Ubuntu Security Podcast

Ubuntu Security Podcast

By Ubuntu Security TeamTechnology
Download on the App Store

Ubuntu Security Podcast episodes

  • Episode 53
    Overview

    This week we look at the details of the latest Intel hardware

    vulnerabilities, including security updates for the Linux kernel and Intel
    microcode, plus Bash, cpio, FriBidi and more.

    This week in Ubuntu Security Updates

    26 unique CVEs addressed

    [USN-4176-1] GNU cpio vulnerability [01:00]
    • 1 CVEs addressed in Precise ESM, Trusty ESM, Xenial, Bionic, Disco, Eoan
      • CVE-2019-14866
      • cpio wouldn’t validate values written to headers of TAR archives - could
      • use cpio to create a TAR containing another TAR with a big size and will
        use wrong context values (ie uses inner TAR values in header) - this
        could allow a TAR to be created which has files with permissions not
        owned by the original user - when extracted by cpio will overwrite target
        files - whereas if using tar to extract will avoid this - fixed to check
        and handle header values correctly
        [USN-4177-1] Rygel vulnerability [02:18]
        • Affecting Eoan
        • Added Rygel in Eoan which is off by default but needed GNOME to handle
        • that - it would disable it dynamically - so if not running GNOME, rygel
          would be running and sharing your stuff on the local network - fixed to
          disable automatically on upgrade - and then can use the GNOME settings
          front-end etc to re-enable if desired
          [USN-4178-1] WebKitGTK+ vulnerabilities [03:34]
          • 4 CVEs addressed in Bionic, Disco
            • CVE-2019-8771
            • CVE-2019-8769
            • CVE-2019-8720
            • CVE-2019-8625
            • [USN-4181-1] WebKitGTK+ vulnerabilities [03:34]
              • 2 CVEs addressed in Bionic, Disco, Eoan
                • CVE-2019-8814
                • CVE-2019-8812
                • [USN-4179-1] FriBidi vulnerability [04:00]
                  • 1 CVEs addressed in Disco, Eoan
                    • CVE-2019-18397
                    • Issue reported about unicode isolated handling in Qt - turns out affected
                    • GTK applications as well - entirely different code with very similar
                      flaw - stack buffer overflow since didn’t check bounds of a fixed array
                      used to store details on nested unicode isolate sections - simple fix to
                      just check bounds before trying to store next element
                      [USN-4180-1] Bash vulnerability [05:38]
                      • 1 CVEs addressed in Precise ESM
                        • CVE-2012-6711
                        • Recently announced vuln (heap-based buffer overflow) in bash affecting
                        • old versions - so most releases unaffected except Precise - can trigger
                          by printing wide characters via echo -e
                          [USN-4182-1, USN-4182-2] Intel Microcode update [06:12]
                          • 2 CVEs addressed in Trusty ESM, Xenial, Bionic, Disco, Eoan
                            • CVE-2019-11139
                            • CVE-2019-11135
                            • Voltage modulation able to be performed by a local privileged user -
                            • disabled via microcode
                            • TSX Asynchronous Abort (TAA) -
                            • https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/TAA_MCEPSC_i915
                              • Another variant of MDS but only affects processsors with Transational
                              • Synchronization Extensions (TSX)
                              • MDS mitigations also can mitigate this - but needs microcode update -
                              • associated kernel update too
                                [USN-4183-1] Linux kernel vulnerabilities [07:58]
                                • 9 CVEs addressed in Eoan
                                  • CVE-2019-17666
                                  • CVE-2019-16746
                                  • CVE-2019-15793
                                  • CVE-2019-15792
                                  • CVE-2019-15791
                                  • CVE-2019-0154
                                  • CVE-2018-12207
                                  • CVE-2019-0155
                                  • CVE-2019-11135
                                  • MCEPSC - https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/TAA_MCEPSC_i915
                                    • trigger a MCE from a guest by changing page size in a particular way
                                    • within the guest -> MCE on host kernel -> DoS
                                    • i915 graphics - userspace can modify PTE via writes to MMIO from blitter
                                    • command streamer or expose kernel memory - privesc
                                    • TAA
                                    • Various other issues:
                                      • Realtek wifi driver buffer overflow - able to be triggered OTA - crash
                                      • / RCE
                                      • Buffer overflow in nl80211 config interface (local user) - crash / code exec
                                      • Jann Horn - shiftfs issues
                                        • UID/GID confusion when namespace of lower file-system is not
                                        • init_user_ns - DAC bypass
                                        • type confusion -> buffer overflow
                                        • reference count underflow -> UAF
                                          • local user crash / code exec
                                          • i915 graphics - userspace read on GT MMIO -> hang -> DoS (low power state)
                                          • [USN-4184-1] Linux kernel vulnerabilities [11:09]
                                            • 14 CVEs addressed in Bionic (HWE), Disco
                                              • CVE-2019-17666
                                              • CVE-2019-17056
                                              • CVE-2019-17055
                                              • CVE-2019-17054
                                              • CVE-2019-17053
                                              • CVE-2019-17052
                                              • CVE-2019-15793
                                              • CVE-2019-15792
                                              • CVE-2019-15791
                                              • CVE-2019-15098
                                              • CVE-2019-0154
                                              • CVE-2018-12207
                                              • CVE-2019-0155
                                              • CVE-2019-11135
                                              • See above plus
                                                • Various network based subsystems failed to enforce CAP_NET_RAW for raw
                                                • socket creation
                                                  • AF_NFC, AF_ISDN, AF_APPLETALK, AF_IEEE802154 (low-rate wireless
                                                  • network), AF_AX25
                                                    [USN-4185-1, USN-4185-2] Linux kernel vulnerabilities [12:06]
                                                    • 11 CVEs addressed in Trusty ESM (Azure), Xenial (HWE), Bionic
                                                      • CVE-2019-17666
                                                      • CVE-2019-17056
                                                      • CVE-2019-17055
                                                      • CVE-2019-17054
                                                      • CVE-2019-17053
                                                      • CVE-2019-17052
                                                      • CVE-2019-15098
                                                      • CVE-2019-0154
                                                      • CVE-2018-12207
                                                      • CVE-2019-0155
                                                      • CVE-2019-11135
                                                      • realtek wifi buffer overflow, AF_XXX CAP_NET_RAW, NULL pointer
                                                      • dereference in Atheros USB Wifi Driver, Intel hardware issues (2xi915 +
                                                        TAA + MCEPSC)
                                                        [USN-4186-1, USN-4186-2] Linux kernel vulnerabilities [12:47]
                                                        • 13 CVEs addressed in Trusty ESM (HWE), Xenial
                                                          • CVE-2019-2215
                                                          • CVE-2019-17666
                                                          • CVE-2019-17056
                                                          • CVE-2019-17055
                                                          • CVE-2019-17054
                                                          • CVE-2019-17053
                                                          • CVE-2019-17052
                                                          • CVE-2019-16746
                                                          • CVE-2019-15098
                                                          • CVE-2019-0154
                                                          • CVE-2018-12207
                                                          • CVE-2019-0155
                                                          • CVE-2019-11135
                                                          • Binder UAF -> crash, DoS -> code exec (CONFIG_DEBUG_LIST mitigates this -
                                                          • looking to add this in future kernels like 20.04)
                                                          • realtek wifi, CAP_NET_RAW, nl80211 config buffer overflow, Intel hardware
                                                          • issues
                                                            [USN-4187-1] Linux kernel vulnerability [13:48]
                                                            • 1 CVEs addressed in Trusty ESM
                                                              • CVE-2019-11135
                                                              • TAA
                                                              • [USN-4188-1] Linux kernel vulnerability [13:48]
                                                                • 1 CVEs addressed in Precise ESM
                                                                  • CVE-2019-11135
                                                                  • TAA
                                                                  • [LSN-0059-1] Linux kernel vulnerability [14:05]
                                                                    • 4 CVEs addressed in Xenial and Bionic
                                                                      • CVE-2019-11135
                                                                      • CVE-2019-0155
                                                                      • CVE-2019-0154
                                                                      • CVE-2018-12207
                                                                      • Intel hardware issues - CAN’T BE LIVEPATCHED - need to update kernel and reboot
                                                                      • Goings on in Ubuntu Security Community
                                                                        20.04 Roadmap Sprint [14:55]
                                                                        Get in contact
                                                                        • #ubuntu-security on the Libera.Chat IRC network
                                                                        • ubuntu-hardened mailing list
                                                                        • Security section on discourse.ubuntu.com
                                                                        • @ubuntu_sec on twitter
                                                                        • 18 min
                                                                        • Episode 52
                                                                          Overview

                                                                          This week we look at security updates for FreeTDS, HAProxy, Nokogiri, plus

                                                                          some regressions in Whoopsie, Apport and Firefox, and Joe and Alex discuss
                                                                          the release of 14.04 ESM for personal use under the Ubuntu Advantage
                                                                          program.

                                                                          This week in Ubuntu Security Updates

                                                                          9 unique CVEs addressed

                                                                          [USN-4171-2] Apport vulnerabilities [00:44]
                                                                          • 5 CVEs addressed in Trusty ESM
                                                                            • CVE-2019-15790
                                                                            • CVE-2019-11485
                                                                            • CVE-2019-11483
                                                                            • CVE-2019-11482
                                                                            • CVE-2019-11481
                                                                            • Episode 51
                                                                            • [USN-4172-1, USN-4172-2] file vulnerability [00:58]
                                                                              • 1 CVEs addressed in Precise ESM, Trusty ESM, Xenial, Bionic, Disco, Eoan
                                                                                • CVE-2019-18218
                                                                                • OSS-Fuzz using libFuzzer - heap based buffer overflow of up to 4 bytes in
                                                                                • the CDF parser when handing vector elements - Composite Document File -
                                                                                  used in MS Office prior to new zipped XML format - ie. the old .doc /
                                                                                  .xls etc
                                                                                  [USN-4173-1] FreeTDS vulnerability [01:48]
                                                                                  • 1 CVEs addressed in Bionic, Disco, Eoan
                                                                                    • CVE-2019-13508
                                                                                    • Felix Wilhelm for Google Security Team - if a server were to downgrade
                                                                                    • the protocol to version 5 and send a UDT type to the client, would cause
                                                                                      a heap buffer overflow due to mismatch in size - fixed by forcing the
                                                                                      size to an appropriate value
                                                                                      [USN-4170-2, USN-4170-3] Whoopsie regressions [02:22]
                                                                                      • Affecting Xenial, Bionic, Disco, Eoan
                                                                                      • Episode 51 - update caused crash on upload to server due to mismatch in
                                                                                      • size and resulting partial uninitialized variable - fixed to intialize
                                                                                        but realised this could still potentially crash on big-endian
                                                                                        architectures so fixed properly by changing size to 32-bit to match
                                                                                        memcpy()
                                                                                        [USN-4171-3, USN-4171-4] Apport regression [04:07]
                                                                                        • 5 CVEs addressed in Trusty ESM, Xenial, Bionic, Disco, Eoan
                                                                                          • CVE-2019-15790
                                                                                          • CVE-2019-11485
                                                                                          • CVE-2019-11483
                                                                                          • CVE-2019-11482
                                                                                          • CVE-2019-11481
                                                                                          • Episode 51 - regression due to missing change to python code to handle
                                                                                          • new internal API - fixed by updating the API to be backwards compatible
                                                                                            [USN-4174-1] HAproxy vulnerability [04:55]
                                                                                            • 1 CVEs addressed in Xenial, Bionic, Disco, Eoan
                                                                                              • CVE-2019-18277
                                                                                              • HTTP Request Smuggling attack
                                                                                                • https://nathandavison.com/blog/haproxy-http-request-smuggling
                                                                                                • Wouldn’t reject messages that specified transfer-encoding without
                                                                                                • “chunked” value
                                                                                                • Could be combined with http reuse for request smuggling - ie. the ability
                                                                                                • to get an attacker controlled chunk appended to a legitimate request and
                                                                                                  hence the response sent back to the attacker etc - fixed to reject if
                                                                                                  transfer-encoding is used without also specifying “chunked”
                                                                                                  [USN-4175-1] Nokogiri vulnerability [06:36]
                                                                                                  • 1 CVEs addressed in Xenial, Bionic, Disco, Eoan
                                                                                                    • CVE-2019-5477
                                                                                                    • Ruby based parser for HTML/XML/SAS etc with XPath & CSS selector support
                                                                                                    • etc
                                                                                                    • Command-injection vulnerability - due to use of the Rexical gem - and
                                                                                                    • would need to have code which then calls the undocumented load_file
                                                                                                      method within the CSS tokenizer with user supplied input for the
                                                                                                      filename - due to use of eval()…
                                                                                                      [USN-4165-2] Firefox regressions [07:38]
                                                                                                      • Affecting Xenial, Bionic, Disco, Eoan
                                                                                                      • Upstream Firefox 70.0.1 release to fix a regression in the 70.0 release
                                                                                                      • (some pages with dynamic javascript would fail to load - v 70.0 had
                                                                                                        enabled a new next-gen local storage feature which caused issues so this
                                                                                                        is now disabled by default)
                                                                                                        Goings on in Ubuntu Security Community
                                                                                                        Alex and Joe discuss news that 14.04 ESM is free for personal use via new UA client [08:19]
                                                                                                        • https://ubuntu.com/blog/ua-services-deployed-from-the-command-line-with-ua-client
                                                                                                        • https://ubuntu.com/esm
                                                                                                        • https://wiki.ubuntu.com/SecurityTeam/ESM/14.04
                                                                                                        • Get in contact
                                                                                                          • #ubuntu-security on the Libera.Chat IRC network
                                                                                                          • ubuntu-hardened mailing list
                                                                                                          • Security section on discourse.ubuntu.com
                                                                                                          • @ubuntu_sec on twitter
                                                                                                          • 19 min
                                                                                                          • Episode 51
                                                                                                            Overview

