{"id":125693,"date":"2025-05-30T15:06:05","date_gmt":"2025-05-30T13:06:05","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimosti-v-apport-i-systemd-coredump-pozvolyayushhie-izvlech-heshi-parolej-polzovatelej-sistemy"},"modified":"2025-05-30T15:06:05","modified_gmt":"2025-05-30T13:06:05","slug":"uyazvimosti-v-apport-i-systemd-coredump-pozvolyayushhie-izvlech-heshi-parolej-polzovatelej-sistemy","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/novosti-interneta\/uyazvimosti-v-apport-i-systemd-coredump-pozvolyayushhie-izvlech-heshi-parolej-polzovatelej-sistemy","title":{"rendered":"Vulnerabilitetet n\u00eb apport dhe systemd-coredump, t\u00eb cilat lejojn\u00eb nxjerrjen e hash-eve t\u00eb fjal\u00ebkalimeve t\u00eb p\u00ebrdoruesve t\u00eb sistemit.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Kompania Qualys identifikoi dy vulnerabilitete n\u00eb mjetet apport (CVE-2025-5054) dhe systemd-coredump (CVE-2025-4598), t\u00eb cilat p\u00ebrdoren p\u00ebr trajtimin e skedar\u00ebve core, t\u00eb gjeneruar pas p\u00ebrfundimit t\u00eb papritur t\u00eb proceseve. Vulnerabilitetet lejojn\u00eb qasjen n\u00eb skedar\u00ebt core t\u00eb ruajtur pas p\u00ebrfundimit t\u00eb papritur t\u00eb aplikacioneve suid ose disa proceseve t\u00eb sistemit, n\u00eb memorien e t\u00eb cil\u00ebve mund t\u00eb p\u00ebrmbahen akreditive t\u00eb ruajtura apo \u00e7el\u00ebsa kriptimi. Mjeti apport thirret automatikisht p\u00ebr ruajtjen e core-damp\u00ebve n\u00eb Ubuntu, nd\u00ebrsa systemd-coredump n\u00eb Red Hat Enterprise Linux 9+, Fedora dhe shum\u00eb distribucione t\u00eb tjera Linux.      <\/p>\n<p>Ka demonstruar nj\u00eb teknik\u00eb sulmi, n\u00eb t\u00eb cil\u00ebn krijoheshin kushte p\u00ebr p\u00ebrfundimin e papritur t\u00eb aplikacionit suid unix_chkpwd dhe p\u00ebr t\u00eb marr\u00eb qasje n\u00eb skedarin core me dump-in e gjendjes gjat\u00eb crash-it. N\u00eb dump-in e ruajtur core ishin pranishme heshat e fjal\u00ebkalimeve t\u00eb p\u00ebrdoruesve t\u00eb sistemit, q\u00eb kishin mbetur n\u00eb memorien e procesit q\u00eb kishte p\u00ebrfunduar papritur pas ngarkimit t\u00eb p\u00ebrmbajtjes nga \/etc\/shadow. Mund\u00ebsia e shfryt\u00ebzimit t\u00eb vulnerabiliteteve \u00ebsht\u00eb demonstruar n\u00eb Ubuntu 24.04 dhe Fedora 40\/41, por supozohet se edhe distribucione t\u00eb tjera jan\u00eb t\u00eb ndjeshme ndaj k\u00ebtyre sulmeve.        <\/p>\n<p>T\u00eb dy vulnerabilitetet shkaktohen nga nj\u00eb gjendje garash, e cila lejon q\u00eb procesi suid i p\u00ebrfunduar papritur t\u00eb z\u00ebvend\u00ebsohet me nj\u00eb proces tjet\u00ebr n\u00eb momentin pas fillimit t\u00eb trajtimit nga b\u00ebrthama t\u00eb p\u00ebrfundimit t\u00eb papritur, por para se t\u00eb verifikohen nga menaxheri i hap\u00ebsir\u00ebs s\u00eb p\u00ebrdoruesit parametrat e procesit p\u00ebrmes \/proc\/pid\/files. Thirrja e apport dhe systemd-coredump b\u00ebhet si m\u00eb posht\u00eb: b\u00ebrthama, pas marrjes s\u00eb informacionit p\u00ebr p\u00ebrfundimin e procesit, th\u00ebrret menaxherin, i cili \u00ebsht\u00eb treguar n\u00eb skedarin \/proc\/sys\/kernel\/core_pattern, dhe pastaj i d\u00ebrgon p\u00ebrmbajtjen e core-dampit p\u00ebrmes rrjedh\u00ebs hyr\u00ebse.    <\/p>\n<p>Generimi i core-dampit dhe ekzekutimi i menaxherit nuk ndodhin menj\u00ebher\u00eb dhe ka mjaft koh\u00eb p\u00ebr t\u00eb z\u00ebvend\u00ebsuar procesin e p\u00ebrfunduar suid me nj\u00eb proces t\u00eb zakonsh\u00ebm t\u00eb p\u00ebrdoruesit. N\u00eb rast z\u00ebvend\u00ebsimi, menaxheri i core-damp\u00ebve do t\u00eb mendoj\u00eb se d\u00ebshtimi ndodhi jo n\u00eb procesin suid, por n\u00eb nj\u00eb aplikacion t\u00eb zakonsh\u00ebm t\u00eb p\u00ebrdoruesit dhe, p\u00ebr pasoj\u00eb, do t\u00eb ruaj\u00eb skedarin core me mund\u00ebsin\u00eb e qasjes s\u00eb p\u00ebrdoruesit t\u00eb zakonsh\u00ebm, jo vet\u00ebm administratorit.    <\/p>\n<p>Sulmi ndaj apport kufizohet n\u00eb hapat e m\u00ebposht\u00ebm:  <\/p>\n<ul>\n<li class=\"l\"> Nj\u00eb proces i ri krijohet dhe thirret funksioni execve() p\u00ebr t\u00eb nisur programin suid, si\u00e7 \u00ebsht\u00eb unix_chkpwd.\n<li class=\"l\"> P\u00ebrjashtohet koha e nevojshme p\u00ebr ngarkimin e t\u00eb dh\u00ebnave konfidenciale n\u00eb memorien e programit suid (n\u00eb rastin e unix_chkpwd pritet ngarkimi i heshave t\u00eb fjal\u00ebkalimeve t\u00eb t\u00eb gjith\u00eb p\u00ebrdoruesve t\u00eb sistemit nga skedari \/etc\/shadow).\n<li class=\"l\"> Para p\u00ebrfundimit t\u00eb ekzekutimit t\u00eb urdhrit, procesit i d\u00ebrgohet sinjali SIGSEGV ose SIGSYS p\u00ebr p\u00ebrfundimin e papritur.\n<li class=\"l\"> N\u00eb p\u00ebrgjigje t\u00eb p\u00ebrfundimit t\u00eb papritur, b\u00ebrthama formon core-dampin dhe nis procesin apport p\u00ebr trajtimin e core-dampit n\u00eb hap\u00ebsir\u00ebn e p\u00ebrdoruesit.\n<li class=\"l\"> Pas nisjes s\u00eb apport, por para se t\u00eb fillohet analiza procesit q\u00eb ka p\u00ebrfunduar papritur, i d\u00ebrgohet sinjali SIGKILL dhe vet\u00eb procesi z\u00ebvend\u00ebsohet me nj\u00eb tjet\u00ebr pa flagun suid. p\u00ebr t\u00eb anashkaluar verifikimet n\u00eb apport, procesi i ri krijohet brenda hap\u00ebsirave t\u00eb ve\u00e7anta t\u00eb emrave (user, pid dhe mount namespace).\n<li class=\"l\"> apport lidhet me soketin unix \/run\/apport.socket n\u00eb hap\u00ebsir\u00ebn e emrave t\u00eb montimit t\u00eb krijuar p\u00ebr procesin e ri dhe d\u00ebrgon nj\u00eb deshifrim skedari p\u00ebr qasje n\u00eb core-damp.    <\/ul>\n<p>P\u00ebr t\u00eb marr\u00eb identifikuesin e nevojsh\u00ebm p\u00ebr procesin e ri, i cili p\u00ebrputhet me identifikuesin e procesit suid, p\u00ebrpara d\u00ebrgimit t\u00eb sinjalit SIGSEGV procesi suid ndalohet me sinjalin SIGSTOP dhe gjat\u00eb ndalimit krijohen ciklikisht procese t\u00eb reja derisa t\u00eb fitohet PID me numrin paraprak, t\u00eb af\u00ebrt me procesin suid q\u00eb po z\u00ebvend\u00ebsohet. Pas zhvendosjes s\u00eb numrave t\u00eb PID, proceseve suid u d\u00ebrgohen sinjalet SIGSEGV dhe SIGCONT, pas t\u00eb cilave d\u00ebrgohet SIGKILL dhe ciklikisht krijohen procese t\u00eb reja p\u00ebr t\u00eb arritur t\u00eb nj\u00ebjtin PID si ai i procesit suid.      <\/p>\n<p>Sa i p\u00ebrket systemd-coredump, nga nj\u00ebra an\u00eb, realizimi i nj\u00eb sulmi ndaj tij \u00ebsht\u00eb m\u00eb i leht\u00eb, pasi nuk ka nevoj\u00eb t\u00eb z\u00ebvend\u00ebsohet nj\u00eb proces suid me nj\u00eb proces n\u00eb nj\u00eb hap\u00ebsir\u00eb t\u00eb ve\u00e7ant\u00eb p\u00ebrdoruesi dhe \u00ebsht\u00eb mjaft e mjaftueshme t\u00eb arrihet p\u00ebrputhja e AT_UID dhe AT_EUID. Nga ana tjet\u00ebr, systemd-coredump \u00ebsht\u00eb shkruar n\u00eb gjuh\u00ebn C dhe ekzekutohet mjaft shpejt, gj\u00eb q\u00eb ofron m\u00eb pak koh\u00eb p\u00ebr z\u00ebvend\u00ebsim, ndryshe nga apport, i cili \u00ebsht\u00eb shkruar n\u00eb Python dhe gjat\u00eb procesit t\u00eb inicializimit ngarkon skedar\u00eb t\u00eb ndrysh\u00ebm pyc. Kjo problematik\u00eb zgjidhet me ngadal\u00ebsimin artificial t\u00eb systemd-coredump \u2014 gjat\u00eb thirrjes s\u00eb skedarit suid, kalohen shum\u00eb argumente t\u00eb m\u00ebdha t\u00eb komand\u00ebs, duke krijuar vones\u00ebn e nevojshme q\u00eb ndodh gjat\u00eb analizimit t\u00eb \/proc\/pid\/cmdline.        <\/p>\n<p>Gjat\u00eb procesit t\u00eb analiz\u00ebs s\u00eb vulnerabiliteteve, studiuesit identifikuan gjithashtu se systemd-coredump, kur konfigurimi i thirrjes nuk p\u00ebrcakton n\u00eb \/proc\/sys\/kernel\/core_pattern flamurin '%d', lejon q\u00eb sulmuesi t\u00eb zbatoj\u00eb nj\u00eb nd\u00ebrprerje t\u00eb papritur t\u00eb proceseve n\u00eb sfond q\u00eb executeshen me t\u00eb drejta root dhe q\u00eb branchojn\u00eb procese t\u00eb tjera me nj\u00eb identifikues p\u00ebrdoruesi q\u00eb ndryshon n\u00eb nj\u00eb p\u00ebrdorues jo t\u00eb privilegjuar n\u00ebn t\u00eb cilin kryhet sulmi. Kjo mund\u00ebsi lejon kryerjen e sulmeve jo vet\u00ebm ndaj aplikacioneve setuid, por edhe ndaj proceseve t\u00eb tilla si sshd-session (OpenSSH), sd-pam (systemd) dhe cron, p\u00ebr t\u00eb marr\u00eb t\u00eb dh\u00ebna t\u00eb ndjeshme q\u00eb mbeten n\u00eb memorien e tyre, t\u00eb tilla si \u00e7el\u00ebsa privat\u00eb, hash-e fjal\u00ebkalimesh nga \/etc\/shadow, etiketat kanarin\u00eb nga stack-u dhe t\u00eb dh\u00ebna p\u00ebr kalimin e randomizimit t\u00eb hap\u00ebsir\u00ebs adresuese (ASLR).        <\/p>\n<p>Mund t\u00eb ndjekim publikimin e azhurnimeve t\u00eb pakove n\u00eb distribucione t\u00eb tilla si: Debian, Ubuntu, RHEL, openSUSE, Fedora, Gentoo, Arch. Si nj\u00eb zgjidhje p\u00ebr t\u00eb bllokuar dob\u00ebsit\u00eb, sugjerohet t\u00eb \u00e7aktivizoni ruajtjen e core-dumps p\u00ebr programet suid dhe p\u00ebr proceset q\u00eb d\u00ebrgojn\u00eb privilegjet, duke caktuar parametrin \/proc\/sys\/fs\/suid_dumpable n\u00eb vler\u00ebn 0. P\u00ebr t\u00eb eliminuar plot\u00ebsisht problemin, \u00ebsht\u00eb e nevojshme t\u00eb b\u00ebhen ndryshime n\u00eb b\u00ebrtham\u00ebn e Linux-it, q\u00eb implementon mund\u00ebsin\u00eb e transfert\u00ebs s\u00eb informacionit p\u00ebr proceset q\u00eb jan\u00eb ndaluar aksidentalisht p\u00ebrmes mekanizmit pidfd (pidfd lidhet me procese t\u00eb caktuara dhe, ndryshe nga pid, nuk ri-caktohet).