TopPodcast.com
Menu
  • Home
  • Top Charts
  • Top Networks
  • Top Apps
  • Top Independents
  • Top Podfluencers
  • Top Picks
    • Top Business Podcasts
    • Top True Crime Podcasts
    • Top Finance Podcasts
    • Top Comedy Podcasts
    • Top Music Podcasts
    • Top Womens Podcasts
    • Top Kids Podcasts
    • Top Sports Podcasts
    • Top News Podcasts
    • Top Tech Podcasts
    • Top Crypto Podcasts
    • Top Entrepreneurial Podcasts
    • Top Fantasy Sports Podcasts
    • Top Political Podcasts
    • Top Science Podcasts
    • Top Self Help Podcasts
    • Top Sports Betting Podcasts
    • Top Stocks Podcasts
  • Podcast News
  • About Us
  • Podcast Advertising
  • Contact
Not in our directory?
Add Show Here
Podcast Equipment
Center

toppodcastlogoOur TOPPODCAST Picks

  • Comedy
  • Crypto
  • Sports
  • News
  • Politics
  • True Crime
  • Business
  • Finance

Follow Us

toppodcastlogoStay Connected

    View Top 200 Chart
    Back to Rankings Page
    Technology

    Ubuntu Security Podcast

    A fortnightly podcast talking about the latest developments and updates from the Ubuntu Security team, including a summary of recent security vulnerabilities and fixes as well as a discussion on some of the goings on in the wider Ubuntu Security community.

    Advertise

    Copyright: © Copyright 2019 Canonical

    • Apple Podcasts
    • Google Play
    • Spotify

    Latest Episodes:
    Episode 53 Nov 15, 2019
    Show notes

    Overview

    This week we look at the details of the latest Intel hardware vulnerabilities, including security updates for the Linux kernel and Intel microcode, plus Bash, cpio, FriBidi and more.

    This week in Ubuntu Security Updates

    26 unique CVEs addressed

    [USN-4176-1] GNU cpio vulnerability [01:00]

    • 1 CVEs addressed in Precise ESM, Trusty ESM, Xenial, Bionic, Disco, Eoan
      • CVE-2019-14866
    • cpio wouldn’t validate values written to headers of TAR archives - could use cpio to create a TAR containing another TAR with a big size and will use wrong context values (ie uses inner TAR values in header) - this could allow a TAR to be created which has files with permissions not owned by the original user - when extracted by cpio will overwrite target files - whereas if using tar to extract will avoid this - fixed to check and handle header values correctly

    [USN-4177-1] Rygel vulnerability [02:18]

    • Affecting Eoan
    • Added Rygel in Eoan which is off by default but needed GNOME to handle that - it would disable it dynamically - so if not running GNOME, rygel would be running and sharing your stuff on the local network - fixed to disable automatically on upgrade - and then can use the GNOME settings front-end etc to re-enable if desired

    [USN-4178-1] WebKitGTK+ vulnerabilities [03:34]

    • 4 CVEs addressed in Bionic, Disco
      • CVE-2019-8771
      • CVE-2019-8769
      • CVE-2019-8720
      • CVE-2019-8625

    [USN-4181-1] WebKitGTK+ vulnerabilities [03:34]

    • 2 CVEs addressed in Bionic, Disco, Eoan
      • CVE-2019-8814
      • CVE-2019-8812

    [USN-4179-1] FriBidi vulnerability [04:00]

    • 1 CVEs addressed in Disco, Eoan
      • CVE-2019-18397
    • Issue reported about unicode isolated handling in Qt - turns out affected GTK applications as well - entirely different code with very similar flaw - stack buffer overflow since didn’t check bounds of a fixed array used to store details on nested unicode isolate sections - simple fix to just check bounds before trying to store next element

    [USN-4180-1] Bash vulnerability [05:38]

    • 1 CVEs addressed in Precise ESM
      • CVE-2012-6711
    • Recently announced vuln (heap-based buffer overflow) in bash affecting old versions - so most releases unaffected except Precise - can trigger by printing wide characters via echo -e

    [USN-4182-1, USN-4182-2] Intel Microcode update [06:12]

    • 2 CVEs addressed in Trusty ESM, Xenial, Bionic, Disco, Eoan
      • CVE-2019-11139
      • CVE-2019-11135
    • Voltage modulation able to be performed by a local privileged user - disabled via microcode
    • TSX Asynchronous Abort (TAA) - https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/TAA_MCEPSC_i915
      • Another variant of MDS but only affects processsors with Transational Synchronization Extensions (TSX)
      • MDS mitigations also can mitigate this - but needs microcode update - associated kernel update too

