Ubuntu Security Podcast

Ubuntu Security Podcast

By Ubuntu Security TeamTechnology
Download on the App Store

Ubuntu Security Podcast episodes

  • Episode 13
    Overview

    This week we look at some details of the 16 unique CVEs addressed across the supported Ubuntu releases and more.

    This week in Ubuntu Security Updates

    16 unique CVEs addressed

    [USN-3816-2] systemd vulnerability
    • 3 CVEs addressed in Xenial, Bionic, Cosmic
      • CVE-2018-15687
      • CVE-2018-15686
      • CVE-2018-6954
      • Episode 12 - original fix for CVE-2018-6954 was incomplete - this includes the complete fix
      • Also includes an update to avoid a possible hang on shutdown in unattended-upgrades - LP #1803391
        • During shutdown, systemd is already in the process of shutting down
        • Then unattended-upgrades runs and it goes and tries to update systemd - which then tries to reexec it - which blocks waiting for it to finish shutting down
        • Creates a deadlock since systemd is waiting on unattended-upgrades to finish but u-u is waiting on systemd reexec
        • Fix is to not do reexec if systemd is already in the process of stopping
        • [USN-3825-1, USN-3825-2] mod_perl vulnerability
          • 1 CVEs addressed in Precise ESM, Trusty, Xenial, Bionic, Cosmic
            • CVE-2011-2767
            • Old CVE - reported to Debian in 2011, who assigned a CVE internally but didn’t go any further with it
            • Recently the original reporter of the vulnerability submitted a patch to Debian to fix it - so vuln was reported to Mitre
            • Now fixed in Ubuntu as well
            • [USN-3801-2] Firefox regressions
              • 12 CVEs addressed in Trusty, Xenial, Bionic, Cosmic
                • CVE-2018-12397
                • CVE-2018-12396
                • CVE-2018-12395
                • CVE-2018-12403
                • CVE-2018-12402
                • CVE-2018-12401
                • CVE-2018-12399
                • CVE-2018-12398
                • CVE-2018-12393
                • CVE-2018-12392
                • CVE-2018-12390
                • CVE-2018-12388
                • Firefox update (v63) (Episode 9) had some minor regressions
                  • These were present in the upstream firefox release itself
                  • This provides 63.0.3 which contains these fixes from upstream to address the regressions
                    • WebGL hangs, slow page loading if using specific proxy settings etc.
                    • Goings on in Ubuntu Security Community
                      Linux Cryptocoin Malware
                      • https://www.zdnet.com/article/new-linux-crypto-miner-steals-your-root-password-and-disables-your-antivirus/
                      • Apparently reports of users affected
                      • Requires SSH to login - bruteforce passwords
                        • Use strong passwords / public key auth
                        • Elevates privileges via two very old CVEs
                          • CVE-2016-5195 - Dirty Cow - fixed for Ubuntu in October 2016
                          • CVE-2013-2094 - perf root privilege escalation - fixed for Ubuntu in May 2013
                          • All Ubuntu users are fine unless you are running a old release AND have not been applying security patches
                          • Please use strong passwords if enabling openssh server
                          • Preview of next episode
                            Upcoming fixes
                            • qemu, webkitgtk
                            • Get in contact
                              • #ubuntu-security on the Libera.Chat IRC network
                              • @ubuntu_sec on twitter
                              • 9 min
                              • Episode 12
                                Overview

                                This week we look at some details of the 33 unique CVEs addressed across the

                                supported Ubuntu releases, including some significant updates for systemd and
                                the kernel, plus we talk about even more Intel side-channel vulnerabilities and
                                more.

                                This week in Ubuntu Security Updates

                                33 unique CVEs addressed

                                [USN-3814-1] libmspack vulnerabilities
                                • 2 CVEs addressed in Xenial, Bionic, Cosmic
                                  • CVE-2018-18585
                                  • CVE-2018-18584
                                  • Out of bounds write of 1 byte when a CAB file uses the maximum Quantum block size - buffer overflow, DoS -> crash, possible code execution
                                  • Failure to validate filenames properly - could accept a filename with embedded NUL bytes - possible DoS -> crash
                                  • [USN-3815-1, USN-3815-2] gettext vulnerability
                                    • 1 CVEs addressed in Precise ESM, Trusty, Xenial, Bionic, Cosmic
                                      • CVE-2018-18751
                                      • Double free for specially crafted translations file, DoS -> crash, possible code execution via heap corruption etc.
                                        • PoC’s on github
                                        • [USN-3816-1] systemd vulnerabilities
                                          • 3 CVEs addressed in Xenial, Bionic, Cosmic
                                            • CVE-2018-6954
                                            • CVE-2018-15687
                                            • CVE-2018-15686
                                            • Large backport of multiple patch series
                                            • Jann Horn (GPZ) reported two issues to Ubuntu regarding systemd
                                              • possible to inject / alter state across re-execution of systemd itself (since serialized state) - but fails to deserialize it correctly
                                                • Insecure use of fgets() when parsing long lines
                                                • Possible root privilege escalation
                                                • When changing ownership of files in a directory via systemd (useful for executing a systemd unit as a given user for example to ensure files it needs are owned by that user)
                                                  • Would try and handle symlinks specially BUT this is racy (since could change where pointed to during check of symlink and then actual work of chown() after)
                                                  • So for instance, could convince systemd to possible change the ownership of a root owned file to that of another user
                                                  • So could allow to change arbitrary files ownerships or even permissions
                                                  • Third issue - older one, systemd-tmpfiles could be used to obtain ownership of arbitrary files
                                                    • Would follow symlinks in non-terminal path components, and then operate on the resulting file
                                                    • Can tell it to set permissions / ownership of given files
                                                    • So could race it to replace path components with symlinks to root-owned files and get it to change their ownership to that of the user (or whomeever)
                                                    • Original patch series (March) didn’t completely fix this - required much more invasive patching later
                                                    • We waited to fix it until the complete fix was available and accepted upstream (August) to then start backporting
                                                    • [USN-3814-2, USN-3814-3] ClamAV vulnerabilities
                                                      • 2 CVEs addressed in Precise ESM & Trusty
                                                        • CVE-2018-18585
                                                        • CVE-2018-18584
                                                        • Same issues as for libmspack earlier (since clamav in Trusty and Precise ESM embeds libmspack, later releases use the system libmspack package instead)
                                                        • [USN-3811-2] SpamAssassin vulnerability
                                                          • 1 CVEs addressed in Precise ESM
                                                            • CVE-2017-15705
                                                            • One of the CVEs for SpamAssassin in Episode 7
                                                            • [USN-3817-1, USN-3817-2] Python vulnerabilities
                                                              • 5 CVEs addressed in Precise ESM, Trusty, Xenial, Bionic
                                                                • CVE-2018-14647
                                                                • CVE-2018-1061
                                                                • CVE-2018-1060
                                                                • CVE-2018-1000802
                                                                • CVE-2018-1000030
                                                                • Failure to initialize hash salt for PRNG in hash tables for elementtree (XML parser)
                                                                  • Could relatively easily cause hash-collisions on specially crafted document
                                                                  • High CPU and memory usage -> DoS
                                                                  • Possible command injection when using Python to create a ZIP file archive
                                                                    • Used spawn() which is vulnerable to shell command injection -> subprocess()
                                                                    • 3 lower priority issues
                                                                      • Race condition in when reading from multiple threads on same file - possible heap buffer overflow or UAF
                                                                      • DoS via CPU usage due to regexes in mail server response handling with backtracking - could be triggered by a malicious mail server
                                                                      • Similar but in regexes in difflib (catastrophic backtracking)
                                                                      • [USN-3818-1] PostgreSQL vulnerability
                                                                        • 1 CVEs addressed in Bionic, Cosmic
                                                                          • CVE-2018-16850
                                                                          • Possible to inject arbitrary SQL with superuser privileges during dump/restore cycle
                                                                          • Can be triggered by regular users in default config since they can trigger as have CREATE privilege on the public schema
                                                                          • [USN-3819-1] Linux kernel vulnerability
                                                                            • 1 CVEs addressed in Cosmic
                                                                              • CVE-2018-15471
                                                                              • [USN-3820-1, USN-3820-2, USN-3820-3] Linux kernel vulnerabilities
                                                                                • 4 CVEs addressed in Bionic, Xenial (Bionic HWE kernel) and Trusty (Azure)
                                                                                  • CVE-2018-9363
                                                                                  • CVE-2018-16658
                                                                                  • CVE-2017-13168
                                                                                  • CVE-2018-15471
                                                                                  • Bluetooth HID integer overflow and info leak in CDROM ioctl (covered in Episode 9 for Xenial kernel)
                                                                                  • Possible privilege escalation via SCSI subsystem
                                                                                  • Xen virtual network driver didn’t check supplied parameters -> integer overflow -> OOB read -> possible OOB write -> privilege escalation, DoS etc
                                                                                  • [USN-3821-1] Linux kernel vulnerabilities
                                                                                    • 7 CVEs addressed in Xenial and Trusty (Xenial HWE kernel)
                                                                                      • CVE-2018-18021
                                                                                      • CVE-2018-17972
                                                                                      • CVE-2018-14617
                                                                                      • CVE-2018-14609
                                                                                      • CVE-2018-13096
                                                                                      • CVE-2018-13053
                                                                                      • CVE-2018-10880
                                                                                      • Potential host system crash / code execution from malicious guest for KVM on ARM64
                                                                                      • Stack unwinding in procfs didn’t check caller was root - anyone could race stack unwinder to read stack of arbitrary kernel processes
                                                                                      • NULL pointer dereferences in various file-system drivers -> triggered by mounting malicious fs image
                                                                                        • HFS+, btrfs, f2fs
                                                                                        • OOB stack write in ext4 with malicious image
                                                                                        • Integer overflow in alarmtimer handling
                                                                                        • [USN-3822-1] Linux kernel vulnerabilities
                                                                                          • 5 CVEs addressed in Trusty and Precise ESM (Trusty HWE kernel)
                                                                                            • CVE-2018-9363
                                                                                            • CVE-2018-16658
                                                                                            • CVE-2017-16649
                                                                                            • CVE-2017-13168
                                                                                            • CVE-2016-9588
                                                                                            • Same bluetooth HID, CDROM and SCSI vulns as for Bionic earlier
                                                                                            • Possible divide by zero in CDC USB ethernet driver for specially crafted device
                                                                                            • KVM guest user could cause guest OS crash due to mismanagement of emulated exception handling
                                                                                            • [USN-3823-1] Linux kernel vulnerabilities
                                                                                              • 2 CVEs addressed in Precise ESM
                                                                                                • CVE-2018-3620
                                                                                                • CVE-2018-3646
                                                                                                • L1TF fixes for Precise ESM (see Episode 1 for more details)
                                                                                                • [LSN-0045-1] Linux kernel vulnerability
                                                                                                  • Live patch covering Bionic, Xenial and Trusty
                                                                                                    • CVE-2017-13168
                                                                                                    • CVE-2018-10880
                                                                                                    • CVE-2018-9363
                                                                                                    • CVE-2018-16658
                                                                                                    • Same bluetooth HID, CDROM, SCSI and ext4 vulnerabilities mentioned earlier
                                                                                                    • [USN-3824-1] OpenJDK 7 vulnerabilities
                                                                                                      • 5 CVEs addressed in Trusty
                                                                                                        • CVE-2018-3180
                                                                                                        • CVE-2018-3169
                                                                                                        • CVE-2018-3149
                                                                                                        • CVE-2018-3139
                                                                                                        • CVE-2018-3136
                                                                                                        • All covered in the previous openjdk-8 update in Episode 10 (that included
                                                                                                        • more as this is just those fixes which also apply to openjdk-7)
                                                                                                          Goings on in Ubuntu Security Community
                                                                                                          New Intel Side Channel Attacks (again…)
                                                                                                          • A Systematic Evaluation of Transient Execution Attacks and Defenses
                                                                                                          • Reclassifies existing Meltdown and Spectre attacks with a new nomenclature
                                                                                                            • ie. original Meltdown is now Meltdown-US (US = User/Supervisor)
                                                                                                            • Identifies a bunch of other possible variants for both Meltdown and Spectre
                                                                                                              • Meltdown-PK - bypass restrictions on Intel memory protection keys
                                                                                                              • Meltdown-BR - Spectre-like attack but using bounds-range exceeded exception to trigger
                                                                                                              • 5 new Spectre variants based on existing ones but targetting different
                                                                                                              • microarchitectural elements (ie targetting the Branch Target Buffer when
                                                                                                                doing a Spectre-RSB attack since some processors fallback to BTB when RSB
                                                                                                                is empty)
                                                                                                              • Compares existing mitigations for each existing and newly identified attack
                                                                                                              • Very comprehensive, demonstrates the utility of such a complete analysis compared to existing approach where different researchers have looked at a single aspect
                                                                                                              • Still an active area of research with new vulnerabilities turning up
                                                                                                              • Hiring
                                                                                                                Ubuntu Security Engineer
                                                                                                                • https://boards.greenhouse.io/canonical/jobs/1158266
                                                                                                                • Get in contact
                                                                                                                  • #ubuntu-security on the Libera.Chat IRC network
                                                                                                                  • @ubuntu_sec on twitter
                                                                                                                  • 21 min
                                                                                                                  • Episode 11
                                                                                                                    Overview

