Overview
This week we look at security updates for GUPnP, OpenJPEG, bsdiff and more.
This week in Ubuntu Security Updates
[USN-4488-2] X.Org X Server vulnerabilities [00:31]
5 CVEs addressed in Trusty ESM (14.04 ESM)CVE-2020-14345 CVE-2020-14362 CVE-2020-14361 CVE-2020-14347 CVE-2020-14346 Episode 90[LSN-0071-1] Linux kernel vulnerability [00:50]
1 CVEs addressed in Bionic (18.04 LTS)CVE-2020-14386 Episode 90 (AF_PACKET OOB write - crash / code exec)Also affects Focal (20.04 LTS) but livepatch is still being prepared[USN-4494-1] GUPnP vulnerability [01:29]
1 CVEs addressed in Focal (20.04 LTS)CVE-2020-12695 GNOME UPnP impl, used by Rygel for media sharing on GNOME (standardUbuntu) desktop and many other applications
Callstranger Vulnerability - vuln in UPnP protocol - callback header inUPnP SUBSCRIBE can contain arbitrary delivery URL - so this could be on a
different network segment than the event subscription URL - so you can
SUBSCRIBE to events and supply one or more URLs for delivery of the
messages. Can then make this point anywhere and so can get the device to
send HTTP traffic to any arbitrary destination - and so can be used for
data exfil or DDoS attacks etc. Fixed to check the destination host is
either a link-local address or the address mask matches - either way,
check is on the same network segment.
[USN-4495-1] Apache Log4j vulnerability [03:21]
1 CVEs addressed in Bionic (18.04 LTS)CVE-2019-17571 Failed to properly deserialise data - so if is listening to untrusted logdata from the network could be exploited to run arbitrary code
[USN-4496-1] Apache XML-RPC vulnerability [03:42]
1 CVEs addressed in Xenial (16.04 LTS), Bionic (18.04 LTS)CVE-2019-17570 Similarly failed to properly deserialize data - a malicious XML-RPCserver could cause code execution on the client as a result
[USN-4497-1] OpenJPEG vulnerabilities [03:58]
7 CVEs addressed in Xenial (16.04 LTS)CVE-2019-12973 CVE-2020-15389 CVE-2020-8112 CVE-2020-6851 CVE-2018-21010 CVE-2018-20847 CVE-2016-9112 Usual mix of memory safety issues in image handling libraries written inC - DoS, RCE etc via crafted image data
[USN-4499-1] MilkyTracker vulnerabilities [04:27]
3 CVEs addressed in Xenial (16.04 LTS)CVE-2019-14497 CVE-2019-14496 CVE-2019-14464 Failed to properly validate files - 2 different heap and 1 stack basedbuffer overflows - RCE if loading untrusted files
[USN-4498-1] Loofah vulnerability [04:52]
1 CVEs addressed in Xenial (16.04 LTS)CVE-2019-15587 ruby module for manipulation and transformation of HTML/XML etcPossible XSS - failed to sanitize JS when handling crafted SVG[USN-4500-1] bsdiff vulnerabilities [05:16]
1 CVEs addressed in Xenial (16.04 LTS)CVE-2014-9862 (Oldest CVE of the week!)Failed to properly validate input patch file -> integer overflow -> heapbased buffer overflow -> code exec / DoS
[USN-4501-1] LuaJIT vulnerability [05:40]
1 CVEs addressed in Xenial (16.04 LTS)CVE-2020-15890 OOB read -> crash / info leak[USN-4502-1] websocket-extensions vulnerability [05:49]
1 CVEs addressed in Xenial (16.04 LTS), Bionic (18.04 LTS), Focal (20.04 LTS)CVE-2020-7663 ruby websockets extension - used regex with backtracking to properlyparse headers, could be sent crafted input which is very computationally
intensive to parse as a result -> CPU based DoS
[USN-4503-1] Perl DBI module vulnerability [06:21]
1 CVEs addressed in Precise ESM (12.04 ESM), Trusty ESM (14.04 ESM), Xenial (16.04 LTS), Bionic (18.04 LTS)CVE-2020-14392 Perl DB interface - underlying code would potentially allocate the stackand hence result in invalid pointers to object that were previously on
the stack - could be manipulated by a remote user to result in memory
corruption etc -> crash
Get in contact
#ubuntu-security on the Libera.Chat IRC networkubuntu-hardened mailing listSecurity section on discourse.ubuntu.com@ubuntu_sec on twitter