{"id":110411,"date":"2023-10-04T08:10:45","date_gmt":"2023-10-04T06:10:45","guid":{"rendered":"https:\/\/prohoster.info\/?p=110411"},"modified":"2023-10-04T08:10:45","modified_gmt":"2023-10-04T06:10:45","slug":"uyazvimost-v-glibc-ld-so-pozvolyayushhaya-poluchit-prava-root-v-sisteme","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimost-v-glibc-ld-so-pozvolyayushhaya-poluchit-prava-root-v-sisteme","title":{"rendered":"Dob\u00ebsi n\u00eb Glibc ld.so q\u00eb mund\u00ebson marrjen e t\u00eb drejtave root n\u00eb sistem","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Kompania Qualys ka zbuluar nj\u00eb dob\u00ebsi t\u00eb rrezikshme (CVE-2023-4911) n\u00eb ngarkuesin ld.so, i cili shp\u00ebrndahet si pjes\u00eb e bibliotek\u00ebs sistemore C Glibc (GNU libc). Dob\u00ebsia i lejon nj\u00eb p\u00ebrdoruesi lokal t\u00eb rris\u00eb privilegjet n\u00eb sistem duke p\u00ebrcaktuar t\u00eb dh\u00ebna t\u00eb formatuara posa\u00e7\u00ebrisht n\u00eb variabl\u00ebn e mjedisit GLIBC_TUNABLES p\u00ebrpara nisjes s\u00eb nj\u00eb skedari t\u00eb ekzekutuesh\u00ebm me flamurin suid root, p\u00ebr shembull, \/usr\/bin\/su.    <\/p>\n<p>Mund\u00ebsia e shfryt\u00ebzimit t\u00eb suksessh\u00ebm t\u00eb k\u00ebsaj dob\u00ebsie \u00ebsht\u00eb demonstruar n\u00eb Fedora 37 dhe 38, Ubuntu 22.04 dhe 23.04, Debian 12 dhe 13. Supozohet se dob\u00ebsia shfaqet edhe n\u00eb \u00e7do shp\u00ebrndarje tjet\u00ebr q\u00eb p\u00ebrdor Glibc. Shp\u00ebrndarjet e bazuara n\u00eb bibliotek\u00ebn sistemore C Musl, si Alpine Linux, nuk preken nga ky problem. Dob\u00ebsia \u00ebsht\u00eb korrigjuar n\u00eb patch-in e shtuar m\u00eb 2 tetor. Ecuria e publikimit t\u00eb p\u00ebrdit\u00ebsimeve t\u00eb paketave n\u00eb shp\u00ebrndarje mund t\u00eb ndiqet n\u00eb faqet e Debian, Ubuntu, RHEL, SUSE\/openSUSE, Fedora, Arch, Gentoo, ALT Linux.    <\/p>\n<p>Vulnerabiliteti \u00ebsht\u00eb shkaktuar nga nj\u00eb ndryshim i b\u00ebr\u00eb n\u00eb prill 2021 dhe \u00ebsht\u00eb p\u00ebrfshir\u00eb n\u00eb versionin glibc 2.34. P\u00ebr shkak t\u00eb nj\u00eb gabimi n\u00eb kodin e analiz\u00ebs s\u00eb vargjeve t\u00eb caktuara n\u00eb variablin e mjedisit GLIBC_TUNABLES, nj\u00eb kombinim i pap\u00ebrshtatsh\u00ebm parametrash n\u00eb k\u00ebt\u00eb variab\u00ebl \u00e7on n\u00eb shkrynjen e vler\u00ebs s\u00eb analizuar jasht\u00eb kufijve t\u00eb memorie t\u00eb alokuar. Problemi shfaqet kur n\u00eb vend t\u00eb sekuencave standarde \u201ename=val\u201c, parametrat jan\u00eb caktuar n\u00eb form\u00ebn e dy caktimeve \u201ename=name=val\u201c. N\u00eb k\u00ebt\u00eb rast, caktimi p\u00ebrpunoj\u00eb dy her\u00eb, s\u00eb pari si \u201ename=name=val\u201c, dhe m\u00eb pas si \u201ename=val\u201c. P\u00ebr shkak t\u00eb k\u00ebtij p\u00ebrpunimi t\u00eb dyfisht\u00eb, formohet treguesi \u201ename=name=val:name=val\u201c, i cili ka nj\u00eb madh\u00ebsi q\u00eb tejkalon madh\u00ebsin\u00eb e buferave tunestr.      <\/p>\n<p>K\u00ebrkuesit kan\u00eb p\u00ebrgatitur nj\u00eb eksploit t\u00eb q\u00ebndruesh\u00ebm, i cili lejon marrjen e privilegjeve root duke u aplikuar praktikisht me \u00e7do program q\u00eb ka flamurin suid root. P\u00ebrjashtim b\u00ebjn\u00eb utiliteti sudo (nd\u00ebrron vler\u00ebn ELF RUNPATH), utilitetet chage dhe passwd n\u00eb Fedora (mbrohen me rregulla t\u00eb ve\u00e7anta SELinux) dhe utiliteti snap-confine n\u00eb Ubuntu (mbrohet me rregulla t\u00eb ve\u00e7anta AppArmor). Metoda e propozuar e shfryt\u00ebzimit gjithashtu nuk funksionon n\u00eb RHEL 8 dhe RHEL 9, megjith\u00ebse k\u00ebto deg\u00eb jan\u00eb t\u00eb ekspozuara ndaj dob\u00ebsis\u00eb (p\u00ebr sulmin k\u00ebrkohet krijimi i nj\u00eb eksploit tjet\u00ebr). Kodi i eksploitit do t\u00eb