{"id":111788,"date":"2023-11-27T15:10:15","date_gmt":"2023-11-27T13:10:15","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimosti-v-perl-owncloud-gstreamer-i-zephyr-rtos"},"modified":"2023-11-27T15:10:15","modified_gmt":"2023-11-27T13:10:15","slug":"uyazvimosti-v-perl-owncloud-gstreamer-i-zephyr-rtos","status":"publish","type":"post","link":"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimosti-v-perl-owncloud-gstreamer-i-zephyr-rtos","title":{"rendered":"Vulnerabilit\u0103\u021bi \u00een Perl, ownCloud, GStreamer \u0219i Zephyr RTOS","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>C\u00e2teva vulnerabilit\u0103\u021bi recent descoperite:  <\/p>\n<ul>\n<li class=\"l\"> \u00cen versiunea corectiv\u0103 Perl 5.38.1 a fost eliminat\u0103 o vulnerabilitate (CVE-2023-47038) care poate duce la scrierea unui byte \u00een afara buffer-ului alocat, atunci c\u00e2nd sunt procesate expresii regulate compilate cu o proprietate intern\u0103 Unicode redefinit\u0103 incorect, ale c\u0103rei nume \u00eencep cu &#171;utf8::perl&#187;. Problema apare \u00eencep\u00e2nd cu ramura Perl 5.30.\n<p>De asemenea, \u00een Perl 5.38.1 a fost remediat\u0103 o vulnerabilitate specific\u0103 platformei Windows (CVE-2023-47039), care permite executarea de cod la rularea scripturilor \u00een prezen\u021ba unui fi\u0219ier cmd.exe \u00een directorul curent (din cauza lipsei filtr\u0103rii c\u0103ilor pentru c\u0103utarea fi\u0219ierelor executabile, Perl \u00eencearc\u0103 mai \u00eent\u00e2i s\u0103 execute cmd.exe \u00een directorul curent). De exemplu, un atacator poate plasa propriul cmd.exe \u00een directorul C:&#092;ProgramData \u0219i \u00ee\u0219i poate cre\u0219te privilegiile dac\u0103 administratorul ruleaz\u0103 un script Perl din acest director.    <\/p>\n<li class=\"l\"> \u00cen platforma cloud ownCloud, care s-a desprins de proiectul Nextcloud \u00een 2016, a fost descoperit\u0103 o vulnerabilitate (CVE-2023-49103) care afecteaz\u0103 aplica\u021bia graphapi \u0219i permite identificarea con\u021binutului variabilelor de mediu, care pot con\u021bine parola administratorului, cheia de licen\u021b\u0103 \u0219i acreditivele pentru conectarea la po\u0219t\u0103. <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/ro\/server\/dts-shicago\/\"   title=\"server\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"2915\">server<\/a>Problema este cauzat\u0103 de utilizarea \u00eentr-un graphapi a unei biblioteci externe, care printre altele ofer\u0103 un handler GetPhpInfo.php, care invoc\u0103 func\u021bia phpinfo(), al c\u0103rei output con\u021bine variabile de mediu.\n<li class=\"l\"> \u00cen cadrul framework-ului multimedia GStreamer au fost identificate dou\u0103 vulnerabilit\u0103\u021bi: CVE-2023-44446 \u2014 accesarea memoriei dup\u0103 eliberare (Use-After-Free) \u00een codul de analiz\u0103 al fi\u0219ierelor MXF; CVE-2023-44429 \u2014 supraaglomerare a buffer-ului \u00een codul de analiz\u0103 a formatului AV1. Prima problem\u0103 este cauzat\u0103 de lipsa verific\u0103rii obiectului \u00eenainte de a efectua opera\u021bii asupra acestuia, iar a doua de lipsa verific\u0103rii dimensiunii datelor \u00eenainte de copierea acestora \u00eentr-un buffer fix. Vulnerabilit\u0103\u021bile pot duce la executarea codului de c\u0103tre un atacator \u00een timpul proces\u0103rii fi\u0219ierelor MXF \u0219i a datelor multimedia \u00een format AV1. Se noteaz\u0103 c\u0103 vectorii de atac depind de implementarea aplica\u021biei atacate. Problemelor li s-a atribuit un nivel de severitate de 8.8 din 10. Vulnerabilit\u0103\u021bile au fost remediate \u00een versiunea GStreamer 1.22.7.