    [USN-4183-1] Linux kernel vulnerabilities [07:58]

    • 9 CVEs addressed in Eoan
      • CVE-2019-17666
      • CVE-2019-16746
      • CVE-2019-15793
      • CVE-2019-15792
      • CVE-2019-15791
      • CVE-2019-0154
      • CVE-2018-12207
      • CVE-2019-0155
      • CVE-2019-11135
    • MCEPSC - https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/TAA_MCEPSC_i915
      • trigger a MCE from a guest by changing page size in a particular way within the guest -> MCE on host kernel -> DoS
    • i915 graphics - userspace can modify PTE via writes to MMIO from blitter command streamer or expose kernel memory - privesc
    • TAA
    • Various other issues:
      • Realtek wifi driver buffer overflow - able to be triggered OTA - crash / RCE
      • Buffer overflow in nl80211 config interface (local user) - crash / code exec
      • Jann Horn - shiftfs issues
        • UID/GID confusion when namespace of lower file-system is not init_user_ns - DAC bypass
        • type confusion -> buffer overflow
        • reference count underflow -> UAF
          • local user crash / code exec
      • i915 graphics - userspace read on GT MMIO -> hang -> DoS (low power state)

    [USN-4184-1] Linux kernel vulnerabilities [11:09]

    • 14 CVEs addressed in Bionic (HWE), Disco
      • CVE-2019-17666
      • CVE-2019-17056
      • CVE-2019-17055
      • CVE-2019-17054
      • CVE-2019-17053
      • CVE-2019-17052
      • CVE-2019-15793
      • CVE-2019-15792
      • CVE-2019-15791
      • CVE-2019-15098
      • CVE-2019-0154
      • CVE-2018-12207
      • CVE-2019-0155
      • CVE-2019-11135
    • See above plus
      • Various network based subsystems failed to enforce CAP_NET_RAW for raw socket creation
        • AF_NFC, AF_ISDN, AF_APPLETALK, AF_IEEE802154 (low-rate wireless network), AF_AX25

    [USN-4185-1, USN-4185-2] Linux kernel vulnerabilities [12:06]

    • 11 CVEs addressed in Trusty ESM (Azure), Xenial (HWE), Bionic
      • CVE-2019-17666
      • CVE-2019-17056
      • CVE-2019-17055
      • CVE-2019-17054
      • CVE-2019-17053
      • CVE-2019-17052
      • CVE-2019-15098
      • CVE-2019-0154
      • CVE-2018-12207
      • CVE-2019-0155
      • CVE-2019-11135
    • realtek wifi buffer overflow, AF_XXX CAP_NET_RAW, NULL pointer dereference in Atheros USB Wifi Driver, Intel hardware issues (2xi915 + TAA + MCEPSC)

    [USN-4186-1, USN-4186-2] Linux kernel vulnerabilities [12:47]

    • 13 CVEs addressed in Trusty ESM (HWE), Xenial
      • CVE-2019-2215
      • CVE-2019-17666
      • CVE-2019-17056
      • CVE-2019-17055
      • CVE-2019-17054
      • CVE-2019-17053
      • CVE-2019-17052
      • CVE-2019-16746
      • CVE-2019-15098
      • CVE-2019-0154
      • CVE-2018-12207
      • CVE-2019-0155
      • CVE-2019-11135
    • Binder UAF -> crash, DoS -> code exec (CONFIG_DEBUG_LIST mitigates this - looking to add this in future kernels like 20.04)
    • realtek wifi, CAP_NET_RAW, nl80211 config buffer overflow, Intel hardware issues

    [USN-4187-1] Linux kernel vulnerability [13:48]

    • 1 CVEs addressed in Trusty ESM
      • CVE-2019-11135
    • TAA

    [USN-4188-1] Linux kernel vulnerability [13:48]

    • 1 CVEs addressed in Precise ESM
      • CVE-2019-11135
    • TAA

    [LSN-0059-1] Linux kernel vulnerability [14:05]

    • 4 CVEs addressed in Xenial and Bionic
      • CVE-2019-11135
      • CVE-2019-0155
      • CVE-2019-0154
      • CVE-2018-12207
    • Intel hardware issues - CAN’T BE LIVEPATCHED - need to update kernel and reboot

    Goings on in Ubuntu Security Community

    20.04 Roadmap Sprint [14:55]

    Get in contact

    • security@ubuntu.com
    • #ubuntu-security on the Libera.Chat IRC network
    • ubuntu-hardened mailing list
    • Security section on discourse.ubuntu.com
    • @ubuntu_sec on twitter

    Episode 52 Nov 08, 2019
    Show notes

    Overview

    This week we look at security updates for FreeTDS, HAProxy, Nokogiri, plus some regressions in Whoopsie, Apport and Firefox, and Joe and Alex discuss the release of 14.04 ESM for personal use under the Ubuntu Advantage program.