                                                                                                                    This week we look at some details of the 23 unique CVEs addressed across the supported Ubuntu releases, discuss the latest purported Intel side-channel vulnerability PortSmash and more.

                                                                                                                    This week in Ubuntu Security Updates

                                                                                                                    23 unique CVEs addressed

                                                                                                                    [USN-3806-1] systemd vulnerability
                                                                                                                    • 1 CVEs addressed in Xenial, Bionic, Cosmic
                                                                                                                      • CVE-2018-15688
                                                                                                                      • Reported by Felix Wilhelm from Google Security Team to Ubuntu in LP #1795921
                                                                                                                      • systemd contains DHCPv6 client written from scratch
                                                                                                                      • Heap buffer overflow in DHCPv6 option handling (say via server id of >=493 bytes)
                                                                                                                      • Coordinated with systemd upstream and Red Hat to resolve this
                                                                                                                      • [USN-3807-1] NetworkManager vulnerability
                                                                                                                        • 1 CVEs addressed in Xenial, Bionic, Cosmic
                                                                                                                          • CVE-2018-15688
                                                                                                                          • NetworkManager contains the same code taken from systemd-networkd so is also vulnerable
                                                                                                                          • [USN-3808-1] Ruby vulnerabilities
                                                                                                                            • 2 CVEs addressed in Trusty, Xenial, Bionic and Cosmic
                                                                                                                              • CVE-2018-16395
                                                                                                                              • CVE-2018-16396
                                                                                                                              • Misuses return value when comparing names in X509 certificates
                                                                                                                                • If returned 1 on comparing name would assume are identical but are in fact not
                                                                                                                                • Could allow to impersonate a certificate
                                                                                                                                • Taint flags not propagated when unpacking arrays into strings, or packing strings into arrays
                                                                                                                                  • Could allow untrusted data to be treated as trusted
                                                                                                                                  • [USN-3809-1] OpenSSH vulnerabilities
                                                                                                                                    • 2 CVEs addressed in Trusty, Xenial, Bionic
                                                                                                                                      • CVE-2018-15473
                                                                                                                                      • CVE-2016-10708
                                                                                                                                      • User enumeration due to fail to bail out early on invalid user authentication
                                                                                                                                        • Would take longer to process a packet with a valid username than an invalid one
                                                                                                                                        • Can determine account names as a result via brute-force timing attack
                                                                                                                                        • Possible to crash the per-connection process on NULL pointer dereference
                                                                                                                                          • Low priority since doesn’t crash the main daemon so not really a DoS
                                                                                                                                          • [USN-3786-2] libxkbcommon vulnerabilities
                                                                                                                                            • 11 CVEs addressed in Bionic
                                                                                                                                              • CVE-2018-15856
                                                                                                                                              • CVE-2018-15864
                                                                                                                                              • CVE-2018-15863
                                                                                                                                              • CVE-2018-15862
                                                                                                                                              • CVE-2018-15861
                                                                                                                                              • CVE-2018-15859
                                                                                                                                              • CVE-2018-15858
                                                                                                                                              • CVE-2018-15857
                                                                                                                                              • CVE-2018-15855
                                                                                                                                              • CVE-2018-15854
                                                                                                                                              • CVE-2018-15853
                                                                                                                                              • Episode 7 for Trusty and Xenial
                                                                                                                                              • Some common CVEs, some new ones specific to Bionic version
                                                                                                                                              • [USN-3810-1] ppp vulnerability
                                                                                                                                                • 1 CVEs addressed in Trusty, Xenial, Bionic
                                                                                                                                                  • CVE-2018-11574
                                                                                                                                                  • Ubuntu specific change to pppd to add support for EAP-TLS authentication
                                                                                                                                                    • Could be triggered on both peer or server side
                                                                                                                                                    • Lack of input validation coupled with an integer overflow lead to crash and possible authentication bypass
                                                                                                                                                    • Leads to memcpy() with a negative length value (and hence very large unsigned value)
                                                                                                                                                    • Theoretically possible to overwrite other data structures related to server state and therefore bypass authentication
                                                                                                                                                    • [USN-3811-1] SpamAssassin vulnerabilities
                                                                                                                                                      • 3 CVEs addressed in Trusty, Xenial, Bionic
                                                                                                                                                        • CVE-2018-11781
                                                                                                                                                        • CVE-2018-11780
                                                                                                                                                        • CVE-2017-15705
                                                                                                                                                        • Updated to latest stable version of spamassassin (3.4.2)
                                                                                                                                                          • So all supported Ubuntu releases now have 3.4.2
                                                                                                                                                          • Local user code injection via meta rule syntax
                                                                                                                                                          • RCE via PDFInfo plugin
                                                                                                                                                          • Failure to handle unclosed HTML tags in emails leading to DoS
                                                                                                                                                          • [USN-3812-1] nginx vulnerabilities
                                                                                                                                                            • 3 CVEs addressed in Trusty, Xenial, Bionic, Cosmic
                                                                                                                                                              • CVE-2018-16845
                                                                                                                                                              • CVE-2018-16844
                                                                                                                                                              • CVE-2018-16843
                                                                                                                                                              • DoS due to memory usage in HTTP/2 handling
                                                                                                                                                              • DoS due to excessive CPU usage in HTTP/2 handling
                                                                                                                                                              • When processing a specially crafted mp4 file, could lead to infinite loop
                                                                                                                                                                • This module is in the nginx-extras package
                                                                                                                                                                • [USN-3813-1] pyOpenSSL vulnerabilities
                                                                                                                                                                  • 2 CVEs addressed in Xenial
                                                                                                                                                                    • CVE-2018-1000808
                                                                                                                                                                    • CVE-2018-1000807
                                                                                                                                                                    • DoS via crash in handling of X509 certificates
                                                                                                                                                                    • UAF in handling of X509 certificates
                                                                                                                                                                    • Goings on in Ubuntu Security Community
                                                                                                                                                                      PortSmash - New Intel side-channel vulnerability or expected behaviour for SMT?
                                                                                                                                                                      • CVE-2018-5407 assigned to OpenSSL but described as a side-channel in Intel SMT / Hyper-Threading
                                                                                                                                                                        • https://www.openwall.com/lists/oss-security/2018/11/01/4
                                                                                                                                                                        • Affects OpenSSL <= 1.1.0h
                                                                                                                                                                        • Originally suggested as a possible side-channel in 2015
                                                                                                                                                                        • Due to sharing of execution engines in SMT
                                                                                                                                                                          • Two processes across shared hyper-threads, contend for execution units across same ports
                                                                                                                                                                          • Meaure port contention delay -> side channel to recover ECDSA private key of server running in other process
                                                                                                                                                                          • So crypto code needs not only to be constant-time, but also secret-independent execution-flow
                                                                                                                                                                            • ie. execute same instruction sequence regardless of secret
                                                                                                                                                                            • all code and data addresses are assumed public
                                                                                                                                                                            • Or disable HT / learn to schedule trust domains across different hyper-threads (gang-scheduling)
                                                                                                                                                                            • Hiring
                                                                                                                                                                              Ubuntu Security Engineer
                                                                                                                                                                              • https://boards.greenhouse.io/canonical/jobs/1158266
                                                                                                                                                                              • Preview of Next Episode
                                                                                                                                                                                Upcoming fixes
                                                                                                                                                                                • libmspack, systemd, gettext
                                                                                                                                                                                • Get in contact
                                                                                                                                                                                  • #ubuntu-security on the Libera.Chat IRC network
                                                                                                                                                                                  • @ubuntu_sec on twitter
                                                                                                                                                                                  • 14 min
                                                                                                                                                                                  • Episode 10
                                                                                                                                                                                    Overview

                                                                                                                                                                                    This week we look at some details of the 17 unique CVEs addressed across the supported Ubuntu releases, have a brief look at some Canonical presentations from LSS-EU and more.

