{"id":103151,"date":"2022-01-31T21:36:52","date_gmt":"2022-01-31T19:36:52","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/udalyonnaya-root-uyazvimost-v-samba"},"modified":"2022-01-31T21:36:52","modified_gmt":"2022-01-31T19:36:52","slug":"udalyonnaya-root-uyazvimost-v-samba","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/news\/udalyonnaya-root-uyazvimost-v-samba","title":{"rendered":"Vulnerabiliteti root i larg\u00ebt n\u00eb Samba \u00ebsht\u00eb hequr.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Jan\u00eb publikuar versionet e korrigjuara 4.15.5, 4.14.12 dhe 4.13.17 p\u00ebr t\u00eb adresuar 3 vulnerabilitete. Vulnerabiliteti m\u00eb rreziksh\u00ebm (CVE-2021-44142) lejon nj\u00eb sulmues t\u00eb larg\u00ebt t\u00eb ekzekutoj\u00eb kod t\u00eb arbitrar me privilegje root n\u00eb nj\u00eb sistem me nj\u00eb version t\u00eb cenuesh\u00ebm t\u00eb Samba. Problemi i \u00ebsht\u00eb caktuar nj\u00eb nivel rreziku prej 9.9 nga 10.    <\/p>\n<p>Vulnerabiliteti shfaqet vet\u00ebm kur p\u00ebrdoret moduli VFS vfs_fruit me parametrat e paracaktuar (fruit:metadata=netatalk ose fruit:resource=file), duke ofruar nj\u00eb nivel shtes\u00eb p\u00ebrputhshm\u00ebrie me klient\u00ebt e macOS dhe p\u00ebrmir\u00ebsim t\u00eb portueshm\u00ebris\u00eb me skedaret Netatalk 3 AFP. <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/sq\/server\/dts-dusseldorf\/\"   title=\"server\u00ebve\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"3448\">server\u00ebve<\/a> Problemi shkaktohet nga mbushja e buffers n\u00eb kodin e analiz\u00ebs s\u00eb metadatas me atribute t\u00eb zgjeruara (EA, xattr), e cila ndodh gjat\u00eb hapjes s\u00eb skedareve n\u00eb smbd. P\u00ebr t\u00eb kryer sulmin, p\u00ebrdoruesi duhet t\u00eb ket\u00eb akses p\u00ebr t\u00eb shkruar n\u00eb atribute t\u00eb zgjeruara t\u00eb skedarit, nd\u00ebrsa sulmi mund t\u00eb realizohet edhe nga nj\u00eb p\u00ebrdorues mysafir, n\u00ebse i lejohet ky tip shkrimi.          <\/p>\n<p>Mund\u00ebsi p\u00ebr t\u00eb ndjekur azhurnimet e paketave n\u00eb shp\u00ebrndarjet mund t\u00eb gjendet n\u00eb faqet: Debian, Ubuntu, RHEL, SUSE, Fedora, Arch, FreeBSD. Si nj\u00eb zgjidhje mbrojt\u00ebse, mund t\u00eb hiqni modulin &#171;fruit&#187; nga lista e &#171;vfs objects&#187; n\u00eb smb.conf.      <\/p>\n<p>Dy vulnerabilitetet e tjera:  <\/p>\n<ul>\n<li class=\"l\"> Vulnerabiliteti CVE-2022-0336 lejon nj\u00eb p\u00ebrdorues t\u00eb Samba AD DC t\u00eb prezantohet si nj\u00eb sh\u00ebrbim tjet\u00ebr dhe t\u00eb organizoj\u00eb kapjen e trafikut t\u00eb adresuar k\u00ebtij sh\u00ebrbimi. P\u00ebr t\u00eb kryer sulmin, p\u00ebrdoruesi duhet t\u00eb ket\u00eb t\u00eb drejtat p\u00ebr t\u00eb ndryshuar atributin servicePrincipalName n\u00eb llogarin\u00eb e tij.\n<li class=\"l\"> Vulnerabiliteti CVE-2021-44141 mund t\u00eb \u00e7oj\u00eb n\u00eb rrjedhjen e informacionit mbi ekzistenc\u00ebn e skedareve dhe dosjeve n\u00eb zon\u00ebn FS p\u00ebrtej pjes\u00ebs s\u00eb eksportuar t\u00eb Samba. Sulmi realizohet p\u00ebrmes manipulimit t\u00eb lidhjeve simbolike.  <\/ul>\n<p>Burimi: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=56615\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d\u044b \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u0438\u0440\u0443\u044e\u0449\u0438\u0435 \u0432\u044b\u043f\u0443\u0441\u043a\u0438 \u043f\u0430\u043a\u0435\u0442\u0430 4.15.5, 4.14.12 \u0438 4.13.17 \u0441 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u0435\u043c 3 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439. \u041d\u0430\u0438\u0431\u043e\u043b\u0435\u0435 \u043e\u043f\u0430\u0441\u043d\u0430\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2021-44142) \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e\u043c\u0443 \u0430\u0442\u0430\u043a\u0443\u044e\u0449\u0435\u043c\u0443 \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u043b\u044c\u043d\u044b\u0439 \u043a\u043e\u0434 \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 root \u043d\u0430 \u0441\u0438\u0441\u0442\u0435\u043c\u0435 \u0441 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0439 \u0432\u0435\u0440\u0441\u0438\u0435\u0439 Samba. