{"id":120608,"date":"2024-11-20T01:09:18","date_gmt":"2024-11-19T23:09:18","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimosti-v-utilite-needrestart-pozvolyayushhie-poluchit-root-dostup-v-ubuntu-server"},"modified":"2024-11-20T01:09:18","modified_gmt":"2024-11-19T23:09:18","slug":"uyazvimosti-v-utilite-needrestart-pozvolyayushhie-poluchit-root-dostup-v-ubuntu-server","status":"publish","type":"post","link":"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimosti-v-utilite-needrestart-pozvolyayushhie-poluchit-root-dostup-v-ubuntu-server","title":{"rendered":"Vulnerabilit\u0103\u021bi \u00een utilitarul needrestart care permit ob\u021binerea accesului root pe Ubuntu Server","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Compania Qualys a descoperit trei vulnerabilit\u0103\u021bi \u00een utilitarul needrestart, destinat repornirii proceselor de fundal dup\u0103 actualizarea bibliotecilor utilizate de procese. \u00cencep\u00e2nd cu Ubuntu 21.04, utilitarul needrestart este inclus \u00een mediul de baz\u0103 al Ubuntu Server, unde ruleaz\u0103 cu drepturi de root la sf\u00e2r\u0219itul fiec\u0103rei tranzac\u021bii a managerului de pachete APT, scaneaz\u0103 procesele active \u0219i reporne\u0219te acele procese care sunt legate de fi\u0219ierele modificate dup\u0103 actualizarea pachetelor. Vulnerabilit\u0103\u021bile identificate permit unui utilizator local f\u0103r\u0103 privilegii s\u0103 ob\u021bin\u0103 drepturi de root \u00een Ubuntu Server \u00een configura\u021bia implicit\u0103.      <\/p>\n<p>Vulnerabilit\u0103\u021bile sunt prezente \u00een needrestart \u00eencep\u00e2nd cu versiunea 0.8 (2014) \u0219i au fost remediate \u00een versiunea needrestart 3.8. Problemele au fost deja rezolvate \u0219i \u00een distribu\u021biile Debian \u0219i Ubuntu. Ca o solu\u021bie temporar\u0103 pentru a bloca exploatarea vulnerabilit\u0103\u021bii, se poate dezactiva scanarea interpretatorilor, specific\u00e2nd \u00een fi\u0219ierul de configurare \/etc\/needrestart\/needrestart.conf parametrul \"$nrconf{interpscan} = 0$\".      <\/p>\n<p>Vulnerabilit\u0103\u021bile sunt prezente \u00een codul cu implementarea modului de determinare a actualiz\u0103rii scripturilor, care sunt lansate utiliz\u00e2nd interpretatori. Problemele identificate sunt:  <\/p>\n<ul>\n<li class=\"l\"> CVE-2024-48990 \u2014 un utilizator local poate ob\u021bine execu\u021bia codului cu drepturi de root prin crearea condi\u021biilor pentru a rula interpretatorul Python cu variabila de mediu PYTHONPATH setat\u0103 de atacator. Pe l\u00e2ng\u0103 utilizarea Python, atacul poate fi realizat (CVE-2024-48992) prin rularea interpretatorului Ruby cu variabila de mediu RUBYLIB.\n<p>Vulnerabilit\u0103\u021bile sunt cauzate de faptul c\u0103, \u00een timpul repornirii unui script modificat, utilitarul needrestart seteaz\u0103 variabila de mediu PYTHONPATH pe baza con\u021binutului fi\u0219ierului \/proc\/pid\/environ, pe care apoi o folose\u0219te \u0219i pentru a rula propriul cod Python. Prin urmare, atacatorul poate a\u0219tepta activit\u0103\u021bi legate de func\u021bionarea managerului de pachete APT, poate simula modificarea scriptului s\u0103u \u0219i poate seta variabila de mediu PYTHONPATH, care va fi aplicat\u0103 \u0219i la rularea codului Python incorporat \u00een needrestart (\"import sys\\n print(sys.path)\"), executat cu drepturi de root.    <\/p>\n<p>De exemplu, pentru a exploata vulnerabilitatea, se poate lansa un proces Python care r\u0103m\u00e2ne constant \u00een memorie, set\u00e2nd pentru acesta variabila de mediu \"PYTHONPATH=\/home\/test\", \u0219i se poate plasa o bibliotec\u0103 partajat\u0103 \"\\\/home\\\/test\\\/importlib\\\/__init__.so\" care va fi executat\u0103 la rularea codului Python privilegiat \u00een needrestart.           <\/p>\n<li class=\"l\"> CVE-2024-48991 \u2014 un utilizator local poate ob\u021bine execu\u021bia codului cu drepturi de root prin ini\u021bierea unei st\u0103ri de concuren\u021b\u0103 (race condition), ca urmare a c\u0103reia needrestart va lansa un interpretator Python fals, introdus de atacator, \u00een locul interpretatorului Python sistemic. Esen\u021ba vulnerabilit\u0103\u021bii este similar\u0103 cu problema men\u021bionat\u0103 anterior, diferen\u021ba const\u00e2nd doar \u00een faptul c\u0103 needrestart determin\u0103 numele procesului Python (de exemplu, \/usr\/bin\/python3) prin citirea \"\\\/proc\\\/pid\\\/exe\".