    This week in Ubuntu Security Updates

    9 unique CVEs addressed

    [USN-4171-2] Apport vulnerabilities [00:44]

    • 5 CVEs addressed in Trusty ESM
      • CVE-2019-15790
      • CVE-2019-11485
      • CVE-2019-11483
      • CVE-2019-11482
      • CVE-2019-11481
    • Episode 51

    [USN-4172-1, USN-4172-2] file vulnerability [00:58]

    • 1 CVEs addressed in Precise ESM, Trusty ESM, Xenial, Bionic, Disco, Eoan
      • CVE-2019-18218
    • OSS-Fuzz using libFuzzer - heap based buffer overflow of up to 4 bytes in the CDF parser when handing vector elements - Composite Document File - used in MS Office prior to new zipped XML format - ie. the old .doc / .xls etc

    [USN-4173-1] FreeTDS vulnerability [01:48]

    • 1 CVEs addressed in Bionic, Disco, Eoan
      • CVE-2019-13508
    • Felix Wilhelm for Google Security Team - if a server were to downgrade the protocol to version 5 and send a UDT type to the client, would cause a heap buffer overflow due to mismatch in size - fixed by forcing the size to an appropriate value

    [USN-4170-2, USN-4170-3] Whoopsie regressions [02:22]

    • Affecting Xenial, Bionic, Disco, Eoan
    • Episode 51 - update caused crash on upload to server due to mismatch in size and resulting partial uninitialized variable - fixed to intialize but realised this could still potentially crash on big-endian architectures so fixed properly by changing size to 32-bit to match memcpy()

    [USN-4171-3, USN-4171-4] Apport regression [04:07]

    • 5 CVEs addressed in Trusty ESM, Xenial, Bionic, Disco, Eoan
      • CVE-2019-15790
      • CVE-2019-11485
      • CVE-2019-11483
      • CVE-2019-11482
      • CVE-2019-11481
    • Episode 51 - regression due to missing change to python code to handle new internal API - fixed by updating the API to be backwards compatible

    [USN-4174-1] HAproxy vulnerability [04:55]

    • 1 CVEs addressed in Xenial, Bionic, Disco, Eoan
      • CVE-2019-18277
    • HTTP Request Smuggling attack
      • https://nathandavison.com/blog/haproxy-http-request-smuggling
    • Wouldn’t reject messages that specified transfer-encoding without “chunked” value
    • Could be combined with http reuse for request smuggling - ie. the ability to get an attacker controlled chunk appended to a legitimate request and hence the response sent back to the attacker etc - fixed to reject if transfer-encoding is used without also specifying “chunked”

    [USN-4175-1] Nokogiri vulnerability [06:36]

    • 1 CVEs addressed in Xenial, Bionic, Disco, Eoan
      • CVE-2019-5477
    • Ruby based parser for HTML/XML/SAS etc with XPath & CSS selector support etc
    • Command-injection vulnerability - due to use of the Rexical gem - and would need to have code which then calls the undocumented load_file method within the CSS tokenizer with user supplied input for the filename - due to use of eval()…

    [USN-4165-2] Firefox regressions [07:38]

    • Affecting Xenial, Bionic, Disco, Eoan
    • Upstream Firefox 70.0.1 release to fix a regression in the 70.0 release (some pages with dynamic javascript would fail to load - v 70.0 had enabled a new next-gen local storage feature which caused issues so this is now disabled by default)

    Goings on in Ubuntu Security Community

    Alex and Joe discuss news that 14.04 ESM is free for personal use via new UA client [08:19]

    • https://ubuntu.com/blog/ua-services-deployed-from-the-command-line-with-ua-client
    • https://ubuntu.com/esm
    • https://wiki.ubuntu.com/SecurityTeam/ESM/14.04

    Get in contact

    • security@ubuntu.com
    • #ubuntu-security on the Libera.Chat IRC network
    • ubuntu-hardened mailing list
    • Security section on discourse.ubuntu.com
    • @ubuntu_sec on twitter

    Episode 51 Oct 31, 2019
    Show notes

    Overview

    In this Halloween Special, Joe and Alex talk about what scares them in security, plus we look at security updates for Firefox, PHP, Samba, Whoopsie, Apport and more.

