{"id":104724,"date":"2022-07-28T15:36:38","date_gmt":"2022-07-28T13:36:38","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimost-v-samba-pozvolyayushhaya-pomenyat-parol-lyubomu-polzovatelyu"},"modified":"2022-07-28T15:36:38","modified_gmt":"2022-07-28T13:36:38","slug":"uyazvimost-v-samba-pozvolyayushhaya-pomenyat-parol-lyubomu-polzovatelyu","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimost-v-samba-pozvolyayushhaya-pomenyat-parol-lyubomu-polzovatelyu","title":{"rendered":"Vulnerabilitet n\u00eb Samba, q\u00eb lejon \u00e7do p\u00ebrdorues t\u00eb ndryshoj\u00eb fjal\u00ebkalimin","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Jan\u00eb publikuar p\u00ebrdit\u00ebsimet korrektuese p\u00ebr paketat Samba 4.16.4, 4.15.9 dhe 4.14.14 q\u00eb adresojn\u00eb 5 vulnerabilitete. Mund t\u00eb ndjekni l\u00ebshimin e p\u00ebrdit\u00ebsimeve t\u00eb paketave n\u00eb shp\u00ebrndarjet: Debian, Ubuntu, RHEL, SUSE, Arch, FreeBSD.    <\/p>\n<p>Vulnerabiliteti m\u00eb i rreziksh\u00ebm (CVE-2022-32744) lejon p\u00ebrdoruesit e domainit Active Directory t\u00eb ndryshojn\u00eb fjal\u00ebkalimin e \u00e7do p\u00ebrdoruesi, duke p\u00ebrfshir\u00eb administratoret, dhe t\u00eb fitojn\u00eb kontroll t\u00eb plot\u00eb mbi domainin. Problemi shkaktohet nga fakti se KDC pranon k\u00ebrkesat kpasswd, t\u00eb koduara me \u00e7far\u00ebdo \u00e7el\u00ebsi t\u00eb njohur.     <\/p>\n<p>Nj\u00eb sulmues q\u00eb ka qasje n\u00eb  <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/sq\/domain\/\"   title=\"domen\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"1234\">domen<\/a>, mund t\u00eb d\u00ebrgoj\u00eb nj\u00eb k\u00ebrkes\u00eb t\u00eb rreme p\u00ebr caktimin e nj\u00eb fjal\u00ebkalimi t\u00eb ri n\u00eb em\u00ebr t\u00eb nj\u00eb p\u00ebrdoruesi tjet\u00ebr, duke e koduar at\u00eb me \u00e7el\u00ebsin e tij, dhe KDC do ta procesoj\u00eb at\u00eb pa verifikimin e p\u00ebrputhshm\u00ebris\u00eb s\u00eb \u00e7el\u00ebsit t\u00eb llogaris\u00eb. \u00c7el\u00ebsat e kontrolluesve t\u00eb domainit q\u00eb operojn\u00eb vet\u00ebm n\u00eb modalitetin e leximit (RODC) q\u00eb nuk kan\u00eb autorizim p\u00ebr t\u00eb ndryshuar fjal\u00ebkalimet, gjithashtu mund t\u00eb p\u00ebrdoren p\u00ebr d\u00ebrgimin e k\u00ebrkesave t\u00eb rreme. Nj\u00eb m\u00ebnyr\u00eb p\u00ebr t\u00eb mbrojtur mund t\u00eb jet\u00eb \u00e7aktivizimi i mb\u00ebshtetjes p\u00ebr protokollin kpasswd, duke shtuar n\u00eb smb.conf rreshtin 'kpasswd port = 0'.    <\/p>\n<p>Dob\u00ebsi t\u00eb tjera:  <\/p>\n<ul>\n<li class=\"l\"> CVE-2022-32746 \u2014 p\u00ebrdoruesit e Active Directory, p\u00ebrmes d\u00ebrgimit t\u00eb k\u00ebrkesave t\u00eb formatuara posa\u00e7\u00ebrisht LDAP 'add' ose 'modify', mund t\u00eb nxisin qasjen n\u00eb memorie pas shkarkimit (use-after-free) n\u00eb procesin e serverit. Problemi shkaktohet nga fakti se moduli p\u00ebr regjistrimin e auditeve qas n\u00eb p\u00ebrmbajtjen e mesazhit LDAP pas \u00e7lirimit t\u00eb memories nga moduli i menaxhimit t\u00eb DB. P\u00ebr t\u00eb kryer sulm, \u00ebsht\u00eb e nevojshme q\u00eb t\u00eb kesh t\u00eb drejta p\u00ebr t\u00eb shtuar ose modifikuar disa atributet privilegjuara, si\u00e7 \u00ebsht\u00eb userAccountControl.\n<li class=\"l\"> CVE-2022-2031 \u2014 p\u00ebrdoruesit e Active Directory mund t\u00eb anashkalojn\u00eb disa kufizime n\u00eb kontrolluesin e domainit. KDC dhe sh\u00ebrbimi kpasswd kan\u00eb mund\u00ebsin\u00eb t\u00eb dekriptojn\u00eb biletat nj\u00ebri-tjetrit, pasi ndajn\u00eb nj\u00eb grup t\u00eb p\u00ebrbashk\u00ebt \u00e7elesh dhe llogarish. Prandaj, p\u00ebrdoruesi q\u00eb ka k\u00ebrkuar ndryshimin e fjal\u00ebkalimit mund t\u00eb p\u00ebrdor\u00eb bilet\u00ebn e marr\u00eb p\u00ebr qasje n\u00eb sh\u00ebrbime t\u00eb tjera.