Ubuntu Security Podcast

Ubuntu Security Podcast

By Ubuntu Security TeamTechnology
Download on the App Store

Ubuntu Security Podcast episodes

  • Episode 3
    Overview

    This week we look at 29 unique CVEs addressed across the supported Ubuntu releases, a discussion of the Main Inclusion Review process and recent news around the bubblewrap package, and open positions within the team.

    This week in Ubuntu Security Updates

    29 unique CVEs addressed

    [USN-3756-1] Intel Microcode vulnerabilities
    • 3 CVEs addressed in Trusty, Xenial, Bionic
      • CVE-2018-3640
      • CVE-2018-3639
      • CVE-2018-3646
      • Intel microcode updates to address L1TF, Spectre Variant 4 and Rogue System Register Read (RSRE)
      • Intel initially released this with a brand new license which included terms around disallowing benchmarking and possibly preventing redistribution via the Ubuntu mirrors
        • As a result, we couldn’t provide updated microcode packages to full address L1TF etc
        • Intel have now reverted back to the license used on previous microcode packages and so this can now finally be released
        • https://perens.com/2018/08/22/new-intel-microcode-license-restriction-is-not-acceptable/
        • [USN-3755-1] GD vulnerabilities
          • 2 CVEs addressed in Trusty, Xenial, Bionic
            • CVE-2018-5711
            • CVE-2018-1000222
            • Popular image manipulation and creating library used by PHP and therefore in many PHP web applications
            • Issue in handling of signed integers in GIF decoder allows an attacker to enter an infinite loop and cause DoS via a specially crafted GIF file
            • Double free in JPEG decoder could allow a user to possibly execute arbitrary code via specially crafted JPEG file
            • [USN-3757-1] poppler vulnerability
              • 1 CVEs addressed in Trusty, Xenial, Bionic
                • CVE-2018-13988
                • Fixed a crash (hence DoS) due to out-of-bounds read in PDF decoding
                • [USN-3758-1] libx11 vulnerabilities
                  • 5 CVEs addressed in Trusty, Xenial, Bionic
                    • CVE-2018-14600
                    • CVE-2018-14599
                    • CVE-2018-14598
                    • CVE-2016-7943
                    • CVE-2016-7942
                    • Bundles some fixes for some low priority old CVEs with some new medium priority CVE fixes
                    • Updates are usually done in this manner, where low priority fixes wait to get fixed along with higher priority fixes for a package
                    • Fixes issues around handling of data from untrusted servers and image decoding
                      • Usual failure to validate inputs, off-by-one, integer signedness confusion and incorrect freeing of dynamically allocated memory style issues
                      • [USN-3758-2] libx11 vulnerabilities
                        • 5 CVEs addressed in Precise ESM
                          • CVE-2018-14600
                          • CVE-2018-14599
                          • CVE-2018-14598
                          • CVE-2016-7943
                          • CVE-2016-7942
                          • [USN-3752-3] Linux kernel (Azure, GCP, OEM) vulnerabilities
                            • 18 CVEs addressed in Xenial, Bionic
                              • CVE-2018-1000204
                              • CVE-2018-9415
                              • CVE-2018-5814
                              • CVE-2018-13406
                              • CVE-2018-13405
                              • CVE-2018-13094
                              • CVE-2018-12904
                              • CVE-2018-12233
                              • CVE-2018-12232
                              • CVE-2018-11506
                              • CVE-2018-11412
                              • CVE-2018-1120
                              • CVE-2018-1108
                              • CVE-2018-1093
                              • CVE-2018-10881
                              • CVE-2018-10840
                              • CVE-2018-10323
                              • CVE-2018-1000200
                              • Kernel updates for various hardware platforms etc corresponding to the same updates from last week
                              • Goings on in Ubuntu Security Community
                                MIR Process and bubblewrap
                                • Security team is responsible for doing security audits of packages which are proposed to be included in the main section of the Ubuntu package repository
                                  • Packages in main are officially maintained, supported and recommended so deserve a high level of scrutiny before promotion into main
                                  • Security team historically only provides security updates to packages in main as well
                                  • So we have to be confident we can maintain and support a given package
                                  • To perform the security review we look at a number of things:
                                    • The code is evaluated to determine how easy or not it would be to maintain
                                    • The package itself is evaluated to look for potential issues
                                    • Code is then evaluated to look for potential existing security vulnerabilities
                                    • This can be a time consuming process, especially to do well
                                    • Recently this was in the news, when Hanno Böck (infosec journalist and
                                    • researcher) and Tavis Ormandy (GPZ) raised the issue of lack of bubblewrap
                                      support for gnome desktop thumbnailers
                                      • bubblewrap provides support for sandboxing processes via namespaces and the
                                      • use of it to sandbox desktop thumbnailers was introduced in the GNOME 3.26
                                        release
                                      • It was planned to be supported for Ubuntu 18.04, but to do this the package
                                      • had to be moved from universe into main, hence a MIR
                                      • Due to shifting priorities, the security team was not able to get this done
                                      • in time and hence the feature had to be disabled
                                      • This MIR is being proritised now so this security hardening feature should be available in an upcoming release
                                      • Security team is also looking at how to strengthen the hardening via AppArmor MAC profiles in addition
                                      • Thanks to Hanno and Tavis for giving this greater visibility
                                      • https://wiki.ubuntu.com/MainInclusionProcess
                                      • https://www.bleepingcomputer.com/news/security/ubuntu-is-undoing-a-gnome-security-feature/
                                      • Hiring
                                        Ubuntu Security Manager
                                        • https://boards.greenhouse.io/canonical/jobs/1278287
                                        • Ubuntu Security Engineer
                                          • https://boards.greenhouse.io/canonical/jobs/1158266
                                          • Get in contact
                                            • #ubuntu-security on the Libera.Chat IRC network
                                            • @ubuntu_sec on twitter
                                            • 11 min
                                            • Episode 2
                                              Overview