publikohet m\u00eb von\u00eb, pas eliminimit t\u00eb p\u00ebrgjithsh\u00ebm t\u00eb dob\u00ebsis\u00eb. P\u00ebr t\u00eb kontrolluar n\u00ebse sistemi juaj \u00ebsht\u00eb i ekspozuar ndaj k\u00ebsaj dob\u00ebsie, mund t\u00eb p\u00ebrdorni komand\u00ebn e m\u00ebposhtme, e cila n\u00eb rast se ka nj\u00eb problem do t\u00eb p\u00ebrfundoj\u00eb me d\u00ebshtim: env -i \"GLIBC_TUNABLES=glibc.malloc.mxfast=glibc.malloc.mxfast=A\" \"Z=`printf '192x' 1`\" \/usr\/bin\/su --help      <\/p>\n<p>Ve\u00e7mas theksohet edhe korrigjimi i dy dob\u00ebsive t\u00eb tjera n\u00eb Glibc:  <\/p>\n<ul>\n<li class=\"l\"> CVE-2023-4806 \u2014 akses n\u00eb nj\u00eb zon\u00eb t\u00eb liruar t\u00eb memories (use-after-free) n\u00eb funksionin getaddrinfo(), i cili shfaqet kur plugin NSS implementon vet\u00ebm thirrjet e call-back \u201e_gethostbyname2_r\u201c dhe \u201e_getcanonname_r\u201c, por nuk mb\u00ebshtet thirrjen \u201e_gethostbyname3_r\u201c. P\u00ebr shfryt\u00ebzimin e dob\u00ebsis\u00eb, serveri DNS duhet t\u00eb kthej\u00eb nj\u00eb num\u00ebr t\u00eb madh adresash IPv6 dhe IPv4 p\u00ebr hostin e k\u00ebrkuar, gj\u00eb q\u00eb do t\u00eb rezultoj\u00eb n\u00eb d\u00ebshtimin e procesit q\u00eb thirri funksionin getaddrinfo p\u00ebr familjen AF_INET6 duke vendosur flamujt AI_CANONNAME, AI_ALL dhe AI_V4MAPPED.\n<li class=\"l\"> CVE-2023-5156 \u2014 rrjedhja e p\u00ebrmbajtjes s\u00eb memories gjat\u00eb thirrjes s\u00eb funksionit getaddrinfo p\u00ebr familjen e adresave AF_INET6 me flamujt AI_CANONNAME, AI_ALL dhe AI_V4MAPPED.        <\/ul>\n<p>Burimi: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=59867\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f Qualys \u0432\u044b\u044f\u0432\u0438\u043b\u0430 \u043e\u043f\u0430\u0441\u043d\u0443\u044e \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2023-4911) \u0432 \u043a\u043e\u043c\u043f\u043e\u043d\u043e\u0432\u0449\u0438\u043a\u0435 ld.so, \u043f\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u0435\u043c\u043e\u043c \u0432 \u0441\u043e\u0441\u0442\u0430\u0432\u0435 \u0441\u0438\u0441\u0442\u0435\u043c\u043d\u043e\u0439 \u0421\u0438-\u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0438 Glibc (GNU libc). \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u043b\u043e\u043a\u0430\u043b\u044c\u043d\u043e\u043c\u0443 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e \u043f\u043e\u0434\u043d\u044f\u0442\u044c \u0441\u0432\u043e\u0438 \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0438 \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435 \u0447\u0435\u0440\u0435\u0437 \u0443\u043a\u0430\u0437\u0430\u043d\u0438\u0435 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043e\u0444\u043e\u0440\u043c\u043b\u0435\u043d\u043d\u044b\u0445 \u0434\u0430\u043d\u043d\u044b\u0445 \u0432 \u043f\u0435\u0440\u0435\u043c\u0435\u043d\u043d\u043e\u0439 \u043e\u043a\u0440\u0443\u0436\u0435\u043d\u0438\u044f GLIBC_TUNABLES \u043f\u0435\u0440\u0435\u0434 \u0437\u0430\u043f\u0443\u0441\u043a\u043e\u043c \u0438\u0441\u043f\u043e\u043b\u043d\u044f\u0435\u043c\u043e\u0433\u043e \u0444\u0430\u0439\u043b\u0430 \u0441 \u0444\u043b\u0430\u0433\u043e\u043c suid root, \u043d\u0430\u043f\u0440\u0438\u043c\u0435\u0440, \/usr\/bin\/su. \u0412\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u044c \u0443\u0441\u043f\u0435\u0448\u043d\u043e\u0439 \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0430\u0446\u0438\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u043f\u0440\u043e\u0434\u0435\u043c\u043e\u043d\u0441\u0442\u0440\u0438\u0440\u043e\u0432\u0430\u043d\u0430 \u0432 Fedora 37 \u0438 38, [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-110411","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f Qualys \u0432\u044b\u044f\u0432\u0438\u043b\u0430 \u043e\u043f\u0430\u0441\u043d\u0443\u044e \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2023-4911) \u0432 \u043a\u043e\u043c\u043f\u043e\u043d\u043e\u0432\u0449\u0438\u043a\u0435 ld.so, \u043f\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u0435\u043c\u043e\u043c \u0432 \u0441\u043e\u0441\u0442\u0430\u0432\u0435 \u0441\u0438\u0441\u0442\u0435\u043c\u043d\u043e\u0439 \u0421\u0438-\u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0438 Glibc (GNU libc).