                                                                                                            In this Halloween Special, Joe and Alex talk about what scares them in

                                                                                                            security, plus we look at security updates for Firefox, PHP, Samba,
                                                                                                            Whoopsie, Apport and more.

                                                                                                            This week in Ubuntu Security Updates

                                                                                                            26 unique CVEs addressed

                                                                                                            [USN-4165-1] Firefox vulnerabilities [00:46]
                                                                                                            • 13 CVEs addressed in Xenial, Bionic, Disco, Eoan
                                                                                                              • CVE-2019-17002
                                                                                                              • CVE-2019-17001
                                                                                                              • CVE-2019-17000
                                                                                                              • CVE-2019-15903
                                                                                                              • CVE-2019-11765
                                                                                                              • CVE-2019-11764
                                                                                                              • CVE-2019-11763
                                                                                                              • CVE-2019-11762
                                                                                                              • CVE-2019-11761
                                                                                                              • CVE-2019-11760
                                                                                                              • CVE-2019-11759
                                                                                                              • CVE-2019-11757
                                                                                                              • CVE-2018-6156
                                                                                                              • 1 high priority, 11 medium and 1 low
                                                                                                                • Heap buffer overflow via a crafted WebRTC video - originally for
                                                                                                                • Chromium and was fixed for that last year - Firefox suffered similarly
                                                                                                                  but disables the feature by default - has finally been fixed for
                                                                                                                  Firefox as well by integrating the original fix from Chromium
                                                                                                                • Usual suspects of stack-based buffer overflows, UAFs, a heap buffer
                                                                                                                • overflow in bundled expat (Episode 47),
                                                                                                                  [USN-4166-1, USN-4166-2] PHP vulnerability [02:10]
                                                                                                                  • 1 CVEs addressed in Precise ESM, Trusty ESM, Xenial, Bionic, Disco, Eoan
                                                                                                                    • CVE-2019-11043
                                                                                                                    • RCE in PHP (FPM - FastCGI Process Manager) - possible to cause the FPM
                                                                                                                    • module to write past allocated buffers - and so ends up also writing into the FCGI
                                                                                                                      protocol data buffers - which can then create a chance for RCE
                                                                                                                    • Exploit on github targetting vulnerable PHP-FPM servers which use nginx
                                                                                                                    • in a particular configuration
                                                                                                                      [USN-4167-1, USN-4167-2] Samba vulnerabilities [03:11]
                                                                                                                      • 3 CVEs addressed in Precise ESM, Trusty ESM, Xenial, Bionic, Disco, Eoan
                                                                                                                        • CVE-2019-14847
                                                                                                                        • CVE-2019-14833
                                                                                                                        • CVE-2019-10218
                                                                                                                        • DoS from a user with “get changes” permissions - could crash an AD DC
                                                                                                                        • LDAP server due to a NULL pointer deref when using dirsync with ranged results
                                                                                                                        • Can configure AD DC to call out to a custom command to verify password
                                                                                                                        • complexity - is handed a copy of the cleartext password - but if this
                                                                                                                          contained any multi-byte characters, would not get the full password -
                                                                                                                          since it would pass the password as bytes but only copy the number of
                                                                                                                          characters - and since multi-byte characters take more than 1 byte would
                                                                                                                          miss the last few bytes of the password - so could circumvent password
                                                                                                                          complexity requirements
                                                                                                                        • Malicious server could craft filenames which contain relative path
                                                                                                                        • characters (../ etc) which would then cause an SMB client to access local
                                                                                                                          files for reading / writing rather than remote files - so a remote server
                                                                                                                          could cause a client to create files outside the working directory on the
                                                                                                                          local machine
                                                                                                                          [USN-4168-1] Libidn2 vulnerabilities [05:15]
                                                                                                                          • 2 CVEs addressed in Bionic, Disco
                                                                                                                            • CVE-2019-18224
                                                                                                                            • CVE-2019-12290
                                                                                                                            • Library for handling internationalised domain names
                                                                                                                            • Heap based buffer overflow via a too-long domain name (greater than 63
                                                                                                                            • characters - in library, caller passes a buffer that is specified to be a
                                                                                                                              minimum of 64 bytes - but libidn strcpy()’s into it so could easily overflow.
                                                                                                                            • Possible domain name impersonation since doesn’t bother to check unicode
                                                                                                                            • conversions - so could use punycode (ascii representation of certain
                                                                                                                              unicode characters) to impersonate a unicode domain
                                                                                                                              [USN-4169-1] libarchive vulnerability [06:32]
                                                                                                                              • 1 CVEs addressed in Trusty ESM, Xenial, Bionic, Disco
                                                                                                                                • CVE-2019-18408
                                                                                                                                • UAF in certain failure conditions when handling RAR archives
                                                                                                                                • [USN-4170-1] Whoopsie vulnerability [06:52]
                                                                                                                                  • 1 CVEs addressed in Xenial, Bionic, Disco, Eoan
                                                                                                                                    • CVE-2019-11484
                                                                                                                                    • Kevin Backhouse from Semmle Security Research Team - integer oveflow ->
                                                                                                                                    • heap based buffer overflow -> code executions a whoopsie user
                                                                                                                                      [USN-4171-1] Apport vulnerabilities [07:51]
                                                                                                                                      • 5 CVEs addressed in Xenial, Bionic, Disco, Eoan

                                                                                                                                        • CVE-2019-15790
                                                                                                                                        • CVE-2019-11485
                                                                                                                                        • CVE-2019-11483
                                                                                                                                        • CVE-2019-11482
                                                                                                                                        • CVE-2019-11481
                                                                                                                                        • Kevin Backhouse from Semmle Security Research Team

                                                                                                                                          • reads /proc/PID files as root - so if can race on process ID reuse
                                                                                                                                          • could cause Apport to generate a crash dump of a privileged process
                                                                                                                                            that is readable by a normal user (so starts dumping an unprivileged
                                                                                                                                            process, then PID race, new PID as privileged user -> this crashes ->
                                                                                                                                            Apport starts writing out the crash report for the first process but
                                                                                                                                            using the details of the new privileged process - since this was
                                                                                                                                            originally an unprivileged process, the crash dump is then unprivileged
                                                                                                                                            too). Fixed by making sure Apport drops privileges to the original
                                                                                                                                            unprivileged user before reading /proc/PID info so if this happens to
                                                                                                                                            then be a different user’s process will not be able to generate the
                                                                                                                                            crash dump
                                                                                                                                          • Apport would read a per-user configuration file - but would do so as
                                                                                                                                          • root - and so this could be a symlink to a root owned file and Apport
                                                                                                                                            would happily read it (but might error out if it looked invalid) - so
                                                                                                                                            drop privileges to read it so it doesn’t include anything which it
                                                                                                                                            shouldn’t in the final crash report
                                                                                                                                          • Sander Bos

                                                                                                                                            • Apport had a lock file in a world-writable directory - so anyone could
                                                                                                                                            • create it to either stop Apport running or to control the execution of
                                                                                                                                              Apport over time - fixed to place in a non-world writable location
                                                                                                                                              instead
                                                                                                                                            • When using containers, Apport uses a socket file to allow it to forward
                                                                                                                                            • crash dumps that it captured on the host to an Apport instance running
                                                                                                                                              within a container containers - it finds the socket file from the host
                                                                                                                                              using the /proc/PID/root magic link - but this could allow an
                                                                                                                                              unprivileged user who (using unprivileged usernamespaces) is root in a
                                                                                                                                              container to chroot() for a process in a container to a different
                                                                                                                                              location so it can then intercept the crash dump of a privileged
                                                                                                                                              process within the container - so could run a setuid process in the
                                                                                                                                              container, and when it crashes be able to read it’s crash dump
                                                                                                                                            • TOCCTOU race on PID (like above) but this is in a different code path -
                                                                                                                                            • reads the cwd of the crashed process to write out the core dump to this
                                                                                                                                              location - but on process ID reuse this could then be in a different
                                                                                                                                              location - so if a user can race against a privileged process dumping
                                                                                                                                              the crash dump could end up in a location of their choosing
                                                                                                                                              Goings on in Ubuntu Security Community
                                                                                                                                              Joe and Alex discuss what scares them for Halloween [12:38]
                                                                                                                                              Get in contact
                                                                                                                                              • #ubuntu-security on the Libera.Chat IRC network
                                                                                                                                              • ubuntu-hardened mailing list
                                                                                                                                              • Security section on discourse.ubuntu.com
                                                                                                                                              • @ubuntu_sec on twitter
                                                                                                                                              • 30 min
                                                                                                                                              • Episode 50
                                                                                                                                                Overview

                                                                                                                                                Alex and Joe discuss the big news of this week - the release of Ubuntu

                                                                                                                                                19.10 Eoan Ermine - plus we look at updates for the Linux kernel, libxslt,
                                                                                                                                                UW IMAP and more.

