{"id":39427,"date":"2019-10-31T22:32:37","date_gmt":"2019-10-31T19:32:37","guid":{"rendered":"https:\/\/prohoster.info\/blog\/10-uyazvimostej-v-gipervizore-xen\/"},"modified":"2019-10-31T22:32:37","modified_gmt":"2019-10-31T19:32:37","slug":"10-uyazvimostej-v-gipervizore-xen","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/novosti-interneta\/10-uyazvimostej-v-gipervizore-xen","title":{"rendered":"10 vulnerabilitete n\u00eb hipervizorin Xen","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><noindex><a rel=\"nofollow\" href=\"https:\/\/www.openwall.com\/lists\/oss-security\/2019\/10\/25\/\">Publikuar<\/a><\/noindex> informacione mbi 10 vulnerabilitete n\u00eb hipervizorin Xen, prej t\u00eb cilave pes\u00eb (<noindex><a rel=\"nofollow\" href=\"https:\/\/www.openwall.com\/lists\/oss-security\/2019\/10\/25\/6\">CVE-2019-17341<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/www.openwall.com\/lists\/oss-security\/2019\/10\/25\/2\">CVE-2019-17342<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/www.openwall.com\/lists\/oss-security\/2019\/10\/25\/1\">CVE-2019-17340<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/www.openwall.com\/lists\/oss-security\/2019\/10\/25\/5\">CVE-2019-17346<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/www.openwall.com\/lists\/oss-security\/2019\/10\/25\/10\">CVE-2019-17343<\/a><\/noindex>) potencialisht lejojn\u00eb daljen jasht\u00eb mjedisit aktual t\u00eb mysafir\u00ebve dhe rritjen e privilegjeve, nj\u00eb vulnerabilitet (CVE-2019-17347) i jep mund\u00ebsin\u00eb nj\u00eb procesi pa privilegje t\u00eb marr\u00eb kontrollin mbi proceset e p\u00ebrdoruesve t\u00eb tjer\u00eb n\u00eb t\u00eb nj\u00ebjtin sistem mysafir, kat\u00ebr t\u00eb tjer\u00eb (CVE-2019-17344, CVE-2019-17345, CVE-2019-17348, CVE-2019-17351) vulnerabilitetet mund t\u00eb shkaktojn\u00eb nj\u00eb d\u00ebshtim t\u00eb sh\u00ebrbimit (kolaps t\u00eb mjedisit t\u00eb hostit). Problemet jan\u00eb zgjidhur n\u00eb versionet <noindex><a rel=\"nofollow\" href=\"https:\/\/xenproject.org\/downloads\/\">Xen 4.12.1, 4.11.2 dhe 4.10.4<\/a><\/noindex>.<\/p>\n<ul>\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/www.openwall.com\/lists\/oss-security\/2019\/10\/25\/6\">CVE-2019-17341<\/a><\/noindex> \u2014 mund\u00ebsi p\u00ebr sistemin e mysafir\u00ebve n\u00ebn kontrollin e sulmuesit t\u00eb fitoj\u00eb qasje n\u00eb nivelin e hipervizorit. Problemi shfaqet vet\u00ebm n\u00eb sistemet x86 dhe mund t\u00eb realizohet nga sistemet mysafir\u00eb q\u00eb punojn\u00eb n\u00eb rethana paravirtualizimi (PV), kur kalon nj\u00eb pajisje PCI t\u00eb re n\u00eb sistemin e mysafir\u00ebve n\u00eb pun\u00eb. N\u00eb sistemet mysafir\u00eb q\u00eb punojn\u00eb n\u00eb rethanat HVM dhe PVH, kjo dob\u00ebsi nuk shfaqet;\n<li class=\"l\">  <noindex><a rel=\"nofollow\" href=\"https:\/\/www.openwall.com\/lists\/oss-security\/2019\/10\/25\/1\">CVE-2019-17340<\/a><\/noindex> \u2014 rrjedhje memories, e cila potencialisht mund t\u00eb lejoj\u00eb rritjen e privilegjeve ose qasjen n\u00eb t\u00eb dh\u00ebnat e sistemeve t\u00eb tjera mysafir\u00ebsh.<br \/>\nProblemi shfaqet vet\u00ebm n\u00eb hostet me m\u00eb shum\u00eb se 16 TB RAM n\u00eb sistemet 64-bit dhe 168 GB n\u00eb 32-bit.<br \/>\nVulnerabiliteti mund t\u00eb eksploatohet vet\u00ebm nga sistemet mysafir\u00eb n\u00eb m\u00ebnyr\u00eb PV (n\u00eb modet HVM dhe PVH kur punoni p\u00ebrmes libxl, vulnerabiliteti nuk shfaqet);<\/p>\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/www.openwall.com\/lists\/oss-security\/2019\/10\/25\/5\">CVE-2019-17346<\/a><\/noindex> \u2014 dob\u00ebsi gjat\u00eb p\u00ebrdorimit t\u00eb PCID (T\u00eb Identifikuesve t\u00eb Kontekstit t\u00eb Procesit) p\u00ebr t\u00eb rritur performanc\u00ebn e mbrojtjes nga sulmet<br \/>\nMeltdown, lejon qasjen n\u00eb t\u00eb dh\u00ebnat e sistemeve t\u00eb tjera t\u00eb mysafir\u00ebve dhe potencialisht rritjen e privilegjeve. Vulnerabiliteti mund t\u00eb eksploatohet vet\u00ebm nga sistemet mysafir\u00eb n\u00eb m\u00ebnyr\u00eb PV n\u00eb sistemet x86 (problemi nuk shfaqet n\u00eb modet HVM dhe PVH, as n\u00eb konfigurimet ku nuk ka sisteme mysafir\u00ebsh me PCID t\u00eb aktivizuar (PCID aktivizohet automatikisht));<\/p>\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/www.openwall.com\/lists\/oss-security\/2019\/10\/25\/2\">CVE-2019-17342<\/a><\/noindex> \u2014 problemi n\u00eb zbatimin e hipervizorit XENMEM_exchange lejon rritjen e privilegjeve n\u00eb ambiente me vet\u00ebm nj\u00eb sistem mysafir. Dob\u00ebsia mund t\u00eb shfryt\u00ebzohet vet\u00ebm nga sistemet mysafir\u00eb n\u00eb rethanat PV (n\u00eb rethanat HVM dhe PVH, dob\u00ebsia nuk shfaqet);\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/www.openwall.com\/lists\/oss-security\/2019\/10\/25\/10\">CVE-2019-17343<\/a><\/noindex> \u2014 mapimi i pap\u00ebrshtatsh\u00ebm n\u00eb IOMMU lejon q\u00eb, n\u00ebse ka qasje nga sistemi i mysafir\u00ebve n\u00eb pajisjen fizike, t\u00eb p\u00ebrdoret DMA p\u00ebr t\u00eb ndryshuar tabel\u00ebn e vet t\u00eb faqeve t\u00eb memories dhe p\u00ebr t\u00eb fituar qasje n\u00eb nivelin e hostit. Dob\u00ebsia shfaqet vet\u00ebm n\u00eb sistemet mysafir\u00eb n\u00eb rethanat PV kur ka t\u00eb drejta p\u00ebr kalimin e pajisjeve PCI.