                                                                                                                                                                                    This week in Ubuntu Security Updates

                                                                                                                                                                                    17 unique CVEs addressed

                                                                                                                                                                                    [USN-3799-2] MySQL vulnerabilities
                                                                                                                                                                                    • 3 CVEs addressed in Precise ESM
                                                                                                                                                                                      • CVE-2018-3282
                                                                                                                                                                                      • CVE-2018-3174
                                                                                                                                                                                      • CVE-2018-3133
                                                                                                                                                                                      • Ubuntu 12.04 Precise ESM update for 3 CVEs fixed in usual supported releases (covered in Episode 9)
                                                                                                                                                                                      • [USN-3803-1] Ghostscript vulnerabilities
                                                                                                                                                                                        • 3 CVEs addressed in Trusty, Xenial, Bionic, Cosmic
                                                                                                                                                                                          • CVE-2018-18284
                                                                                                                                                                                          • CVE-2018-18073
                                                                                                                                                                                          • CVE-2018-17961
                                                                                                                                                                                          • More ghostscript vulnerabilities! (others recent ones covered in Episodes 5 and 7)
                                                                                                                                                                                          • 2 brand new sandbox (-dSAFER) bypasses by Tavis Ormandy
                                                                                                                                                                                          • Third one is due to an incomplete fix for CVE-2018-17183
                                                                                                                                                                                          • [USN-3804-1] OpenJDK vulnerabilities
                                                                                                                                                                                            • 8 CVEs addressed in Xenial, Bionic, Cosmic
                                                                                                                                                                                              • CVE-2018-3214
                                                                                                                                                                                              • CVE-2018-3183
                                                                                                                                                                                              • CVE-2018-3180
                                                                                                                                                                                              • CVE-2018-3169
                                                                                                                                                                                              • CVE-2018-3150
                                                                                                                                                                                              • CVE-2018-3149
                                                                                                                                                                                              • CVE-2018-3139
                                                                                                                                                                                              • CVE-2018-3136
                                                                                                                                                                                              • New OpenJDK release covering multiple vulnerabilities including:
                                                                                                                                                                                                • Insufficient checking of signatures in manifest elements could allow untrusted Java application to escape sandbox
                                                                                                                                                                                                • Insufficient checking of all JAR attributes could allow untrusted Java application to escape sandbox
                                                                                                                                                                                                • Failure to clear HTTP header elements could result in exposure of sensitive info when follow redirect to another host
                                                                                                                                                                                                • Possible arbitrary code execution due to failure to enforce system security properties
                                                                                                                                                                                                • [USN-3805-1, USN-3805-2] curl vulnerabilities
                                                                                                                                                                                                  • 3 CVEs addressed in Trusty, Xenial, Bionic, Cosmic
                                                                                                                                                                                                    • CVE-2018-16842
                                                                                                                                                                                                    • CVE-2018-16840
                                                                                                                                                                                                    • CVE-2018-16839
                                                                                                                                                                                                    • 1 CVE addressed in Precise ESM
                                                                                                                                                                                                      • CVE-2018-16839
                                                                                                                                                                                                      • Buffer overflow in SASL authentication (very similar to CVE-2018-14618 from Episode 5)
                                                                                                                                                                                                      • UAF when closing handle (DoS / crash)
                                                                                                                                                                                                      • Out-of-bounds read when using curl to print show error messages via command-line
                                                                                                                                                                                                        • This is fixed for Precise ESM too
                                                                                                                                                                                                        • Goings on in Ubuntu Security Community
                                                                                                                                                                                                          Linux Security Summit Europe (LSS-EU)
                                                                                                                                                                                                          • 2 presentations by Canonical engineers
                                                                                                                                                                                                          • https://events.linuxfoundation.org/events/linux-security-summit-europe-2018/
                                                                                                                                                                                                          • Overview and Recent Developments: Namespaces and Capabilities
                                                                                                                                                                                                            • Christian Brauner (Kernel engineer focussing on lxd at Canonical)
                                                                                                                                                                                                            • Namespaces and Capabilities are building blocks for containers
                                                                                                                                                                                                            • Summarises recent enhancements to various namespaces etc
                                                                                                                                                                                                            • Future highlights: seccomp trap to userspace, LSM stacking, CAP_SYS_ADMIN split?
                                                                                                                                                                                                            • Slides: https://events.linuxfoundation.org/wp-content/uploads/2017/12/2018-LSS-Europe-Edinburgh-Namespaces-and-Capabilities_Christian-Brauner.pdf
                                                                                                                                                                                                            • Video: https://www.youtube.com/watch?v=-PZNF8XDNn8&list=PLbzoR-pLrL6oa4x78bHssxmGAw_ns1Tm2&index=8
                                                                                                                                                                                                            • Overview and Recent Developments: AppArmor
                                                                                                                                                                                                              • John Johansen (Ubuntu Security team, AppArmor (kernel) maintainer)
                                                                                                                                                                                                              • Summarises some of the history, use of and the latest developments in AppArmor
                                                                                                                                                                                                              • Future highlights: Allow user / apps to load policy, delegation, pam_apparmor
                                                                                                                                                                                                              • Slides: https://events.linuxfoundation.org/wp-content/uploads/2017/12/lss-eu-apparmor-overview-2018.pdf
                                                                                                                                                                                                              • Video: https://www.youtube.com/watch?v=3MkU_Z-fClE&list=PLbzoR-pLrL6oa4x78bHssxmGAw_ns1Tm2&index=15
                                                                                                                                                                                                              • Blog posts
                                                                                                                                                                                                                A guide to snap permissions and interfaces
                                                                                                                                                                                                                • https://blog.ubuntu.com/2018/11/01/a-guide-to-snap-permissions-and-interfaces
                                                                                                                                                                                                                • Hiring
                                                                                                                                                                                                                  Ubuntu Security Engineer
                                                                                                                                                                                                                  • https://boards.greenhouse.io/canonical/jobs/1158266
                                                                                                                                                                                                                  • Get in contact
                                                                                                                                                                                                                    • #ubuntu-security on the Libera.Chat IRC network
                                                                                                                                                                                                                    • @ubuntu_sec on twitter
                                                                                                                                                                                                                    • 10 min
                                                                                                                                                                                                                    • Episode 9
                                                                                                                                                                                                                      Overview

                                                                                                                                                                                                                      This week we look at some details of the 61 unique CVEs addressed across the supported Ubuntu releases, with a particular focus on the recent Xorg vulnerability (CVE-2018-14665), plus Cosmic is now officially supported by the Security Team.

