoo, RHEL, SUSE, Arch, FreeBSD, NetBSD. Pentru a reduce riscul de atac, \u00een cazul \u00een care actualizarea nu poate fi instalat\u0103 la timp, se recomand\u0103 evitarea lucrului cu repositoare nesigure \u0219i utilizarea comenzii &#171;git archive&#187;. Este important de re\u021binut c\u0103 comanda &#171;git archive&#187; poate fi lansat\u0103 \u00een mod implicit, de exemplu, din git daemon. Pentru a dezactiva lansarea &#171;git archive&#187; \u00een git daemon, trebuie modificat parametru daemon.uploadArch cu comanda &#171;git config &#8212;global daemon.uploadArch false&#187;.          <\/p>\n<p>De asemenea, putem men\u021biona o alt\u0103 vulnerabilitate (CVE-2022-41953) \u00een produsul Git for Windows, care permite executarea codului la clonarea prin interfa\u021ba grafic\u0103 a repositoarelor externe neverificate. Problema este cauzat\u0103 de faptul c\u0103 Git GUI pentru Windows, dup\u0103 opera\u021bia &#171;checkout&#187;, lanseaz\u0103 automat anumite comenzi de procesare, cum ar fi executarea programului de verificare a ortografiei (spell-check), av\u00e2nd \u00een vedere c\u0103 c\u0103ile de c\u0103utare pentru fi\u0219ierul spell-check acoper\u0103 \u0219i arborele de lucru clonat (atacul se rezum\u0103 la ad\u0103ugarea spell-check \u00een arborele de lucru al repositoarului).<br \/>\n<br \/>Sursa: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=58498\">opennet.ro<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d\u044b \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u0438\u0440\u0443\u044e\u0449\u0438\u0435 \u0432\u044b\u043f\u0443\u0441\u043a\u0438 \u0440\u0430\u0441\u043f\u0440\u0435\u0434\u0435\u043b\u0451\u043d\u043d\u043e\u0439 \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u0443\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u044f \u0438\u0441\u0445\u043e\u0434\u043d\u044b\u043c\u0438 \u0442\u0435\u043a\u0441\u0442\u0430\u043c\u0438 Git 2.39.1, 2.38.3, 2.37.5, 2.36.4, 2.35.6, 2.34.6, 2.33.6, 2.32.5, 2.31.6 \u0438 2.30.7, \u0432 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u044b \u0434\u0432\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0435 \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u043e\u0432\u0430\u0442\u044c \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0435 \u0441\u0432\u043e\u0435\u0433\u043e \u043a\u043e\u0434\u0430 \u043d\u0430 \u0441\u0438\u0441\u0442\u0435\u043c\u0435 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f \u043f\u0440\u0438 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0438 \u043a\u043e\u043c\u0430\u043d\u0434\u044b &#171;git archive&#187; \u0438 \u0440\u0430\u0431\u043e\u0442\u0435 \u0441 \u043d\u0435 \u0437\u0430\u0441\u043b\u0443\u0436\u0438\u0432\u0430\u044e\u0449\u0438\u043c\u0438 \u0434\u043e\u0432\u0435\u0440\u0438\u044f \u0432\u043d\u0435\u0448\u043d\u0438\u043c\u0438 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u044f\u043c\u0438. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432\u044b\u0437\u0432\u0430\u043d\u044b \u043e\u0448\u0438\u0431\u043a\u0430\u043c\u0438 \u0432 \u043a\u043e\u0434\u0435 \u0444\u043e\u0440\u043c\u0430\u0442\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u043a\u043e\u043c\u043c\u0438\u0442\u043e\u0432 \u0438 \u0440\u0430\u0437\u0431\u043e\u0440\u0435 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-106404","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d\u044b \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u0438\u0440\u0443\u044e\u0449\u0438\u0435 \u0432\u044b\u043f\u0443\u0441\u043a\u0438 \u0440\u0430\u0441\u043f\u0440\u0435\u0434\u0435\u043b\u0451\u043d\u043d\u043e\u0439 \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u0443\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u044f \u0438\u0441\u0445\u043e\u0434\u043d\u044b\u043c\u0438 \u0442\u0435\u043a\u0441\u0442\u0430\u043c\u0438 Git 2.39.1, 2.38.3, 2.37.5, 2.36.4, 2.35.6, 2.34.6, 2.33.6, 2.32.5, 2.31.6 \u0438 2.30.7, \u0432 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u044b \u0434\u0432\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/ro\/blog\/news\/dve-uyazvimosti-v-git-sposobnye-privesti-k-udalyonnomu-vypolneniyu-koda\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"ro_RO\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0414\u0432\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 Git, \u0441\u043f\u043e\u0441\u043e\u0431\u043d\u044b\u0435 \u043f\u0440\u0438\u0432\u0435\u0441\u0442\u0438 \u043a \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e\u043c\u0443 \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044e \u043a\u043e\u0434\u0430 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d\u044b \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u0438\u0440\u0443\u044e\u0449\u0438\u0435 \u0432\u044b\u043f\u0443\u0441\u043a\u0438 \u0440\u0430\u0441\u043f\u0440\u0435\u0434\u0435\u043b\u0451\u043d\u043d\u043e\u0439 \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u0443\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u044f \u0438\u0441\u0445\u043e\u0434\u043d\u044b\u043c\u0438 \u0442\u0435\u043a\u0441\u0442\u0430\u043c\u0438 Git 2.39.1, 2.38.3, 2.37.5, 2.36.4, 2.35.6, 2.34.6, 2.33.6, 2.32.5, 2.31.6 \u0438 2.30.7, \u0432 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u044b \u0434\u0432\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/ro\/blog\/news\/dve-uyazvimosti-v-git-sposobnye-privesti-k-udalyonnomu-vypolneniyu-koda\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2023-01-19T04:48:10+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2023-01-19T12:02:40+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Dou\u0103 vulnerabilit\u0103\u021bi \u00een Git, capabile s\u0103 conduc\u0103 la executarea de cod de la distan\u021b\u0103 | ProHoster","description":"Au fost publicate versiuni de corectare pentru sistemul distribuit de gestionare a codului surs\u0103 Git 2.39.1, 2.38.3, 2.37.5, 2.36.4, 2.35.6, 2.34.6, 2.33.6, 2.32.5, 2.31.6 \u0219i 2.30.7, \u00een care au fost remediate dou\u0103 vulnerabilit\u0103\u021bi.","canonical_url":"https:\/\/prohoster.info\/ro\/blog\/news\/dve-uyazvimosti-v-git-sposobnye-privesti-k-udalyonnomu-vypolneniyu-koda","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"ro_RO","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0414\u0432\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 Git, \u0441\u043f\u043e\u0441\u043e\u0431\u043d\u044b\u0435 \u043f\u0440\u0438\u0432\u0435\u0441\u0442\u0438 \u043a \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e\u043c\u0443 \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044e \u043a\u043e\u0434\u0430 | ProHoster","og:description":"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d\u044b \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u0438\u0440\u0443\u044e\u0449\u0438\u0435 \u0432\u044b\u043f\u0443\u0441\u043a\u0438 \u0440\u0430\u0441\u043f\u0440\u0435\u0434\u0435\u043b\u0451\u043d\u043d\u043e\u0439 \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u0443\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u044f \u0438\u0441\u0445\u043e\u0434\u043d\u044b\u043c\u0438 \u0442\u0435\u043a\u0441\u0442\u0430\u043c\u0438 Git 2.39.1, 2.38.3, 2.37.5, 2.36.4, 2.35.6, 2.34.6, 2.33.6, 2.32.5, 2.31.6 \u0438 2.30.7, \u0432 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u044b \u0434\u0432\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438.","og:url":"https:\/\/prohoster.info\/ro\/blog\/news\/dve-uyazvimosti-v-git-sposobnye-privesti-k-udalyonnomu-vypolneniyu-koda","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2023-01-19T04:48:10+00:00","article:modified_time":"2023-01-19T12:02:40+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":[],"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/106404","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/comments?post=106404"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/106404\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/media?parent=106404"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/categories?post=106404"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/tags?post=106404"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}