{"id":109367,"date":"2023-07-12T21:10:19","date_gmt":"2023-07-12T19:10:19","guid":{"rendered":"https:\/\/prohoster.info\/?p=109367"},"modified":"2023-07-13T09:57:04","modified_gmt":"2023-07-13T07:57:04","slug":"uyazvimosti-v-redis-ghostscript-asterisk-i-parse-server","status":"publish","type":"post","link":"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimosti-v-redis-ghostscript-asterisk-i-parse-server","title":{"rendered":"Vulnerabilit\u0103\u021bi \u00een Redis, Ghostscript, Asterisk \u0219i Parse Server","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>C\u00e2teva vulnerabilit\u0103\u021bi periculoase recent descoperite:  <\/p>\n<ul>\n<li class=\"l\"> CVE-2022-24834 \u2014 o vulnerabilitate \u00een baza de date Redis, care permite provocarea unui overflow de buffer \u00een bibliotecile cjson \u0219i cmsgpack prin executarea unui script special formulat \u00een limba Lua. Vulnerabilitatea poate duce poten\u021bial la execu\u021bia de cod de la distan\u021b\u0103 pe <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/ro\/server\/dts-newyork\/\"   title=\"server\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"2763\">server<\/a>. Problema apare \u00eencep\u00e2nd cu Redis 2.6 \u0219i a fost remediat\u0103 \u00een versiunile 7.0.12, 6.2.13 \u0219i 6.0.20. Ca solu\u021bie de protec\u021bie, utilizatorii Redis pot fi interzi\u0219i prin ACL s\u0103 execute comenzi EVAL \u0219i EVALSHA.\n<li class=\"l\"> CVE-2023-36824 \u2014 vulnerabilitate \u00een SGBD-ul Redis care conduce la o dep\u0103\u0219ire de buffer atunci c\u00e2nd se prelucreaz\u0103 numele cheilor transmise prin comanda COMMAND GETKEYS sau COMMAND GETKEYSANDFLAGS, precum \u0219i listele de chei din regulile ACL. Vulnerabilitatea poate conduce, poten\u021bial, la execu\u021bia de cod de la distan\u021b\u0103 pe server. Problema apare doar \u00een ramura 7.0.x \u0219i a fost remediat\u0103 \u00een versiunea 7.0.12.\n<li class=\"l\"> CVE-2022-23537 \u2014 o vulnerabilitate \u00een platforma de comunica\u021bie Asterisk, care duce la un overflow de buffer \u00een timpul analizei <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/ro\/server\/dts-prohoster\/\"   title=\"serverul\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"3076\">serverul<\/a> mesaje STUN formattate special, care con\u021bin un atribut necunoscut. Problema apare la folosirea protocolului ICE sau WebRTC \u00een Asterisk. Vulnerabilitatea a fost remediat\u0103 \u00een versiunile 16.30.1, 18.18.1, 19.8.1 \u0219i 20.3.1.\n<li class=\"l\"> CVE-2023-36664 \u2014 o vulnerabilitate \u00een Ghostscript, un set de instrumente pentru procesarea, convertirea \u0219i generarea documentelor \u00een formatele PostScript \u0219i PDF, care permite executarea de cod arbitrar atunci c\u00e2nd se deschid documente special formulate \u00een format PostScript. Problema este cauzat\u0103 de procesarea incorect\u0103 a numelui fi\u0219ierelor care \u00eencep cu caracterul \u00ab|\u00bb sau prefixul %pipe%. Vulnerabilitatea a fost remediat\u0103 \u00een versiunea Ghostscript 10.01.2.\n<p>\u00cen multe medii, Ghostscript este apelat \u00een procesul de creare a miniaturilor pe desktop sau \u00een timpul index\u0103rii de fond a datelor, astfel c\u0103 pentru atac este uneori suficient s\u0103 \u00eencarci un fi\u0219ier cu un exploit sau s\u0103 vizualizezi un director cu acesta \u00een Nautilus. Un atac asupra sistemelor serve poate fi organizat prin intermediul handler-elor de imagini pe baza pachetelor ImageMagick \u0219i GraphicsMagick, care invoc\u0103 Ghostscript atunci c\u00e2nd se transfer\u0103 fi\u0219iere JPEG sau PNG, \u00een care \u00een loc de imagine se afl\u0103 cod PostScript (acest fi\u0219ier va fi procesat \u00een Ghostscript, deoarece tipul MIME este recunoscut dup\u0103 con\u021binut, \u0219i nu se bazeaz\u0103 pe extensie).    <\/p>\n<li class=\"l\"> CVE-2023-36475 \u2014 o vulnerabilitate \u00een Parse Server, backend-ul pentru Node.js care lucreaz\u0103 cu framework-ul web Express, care permite executarea codului propriu de la distan\u021b\u0103 pe server. Vulnerabilitatea permite aplicarea metodei de poluare a prototipului obiectelor JavaScript (\u00abprototype pollution\u00bb) pentru a executa codul propriu prin parserul BSON MongoDB. Vulnerabilitatea a fost evaluat\u0103 cu un nivel de severitate de 9.8 din 10. Problema a fost remediat\u0103 \u00een actualiz\u0103rile parse-server 5.5.2 \u0219i 6.2.1.      <\/ul>\n<p>Sursa: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=59430\">opennet.ro<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u043d\u0435\u0434\u0430\u0432\u043d\u043e \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043d\u044b\u0445 \u043e\u043f\u0430\u0441\u043d\u044b\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439: CVE-2022-24834 &#8212; \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 \u0421\u0423\u0411\u0414 Redis, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0432\u044b\u0437\u0432\u0430\u0442\u044c \u043f\u0435\u0440\u0435\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0435 \u0431\u0443\u0444\u0435\u0440\u0430 \u0432 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0430\u0445 cjson \u0438 cmsgpack \u043f\u0440\u0438 \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0438 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043e\u0444\u043e\u0440\u043c\u043b\u0435\u043d\u043d\u043e\u0433\u043e \u0441\u0446\u0435\u043d\u0430\u0440\u0438\u044f \u043d\u0430 \u044f\u0437\u044b\u043a\u0435 Lua. \u041f\u043e\u0442\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u043c\u043e\u0436\u0435\u0442 \u043f\u0440\u0438\u0432\u0435\u0441\u0442\u0438 \u043a \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e\u043c\u0443 \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044e \u043a\u043e\u0434\u0430 \u043d\u0430 \u0441\u0435\u0440\u0432\u0435\u0440\u0435. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u043f\u0440\u043e\u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u043d\u0430\u0447\u0438\u043d\u0430\u044f \u0441 Redis 2.6 \u0438 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0430 \u0432 \u0432\u044b\u043f\u0443\u0441\u043a\u0430\u0445 7.0.12, 6.2.13 \u0438 6.0.20. \u0412 \u043a\u0430\u0447\u0435\u0441\u0442\u0432\u0435 \u043e\u0431\u0445\u043e\u0434\u043d\u043e\u0433\u043e [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-109367","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u043d\u0435\u0434\u0430\u0432\u043d\u043e \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043d\u044b\u0445 \u043e\u043f\u0430\u0441\u043d\u044b\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439: CVE-2022-24834 - \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 \u0421\u0423\u0411\u0414 Redis, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0432\u044b\u0437\u0432\u0430\u0442\u044c \u043f\u0435\u0440\u0435\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0435 \u0431\u0443\u0444\u0435\u0440\u0430 \u0432 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0430\u0445 cjson \u0438 cmsgpack \u043f\u0440\u0438 \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0438 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimosti-v-redis-ghostscript-asterisk-i-parse-server\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"ro_RO\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 Redis, Ghostscript, Asterisk \u0438 Parse Server | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u043d\u0435\u0434\u0430\u0432\u043d\u043e \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043d\u044b\u0445 \u043e\u043f\u0430\u0441\u043d\u044b\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439: CVE-2022-24834 - \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 \u0421\u0423\u0411\u0414 Redis, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0432\u044b\u0437\u0432\u0430\u0442\u044c \u043f\u0435\u0440\u0435\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0435 \u0431\u0443\u0444\u0435\u0440\u0430 \u0432 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0430\u0445 cjson \u0438 cmsgpack \u043f\u0440\u0438 \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0438 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimosti-v-redis-ghostscript-asterisk-i-parse-server\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2023-07-12T19:10:19+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2023-07-13T07:57:04+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vulnerabilit\u0103\u021bi \u00een Redis, Ghostscript, Asterisk \u0219i Parse Server | ProHoster","description":"Mai multe vulnerabilit\u0103\u021bi periculoase recent descoperite: CVE-2022-24834 - o vulnerabilitate \u00een SGBD-ul Redis, care permite provocarea unui overflow de buffer \u00een bibliotecile cjson \u0219i cmsgpack \u00een timpul execu\u021biei special concepute.","canonical_url":"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimosti-v-redis-ghostscript-asterisk-i-parse-server","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"ro_RO","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 Redis, Ghostscript, Asterisk \u0438 Parse Server | ProHoster","og:description":"\u041d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u043d\u0435\u0434\u0430\u0432\u043d\u043e \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043d\u044b\u0445 \u043e\u043f\u0430\u0441\u043d\u044b\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439: CVE-2022-24834 - \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 \u0421\u0423\u0411\u0414 Redis, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0432\u044b\u0437\u0432\u0430\u0442\u044c \u043f\u0435\u0440\u0435\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0435 \u0431\u0443\u0444\u0435\u0440\u0430 \u0432 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0430\u0445 cjson \u0438 cmsgpack \u043f\u0440\u0438 \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0438 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e.","og:url":"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimosti-v-redis-ghostscript-asterisk-i-parse-server","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2023-07-12T19:10:19+00:00","article:modified_time":"2023-07-13T07:57:04+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"109367","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2026-02-09 21:40:03","updated":"2026-02-09 21:46:52","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/109367","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/comments?post=109367"}],"version-history":[{"count":2,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/109367\/revisions"}],"predecessor-version":[{"id":160357,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/109367\/revisions\/160357"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/media?parent=109367"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/categories?post=109367"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/tags?post=109367"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}