                                                                                                                                                                                                                      This week in Ubuntu Security Updates

                                                                                                                                                                                                                      61 unique CVEs addressed

                                                                                                                                                                                                                      [USN-3790-2] Requests vulnerability
                                                                                                                                                                                                                      • 1 CVEs addressed in Cosmic
                                                                                                                                                                                                                        • CVE-2018-18074
                                                                                                                                                                                                                        • Cosmic is now officially released and so is officially supported by the Security Team
                                                                                                                                                                                                                        • This is the same vulnerability which we covered in Episode 8 for Trusty, Xenial, Bionic now fixed for Cosmic
                                                                                                                                                                                                                        • [USN-3795-2] libssh vulnerability
                                                                                                                                                                                                                          • 1 CVEs addressed in Cosmic
                                                                                                                                                                                                                            • CVE-2018-10933
                                                                                                                                                                                                                            • This is the same vulnerability which we covered in Episode 8 for Trusty, Xenial, Bionic now fixed for Cosmic
                                                                                                                                                                                                                            • [USN-3792-3] Net-SNMP vulnerability
                                                                                                                                                                                                                              • 1 CVEs addressed in Cosmic
                                                                                                                                                                                                                                • CVE-2018-18065
                                                                                                                                                                                                                                • This is the same vulnerability which we covered in Episode 8 for Trusty, Xenial & Bionic now fixed for Cosmic
                                                                                                                                                                                                                                • [USN-3796-3] Paramiko vulnerability
                                                                                                                                                                                                                                  • 1 CVEs addressed in Cosmic
                                                                                                                                                                                                                                    • CVE-2018-1000805
                                                                                                                                                                                                                                    • This is the same vulnerability which we covered in Episode 8 for Trusty, Xenial & Bionic now fixed for Cosmic
                                                                                                                                                                                                                                    • [USN-3788-2] Tex Live-bin vulnerability
                                                                                                                                                                                                                                      • 1 CVEs addressed in Cosmic
                                                                                                                                                                                                                                        • CVE-2018-17407
                                                                                                                                                                                                                                        • This is the same vulnerability which we covered in Episode 7 for Trusty, Xenial & Bionic now fixed for Cosmic
                                                                                                                                                                                                                                        • [USN-3797-1, USN-3797-2] Linux kernel vulnerabilities
                                                                                                                                                                                                                                          • 4 CVEs addressed in Xenial and Trusty for the Xenial HWE kernel for Trusty
                                                                                                                                                                                                                                            • CVE-2018-10938
                                                                                                                                                                                                                                            • CVE-2018-9363
                                                                                                                                                                                                                                            • CVE-2018-16658
                                                                                                                                                                                                                                            • CVE-2018-14734
                                                                                                                                                                                                                                            • Includes:
                                                                                                                                                                                                                                              • UAF in Infiniband -> DoS via crash
                                                                                                                                                                                                                                              • Integer overflow in CDROM -> info disclosure of kernel memory
                                                                                                                                                                                                                                              • Integer overflow in bluetooth HID -> buffer overflow -> DoS / possible arbitrary code execution
                                                                                                                                                                                                                                              • Remotely triggerable infinite loop in labelled network handler (CIPSO)
                                                                                                                                                                                                                                                • CIPSO used by SELinux / SMACK not AppArmor so unlikely Ubuntu users affected
                                                                                                                                                                                                                                                • [USN-3798-1] Linux kernel vulnerabilities
                                                                                                                                                                                                                                                  • 8 CVEs addressed in Trusty and Precise ESM (for the Trusty HWE kernel for Precise ESM)
                                                                                                                                                                                                                                                    • CVE-2018-9518
                                                                                                                                                                                                                                                    • CVE-2018-7566
                                                                                                                                                                                                                                                    • CVE-2018-1000004
                                                                                                                                                                                                                                                    • CVE-2017-18216
                                                                                                                                                                                                                                                    • CVE-2017-15299
                                                                                                                                                                                                                                                    • CVE-2017-0794
                                                                                                                                                                                                                                                    • CVE-2016-7913
                                                                                                                                                                                                                                                    • CVE-2015-8539
                                                                                                                                                                                                                                                    • Includes:
                                                                                                                                                                                                                                                      • Local DoS / code exec via insertion of an already existing key into kernel keyring
                                                                                                                                                                                                                                                      • UAF in XCeive driver, local DoS / code exec (crash)
                                                                                                                                                                                                                                                      • Race condition in generic SCSI -> Local DoS (crash) / code exec
                                                                                                                                                                                                                                                      • NULL ptr dereference in ocfs2 -> Local DoS (crash)
                                                                                                                                                                                                                                                      • Race condition in ALSA handling of ioctls -> Local DoS via deadlock
                                                                                                                                                                                                                                                      • Race condition in ALSA -> UAF / out of bounds read -> Local DoS (crash) / code exec
                                                                                                                                                                                                                                                      • Buffer overflow in NFC LLCP impl -> remote DoS / code exec
                                                                                                                                                                                                                                                      • [USN-3777-3] Linux kernel (Azure) vulnerabilities
                                                                                                                                                                                                                                                        • 8 CVEs addressed in Xenial, Bionic
                                                                                                                                                                                                                                                          • CVE-2018-6555
                                                                                                                                                                                                                                                          • CVE-2018-6554
                                                                                                                                                                                                                                                          • CVE-2018-3639
                                                                                                                                                                                                                                                          • CVE-2018-14633
                                                                                                                                                                                                                                                          • CVE-2017-5715
                                                                                                                                                                                                                                                          • CVE-2018-15572
                                                                                                                                                                                                                                                          • CVE-2018-15594
                                                                                                                                                                                                                                                          • CVE-2018-17182
                                                                                                                                                                                                                                                          • Corresponding fixes for Azure Cloud specific kernel as covered in Episode 7
                                                                                                                                                                                                                                                          • for standard Bionic kernel
                                                                                                                                                                                                                                                            [USN-3799-1] MySQL vulnerabilities
                                                                                                                                                                                                                                                            • 21 CVEs addressed in Trusty, Xenial, Bionic, Cosmic
                                                                                                                                                                                                                                                              • CVE-2018-3284
                                                                                                                                                                                                                                                              • CVE-2018-3283
                                                                                                                                                                                                                                                              • CVE-2018-3282
                                                                                                                                                                                                                                                              • CVE-2018-3278
                                                                                                                                                                                                                                                              • CVE-2018-3277
                                                                                                                                                                                                                                                              • CVE-2018-3276
                                                                                                                                                                                                                                                              • CVE-2018-3251
                                                                                                                                                                                                                                                              • CVE-2018-3247
                                                                                                                                                                                                                                                              • CVE-2018-3200
                                                                                                                                                                                                                                                              • CVE-2018-3187
                                                                                                                                                                                                                                                              • CVE-2018-3185
                                                                                                                                                                                                                                                              • CVE-2018-3174
                                                                                                                                                                                                                                                              • CVE-2018-3173
                                                                                                                                                                                                                                                              • CVE-2018-3171
                                                                                                                                                                                                                                                              • CVE-2018-3162
                                                                                                                                                                                                                                                              • CVE-2018-3161
                                                                                                                                                                                                                                                              • CVE-2018-3156
                                                                                                                                                                                                                                                              • CVE-2018-3155
                                                                                                                                                                                                                                                              • CVE-2018-3144
                                                                                                                                                                                                                                                              • CVE-2018-3143
                                                                                                                                                                                                                                                              • CVE-2018-3133
                                                                                                                                                                                                                                                              • New upstream versions of MySQL for all supported releases to fix multiple
                                                                                                                                                                                                                                                              • vulnerabilities, add features and possible incompatible changes
                                                                                                                                                                                                                                                              • Trusty: 5.5.62
                                                                                                                                                                                                                                                              • Xenial, Bionic & Cosmic: 5.7.24
                                                                                                                                                                                                                                                              • [USN-3800-1] audiofile vulnerabilities
                                                                                                                                                                                                                                                                • 2 CVEs addressed in Trusty
                                                                                                                                                                                                                                                                  • CVE-2018-17095
                                                                                                                                                                                                                                                                  • CVE-2018-13440
                                                                                                                                                                                                                                                                  • DoS (crash) and possible code execution via specially crafted audio files
                                                                                                                                                                                                                                                                  • [USN-3801-1] Firefox vulnerabilities
                                                                                                                                                                                                                                                                    • 12 CVEs addressed in Trusty, Xenial, Bionic, Cosmic
                                                                                                                                                                                                                                                                      • CVE-2018-12397
                                                                                                                                                                                                                                                                      • CVE-2018-12396
                                                                                                                                                                                                                                                                      • CVE-2018-12395
                                                                                                                                                                                                                                                                      • CVE-2018-12403
                                                                                                                                                                                                                                                                      • CVE-2018-12402
                                                                                                                                                                                                                                                                      • CVE-2018-12401
                                                                                                                                                                                                                                                                      • CVE-2018-12399
                                                                                                                                                                                                                                                                      • CVE-2018-12398
                                                                                                                                                                                                                                                                      • CVE-2018-12393
                                                                                                                                                                                                                                                                      • CVE-2018-12392
                                                                                                                                                                                                                                                                      • CVE-2018-12390
                                                                                                                                                                                                                                                                      • CVE-2018-12388
                                                                                                                                                                                                                                                                      • Firefox 63
                                                                                                                                                                                                                                                                      • Includes fixes for a range of issues, most severe is possible RCE
                                                                                                                                                                                                                                                                      • Also fixes for WebExtensions in Firefox - to exploit need to install a
                                                                                                                                                                                                                                                                      • malicious extension - then could privilege escalation or local code execution
                                                                                                                                                                                                                                                                        [USN-3802-1] X.Org X server vulnerability
                                                                                                                                                                                                                                                                        • 1 CVEs addressed in Xenial, Bionic, Cosmic
                                                                                                                                                                                                                                                                          • CVE-2018-14665
                                                                                                                                                                                                                                                                          • Incorrect permissions check for 2 command-line arguments (-modulepath and -logfile)
                                                                                                                                                                                                                                                                          • On some platforms (not Ubuntu) Xorg itself is setuid
                                                                                                                                                                                                                                                                          • Can then use these command-line options to overwrite arbitrary files etc -> privilege escalation to root via say overwrite of /etc/shadow
                                                                                                                                                                                                                                                                          • Generated a lot of press - BUT missed the distinction that Xorg is not really setuid on Ubuntu
                                                                                                                                                                                                                                                                          • We use Xorg.wrap as setuid to first run and drop permissions if using KMS driver
                                                                                                                                                                                                                                                                            • This is the case for the vast majority of drivers, and for almost all free drivers
                                                                                                                                                                                                                                                                            • So most Ubuntu users unaffected by this vulnerability
                                                                                                                                                                                                                                                                            • Special Friday release :)
                                                                                                                                                                                                                                                                            • Goings on in Ubuntu Security Community
                                                                                                                                                                                                                                                                              Hiring
                                                                                                                                                                                                                                                                              Ubuntu Security Engineer
                                                                                                                                                                                                                                                                              • https://boards.greenhouse.io/canonical/jobs/1158266
                                                                                                                                                                                                                                                                              • Get in contact
                                                                                                                                                                                                                                                                                • #ubuntu-security on the Libera.Chat IRC network
                                                                                                                                                                                                                                                                                • @ubuntu_sec on twitter
                                                                                                                                                                                                                                                                                • 12 min
                                                                                                                                                                                                                                                                                • Episode 8
                                                                                                                                                                                                                                                                                  Overview

                                                                                                                                                                                                                                                                                  This week we look at some details of the 15 unique CVEs addressed across the supported Ubuntu releases and discuss some of the security relevant changes in Ubuntu 18.10, plus a refresh of the Ubuntu CVE tracker and more.

