{"id":84053,"date":"2020-06-05T01:42:08","date_gmt":"2020-06-04T23:42:08","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/opasnye-uyazvimosti-v-qemu-node-js-grafana-i-android"},"modified":"2020-06-05T01:42:08","modified_gmt":"2020-06-04T23:42:08","slug":"opasnye-uyazvimosti-v-qemu-node-js-grafana-i-android","status":"publish","type":"post","link":"https:\/\/prohoster.info\/ro\/blog\/news\/opasnye-uyazvimosti-v-qemu-node-js-grafana-i-android","title":{"rendered":"Vulnerabilit\u0103\u021bi periculoase \u00een QEMU, Node.js, Grafana \u0219i Android","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>C\u00e2teva vulnerabilit\u0103\u021bi recent identificate:<\/p>\n<ul>\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/www.openwall.com\/lists\/oss-security\/2020\/06\/03\/6\">Vulnerabilitatea<\/a><\/noindex> (<noindex><a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2020-13765\">CVE-2020-13765<\/a><\/noindex>) \u00een QEMU, care poate duce poten\u021bial la executarea de cod cu drepturile procesului QEMU pe sistemul gazd\u0103 la \u00eenc\u0103rcarea unei imagini de kernel \u00een sistemul gazd\u0103 special concepute. Problema este cauzat\u0103 de o dep\u0103\u0219ire a buffer-ului \u00een codul de copiere a con\u021binutului ROM \u00een etapa de \u00eenc\u0103rcare a sistemului \u0219i se manifest\u0103 prin \u00eenc\u0103rcarea con\u021binutului unei imagini de kernel pe 32 de bi\u021bi \u00een memorie. Corectivul este disponibil momentan doar sub form\u0103 de <noindex><a rel=\"nofollow\" href=\"https:\/\/git.qemu.org\/?p=qemu.git;a=commitdiff;h=e423455c4f23a1a828901c78fe6d03b7dde79319\">patch<\/a><\/noindex>.\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/nodejs.org\/en\/blog\/vulnerability\/june-2020-security-releases\/\">Patru vulnerabilit\u0103\u021bi<\/a><\/noindex> \u00een Node.js. Vulnerabilit\u0103\u021bile <noindex><a rel=\"nofollow\" href=\"https:\/\/nodejs.org\/en\/blog\/release\/v14.4.0\/\">remediate<\/a><\/noindex> sunt prezente \u00een versiunile 14.4.0, 10.21.0 \u0219i 12.18.0.\n<ul>\n<li class=\"l\"> CVE-2020-8172 \u2014 permite o contornar a verifica\u00e7\u00e3o do certificado do host ao reutilizar uma sess\u00e3o TLS.\n<li class=\"l\"> CVE-2020-8174 \u2014 permite potencialmente a execu\u00e7\u00e3o de c\u00f3digo no sistema devido a um estouro de buffer nas fun\u00e7\u00f5es napi_get_value_string_*(), que ocorre em certas chamadas a <noindex><a rel=\"nofollow\" href=\"https:\/\/www.npmjs.com\/package\/node-addon-api\">N-API<\/a><\/noindex> (API C pentru scrierea extensiilor native).\n<li class=\"l\"> CVE-2020-10531 \u2014 estouro inteiro no ICU (Componentes Internacionais para Unicode) para C\/C++, que pode levar a um estouro de buffer ao utilizar a fun\u00e7\u00e3o UnicodeString::doAppend().\n<li class=\"l\"> CVE-2020-11080 \u2014 permite a realiza\u00e7\u00e3o de um ataque de nega\u00e7\u00e3o de servi\u00e7o (100% de carga na CPU) atrav\u00e9s do envio de quadros grandes 'SETTINGS' ao conectar via HTTP\/2.\n<\/ul>\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/www.openwall.com\/lists\/oss-security\/2020\/06\/03\/4\">Vulnerabilitatea<\/a><\/noindex> \u00een platforma de vizualizare interactiv\u0103 a metricilor Grafana, utilizat\u0103 pentru crearea de grafice de monitorizare vizual\u0103 pe baza diverselor surse de date. O eroare \u00een codul care lucreaz\u0103 cu avatarele permite, f\u0103r\u0103 a parcurge autentificarea, ini\u021bierea trimiterii unei cereri HTTP din partea Grafana c\u0103tre orice URL \u0219i vizualizarea rezultatului acelei cereri. Aceast\u0103 caracteristic\u0103 poate fi folosit\u0103, de exemplu, pentru a explora re\u021beaua intern\u0103 a companiilor care utilizeaz\u0103 Grafana. Problema <noindex><a rel=\"nofollow\" href=\"https:\/\/grafana.com\/blog\/2020\/06\/03\/grafana-6.7.4-and-7.0.2-released-with-important-security-fix\/\">remediat\u0103<\/a><\/noindex> este \u00een versiunile<br \/>\nGrafana 6.7.4 e 7.0.2. Como uma solu\u00e7\u00e3o alternativa de seguran\u00e7a, recomenda-se limitar o acesso \u00e0 URL '\/avatar\/*' no servidor com Grafana.<\/p>\n<li class=\"l\">  <noindex><a rel=\"nofollow\" href=\"https:\/\/source.android.com\/security\/bulletin\/2020-06-01\">Publicat<\/a><\/noindex> pacote de corre\u00e7\u00f5es de seguran\u00e7a de junho para Android, que resolve 34 vulnerabilidades. Quatro problemas receberam n\u00edvel cr\u00edtico de gravidade: duas vulnerabilidades (CVE-2019-14073, CVE-2019-14080) em componentes propriet\u00e1rios da Qualcomm e duas vulnerabilidades no sistema que permitem a execu\u00e7\u00e3o de c\u00f3digo ao lidar com dados externos formatados de forma especial (CVE-2020-0117 \u2014 estouro inteiro) <noindex><a rel=\"nofollow\" href=\"https:\/\/android.googlesource.com\/platform\/system\/bt\/+\/1570b62c88d7c5b9c6bfe43da8cc16ea30d3e8df\">\u00een stiva Bluetooth,<\/a><\/noindex> CVE-2020-8597 - dep\u0103\u0219ire EAP \u00een pppd <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=52498\">CVE-2020-8597 \u2014 estouro EAP no pppd<\/a><\/noindex>).