{"id":34705,"date":"2022-03-15T04:09:33","date_gmt":"2022-03-15T06:09:33","guid":{"rendered":"https:\/\/teknomers.com\/fr\/la-faille-linux-dirty-pipe-affecte-une-large-gamme-de-peripheriques-nas-qnap\/"},"modified":"2022-03-15T04:09:53","modified_gmt":"2022-03-15T06:09:53","slug":"la-faille-linux-dirty-pipe-affecte-une-large-gamme-de-peripheriques-nas-qnap","status":"publish","type":"post","link":"https:\/\/teknomers.com\/fr\/la-faille-linux-dirty-pipe-affecte-une-large-gamme-de-peripheriques-nas-qnap\/","title":{"rendered":"La faille Linux &#8216;Dirty Pipe&#8217; affecte une large gamme de p\u00e9riph\u00e9riques NAS QNAP"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both\"><\/div>\n<p>Lundi, le fabricant d&#8217;appareils de stockage en r\u00e9seau (NAS) QNAP a mis en garde contre une vuln\u00e9rabilit\u00e9 Linux r\u00e9cemment r\u00e9v\u00e9l\u00e9e affectant ses appareils qui pourrait \u00eatre exploit\u00e9e pour \u00e9lever les privil\u00e8ges et prendre le contr\u00f4le des syst\u00e8mes concern\u00e9s.<\/p>\n<p>&#8220;Une vuln\u00e9rabilit\u00e9 d&#8217;escalade de privil\u00e8ges locale, \u00e9galement connue sous le nom de&#8221; Dirty Pipe &#8220;, a \u00e9t\u00e9 signal\u00e9e comme affectant le noyau Linux sur QNAP NAS ex\u00e9cutant QTS 5.0.x et QuTS hero h5.0.x&#8221;, a d\u00e9clar\u00e9 la soci\u00e9t\u00e9. <a rel=\"nofollow noopener\" href=\"https:\/\/www.qnap.com\/en-us\/security-advisory\/qsa-22-05\" target=\"_blank\">mentionn\u00e9<\/a>.  &#8220;Si elle est exploit\u00e9e, cette vuln\u00e9rabilit\u00e9 permet \u00e0 un utilisateur non privil\u00e9gi\u00e9 d&#8217;obtenir des privil\u00e8ges d&#8217;administrateur et d&#8217;injecter du code malveillant.&#8221;<\/p>\n<div class=\"ad_two clear\"><a rel=\"nofollow noopener\" href=\"https:\/\/go.thn.li\/cs-feb-header\" target=\"_blank\" title=\"Prevent Data Breaches\"><img loading=\"lazy\" decoding=\"async\" alt=\"Emp\u00eacher les violations de donn\u00e9es\" class=\"lazyload\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2022\/03\/1646326908_645_Correctifs-critiques-publies-pour-la-gamme-Cisco-Expressway-les-produits.jpeg\" width=\"728\" height=\"90\" \/><\/a><\/div>\n<p>La soci\u00e9t\u00e9 ta\u00efwanaise a d\u00e9clar\u00e9 qu&#8217;elle continuait \u00e0 <a rel=\"nofollow noopener\" href=\"https:\/\/www.qnap.com\/en-us\/release-notes\/kernel\" target=\"_blank\">enqu\u00eater sur sa gamme de produits<\/a> pour la vuln\u00e9rabilit\u00e9 et qu&#8217;il n&#8217;y a pas de NAS QNAP ex\u00e9cutant QTS 4.x sont \u00e0 l&#8217;abri de la faille Dirty Pipe.<\/p>\n<div class=\"separator\" style=\"clear: both\"><img decoding=\"async\" alt=\"\" border=\"0\" data-original-height=\"654\" data-original-width=\"728\" src=\"https:\/\/thehackernews.com\/new-images\/img\/a\/AVvXsEgsdVjI1xN2YtY9TgG-BtpY03LfqPZvFQHVoTGBPEbLBoHs3MYwsxcBJeQVbqMs7Q7UUbtCi-grpzQcPZJ0Lp4StFwHg1sL2He-SZhlWn6IxMwKkqn-fV8WCNfdiDfjRvB7q1ox1umW0B-HderXX72kXve657gqAxsmxB-IHdi3RkBV_cT6x7KQoTFm\" \/><\/div>\n<p>Suivi comme CVE-2022-0847 (score CVSS\u00a0: 7,8), la lacune r\u00e9side dans le noyau Linux qui pourrait permettre \u00e0 un attaquant d&#8217;\u00e9craser des donn\u00e9es arbitraires dans n&#8217;importe quel fichier en lecture seule et permettre une prise de contr\u00f4le compl\u00e8te des machines vuln\u00e9rables.