                                                                                                                                                                                                                                                                                  This week in Ubuntu Security Updates

                                                                                                                                                                                                                                                                                  15 unique CVEs addressed

                                                                                                                                                                                                                                                                                  [USN-3790-1] Requests vulnerability
                                                                                                                                                                                                                                                                                  • 1 CVEs addressed in Trusty, Xenial, Bionic
                                                                                                                                                                                                                                                                                    • CVE-2018-18074
                                                                                                                                                                                                                                                                                    • Requests library could end up sending credentials in clear text if server is configured with a https -> http redirect
                                                                                                                                                                                                                                                                                    • [USN-3792-1, USN-3792-2] Net-SNMP vulnerability
                                                                                                                                                                                                                                                                                      • 1 CVEs addressed in Trusty, Xenial, Bionic & Precise ESM
                                                                                                                                                                                                                                                                                        • CVE-2018-18065
                                                                                                                                                                                                                                                                                        • Remote DoS via a NULL pointer dereference from an authenticated attacker
                                                                                                                                                                                                                                                                                        • [USN-3793-1] Thunderbird vulnerabilities
                                                                                                                                                                                                                                                                                          • 5 CVEs addressed in Trusty, Xenial, Bionic
                                                                                                                                                                                                                                                                                            • CVE-2018-12385
                                                                                                                                                                                                                                                                                            • CVE-2018-12383
                                                                                                                                                                                                                                                                                            • CVE-2018-12378
                                                                                                                                                                                                                                                                                            • CVE-2018-12377
                                                                                                                                                                                                                                                                                            • CVE-2018-12376
                                                                                                                                                                                                                                                                                            • New Thunderbird version (60) containing 5 fixes
                                                                                                                                                                                                                                                                                            • Interestingly all of these were also vulnerabilities in Firefox - in
                                                                                                                                                                                                                                                                                            • particular CVE-2018-12383 was discussed in Episode 4 for Firefox
                                                                                                                                                                                                                                                                                              [USN-3794-1] MoinMoin vulnerability
                                                                                                                                                                                                                                                                                              • 1 CVEs addressed in Trusty, Xenial, Bionic
                                                                                                                                                                                                                                                                                                • CVE-2017-5934
                                                                                                                                                                                                                                                                                                • XSS in link editor dialog allow injection of arbitrary web content (HTML, scripts etc)
                                                                                                                                                                                                                                                                                                • [USN-3789-2] ClamAV vulnerabilities
                                                                                                                                                                                                                                                                                                  • 5 CVEs addressed in Precise ESM
                                                                                                                                                                                                                                                                                                    • CVE-2018-15378
                                                                                                                                                                                                                                                                                                    • CVE-2018-14682
                                                                                                                                                                                                                                                                                                    • CVE-2018-14681
                                                                                                                                                                                                                                                                                                    • CVE-2018-14680
                                                                                                                                                                                                                                                                                                    • CVE-2018-14679
                                                                                                                                                                                                                                                                                                    • Corresponding fix for Precise ESM from ClamAV which we discussed in Episode 7
                                                                                                                                                                                                                                                                                                    • Also rolls in fixes for 4 other vulnerabilities in the embedded mspack library
                                                                                                                                                                                                                                                                                                      • In trusty and precise we used the embedded libmspack, newer releases use
                                                                                                                                                                                                                                                                                                      • the system package so weren’t affected
                                                                                                                                                                                                                                                                                                        [USN-3795-1] libssh vulnerability
                                                                                                                                                                                                                                                                                                        • 1 CVEs addressed in Trusty, Xenial, Bionic
                                                                                                                                                                                                                                                                                                          • CVE-2018-10933
                                                                                                                                                                                                                                                                                                          • Embedded SSH server and client implementation
                                                                                                                                                                                                                                                                                                          • Allows bypass of authentication by remote attackers if they send a SSH2_MSG_USERAUTH_SUCCESS message instead of the SSH2_MSG_USERAUTH_REQUEST message to initiate the authentication process
                                                                                                                                                                                                                                                                                                          • This message is meant to be sent from the server to the client but in this case are sending it to the server
                                                                                                                                                                                                                                                                                                          • State machine on server-side then jumps straight to ‘Authenticated’
                                                                                                                                                                                                                                                                                                          • Only affects applications which use libssh as a server
                                                                                                                                                                                                                                                                                                          • [USN-3796-1, USN-3796-2] Paramiko vulnerability
                                                                                                                                                                                                                                                                                                            • 1 CVEs addressed in Trusty, Xenial, Bionic & Precise ESM
                                                                                                                                                                                                                                                                                                              • CVE-2018-1000805
                                                                                                                                                                                                                                                                                                              • Python SSH library for both servers and clients
                                                                                                                                                                                                                                                                                                              • Very similar to CVE-2018-10933 for libssh - remote authentication bypass by presenting SSH2_MSG_USERAUTH_SUCCESS in place of SSH2_MSG_USERAUTH_REQUEST
                                                                                                                                                                                                                                                                                                              • Due to code-reuse between client and server implementations
                                                                                                                                                                                                                                                                                                              • On server side, runs the normal client side code to be used when receiving this authentication success from the server, and flips the ‘authenticated’ flag - which is shared by both the server and client code
                                                                                                                                                                                                                                                                                                              • Goings on in Ubuntu Security Community
                                                                                                                                                                                                                                                                                                                Ubuntu 18.10 Cosmic Cuttlefish Released
                                                                                                                                                                                                                                                                                                                • Includes OpenSSL 1.1.1 for TLS 1.3 support
                                                                                                                                                                                                                                                                                                                • Support for using fingerprint readers to unlock screen etc
                                                                                                                                                                                                                                                                                                                  • Ubuntu Security Team consider fingerprints to be akin to usernames only - so we don’t enable fingerprint authentication by default - need to opt-in
                                                                                                                                                                                                                                                                                                                  • libfprint and fprintd promoted to main to allow this
                                                                                                                                                                                                                                                                                                                  • Ubuntu CVE Tracker facelift
                                                                                                                                                                                                                                                                                                                    • Refreshed look and feel via bootstrap
                                                                                                                                                                                                                                                                                                                    • https://ubuntu.com/security/
                                                                                                                                                                                                                                                                                                                    • Hiring
                                                                                                                                                                                                                                                                                                                      Ubuntu Security Engineer
                                                                                                                                                                                                                                                                                                                      • https://boards.greenhouse.io/canonical/jobs/1158266
                                                                                                                                                                                                                                                                                                                      • Get in contact
                                                                                                                                                                                                                                                                                                                        • #ubuntu-security on the Libera.Chat IRC network
                                                                                                                                                                                                                                                                                                                        • @ubuntu_sec on twitter
                                                                                                                                                                                                                                                                                                                        • 10 min
                                                                                                                                                                                                                                                                                                                        • Episode 7
                                                                                                                                                                                                                                                                                                                          Overview

                                                                                                                                                                                                                                                                                                                          This week we look at some details of the 78 unique CVEs addressed across the supported Ubuntu releases including more GhostScript, ImageMagick, WebKitGTK, Linux kernel and more.