                                              83 unique CVEs addressed across the supported Ubuntu releases.

                                              This week in Ubuntu Security Updates
                                              [USN-3742-3] Linux kernel (Trusty HWE) regressions
                                              • Security team issues USNs for package updates caused by regressions in previous security updates
                                              • Fix for regressions caused by the original kernel update for L1TF
                                              • Could cause Java applications to fail to start and possible kernel panics on
                                              • boot for some hardware configurations
                                                [USN-3745-1] wpa_supplicant and hostapd vulnerability
                                                • 1 CVEs addressed in Bionic
                                                  • CVE-2018-14526
                                                  • Researchers analysed WPA2 4-way handshake via symbolic execution to find weaknesses
                                                    • Found a number of issues including a decryption oracle
                                                    • In this case, the would decrypt but not authenticate frame and then could allow recovery of the group key via a timing side-channel
                                                    • In theory, allows an unauthenticated attacker to recover WPA2 group key via frame manipulation when used with TKIP
                                                      • NOTE: is not advised to use TKIP in practice anyway (should use WPA2/CCMP) and so should have limited applicability
                                                      • In practice, due to large number of attempts needed to recover the full key, this is impractical (especially given that the group key is changed periodically)
                                                      • https://w1.fi/security/2018-1/unauthenticated-eapol-key-decryption.txt
                                                      • https://papers.mathyvanhoef.com/woot2018.pdf
                                                      • [USN-3746-1] APT vulnerability
                                                        • 1 CVEs addressed in Bionic
                                                          • CVE-2018-0501
                                                          • Dubbed “mirror fail” by the author and even a website - https://mirror.fail/
                                                          • mirror protocol in apt allows to specify a list of mirrors to try rather than just a single mirror in source.list
                                                            • not enabled by default
                                                            • in APT 1.6 this was reworked and a bug introduced
                                                              • on fallback from one mirror to the next, the previous mirrors InRelease file would be used without checking the one from the new mirror
                                                              • hence failing to authenticate the one from the new mirror
                                                              • could potentially allow installation of untrusted packages BUT would need at least two mirrors to be compromised AND for the user to have setup use of multiple mirrors in the first place
                                                              • [USN-3748-1] base-files vulnerability
                                                                • 1 CVEs addressed in Bionic
                                                                  • CVE-2018-6557
                                                                  • Vulnerability in the motd update script via insecure use of temporary files
                                                                    • Could allow DoS or privelege escalation if user has turned off kernel symlink restrictions
                                                                    • [USN-3751-1] Spice vulnerability
                                                                      • 1 CVEs addressed in Trusty, Xenial, Bionic
                                                                        • CVE-2018-10873
                                                                        • Insufficient bounds checks could allow to crash a server OR client from an authenticated peer
                                                                        • Requires authentication
                                                                        • [USN-3747-1] OpenJDK 10 vulnerabilities
                                                                          • 4 CVEs addressed in Bionic
                                                                            • CVE-2018-2972
                                                                            • CVE-2018-2952
                                                                            • CVE-2018-2826
                                                                            • CVE-2018-2825
                                                                            • Regular Java update to fix multiple vulnerabilities
                                                                            • [USN-3749-1] Spidermonkey vulnerabilities
                                                                              • 1 CVEs addressed in Bionic
                                                                                • CVE-2018-5188
                                                                                • Regular Spidermonkey update to fix vulnerabilities
                                                                                • [USN-3750-1] Pango vulnerability
                                                                                  • 1 CVEs addressed in Bionic
                                                                                    • CVE-2018-15120
                                                                                    • Kernel packages updated
                                                                                      [USN-3752-1] Linux kernel vulnerabilities
                                                                                      • 18 CVEs addressed in Bionic
                                                                                        • CVE-2018-1000204
                                                                                        • CVE-2018-9415
                                                                                        • CVE-2018-5814
                                                                                        • CVE-2018-13406
                                                                                        • CVE-2018-13405
                                                                                        • CVE-2018-13094
                                                                                        • CVE-2018-12904
                                                                                        • CVE-2018-12233
                                                                                        • CVE-2018-12232
                                                                                        • CVE-2018-11506
                                                                                        • CVE-2018-11412
                                                                                        • CVE-2018-1120
                                                                                        • CVE-2018-1108
                                                                                        • CVE-2018-1093
                                                                                        • CVE-2018-10881
                                                                                        • CVE-2018-10840
                                                                                        • CVE-2018-10323
                                                                                        • CVE-2018-1000200
                                                                                        • [USN-3752-2] Linux kernel (HWE) vulnerabilities
                                                                                          • 18 CVEs addressed in Xenial
                                                                                            • CVE-2018-1000204
                                                                                            • CVE-2018-9415
                                                                                            • CVE-2018-5814
                                                                                            • CVE-2018-13406
                                                                                            • CVE-2018-13405
                                                                                            • CVE-2018-13094
                                                                                            • CVE-2018-12904
                                                                                            • CVE-2018-12233
                                                                                            • CVE-2018-12232
                                                                                            • CVE-2018-11506
                                                                                            • CVE-2018-11412
                                                                                            • CVE-2018-1120
                                                                                            • CVE-2018-1108
                                                                                            • CVE-2018-1093
                                                                                            • CVE-2018-10881