<\/p>\n<p>Le probl\u00e8me a depuis \u00e9t\u00e9 r\u00e9solu dans les versions Linux 5.16.11, 5.15.25 et 5.10.102 au 23 f\u00e9vrier 2022, trois jours apr\u00e8s avoir \u00e9t\u00e9 signal\u00e9 \u00e0 l&#8217;\u00e9quipe de s\u00e9curit\u00e9 du noyau Linux.<\/p>\n<p>&#8220;Actuellement, il n&#8217;y a pas d&#8217;att\u00e9nuation disponible pour cette vuln\u00e9rabilit\u00e9&#8221;, a ajout\u00e9 la soci\u00e9t\u00e9.  &#8220;Nous recommandons aux utilisateurs de v\u00e9rifier et d&#8217;installer les mises \u00e0 jour de s\u00e9curit\u00e9 d\u00e8s qu&#8217;elles sont disponibles.&#8221;<\/p>\n<p><\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/thehackernews.com\/2022\/03\/dirty-pipe-linux-flaw-affects-wide.html\" rel=\"nofollow noopener\" target=\"_blank\">ttn-fr-57<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Lundi, le fabricant d&#8217;appareils de stockage en r\u00e9seau (NAS) QNAP a mis en garde contre une vuln\u00e9rabilit\u00e9 Linux r\u00e9cemment r\u00e9v\u00e9l\u00e9e affectant ses appareils qui pourrait \u00eatre exploit\u00e9e pour \u00e9lever les privil\u00e8ges et prendre le contr\u00f4le des syst\u00e8mes concern\u00e9s. &#8220;Une vuln\u00e9rabilit\u00e9 d&#8217;escalade de privil\u00e8ges locale, \u00e9galement connue sous le nom de&#8221; Dirty Pipe &#8220;, a \u00e9t\u00e9 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":34706,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[1132,4168,4158,4165,4161,21770,9048,10893,4157,4159,4171,4170,13287,18088,4167,4160,5266,4163,4162,5265,21771,27510,4172,4169,196,4166,4164],"class_list":["post-34705","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technologie","tag-affecte","tag-comment-pirater","tag-cyber-actualites","tag-cyber-attaques","tag-cyber-mises-a-jour","tag-dirty","tag-faille","tag-gamme","tag-lactualite-de-la-cybersecurite","tag-lactualite-de-la-cybersecurite-aujourdhui","tag-lactualite-des-hackers","tag-la-securite-des-informations","tag-large","tag-linux","tag-logiciel-malveillant-de-ransomware","tag-mises-a-jour-de-la-cybersecurite","tag-nas","tag-nouvelles-de-piratage","tag-nouvelles-de-pirates","tag-peripheriques","tag-pipe","tag-qnap","tag-securite-informatique","tag-securite-internet","tag-une","tag-violation-de-donnees","tag-vulnerabilite-logicielle"],"_links":{"self":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/34705","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/comments?post=34705"}],"version-history":[{"count":0,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/34705\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media\/34706"}],"wp:attachment":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media?parent=34705"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/categories?post=34705"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/tags?post=34705"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}