{"id":130249,"date":"2022-05-06T04:59:30","date_gmt":"2022-05-06T06:59:30","guid":{"rendered":"https:\/\/teknomers.com\/fr\/google-publie-une-mise-a-jour-android-pour-corriger-une-vulnerabilite-activement-exploitee\/"},"modified":"2022-05-06T04:59:47","modified_gmt":"2022-05-06T06:59:47","slug":"google-publie-une-mise-a-jour-android-pour-corriger-une-vulnerabilite-activement-exploitee","status":"publish","type":"post","link":"https:\/\/teknomers.com\/fr\/google-publie-une-mise-a-jour-android-pour-corriger-une-vulnerabilite-activement-exploitee\/","title":{"rendered":"Google publie une mise \u00e0 jour Android pour corriger une vuln\u00e9rabilit\u00e9 activement exploit\u00e9e"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both\"><\/div>\n<p>Google a publi\u00e9 des correctifs de s\u00e9curit\u00e9 mensuels pour Android avec des correctifs pour 37 failles sur diff\u00e9rents composants, dont l&#8217;un est un correctif pour une vuln\u00e9rabilit\u00e9 du noyau Linux activement exploit\u00e9e qui a \u00e9t\u00e9 r\u00e9v\u00e9l\u00e9e plus t\u00f4t cette ann\u00e9e.<\/p>\n<p>Suivi comme <a rel=\"nofollow noopener\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2021-22600\" target=\"_blank\">CVE-2021-22600<\/a> (score CVSS\u00a0: 7,8), la vuln\u00e9rabilit\u00e9 est class\u00e9e &#8220;\u00e9lev\u00e9e&#8221; en termes de gravit\u00e9 et pourrait \u00eatre exploit\u00e9e par un utilisateur local pour \u00e9lever ses privil\u00e8ges ou refuser le service.<\/p>\n<p>Le probl\u00e8me porte sur une <a rel=\"nofollow noopener\" href=\"https:\/\/cwe.mitre.org\/data\/definitions\/415.html\" target=\"_blank\">vuln\u00e9rabilit\u00e9 double-libre<\/a> r\u00e9sidant dans le <a rel=\"nofollow noopener\" href=\"https:\/\/github.com\/torvalds\/linux\/blob\/master\/net\/packet\/af_packet.c\" target=\"_blank\">Paquet<\/a> impl\u00e9mentation de protocole r\u00e9seau dans le noyau Linux pouvant entra\u00eener une corruption de la m\u00e9moire, pouvant conduire \u00e0 un d\u00e9ni de service ou \u00e0 l&#8217;ex\u00e9cution de code arbitraire.<\/p>\n<p>Des correctifs ont \u00e9t\u00e9 publi\u00e9s par diff\u00e9rentes distributions Linux, notamment <a rel=\"nofollow noopener\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2021-22600\" target=\"_blank\">DebianName<\/a>, <a rel=\"nofollow noopener\" href=\"https:\/\/access.redhat.com\/security\/cve\/cve-2021-22600\" target=\"_blank\">chapeau rouge<\/a>, <a rel=\"nofollow noopener\" href=\"https:\/\/www.suse.com\/security\/cve\/CVE-2021-22600.html\" target=\"_blank\">SUSE<\/a>et <a rel=\"nofollow noopener\" href=\"https:\/\/ubuntu.com\/security\/CVE-2021-22600\" target=\"_blank\">Ubuntu<\/a> en janvier 2022.<\/p>\n<p>&#8220;Il y a des indications que CVE-2021-22600 pourrait faire l&#8217;objet d&#8217;une exploitation limit\u00e9e et cibl\u00e9e&#8221;, Google <a rel=\"nofollow noopener\" href=\"https:\/\/source.android.com\/security\/bulletin\/2022-05-01\" target=\"_blank\">c&#8217;est not\u00e9<\/a> dans son Android Security Bulletin de mai 2022. Les d\u00e9tails sur la nature des attaques sont encore inconnus.<\/p>\n<p>Il convient de noter que la vuln\u00e9rabilit\u00e9 a \u00e9galement \u00e9t\u00e9 ajout\u00e9e par la Cybersecurity and Infrastructure Security Agency (CISA) des \u00c9tats-Unis \u00e0 son <a rel=\"nofollow noopener\" href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog\" target=\"_blank\">Catalogue des vuln\u00e9rabilit\u00e9s exploit\u00e9es connues<\/a> le mois dernier sur la base de preuves d&#8217;exploitation active.<\/p>\n<p>Dans le cadre des correctifs de ce mois-ci, trois autres bogues ont \u00e9galement \u00e9t\u00e9 corrig\u00e9s dans le noyau, ainsi que 18 failles de gravit\u00e9 \u00e9lev\u00e9e et une de gravit\u00e9 critique dans les composants MediaTek et Qualcomm.<\/p>\n<p><\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/thehackernews.com\/2022\/05\/google-releases-android-update-to-patch.html\" rel=\"nofollow noopener\" target=\"_blank\">ttn-fr-57<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Google a publi\u00e9 des correctifs de s\u00e9curit\u00e9 mensuels pour Android avec des correctifs pour 37 failles sur diff\u00e9rents composants, dont l&#8217;un est un correctif pour une vuln\u00e9rabilit\u00e9 du noyau Linux activement exploit\u00e9e qui a \u00e9t\u00e9 r\u00e9v\u00e9l\u00e9e plus t\u00f4t cette ann\u00e9e. Suivi comme CVE-2021-22600 (score CVSS\u00a0: 7,8), la vuln\u00e9rabilit\u00e9 est class\u00e9e &#8220;\u00e9lev\u00e9e&#8221; en termes de gravit\u00e9 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":130250,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[4807,8738,4168,25646,4158,4165,4161,36372,7755,3995,4157,4159,4171,4170,4167,2811,4160,4163,4162,185,2212,4172,4169,196,4166,3667,4164],"class_list":["post-130249","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technologie","tag-activement","tag-android","tag-comment-pirater","tag-corriger","tag-cyber-actualites","tag-cyber-attaques","tag-cyber-mises-a-jour","tag-exploitee","tag-google","tag-jour","tag-lactualite-de-la-cybersecurite","tag-lactualite-de-la-cybersecurite-aujourdhui","tag-lactualite-des-hackers","tag-la-securite-des-informations","tag-logiciel-malveillant-de-ransomware","tag-mise","tag-mises-a-jour-de-la-cybersecurite","tag-nouvelles-de-piratage","tag-nouvelles-de-pirates","tag-pour","tag-publie","tag-securite-informatique","tag-securite-internet","tag-une","tag-violation-de-donnees","tag-vulnerabilite","tag-vulnerabilite-logicielle"],"_links":{"self":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/130249","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/comments?post=130249"}],"version-history":[{"count":0,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/130249\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media\/130250"}],"wp:attachment":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media?parent=130249"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/categories?post=130249"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/tags?post=130249"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}