                                                                                                                                                This week in Ubuntu Security Updates

                                                                                                                                                51 unique CVEs addressed

                                                                                                                                                [USN-4156-2] SDL vulnerabilities [00:37]
                                                                                                                                                • 11 CVEs addressed in Precise ESM, Trusty ESM
                                                                                                                                                  • CVE-2019-7637
                                                                                                                                                  • CVE-2019-7636
                                                                                                                                                  • CVE-2019-7635
                                                                                                                                                  • CVE-2019-7578
                                                                                                                                                  • CVE-2019-7577
                                                                                                                                                  • CVE-2019-7576
                                                                                                                                                  • CVE-2019-7575
                                                                                                                                                  • CVE-2019-7574
                                                                                                                                                  • CVE-2019-7573
                                                                                                                                                  • CVE-2019-7572
                                                                                                                                                  • CVE-2019-13616
                                                                                                                                                  • Covered in Episode 49 and Episode 48
                                                                                                                                                  • [USN-4160-1] UW IMAP vulnerability [01:04]
                                                                                                                                                    • 1 CVEs addressed in Xenial, Bionic, Disco
                                                                                                                                                      • CVE-2018-19518
                                                                                                                                                      • University of Washington IMAP toolkit (used by PHP for it’s IMAP implementation)
                                                                                                                                                      • Used rsh to implement various operations - wouldn’t try and sanitize the
                                                                                                                                                      • provided hostname - so if attacker could provide a hostname/mailbox to
                                                                                                                                                        php’s IMAP without any validation could execute arbitrary commands on the
                                                                                                                                                        host
                                                                                                                                                        • Fixed by turning off the rsh based functionality by default in PHP - if
                                                                                                                                                        • you still want this you can set imap.enable_insecure_rsh but this is
                                                                                                                                                          not advised…
                                                                                                                                                          [USN-4158-1] LibTIFF vulnerabilities [02:17]
                                                                                                                                                          • 2 CVEs addressed in Xenial, Bionic, Disco
                                                                                                                                                            • CVE-2019-17546
                                                                                                                                                            • CVE-2019-14973
                                                                                                                                                            • Integer overflow -> heap based buffer overflow -> crash, DoS or code
                                                                                                                                                            • execution
                                                                                                                                                            • (Low) Integer overflow due to undefined behaviour in existing overflow
                                                                                                                                                            • checking code when multiplying various elements -> no known way to
                                                                                                                                                              exploit
                                                                                                                                                              [USN-4155-2] Aspell vulnerability [03:13]
                                                                                                                                                              • 1 CVEs addressed in Eoan
                                                                                                                                                                • CVE-2019-17544
                                                                                                                                                                • Episode 49 covered for older releases - Eoan is now out so updated there too
                                                                                                                                                                • [USN-4159-1] Exiv2 vulnerability [03:31]
                                                                                                                                                                  • 1 CVEs addressed in Xenial, Bionic, Disco, Eoan
                                                                                                                                                                    • CVE-2019-17402
                                                                                                                                                                    • OOB read -> crash, DoS
                                                                                                                                                                    • [USN-4164-1] Libxslt vulnerabilities [03:44]
                                                                                                                                                                      • 3 CVEs addressed in Precise ESM, Trusty ESM, Xenial, Bionic, Disco, Eoan
                                                                                                                                                                        • CVE-2019-18197
                                                                                                                                                                        • CVE-2019-13118
                                                                                                                                                                        • CVE-2019-13117
                                                                                                                                                                        • OSS-Fuzz found 3 issues
                                                                                                                                                                          • possible heap buffer overflow as a result of a dangling pointer - so
                                                                                                                                                                          • same memory area could be reused for future memory operations -> fixed
                                                                                                                                                                            to reset the pointer when done
                                                                                                                                                                          • 2 low priority issues - both stack memory info disclosures
                                                                                                                                                                          • [USN-4157-1, USN-4157-2] Linux kernel vulnerabilities [04:59]
                                                                                                                                                                            • 9 CVEs addressed in Bionic (HWE) and Disco
                                                                                                                                                                              • CVE-2019-2181
                                                                                                                                                                              • CVE-2019-16714
                                                                                                                                                                              • CVE-2019-15902
                                                                                                                                                                              • CVE-2019-15505
                                                                                                                                                                              • CVE-2019-15504
                                                                                                                                                                              • CVE-2019-14821
                                                                                                                                                                              • CVE-2019-14816
                                                                                                                                                                              • CVE-2019-14815
                                                                                                                                                                              • CVE-2019-14814
                                                                                                                                                                              • Integer overflow -> buffer overflow -> root privesc in binder
                                                                                                                                                                              • Reintroduction of Spectre v1 vulnerability in ptrace subsystem - Brad
                                                                                                                                                                              • Spengler - fixed properly in Linus’ tree but not when it got backported
                                                                                                                                                                                to the stable tree - two lines of code got reordered - so load of
                                                                                                                                                                                possible speculative value occurred _after_it had been used - so the
                                                                                                                                                                                speculative load barrier had no effect - Ubuntu regularly backports fixes
                                                                                                                                                                                from the latest stable tree so we ended up affected as well
                                                                                                                                                                                • https://grsecurity.net/teardown_of_a_failed_linux_lts_spectre_fix.php
                                                                                                                                                                                • Possible DoS (kernel crash) if users can write to /dev/kvm - by default
                                                                                                                                                                                • on Ubuntu users don’t have this privilege so generally not affected
                                                                                                                                                                                • 2 different heap based buffer overflows in Marvell Wifi driver ->
                                                                                                                                                                                • occurred when setting parameters for the driver so could be triggered by
                                                                                                                                                                                  a local users -> crash, DoS or
                                                                                                                                                                                  possible code execution
                                                                                                                                                                                  [USN-4161-1] Linux kernel vulnerability [07:40]
                                                                                                                                                                                  • 1 CVEs addressed in Eoan
                                                                                                                                                                                    • CVE-2019-18198
                                                                                                                                                                                    • Eoan kernel “0-day” - will discuss with Joe later
                                                                                                                                                                                    • [USN-4162-1] Linux kernel vulnerabilities [07:58]
                                                                                                                                                                                      • 10 CVEs addressed in Trusty ESM (Azure), Xenial (HWE), Bionic
                                                                                                                                                                                        • CVE-2019-15918
                                                                                                                                                                                        • CVE-2019-15902
                                                                                                                                                                                        • CVE-2019-15505
                                                                                                                                                                                        • CVE-2019-15118
                                                                                                                                                                                        • CVE-2019-15117
                                                                                                                                                                                        • CVE-2019-14821
                                                                                                                                                                                        • CVE-2019-14816
                                                                                                                                                                                        • CVE-2019-14815
                                                                                                                                                                                        • CVE-2019-14814
                                                                                                                                                                                        • CVE-2018-21008
                                                                                                                                                                                        • SMB based buffer overread if try mounting a share with version specified
                                                                                                                                                                                        • as 3.0 but the share itself is version 2.10 -> parameter size mismatch ->
                                                                                                                                                                                          read of too much memory -> info disclosure
                                                                                                                                                                                        • UAF in RSI 91x Wi-Fi driver -> able to be triggered by a remote network
                                                                                                                                                                                        • peer -> crash, DoS or possible RCE
                                                                                                                                                                                        • ptrace spectrev1 reissue, KVM crash, Marvell Wifi Driver issues from above
                                                                                                                                                                                        • USB audio issues from Episode 48 (Disco kernel -> now fixed in Bionic
                                                                                                                                                                                        • kernel as well)
                                                                                                                                                                                          [USN-4163-1, USN-4163-2] Linux kernel vulnerabilities [09:29]
                                                                                                                                                                                          • 10 CVEs addressed in Xenial and Trusty ESM (HWE)
                                                                                                                                                                                            • CVE-2019-15902
                                                                                                                                                                                            • CVE-2019-15505
                                                                                                                                                                                            • CVE-2019-15118
                                                                                                                                                                                            • CVE-2019-15117
                                                                                                                                                                                            • CVE-2019-14821
                                                                                                                                                                                            • CVE-2019-14816
                                                                                                                                                                                            • CVE-2019-14814
                                                                                                                                                                                            • CVE-2018-21008
                                                                                                                                                                                            • CVE-2017-18232
                                                                                                                                                                                            • CVE-2016-10906
                                                                                                                                                                                            • Spectrev1 reissue, USB Audio, KVM crash, Marvell and RSI 91x WiFi Driver
                                                                                                                                                                                            • issues all covered earlier
                                                                                                                                                                                            • Serial attached SCSI implementation mishandled error condition leading to
                                                                                                                                                                                            • deadlock -> local user could possibly trigger this leading to a DoS
                                                                                                                                                                                              [LSN-0058-1] Linux kernel vulnerability [10:09]
                                                                                                                                                                                              • 22 CVEs addressed in Bionic and Xenial + Xenial (HWE)
                                                                                                                                                                                                • CVE-2019-14835
                                                                                                                                                                                                • CVE-2019-14821
                                                                                                                                                                                                • CVE-2019-14816
                                                                                                                                                                                                • CVE-2019-14815
                                                                                                                                                                                                • CVE-2019-14814
                                                                                                                                                                                                • CVE-2019-14284
                                                                                                                                                                                                • CVE-2019-14283
                                                                                                                                                                                                • CVE-2019-12614
                                                                                                                                                                                                • CVE-2019-11833
                                                                                                                                                                                                • CVE-2019-11478
                                                                                                                                                                                                • CVE-2019-11477
                                                                                                                                                                                                • CVE-2019-10207
                                                                                                                                                                                                • CVE-2019-10126
                                                                                                                                                                                                • CVE-2019-3846
                                                                                                                                                                                                • CVE-2019-2181
                                                                                                                                                                                                • CVE-2019-2054
                                                                                                                                                                                                • CVE-2019-0136
                                                                                                                                                                                                • CVE-2018-21008
                                                                                                                                                                                                • CVE-2018-20976
                                                                                                                                                                                                • CVE-2018-20961
                                                                                                                                                                                                • CVE-2018-20856
                                                                                                                                                                                                • CVE-2016-10905
                                                                                                                                                                                                • Most all covered in previous episodes or previously in this episode
                                                                                                                                                                                                • 2 high priority issues
                                                                                                                                                                                                  • vhost_net issue from Episode 47
                                                                                                                                                                                                  • SACKPanic from Episode 37
                                                                                                                                                                                                  • Goings on in Ubuntu Security Community
                                                                                                                                                                                                    Joe and Alex on Ubuntu 19.10 (Eoan Ermine) released but with possible local user kernel DoS bug [11:02]
                                                                                                                                                                                                    • https://twitter.com/sylvia_ritter
                                                                                                                                                                                                    • https://www.phoronix.com/scan.php?page=news_item&px=Ubuntu-19.10-Kernel-Bug
                                                                                                                                                                                                      • Mitigate by installing the latest eoan kernel update or by disabling
                                                                                                                                                                                                      • user namspaces:
                                                                                                                                                                                                        sysctl user.max_user_namespaces=0
                                                                                                                                                                                                        Get in contact
                                                                                                                                                                                                        • #ubuntu-security on the Libera.Chat IRC network
                                                                                                                                                                                                        • ubuntu-hardened mailing list
                                                                                                                                                                                                        • Security section on discourse.ubuntu.com
                                                                                                                                                                                                        • @ubuntu_sec on twitter
                                                                                                                                                                                                        • 24 min
                                                                                                                                                                                                        • Episode 49
                                                                                                                                                                                                          Overview

                                                                                                                                                                                                          This week we look at updates for Sudo, Python, OpenStack Octavia and more,

                                                                                                                                                                                                          plus we discuss a recent CVE for Python which resulted in erroneous
                                                                                                                                                                                                          scientific research results, and we go over some of your feedback from
                                                                                                                                                                                                          Episode 48.

