Overview
Security updates for DPDK, Linux kernel, QEMU, ImageMagick, Ghostscript and
more, plus Joe and Alex talk about how to get into information security.
This week in Ubuntu Security Updates
[USN-4189-1] DPDK vulnerability [01:00]
1 CVEs addressed in Bionic, Disco, EoanCVE-2019-14818 Data Plane Development Kit - Memory and file-descriptor leak, able to betriggered by a malicious master or a container with access to the
vhost_user socket
[USN-4190-1] libjpeg-turbo vulnerabilities [01:41]
4 CVEs addressed in Xenial, Bionic, DiscoCVE-2019-2201 CVE-2018-20330 CVE-2018-19664 CVE-2018-14498 2 x heap-buffer overflow - crash or possible RCE2 x heap-buffer overread - crash[USN-4183-2] Linux kernel vulnerability [02:48]
9 CVEs addressed in EoanCVE-2019-17666 CVE-2019-16746 CVE-2019-15793 CVE-2019-15792 CVE-2019-15791 CVE-2019-0154 CVE-2018-12207 CVE-2019-11135 CVE-2019-0155 Episode 53 - Extra update for CVE-2019-0155 (i915 blitter command streamer) - previousone was based on an in-flight patch that got changed at the last minute
before the CRD - part of this fix is to whitelist certain commands to the
command-streamer, and this is done via a bitmask - this used a memset()
to zero it out but assumed the size of the underlying data was 32-bit -
so on 64-bit platforms this becomes a 64-bit size and so half the bitmask
is not zeroed out - meaning the whitelist may be able to be bypassed -
this fix includes the final upstream fix
[USN-4184-2] Linux kernel vulnerability and regression [04:37]
14 CVEs addressed in Bionic (HWE), DiscoCVE-2019-17666 CVE-2019-17056 CVE-2019-17055 CVE-2019-17054 CVE-2019-17053 CVE-2019-17052 CVE-2019-15793 CVE-2019-15792 CVE-2019-15791 CVE-2019-15098 CVE-2019-0154 CVE-2018-12207 CVE-2019-11135 CVE-2019-0155 See above (i915 vuln) - but also includes a fix for a regression that wasintroduced in last week’s kernel - KVM guests would fail to launch if
extended page tables were disabled or not supported.
[USN-4185-3] Linux kernel vulnerability and regression [05:05]
11 CVEs addressed in Xenial (HWE), BionicCVE-2019-17666 CVE-2019-17056 CVE-2019-17055 CVE-2019-17054 CVE-2019-17053 CVE-2019-17052 CVE-2019-15098 CVE-2019-0154 CVE-2018-12207 CVE-2019-11135 CVE-2019-0155 See above (both i915 vuln and KVM regression)[USN-4186-3] Linux kernel vulnerability [05:22]
13 CVEs addressed in XenialCVE-2019-2215 CVE-2019-17666 CVE-2019-17056 CVE-2019-17055 CVE-2019-17054 CVE-2019-17053 CVE-2019-17052 CVE-2019-16746 CVE-2019-15098 CVE-2019-0154 CVE-2018-12207 CVE-2019-11135 CVE-2019-0155 i915 vuln[USN-4191-1, USN-4191-2] QEMU vulnerabilities [05:32]
5 CVEs addressed in Trusty ESM, Xenial, Bionic, Disco, EoanCVE-2019-15890 CVE-2019-14378 CVE-2019-13164 CVE-2019-12155 CVE-2019-12068 Heap buffer overflow and UAF in SLiRP networking implementation - DoS +possible code exec
Bridge helper didn’t validate interface names to be within IFNAMSIZ -could be used to bypass ACL restrictions
NULL pointer dereference in qxl paravirtual graphics driver - DoSPossible CPU based DoS via an infinite loop able to be triggered in theLSI SCSI adaptor emulator
[USN-4192-1] ImageMagick vulnerabilities [06:48]
30 CVEs addressed in Xenial, Bionic, Disco, EoanCVE-2019-16713 CVE-2019-16711 CVE-2019-16710 CVE-2019-16709 CVE-2019-16708 CVE-2019-15140 CVE-2019-15139 CVE-2019-14981 CVE-2019-13454 CVE-2019-13391 CVE-2019-13311 CVE-2019-13310 CVE-2019-13309 CVE-2019-13308 CVE-2019-13307 CVE-2019-13306 CVE-2019-13305 CVE-2019-13304 CVE-2019-13301 CVE-2019-13300 CVE-2019-13297 CVE-2019-13295 CVE-2019-13137 CVE-2019-13135 CVE-2019-12979 CVE-2019-12978 CVE-2019-12977 CVE-2019-12976 CVE-2019-12975 CVE-2019-12974 Usual raft of issues - DoS, RCE etc - in various image decoders etc - sojust need to display or process a malicious image via ImageMagick to
trigger - interestingly, seems to be noticed - some applications (Emacs)
chose not to automatically link against and use ImageMagick now as a
result of all the various vulnerablilties which keep being found in it…
[USN-4193-1] Ghostscript vulnerability [08:13]
1 CVEs addressed in Xenial, Bionic, Disco, EoanCVE-2019-14869 Another -dSAFER bypass - newest Ghostscript is not affected since itrewrote the SAFER sandbox - but older versions are - allows a malicious
postscript file to bypass the sandbox and access files or execute
commands etc.
[USN-4194-1] postgresql-common vulnerability [09:17]
1 CVEs addressed in Xenial, Bionic, Disco, EoanCVE-2019-3466 Privesc via arbitrary directory creation through the pg_ctlclustercommand - allows to create a dir as postgres user - say
/usr/lib/sudo/haswell - then dump a shared lib there which will be loaded
by sudo to gain a root shell - by specifying this as the
stats_temp_directory in the config
Interesting but requires ability to configure and run as postgres[USN-4195-1] MySQL vulnerabilities [11:07]
29 CVEs addressed in Xenial, Bionic, Disco, EoanCVE-2019-3018 CVE-2019-3011 CVE-2019-3009 CVE-2019-3004 CVE-2019-3003 CVE-2019-2998 CVE-2019-2997 CVE-2019-2993 CVE-2019-2991 CVE-2019-2982 CVE-2019-2974 CVE-2019-2969 CVE-2019-2968 CVE-2019-2967 CVE-2019-2966 CVE-2019-2963 CVE-2019-2960 CVE-2019-2957 CVE-2019-2950 CVE-2019-2948 CVE-2019-2946 CVE-2019-2938 CVE-2019-2924 CVE-2019-2923 CVE-2019-2922 CVE-2019-2920 CVE-2019-2914 CVE-2019-2911 CVE-2019-2910 Multiple issues fixed in MySQL - updated to 8.0.18 in eoan, whilst inxenial, bionic and disco - 5.7.28 - for more details see upstream notices
https://dev.mysql.com/doc/relnotes/mysql/5.7/en/news-5-7-28.htmlhttps://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-18.htmlhttps://www.oracle.com/security-alerts/cpuoct2019.html[USN-4196-1] python-ecdsa vulnerabilities [11:42]
2 CVEs addressed in Xenial, Bionic, Disco, EoanCVE-2019-14859 CVE-2019-14853 Issues in handling DER encoding of signatures - failed to verify properDER encoding but also might raise exceptions unexpectedly on valid input
so would cause a DoS
Goings on in Ubuntu Security Community
Joe and Alex discuss how to get into infosec [12:18]
Get in contact
#ubuntu-security on the Libera.Chat IRC networkubuntu-hardened mailing listSecurity section on discourse.ubuntu.com@ubuntu_sec on twitter