<br \/>\n<br \/>Burimi: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=63328\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f Qualys \u0432\u044b\u044f\u0432\u0438\u043b\u0430 \u0434\u0432\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 \u0438\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u0430\u0445 apport (CVE-2025-5054) \u0438 systemd-coredump (CVE-2025-4598), \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u044b\u0445 \u0434\u043b\u044f \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0438 core-\u0444\u0430\u0439\u043b\u043e\u0432, \u0433\u0435\u043d\u0435\u0440\u0438\u0440\u0443\u0435\u043c\u044b\u0445 \u043f\u043e\u0441\u043b\u0435 \u0430\u0432\u0430\u0440\u0438\u0439\u043d\u043e\u0433\u043e \u0437\u0430\u0432\u0435\u0440\u0448\u0435\u043d\u0438\u044f \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u043e\u0432. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0442 \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u0434\u043e\u0441\u0442\u0443\u043f \u043a core-\u0444\u0430\u0439\u043b\u0430\u043c, \u0441\u043e\u0445\u0440\u0430\u043d\u0451\u043d\u043d\u044b\u043c \u043f\u043e\u0441\u043b\u0435 \u0430\u0432\u0430\u0440\u0438\u0439\u043d\u043e\u0433\u043e \u0437\u0430\u0432\u0435\u0440\u0448\u0435\u043d\u0438\u044f suid-\u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439 \u0438\u043b\u0438 \u043d\u0435\u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u0441\u0438\u0441\u0442\u0435\u043c\u043d\u044b\u0445 \u0444\u043e\u043d\u043e\u0432\u044b\u0445 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u043e\u0432, \u0432 \u043f\u0430\u043c\u044f\u0442\u0438 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043c\u043e\u0433\u0443\u0442 \u0441\u043e\u0434\u0435\u0440\u0436\u0430\u0442\u044c\u0441\u044f \u043f\u0440\u043e\u043a\u044d\u0448\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u0435 \u0443\u0447\u0451\u0442\u043d\u044b\u0435 \u0434\u0430\u043d\u043d\u044b\u0435 \u0438\u043b\u0438 \u043a\u043b\u044e\u0447\u0438 \u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043d\u0438\u044f. \u0423\u0442\u0438\u043b\u0438\u0442\u0430 apport \u0430\u0432\u0442\u043e\u043c\u0430\u0442\u0438\u0447\u0435\u0441\u043a\u0438 \u0432\u044b\u0437\u044b\u0432\u0430\u0435\u0442\u0441\u044f \u0434\u043b\u044f \u0441\u043e\u0445\u0440\u0430\u043d\u0435\u043d\u0438\u044f core-\u0434\u0430\u043c\u043f\u043e\u0432 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-125693","post","type-post","status-publish","format-standard","hentry","category-novosti-interneta"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 4.9.10 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f Qualys \u0432\u044b\u044f\u0432\u0438\u043b\u0430 \u0434\u0432\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 \u0438\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u0430\u0445 apport (CVE-2025-5054) \u0438 systemd-coredump (CVE-2025-4598), \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u044b\u0445 \u0434\u043b\u044f \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0438 core-\u0444\u0430\u0439\u043b\u043e\u0432, \u0433\u0435\u043d\u0435\u0440\u0438\u0440\u0443\u0435\u043c\u044b\u0445 \u043f\u043e\u0441\u043b\u0435 \u0430\u0432\u0430\u0440\u0438\u0439\u043d\u043e\u0433\u043e \u0437\u0430\u0432\u0435\u0440\u0448\u0435\u043d\u0438\u044f \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u043e\u0432. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0442 \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u0434\u043e\u0441\u0442\u0443\u043f \u043a core-\u0444\u0430\u0439\u043b\u0430\u043c, \u0441\u043e\u0445\u0440\u0430\u043d\u0451\u043d\u043d\u044b\u043c \u043f\u043e\u0441\u043b\u0435 \u0430\u0432\u0430\u0440\u0438\u0439\u043d\u043e\u0433\u043e \u0437\u0430\u0432\u0435\u0440\u0448\u0435\u043d\u0438\u044f suid-\u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439 \u0438\u043b\u0438 \u043d\u0435\u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u0441\u0438\u0441\u0442\u0435\u043c\u043d\u044b\u0445 \u0444\u043e\u043d\u043e\u0432\u044b\u0445 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u043e\u0432, \u0432 \u043f\u0430\u043c\u044f\u0442\u0438 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043c\u043e\u0433\u0443\u0442 \u0441\u043e\u0434\u0435\u0440\u0436\u0430\u0442\u044c\u0441\u044f \u043f\u0440\u043e\u043a\u044d\u0448\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u0435 \u0443\u0447\u0451\u0442\u043d\u044b\u0435 \u0434\u0430\u043d\u043d\u044b\u0435 \u0438\u043b\u0438 \u043a\u043b\u044e\u0447\u0438 \u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043d\u0438\u044f. \u0423\u0442\u0438\u043b\u0438\u0442\u0430 apport \u0430\u0432\u0442\u043e\u043c\u0430\u0442\u0438\u0447\u0435\u0441\u043a\u0438 \u0432\u044b\u0437\u044b\u0432\u0430\u0435\u0442\u0441\u044f \u0434\u043b\u044f \u0441\u043e\u0445\u0440\u0430\u043d\u0435\u043d\u0438\u044f core-\u0434\u0430\u043c\u043f\u043e\u0432\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/novosti-interneta\/uyazvimosti-v-apport-i-systemd-coredump-pozvolyayushhie-izvlech-heshi-parolej-polzovatelej-sistemy\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 4.9.10\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 apport \u0438 systemd-coredump, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0435 \u0438\u0437\u0432\u043b\u0435\u0447\u044c \u0445\u044d\u0448\u0438 \u043f\u0430\u0440\u043e\u043b\u0435\u0439 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0441\u0438\u0441\u0442\u0435\u043c\u044b | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f Qualys \u0432\u044b\u044f\u0432\u0438\u043b\u0430 \u0434\u0432\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 \u0438\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u0430\u0445 apport (CVE-2025-5054) \u0438 systemd-coredump (CVE-2025-4598), \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u044b\u0445 \u0434\u043b\u044f \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0438 core-\u0444\u0430\u0439\u043b\u043e\u0432, \u0433\u0435\u043d\u0435\u0440\u0438\u0440\u0443\u0435\u043c\u044b\u0445 \u043f\u043e\u0441\u043b\u0435 \u0430\u0432\u0430\u0440\u0438\u0439\u043d\u043e\u0433\u043e \u0437\u0430\u0432\u0435\u0440\u0448\u0435\u043d\u0438\u044f \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u043e\u0432. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0442 \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u0434\u043e\u0441\u0442\u0443\u043f \u043a core-\u0444\u0430\u0439\u043b\u0430\u043c, \u0441\u043e\u0445\u0440\u0430\u043d\u0451\u043d\u043d\u044b\u043c \u043f\u043e\u0441\u043b\u0435 \u0430\u0432\u0430\u0440\u0438\u0439\u043d\u043e\u0433\u043e \u0437\u0430\u0432\u0435\u0440\u0448\u0435\u043d\u0438\u044f suid-\u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439 \u0438\u043b\u0438 \u043d\u0435\u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u0441\u0438\u0441\u0442\u0435\u043c\u043d\u044b\u0445 \u0444\u043e\u043d\u043e\u0432\u044b\u0445 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u043e\u0432, \u0432 \u043f\u0430\u043c\u044f\u0442\u0438 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043c\u043e\u0433\u0443\u0442 \u0441\u043e\u0434\u0435\u0440\u0436\u0430\u0442\u044c\u0441\u044f \u043f\u0440\u043e\u043a\u044d\u0448\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u0435 \u0443\u0447\u0451\u0442\u043d\u044b\u0435 \u0434\u0430\u043d\u043d\u044b\u0435 \u0438\u043b\u0438 \u043a\u043b\u044e\u0447\u0438 \u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043d\u0438\u044f. \u0423\u0442\u0438\u043b\u0438\u0442\u0430 apport \u0430\u0432\u0442\u043e\u043c\u0430\u0442\u0438\u0447\u0435\u0441\u043a\u0438 \u0432\u044b\u0437\u044b\u0432\u0430\u0435\u0442\u0441\u044f \u0434\u043b\u044f \u0441\u043e\u0445\u0440\u0430\u043d\u0435\u043d\u0438\u044f core-\u0434\u0430\u043c\u043f\u043e\u0432\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/novosti-interneta\/uyazvimosti-v-apport-i-systemd-coredump-pozvolyayushhie-izvlech-heshi-parolej-polzovatelej-sistemy\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2025-05-30T13:06:05+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2025-05-30T13:06:05+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Dob\u00ebsit\u00eb n\u00eb apport dhe systemd-coredump, q\u00eb lejojn\u00eb nxjerrjen e hashes e fjal\u00ebkalimeve t\u00eb p\u00ebrdoruesve t\u00eb sistemit | ProHoster","description":"Kompania Qualys zbuloi dy dob\u00ebsi n\u00eb mjetet apport (CVE-2025-5054) dhe systemd-coredump (CVE-2025-4598), t\u00eb cilat p\u00ebrdoren p\u00ebr t\u00eb trajtuar skedar\u00ebt core, t\u00eb gjeneruar pas ndalimit aksidental t\u00eb proceseve. Dob\u00ebsit\u00eb lejojn\u00eb aksesin n\u00eb skedar\u00ebt core t\u00eb ruajtur pas ndalimit t\u00eb aplikacioneve suid ose disa proceseve t\u00eb sistemit n\u00eb sfond, n\u00eb memorjen e t\u00eb cilave mund t\u00eb jen\u00eb t\u00eb ruajtura akreditimet e skeduar ose \u00e7el\u00ebsat e enkriptimit. Utiliteti apport thirret automatikisht p\u00ebr t\u00eb ruajtur core-dumps.","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/novosti-interneta\/uyazvimosti-v-apport-i-systemd-coredump-pozvolyayushhie-izvlech-heshi-parolej-polzovatelej-sistemy","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 apport \u0438 systemd-coredump, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0435 \u0438\u0437\u0432\u043b\u0435\u0447\u044c \u0445\u044d\u0448\u0438 \u043f\u0430\u0440\u043e\u043b\u0435\u0439 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0441\u0438\u0441\u0442\u0435\u043c\u044b | ProHoster","og:description":"\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f Qualys \u0432\u044b\u044f\u0432\u0438\u043b\u0430 \u0434\u0432\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 \u0438\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u0430\u0445 apport (CVE-2025-5054) \u0438 systemd-coredump (CVE-2025-4598), \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u044b\u0445 \u0434\u043b\u044f \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0438 core-\u0444\u0430\u0439\u043b\u043e\u0432, \u0433\u0435\u043d\u0435\u0440\u0438\u0440\u0443\u0435\u043c\u044b\u0445 \u043f\u043e\u0441\u043b\u0435 \u0430\u0432\u0430\u0440\u0438\u0439\u043d\u043e\u0433\u043e \u0437\u0430\u0432\u0435\u0440\u0448\u0435\u043d\u0438\u044f \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u043e\u0432. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0442 \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u0434\u043e\u0441\u0442\u0443\u043f \u043a core-\u0444\u0430\u0439\u043b\u0430\u043c, \u0441\u043e\u0445\u0440\u0430\u043d\u0451\u043d\u043d\u044b\u043c \u043f\u043e\u0441\u043b\u0435 \u0430\u0432\u0430\u0440\u0438\u0439\u043d\u043e\u0433\u043e \u0437\u0430\u0432\u0435\u0440\u0448\u0435\u043d\u0438\u044f suid-\u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439 \u0438\u043b\u0438 \u043d\u0435\u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u0441\u0438\u0441\u0442\u0435\u043c\u043d\u044b\u0445 \u0444\u043e\u043d\u043e\u0432\u044b\u0445 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u043e\u0432, \u0432 \u043f\u0430\u043c\u044f\u0442\u0438 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043c\u043e\u0433\u0443\u0442 \u0441\u043e\u0434\u0435\u0440\u0436\u0430\u0442\u044c\u0441\u044f \u043f\u0440\u043e\u043a\u044d\u0448\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u0435 \u0443\u0447\u0451\u0442\u043d\u044b\u0435 \u0434\u0430\u043d\u043d\u044b\u0435 \u0438\u043b\u0438 \u043a\u043b\u044e\u0447\u0438 \u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043d\u0438\u044f. \u0423\u0442\u0438\u043b\u0438\u0442\u0430 apport \u0430\u0432\u0442\u043e\u043c\u0430\u0442\u0438\u0447\u0435\u0441\u043a\u0438 \u0432\u044b\u0437\u044b\u0432\u0430\u0435\u0442\u0441\u044f \u0434\u043b\u044f \u0441\u043e\u0445\u0440\u0430\u043d\u0435\u043d\u0438\u044f core-\u0434\u0430\u043c\u043f\u043e\u0432","og:url":"https:\/\/prohoster.info\/sq\/blog\/novosti-interneta\/uyazvimosti-v-apport-i-systemd-coredump-pozvolyayushhie-izvlech-heshi-parolej-polzovatelej-sistemy","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2025-05-30T13:06:05+00:00","article:modified_time":"2025-05-30T13:06:05+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"125693","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-23 13:05:20","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2026-01-23 13:05:20","updated":"2026-01-23 13:05:20"},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/125693","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=125693"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/125693\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=125693"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=125693"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=125693"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}