                                                                                                                                                                                                          This week in Ubuntu Security Updates

                                                                                                                                                                                                          27 unique CVEs addressed

                                                                                                                                                                                                          [USN-4148-1] OpenEXR vulnerabilities [00:45]
                                                                                                                                                                                                          • 8 CVEs addressed in Xenial, Bionic, Disco
                                                                                                                                                                                                            • CVE-2018-18444
                                                                                                                                                                                                            • CVE-2017-9115
                                                                                                                                                                                                            • CVE-2017-9113
                                                                                                                                                                                                            • CVE-2017-9111
                                                                                                                                                                                                            • CVE-2017-9116
                                                                                                                                                                                                            • CVE-2017-9112
                                                                                                                                                                                                            • CVE-2017-9110
                                                                                                                                                                                                            • CVE-2017-12596
                                                                                                                                                                                                            • Image format developed by ILM with a high definition range for computer
                                                                                                                                                                                                            • imaging applications
                                                                                                                                                                                                            • Range of issues (c++ codebase)
                                                                                                                                                                                                              • OOB writes (usually only of a few bytes past the end of a buffer) -
                                                                                                                                                                                                              • assertion failure or memory corruption -> crash / code execution
                                                                                                                                                                                                              • OOB reads (same) - crash
                                                                                                                                                                                                              • [USN-4149-1] Unbound vulnerability [02:06]
                                                                                                                                                                                                                • 1 CVEs addressed in Disco
                                                                                                                                                                                                                  • CVE-2019-16866
                                                                                                                                                                                                                  • Validating, recursive DNS resolver
                                                                                                                                                                                                                  • OOB read due to a remotely crafted NOTIFY query (source IP needs to match
                                                                                                                                                                                                                  • an ACL) -> crash
                                                                                                                                                                                                                    [USN-4151-1, USN-4151-2] Python vulnerabilities [02:40]
                                                                                                                                                                                                                    • 2 CVEs addressed in Precise ESM, Trusty ESM, Xenial, Bionic, Disco
                                                                                                                                                                                                                      • CVE-2019-16935
                                                                                                                                                                                                                      • CVE-2019-16056
                                                                                                                                                                                                                      • XML-RPC server module could end up serving arbitrary JS if set via the
                                                                                                                                                                                                                      • set_server_title() method as did not escape content
                                                                                                                                                                                                                      • Python email module tries to parse email address into sender + domain -
                                                                                                                                                                                                                      • if domain contains multiple @ chars could get confused and return wrong
                                                                                                                                                                                                                        output - so applications which rely on this for validating email
                                                                                                                                                                                                                        addresses could accept an email address which is actually invalid
                                                                                                                                                                                                                        [USN-4152-1] libsoup vulnerability [03:53]
                                                                                                                                                                                                                        • 1 CVEs addressed in Bionic, Disco
                                                                                                                                                                                                                          • CVE-2019-17266
                                                                                                                                                                                                                          • Heap buffer OOB read - fails to check the specified length of message
                                                                                                                                                                                                                          • against the actual received message - could then memcpy past the end of
                                                                                                                                                                                                                            the input message -> crash
                                                                                                                                                                                                                            [USN-4153-1] Octavia vulnerability [04:33]
                                                                                                                                                                                                                            • 1 CVEs addressed in Disco
                                                                                                                                                                                                                              • CVE-2019-17134
                                                                                                                                                                                                                              • Amphora Images in OpenStack Octavia - fails to properly validate client
                                                                                                                                                                                                                              • certificates for management network clients -> could allow anyone with
                                                                                                                                                                                                                                management network access to retrieve information / issue config commands
                                                                                                                                                                                                                                [USN-4154-1] Sudo vulnerability [05:06]
                                                                                                                                                                                                                                • 1 CVEs addressed in Precise ESM, Trusty ESM, Xenial, Bionic, Disco
                                                                                                                                                                                                                                  • CVE-2019-14287
                                                                                                                                                                                                                                  • Lots of press around a seemingly high priority privilege escalation
                                                                                                                                                                                                                                  • vulnerability - BUT requires an admin to have configured sudo with a
                                                                                                                                                                                                                                    particular configuration (ie specifying a user can run a command as any
                                                                                                                                                                                                                                    other user via the ALL keyword in a Runas rule). In this case if the rule
                                                                                                                                                                                                                                    had also been configured to explicitly deny running the command as root,
                                                                                                                                                                                                                                    this could be bypassed by the user specifying a UID of -1. So would only
                                                                                                                                                                                                                                    affect a very small number of installations.
                                                                                                                                                                                                                                    [USN-4155-1] Aspell vulnerability [07:26]
                                                                                                                                                                                                                                    • 1 CVEs addressed in Precise ESM, Trusty ESM, Xenial, Bionic, Disco
                                                                                                                                                                                                                                      • CVE-2019-17544
                                                                                                                                                                                                                                      • Stack buffer over-read - found by Google’s oss-fuzz
                                                                                                                                                                                                                                      • [USN-4156-1] SDL vulnerabilities [08:03]
                                                                                                                                                                                                                                        • 12 CVEs addressed in Xenial, Bionic
                                                                                                                                                                                                                                          • CVE-2019-7638
                                                                                                                                                                                                                                          • CVE-2019-7637
                                                                                                                                                                                                                                          • CVE-2019-7636
                                                                                                                                                                                                                                          • CVE-2019-7635
                                                                                                                                                                                                                                          • CVE-2019-7578
                                                                                                                                                                                                                                          • CVE-2019-7577
                                                                                                                                                                                                                                          • CVE-2019-7576
                                                                                                                                                                                                                                          • CVE-2019-7575
                                                                                                                                                                                                                                          • CVE-2019-7574
                                                                                                                                                                                                                                          • CVE-2019-7573
                                                                                                                                                                                                                                          • CVE-2019-7572
                                                                                                                                                                                                                                          • CVE-2019-13616
                                                                                                                                                                                                                                          • Covered all the higher priority ones in Episode 48 for SDL 2.0 - fixed
                                                                                                                                                                                                                                          • now for SDL1.2 as well, plus rolled in a bunch of fixes for lower
                                                                                                                                                                                                                                            priority issues (buffer over-reads in WAV handling etc)
                                                                                                                                                                                                                                            Goings on in Ubuntu Security Community
                                                                                                                                                                                                                                            Alex and Joe talk CVEs for bad documentation and resulting scientific research? [09:20]
                                                                                                                                                                                                                                            • https://nvd.nist.gov/vuln/detail/CVE-2019-17514
                                                                                                                                                                                                                                            • Feedback on desired features for 20.04 [18:53]
                                                                                                                                                                                                                                              • cafzo on discourse.ubuntu.com
                                                                                                                                                                                                                                                • encrypted home directories
                                                                                                                                                                                                                                                • guest-accounts
                                                                                                                                                                                                                                                • Get in contact
                                                                                                                                                                                                                                                  • #ubuntu-security on the Libera.Chat IRC network
                                                                                                                                                                                                                                                  • ubuntu-hardened mailing list
                                                                                                                                                                                                                                                  • Security section on discourse.ubuntu.com
                                                                                                                                                                                                                                                  • @ubuntu_sec on twitter
                                                                                                                                                                                                                                                  • 23 min
                                                                                                                                                                                                                                                  • Episode 48
                                                                                                                                                                                                                                                    Overview

                                                                                                                                                                                                                                                    This week we look at security updates for the Linux kernel, SDL 2, ClamAV

                                                                                                                                                                                                                                                    and more, plus Alex and Joe talk security and performance trade-offs, snaps
                                                                                                                                                                                                                                                    and OWASP Top 10 Cloud Security recommendations, and finally Alex covers
                                                                                                                                                                                                                                                    some recent concerns about the security of the Snap Store.

                                                                                                                                                                                                                                                    This week in Ubuntu Security Updates

                                                                                                                                                                                                                                                    31 unique CVEs addressed

                                                                                                                                                                                                                                                    [USN-4142-1, USN-4142-2] e2fsprogs vulnerability [00:37]
                                                                                                                                                                                                                                                    • 1 CVEs addressed in Precise ESM, Trusty ESM, Xenial, Bionic, Disco
                                                                                                                                                                                                                                                      • CVE-2019-5094
                                                                                                                                                                                                                                                      • Cisco TALOS - possible code execution via OOB write to the heap for code
                                                                                                                                                                                                                                                      • which handles quota support in ext4 - so possible to trigger via a
                                                                                                                                                                                                                                                        specially crafted ext4 partition - could be triggered during an fsck on
                                                                                                                                                                                                                                                        the partition etc.
                                                                                                                                                                                                                                                        [USN-4143-1] SDL 2.0 vulnerabilities [01:37]
                                                                                                                                                                                                                                                        • 5 CVEs addressed in Xenial, Bionic, Disco
                                                                                                                                                                                                                                                          • CVE-2019-7638
                                                                                                                                                                                                                                                          • CVE-2019-7637
                                                                                                                                                                                                                                                          • CVE-2019-7636
                                                                                                                                                                                                                                                          • CVE-2019-7635
                                                                                                                                                                                                                                                          • CVE-2017-2888
                                                                                                                                                                                                                                                          • 3 different heap based buffer over-reads -> crash, DoS
                                                                                                                                                                                                                                                          • Heap based buffer over-write -> possible code execution or at least crash -> DoS
                                                                                                                                                                                                                                                          • Integer overflow -> small alloc -> heap based buffer overflow -> possible
                                                                                                                                                                                                                                                          • code execution
                                                                                                                                                                                                                                                            [USN-4147-1] Linux kernel vulnerabilities [02:23]
                                                                                                                                                                                                                                                            • 18 CVEs addressed in Bionic (HWE), Disco
                                                                                                                                                                                                                                                              • CVE-2019-15223
                                                                                                                                                                                                                                                              • CVE-2019-15221
                                                                                                                                                                                                                                                              • CVE-2019-15218
                                                                                                                                                                                                                                                              • CVE-2019-15217
                                                                                                                                                                                                                                                              • CVE-2019-9506
                                                                                                                                                                                                                                                              • CVE-2019-15926
                                                                                                                                                                                                                                                              • CVE-2019-15925
                                                                                                                                                                                                                                                              • CVE-2019-15538
                                                                                                                                                                                                                                                              • CVE-2019-15220
                                                                                                                                                                                                                                                              • CVE-2019-15215
                                                                                                                                                                                                                                                              • CVE-2019-15212
                                                                                                                                                                                                                                                              • CVE-2019-15211
                                                                                                                                                                                                                                                              • CVE-2019-15118
                                                                                                                                                                                                                                                              • CVE-2019-15117
                                                                                                                                                                                                                                                              • CVE-2019-15090
                                                                                                                                                                                                                                                              • CVE-2019-13631
                                                                                                                                                                                                                                                              • CVE-2019-10207
                                                                                                                                                                                                                                                              • CVE-2019-0136
                                                                                                                                                                                                                                                              • OOB read in ath6kl driver - possible to trigger remotely from the network - crash, DoS
                                                                                                                                                                                                                                                              • Bluetooth KNOB attack
                                                                                                                                                                                                                                                              • Crashes from malicious USB audio devices:
                                                                                                                                                                                                                                                                • Infinite recursion when parsing device descriptors (if
                                                                                                                                                                                                                                                                • had multiple identical device descriptors could be triggered)
                                                                                                                                                                                                                                                                • OOB read if specified an invalid input pin
                                                                                                                                                                                                                                                                • OOB read in QLogic QEDI iSCSI driver
                                                                                                                                                                                                                                                                • 2 covered in Episode 46
                                                                                                                                                                                                                                                                  • Possible code execution via a NULL pointer dereference in bluetooth UART
                                                                                                                                                                                                                                                                  • driver - so if an attacker can map executable code at address zero can
                                                                                                                                                                                                                                                                    achieve code execution - in Ubuntu we have mmap_min_addr set to a
                                                                                                                                                                                                                                                                    non-zero value so this is mitigated by default
                                                                                                                                                                                                                                                                  • DoS in Intel wifi driver - allows a malicious client to knock a peer of
                                                                                                                                                                                                                                                                  • the network
                                                                                                                                                                                                                                                                    [USN-4144-1] Linux kernel vulnerabilities [05:02]
                                                                                                                                                                                                                                                                    • 2 CVEs addressed in Xenial (HWE), Bionic
                                                                                                                                                                                                                                                                      • CVE-2019-15538
                                                                                                                                                                                                                                                                      • CVE-2018-20976
                                                                                                                                                                                                                                                                      • 2 different XFS issues
                                                                                                                                                                                                                                                                        • UAF triggered from a malicious XFS image -> code exection? -> crash, DoS
                                                                                                                                                                                                                                                                        • CPU based DoS if can trigger a chgrp() error due to out-of-quota
                                                                                                                                                                                                                                                                        • [USN-4145-1] Linux kernel vulnerabilities [05:46]
                                                                                                                                                                                                                                                                          • 11 CVEs addressed in Xenial
                                                                                                                                                                                                                                                                            • CVE-2019-15926
                                                                                                                                                                                                                                                                            • CVE-2019-15215
                                                                                                                                                                                                                                                                            • CVE-2019-15211
                                                                                                                                                                                                                                                                            • CVE-2019-13631
                                                                                                                                                                                                                                                                            • CVE-2019-11487
                                                                                                                                                                                                                                                                            • CVE-2019-10207
                                                                                                                                                                                                                                                                            • CVE-2019-0136
                                                                                                                                                                                                                                                                            • CVE-2018-20976
                                                                                                                                                                                                                                                                            • CVE-2018-20961
                                                                                                                                                                                                                                                                            • CVE-2017-18509
                                                                                                                                                                                                                                                                            • CVE-2016-10905
                                                                                                                                                                                                                                                                            • Most covered above
                                                                                                                                                                                                                                                                            • [USN-4146-1, USN-4146-2] ClamAV vulnerabilities [06:00]
                                                                                                                                                                                                                                                                              • 2 CVEs addressed in Precise ESM, Trusty ESM, Xenial, Bionic, Disco
                                                                                                                                                                                                                                                                                • CVE-2019-12900
                                                                                                                                                                                                                                                                                • CVE-2019-12625
                                                                                                                                                                                                                                                                                • Update to latest upstream version (0.101.4)
                                                                                                                                                                                                                                                                                • OOB read when handling crafted BZIP2 and ZIP files - was covered for
                                                                                                                                                                                                                                                                                • bzip2 itself in Ubuntu in Episode 38 - vendored in clamav
                                                                                                                                                                                                                                                                                  Goings on in Ubuntu Security Community
                                                                                                                                                                                                                                                                                  Alex and Joe talk security and performance trade-offs, snaps and OWASP Top 10 Cloud Security recommendations [07:01]
                                                                                                                                                                                                                                                                                  • https://snapcraft.io/teamtime
                                                                                                                                                                                                                                                                                  • https://threatpost.com/intimate-details-healthcare-workers-exposed-cloud-security/149007/
                                                                                                                                                                                                                                                                                  • https://www.owasp.org/index.php/Category:OWASP_Cloud_%E2%80%90_10_Project
                                                                                                                                                                                                                                                                                  • Alex addresses some concerns with the perceived security of the Snap Store [20:44]
                                                                                                                                                                                                                                                                                    Get in contact
                                                                                                                                                                                                                                                                                    • #ubuntu-security on the Libera.Chat IRC network
                                                                                                                                                                                                                                                                                    • ubuntu-hardened mailing list
                                                                                                                                                                                                                                                                                    • Security section on discourse.ubuntu.com
                                                                                                                                                                                                                                                                                    • @ubuntu_sec on twitter
                                                                                                                                                                                                                                                                                    • 25 min
                                                                                                                                                                                                                                                                                    • Episode 47
                                                                                                                                                                                                                                                                                      Overview

