Overview
This week we look at some details of the 16 unique CVEs addressed across the supported Ubuntu releases and more.
This week in Ubuntu Security Updates
[USN-3816-2] systemd vulnerability
3 CVEs addressed in Xenial, Bionic, CosmicCVE-2018-15687CVE-2018-15686CVE-2018-6954Episode 12 - original fix for CVE-2018-6954 was incomplete - this includes the complete fixAlso includes an update to avoid a possible hang on shutdown in unattended-upgrades - LP #1803391During shutdown, systemd is already in the process of shutting downThen unattended-upgrades runs and it goes and tries to update systemd - which then tries to reexec it - which blocks waiting for it to finish shutting downCreates a deadlock since systemd is waiting on unattended-upgrades to finish but u-u is waiting on systemd reexecFix is to not do reexec if systemd is already in the process of stopping[USN-3825-1, USN-3825-2] mod_perl vulnerability
1 CVEs addressed in Precise ESM, Trusty, Xenial, Bionic, CosmicCVE-2011-2767Old CVE - reported to Debian in 2011, who assigned a CVE internally but didn’t go any further with itRecently the original reporter of the vulnerability submitted a patch to Debian to fix it - so vuln was reported to MitreNow fixed in Ubuntu as well[USN-3801-2] Firefox regressions
12 CVEs addressed in Trusty, Xenial, Bionic, CosmicCVE-2018-12397CVE-2018-12396CVE-2018-12395CVE-2018-12403CVE-2018-12402CVE-2018-12401CVE-2018-12399CVE-2018-12398CVE-2018-12393CVE-2018-12392CVE-2018-12390CVE-2018-12388Firefox update (v63) (Episode 9) had some minor regressionsThese were present in the upstream firefox release itselfThis provides 63.0.3 which contains these fixes from upstream to address the regressionsWebGL hangs, slow page loading if using specific proxy settings etc.Goings on in Ubuntu Security Community
Linux Cryptocoin Malware
https://www.zdnet.com/article/new-linux-crypto-miner-steals-your-root-password-and-disables-your-antivirus/Apparently reports of users affectedRequires SSH to login - bruteforce passwordsUse strong passwords / public key authElevates privileges via two very old CVEsCVE-2016-5195 - Dirty Cow - fixed for Ubuntu in October 2016CVE-2013-2094 - perf root privilege escalation - fixed for Ubuntu in May 2013All Ubuntu users are fine unless you are running a old release AND have not been applying security patchesPlease use strong passwords if enabling openssh serverPreview of next episode
Upcoming fixes
qemu, webkitgtkGet in contact
#ubuntu-security on the Libera.Chat IRC network@ubuntu_sec on twitter