\n<\/ul>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Sursa: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=53085\">opennet.ro<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u043d\u0435\u0434\u0430\u0432\u043d\u043e \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043d\u044b\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439: \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2020-13765) \u0432 QEMU, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u043f\u043e\u0442\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043c\u043e\u0436\u0435\u0442 \u043f\u0440\u0438\u0432\u0435\u0441\u0442\u0438 \u043a \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044e \u043a\u043e\u0434\u0430 \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430 QEMU \u043d\u0430 \u0441\u0442\u043e\u0440\u043e\u043d\u0435 \u0445\u043e\u0441\u0442-\u0441\u0438\u0441\u0442\u0435\u043c\u044b \u043f\u0440\u0438 \u0437\u0430\u0433\u0440\u0443\u0437\u043a\u0435 \u0432 \u0433\u043e\u0441\u0442\u0435\u0432\u043e\u0439 \u0441\u0438\u0441\u0442\u0435\u043c\u0435 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043e\u0444\u043e\u0440\u043c\u043b\u0435\u043d\u043d\u043e\u0433\u043e \u043e\u0431\u0440\u0430\u0437\u0430 \u044f\u0434\u0440\u0430. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u0432\u044b\u0437\u0432\u0430\u043d\u0430 \u043f\u0435\u0440\u0435\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0435\u043c \u0431\u0443\u0444\u0435\u0440\u0430 \u0432 \u043a\u043e\u0434\u0435 \u043a\u043e\u043f\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u0441\u043e\u0434\u0435\u0440\u0436\u0438\u043c\u043e\u0433\u043e \u041f\u0417\u0423 \u043d\u0430 \u044d\u0442\u0430\u043f\u0435 \u0437\u0430\u0433\u0440\u0443\u0437\u043a\u0438 \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u0438 \u043f\u0440\u043e\u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u043f\u0440\u0438 \u0437\u0430\u0433\u0440\u0443\u0437\u043a\u0435 \u0441\u043e\u0434\u0435\u0440\u0436\u0438\u043c\u043e\u0433\u043e 32-\u0440\u0430\u0437\u0440\u044f\u0434\u043d\u043e\u0433\u043e \u043e\u0431\u0440\u0430\u0437\u0430 \u044f\u0434\u0440\u0430 \u0432 \u043f\u0430\u043c\u044f\u0442\u044c. \u0418\u0441\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u0435 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-84053","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u043d\u0435\u0434\u0430\u0432\u043d\u043e \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043d\u044b\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439: \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/ro\/blog\/news\/opasnye-uyazvimosti-v-qemu-node-js-grafana-i-android\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"ro_RO\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041e\u043f\u0430\u0441\u043d\u044b\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 QEMU, Node.js, Grafana \u0438 Android | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u043d\u0435\u0434\u0430\u0432\u043d\u043e \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043d\u044b\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439: \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/ro\/blog\/news\/opasnye-uyazvimosti-v-qemu-node-js-grafana-i-android\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-06-04T23:42:08+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-06-04T23:42:08+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vulnerabilit\u0103\u021bi periculoase \u00een QEMU, Node.js, Grafana \u0219i Android | ProHoster","description":"Mai multe vulnerabilit\u0103\u021bi recent descoperite: Vulnerabilitate (","canonical_url":"https:\/\/prohoster.info\/ro\/blog\/news\/opasnye-uyazvimosti-v-qemu-node-js-grafana-i-android","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"ro_RO","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041e\u043f\u0430\u0441\u043d\u044b\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 QEMU, Node.js, Grafana \u0438 Android | ProHoster","og:description":"\u041d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u043d\u0435\u0434\u0430\u0432\u043d\u043e \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043d\u044b\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439: \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (","og:url":"https:\/\/prohoster.info\/ro\/blog\/news\/opasnye-uyazvimosti-v-qemu-node-js-grafana-i-android","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-06-04T23:42:08+00:00","article:modified_time":"2020-06-04T23:42:08+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"84053","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 15:05:33","updated":"2022-09-28 11:57:16","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/84053","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/comments?post=84053"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/84053\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/media?parent=84053"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/categories?post=84053"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/tags?post=84053"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}