                                                                                            • CVE-2018-10840
                                                                                            • CVE-2018-10323
                                                                                            • CVE-2018-1000200
                                                                                            • [USN-3753-1] Linux kernel vulnerabilities
                                                                                              • 11 CVEs addressed in Xenial
                                                                                                • CVE-2018-13406
                                                                                                • CVE-2018-13405
                                                                                                • CVE-2018-13094
                                                                                                • CVE-2018-12233
                                                                                                • CVE-2018-10881
                                                                                                • CVE-2018-10882
                                                                                                • CVE-2018-10878
                                                                                                • CVE-2018-10877
                                                                                                • CVE-2018-10879
                                                                                                • CVE-2018-10876
                                                                                                • CVE-2017-13168
                                                                                                • [USN-3753-2] Linux kernel (Xenial HWE) vulnerabilities
                                                                                                  • 11 CVEs addressed in Trusty
                                                                                                    • CVE-2018-13406
                                                                                                    • CVE-2018-13405
                                                                                                    • CVE-2018-13094
                                                                                                    • CVE-2018-12233
                                                                                                    • CVE-2018-10881
                                                                                                    • CVE-2018-10882
                                                                                                    • CVE-2018-10878
                                                                                                    • CVE-2018-10877
                                                                                                    • CVE-2018-10879
                                                                                                    • CVE-2018-10876
                                                                                                    • CVE-2017-13168
                                                                                                    • [USN-3754-1] Linux kernel vulnerabilities
                                                                                                      • 53 CVEs addressed in Trusty
                                                                                                        • CVE-2018-10021
                                                                                                        • CVE-2018-1000204
                                                                                                        • CVE-2017-2671
                                                                                                        • CVE-2018-13406
                                                                                                        • CVE-2018-13405
                                                                                                        • CVE-2018-13094
                                                                                                        • CVE-2018-12233
                                                                                                        • CVE-2018-10940
                                                                                                        • CVE-2018-1093
                                                                                                        • CVE-2018-1092
                                                                                                        • CVE-2018-10881
                                                                                                        • CVE-2018-10877
                                                                                                        • CVE-2018-10675
                                                                                                        • CVE-2018-10323
                                                                                                        • CVE-2018-10124
                                                                                                        • CVE-2018-10087
                                                                                                        • CVE-2017-9985
                                                                                                        • CVE-2017-9984
                                                                                                        • CVE-2017-8831
                                                                                                        • CVE-2017-7645
                                                                                                        • CVE-2017-7518
                                                                                                        • CVE-2017-6348
                                                                                                        • CVE-2017-6345
                                                                                                        • CVE-2017-5897
                                                                                                        • CVE-2017-5549
                                                                                                        • CVE-2017-2584
                                                                                                        • CVE-2017-2583
                                                                                                        • CVE-2017-18270
                                                                                                        • CVE-2017-18255
                                                                                                        • CVE-2017-17558
                                                                                                        • CVE-2017-16914
                                                                                                        • CVE-2017-16913
                                                                                                        • CVE-2017-16912
                                                                                                        • CVE-2017-16911
                                                                                                        • CVE-2017-16650
                                                                                                        • CVE-2017-16645
                                                                                                        • CVE-2017-16644
                                                                                                        • CVE-2017-16643
                                                                                                        • CVE-2017-16538
                                                                                                        • CVE-2017-16537
                                                                                                        • CVE-2017-16536
                                                                                                        • CVE-2017-16535
                                                                                                        • CVE-2017-16533
                                                                                                        • CVE-2017-16532
                                                                                                        • CVE-2017-16531
                                                                                                        • CVE-2017-16529
                                                                                                        • CVE-2017-16527
                                                                                                        • CVE-2017-16526
                                                                                                        • CVE-2017-15649
                                                                                                        • CVE-2017-14991
                                                                                                        • CVE-2017-11473
                                                                                                        • CVE-2017-11472
                                                                                                        • CVE-2016-10208
                                                                                                        • Goings on in Ubuntu Security Community
                                                                                                          Hiring