                                                                                                                                                                                                                                                                                      We catch up on details of the past few weeks of security updates, including

                                                                                                                                                                                                                                                                                      Python, curl, Linux kernel, Exim and more, plus Alex and Joe discuss the
                                                                                                                                                                                                                                                                                      recent Ubuntu Engineering Sprint in Paris and building a HoneyBot for Admin
                                                                                                                                                                                                                                                                                      Magazine.

                                                                                                                                                                                                                                                                                      This week in Ubuntu Security Updates

                                                                                                                                                                                                                                                                                      93 unique CVEs addressed

                                                                                                                                                                                                                                                                                      [USN-4125-1] Memcached vulnerability [00:42]
                                                                                                                                                                                                                                                                                      • 1 CVEs addressed in Xenial, Bionic, Disco
                                                                                                                                                                                                                                                                                        • CVE-2019-15026
                                                                                                                                                                                                                                                                                        • Possible stack buffer over-read when using UNIX sockets (copies address
                                                                                                                                                                                                                                                                                        • of UNIX socket using strncpy() which could possibly read past the end of
                                                                                                                                                                                                                                                                                          the src buffer) - possible crash -> DoS - fixed to explicitly limit
                                                                                                                                                                                                                                                                                          length to smallest of src/dst buffers rather than just size of dest
                                                                                                                                                                                                                                                                                          buffer
                                                                                                                                                                                                                                                                                          [USN-4126-1] FreeType vulnerability [01:49]
                                                                                                                                                                                                                                                                                          • 1 CVEs addressed in Precise ESM, Trusty ESM, Xenial
                                                                                                                                                                                                                                                                                            • CVE-2015-9383
                                                                                                                                                                                                                                                                                            • 2 CVEs addressed in Precise ESM, Trusty ESM only
                                                                                                                                                                                                                                                                                              • CVE-2015-9382
                                                                                                                                                                                                                                                                                              • CVE-2015-9381
                                                                                                                                                                                                                                                                                              • All various heap based buffer over-reads - crash -> DoS
                                                                                                                                                                                                                                                                                              • [USN-4127-1, USN-4127-2] Python vulnerabilities [02:13]
                                                                                                                                                                                                                                                                                                • 8 CVEs addressed in Precise ESM, Trusty ESM, Xenial, Bionic, Disco
                                                                                                                                                                                                                                                                                                  • CVE-2019-9948
                                                                                                                                                                                                                                                                                                  • CVE-2019-9947
                                                                                                                                                                                                                                                                                                  • CVE-2019-9740
                                                                                                                                                                                                                                                                                                  • CVE-2019-5010
                                                                                                                                                                                                                                                                                                  • CVE-2019-10160
                                                                                                                                                                                                                                                                                                  • CVE-2019-9636
                                                                                                                                                                                                                                                                                                  • CVE-2018-20852
                                                                                                                                                                                                                                                                                                  • CVE-2018-20406
                                                                                                                                                                                                                                                                                                  • 4 issues in urllib:
                                                                                                                                                                                                                                                                                                    • would allow to easily open files from local file-system
                                                                                                                                                                                                                                                                                                    • 2 different CRLF injection issues
                                                                                                                                                                                                                                                                                                    • specially crafted URL could cause urllib to send cookies / auth data
                                                                                                                                                                                                                                                                                                    • for wrong host
                                                                                                                                                                                                                                                                                                      • Fixed incorrectly upstream so had a two CVEs assigned
                                                                                                                                                                                                                                                                                                      • http cookiejar wouldn’t validate URL correctly so could also send cookies
                                                                                                                                                                                                                                                                                                      • for another domain
                                                                                                                                                                                                                                                                                                      • Possible NULL ptr deref when parsing X509 certs if had an empty CRL
                                                                                                                                                                                                                                                                                                      • distpoint / URI
                                                                                                                                                                                                                                                                                                      • Possible integer overflow when serializing a tens of hundreds of
                                                                                                                                                                                                                                                                                                      • gigabytes of data via the pickle format - could cause memory exhaustion
                                                                                                                                                                                                                                                                                                        [USN-4128-1, USN-4128-2] Tomcat vulnerabilities [03:35]
                                                                                                                                                                                                                                                                                                        • 3 CVEs addressed in Xenial, Bionic (tomcat-8) and Bionic, Disco (tomcat-9)
                                                                                                                                                                                                                                                                                                          • CVE-2019-10072
                                                                                                                                                                                                                                                                                                          • CVE-2019-0199
                                                                                                                                                                                                                                                                                                          • CVE-2019-0221
                                                                                                                                                                                                                                                                                                          • HTTP/2 server would accept streams with an excessive number of SETTINGS
                                                                                                                                                                                                                                                                                                          • frames and would permit clients to keep streams open without reading /
                                                                                                                                                                                                                                                                                                            writing anything - could lead to DoS by causing server-side threads to
                                                                                                                                                                                                                                                                                                            block
                                                                                                                                                                                                                                                                                                            • Original fix was incomplete - so got a second CVE
                                                                                                                                                                                                                                                                                                            • Possible XSS injection if using SSI printenv command as would echo user
                                                                                                                                                                                                                                                                                                            • provided data without escaping - intended only for debugging so shouldn’t
                                                                                                                                                                                                                                                                                                              be used in a production website anyway
                                                                                                                                                                                                                                                                                                              [USN-4120-2] systemd regression [04:45]
                                                                                                                                                                                                                                                                                                              • Affecting Bionic, Disco
                                                                                                                                                                                                                                                                                                              • Episode 46 - systemd-resolved dbus access control - the update was
                                                                                                                                                                                                                                                                                                              • prepared using a pending SRU update - but this contained a regression in
                                                                                                                                                                                                                                                                                                                networking - re-released the security fix but without this SRU update
                                                                                                                                                                                                                                                                                                                included.
                                                                                                                                                                                                                                                                                                                [USN-4115-2] Linux kernel regression [05:18]
                                                                                                                                                                                                                                                                                                                • Affecting Xenial (HWE), Bionic
                                                                                                                                                                                                                                                                                                                • Recent kernel update (Episode 46) could possibly crash on handling
                                                                                                                                                                                                                                                                                                                • fragmented packets
                                                                                                                                                                                                                                                                                                                  [USN-4129-1, USN-4129-2] curl vulnerabilities [05:42]
                                                                                                                                                                                                                                                                                                                  • 1 CVEs addressed in Precise ESM, Trusty ESM, Xenial, Bionic, Disco
                                                                                                                                                                                                                                                                                                                    • CVE-2019-5482
                                                                                                                                                                                                                                                                                                                      • Heap buffer overflow in TFTP protocol handler
                                                                                                                                                                                                                                                                                                                      • 1 extra CVEs addressed in Xenial, Bionic, Disco
                                                                                                                                                                                                                                                                                                                        • CVE-2019-5481
                                                                                                                                                                                                                                                                                                                          • Double free in FTP-kerberos code
                                                                                                                                                                                                                                                                                                                          • [USN-4130-1] WebKitGTK+ vulnerabilities [06:15]
                                                                                                                                                                                                                                                                                                                            • 16 CVEs addressed in Bionic, Disco
                                                                                                                                                                                                                                                                                                                              • CVE-2019-8690
                                                                                                                                                                                                                                                                                                                              • CVE-2019-8689
                                                                                                                                                                                                                                                                                                                              • CVE-2019-8688
                                                                                                                                                                                                                                                                                                                              • CVE-2019-8687
                                                                                                                                                                                                                                                                                                                              • CVE-2019-8684
                                                                                                                                                                                                                                                                                                                              • CVE-2019-8683
                                                                                                                                                                                                                                                                                                                              • CVE-2019-8681
                                                                                                                                                                                                                                                                                                                              • CVE-2019-8680
                                                                                                                                                                                                                                                                                                                              • CVE-2019-8678
                                                                                                                                                                                                                                                                                                                              • CVE-2019-8676
                                                                                                                                                                                                                                                                                                                              • CVE-2019-8673
                                                                                                                                                                                                                                                                                                                              • CVE-2019-8669
                                                                                                                                                                                                                                                                                                                              • CVE-2019-8666
                                                                                                                                                                                                                                                                                                                              • CVE-2019-8658
                                                                                                                                                                                                                                                                                                                              • CVE-2019-8649
                                                                                                                                                                                                                                                                                                                              • CVE-2019-8644
                                                                                                                                                                                                                                                                                                                              • Update to latest WebKitGTK upstream release (2.24.4)
                                                                                                                                                                                                                                                                                                                              • [USN-4131-1] VLC vulnerabilities [06:38]
                                                                                                                                                                                                                                                                                                                                • 11 CVEs addressed in Bionic, Disco
                                                                                                                                                                                                                                                                                                                                  • CVE-2019-14970
                                                                                                                                                                                                                                                                                                                                  • CVE-2019-14778
                                                                                                                                                                                                                                                                                                                                  • CVE-2019-14777
                                                                                                                                                                                                                                                                                                                                  • CVE-2019-14776
                                                                                                                                                                                                                                                                                                                                  • CVE-2019-14535
                                                                                                                                                                                                                                                                                                                                  • CVE-2019-14534
                                                                                                                                                                                                                                                                                                                                  • CVE-2019-14533
                                                                                                                                                                                                                                                                                                                                  • CVE-2019-14498
                                                                                                                                                                                                                                                                                                                                  • CVE-2019-14438
                                                                                                                                                                                                                                                                                                                                  • CVE-2019-14437
                                                                                                                                                                                                                                                                                                                                  • CVE-2019-13962
                                                                                                                                                                                                                                                                                                                                  • Update to latest VLC upstream release (3.0.8)
                                                                                                                                                                                                                                                                                                                                  • [USN-4133-1] Wireshark vulnerabilities [06:48]
                                                                                                                                                                                                                                                                                                                                    • 2 CVEs addressed in Xenial, Bionic, Disco
                                                                                                                                                                                                                                                                                                                                      • CVE-2019-13619
                                                                                                                                                                                                                                                                                                                                      • CVE-2019-12295
                                                                                                                                                                                                                                                                                                                                      • Update to latest upstream release (2.6.10-1)