    This week in Ubuntu Security Updates

    26 unique CVEs addressed

    [USN-4165-1] Firefox vulnerabilities [00:46]

    • 13 CVEs addressed in Xenial, Bionic, Disco, Eoan
      • CVE-2019-17002
      • CVE-2019-17001
      • CVE-2019-17000
      • CVE-2019-15903
      • CVE-2019-11765
      • CVE-2019-11764
      • CVE-2019-11763
      • CVE-2019-11762
      • CVE-2019-11761
      • CVE-2019-11760
      • CVE-2019-11759
      • CVE-2019-11757
      • CVE-2018-6156
    • 1 high priority, 11 medium and 1 low
      • Heap buffer overflow via a crafted WebRTC video - originally for Chromium and was fixed for that last year - Firefox suffered similarly but disables the feature by default - has finally been fixed for Firefox as well by integrating the original fix from Chromium
      • Usual suspects of stack-based buffer overflows, UAFs, a heap buffer overflow in bundled expat (Episode 47),

    [USN-4166-1, USN-4166-2] PHP vulnerability [02:10]

    • 1 CVEs addressed in Precise ESM, Trusty ESM, Xenial, Bionic, Disco, Eoan
      • CVE-2019-11043
    • RCE in PHP (FPM - FastCGI Process Manager) - possible to cause the FPM module to write past allocated buffers - and so ends up also writing into the FCGI protocol data buffers - which can then create a chance for RCE
    • Exploit on github targetting vulnerable PHP-FPM servers which use nginx in a particular configuration

    [USN-4167-1, USN-4167-2] Samba vulnerabilities [03:11]

    • 3 CVEs addressed in Precise ESM, Trusty ESM, Xenial, Bionic, Disco, Eoan
      • CVE-2019-14847
      • CVE-2019-14833
      • CVE-2019-10218
    • DoS from a user with “get changes” permissions - could crash an AD DC LDAP server due to a NULL pointer deref when using dirsync with ranged results
    • Can configure AD DC to call out to a custom command to verify password complexity - is handed a copy of the cleartext password - but if this contained any multi-byte characters, would not get the full password - since it would pass the password as bytes but only copy the number of characters - and since multi-byte characters take more than 1 byte would miss the last few bytes of the password - so could circumvent password complexity requirements
    • Malicious server could craft filenames which contain relative path characters (../ etc) which would then cause an SMB client to access local files for reading / writing rather than remote files - so a remote server could cause a client to create files outside the working directory on the local machine

    [USN-4168-1] Libidn2 vulnerabilities [05:15]

    • 2 CVEs addressed in Bionic, Disco
      • CVE-2019-18224
      • CVE-2019-12290
    • Library for handling internationalised domain names
    • Heap based buffer overflow via a too-long domain name (greater than 63 characters - in library, caller passes a buffer that is specified to be a minimum of 64 bytes - but libidn strcpy()’s into it so could easily overflow.
    • Possible domain name impersonation since doesn’t bother to check unicode conversions - so could use punycode (ascii representation of certain unicode characters) to impersonate a unicode domain

    [USN-4169-1] libarchive vulnerability [06:32]

    • 1 CVEs addressed in Trusty ESM, Xenial, Bionic, Disco
      • CVE-2019-18408
    • UAF in certain failure conditions when handling RAR archives

    [USN-4170-1] Whoopsie vulnerability [06:52]

    • 1 CVEs addressed in Xenial, Bionic, Disco, Eoan
      • CVE-2019-11484
    • Kevin Backhouse from Semmle Security Research Team - integer oveflow -> heap based buffer overflow -> code executions a whoopsie user

    [USN-4171-1] Apport vulnerabilities [07:51]

    • 5 CVEs addressed in Xenial, Bionic, Disco, Eoan

      • CVE-2019-15790
      • CVE-2019-11485
      • CVE-2019-11483
      • CVE-2019-11482
      • CVE-2019-11481
    • Kevin Backhouse from Semmle Security Research Team