                                                                                                          Ubuntu Security Manager
                                                                                                          • https://boards.greenhouse.io/canonical/jobs/1278287
                                                                                                          • Ubuntu Security Engineer
                                                                                                            • https://boards.greenhouse.io/canonical/jobs/1158266
                                                                                                            • Get in contact
                                                                                                              • #ubuntu-security on the Libera.Chat IRC network
                                                                                                              • @ubuntu_sec on twitter
                                                                                                              • 9 min
                                                                                                              • Episode 1
                                                                                                                Overview
                                                                                                                • Security fixes for 39 CVEs this week including L1TF and FragmentSmack
                                                                                                                • This week in Ubuntu Security Updates
                                                                                                                  GDM (USN-3737-1) (CVE-2018-14424)
                                                                                                                  • Found by Ubuntu Security Team member Chris Coulson during audit of gdm3 source code
                                                                                                                  • Local user can exploit via DBus to crash GDM via use-after-free (create a transient display which is automatically cleaned up, then try to query info for the previously created display)
                                                                                                                  • Bionic only so far
                                                                                                                  • libarchive (USN-3736-1)
                                                                                                                    • 6 CVEs addressed across Bionic, Xenial and Trusty
                                                                                                                      • CVE-2016-10209
                                                                                                                      • CVE-2016-10349
                                                                                                                      • CVE-2016-10350
                                                                                                                      • CVE-2017-14166
                                                                                                                      • CVE-2017-14501
                                                                                                                      • CVE-2017-14503
                                                                                                                      • All local crashes / DoS / unspecified impact via specially crafted archives in various formats
                                                                                                                      • Samba (USN-3738-1)
                                                                                                                        • 4 CVEs addressed across Bionic, Xenial and Trusty
                                                                                                                          • CVE-2018-10858
                                                                                                                          • CVE-2018-10918
                                                                                                                          • CVE-2018-10919
                                                                                                                          • CVE-2018-1139
                                                                                                                          • Includes vulnerabilities in both the samba client and server
                                                                                                                            • Likely to affect most Ubuntu users
                                                                                                                            • libxml2 (USN-3739-1) (USN-3739-2)
                                                                                                                              • XML parsing library used across lots of different software packages
                                                                                                                              • 5 CVEs fixed across releases for Bionic, Xenial and Trusty
                                                                                                                                • 2 CVEs fixed for Precise ESM
                                                                                                                                • CVE-2016-9318
                                                                                                                                • CVE-2017-16932
                                                                                                                                • CVE-2017-18258
                                                                                                                                • CVE-2018-14404
                                                                                                                                • CVE-2018-14567
                                                                                                                                • Includes information disclosure and DoS
                                                                                                                                • L1TF and FragmentSmack vulnerabilities in Linux Kernel (USN-3740-1) (USN-3740-2) (USN-3741-1) (USN-3741-2) (USN-3742-1) (USN-3742-2)
                                                                                                                                  L1TF (CVE-2018-3620) (CVE-2018-3646)
                                                                                                                                  • Latest speculative execution cache side channel attack affecting Intel processors
                                                                                                                                  • Allows to access contents from L1 Data Cache via speculative execution, can then be read by cache side channel
                                                                                                                                  • 3 variants, SGX, SMM and VMM but only 2 affect Ubuntu
                                                                                                                                  • Processors access virtual addresses which need to be translated to physical addresses
                                                                                                                                  • Page Table Entries map from one to the other (contains metadata of page including offset and present bit)
                                                                                                                                  • Pages can be swapped in our out of memory (Present or not) - so if not present then need to do a full page table walk to look up physical address
                                                                                                                                  • But Intel processor will use offset value from PTE even on non-present pages speculatively
                                                                                                                                  • For non-present pages, this value is usually junk so can essentially speculatively read arbitrary memory from L1D cache depending on PTE value
                                                                                                                                  • SGX doesn’t affect Ubuntu since not used
                                                                                                                                  • SMM fixed via ensuring PTEs of not present pages always refer to non-cacheable memory and hence can’t be used for this
                                                                                                                                  • VMM is trickier
                                                                                                                                    • VMs maintain their own PTEs so also need to ensure they are doing the right thing
                                                                                                                                    • OR if running untrusted VMs need to do a full L1D flush on switching from host to VM
                                                                                                                                    • Made more trickier by Hyper Threading since sibling hyper-threads share the L1D cache
                                                                                                                                    • So if have different trust domains on sibling hyper-threads may have to disable HT in certain circumstances