                                                                                                                                                                                                                                                                                                                                      • [USN-4132-1, USN-4132-2] Expat vulnerability [06:55]
                                                                                                                                                                                                                                                                                                                                        • 1 CVEs addressed in Precise ESM, Trusty ESM, Xenial, Bionic, Disco
                                                                                                                                                                                                                                                                                                                                          • CVE-2019-15903
                                                                                                                                                                                                                                                                                                                                          • Crafted XML could fool the parser to switch to document parsing too early
                                                                                                                                                                                                                                                                                                                                          • (whilst still in DTD) - could then result in a heap-based buffer
                                                                                                                                                                                                                                                                                                                                            over-read when looking up current line / column number - possible crash
                                                                                                                                                                                                                                                                                                                                            -> DoS
                                                                                                                                                                                                                                                                                                                                            [USN-4134-1] IBus vulnerability [07:30]
                                                                                                                                                                                                                                                                                                                                            • 1 CVEs addressed in Xenial, Bionic, Disco
                                                                                                                                                                                                                                                                                                                                              • CVE-2019-14822
                                                                                                                                                                                                                                                                                                                                              • Failed to apply access controls to D-Bus server socket - could allow
                                                                                                                                                                                                                                                                                                                                              • another local user to connect to logged in local user’s IBus daemon and
                                                                                                                                                                                                                                                                                                                                                snoop on keystrokes etc
                                                                                                                                                                                                                                                                                                                                                • Attacker needs to know IBus socket address which is randomised and not
                                                                                                                                                                                                                                                                                                                                                • easily discoverable
                                                                                                                                                                                                                                                                                                                                                  [USN-4134-2] IBus regression [08:00]
                                                                                                                                                                                                                                                                                                                                                  • Affecting Xenial, Bionic, Disco
                                                                                                                                                                                                                                                                                                                                                  • Regressed for Qt users - Qt seems unable to connect to IBus socket - so
                                                                                                                                                                                                                                                                                                                                                  • reverted
                                                                                                                                                                                                                                                                                                                                                    [USN-4124-2] Exim vulnerability [08:25]
                                                                                                                                                                                                                                                                                                                                                    • 1 CVEs addressed in Trusty ESM
                                                                                                                                                                                                                                                                                                                                                      • CVE-2019-15846
                                                                                                                                                                                                                                                                                                                                                      • Episode 46 - high profile possible remote root exploit
                                                                                                                                                                                                                                                                                                                                                      • [USN-4113-2] Apache HTTP Server regression [08:38]
                                                                                                                                                                                                                                                                                                                                                        • Affecting Xenial, Bionic, Disco
                                                                                                                                                                                                                                                                                                                                                        • Episode 45 - HTTP/2 DoS issues - update caused a regression when proxying
                                                                                                                                                                                                                                                                                                                                                        • balance manager connections - fixed by incorporating missing upstream
                                                                                                                                                                                                                                                                                                                                                          patches
                                                                                                                                                                                                                                                                                                                                                          [USN-4135-1, USN-4135-2] Linux kernel vulnerabilities [09:01]
                                                                                                                                                                                                                                                                                                                                                          • 3 CVEs addressed in Precise ESM, Trusty ESM, Xenial, Bionic, Disco
                                                                                                                                                                                                                                                                                                                                                            • CVE-2019-15031
                                                                                                                                                                                                                                                                                                                                                            • CVE-2019-15030
                                                                                                                                                                                                                                                                                                                                                            • CVE-2019-14835
                                                                                                                                                                                                                                                                                                                                                            • Possible host privilege escalation from a libvirt guest (guest user needs
                                                                                                                                                                                                                                                                                                                                                            • to be privileged)
                                                                                                                                                                                                                                                                                                                                                            • 2 related info disclosures on PowerPC - local user could possibly read
                                                                                                                                                                                                                                                                                                                                                            • vector registers of other users’ processes either during an interrupt or
                                                                                                                                                                                                                                                                                                                                                              via a facility unavailable exception
                                                                                                                                                                                                                                                                                                                                                              [LSN-0056-1] Linux kernel vulnerability [09:51]
                                                                                                                                                                                                                                                                                                                                                              • 1 CVEs addressed in Xenial, Bionic
                                                                                                                                                                                                                                                                                                                                                                • CVE-2019-14835
                                                                                                                                                                                                                                                                                                                                                                • Livepatch notification of above libvirt host privesc
                                                                                                                                                                                                                                                                                                                                                                • [USN-4136-1, USN-4136-2] wpa_supplicant and hostapd vulnerability [10:06]
                                                                                                                                                                                                                                                                                                                                                                  • 1 CVEs addressed in Precise ESM, Trusty ESM, Xenial, Bionic, Disco
                                                                                                                                                                                                                                                                                                                                                                    • CVE-2019-16275
                                                                                                                                                                                                                                                                                                                                                                    • Attacker in radio range could cause a station to disconnect by sending a
                                                                                                                                                                                                                                                                                                                                                                    • specially crafted management frame (since would not properly validate the
                                                                                                                                                                                                                                                                                                                                                                      source address of the frame)
                                                                                                                                                                                                                                                                                                                                                                      [USN-4137-1] Mosquitto vulnerability [10:44]
                                                                                                                                                                                                                                                                                                                                                                      • 1 CVEs addressed in Disco
                                                                                                                                                                                                                                                                                                                                                                        • CVE-2019-11779
                                                                                                                                                                                                                                                                                                                                                                        • Stack overflow if a malicious client sends a SUBSCRIBE with a topic of
                                                                                                                                                                                                                                                                                                                                                                        • ~65k ‘/’ characters
                                                                                                                                                                                                                                                                                                                                                                          [USN-4138-1] LibreOffice vulnerability [10:56]
                                                                                                                                                                                                                                                                                                                                                                          • 1 CVEs addressed in Xenial, Bionic, Disco
                                                                                                                                                                                                                                                                                                                                                                            • CVE-2019-9854
                                                                                                                                                                                                                                                                                                                                                                            • Episode 44 - able to bypass protections added to try and stop inclusion
                                                                                                                                                                                                                                                                                                                                                                            • of code on local file-system in macros etc via URL encoding
                                                                                                                                                                                                                                                                                                                                                                              [USN-4139-1] File Roller vulnerability [11:18]
                                                                                                                                                                                                                                                                                                                                                                              • 1 CVEs addressed in Xenial, Bionic
                                                                                                                                                                                                                                                                                                                                                                                • CVE-2019-16680
                                                                                                                                                                                                                                                                                                                                                                                • Path traversal outside of CWD to parent
                                                                                                                                                                                                                                                                                                                                                                                • [USN-4140-1] Firefox vulnerability [11:33]
                                                                                                                                                                                                                                                                                                                                                                                  • 1 CVEs addressed in Xenial, Bionic, Disco
                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2019-11754
                                                                                                                                                                                                                                                                                                                                                                                    • Latest upstream release (69.0.1) - pointer lock able to be enabled
                                                                                                                                                                                                                                                                                                                                                                                    • without any notification to user - could allow a malicious website to
                                                                                                                                                                                                                                                                                                                                                                                      hijack mouse cursor and confuse user
                                                                                                                                                                                                                                                                                                                                                                                      [USN-4141-1] Exim vulnerability [11:54]
                                                                                                                                                                                                                                                                                                                                                                                      • 1 CVEs addressed in Disco
                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2019-16928
                                                                                                                                                                                                                                                                                                                                                                                        • Heap-based buffer overflow - could possibly allow remote code execution -
                                                                                                                                                                                                                                                                                                                                                                                        • was announced on Saturday 28th - thanks Marc for the quick update :)
                                                                                                                                                                                                                                                                                                                                                                                          Goings on in Ubuntu Security Community
                                                                                                                                                                                                                                                                                                                                                                                          Joe and Alex talk about the Paris Engineering Sprint and Joe’s recent article in Admin Magazine [12:42]
                                                                                                                                                                                                                                                                                                                                                                                          • http://www.admin-magazine.com/Articles/Build-a-honeypot-with-real-world-alerts?utm_source=AMTW
                                                                                                                                                                                                                                                                                                                                                                                          • https://github.com/joemcmanus/honeybot
                                                                                                                                                                                                                                                                                                                                                                                          • New security category on discourse.ubuntu.com [25:52]
                                                                                                                                                                                                                                                                                                                                                                                            • https://discourse.ubuntu.com/c/security
                                                                                                                                                                                                                                                                                                                                                                                            • Created to allow discussion of security relevant Ubuntu topics and issues
                                                                                                                                                                                                                                                                                                                                                                                            • in a more user-friendly and centralised location
                                                                                                                                                                                                                                                                                                                                                                                              • Will be used in addition to the existing ubuntu-hardened mailing list
                                                                                                                                                                                                                                                                                                                                                                                              • and #ubuntu-hardened IRC channel
                                                                                                                                                                                                                                                                                                                                                                                                Get in contact
                                                                                                                                                                                                                                                                                                                                                                                                • #ubuntu-security on the Libera.Chat IRC network
                                                                                                                                                                                                                                                                                                                                                                                                • ubuntu-hardened mailing list
                                                                                                                                                                                                                                                                                                                                                                                                • Security section on discourse.ubuntu.com
                                                                                                                                                                                                                                                                                                                                                                                                • @ubuntu_sec on twitter
                                                                                                                                                                                                                                                                                                                                                                                                • 29 min
                                                                                                                                                                                                                                                                                                                                                                                                • Episode 46
                                                                                                                                                                                                                                                                                                                                                                                                  Overview

                                                                                                                                                                                                                                                                                                                                                                                                  A massive 85 CVEs addressed this week, including updates for Exim, the

                                                                                                                                                                                                                                                                                                                                                                                                  Linux Kernel, Samba, systemd and more, plus we discuss hacking BMCs via
                                                                                                                                                                                                                                                                                                                                                                                                  remote USB devices and password stashes.

