{"id":41582,"date":"2020-02-12T16:19:30","date_gmt":"2020-02-12T13:19:30","guid":{"rendered":"https:\/\/prohoster.info\/blog\/blog_prohoster\/uyazvimost-v-systemd-potenczialno-pozvolyayushhaya-povysit-svoi-privilegii"},"modified":"2020-02-12T16:19:30","modified_gmt":"2020-02-12T13:19:30","slug":"uyazvimost-v-systemd-potenczialno-pozvolyayushhaya-povysit-svoi-privilegii","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/uyazvimost-v-systemd-potenczialno-pozvolyayushhaya-povysit-svoi-privilegii","title":{"rendered":"Vulnerabilitet n\u00eb systemd, q\u00eb potencialisht lejon rritjen e privilegjeve","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>N\u00eb menaxherin e sistemit systemd <noindex><a rel=\"nofollow\" href=\"https:\/\/www.openwall.com\/lists\/oss-security\/2020\/02\/05\/1\">u identifikua<\/a><\/noindex> vulneraibiliteti (<noindex><a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2020-1712\">CVE-2020-1712<\/a><\/noindex>), e cila potencialisht lejon arrinj\u00ebn e ekzekutimit t\u00eb kodit me privilegje t\u00eb rritura p\u00ebrmes d\u00ebrgimit t\u00eb nj\u00eb k\u00ebrkese t\u00eb ve\u00e7ant\u00eb n\u00eb autobusin DBus. Problemi \u00ebsht\u00eb rregulluar n\u00eb versionin testues <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/systemd\/systemd\/commit\/ea0d0ede03c6f18dbc5036c5e9cccf97e415ccc2\">systemd 245-rc1<\/a><\/noindex> (patch-et q\u00eb zgjidhin problemin: <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/systemd\/systemd\/commit\/1068447e6954dc6ce52f099ed174c442cb89ed54\">1<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/systemd\/systemd\/commit\/637486261528e8aa3da9f26a4487dc254f4b7abb\">2<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/systemd\/systemd\/commit\/bc130b6858327b382b07b3985cf48e2aa9016b2d\">3<\/a><\/noindex>). Vulnerabiliteti \u00ebsht\u00eb eliminuar n\u00eb distribuimet <noindex><a rel=\"nofollow\" href=\"https:\/\/people.canonical.com\/~ubuntu-security\/cve\/CVE-2020-1712\">Ubuntu<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=1798414\">Fedora<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=CVE-2020-1712\">RHEL<\/a><\/noindex> (manifestohet n\u00eb RHEL 8, por nuk preku RHEL 7), <noindex><a rel=\"nofollow\" href=\"https:\/\/lists.centos.org\/pipermail\/centos-announce\/2020-February\/035631.html\">CentOS<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/bugzilla.suse.com\/show_bug.cgi?id=CVE-2020-1712\">SUSE\/openSUSE<\/a><\/noindex> dhe <noindex><a rel=\"nofollow\" href=\"https:\/\/bugzilla.rosalinux.ru\/show_bug.cgi?id=10451\">ROSA<\/a><\/noindex>, por n\u00eb momentin e shkruajtes s\u00eb lajmit mbetet e pap\u00ebrmir\u00ebsuar n\u00eb <noindex><a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2020-1712\">Debian<\/a><\/noindex> dhe <noindex><a rel=\"nofollow\" href=\"https:\/\/security.archlinux.org\/CVE-2020-1712\">Arch Linux<\/a><\/noindex>. <\/p>\n<p>Vulnerabiliteti shkaktohet nga aksesimi i nj\u00eb zone t\u00eb liruar t\u00eb memories (use-after-free), q\u00eb ndodh gjat\u00eb ekzekutimit asinkron t\u00eb k\u00ebrkesave ndaj Polkit gjat\u00eb p\u00ebrpunimit t\u00eb mesazheve DBus. Disa interfaca DBus p\u00ebrdorin nj\u00eb memorie cache p\u00ebr t\u00eb ruajtur objekte p\u00ebr nj\u00eb koh\u00eb t\u00eb shkurt\u00ebr dhe pastruan elementet e caches sapo autobusi DBus lirohet p\u00ebr t\u00eb p\u00ebrpunuar k\u00ebrkesa t\u00eb tjera. N\u00ebse nj\u00eb menaxher DBus p\u00ebrdor bus_verify_polkit_async(), ai mund t\u00eb duhet t\u00eb pres\u00eb p\u00ebrfundimin e veprimit n\u00eb Polkit. Pas p\u00ebrfundimit t\u00eb Polkit, menaxheri thirret p\u00ebrs\u00ebri dhe i qaset t\u00eb dh\u00ebnave q\u00eb ishin m\u00eb par\u00eb shp\u00ebrndar\u00eb n\u00eb memorie. N\u00ebse k\u00ebrkesa ndaj Polkit zgjat shum\u00eb, elementet n\u00eb cache mund t\u00eb pastruar para se menaxheri DBus t\u00eb thirret p\u00ebr her\u00eb t\u00eb dyt\u00eb. <\/p>\n<p>Nga sh\u00ebrbimet q\u00eb lejojn\u00eb shfryt\u00ebzimin e vulnerabilitetit, p\u00ebrmendet systemd-machined, i cili ofron DBus API org.freedesktop.machine1.Image.Clone, i cili \u00e7on n\u00eb ruajtjen e p\u00ebrkohshme t\u00eb t\u00eb dh\u00ebnave n\u00eb cache dhe qasjen asinkrone ndaj Polkit. Interfaci<br \/>\norg.freedesktop.machine1.Image.Clone \u00ebsht\u00eb i qassh\u00ebm p\u00ebr t\u00eb gjith\u00eb p\u00ebrdoruesit e pafavorizuar t\u00eb sistemit, t\u00eb cil\u00ebt mund t\u00eb iniciativet crash-in e sh\u00ebrbimeve systemd ose potencialisht t\u00eb arrijn\u00eb ekzekutimin e kodit me t\u00eb drejta root (prototipi i exploit-it ende nuk \u00ebsht\u00eb demonstruar). Kodi q\u00eb lejon shfryt\u00ebzimin e vulnerabilitetit ishte <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/systemd\/systemd\/commit\/70244d1d25eb80b57e160ea004d0e6bf793d4caf\">u shtua<\/a><\/noindex> n\u00eb systemd-machined n\u00eb vitin <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=42278\">systemd 