                                                                                                                                                                                                                                                                                                                          This week in Ubuntu Security Updates

                                                                                                                                                                                                                                                                                                                          78 unique CVEs addressed

                                                                                                                                                                                                                                                                                                                          [USN-3773-1] Ghostscript vulnerabilities
                                                                                                                                                                                                                                                                                                                          • 2 CVEs addressed in Trusty, Xenial, Bionic
                                                                                                                                                                                                                                                                                                                            • CVE-2018-17183
                                                                                                                                                                                                                                                                                                                            • CVE-2018-16510
                                                                                                                                                                                                                                                                                                                            • Similar to [USN-3768-1] from Episode 5
                                                                                                                                                                                                                                                                                                                            • [USN-3769-2] Bind vulnerability
                                                                                                                                                                                                                                                                                                                              • 1 CVEs addressed in Precise ESM
                                                                                                                                                                                                                                                                                                                                • CVE-2018-5740
                                                                                                                                                                                                                                                                                                                                • Extended Security Maintenance version of [USN-3769-1]
                                                                                                                                                                                                                                                                                                                                • [USN-3774-1] strongSwan vulnerability
                                                                                                                                                                                                                                                                                                                                  • 1 CVEs addressed in Trusty, Xenial, Bionic
                                                                                                                                                                                                                                                                                                                                    • CVE-2018-17540
                                                                                                                                                                                                                                                                                                                                    • [USN-3771-1] incorporated fixes for multiple CVEs - but these fixes themselves introduced this new vulnerability
                                                                                                                                                                                                                                                                                                                                    • Heap buffer overflow found by Google’s OSS-Fuzz leading to DoS for gmp plugin
                                                                                                                                                                                                                                                                                                                                    • [USN-3775-1, USN-3775-2, USN-3776-1, USN-3776-2, USN-3777-1, USN-3777-2] Linux kernel vulnerabilities
                                                                                                                                                                                                                                                                                                                                      • 11 CVEs addressed across Precise ESM, Trusty, Xenial and Bionic including HWE kernels
                                                                                                                                                                                                                                                                                                                                        • CVE-2018-6555
                                                                                                                                                                                                                                                                                                                                        • CVE-2018-6554
                                                                                                                                                                                                                                                                                                                                        • CVE-2018-14633
                                                                                                                                                                                                                                                                                                                                        • CVE-2018-14634
                                                                                                                                                                                                                                                                                                                                        • CVE-2018-15572
                                                                                                                                                                                                                                                                                                                                        • CVE-2018-15594
                                                                                                                                                                                                                                                                                                                                        • CVE-2018-16276
                                                                                                                                                                                                                                                                                                                                        • CVE-2018-10902
                                                                                                                                                                                                                                                                                                                                        • CVE-2018-10853
                                                                                                                                                                                                                                                                                                                                        • CVE-2017-18216
                                                                                                                                                                                                                                                                                                                                        • CVE-2018-17182
                                                                                                                                                                                                                                                                                                                                        • Not all CVEs affect all releases
                                                                                                                                                                                                                                                                                                                                        • Includes:
                                                                                                                                                                                                                                                                                                                                          • UAF and memory leak -> DoS in IRDA
                                                                                                                                                                                                                                                                                                                                          • Stack buffer overwrite in iSCSI - low chance of privilege escalation
                                                                                                                                                                                                                                                                                                                                          • Integer overflow leading to possible privilege escalation but only on machines with >32GB RAM
                                                                                                                                                                                                                                                                                                                                          • Insufficiencies discovered in various Spectre variant mitigations previously deployed
                                                                                                                                                                                                                                                                                                                                          • Incorrect bounds checking in yurex USB driver from userspace -> crash / privilege escalation for local user
                                                                                                                                                                                                                                                                                                                                          • Race condition in midi driver - double free -> privilege escalation
                                                                                                                                                                                                                                                                                                                                          • KVM hypervisor instruction emulation fail to check privileges - privilege escalation inside guest
                                                                                                                                                                                                                                                                                                                                          • OCFS2 file-system driver NULL pointer dereference -> BUG (mutex logic bug)
                                                                                                                                                                                                                                                                                                                                          • Memory management sequence number overflow leading to UAF -> possible privilege escalation - Jann Horn (GPZ)
                                                                                                                                                                                                                                                                                                                                          • [USN-3780-1] HAProxy vulnerability
                                                                                                                                                                                                                                                                                                                                            • 1 CVEs addressed in Bionic
                                                                                                                                                                                                                                                                                                                                              • CVE-2018-14645
                                                                                                                                                                                                                                                                                                                                              • Out of bounds read leading to remote crash -> DoS
                                                                                                                                                                                                                                                                                                                                              • [USN-3781-1] WebKitGTK+ vulnerabilities
                                                                                                                                                                                                                                                                                                                                                • 24 CVEs addressed in Bionic
                                                                                                                                                                                                                                                                                                                                                  • CVE-2018-4361
                                                                                                                                                                                                                                                                                                                                                  • CVE-2018-4359
                                                                                                                                                                                                                                                                                                                                                  • CVE-2018-4358
                                                                                                                                                                                                                                                                                                                                                  • CVE-2018-4328
                                                                                                                                                                                                                                                                                                                                                  • CVE-2018-4323
                                                                                                                                                                                                                                                                                                                                                  • CVE-2018-4319
                                                                                                                                                                                                                                                                                                                                                  • CVE-2018-4318
                                                                                                                                                                                                                                                                                                                                                  • CVE-2018-4317
                                                                                                                                                                                                                                                                                                                                                  • CVE-2018-4316
                                                                                                                                                                                                                                                                                                                                                  • CVE-2018-4315
                                                                                                                                                                                                                                                                                                                                                  • CVE-2018-4314
                                                                                                                                                                                                                                                                                                                                                  • CVE-2018-4312
                                                                                                                                                                                                                                                                                                                                                  • CVE-2018-4311
                                                                                                                                                                                                                                                                                                                                                  • CVE-2018-4309
                                                                                                                                                                                                                                                                                                                                                  • CVE-2018-4306
                                                                                                                                                                                                                                                                                                                                                  • CVE-2018-4299
                                                                                                                                                                                                                                                                                                                                                  • CVE-2018-4213
                                                                                                                                                                                                                                                                                                                                                  • CVE-2018-4212
                                                                                                                                                                                                                                                                                                                                                  • CVE-2018-4210
                                                                                                                                                                                                                                                                                                                                                  • CVE-2018-4209
                                                                                                                                                                                                                                                                                                                                                  • CVE-2018-4208
                                                                                                                                                                                                                                                                                                                                                  • CVE-2018-4207
                                                                                                                                                                                                                                                                                                                                                  • CVE-2018-4197
                                                                                                                                                                                                                                                                                                                                                  • CVE-2018-4191
                                                                                                                                                                                                                                                                                                                                                  • Used by many GNOME applications to render web content (Epiphany, Evolution, Boxes, GThumb, Buidler, Empathy, etc)
                                                                                                                                                                                                                                                                                                                                                  • Many issues fixed in this release including, XSS, DoS, RCE etc
                                                                                                                                                                                                                                                                                                                                                  • [USN-3782-1] Liblouis vulnerabilities
                                                                                                                                                                                                                                                                                                                                                    • 2 CVEs addressed in Trusty, Xenial, Bionic
                                                                                                                                                                                                                                                                                                                                                      • CVE-2018-17294
                                                                                                                                                                                                                                                                                                                                                      • CVE-2018-12085
                                                                                                                                                                                                                                                                                                                                                      • [USN-3778-1] Firefox vulnerabilities
                                                                                                                                                                                                                                                                                                                                                        • 3 CVEs addressed in Trusty, Xenial, Bionic
                                                                                                                                                                                                                                                                                                                                                          • CVE-2018-12387
                                                                                                                                                                                                                                                                                                                                                          • CVE-2018-12386
                                                                                                                                                                                                                                                                                                                                                          • CVE-2018-12385
                                                                                                                                                                                                                                                                                                                                                          • Firefox 62 release - includes fixes for RCE, local cache poisoning and information disclosures
                                                                                                                                                                                                                                                                                                                                                          • [USN-3783-1] Apache HTTP Server vulnerabilities
                                                                                                                                                                                                                                                                                                                                                            • 3 CVEs addressed in Bionic
                                                                                                                                                                                                                                                                                                                                                              • CVE-2018-11763
                                                                                                                                                                                                                                                                                                                                                              • CVE-2018-1333
                                                                                                                                                                                                                                                                                                                                                              • CVE-2018-1302
                                                                                                                                                                                                                                                                                                                                                              • DoS (crash) via incorrect stream destruction and DoS (resources) from incorrect frame handling
                                                                                                                                                                                                                                                                                                                                                              • [USN-3785-1] ImageMagick vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                • 14 CVEs addressed in Trusty, Xenial, Bionic
                                                                                                                                                                                                                                                                                                                                                                  • CVE-2017-13144
                                                                                                                                                                                                                                                                                                                                                                  • CVE-2018-16749
                                                                                                                                                                                                                                                                                                                                                                  • CVE-2018-16645
                                                                                                                                                                                                                                                                                                                                                                  • CVE-2018-16644
                                                                                                                                                                                                                                                                                                                                                                  • CVE-2018-16643
                                                                                                                                                                                                                                                                                                                                                                  • CVE-2018-16642
                                                                                                                                                                                                                                                                                                                                                                  • CVE-2018-16323
                                                                                                                                                                                                                                                                                                                                                                  • CVE-2018-14551
                                                                                                                                                                                                                                                                                                                                                                  • CVE-2018-16750
                                                                                                                                                                                                                                                                                                                                                                  • CVE-2018-16640
                                                                                                                                                                                                                                                                                                                                                                  • CVE-2018-14437
                                                                                                                                                                                                                                                                                                                                                                  • CVE-2018-14436
                                                                                                                                                                                                                                                                                                                                                                  • CVE-2018-14435
                                                                                                                                                                                                                                                                                                                                                                  • CVE-2018-14434
                                                                                                                                                                                                                                                                                                                                                                  • Disables support for using PS and PDF from Ghostscript in ImageMagick due to
                                                                                                                                                                                                                                                                                                                                                                  • large number of GS vulns (see Episode 5)
                                                                                                                                                                                                                                                                                                                                                                  • Also multiple fixes for ImageMagick itself, including memory leaks (DoS), information disclosure, RCE etc
                                                                                                                                                                                                                                                                                                                                                                  • [USN-3784-1] AppArmor update
                                                                                                                                                                                                                                                                                                                                                                    • Hardening of various AppArmor profiles (mentioned in Episode 5)
                                                                                                                                                                                                                                                                                                                                                                    • [LSN-0044-1] Linux kernel vulnerability
                                                                                                                                                                                                                                                                                                                                                                      • Livepatch incorporating L1TF, Spectrev2 and other fixes as well
                                                                                                                                                                                                                                                                                                                                                                      • [USN-3786-1] libxkbcommon vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                        • 11 CVEs addressed in Trusty, Xenial
                                                                                                                                                                                                                                                                                                                                                                          • CVE-2018-15864
                                                                                                                                                                                                                                                                                                                                                                          • CVE-2018-15863
                                                                                                                                                                                                                                                                                                                                                                          • CVE-2018-15862
                                                                                                                                                                                                                                                                                                                                                                          • CVE-2018-15861
                                                                                                                                                                                                                                                                                                                                                                          • CVE-2018-15859
                                                                                                                                                                                                                                                                                                                                                                          • CVE-2018-15858
                                                                                                                                                                                                                                                                                                                                                                          • CVE-2018-15857
                                                                                                                                                                                                                                                                                                                                                                          • CVE-2018-15856
                                                                                                                                                                                                                                                                                                                                                                          • CVE-2018-15855
                                                                                                                                                                                                                                                                                                                                                                          • CVE-2018-15854
                                                                                                                                                                                                                                                                                                                                                                          • CVE-2018-15853
                                                                                                                                                                                                                                                                                                                                                                          • Loads keyboard descriptions from disk - multiple vulnerabilities in file
                                                                                                                                                                                                                                                                                                                                                                          • format handling leading to DoS etc
                                                                                                                                                                                                                                                                                                                                                                            [USN-3787-1] Tomcat vulnerability
                                                                                                                                                                                                                                                                                                                                                                            • 1 CVEs addressed in Trusty, Xenial
                                                                                                                                                                                                                                                                                                                                                                              • CVE-2018-11784
                                                                                                                                                                                                                                                                                                                                                                              • Redirect handling allowed attacker to redirect to any URI of their choice
                                                                                                                                                                                                                                                                                                                                                                              • Can be avoided if had manually enabled both mapperDirectoryRedirectEnabled and mapperContextRootRedirectEnabled
                                                                                                                                                                                                                                                                                                                                                                              • [USN-3789-1] ClamAV vulnerability
                                                                                                                                                                                                                                                                                                                                                                                • 1 CVEs addressed in Trusty, Xenial, Bionic
                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2018-15378
                                                                                                                                                                                                                                                                                                                                                                                  • Crash in handling of unpacked MEW executable files
                                                                                                                                                                                                                                                                                                                                                                                  • [USN-3788-1] Tex Live vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                    • 2 CVEs addressed in Trusty, Xenial, Bionic
                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2018-17407
                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2015-5700
                                                                                                                                                                                                                                                                                                                                                                                      • File overwrite via insecure symlink handling
                                                                                                                                                                                                                                                                                                                                                                                      • Code execution via buffer overflow in Type1 font handler
                                                                                                                                                                                                                                                                                                                                                                                      • [USN-3791-1] Git vulnerability
                                                                                                                                                                                                                                                                                                                                                                                        • 1 CVEs addressed in Trusty, Xenial, Bionic
                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2018-17456
                                                                                                                                                                                                                                                                                                                                                                                          • RCE when cloning a malicious repository - due to insufficient validation of git submodule URLs and paths.
                                                                                                                                                                                                                                                                                                                                                                                          • Goings on in Ubuntu Security Community
                                                                                                                                                                                                                                                                                                                                                                                            Hiring
                                                                                                                                                                                                                                                                                                                                                                                            Ubuntu Security Engineer
                                                                                                                                                                                                                                                                                                                                                                                            • https://boards.greenhouse.io/canonical/jobs/1158266
                                                                                                                                                                                                                                                                                                                                                                                            • Get in contact
                                                                                                                                                                                                                                                                                                                                                                                              • #ubuntu-security on the Libera.Chat IRC network
                                                                                                                                                                                                                                                                                                                                                                                              • @ubuntu_sec on twitter
                                                                                                                                                                                                                                                                                                                                                                                              • 12 min
                                                                                                                                                                                                                                                                                                                                                                                              • Episode 6
                                                                                                                                                                                                                                                                                                                                                                                                Overview