                                                                                                                                                                                                                                                                                                                                                                                                  This week in Ubuntu Security Updates

                                                                                                                                                                                                                                                                                                                                                                                                  85 unique CVEs addressed

                                                                                                                                                                                                                                                                                                                                                                                                  [USN-4124-1] Exim vulnerability [00:49]
                                                                                                                                                                                                                                                                                                                                                                                                  • 1 CVEs addressed in Xenial, Bionic, Disco
                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2019-15846
                                                                                                                                                                                                                                                                                                                                                                                                      • When doing TLS negotiation, parses the Server Name Indication
                                                                                                                                                                                                                                                                                                                                                                                                      • headers - would try and handle escape sequences in this string.
                                                                                                                                                                                                                                                                                                                                                                                                      • Does so by looking at the character after a backslash to determine
                                                                                                                                                                                                                                                                                                                                                                                                      • what escape sequence is (\b etc) and then returns that actual value
                                                                                                                                                                                                                                                                                                                                                                                                        (in string_interpret_escape())
                                                                                                                                                                                                                                                                                                                                                                                                      • This gets called by the function string_unprinting() which is used to
                                                                                                                                                                                                                                                                                                                                                                                                      • translate escaped characters into their proper form in a new string -
                                                                                                                                                                                                                                                                                                                                                                                                        and this will run over the bounds of the original string if it ends
                                                                                                                                                                                                                                                                                                                                                                                                        with a backslash - since string_interpret_escape() would assume there
                                                                                                                                                                                                                                                                                                                                                                                                        was contents afterwards to interpret
                                                                                                                                                                                                                                                                                                                                                                                                      • Qualsys were able to develop a PoC which leverages this OOB behaviour
                                                                                                                                                                                                                                                                                                                                                                                                      • into a remote root exploit (since this part of the code runs as root
                                                                                                                                                                                                                                                                                                                                                                                                        and they were able to use a combination of heap corruption and OOB
                                                                                                                                                                                                                                                                                                                                                                                                        writes to get code execution)
                                                                                                                                                                                                                                                                                                                                                                                                      • Fixed to first check if reached end of string (NUL) before trying to
                                                                                                                                                                                                                                                                                                                                                                                                      • handle the escaped character
                                                                                                                                                                                                                                                                                                                                                                                                      • Able to be mitigated by setting ACLs to deny connections which contain
                                                                                                                                                                                                                                                                                                                                                                                                      • a trailing backslash in the SNI field - see CVE-2019-15846 in the Ubuntu CVE Tracker
                                                                                                                                                                                                                                                                                                                                                                                                      • Lots of press coverage:
                                                                                                                                                                                                                                                                                                                                                                                                        • https://www.zdnet.com/article/millions-of-exim-servers-vulnerable-to-root-granting-exploit/
                                                                                                                                                                                                                                                                                                                                                                                                        • https://threatpost.com/critical-exim-flaw-opens-millions-of-servers-to-takeover/148108/
                                                                                                                                                                                                                                                                                                                                                                                                        • https://www.theregister.co.uk/2019/09/06/exim_vulnerability_patch/
                                                                                                                                                                                                                                                                                                                                                                                                        • https://www.bleepingcomputer.com/news/security/critical-exim-tls-flaw-lets-attackers-remotely-execute-commands-as-root/
                                                                                                                                                                                                                                                                                                                                                                                                        • [USN-4114-1] Linux kernel vulnerabilities [03:49]
                                                                                                                                                                                                                                                                                                                                                                                                          • 5 CVEs addressed in Bionic (HWE), Disco
                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2019-3900
                                                                                                                                                                                                                                                                                                                                                                                                              • Infinite loop in virtio network driver - guest VM cause host DoS by stalling vhost_net kernel thread
                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2019-14284
                                                                                                                                                                                                                                                                                                                                                                                                                • Divide by zero in floppy driver ioctl() handler (created by default by qemu)
                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2019-14283
                                                                                                                                                                                                                                                                                                                                                                                                                  • Integer overflow and OOB read in floppy driver
                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2019-13648
                                                                                                                                                                                                                                                                                                                                                                                                                    • DoS for PowerPC if user calls sigreturn() with crafted signal stack
                                                                                                                                                                                                                                                                                                                                                                                                                    • frame - exception and system crash (requires transactional memory to
                                                                                                                                                                                                                                                                                                                                                                                                                      be disabled)
                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2019-10638
                                                                                                                                                                                                                                                                                                                                                                                                                      • Kernel tries to randomise IP ID values (used for de-fragmentation of
                                                                                                                                                                                                                                                                                                                                                                                                                      • IP packets) for connection-less protocols to avoid tracking
                                                                                                                                                                                                                                                                                                                                                                                                                      • Is meant to be random across source + dest address + protocol
                                                                                                                                                                                                                                                                                                                                                                                                                      • But if an attacker can observe traffic to multiple hosts, can infer
                                                                                                                                                                                                                                                                                                                                                                                                                      • the hashing key used to generate the ID values
                                                                                                                                                                                                                                                                                                                                                                                                                      • And then can associate different streams of packets back to the same
                                                                                                                                                                                                                                                                                                                                                                                                                      • source host and hence can track devices
                                                                                                                                                                                                                                                                                                                                                                                                                      • Fixed to used an actual random value for the base of the hash and use
                                                                                                                                                                                                                                                                                                                                                                                                                      • a better hashing algorithm (siphash) for ID generation
                                                                                                                                                                                                                                                                                                                                                                                                                        [USN-4115-1] Linux kernel vulnerabilities [06:42]
                                                                                                                                                                                                                                                                                                                                                                                                                        • 28 CVEs addressed in Xenial (HWE), Bionic
                                                                                                                                                                                                                                                                                                                                                                                                                        • 5 negligible (not enabled by default), 11 low (very unlikely to trigger -
                                                                                                                                                                                                                                                                                                                                                                                                                        • module unload after proc initialization failure etc), 12 medium
                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2019-3819
                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2019-3701
                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2019-15221
                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2019-15218
                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2019-15216
                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2019-9506
                                                                                                                                                                                                                                                                                                                                                                                                                            • Bluetooth KNOB attack
                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2019-3900
                                                                                                                                                                                                                                                                                                                                                                                                                              • Infinite loop in virtio net driver (guest VM cause host DoS)
                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2019-15292
                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2019-15220
                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2019-15215
                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2019-15214
                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2019-15212
                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2019-15211
                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2019-15090
                                                                                                                                                                                                                                                                                                                                                                                                                                • OOB read in debug functions of QLogic QEDI iSCSI Initiator Driver
                                                                                                                                                                                                                                                                                                                                                                                                                                • (allows to read kernel memory - KASLR defeat?)
                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2019-14763
                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2019-14284
                                                                                                                                                                                                                                                                                                                                                                                                                                  • See above (Divide by zero in floppy driver)
                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2019-14283
                                                                                                                                                                                                                                                                                                                                                                                                                                    • See above (Integer overflow and OOB read in floppy driver)
                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2019-13648
                                                                                                                                                                                                                                                                                                                                                                                                                                      • See above (PowerPC DoS on sigreturn())
                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2019-13631
                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2019-11810
                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2019-11599
                                                                                                                                                                                                                                                                                                                                                                                                                                        • Core dump race (Episode 41)
                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2019-11487
                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2019-10639
                                                                                                                                                                                                                                                                                                                                                                                                                                          • Related to CVE-2019-10638 - since used base address of kernel
                                                                                                                                                                                                                                                                                                                                                                                                                                          • structure in memory as hash base, could allow attacker to infer this
                                                                                                                                                                                                                                                                                                                                                                                                                                            address and so defeat KASLR
                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2019-10638
                                                                                                                                                                                                                                                                                                                                                                                                                                            • See above (IP ID randomisation)
                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2019-10207
                                                                                                                                                                                                                                                                                                                                                                                                                                              • NULL pointer address execution (call function pointer which is NULL
                                                                                                                                                                                                                                                                                                                                                                                                                                              • since is not initializated) - Ubuntu defaults to a non-zero
                                                                                                                                                                                                                                                                                                                                                                                                                                                mmap_min_addr value which means can’t map a page at 0 address so this
                                                                                                                                                                                                                                                                                                                                                                                                                                                is just a NULL pointer dereference in default config (otherwise is
                                                                                                                                                                                                                                                                                                                                                                                                                                                arbitrary kernel code execution)
                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2019-0136
                                                                                                                                                                                                                                                                                                                                                                                                                                                • Intel Wifi Driver Tunneled Direct Link Setup (allows devices to
                                                                                                                                                                                                                                                                                                                                                                                                                                                • communicate directly with one-another on the same network without
                                                                                                                                                                                                                                                                                                                                                                                                                                                  going via AP) - flaw allows a peer to cause wifi disconnection (DoS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2018-20784
                                                                                                                                                                                                                                                                                                                                                                                                                                                  • Infinite loop in CFS schedular - DoS
                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2018-19985
                                                                                                                                                                                                                                                                                                                                                                                                                                                  • [USN-4116-1] Linux kernel vulnerabilities [09:12]
                                                                                                                                                                                                                                                                                                                                                                                                                                                    • 6 CVEs addressed in Xenial
                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2019-3900
                                                                                                                                                                                                                                                                                                                                                                                                                                                        • Infinite loop in virtio net driver (guest VM cause host DoS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2019-14284
                                                                                                                                                                                                                                                                                                                                                                                                                                                          • See above (Divide by zero in floppy driver)
                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2019-14283
                                                                                                                                                                                                                                                                                                                                                                                                                                                            • See above (Integer overflow and OOB read in floppy driver)
                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2019-13648
                                                                                                                                                                                                                                                                                                                                                                                                                                                              • See above (PowerPC DoS on sigreturn())
                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2019-10638
                                                                                                                                                                                                                                                                                                                                                                                                                                                                • See above (IP ID randomisation)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2018-20856
                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • UAF in block-layer under particular failure conditions
                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • [USN-4117-1] Linux kernel (AWS) vulnerabilities [09:43]
                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • 9 CVEs addressed in Disco
                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2019-3900
                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • Infinite loop in virtio net driver (guest VM cause host DoS)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2019-3846
                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • Marvell Wifi OOB write (Episode 43)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2019-10126
                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • Marvell Wifi OOB write (Episode 43)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2019-14284
                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • See above (Divide by zero in floppy driver)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2019-14283
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • See above (Integer overflow and OOB read in floppy driver)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2019-13272
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • ptrace race (Episode 43)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2019-13233
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • UAF in handling of x86 LDT entries (Episode 43)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2019-12984
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • NULL ptr dereference in NFC subsystem (Episode 43)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2019-10638
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • See above (IP ID randomisation)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • [USN-4118-1] Linux kernel (AWS) vulnerabilities [10:17]
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • 61 CVEs addressed in Xenial, Bionic
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2019-3819
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2019-3701
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2019-15221
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2019-15218
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2019-15216
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2018-20511
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2019-9506
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2019-3900
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2019-3846
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2019-2101
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2019-2024
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2019-15292
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2019-15220
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2019-15215
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2019-15214
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2019-15212
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2019-15211
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2019-15090
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2019-14763
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2019-14284
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2019-14283
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2019-13631
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2019-13272
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2019-13233
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2019-12984
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2019-12819
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2019-12818
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2019-11884
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2019-11833
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2019-11815
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2019-11810
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2019-11599
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2019-11487
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2019-11085
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2019-10639
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2019-10638
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2019-10207
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2019-10126
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2019-0136
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2018-5383
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2018-20856
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2018-20784
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2018-20169
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2018-19985
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2018-16862
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2018-14617
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2018-14613
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2018-14612
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2018-14611
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2018-14610
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2018-14609
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2018-14616
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2018-14615
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2018-14614
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2018-13100
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2018-13099
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2018-13098
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2018-13097
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2018-13096
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2018-13093
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2018-13053
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • [USN-3934-2] PolicyKit vulnerability [10:36]
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • 1 CVEs addressed in Precise ESM
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2019-6133
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • Episode 27 - PolicyKit could get confused via PID reuse - fix was 2
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • parts - 1 kernel to ensure can’t race kernel on PID assignment, and
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  second was in PolicyKit itself to check on PID, UID and start time.
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  [USN-4119-1] Irssi vulnerability [11:23]
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • 1 CVEs addressed in Disco
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2019-15717
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • UAF if server sends two CAP commands (used by client and server to negotiate
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • capabilities - ie sasl support etc)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        [USN-4121-1] Samba vulnerability [11:52]
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • 1 CVEs addressed in Disco
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2019-10197
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • Possible directory share escape by unauthenticated users - allows
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • attackers to gain access to the host filesystem outside the share
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              root (limited as per underlying file-system permissions)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • Needs the server to have explicitly enabled ‘wide links’ and not be
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • using ‘unix extensions’ OR to have also set ‘allow insecure wide
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              links’
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              [USN-4120-1] systemd vulnerability [12:40]
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • 1 CVEs addressed in Bionic, Disco
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2019-15718
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • systemd-resolved failed to properly setup access controls on its DBus
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • server socket, whic allows unprivileged users to execute DBus methods
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    that should only be executable by privileged users - such as changing
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    the systems DNS resolver settings
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    [USN-4122-1] Firefox vulnerabilities [13:10]
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • 17 CVEs addressed in Xenial, Bionic, Disco
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2019-11747
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2019-11741
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2019-9812
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2019-11752
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2019-11750
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2019-11749
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2019-11748
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2019-11746
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2019-11744
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2019-11743
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2019-11742
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2019-11740
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2019-11738
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2019-11737
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2019-11735
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2019-11734
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2019-5849
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • Upstream Firefox 69.0 release
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • https://www.mozilla.org/en-US/security/advisories/mfsa2019-25/
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • [USN-4123-1] npm/fstream vulnerability [13:29]
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • 1 CVEs addressed in Bionic, Disco
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2019-13173
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • Goings on in Ubuntu Security Community
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Joe and Alex discuss hacking BMCs via a remote USN attack [13:53]
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • https://thehackernews.com/2019/09/hacking-bmc-server.html
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • Joe and Alex also discuss password stashes [20:33]
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Get in contact
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • #ubuntu-security on the Libera.Chat IRC network
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • @ubuntu_sec on twitter
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • 26 min
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • Episode 45
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Overview