                                                                                                                                    • FragmentSmack (CVE-2018-5391)
                                                                                                                                      • Last week was SegmentSmack in TCP fragment reassembly, this week is FragmentSmack
                                                                                                                                      • Similar but for IP fragmentation reassembly
                                                                                                                                        • Exploiting high algorithmic complexity of IP fragment reassembly code paths to cause DoS
                                                                                                                                        • GnuPG (USN-3733-2) (CVE-2017-7526)
                                                                                                                                          • Last week GnuPG was fixed for Xenial and Trusty for RSA cache side-channel issue
                                                                                                                                          • This is corresponding fix for Precise ESM
                                                                                                                                          • WebKitGTK+ vulnerabilities (USN-3743-1)
                                                                                                                                            • 14 CVEs fixed in web content renderer used in many desktop apps
                                                                                                                                              • CVE-2018-12911
                                                                                                                                              • CVE-2018-4246
                                                                                                                                              • CVE-2018-4261
                                                                                                                                              • CVE-2018-4262
                                                                                                                                              • CVE-2018-4263
                                                                                                                                              • CVE-2018-4264
                                                                                                                                              • CVE-2018-4265
                                                                                                                                              • CVE-2018-4266
                                                                                                                                              • CVE-2018-4267
                                                                                                                                              • CVE-2018-4270
                                                                                                                                              • CVE-2018-4272
                                                                                                                                              • CVE-2018-4273
                                                                                                                                              • CVE-2018-4278
                                                                                                                                              • CVE-2018-4284
                                                                                                                                              • Fixes for Bionic and Xenial
                                                                                                                                              • PostgreSQL (USN-3744-1) (CVE-2018-10915) (CVE-2018-10925)
                                                                                                                                                • 2 CVEs fixed in popular relational database across Bionic, Xenial and Trusty
                                                                                                                                                • procps-ng (USN-3658-3)
                                                                                                                                                  • 3 CVEs fixed in Precise ESM procps-ng package
                                                                                                                                                    • CVE-2018-1122
                                                                                                                                                    • CVE-2018-1123
                                                                                                                                                    • CVE-2018-1125
                                                                                                                                                    • Linux kernel livepatch (LSN-0042-1)
                                                                                                                                                      • No Livepatch possible for L1TF so a LSN to advise to do an update and reboot
                                                                                                                                                      • Goings on in Ubuntu Security Community
                                                                                                                                                        Hiring
                                                                                                                                                        Ubuntu Security Manger
                                                                                                                                                        • https://boards.greenhouse.io/canonical/jobs/1278287
                                                                                                                                                        • Ubuntu Security Engineer
                                                                                                                                                          • https://boards.greenhouse.io/canonical/jobs/1158266
                                                                                                                                                          • Get in contact
                                                                                                                                                            • #ubuntu-security on the Libera.Chat IRC network
                                                                                                                                                            • @ubuntu_sec on twitter
                                                                                                                                                            • Special thanks
                                                                                                                                                              • Thanks to Emily Ratliff - a great manager of the team (and a good friend too)
                                                                                                                                                              • We will miss you :)
                                                                                                                                                              • 11 min
                                                                                                                                                              • Episode 0
                                                                                                                                                                Introduction
                                                                                                                                                                What will be covered
                                                                                                                                                                • Overview of latest security updates for Ubuntu
                                                                                                                                                                • In depth discussion of trending CVEs
                                                                                                                                                                • Other things the team has been up to
                                                                                                                                                                • This week in Ubuntu Security Updates
                                                                                                                                                                  SegmentSmack (CVE-2018-5390) (USN-3732-1)
                                                                                                                                                                  • DoS via expensive algorithmic computation in TCP stream reassembly
                                                                                                                                                                  • Requires attacker to have an existing TCP session