\n<p>Pentru a exploata vulnerabilitatea, se poate crea un proces \/home\/test\/race, care prin intermediul mecanismului inotify va a\u0219tepta momentul \u00een care needrestart va \u00eencepe s\u0103 citeasc\u0103 con\u021binutul \/proc\/pid\/exe \u0219i imediat va lansa interpretul sistemic Python prin func\u021bia execve. Deoarece needrestart nu verific\u0103 dac\u0103 acesta este \u00eentr-adev\u0103r Python, el va considera c\u0103 \/home\/test\/race este interpretul Python \u0219i \u00eel va lansa pentru codul s\u0103u.         <\/p>\n<li class=\"l\"> CVE-2024-11003 \u2014 un utilizator local poate reu\u0219i s\u0103 execute comenzi shell arbitrare cu privilegii root prin crearea de condi\u021bii pentru procesarea \u00een needrestart a numelui fi\u0219ierelor \u00een formatul \u201ecomand\u0103|\u201d, transmiterea c\u0103rora \u00een func\u021bia Perl open() va duce la executarea comenzii. De fapt, vulnerabilitatea se manifest\u0103 \u00een modulul Perl ScanDeps (CVE-2024-10224), dar este cauzat\u0103 de transmiterea de parametri externi c\u0103tre acest modul f\u0103r\u0103 o verificare corespunz\u0103toare.\n<p>Atacul poate fi realizat prin lansarea unui script Perl cu simbolul \u201e|\u201d \u00een nume, de exemplu, \u201e\/home\/test\/perl|\u201d. \u00cen timpul execu\u021biei func\u021biei scan_deps() \u00een needrestart, acest fi\u0219ier va fi deschis prin func\u021bia open(), care va trata simbolul \u201e|\u201d ca pe un semn pentru a lansa programul \u201e\/home\/test\/perl\u201d \u0219i a utiliza fluxul de ie\u0219ire ob\u021binut de la acest program.                 <\/ul>\n<p>Sursa: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=62261\">opennet.ro<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f Qualys \u0432\u044b\u044f\u0432\u0438\u043b\u0430 \u0442\u0440\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 \u0443\u0442\u0438\u043b\u0438\u0442\u0435 needrestart, \u043f\u0440\u0435\u0434\u043d\u0430\u0437\u043d\u0430\u0447\u0435\u043d\u043d\u043e\u0439 \u0434\u043b\u044f \u043f\u0435\u0440\u0435\u0437\u0430\u043f\u0443\u0441\u043a\u0430 \u0444\u043e\u043d\u043e\u0432\u044b\u0445 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u043e\u0432 \u043f\u043e\u0441\u043b\u0435 \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u044f \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u044b\u0445 \u0434\u0430\u043d\u043d\u044b\u043c\u0438 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430\u043c\u0438 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a. \u041d\u0430\u0447\u0438\u043d\u0430\u044f \u0441 Ubuntu 21.04 \u0443\u0442\u0438\u043b\u0438\u0442\u0430 needrestart \u0432\u043a\u043b\u044e\u0447\u0435\u043d\u0430 \u0432 \u0441\u043e\u0441\u0442\u0430\u0432 \u0431\u0430\u0437\u043e\u0432\u043e\u0433\u043e \u043e\u043a\u0440\u0443\u0436\u0435\u043d\u0438\u044f Ubuntu Server, \u0432 \u043a\u043e\u0442\u043e\u0440\u043e\u043c \u0437\u0430\u043f\u0443\u0441\u043a\u0430\u0435\u0442\u0441\u044f \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 root \u0432 \u043a\u043e\u043d\u0446\u0435 \u043a\u0430\u0436\u0434\u043e\u0439 \u0442\u0440\u0430\u043d\u0437\u0430\u043a\u0446\u0438\u0438 \u043f\u0430\u043a\u0435\u0442\u043d\u043e\u0433\u043e \u043c\u0435\u043d\u0435\u0434\u0436\u0435\u0440\u0430 APT, \u0441\u043a\u0430\u043d\u0438\u0440\u0443\u0435\u0442 \u0437\u0430\u043f\u0443\u0449\u0435\u043d\u043d\u044b\u0435 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u044b \u0438 \u043f\u0435\u0440\u0435\u0437\u0430\u043f\u0443\u0441\u043a\u0430\u0435\u0442 \u0442\u0435 \u0438\u0445 \u043d\u0438\u0445, \u0447\u0442\u043e \u0441\u0432\u044f\u0437\u0430\u043d\u043d\u044b [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-120608","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f Qualys \u0432\u044b\u044f\u0432\u0438\u043b\u0430 \u0442\u0440\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 \u0443\u0442\u0438\u043b\u0438\u0442\u0435 needrestart, \u043f\u0440\u0435\u0434\u043d\u0430\u0437\u043d\u0430\u0447\u0435\u043d\u043d\u043e\u0439 \u0434\u043b\u044f \u043f\u0435\u0440\u0435\u0437\u0430\u043f\u0443\u0441\u043a\u0430 \u0444\u043e\u043d\u043e\u0432\u044b\u0445 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u043e\u0432 \u043f\u043e\u0441\u043b\u0435 \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u044f \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u044b\u0445 \u0434\u0430\u043d\u043d\u044b\u043c\u0438 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430\u043c\u0438 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimosti-v-utilite-needrestart-pozvolyayushhie-poluchit-root-dostup-v-ubuntu-server\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"ro_RO\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 \u0443\u0442\u0438\u043b\u0438\u0442\u0435 needrestart, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0435 \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c root-\u0434\u043e\u0441\u0442\u0443\u043f \u0432 Ubuntu Server | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f Qualys \u0432\u044b\u044f\u0432\u0438\u043b\u0430 \u0442\u0440\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 \u0443\u0442\u0438\u043b\u0438\u0442\u0435 needrestart, \u043f\u0440\u0435\u0434\u043d\u0430\u0437\u043d\u0430\u0447\u0435\u043d\u043d\u043e\u0439 \u0434\u043b\u044f \u043f\u0435\u0440\u0435\u0437\u0430\u043f\u0443\u0441\u043a\u0430 \u0444\u043e\u043d\u043e\u0432\u044b\u0445 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u043e\u0432 \u043f\u043e\u0441\u043b\u0435 \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u044f \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u044b\u0445 \u0434\u0430\u043d\u043d\u044b\u043c\u0438 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430\u043c\u0438 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimosti-v-utilite-needrestart-pozvolyayushhie-poluchit-root-dostup-v-ubuntu-server\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2024-11-19T23:09:18+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2024-11-19T23:09:18+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vulnerabilit\u0103\u021bi \u00een utilitarul needrestart, care permit ob\u021binerea accesului root \u00een Ubuntu Server | ProHoster","description":"Compania Qualys a identificat trei vulnerabilit\u0103\u021bi \u00een utilitarul needrestart, destinat relu\u0103rii proceselor de fundal dup\u0103 actualizarea bibliotecilor utilizate de procesele respective.","canonical_url":"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimosti-v-utilite-needrestart-pozvolyayushhie-poluchit-root-dostup-v-ubuntu-server","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"ro_RO","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 \u0443\u0442\u0438\u043b\u0438\u0442\u0435 needrestart, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0435 \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c root-\u0434\u043e\u0441\u0442\u0443\u043f \u0432 Ubuntu Server | ProHoster","og:description":"\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f Qualys \u0432\u044b\u044f\u0432\u0438\u043b\u0430 \u0442\u0440\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 \u0443\u0442\u0438\u043b\u0438\u0442\u0435 needrestart, \u043f\u0440\u0435\u0434\u043d\u0430\u0437\u043d\u0430\u0447\u0435\u043d\u043d\u043e\u0439 \u0434\u043b\u044f \u043f\u0435\u0440\u0435\u0437\u0430\u043f\u0443\u0441\u043a\u0430 \u0444\u043e\u043d\u043e\u0432\u044b\u0445 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u043e\u0432 \u043f\u043e\u0441\u043b\u0435 \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u044f \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u044b\u0445 \u0434\u0430\u043d\u043d\u044b\u043c\u0438 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430\u043c\u0438 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a.","og:url":"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimosti-v-utilite-needrestart-pozvolyayushhie-poluchit-root-dostup-v-ubuntu-server","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2024-11-19T23:09:18+00:00","article:modified_time":"2024-11-19T23:09:18+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"120608","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-23 08:09:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2026-01-23 08:09:19","updated":"2026-01-23 08:09:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/120608","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/comments?post=120608"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/120608\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/media?parent=120608"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/categories?post=120608"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/tags?post=120608"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}