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  This week we look at security updates for Dovecot, Ghostscript, a livepatch update for the Linux kernel, Ceph and Apache, plus Alex and Joe discuss recent Wordpress plugin vulnerabilities and the Hostinger breach, and more.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  This week in Ubuntu Security Updates

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  22 unique CVEs addressed

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  [USN-4110-1, USN-4110-2] Dovecot vulnerability [00:52]
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • 1 CVEs addressed in Precise ESM, Trusty ESM, Xenial, Bionic, Disco
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2019-11500
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • IMAP and ManageSieve protocol parsers would not check for embedded NUL bytes in strings
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • When parsing these strings, would return indexes outside the normal
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • string bounds as the first character which needed unescaping
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • Would then go and try to unescape the string from this index, which
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • rewrites the string on the fly, and so would then go and rewrite
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        outside the bounds of the string
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • Fixed to disallow embedded NUL bytes AND to not try and skip up to
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • first unescaped character but instead loop over the whole string in
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        unescaping
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        [USN-4110-3, USN-4110-4] Dovecot regression [02:08]
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • 1 CVEs addressed in Precise ESM, Trusty ESM, Xenial, Bionic, Disco
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2019-11500
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • Original patch used pre-release version of the fix from upstream which
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • contained an error such that the checking of NUL bytes was skipped -
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            re-released with correct final upstream fix
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            [LSN-0054-1] Linux kernel vulnerability [02:38]
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • 9 CVEs addressed in Xenial, Bionic
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2018-1129
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2019-13272
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2019-12984
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2019-12819
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2019-12818
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2019-12614
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2019-10126
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2019-3846
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2019-2101
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • Livepatch for CVEs addressed in regular kernel updates (Episode 43)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • ptrace credentials race, Marvell Wifi heap-buffer overflows, NULL
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • pointer dereferences
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  [USN-4111-1] Ghostscript vulnerabilities [03:20]
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • 4 CVEs addressed in Xenial, Bionic, Disco
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2019-14817
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2019-14813
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2019-14812
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2019-14811
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • Four more -dSAFER sandbox bypasses (see Episode 43 for the last one)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • All variations on the theme of using the .forceput operator to escape the
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • sandbox
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      [USN-4112-1] Ceph vulnerability [04:01]
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • 1 CVEs addressed in Bionic, Disco
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2019-10222
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • DoS - unauthenticated clients can crash the rados gateway by
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • disconnecting at certain time (triggering a NULL pointer deference when
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          looking up the remote address for a connected client)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • Older versions are not affected since this is in the beast RGW
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • frontend - which is not in the versions in trusty / xenial - and only
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            in the bionic version as an experimental feature
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            [USN-4113-1] Apache HTTP Server vulnerabilities [04:41]
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • 7 CVEs addressed in Xenial, Bionic, Disco

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2019-9517
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2019-10098
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2019-10097
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2019-10092
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2019-10082
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2019-10081
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2019-0197
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • HTTP/2 DoS issue (Internal Data Buffering) - Episode 43 for nginx

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/http2
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • Open redirect in mod_rewrite if have self-referential redirects

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • Stack buffer overflow + NULL pointer dereference in mod_remoteip

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • Possible XSS in mod_proxy where the link shown on error pages could be

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  controlled by an attacker - but only possible where configured with
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  proxying enable but misconfigured so that Proxy Error page is shown.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • UAF (read) during HTTP/2 connection shutdown

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • HTTP/2 push - allows server to send resources to a client before it

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  requests them - could overwrite memory of the server’s request pool -
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  this is preconfigured and not under control of client but could cause a
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  crash etc.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • HTTP/2 upgrade - can configure to automatically upgrade HTTP/1.1 requests

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  to HTTP/2 - but if this was not the first request on the connection could
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  lead to crash

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Goings on in Ubuntu Security Community
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Alex and Joe talk Wordpress plugin vulnerabiliies and Hostinger password breach [07:03]
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • https://threatpost.com/wordpress-plugins-exploited-in-ongoing-attack-researchers-warn/147671/
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • https://www.zdnet.com/article/hostinger-resets-customer-passwords-after-security-incident/
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • https://www.nccgroup.trust/us/about-us/newsroom-and-events/blog/2009/july/if-youre-typing-the-letters-a-e-s-into-your-code-youre-doing-it-wrong/
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • OpenSSL 1.1.1 with TLS 1.3 support complete for Ubuntu 18.04 LTS (Bionic) [17:29]
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • OpenSSL upgraded to version 1.1.1 in Ubuntu 18.04 LTS - supports TLS
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • 1.3 - now published via -updates and -security
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Get in contact
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • #ubuntu-security on the Libera.Chat IRC network
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • @ubuntu_sec on twitter
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • 20 min
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • Episode 44
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Overview

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        This week Joe and Alex discuss a recently disclosed backdoor in Webmin, plus we cover security updates from the past week, including for Nova, KDE, LibreOffice, Docker, CUPS and more.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        This week in Ubuntu Security Updates

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        21 unique CVEs addressed

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        [USN-4100-1] KConfig and KDE libraries vulnerabilities [00:46]
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • 2 CVEs addressed in Xenial, Bionic, Disco
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2016-6232
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2019-14744
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • Directory traversal in KArchive via ../
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • RCE via malicious .desktop file - contianed extra functionality outside
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • of XDG spec, where could contain shell commands that would get expanded -
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            so if you view a .desktop file in Dolphin, and the Icon property
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            contained shell commands, this would get evaluated - so wouldn’t need to
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            interact at all - upstream now removed this ‘feature’
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            [USN-4102-1] LibreOffice vulnerabilities [02:45]
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • 3 CVEs addressed in Xenial, Bionic, Disco
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2019-9852
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2019-9851
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2019-9850
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • Docs can have macros & scripts on action - document-open, mouse-over
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • Should only be for scripts shipped in libreoffice itself
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • Path bypass in CVE-2018-16858 - so added more protections
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • Could be bypassed again with URL encoding - so fix again
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • Second LibreLogo issue (Episode 40) - could bypass previous protections
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • again - was fixed upstream but found to still be inadequate - hence 2
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  CVEs for this (incomplete fix the first time around)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  [USN-4078-2] OpenLDAP vulnerabilities [04:26]
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • 2 CVEs addressed in Precise ESM, Trusty ESM
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2019-13565
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2019-13057
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • Episode 41 for regular releases - now ESM as well
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • [USN-4103-1, USN-4103-2] docker-credential-helpers and Docker vulnerabilities [04:52]
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • 1 CVEs addressed in Disco (docker-credential-helpers)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • 1 CVEs addressed in Xenial, Bionic, Disco (docker)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2019-1020014
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • golang-docker-credentials package had a double-free which could be
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • triggered via a local user -> crash, DoS
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • Bundled with docker.io package so update both
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • [USN-4104-1] Nova vulnerability [05:28]
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • 1 CVEs addressed in Xenial, Bionic, Disco
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2019-14433
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • API requests which end in fault conditions from authenticated users could
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • result in keys or other details being leaked / returned in responses to
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              further API requests (not just any error / fault but say if tried to
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              hard-reboot and this fails) - fixed to sanitize any possible details out
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              of faults
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              [USN-4105-1] CUPS vulnerabilities [06:30]
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • 2 CVEs addressed in Xenial, Bionic, Disco
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2019-8675
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2019-8696
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • SNMP backend - parses ASN.1 encoded data - can be used to automatically
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • get status from printers etc - would not do bounds checking on actual
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  encoded ASN.1 data vs the description of it - so could easily get a stack
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  buffer overflow - fixed to add bounds checking
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • Also includes some other upstream fixes for potential security issues
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • (without CVEs), including a CPU based DoS if a cups client unexpectedly
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  disconnected
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  [USN-4106-1] NLTK vulnerability [07:37]
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • 1 CVEs addressed in Xenial, Bionic, Disco
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2019-14751
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • Python Natural Language Toolkit - downloads datasets as ZIP compressed
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • Mike Salvatore - ZipSlip
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • https://salvatoresecurity.com/zip-slip-in-nltk-cve-2019-14751/
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • Fixed to use inbuilt python zipfile handling to unzip rather than custom
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • implementation
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      [USN-4107-1] GIFLIB vulnerabilities [08:35]
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • 3 CVEs addressed in Xenial, Bionic, Disco
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2019-15133
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2018-11490
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2016-3977
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • Common library used for handling GIF images (openjdk, ffmpeg, gstreamer, kde)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • Divide-by-zero
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • 2 different heap based buffer overflows - one was originally fixed in
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • Debian but the patch for it got dropped in a later release - so we have
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          repatched that
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          [USN-4108-1] Zstandard vulnerability [09:20]
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • 1 CVEs addressed in Bionic
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2019-11922
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • Common library (maintained by Facebook) for handling the zstd compression algorithm
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • Race condition when using single-pass compression, might allow attacker
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • to get OOB write IF the caller had provided a smaller output buffer than
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              the recommended size
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • So likely won’t affect all packages which use zstd (there are many) -
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • should always follow best practice
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              [USN-4109-1] OpenJPEG vulnerabilities [10:11]
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • 5 CVEs addressed in Bionic
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2018-6616
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2018-5785
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2018-18088
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2018-14423
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2017-17480
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • 4 different DoS issues:
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • 2 in BMP handling:
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CPU based DoS due to inefficient algorithm implementation
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • Integer overflow -> OOB read -> DoS
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • NULL pointer dereference when converting to PNM
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • Divide by zero
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • Stack based buffer overflow when handling JP3D encoded data - OOB write -
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • DoS / RCE
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Goings on in Ubuntu Security Community
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Joe and Alex discuss webmin backdoor [11:21]
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • http://www.webmin.com/exploit.html
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • Get in contact [21:45]
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • #ubuntu-security on the Libera.Chat IRC network
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • @ubuntu_sec on twitter
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • 23 min

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        About Ubuntu Security Podcast

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        From the publisher's feed

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        A fortnightly podcast talking about the latest developments and updates from the Ubuntu Security team, including a summary of recent security vulnerabilities and fixes as well as a discussion on some…