      • reads /proc/PID files as root - so if can race on process ID reuse could cause Apport to generate a crash dump of a privileged process that is readable by a normal user (so starts dumping an unprivileged process, then PID race, new PID as privileged user -> this crashes -> Apport starts writing out the crash report for the first process but using the details of the new privileged process - since this was originally an unprivileged process, the crash dump is then unprivileged too). Fixed by making sure Apport drops privileges to the original unprivileged user before reading /proc/PID info so if this happens to then be a different user’s process will not be able to generate the crash dump
      • Apport would read a per-user configuration file - but would do so as root - and so this could be a symlink to a root owned file and Apport would happily read it (but might error out if it looked invalid) - so drop privileges to read it so it doesn’t include anything which it shouldn’t in the final crash report
    • Sander Bos

      • Apport had a lock file in a world-writable directory - so anyone could create it to either stop Apport running or to control the execution of Apport over time - fixed to place in a non-world writable location instead
      • When using containers, Apport uses a socket file to allow it to forward crash dumps that it captured on the host to an Apport instance running within a container containers - it finds the socket file from the host using the /proc/PID/root magic link - but this could allow an unprivileged user who (using unprivileged usernamespaces) is root in a container to chroot() for a process in a container to a different location so it can then intercept the crash dump of a privileged process within the container - so could run a setuid process in the container, and when it crashes be able to read it’s crash dump
      • TOCCTOU race on PID (like above) but this is in a different code path - reads the cwd of the crashed process to write out the core dump to this location - but on process ID reuse this could then be in a different location - so if a user can race against a privileged process dumping the crash dump could end up in a location of their choosing

    Goings on in Ubuntu Security Community

    Joe and Alex discuss what scares them for Halloween [12:38]

    Get in contact

    • security@ubuntu.com
    • #ubuntu-security on the Libera.Chat IRC network
    • ubuntu-hardened mailing list
    • Security section on discourse.ubuntu.com
    • @ubuntu_sec on twitter

    Episode 50 Oct 24, 2019
    Show notes

    Overview

    Alex and Joe discuss the big news of this week - the release of Ubuntu 19.10 Eoan Ermine - plus we look at updates for the Linux kernel, libxslt, UW IMAP and more.

    This week in Ubuntu Security Updates

    51 unique CVEs addressed

    [USN-4156-2] SDL vulnerabilities [00:37]

    • 11 CVEs addressed in Precise ESM, Trusty ESM
      • CVE-2019-7637
      • CVE-2019-7636
      • CVE-2019-7635
      • CVE-2019-7578
      • CVE-2019-7577
      • CVE-2019-7576
      • CVE-2019-7575
      • CVE-2019-7574
      • CVE-2019-7573
      • CVE-2019-7572
      • CVE-2019-13616
    • Covered in Episode 49 and Episode 48

    [USN-4160-1] UW IMAP vulnerability [01:04]

    • 1 CVEs addressed in Xenial, Bionic, Disco
      • CVE-2018-19518
    • University of Washington IMAP toolkit (used by PHP for it’s IMAP implementation)
    • Used rsh to implement various operations - wouldn’t try and sanitize the provided hostname - so if attacker could provide a hostname/mailbox to php’s IMAP without any validation could execute arbitrary commands on the host
      • Fixed by turning off the rsh based functionality by default in PHP - if you still want this you can set imap.enable_insecure_rsh but this is not advised…

    [USN-4158-1] LibTIFF vulnerabilities [02:17]

    • 2 CVEs addressed in Xenial, Bionic, Disco
      • CVE-2019-17546
      • CVE-2019-14973
    • Integer overflow -> heap based buffer overflow -> crash, DoS or code execution
    • (Low) Integer overflow due to undefined behaviour in existing overflow checking code when multiplying various elements -> no known way to exploit

    [USN-4155-2] Aspell vulnerability [03:13]

    • 1 CVEs addressed in Eoan
      • CVE-2019-17544
    • Episode 49 covered for older releases - Eoan is now out so updated there too

    [USN-4159-1] Exiv2 vulnerability [03:31]

    • 1 CVEs addressed in Xenial, Bionic, Disco, Eoan
      • CVE-2019-17402
    • OOB read -> crash, DoS

    [USN-4164-1] Libxslt vulnerabilities [03:44]