\n<li class=\"l\"> \u00cen sistemul de operare \u00een timp real Zephyr RTOS au fost identificate 25 de vulnerabilit\u0103\u021bi, dintre care cele mai multe pot duce poten\u021bial la executarea codului de c\u0103tre un atacator. Vulnerabilit\u0103\u021bile sunt cauzate de suprasarcini de buffer \u00een WiFi shell, stiva Bluetooth, driverul IPM, stiva USB, driverul IEEE 802.15.4, subsystemul Mgmt, sistemul de fi\u0219iere, driverul eS-WiFi \u0219i subsystemul CANbus. Cele mai multe vulnerabilit\u0103\u021bi au fost remediate \u00een versiunea Zephyr 3.5.0, dar o problem\u0103 (CVE-2023-4261) r\u0103m\u00e2ne nerezolvat\u0103 (detaliile despre aceast\u0103 vulnerabilitate nu sunt publicate p\u00e2n\u0103 la apari\u021bia unei solu\u021bii).    <\/ul>\n<p>Sursa: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=60185\">opennet.ro<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u043d\u0435\u0434\u0430\u0432\u043d\u043e \u043e\u0431\u043d\u0430\u0440\u0443\u0436\u0435\u043d\u043d\u044b\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439: \u0412 \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u0438\u0440\u0443\u044e\u0449\u0435\u043c \u0432\u044b\u043f\u0443\u0441\u043a\u0435 Perl 5.38.1 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2023-47038), \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u043c\u043e\u0436\u0435\u0442 \u043f\u0440\u0438\u0432\u0435\u0441\u0442\u0438 \u043a \u0437\u0430\u043f\u0438\u0441\u0438 \u043e\u0434\u043d\u043e\u0433\u043e \u0431\u0430\u0439\u0442\u0430 \u0437\u0430 \u043f\u0440\u0435\u0434\u0435\u043b\u044b \u0432\u044b\u0434\u0435\u043b\u0435\u043d\u043d\u043e\u0433\u043e \u0431\u0443\u0444\u0435\u0440\u0430 \u043f\u0440\u0438 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0435 \u0441\u043a\u043e\u043c\u043f\u0438\u043b\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u0445 \u0440\u0435\u0433\u0443\u043b\u044f\u0440\u043d\u044b\u0445 \u0432\u044b\u0440\u0430\u0436\u0435\u043d\u0438\u0439 \u0441 \u043d\u0435\u043a\u043e\u0440\u0440\u0435\u043a\u0442\u043d\u043e \u043f\u043e\u0432\u0442\u043e\u0440\u043d\u043e \u043e\u043f\u0440\u0435\u0434\u0435\u043b\u0451\u043d\u043d\u044b\u043c \u0432\u043d\u0443\u0442\u0440\u0435\u043d\u043d\u0438\u043c Unicode-\u0441\u0432\u043e\u0439\u0441\u0442\u0432\u043e\u043c \u0441 \u0438\u043c\u0435\u043d\u0435\u043c, \u043d\u0430\u0447\u0438\u043d\u0430\u044e\u0449\u0438\u043c\u0441\u044f \u043d\u0430 &#171;utf8::perl&#187;. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u043f\u0440\u043e\u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u043d\u0430\u0447\u0438\u043d\u0430\u044f \u0441 \u0432\u0435\u0442\u043a\u0438 Perl 5.30. \u041a\u0440\u043e\u043c\u0435 \u0442\u043e\u0433\u043e, \u0432 Perl 5.38.1 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0430 \u0441\u043f\u0435\u0446\u0438\u0444\u0438\u0447\u043d\u0430\u044f \u0434\u043b\u044f \u043f\u043b\u0430\u0442\u0444\u043e\u0440\u043c\u044b [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-111788","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u043d\u0435\u0434\u0430\u0432\u043d\u043e \u043e\u0431\u043d\u0430\u0440\u0443\u0436\u0435\u043d\u043d\u044b\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439: \u0412 \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u0438\u0440\u0443\u044e\u0449\u0435\u043c \u0432\u044b\u043f\u0443\u0441\u043a\u0435 Perl 5.38.1 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2023-47038), \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u043c\u043e\u0436\u0435\u0442 \u043f\u0440\u0438\u0432\u0435\u0441\u0442\u0438 \u043a \u0437\u0430\u043f\u0438\u0441\u0438 \u043e\u0434\u043d\u043e\u0433\u043e \u0431\u0430\u0439\u0442\u0430 \u0437\u0430 \u043f\u0440\u0435\u0434\u0435\u043b\u044b \u0432\u044b\u0434\u0435\u043b\u0435\u043d\u043d\u043e\u0433\u043e \u0431\u0443\u0444\u0435\u0440\u0430 \u043f\u0440\u0438.