\n<li class=\"l\"> CVE-2022-32745 \u2014 p\u00ebrdoruesit e Active Directory mund t\u00eb shkaktojn\u00eb p\u00ebrfundim t\u00eb papritur t\u00eb procesit t\u00eb serverit p\u00ebrmes d\u00ebrgimit t\u00eb k\u00ebrkesave LDAP 'add' ose 'modify', q\u00eb \u00e7ojn\u00eb n\u00eb qasje n\u00eb t\u00eb dh\u00ebna t\u00eb pa inicializuara.\n<li class=\"l\"> CVE-2022-32742 \u2014 shp\u00ebrthimi i informacionit mbi p\u00ebrmbajtjen e memories <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/sq\/server\/dts-los-angeles\/\"   title=\"\u0441\u0435\u0440\u0432\u0435\u0440\u0430\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"3841\">\u0441\u0435\u0440\u0432\u0435\u0440\u0430<\/a> p\u00ebrmes manipulimeve me protokollin SMB1. Klienti SMB1, i cili ka t\u00eb drejt\u00eb t\u00eb shkruaj\u00eb n\u00eb ruajtjen e p\u00ebrbashk\u00ebt, mund t\u00eb krijoj\u00eb kushte p\u00ebr t\u00eb shkruar fragmente t\u00eb p\u00ebrmbajtjes s\u00eb memories s\u00eb procesit server n\u00eb nj\u00eb skedar ose p\u00ebr t'i d\u00ebrguar ato n\u00eb printer. Sulmi kryhet p\u00ebrmes d\u00ebrgimit t\u00eb nj\u00eb k\u00ebrkese \"write\" me nj\u00eb interval t\u00eb pasakt\u00eb. Problemi ka t\u00eb b\u00ebj\u00eb vet\u00ebm me deg\u00ebt Samba deri n\u00eb 4.11 (n\u00eb deg\u00ebn 4.11, mb\u00ebshtetje p\u00ebr SMB1 \u00ebsht\u00eb \u00e7aktivizuar si parazgjedhje).                 <\/ul>\n<p>Burimi: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=57565\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d\u044b \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u0438\u0440\u0443\u044e\u0449\u0438\u0435 \u0432\u044b\u043f\u0443\u0441\u043a\u0438 \u043f\u0430\u043a\u0435\u0442\u0430 Samba 4.16.4, 4.15.9 \u0438 4.14.14 \u0441 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u0435\u043c 5 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439. \u0412\u044b\u043f\u0443\u0441\u043a \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u0439 \u043f\u0430\u043a\u0435\u0442\u043e\u0432 \u0432 \u0434\u0438\u0441\u0442\u0440\u0438\u0431\u0443\u0442\u0438\u0432\u0430\u0445 \u043c\u043e\u0436\u043d\u043e \u043f\u0440\u043e\u0441\u043b\u0435\u0434\u0438\u0442\u044c \u043d\u0430 \u0441\u0442\u0440\u0430\u043d\u0438\u0446\u0430\u0445: Debian, Ubuntu, RHEL, SUSE, Arch, FreeBSD. \u041d\u0430\u0438\u0431\u043e\u043b\u0435\u0435 \u043e\u043f\u0430\u0441\u043d\u0430\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2022-32744) \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f\u043c \u0434\u043e\u043c\u0435\u043d\u0430 Active Directory \u0438\u0437\u043c\u0435\u043d\u0438\u0442\u044c \u043f\u0430\u0440\u043e\u043b\u044c \u043b\u044e\u0431\u043e\u0433\u043e \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f, \u0432 \u0442\u043e\u043c \u0447\u0438\u0441\u043b\u0435 \u043c\u043e\u0436\u043d\u043e \u0438\u0437\u043c\u0435\u043d\u0438\u0442\u044c \u043f\u0430\u0440\u043e\u043b\u044c \u0430\u0434\u043c\u0438\u043d\u0438\u0441\u0442\u0440\u0430\u0442\u043e\u0440\u0430 \u0438 \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u043f\u043e\u043b\u043d\u044b\u0439 \u043a\u043e\u043d\u0442\u0440\u043e\u043b\u044c \u043d\u0430\u0434 \u0434\u043e\u043c\u0435\u043d\u043e\u043c. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-104724","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d\u044b \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u0438\u0440\u0443\u044e\u0449\u0438\u0435 \u0432\u044b\u043f\u0443\u0441\u043a\u0438 \u043f\u0430\u043a\u0435\u0442\u0430 Samba 4.16.4, 4.15.9 \u0438 4.14.14 \u0441 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u0435\u043c 5 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimost-v-samba-pozvolyayushhaya-pomenyat-parol-lyubomu-polzovatelyu\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 Samba, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043f\u043e\u043c\u0435\u043d\u044f\u0442\u044c \u043f\u0430\u0440\u043e\u043b\u044c \u043b\u044e\u0431\u043e\u043c\u0443 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d\u044b \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u0438\u0440\u0443\u044e\u0449\u0438\u0435 \u0432\u044b\u043f\u0443\u0441\u043a\u0438 \u043f\u0430\u043a\u0435\u0442\u0430 Samba 4.16.4, 4.15.9 \u0438 4.14.14 \u0441 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u0435\u043c 5 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimost-v-samba-pozvolyayushhaya-pomenyat-parol-lyubomu-polzovatelyu\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2022-07-28T13:36:38+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2022-07-28T13:36:38+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vulnerabiliteti n\u00eb Samba q\u00eb lejon \u00e7do p\u00ebrdorues t\u00eb ndryshoj\u00eb fjal\u00ebkalimin | ProHoster","description":"Jan\u00eb publikuar p\u00ebrdit\u00ebsimet rekuizuese p\u00ebr paket\u00ebn Samba 4.16.4, 4.15.9 dhe 4.14.14, q\u00eb adresojn\u00eb 5 dob\u00ebsi.","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimost-v-samba-pozvolyayushhaya-pomenyat-parol-lyubomu-polzovatelyu","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 Samba, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043f\u043e\u043c\u0435\u043d\u044f\u0442\u044c \u043f\u0430\u0440\u043e\u043b\u044c \u043b\u044e\u0431\u043e\u043c\u0443 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e | ProHoster","og:description":"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d\u044b \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u0438\u0440\u0443\u044e\u0449\u0438\u0435 \u0432\u044b\u043f\u0443\u0441\u043a\u0438 \u043f\u0430\u043a\u0435\u0442\u0430 Samba 4.16.4, 4.15.9 \u0438 4.14.14 \u0441 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u0435\u043c 5 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439.","og:url":"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimost-v-samba-pozvolyayushhaya-pomenyat-parol-lyubomu-polzovatelyu","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2022-07-28T13:36:38+00:00","article:modified_time":"2022-07-28T13:36:38+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"104724","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2022-07-28 13:37:27","updated":"2026-02-22 15:30:56","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/104724","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=104724"}],"version-history":[{"count":2,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/104724\/revisions"}],"predecessor-version":[{"id":162369,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/104724\/revisions\/162369"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=104724"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=104724"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=104724"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}