                                                                                                                                                                                                                                                                                                                                                                                                This week we look at some details of the 17 unique CVEs addressed across the supported Ubuntu releases and more.

                                                                                                                                                                                                                                                                                                                                                                                                This week in Ubuntu Security Updates

                                                                                                                                                                                                                                                                                                                                                                                                17 unique CVEs addressed

                                                                                                                                                                                                                                                                                                                                                                                                [USN-3771-1] strongSwan vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                • 4 CVEs addressed in Trusty, Xenial, Bionic
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2018-5388
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2018-16152
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2018-16151
                                                                                                                                                                                                                                                                                                                                                                                                  • CVE-2018-10811
                                                                                                                                                                                                                                                                                                                                                                                                  • 2 CVEs: flaws in RSA implementation allow Bleichenbacher-style attacks in parsing of the ASN.1 encoded digestInfo
                                                                                                                                                                                                                                                                                                                                                                                                  • strongSwan implementation was too lenient and would allow arbitrary random data to be contained following various elements in the ASN.1
                                                                                                                                                                                                                                                                                                                                                                                                  • Also would not check the correct amount of padding had been used
                                                                                                                                                                                                                                                                                                                                                                                                  • Allows attackers to potentially forge low-exponent signature forgery and hence authentication during IKE authentication
                                                                                                                                                                                                                                                                                                                                                                                                  • 2 CVEs for DoS due to missing length check and missing variable initialization
                                                                                                                                                                                                                                                                                                                                                                                                  • [USN-3772-1] UDisks vulnerability
                                                                                                                                                                                                                                                                                                                                                                                                    • 1 CVEs addressed in Bionic
                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2018-17336
                                                                                                                                                                                                                                                                                                                                                                                                      • Format string vulnerability which could be exploited via specially crafted disk label
                                                                                                                                                                                                                                                                                                                                                                                                      • udisks prints volume label via printf() passing the label as part of the format string
                                                                                                                                                                                                                                                                                                                                                                                                        • Simple fix to replace the label with a %s directive and then pass the label to that
                                                                                                                                                                                                                                                                                                                                                                                                        • ie. don’t interpret label as printf() directives directly
                                                                                                                                                                                                                                                                                                                                                                                                        • [USN-3719-3] Mutt vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                          • 12 CVEs addressed in Xenial
                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2018-14349
                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2018-14362
                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2018-14351
                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2018-14356
                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2018-14355
                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2018-14357
                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2018-14353
                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2018-14358
                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2018-14359
                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2018-14354
                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2018-14352
                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2018-14350
                                                                                                                                                                                                                                                                                                                                                                                                            • Goings on in Ubuntu Security Community
                                                                                                                                                                                                                                                                                                                                                                                                              LSM Stacking upstreaming
                                                                                                                                                                                                                                                                                                                                                                                                              • Casey Schaufler (Intel, SMACK maintainer) primary developer along with John Johansen and Kees Cook (Google) to upstream support for LSM stacking
                                                                                                                                                                                                                                                                                                                                                                                                              • Currently upstream allows use of one ‘major’ module (SELinux / AppArmor / Tomoyo) with a minor module (Yama etc)
                                                                                                                                                                                                                                                                                                                                                                                                              • Goal of stacking is to allow multiple major modules to be used in conjunction (AppArmor with SELinux)
                                                                                                                                                                                                                                                                                                                                                                                                                • Primary use-case is containers
                                                                                                                                                                                                                                                                                                                                                                                                                • Current stacking patches allow to stack Tomoyo with either SELinux / AppArmor
                                                                                                                                                                                                                                                                                                                                                                                                                  • Eventually should be able to stack SELinux with AppArmor but still WIP
                                                                                                                                                                                                                                                                                                                                                                                                                  • Ubuntu already carries these patches in Bionic etc
                                                                                                                                                                                                                                                                                                                                                                                                                  • Likely to be merged in the near future
                                                                                                                                                                                                                                                                                                                                                                                                                  • Evince AppArmor hardening LP #1788929
                                                                                                                                                                                                                                                                                                                                                                                                                    • Jann Horn (GPZ) reported gaps in evince AppArmor profile
                                                                                                                                                                                                                                                                                                                                                                                                                    • Clever use of GNOME thumbnailer infrastructure to specify a new ’evil’ thumbnailer and the use of systemd via DBus to escape AppArmor confinement
                                                                                                                                                                                                                                                                                                                                                                                                                    • Policy fixed in Cosmic, in process of updating for Bionic etc
                                                                                                                                                                                                                                                                                                                                                                                                                    • New Ubuntu Security Manager
                                                                                                                                                                                                                                                                                                                                                                                                                      • Joe McManus
                                                                                                                                                                                                                                                                                                                                                                                                                      • Hiring
                                                                                                                                                                                                                                                                                                                                                                                                                        Ubuntu Security Engineer
                                                                                                                                                                                                                                                                                                                                                                                                                        • https://boards.greenhouse.io/canonical/jobs/1158266
                                                                                                                                                                                                                                                                                                                                                                                                                        • Get in contact
                                                                                                                                                                                                                                                                                                                                                                                                                          • #ubuntu-security on the Libera.Chat IRC network
                                                                                                                                                                                                                                                                                                                                                                                                                          • @ubuntu_sec on twitter
                                                                                                                                                                                                                                                                                                                                                                                                                          • 12 min
                                                                                                                                                                                                                                                                                                                                                                                                                          • Episode 5
                                                                                                                                                                                                                                                                                                                                                                                                                            Overview

                                                                                                                                                                                                                                                                                                                                                                                                                            This week we look at some details of the 43 unique CVEs addressed across the

                                                                                                                                                                                                                                                                                                                                                                                                                            supported Ubuntu releases and talk about the recently announced Extended
                                                                                                                                                                                                                                                                                                                                                                                                                            Security Maintenance support for Ubuntu 14.04 Trusty Tahr.

                                                                                                                                                                                                                                                                                                                                                                                                                            This week in Ubuntu Security Updates

                                                                                                                                                                                                                                                                                                                                                                                                                            43 unique CVEs addressed across the various supported releases of Ubuntu

                                                                                                                                                                                                                                                                                                                                                                                                                            (Bionic, Xenial, Trusty and Precise ESM)