                                                                                                                                                                  • Affecting kernel >= 4.9
                                                                                                                                                                  • Fixed in Bionic and Xenial for HWE
                                                                                                                                                                  • No known exploits in the wild
                                                                                                                                                                  • linux kernel (LSN-0041-1)
                                                                                                                                                                    • brief description of livepatch
                                                                                                                                                                    • Several issues (5 CVEs)
                                                                                                                                                                      • stack overflow in SCSI / cdrom layers (CVE-2018-11506)
                                                                                                                                                                      • DoS / crash via specially crafted ext4 filesystem (CVE-2018-1094)
                                                                                                                                                                      • files can be created with group permissions which the original owner did not have within sgid directories (CVE-2018-13405)
                                                                                                                                                                        • Originally reported by Jann Horn in relation to whoopsie / apport in Ubuntu
                                                                                                                                                                        • DoS / crash via specially crafted xfs filesystem (CVE-2018-13094)
                                                                                                                                                                        • SegmentSmack fix (CVE-2018-5390)
                                                                                                                                                                        • generic & lowlatency kernels for Trusty, Xenial and Bionic
                                                                                                                                                                        • gnupg (CVE-2017-7526) (USN-3733-1)
                                                                                                                                                                          • Cache side-channel attack on RSA implementation
                                                                                                                                                                          • When CVE was created, only assigned to libgcrypt
                                                                                                                                                                          • gnupg quietly announced 1.4.23 as fixing this CVE as well in June
                                                                                                                                                                            • Turns out was actually fixed in 1.4.22
                                                                                                                                                                            • So Bionic etc not affected
                                                                                                                                                                            • Fixed in Trusty and Xenial
                                                                                                                                                                            • No known exploits in the wild
                                                                                                                                                                            • openjdk (CVE-2018-2952) (USN-3734-1)
                                                                                                                                                                              • Denial of service via excessive memory consumption
                                                                                                                                                                              • openjdk-7 in trusty and openjdk-8 in xenial
                                                                                                                                                                              • lxc (CVE-2018-6556) (USN-3730-1)
                                                                                                                                                                                • Allows opening (but not reading) of arbitrary files
                                                                                                                                                                                  • Information disclosure / DoS since could open pseudoterminals or other kernel devices and cause exhausting of resources
                                                                                                                                                                                  • For lxc >=2.0 - bionic, xenial-backports
                                                                                                                                                                                  • libxcursor (CVE-2015-9262) (USN-3729-1)
                                                                                                                                                                                    • Classic off-by-one error - string allocation but forgot to allocate byte for NUL terminator
                                                                                                                                                                                      • As on the heap allows heap memory corruption
                                                                                                                                                                                      • Possible code execution etc
                                                                                                                                                                                      • In handling of cursor themes so could be triggered when loading a malicious themes
                                                                                                                                                                                      • Affects libxcursor in trusty and xenial - both fixed
                                                                                                                                                                                      • lftp (CVE-2018-10196) (USN-3731-1)
                                                                                                                                                                                        • Command-line FTP / HTTP / BitTorrent clients
                                                                                                                                                                                        • Does not properly validate filenames from server when mirroring locally
                                                                                                                                                                                          • Could allow a malicious server to remove all files in PWD
                                                                                                                                                                                          • Fixed in Bionic, Xenial, Trusty & Precise ESM
                                                                                                                                                                                          • Subscribe to ubuntu-security-announce mailing list
                                                                                                                                                                                            • https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce
                                                                                                                                                                                            • Goings on in Ubuntu Security
                                                                                                                                                                                              NCSC publish Ubuntu 18.04 LTS Security Guide
                                                                                                                                                                                              • A couple weeks old now, but worth mentioning
                                                                                                                                                                                              • National Cyber Security Centre in UK
                                                                                                                                                                                                • Provide infosec guidance to public and private sector
