Overview
This week we look at some details of the 78 unique CVEs addressed across the supported Ubuntu releases including more GhostScript, ImageMagick, WebKitGTK, Linux kernel and more.
This week in Ubuntu Security Updates
[USN-3773-1] Ghostscript vulnerabilities
2 CVEs addressed in Trusty, Xenial, BionicCVE-2018-17183CVE-2018-16510Similar to [USN-3768-1] from Episode 5[USN-3769-2] Bind vulnerability
1 CVEs addressed in Precise ESMCVE-2018-5740Extended Security Maintenance version of [USN-3769-1][USN-3774-1] strongSwan vulnerability
1 CVEs addressed in Trusty, Xenial, BionicCVE-2018-17540[USN-3771-1] incorporated fixes for multiple CVEs - but these fixes themselves introduced this new vulnerabilityHeap buffer overflow found by Google’s OSS-Fuzz leading to DoS for gmp plugin[USN-3775-1, USN-3775-2, USN-3776-1, USN-3776-2, USN-3777-1, USN-3777-2] Linux kernel vulnerabilities
11 CVEs addressed across Precise ESM, Trusty, Xenial and Bionic including HWE kernelsCVE-2018-6555CVE-2018-6554CVE-2018-14633CVE-2018-14634CVE-2018-15572CVE-2018-15594CVE-2018-16276CVE-2018-10902CVE-2018-10853CVE-2017-18216CVE-2018-17182Not all CVEs affect all releasesIncludes:UAF and memory leak -> DoS in IRDAStack buffer overwrite in iSCSI - low chance of privilege escalationInteger overflow leading to possible privilege escalation but only on machines with >32GB RAMInsufficiencies discovered in various Spectre variant mitigations previously deployedIncorrect bounds checking in yurex USB driver from userspace -> crash / privilege escalation for local userRace condition in midi driver - double free -> privilege escalationKVM hypervisor instruction emulation fail to check privileges - privilege escalation inside guestOCFS2 file-system driver NULL pointer dereference -> BUG (mutex logic bug)Memory management sequence number overflow leading to UAF -> possible privilege escalation - Jann Horn (GPZ)[USN-3780-1] HAProxy vulnerability
1 CVEs addressed in BionicCVE-2018-14645Out of bounds read leading to remote crash -> DoS[USN-3781-1] WebKitGTK+ vulnerabilities
24 CVEs addressed in BionicCVE-2018-4361CVE-2018-4359CVE-2018-4358CVE-2018-4328CVE-2018-4323CVE-2018-4319CVE-2018-4318CVE-2018-4317CVE-2018-4316CVE-2018-4315CVE-2018-4314CVE-2018-4312CVE-2018-4311CVE-2018-4309CVE-2018-4306CVE-2018-4299CVE-2018-4213CVE-2018-4212CVE-2018-4210CVE-2018-4209CVE-2018-4208CVE-2018-4207CVE-2018-4197CVE-2018-4191Used by many GNOME applications to render web content (Epiphany, Evolution, Boxes, GThumb, Buidler, Empathy, etc)Many issues fixed in this release including, XSS, DoS, RCE etc[USN-3782-1] Liblouis vulnerabilities
2 CVEs addressed in Trusty, Xenial, BionicCVE-2018-17294CVE-2018-12085[USN-3778-1] Firefox vulnerabilities
3 CVEs addressed in Trusty, Xenial, BionicCVE-2018-12387CVE-2018-12386CVE-2018-12385Firefox 62 release - includes fixes for RCE, local cache poisoning and information disclosures[USN-3783-1] Apache HTTP Server vulnerabilities
3 CVEs addressed in BionicCVE-2018-11763CVE-2018-1333CVE-2018-1302DoS (crash) via incorrect stream destruction and DoS (resources) from incorrect frame handling[USN-3785-1] ImageMagick vulnerabilities
14 CVEs addressed in Trusty, Xenial, BionicCVE-2017-13144CVE-2018-16749CVE-2018-16645CVE-2018-16644CVE-2018-16643CVE-2018-16642CVE-2018-16323CVE-2018-14551CVE-2018-16750CVE-2018-16640CVE-2018-14437CVE-2018-14436CVE-2018-14435CVE-2018-14434Disables support for using PS and PDF from Ghostscript in ImageMagick due tolarge number of GS vulns (see Episode 5)
Also multiple fixes for ImageMagick itself, including memory leaks (DoS), information disclosure, RCE etc[USN-3784-1] AppArmor update
Hardening of various AppArmor profiles (mentioned in Episode 5)[LSN-0044-1] Linux kernel vulnerability
Livepatch incorporating L1TF, Spectrev2 and other fixes as well[USN-3786-1] libxkbcommon vulnerabilities
11 CVEs addressed in Trusty, XenialCVE-2018-15864CVE-2018-15863CVE-2018-15862CVE-2018-15861CVE-2018-15859CVE-2018-15858CVE-2018-15857CVE-2018-15856CVE-2018-15855CVE-2018-15854CVE-2018-15853Loads keyboard descriptions from disk - multiple vulnerabilities in fileformat handling leading to DoS etc
[USN-3787-1] Tomcat vulnerability
1 CVEs addressed in Trusty, XenialCVE-2018-11784Redirect handling allowed attacker to redirect to any URI of their choiceCan be avoided if had manually enabled both mapperDirectoryRedirectEnabled and mapperContextRootRedirectEnabled[USN-3789-1] ClamAV vulnerability
1 CVEs addressed in Trusty, Xenial, BionicCVE-2018-15378Crash in handling of unpacked MEW executable files[USN-3788-1] Tex Live vulnerabilities
2 CVEs addressed in Trusty, Xenial, BionicCVE-2018-17407CVE-2015-5700File overwrite via insecure symlink handlingCode execution via buffer overflow in Type1 font handler[USN-3791-1] Git vulnerability
1 CVEs addressed in Trusty, Xenial, BionicCVE-2018-17456RCE when cloning a malicious repository - due to insufficient validation of git submodule URLs and paths.Goings on in Ubuntu Security Community
Hiring
Ubuntu Security Engineer
https://boards.greenhouse.io/canonical/jobs/1158266Get in contact
#ubuntu-security on the Libera.Chat IRC network@ubuntu_sec on twitter