                                                                                                                                                                                                                                                                                                                                                                                                                            [USN-3762-1, USN-3762-2] Linux kernel vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                            • 2 CVEs addressed in Bionic and corresponding HWE kernel for Xenial
                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2017-13695
                                                                                                                                                                                                                                                                                                                                                                                                                              • CVE-2018-1118
                                                                                                                                                                                                                                                                                                                                                                                                                              • Both information disclosure vulnerabilities which could allow exposure of kernel addresses
                                                                                                                                                                                                                                                                                                                                                                                                                                • Not directly an issue but could be used to defeat ASLR when combined with another vulnerability
                                                                                                                                                                                                                                                                                                                                                                                                                                • [USN-3763-1] Linux kernel vulnerability
                                                                                                                                                                                                                                                                                                                                                                                                                                  • 1 CVEs addressed in Precise ESM
                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2018-5390
                                                                                                                                                                                                                                                                                                                                                                                                                                    • SegmentSmack (see episode 0)
                                                                                                                                                                                                                                                                                                                                                                                                                                    • [LSN-0043-1] Linux kernel vulnerability
                                                                                                                                                                                                                                                                                                                                                                                                                                      • Livepatch to fix multiple vulnerabilities fixed in previous kernel package updates
                                                                                                                                                                                                                                                                                                                                                                                                                                      • [USN-3764-1] Zsh vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                                        • 3 CVEs addressed in Trusty, Xenial, Bionic
                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2018-1100
                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2018-13259
                                                                                                                                                                                                                                                                                                                                                                                                                                          • CVE-2018-0502
                                                                                                                                                                                                                                                                                                                                                                                                                                          • 2 issues in shebang / hashbang handling
                                                                                                                                                                                                                                                                                                                                                                                                                                            • shebang lines longer than 64 bytes truncated - could execute wrong interpreter
                                                                                                                                                                                                                                                                                                                                                                                                                                            • mishandling of some particular formatted shebang lines which could execute
                                                                                                                                                                                                                                                                                                                                                                                                                                            • interpreter from second line of file
                                                                                                                                                                                                                                                                                                                                                                                                                                            • Stack based buffer-overflow allowing code execution in the context of a different user
                                                                                                                                                                                                                                                                                                                                                                                                                                            • [USN-3747-2] OpenJDK 10 regression
                                                                                                                                                                                                                                                                                                                                                                                                                                              • 4 CVEs addressed in Bionic
                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2018-2972
                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2018-2952
                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2018-2826
                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2018-2825
                                                                                                                                                                                                                                                                                                                                                                                                                                                • [USN-3761-2, USN-3761-3] Firefox regressions
                                                                                                                                                                                                                                                                                                                                                                                                                                                  • 5 CVEs addressed in Trusty, Xenial, Bionic
                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2018-12383
                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2018-12378
                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2018-12377
                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2018-12376
                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2018-12375
                                                                                                                                                                                                                                                                                                                                                                                                                                                    • Previous update to latest firefox resulted in issues due to language packs
                                                                                                                                                                                                                                                                                                                                                                                                                                                    • missing (and hence missing spellcheck dictionaries) and use of wrong search
                                                                                                                                                                                                                                                                                                                                                                                                                                                      provider
                                                                                                                                                                                                                                                                                                                                                                                                                                                      [USN-3765-1, USN-3765-2] curl vulnerability
                                                                                                                                                                                                                                                                                                                                                                                                                                                      • 1 CVEs addressed in Trusty, Xenial, Bionic and Precise ESM
                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2018-14618
                                                                                                                                                                                                                                                                                                                                                                                                                                                        • Similar to previous CVE-2017-8816 - integer overflow in calculations during
                                                                                                                                                                                                                                                                                                                                                                                                                                                        • NTLM authentication could allow heap buffer overflow and hence RCE
                                                                                                                                                                                                                                                                                                                                                                                                                                                        • Uses the password length in this calculation (which is supplied by the attacker) so relatively easy to trigger
                                                                                                                                                                                                                                                                                                                                                                                                                                                        • [USN-3722-5] ClamAV regression
                                                                                                                                                                                                                                                                                                                                                                                                                                                          • 2 CVEs addressed in Trusty, Xenial, Bionic
                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2018-0361
                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2018-0360
                                                                                                                                                                                                                                                                                                                                                                                                                                                            • [USN-3766-1, USN-3766-2] PHP vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                                                              • 3 CVEs addressed in Trusty, Xenial, Bionic and Precise ESM
                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2018-14883
                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2018-14851
                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2015-9253
                                                                                                                                                                                                                                                                                                                                                                                                                                                                • Integer overflows in JPEG and EXIF handlers leading to out-of-bounds reads and hence crash - DoS
                                                                                                                                                                                                                                                                                                                                                                                                                                                                • php-fpm (FastCGI process manager) - alternative FastCGI implementation for
                                                                                                                                                                                                                                                                                                                                                                                                                                                                • PHP - could cause DoS since didn’t restart child processes correctly - then
                                                                                                                                                                                                                                                                                                                                                                                                                                                                  consume CPU and disk space (via logging) - only fixed in Bionic for now
                                                                                                                                                                                                                                                                                                                                                                                                                                                                  [USN-3722-6] ClamAV vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • 2 CVEs addressed in Precise ESM
                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2018-0361
                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2018-0360
                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • [USN-3767-1, USN-3767-2] GLib vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • 2 CVEs addressed in Trusty, Xenial, Bionic and Precise ESM
                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2018-16429
                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2018-16428
                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • Issues with markup parsing
                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • [USN-3768-1] Ghostscript vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • 16 CVEs addressed in Trusty, Xenial, Bionic
                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2018-16802
                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2018-16585
                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2018-16543
                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2018-16542
                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2018-16541
                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2018-16540
                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2018-16539
                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2018-16513
                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2018-16511
                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2018-16510
                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2018-16509
                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2018-15911
                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2018-15910
                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2018-15909
                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2018-15908
                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2018-11645
                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • Ghostscript is used to process Postscript (and other formats) - PS is Turing
                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • Complete so in general is unsafe
                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • Hence Ghostscript includes a sandbox (-dSAFER) to try and prevent issues with
                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • handling of untrusted files
                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • Tavis Ormandy previously found a number of issues in the SAFER sandbox which
                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • allowed escape from it and execution of commands (ie. CVE-2016-7977 etc.)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • Recently discovered more - including ability to execute arbitrary code.
                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • [USN-3769-1] Bind vulnerability
                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • 1 CVEs addressed in Trusty, Xenial, Bionic
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2018-5740
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • Trigger assertion failure from specific input from remote server to cause crash and hence DoS
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • In deny-answer-aliases feature which is not enabled by default so not so high impact
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • [USN-3770-1, USN-3770-2] Little CMS vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • 2 CVEs addressed in Trusty, Xenial, Bionic and Precise ESM
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2018-16435
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • CVE-2016-10165
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • 1 CVEs addressed in Precise ESM only
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CVE-2013-4276
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • Multiple issues in handling of ICC colour profiles (integer overflow leading
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • to stack and heap buffer overflows on reads an writes)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • Little CMS often used in webapps which do image processing - in this case
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • allows remote DoS or possibly remote code execution
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Goings on in Ubuntu Security Community
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Ubuntu 14.04 ESM Announced
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • Extended Security Maintenance for Trusty 14.04 past the official EOL
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • Security updates for the kernel and the most widely used packages in main
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • https://blog.ubuntu.com/2018/09/19/extended-security-maintenance-ubuntu-14-04-trusty-tahr
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • Hiring
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Ubuntu Security Manager
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • https://boards.greenhouse.io/canonical/jobs/1278287
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • Ubuntu Security Engineer
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • https://boards.greenhouse.io/canonical/jobs/1158266
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • Get in contact
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • #ubuntu-security on the Libera.Chat IRC network
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • @ubuntu_sec on twitter
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • 16 min
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • Episode 4
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Overview

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  A quieter week in package updates - this week we look at some details of the 9

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  unique CVEs addressed across the supported Ubuntu releases and talk about
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  various hardening guides for Ubuntu.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  This week in Ubuntu Security Updates

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  9 unique CVEs addressed

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  [USN-3759-1] libtirpc vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • 3 CVEs addressed in Trusty, Xenial, Bionic
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2017-8779
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2018-14622
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2016-4429
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • Transport Independent RPC Library, used by NFS
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • 1 medium priority issue:
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • Crash from NULL pointer dereference when run out of file descriptions (failure to check return value) - a remote attacker could cause crash by flooding with new connections
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • 2 low priority issues:
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • “rpcbomb” - allows an unauthenticated attacker to DoS via memory exhaustion
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • Stack based buffer overflow could cause a crash when flooded by ICMP and UDP packets in the sunrpc implementation - fixed by replacing stack based memory allocation with heap-based allocation instead
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • Common pattern to fix this type of issue - similar work in Linux kernel recently by KSPP to replace VLAs
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • [USN-3759-2] libtirpc vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • 3 CVEs addressed in Precise ESM
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2017-8779
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2018-14622
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • CVE-2016-4429
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • Same as above for the Precise Extended Security Maintenence release
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • [USN-3760-1] transfig vulnerability
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • 1 CVEs addressed in Trusty, Xenial
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • CVE-2018-16140
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • transfig / fig2dev - utilities for converting XFig files
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • Fixes an error which allows memory corruption when handling specially crafted files
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • [USN-3761-1] Firefox vulnerabilities
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • 5 CVEs addressed in Trusty, Xenial, Bionic
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2018-12383
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2018-12378
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2018-12377
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2018-12376
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • CVE-2018-12375
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • Latest firefox release (62) fixing a number of issues including DoS and RCE
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • One interesting one is CVE-2018-12383 - in Firefox 58 the password storage
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    • format was changed (was sqlite, then was changed to json). When user sets a
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      master password, this is used to encrypt all stored passwords. However, this
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      was only done for the copy stored with the new format - the old copy would
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      still be stored unencrypted since it never had a master password set on
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      it. This is now fixed to simply delete the old copy of the password DB.
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Goings on in Ubuntu Security Community
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Discussions around hardening guides for Ubuntu
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      • A number of ‘best practices’ guides exist for hardening Ubuntu installations from reputable organisations
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • NCSC
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • CIS Benchmarks
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • many others
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        • In general these have similar recommendations:
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • Use UEFI Secure Boot
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • Disable unnecesary services
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • Use a known and fixed networking configuration (disable DHCP / use VPN etc)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • Enable Mandatory Access Control frameworks (ie. AppArmor)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • Use a specific password policy
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • Enable auditing
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • Differ in level of detail and technical knowledge needed to deploy
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • Typically aimed at computer and network administrators (not end-users)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          • Ubuntu already includes a number of these recommendations out of the box:
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • https://wiki.ubuntu.com/Security/Features
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • Ubuntu strives to strike a balance between security and usability out-of-the-box
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            • Hiring
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Ubuntu Security Manager
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • https://boards.greenhouse.io/canonical/jobs/1278287
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              • Ubuntu Security Engineer
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • https://boards.greenhouse.io/canonical/jobs/1158266
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • Get in contact
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • #ubuntu-security on the Libera.Chat IRC network
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • @ubuntu_sec on twitter
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  • 11 min

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  About Ubuntu Security Podcast

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  From the publisher's feed

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  A fortnightly podcast talking about the latest developments and updates from the Ubuntu Security team, including a summary of recent security vulnerabilities and fixes as well as a discussion on some…