    • 3 CVEs addressed in Precise ESM, Trusty ESM, Xenial, Bionic, Disco, Eoan
      • CVE-2019-18197
      • CVE-2019-13118
      • CVE-2019-13117
    • OSS-Fuzz found 3 issues
      • possible heap buffer overflow as a result of a dangling pointer - so same memory area could be reused for future memory operations -> fixed to reset the pointer when done
      • 2 low priority issues - both stack memory info disclosures

    [USN-4157-1, USN-4157-2] Linux kernel vulnerabilities [04:59]

    • 9 CVEs addressed in Bionic (HWE) and Disco
      • CVE-2019-2181
      • CVE-2019-16714
      • CVE-2019-15902
      • CVE-2019-15505
      • CVE-2019-15504
      • CVE-2019-14821
      • CVE-2019-14816
      • CVE-2019-14815
      • CVE-2019-14814
    • Integer overflow -> buffer overflow -> root privesc in binder
    • Reintroduction of Spectre v1 vulnerability in ptrace subsystem - Brad Spengler - fixed properly in Linus’ tree but not when it got backported to the stable tree - two lines of code got reordered - so load of possible speculative value occurred _after_it had been used - so the speculative load barrier had no effect - Ubuntu regularly backports fixes from the latest stable tree so we ended up affected as well
      • https://grsecurity.net/teardown_of_a_failed_linux_lts_spectre_fix.php
    • Possible DoS (kernel crash) if users can write to /dev/kvm - by default on Ubuntu users don’t have this privilege so generally not affected
    • 2 different heap based buffer overflows in Marvell Wifi driver -> occurred when setting parameters for the driver so could be triggered by a local users -> crash, DoS or possible code execution

    [USN-4161-1] Linux kernel vulnerability [07:40]

    • 1 CVEs addressed in Eoan
      • CVE-2019-18198
    • Eoan kernel “0-day” - will discuss with Joe later

    [USN-4162-1] Linux kernel vulnerabilities [07:58]

    • 10 CVEs addressed in Trusty ESM (Azure), Xenial (HWE), Bionic
      • CVE-2019-15918
      • CVE-2019-15902
      • CVE-2019-15505
      • CVE-2019-15118
      • CVE-2019-15117
      • CVE-2019-14821
      • CVE-2019-14816
      • CVE-2019-14815
      • CVE-2019-14814
      • CVE-2018-21008
    • SMB based buffer overread if try mounting a share with version specified as 3.0 but the share itself is version 2.10 -> parameter size mismatch -> read of too much memory -> info disclosure
    • UAF in RSI 91x Wi-Fi driver -> able to be triggered by a remote network peer -> crash, DoS or possible RCE
    • ptrace spectrev1 reissue, KVM crash, Marvell Wifi Driver issues from above
    • USB audio issues from Episode 48 (Disco kernel -> now fixed in Bionic kernel as well)

    [USN-4163-1, USN-4163-2] Linux kernel vulnerabilities [09:29]

    • 10 CVEs addressed in Xenial and Trusty ESM (HWE)
      • CVE-2019-15902
      • CVE-2019-15505
      • CVE-2019-15118
      • CVE-2019-15117
      • CVE-2019-14821
      • CVE-2019-14816
      • CVE-2019-14814
      • CVE-2018-21008
      • CVE-2017-18232
      • CVE-2016-10906
    • Spectrev1 reissue, USB Audio, KVM crash, Marvell and RSI 91x WiFi Driver issues all covered earlier
    • Serial attached SCSI implementation mishandled error condition leading to deadlock -> local user could possibly trigger this leading to a DoS

    [LSN-0058-1] Linux kernel vulnerability [10:09]

    • 22 CVEs addressed in Bionic and Xenial + Xenial (HWE)
      • CVE-2019-14835
      • CVE-2019-14821
      • CVE-2019-14816
      • CVE-2019-14815
      • CVE-2019-14814
      • CVE-2019-14284
      • CVE-2019-14283
      • CVE-2019-12614
      • CVE-2019-11833
      • CVE-2019-11478
      • CVE-2019-11477
      • CVE-2019-10207
      • CVE-2019-10126
      • CVE-2019-3846
      • CVE-2019-2181
      • CVE-2019-2054
      • CVE-2019-0136
      • CVE-2018-21008
      • CVE-2018-20976
      • CVE-2018-20961
      • CVE-2018-20856
      • CVE-2016-10905
    • Most all covered in previous episodes or previously in this episode
    • 2 high priority issues
      • vhost_net issue from Episode 47
      • SACKPanic from Episode 37