\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimost-v-glibc-ld-so-pozvolyayushhaya-poluchit-prava-root-v-sisteme\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 Glibc ld.so, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u043f\u0440\u0430\u0432\u0430 root \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f Qualys \u0432\u044b\u044f\u0432\u0438\u043b\u0430 \u043e\u043f\u0430\u0441\u043d\u0443\u044e \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2023-4911) \u0432 \u043a\u043e\u043c\u043f\u043e\u043d\u043e\u0432\u0449\u0438\u043a\u0435 ld.so, \u043f\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u0435\u043c\u043e\u043c \u0432 \u0441\u043e\u0441\u0442\u0430\u0432\u0435 \u0441\u0438\u0441\u0442\u0435\u043c\u043d\u043e\u0439 \u0421\u0438-\u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0438 Glibc (GNU libc).\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimost-v-glibc-ld-so-pozvolyayushhaya-poluchit-prava-root-v-sisteme\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2023-10-04T06:10:45+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2023-10-04T06:10:45+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Dob\u00ebsi n\u00eb Glibc ld.so q\u00eb lejon marrjen e t\u00eb drejtave root n\u00eb sistem | ProHoster","description":"Kompania Qualys ka zbuluar nj\u00eb dob\u00ebsi t\u00eb rrezikshme (CVE-2023-4911) n\u00eb ngarkuesin ld.so, i shp\u00ebrndar\u00eb si pjes\u00eb e bibliotek\u00ebs sistemore C Glibc (GNU libc).","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimost-v-glibc-ld-so-pozvolyayushhaya-poluchit-prava-root-v-sisteme","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 Glibc ld.so, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u043f\u0440\u0430\u0432\u0430 root \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435 | ProHoster","og:description":"\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f Qualys \u0432\u044b\u044f\u0432\u0438\u043b\u0430 \u043e\u043f\u0430\u0441\u043d\u0443\u044e \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2023-4911) \u0432 \u043a\u043e\u043c\u043f\u043e\u043d\u043e\u0432\u0449\u0438\u043a\u0435 ld.so, \u043f\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u0435\u043c\u043e\u043c \u0432 \u0441\u043e\u0441\u0442\u0430\u0432\u0435 \u0441\u0438\u0441\u0442\u0435\u043c\u043d\u043e\u0439 \u0421\u0438-\u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0438 Glibc (GNU libc).","og:url":"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimost-v-glibc-ld-so-pozvolyayushhaya-poluchit-prava-root-v-sisteme","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2023-10-04T06:10:45+00:00","article:modified_time":"2023-10-04T06:10:45+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":[],"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/110411","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=110411"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/110411\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=110411"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=110411"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=110411"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}