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0435 \u043f\u0440\u0438\u0441\u0432\u043e\u0435\u043d \u0443\u0440\u043e\u0432\u0435\u043d\u044c \u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 9.9 \u0438\u0437 10. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u043f\u0440\u043e\u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u0442\u043e\u043b\u044c\u043a\u043e \u043f\u0440\u0438 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0438 VFS-\u043c\u043e\u0434\u0443\u043b\u044f vfs_fruit \u0441 \u043f\u0430\u0440\u0430\u043c\u0435\u0442\u0440\u0430\u043c\u0438 \u043f\u043e \u0443\u043c\u043e\u043b\u0447\u0430\u043d\u0438\u044e (fruit:metadata=netatalk \u0438\u043b\u0438 fruit:resource=file), \u043e\u0431\u0435\u0441\u043f\u0435\u0447\u0438\u0432\u0430\u044e\u0449\u0435\u0433\u043e \u0434\u043e\u043f\u043e\u043b\u043d\u0438\u0442\u0435\u043b\u044c\u043d\u044b\u0439 \u0443\u0440\u043e\u0432\u0435\u043d\u044c [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-103151","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.0.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d\u044b \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u0438\u0440\u0443\u044e\u0449\u0438\u0435 \u0432\u044b\u043f\u0443\u0441\u043a\u0438 \u043f\u0430\u043a\u0435\u0442\u0430 4.15.5, 4.14.12 \u0438 4.13.17 \u0441 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u0435\u043c 3 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/news\/udalyonnaya-root-uyazvimost-v-samba\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.0.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u0434\u0430\u043b\u0451\u043d\u043d\u0430\u044f root-\u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 Samba | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d\u044b \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u0438\u0440\u0443\u044e\u0449\u0438\u0435 \u0432\u044b\u043f\u0443\u0441\u043a\u0438 \u043f\u0430\u043a\u0435\u0442\u0430 4.15.5, 4.14.12 \u0438 4.13.17 \u0441 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u0435\u043c 3 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/news\/udalyonnaya-root-uyazvimost-v-samba\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2022-01-31T19:36:52+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2022-01-31T19:36:52+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47 Vulnerabiliteti i larg\u00ebt root n\u00eb Samba | ProHoster","description":"Jan\u00eb publikuar l\u00ebshime korrigjuese t\u00eb paket\u00ebs 4.15.5, 4.14.12 dhe 4.13.17 q\u00eb adresojn\u00eb 3 dob\u00ebsi t\u00eb siguris\u00eb.","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/news\/udalyonnaya-root-uyazvimost-v-samba","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u0434\u0430\u043b\u0451\u043d\u043d\u0430\u044f root-\u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 Samba | ProHoster","og:description":"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d\u044b \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u0438\u0440\u0443\u044e\u0449\u0438\u0435 \u0432\u044b\u043f\u0443\u0441\u043a\u0438 \u043f\u0430\u043a\u0435\u0442\u0430 4.15.5, 4.14.12 \u0438 4.13.17 \u0441 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u0435\u043c 3 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439.","og:url":"https:\/\/prohoster.info\/sq\/blog\/news\/udalyonnaya-root-uyazvimost-v-samba","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2022-01-31T19:36:52+00:00","article:modified_time":"2022-01-31T19:36:52+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"103151","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2022-01-31 19:37:46","updated":"2026-02-19 09:14:04","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/103151","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=103151"}],"version-history":[{"count":1,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/103151\/revisions"}],"predecessor-version":[{"id":161823,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/103151\/revisions\/161823"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=103151"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=103151"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=103151"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}