    Goings on in Ubuntu Security Community

    Joe and Alex on Ubuntu 19.10 (Eoan Ermine) released but with possible local user kernel DoS bug [11:02]

    • https://twitter.com/sylvia_ritter
    • https://www.phoronix.com/scan.php?page=news_item&px=Ubuntu-19.10-Kernel-Bug
      • Mitigate by installing the latest eoan kernel update or by disabling user namspaces: sysctl user.max_user_namespaces=0

    Get in contact

    • security@ubuntu.com
    • #ubuntu-security on the Libera.Chat IRC network
    • ubuntu-hardened mailing list
    • Security section on discourse.ubuntu.com
    • @ubuntu_sec on twitter

    Episode 49 Oct 18, 2019
    Show notes

    Overview

    This week we look at updates for Sudo, Python, OpenStack Octavia and more, plus we discuss a recent CVE for Python which resulted in erroneous scientific research results, and we go over some of your feedback from Episode 48.

    This week in Ubuntu Security Updates

    27 unique CVEs addressed

    [USN-4148-1] OpenEXR vulnerabilities [00:45]

    • 8 CVEs addressed in Xenial, Bionic, Disco
      • CVE-2018-18444
      • CVE-2017-9115
      • CVE-2017-9113
      • CVE-2017-9111
      • CVE-2017-9116
      • CVE-2017-9112
      • CVE-2017-9110
      • CVE-2017-12596
    • Image format developed by ILM with a high definition range for computer imaging applications
    • Range of issues (c++ codebase)
      • OOB writes (usually only of a few bytes past the end of a buffer) - assertion failure or memory corruption -> crash / code execution
      • OOB reads (same) - crash

    [USN-4149-1] Unbound vulnerability [02:06]

    • 1 CVEs addressed in Disco
      • CVE-2019-16866
    • Validating, recursive DNS resolver
    • OOB read due to a remotely crafted NOTIFY query (source IP needs to match an ACL) -> crash

    [USN-4151-1, USN-4151-2] Python vulnerabilities [02:40]

    • 2 CVEs addressed in Precise ESM, Trusty ESM, Xenial, Bionic, Disco
      • CVE-2019-16935
      • CVE-2019-16056
    • XML-RPC server module could end up serving arbitrary JS if set via the set_server_title() method as did not escape content
    • Python email module tries to parse email address into sender + domain - if domain contains multiple @ chars could get confused and return wrong output - so applications which rely on this for validating email addresses could accept an email address which is actually invalid

    [USN-4152-1] libsoup vulnerability [03:53]

    • 1 CVEs addressed in Bionic, Disco
      • CVE-2019-17266
    • Heap buffer OOB read - fails to check the specified length of message against the actual received message - could then memcpy past the end of the input message -> crash

    [USN-4153-1] Octavia vulnerability [04:33]

    • 1 CVEs addressed in Disco
      • CVE-2019-17134
    • Amphora Images in OpenStack Octavia - fails to properly validate client certificates for management network clients -> could allow anyone with management network access to retrieve information / issue config commands

    [USN-4154-1] Sudo vulnerability [05:06]

    • 1 CVEs addressed in Precise ESM, Trusty ESM, Xenial, Bionic, Disco
      • CVE-2019-14287
    • Lots of press around a seemingly high priority privilege escalation vulnerability - BUT requires an admin to have configured sudo with a particular configuration (ie specifying a user can run a command as any other user via the ALL keyword in a Runas rule). In this case if the rule had also been configured to explicitly deny running the command as root, this could be bypassed by the user specifying a UID of -1. So would only affect a very small number of installations.

    [USN-4155-1] Aspell vulnerability [07:26]

    • 1 CVEs addressed in Precise ESM, Trusty ESM, Xenial, Bionic, Disco
      • CVE-2019-17544
    • Stack buffer over-read - found by Google’s oss-fuzz

    [USN-4156-1] SDL vulnerabilities [08:03]

    • 12 CVEs addressed in Xenial, Bionic
      • CVE-2019-7638
      • CVE-2019-7637
      • CVE-2019-7636
      • CVE-2019-7635
      • CVE-2019-7578
      • CVE-2019-7577
      • CVE-2019-7576
      • CVE-2019-7575
      • CVE-2019-7574
      • CVE-2019-7573
      • CVE-2019-7572
      • CVE-2019-13616
    • Covered all the higher priority ones in Episode 48 for SDL 2.0 - fixed now for SDL1.2 as well, plus rolled in a bunch of fixes for lower priority issues (buffer over-reads in WAV handling etc)