\n<\/ul>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Burimi: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51764\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d\u044b \u0441\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u043e 10 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044f\u0445 \u0432 \u0433\u0438\u043f\u0435\u0440\u0432\u0438\u0437\u043e\u0440\u0435 Xen, \u0438\u0437 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043f\u044f\u0442\u044c (CVE-2019-17341, CVE-2019-17342, CVE-2019-17340, CVE-2019-17346, CVE-2019-17343) \u043f\u043e\u0442\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0442 \u0432\u044b\u0439\u0442\u0438 \u0437\u0430 \u043f\u0440\u0435\u0434\u0435\u043b\u044b \u0442\u0435\u043a\u0443\u0449\u0435\u0433\u043e \u0433\u043e\u0441\u0442\u0435\u0432\u043e\u0433\u043e \u043e\u043a\u0440\u0443\u0436\u0435\u043d\u0438\u044f \u0438 \u043f\u043e\u0432\u044b\u0441\u0438\u0442\u044c \u0441\u0432\u043e\u0438 \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0438, \u043e\u0434\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2019-17347) \u0434\u0430\u0451\u0442 \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u044c \u043d\u0435\u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u043c\u0443 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0443 \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u043a\u043e\u043d\u0442\u0440\u043e\u043b\u044c \u043d\u0430\u0434 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430\u043c\u0438 \u0434\u0440\u0443\u0433\u0438\u0445 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0432 \u0442\u043e\u0439 \u0436\u0435 \u0433\u043e\u0441\u0442\u0435\u0432\u043e\u0439 \u0441\u0438\u0441\u0442\u0435\u043c\u0435, \u043e\u0441\u0442\u0430\u0432\u0448\u0438\u0435\u0441\u044f \u0447\u0435\u0442\u044b\u0440\u0435 (CVE-2019-17344, CVE-2019-17345, CVE-2019-17348, CVE-2019-17351) \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0442 \u0432\u044b\u0437\u0432\u0430\u0442\u044c [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-39427","post","type-post","status-publish","format-standard","hentry","category-novosti-interneta"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.0.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d\u044b \u0441\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u043e 10 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044f\u0445 \u0432 \u0433\u0438\u043f\u0435\u0440\u0432\u0438\u0437\u043e\u0440\u0435 Xen, \u0438\u0437 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043f\u044f\u0442\u044c (\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/novosti-interneta\/10-uyazvimostej-v-gipervizore-xen\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.0.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd4710 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0432 \u0433\u0438\u043f\u0435\u0440\u0432\u0438\u0437\u043e\u0440\u0435 Xen | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d\u044b \u0441\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u043e 10 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044f\u0445 \u0432 \u0433\u0438\u043f\u0435\u0440\u0432\u0438\u0437\u043e\u0440\u0435 Xen, \u0438\u0437 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043f\u044f\u0442\u044c (\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/novosti-interneta\/10-uyazvimostej-v-gipervizore-xen\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:32:37+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T19:32:37+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd4710 vulnerabilitete n\u00eb hipervizorin Xen | ProHoster","description":"Jan\u00eb publikuar informacionet p\u00ebr 10 vulnerabilitete n\u00eb hipervizorin Xen, nga t\u00eb cilat pes\u00eb (","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/novosti-interneta\/10-uyazvimostej-v-gipervizore-xen","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd4710 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0432 \u0433\u0438\u043f\u0435\u0440\u0432\u0438\u0437\u043e\u0440\u0435 Xen | ProHoster","og:description":"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d\u044b \u0441\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u043e 10 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044f\u0445 \u0432 \u0433\u0438\u043f\u0435\u0440\u0432\u0438\u0437\u043e\u0440\u0435 Xen, \u0438\u0437 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043f\u044f\u0442\u044c (","og:url":"https:\/\/prohoster.info\/sq\/blog\/novosti-interneta\/10-uyazvimostej-v-gipervizore-xen","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:32:37+00:00","article:modified_time":"2019-10-31T19:32:37+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"39427","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-24 01:57:20","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 00:50:24","updated":"2026-01-24 01:57:20","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/39427","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=39427"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/39427\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=39427"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=39427"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=39427"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}