Overview
This week we look at fixes from the past two weeks including BIND, NTFS-3G,
Dovecot, Pacemaker and more, plus we follow up last episodes IoT security
discussion with Joe McManus talking about Ubuntu Core. Finally we cover the
release of Ubuntu 19.04 Disco Dingo and the transition of Ubuntu 14.04
Trusty Tahr to Extended Security Maintenance.
These past two weeks in Ubuntu Security Updates
[USN-3947-1, USN-3947-2] Libxslt vulnerability
1 CVEs addressed in Precise ESM, Trusty, Xenial, Bionic, CosmicCVE-2019-11068Library to transform XML via XML definitionsIncludes a security framework since XSLT can define operations tofetch/read/write files and resources etc
Various functions would return 0 if an operation is not allowed by theframework which was checked for and correctly disallowed - BUT they could
also return -1 on error (say from a potentially bad URL) which would not
be caught and so then would proceed and would fetch from the URL in
question thereby violating the security policy
Fixed to also check for error codes on handle the same as an explicitpolicy violation
[USN-3948-1] WebKitGTK+ vulnerabilities
14 CVEs addressed in Bionic, CosmicCVE-2019-8563CVE-2019-8559CVE-2019-8558CVE-2019-8551CVE-2019-8544CVE-2019-8536CVE-2019-8535CVE-2019-8524CVE-2019-8523CVE-2019-8518CVE-2019-8506CVE-2019-8375CVE-2019-6251CVE-2019-11070Wide mix of issues fixed including XSS and DoS attacks or possiblearbitrary code execution if visiting a malicious website
[USN-3949-1] OpenJDK 11 vulnerability
1 CVEs addressed in BionicCVE-2019-2422Backport of openjdk-11 from Disco to Bionic, includes a minor securityfix to memory disclosure vulnerablity which could enable an attacker to
bypass sandbox
[USN-3918-4] Firefox regressions
17 CVEs addressed in Trusty, Xenial, Bionic, CosmicCVE-2019-9803CVE-2019-9793CVE-2019-9809CVE-2019-9808CVE-2019-9807CVE-2019-9806CVE-2019-9805CVE-2019-9802CVE-2019-9799CVE-2019-9797CVE-2019-9796CVE-2019-9795CVE-2019-9792CVE-2019-9791CVE-2019-9790CVE-2019-9789CVE-2019-9788Episode 26 covered 66.0.2 regression - this is now 66.0.3 to fix furtherregressions in keyboard handling as discussed previously
[USN-3914-2] NTFS-3G update
Affecting Xenial, Bionic, CosmicEpisode 25 covered ntfs-3g update for possible heap buffer overflowAs was setuid root this could possibly be used for root privilegeescalation
This update removes setuid root to additionally harden ntfs-3g so thatany future vulnerablilites can’t be used for privilege escalation
[USN-3950-1] ZNC vulnerability
1 CVEs addressed in CosmicCVE-2019-9917crash -> DoS due to improper handling of character encoding - if a remoteuser specified an invalid encoding it could cause znc to crash
Fixed to fallback to utf-8 if unknown encoding specified[USN-3951-1] Dovecot vulnerability
1 CVEs addressed in Cosmic, DiscoCVE-2019-10691Only affects Dovecot 2.3 and hence only Cosmic, Disco, Eoan etcImproper handling of invalid utf-8 username in JSON encoding could causethe authentication service to crash
[USN-3952-1] Pacemaker vulnerabilities
3 CVEs addressed in Xenial, Bionic, Cosmic, DiscoCVE-2019-3885CVE-2018-16878CVE-2018-16877Cluster resource manager - high availability and load balancing for OpenStackAll discovered by Jan Pokorný - local attacker could possibly escalateprivileges or cause a denial of service or to cause sensitive information
to be leaked to system logs
[USN-3953-1] PHP vulnerabilities
2 CVEs addressed in Xenial, Bionic, Cosmic, DiscoCVE-2019-11035CVE-2019-11034php7.2 and php7.0Buffer over-read when processing certain EXIF tags - possible informationdisclosure or crash -> DoS
[USN-3922-2, USN-3922-3] PHP vulnerabilities
7 CVEs addressed in Precise ESM, TrustyCVE-2019-9641CVE-2019-9640CVE-2019-9639CVE-2019-9638CVE-2019-9637CVE-2019-9675CVE-2019-9022Most covered back in Episode 26[USN-3936-2] AdvanceCOMP vulnerability
1 CVEs addressed in DiscoCVE-2019-9210Corresponding update for Disco - covered in Episode 27[USN-3954-1] FreeRADIUS vulnerabilities
2 CVEs addressed in Bionic, Cosmic, DiscoCVE-2019-11235CVE-2019-112342 possible “Dragonblood” authentication bypass issues - mentioned back inEpisode 28 in the context of wpa_supplicant and hostapd - similar issue
for FreeRADIUS
[USN-3955-1] tcpflow vulnerabilities
2 CVEs addressed in Xenial, Bionic, CosmicCVE-2018-18409CVE-2018-14938Stack based buffer overflow and an integer overflow -> usual effects(crash -> DoS / information disclosure)
[USN-3956-1] Bind vulnerability
1 CVEs addressed in Xenial, Bionic, Cosmic, DiscoCVE-2018-5743DoS - possible to bypass bind’s limits on simultaneous TCP clients and socause a DoS via excessive resource usage
IoT Security follow-up with Joe McManus
Alex and Joe follow up on last episode’s conversation about IoT and inparticular talk about Ubuntu Core and how this has been engineered to
address many of these common IoT security design and implementation flaws
Goings on in Ubuntu Security Community
Ubuntu 19.04 Disco Dingo Released
Released on Thursday 18th AprilOfficially supported by Canonical for 9 months - with security fixes forpackages in main by the security team
Ubuntu 14.04 Trusty Tahr transitions to Extended Security Maintenance
Standard support period concluded on Thursday 25th AprilUsers are encouraged to upgrade to our latest LTS release 18.04 via 16.04Extended security maintenance is now available via Ubuntu Advantagehttps://blog.ubuntu.com/2019/02/05/ubuntu-14-04-trusty-tahrhttps://www.ubuntu.com/esmHiring
Ubuntu Security Generalist
https://boards.greenhouse.io/canonical/jobs/1548812Robotics Security Engineer
https://boards.greenhouse.io/canonical/jobs/1550997Get in contact
#ubuntu-security on the Libera.Chat IRC network@ubuntu_sec on twitter