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimosti-v-perl-owncloud-gstreamer-i-zephyr-rtos\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"ro_RO\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 Perl, ownCloud, GStreamer \u0438 Zephyr RTOS | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u043d\u0435\u0434\u0430\u0432\u043d\u043e \u043e\u0431\u043d\u0430\u0440\u0443\u0436\u0435\u043d\u043d\u044b\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439: \u0412 \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u0438\u0440\u0443\u044e\u0449\u0435\u043c \u0432\u044b\u043f\u0443\u0441\u043a\u0435 Perl 5.38.1 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2023-47038), \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u043c\u043e\u0436\u0435\u0442 \u043f\u0440\u0438\u0432\u0435\u0441\u0442\u0438 \u043a \u0437\u0430\u043f\u0438\u0441\u0438 \u043e\u0434\u043d\u043e\u0433\u043e \u0431\u0430\u0439\u0442\u0430 \u0437\u0430 \u043f\u0440\u0435\u0434\u0435\u043b\u044b \u0432\u044b\u0434\u0435\u043b\u0435\u043d\u043d\u043e\u0433\u043e \u0431\u0443\u0444\u0435\u0440\u0430 \u043f\u0440\u0438.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimosti-v-perl-owncloud-gstreamer-i-zephyr-rtos\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2023-11-27T13:10:15+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2023-11-27T13:10:15+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vulnerabilit\u0103\u021bi \u00een Perl, ownCloud, GStreamer \u0219i Zephyr RTOS | ProHoster","description":"C\u00e2teva vulnerabilit\u0103\u021bi recent descoperite: \u00cen versiunea corectiv\u0103 Perl 5.38.1 a fost remediat\u0103 vulnerabilitatea (CVE-2023-47038), care poate duce la scrierea unui singur byte dincolo de bufferul alocat.","canonical_url":"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimosti-v-perl-owncloud-gstreamer-i-zephyr-rtos","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"ro_RO","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 Perl, ownCloud, GStreamer \u0438 Zephyr RTOS | ProHoster","og:description":"\u041d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u043d\u0435\u0434\u0430\u0432\u043d\u043e \u043e\u0431\u043d\u0430\u0440\u0443\u0436\u0435\u043d\u043d\u044b\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439: \u0412 \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u0438\u0440\u0443\u044e\u0449\u0435\u043c \u0432\u044b\u043f\u0443\u0441\u043a\u0435 Perl 5.38.1 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2023-47038), \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u043c\u043e\u0436\u0435\u0442 \u043f\u0440\u0438\u0432\u0435\u0441\u0442\u0438 \u043a \u0437\u0430\u043f\u0438\u0441\u0438 \u043e\u0434\u043d\u043e\u0433\u043e \u0431\u0430\u0439\u0442\u0430 \u0437\u0430 \u043f\u0440\u0435\u0434\u0435\u043b\u044b \u0432\u044b\u0434\u0435\u043b\u0435\u043d\u043d\u043e\u0433\u043e \u0431\u0443\u0444\u0435\u0440\u0430 \u043f\u0440\u0438.","og:url":"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimosti-v-perl-owncloud-gstreamer-i-zephyr-rtos","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2023-11-27T13:10:15+00:00","article:modified_time":"2023-11-27T13:10:15+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"111788","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2026-02-09 21:42:03","updated":"2026-02-09 21:42:03","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/111788","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/comments?post=111788"}],"version-history":[{"count":1,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/111788\/revisions"}],"predecessor-version":[{"id":160195,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/111788\/revisions\/160195"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/media?parent=111788"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/categories?post=111788"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/tags?post=111788"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}