Overview
This week we look at some details of the 43 unique CVEs addressed across the
supported Ubuntu releases and talk about the recently announced Extended
Security Maintenance support for Ubuntu 14.04 Trusty Tahr.
This week in Ubuntu Security Updates
43 unique CVEs addressed across the various supported releases of Ubuntu
(Bionic, Xenial, Trusty and Precise ESM)
[USN-3762-1, USN-3762-2] Linux kernel vulnerabilities
2 CVEs addressed in Bionic and corresponding HWE kernel for XenialCVE-2017-13695CVE-2018-1118Both information disclosure vulnerabilities which could allow exposure of kernel addressesNot directly an issue but could be used to defeat ASLR when combined with another vulnerability[USN-3763-1] Linux kernel vulnerability
1 CVEs addressed in Precise ESMCVE-2018-5390SegmentSmack (see episode 0)[LSN-0043-1] Linux kernel vulnerability
Livepatch to fix multiple vulnerabilities fixed in previous kernel package updates[USN-3764-1] Zsh vulnerabilities
3 CVEs addressed in Trusty, Xenial, BionicCVE-2018-1100CVE-2018-13259CVE-2018-05022 issues in shebang / hashbang handlingshebang lines longer than 64 bytes truncated - could execute wrong interpretermishandling of some particular formatted shebang lines which could executeinterpreter from second line of file
Stack based buffer-overflow allowing code execution in the context of a different user[USN-3747-2] OpenJDK 10 regression
4 CVEs addressed in BionicCVE-2018-2972CVE-2018-2952CVE-2018-2826CVE-2018-2825[USN-3761-2, USN-3761-3] Firefox regressions
5 CVEs addressed in Trusty, Xenial, BionicCVE-2018-12383CVE-2018-12378CVE-2018-12377CVE-2018-12376CVE-2018-12375Previous update to latest firefox resulted in issues due to language packsmissing (and hence missing spellcheck dictionaries) and use of wrong search
provider
[USN-3765-1, USN-3765-2] curl vulnerability
1 CVEs addressed in Trusty, Xenial, Bionic and Precise ESMCVE-2018-14618Similar to previous CVE-2017-8816 - integer overflow in calculations duringNTLM authentication could allow heap buffer overflow and hence RCE
Uses the password length in this calculation (which is supplied by the attacker) so relatively easy to trigger[USN-3722-5] ClamAV regression
2 CVEs addressed in Trusty, Xenial, BionicCVE-2018-0361CVE-2018-0360[USN-3766-1, USN-3766-2] PHP vulnerabilities
3 CVEs addressed in Trusty, Xenial, Bionic and Precise ESMCVE-2018-14883CVE-2018-14851CVE-2015-9253Integer overflows in JPEG and EXIF handlers leading to out-of-bounds reads and hence crash - DoSphp-fpm (FastCGI process manager) - alternative FastCGI implementation forPHP - could cause DoS since didn’t restart child processes correctly - then
consume CPU and disk space (via logging) - only fixed in Bionic for now
[USN-3722-6] ClamAV vulnerabilities
2 CVEs addressed in Precise ESMCVE-2018-0361CVE-2018-0360[USN-3767-1, USN-3767-2] GLib vulnerabilities
2 CVEs addressed in Trusty, Xenial, Bionic and Precise ESMCVE-2018-16429CVE-2018-16428Issues with markup parsing[USN-3768-1] Ghostscript vulnerabilities
16 CVEs addressed in Trusty, Xenial, BionicCVE-2018-16802CVE-2018-16585CVE-2018-16543CVE-2018-16542CVE-2018-16541CVE-2018-16540CVE-2018-16539CVE-2018-16513CVE-2018-16511CVE-2018-16510CVE-2018-16509CVE-2018-15911CVE-2018-15910CVE-2018-15909CVE-2018-15908CVE-2018-11645Ghostscript is used to process Postscript (and other formats) - PS is TuringComplete so in general is unsafe
Hence Ghostscript includes a sandbox (-dSAFER) to try and prevent issues withhandling of untrusted files
Tavis Ormandy previously found a number of issues in the SAFER sandbox whichallowed escape from it and execution of commands (ie. CVE-2016-7977 etc.)
Recently discovered more - including ability to execute arbitrary code.[USN-3769-1] Bind vulnerability
1 CVEs addressed in Trusty, Xenial, BionicCVE-2018-5740Trigger assertion failure from specific input from remote server to cause crash and hence DoSIn deny-answer-aliases feature which is not enabled by default so not so high impact[USN-3770-1, USN-3770-2] Little CMS vulnerabilities
2 CVEs addressed in Trusty, Xenial, Bionic and Precise ESMCVE-2018-16435CVE-2016-101651 CVEs addressed in Precise ESM onlyCVE-2013-4276Multiple issues in handling of ICC colour profiles (integer overflow leadingto stack and heap buffer overflows on reads an writes)
Little CMS often used in webapps which do image processing - in this caseallows remote DoS or possibly remote code execution
Goings on in Ubuntu Security Community
Ubuntu 14.04 ESM Announced
Extended Security Maintenance for Trusty 14.04 past the official EOLSecurity updates for the kernel and the most widely used packages in mainhttps://blog.ubuntu.com/2018/09/19/extended-security-maintenance-ubuntu-14-04-trusty-tahrHiring
Ubuntu Security Manager
https://boards.greenhouse.io/canonical/jobs/1278287Ubuntu Security Engineer
https://boards.greenhouse.io/canonical/jobs/1158266Get in contact
#ubuntu-security on the Libera.Chat IRC network@ubuntu_sec on twitter