220<\/a><\/noindex> (n\u00eb RHEL 7.x p\u00ebrdoret systemd 219). <\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Burimi: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=52340\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u0441\u0438\u0441\u0442\u0435\u043c\u043d\u043e\u043c \u043c\u0435\u043d\u0435\u0434\u0436\u0435\u0440\u0435 systemd \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2020-1712), \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u043f\u043e\u0442\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u0434\u043e\u0431\u0438\u0442\u044c\u0441\u044f \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u0441\u0432\u043e\u0435\u0433\u043e \u043a\u043e\u0434\u0430 \u0441 \u043f\u043e\u0432\u044b\u0448\u0435\u043d\u043d\u044b\u043c\u0438 \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u044f\u043c\u0438 \u0447\u0435\u0440\u0435\u0437 \u043e\u0442\u043f\u0440\u0430\u0432\u043a\u0443 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043e\u0444\u043e\u0440\u043c\u043b\u0435\u043d\u043d\u043e\u0433\u043e \u0437\u0430\u043f\u0440\u043e\u0441\u0430 \u043f\u043e \u0448\u0438\u043d\u0435 DBus. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u0438\u0441\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0430 \u0432 \u0442\u0435\u0441\u0442\u043e\u0432\u043e\u043c \u0432\u044b\u043f\u0443\u0441\u043a\u0435 systemd 245-rc1 (\u0440\u0435\u0448\u0430\u044e\u0449\u0438\u0435 \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u0443 \u043f\u0430\u0442\u0447\u0438: 1, 2, 3). \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0430 \u0432 \u0434\u0438\u0441\u0442\u0440\u0438\u0431\u0443\u0442\u0438\u0432\u0430\u0445 Ubuntu, Fedora, RHEL (\u043f\u0440\u043e\u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u0432 RHEL 8, \u043d\u043e \u043d\u0435 \u0437\u0430\u0442\u0440\u0430\u0433\u0438\u0432\u0430\u0435\u0442 RHEL 7), CentOS, [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[],"tags":[],"class_list":["post-41582","post","type-post","status-publish","format-standard","hentry"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.0.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u0441\u0438\u0441\u0442\u0435\u043c\u043d\u043e\u043c \u043c\u0435\u043d\u0435\u0434\u0436\u0435\u0440\u0435 systemd \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/uyazvimost-v-systemd-potenczialno-pozvolyayushhaya-povysit-svoi-privilegii\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.0.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 systemd, \u043f\u043e\u0442\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043f\u043e\u0432\u044b\u0441\u0438\u0442\u044c \u0441\u0432\u043e\u0438 \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0438 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u0441\u0438\u0441\u0442\u0435\u043c\u043d\u043e\u043c \u043c\u0435\u043d\u0435\u0434\u0436\u0435\u0440\u0435 systemd \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/uyazvimost-v-systemd-potenczialno-pozvolyayushhaya-povysit-svoi-privilegii\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-02-12T13:19:30+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-02-12T13:19:30+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vuln\u00ebrabiliteti n\u00eb systemd, i cili potencialisht lejon rritjen e privilegjeve | ProHoster","description":"Nj\u00eb cenueshm\u00ebri \u00ebsht\u00eb identifikuar n\u00eb menaxherin e sistemit systemd (","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/uyazvimost-v-systemd-potenczialno-pozvolyayushhaya-povysit-svoi-privilegii","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 systemd, \u043f\u043e\u0442\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043f\u043e\u0432\u044b\u0441\u0438\u0442\u044c \u0441\u0432\u043e\u0438 \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0438 | ProHoster","og:description":"\u0412 \u0441\u0438\u0441\u0442\u0435\u043c\u043d\u043e\u043c \u043c\u0435\u043d\u0435\u0434\u0436\u0435\u0440\u0435 systemd \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (","og:url":"https:\/\/prohoster.info\/sq\/blog\/uyazvimost-v-systemd-potenczialno-pozvolyayushhaya-povysit-svoi-privilegii","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-02-12T13:19:30+00:00","article:modified_time":"2020-02-12T13:19:30+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"41582","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 00:14:28","updated":"2022-09-30 17:11:33","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/41582","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=41582"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/41582\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=41582"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=41582"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=41582"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}