                                                                                                                                                                                                • Focuses around End User Devices deployed for remote work but applies equally to home / office as well
                                                                                                                                                                                                • Covers guidance such as:
                                                                                                                                                                                                  • VPN
                                                                                                                                                                                                  • Enforcing a given password policy
                                                                                                                                                                                                  • UEFI Secure Boot
                                                                                                                                                                                                  • Livepatch
                                                                                                                                                                                                  • Firewall configuration
                                                                                                                                                                                                  • Auditing
                                                                                                                                                                                                  • https://www.ncsc.gov.uk/guidance/eud-security-guidance-ubuntu-1804-lts
                                                                                                                                                                                                  • https://blog.ubuntu.com/2018/07/30/national-cyber-security-centre-publish-ubuntu-18-04-lts-security-guide
                                                                                                                                                                                                  • Seth Arnold’s AppArmor 3.0 presentation at DebConf
                                                                                                                                                                                                    • Overview of AppArmor with brief history and walkthough of main features
                                                                                                                                                                                                    • Efforts to enable AppArmor by default in Debian Buster (10)
                                                                                                                                                                                                    • Ongoing work to upstream the latest AppArmor changes
                                                                                                                                                                                                      • Course-grained network mediation (AF_INET / AF_IET6)
                                                                                                                                                                                                      • DBus mediation
                                                                                                                                                                                                        • Almost all are now in Linux kernel 4.19
                                                                                                                                                                                                        • Some remain for 4.20
                                                                                                                                                                                                          • Unix sockets
                                                                                                                                                                                                          • Future directions for AppArmor
                                                                                                                                                                                                            • IMA-aware policy (in 4.17, requires AppArmor 3.0 userspace)
                                                                                                                                                                                                              • Contributed by Google, hopefully will be available soon
                                                                                                                                                                                                              • Fine-grained networking mediation (ie. port level mediation)
                                                                                                                                                                                                              • Shared memory mediation
                                                                                                                                                                                                              • cgroups
                                                                                                                                                                                                              • overlayfs
                                                                                                                                                                                                              • user specific policy
                                                                                                                                                                                                              • Multiple namespaces support for AppArmor
                                                                                                                                                                                                                • LXD / libvirt / snapd / docker
                                                                                                                                                                                                                • policy within a namespace (and policy outside the namespace too)
                                                                                                                                                                                                                • Demo of LXD with namespaced policy
                                                                                                                                                                                                                • https://debconf18.debconf.org/talks/106-apparmor-30/
                                                                                                                                                                                                                • Hiring
                                                                                                                                                                                                                  Ubuntu Security Engineer
                                                                                                                                                                                                                  • https://boards.greenhouse.io/canonical/jobs/1158266
                                                                                                                                                                                                                  • Get in contact
                                                                                                                                                                                                                    • #ubuntu-security on the Libera.Chat IRC network
                                                                                                                                                                                                                    • @ubuntu_sec on twitter
                                                                                                                                                                                                                    • 13 min

                                                                                                                                                                                                                    About Ubuntu Security Podcast

                                                                                                                                                                                                                    From the publisher's feed

                                                                                                                                                                                                                    A fortnightly podcast talking about the latest developments and updates from the Ubuntu Security team, including a summary of recent security vulnerabilities and fixes as well as a discussion on some…