    Goings on in Ubuntu Security Community

    Alex and Joe talk CVEs for bad documentation and resulting scientific research? [09:20]

    • https://nvd.nist.gov/vuln/detail/CVE-2019-17514

    Feedback on desired features for 20.04 [18:53]

    • cafzo on discourse.ubuntu.com
      • encrypted home directories
      • guest-accounts

    Get in contact

    • security@ubuntu.com
    • #ubuntu-security on the Libera.Chat IRC network
    • ubuntu-hardened mailing list
    • Security section on discourse.ubuntu.com
    • @ubuntu_sec on twitter

    Episode 48 Oct 10, 2019
    Show notes

    Overview

    This week we look at security updates for the Linux kernel, SDL 2, ClamAV and more, plus Alex and Joe talk security and performance trade-offs, snaps and OWASP Top 10 Cloud Security recommendations, and finally Alex covers some recent concerns about the security of the Snap Store.

    This week in Ubuntu Security Updates

    31 unique CVEs addressed

    [USN-4142-1, USN-4142-2] e2fsprogs vulnerability [00:37]

    • 1 CVEs addressed in Precise ESM, Trusty ESM, Xenial, Bionic, Disco
      • CVE-2019-5094
    • Cisco TALOS - possible code execution via OOB write to the heap for code which handles quota support in ext4 - so possible to trigger via a specially crafted ext4 partition - could be triggered during an fsck on the partition etc.

    [USN-4143-1] SDL 2.0 vulnerabilities [01:37]

    • 5 CVEs addressed in Xenial, Bionic, Disco
      • CVE-2019-7638
      • CVE-2019-7637
      • CVE-2019-7636
      • CVE-2019-7635
      • CVE-2017-2888
    • 3 different heap based buffer over-reads -> crash, DoS
    • Heap based buffer over-write -> possible code execution or at least crash -> DoS
    • Integer overflow -> small alloc -> heap based buffer overflow -> possible code execution

    [USN-4147-1] Linux kernel vulnerabilities [02:23]

    • 18 CVEs addressed in Bionic (HWE), Disco
      • CVE-2019-15223
      • CVE-2019-15221
      • CVE-2019-15218
      • CVE-2019-15217
      • CVE-2019-9506
      • CVE-2019-15926
      • CVE-2019-15925
      • CVE-2019-15538
      • CVE-2019-15220
      • CVE-2019-15215
      • CVE-2019-15212
      • CVE-2019-15211
      • CVE-2019-15118
      • CVE-2019-15117
      • CVE-2019-15090
      • CVE-2019-13631
      • CVE-2019-10207
      • CVE-2019-0136
    • OOB read in ath6kl driver - possible to trigger remotely from the network - crash, DoS
    • Bluetooth KNOB attack
    • Crashes from malicious USB audio devices:
      • Infinite recursion when parsing device descriptors (if had multiple identical device descriptors could be triggered)
      • OOB read if specified an invalid input pin
    • OOB read in QLogic QEDI iSCSI driver
    • 2 covered in Episode 46
      • Possible code execution via a NULL pointer dereference in bluetooth UART driver - so if an attacker can map executable code at address zero can achieve code execution - in Ubuntu we have mmap_min_addr set to a non-zero value so this is mitigated by default
      • DoS in Intel wifi driver - allows a malicious client to knock a peer of the network

    [USN-4144-1] Linux kernel vulnerabilities [05:02]

    • 2 CVEs addressed in Xenial (HWE), Bionic
      • CVE-2019-15538
      • CVE-2018-20976
    • 2 different XFS issues
      • UAF triggered from a malicious XFS image -> code exection? -> crash, DoS
      • CPU based DoS if can trigger a chgrp() error due to out-of-quota

    [USN-4145-1] Linux kernel vulnerabilities [05:46]

    • 11 CVEs addressed in Xenial
      • CVE-2019-15926
      • CVE-2019-15215
      • CVE-2019-15211
      • CVE-2019-13631
      • CVE-2019-11487
      • CVE-2019-10207
      • CVE-2019-0136
      • CVE-2018-20976
      • CVE-2018-20961
      • CVE-2017-18509
      • CVE-2016-10905
    • Most covered above

    [USN-4146-1, USN-4146-2] ClamAV vulnerabilities [06:00]

    • 2 CVEs addressed in Precise ESM, Trusty ESM, Xenial, Bionic, Disco
      • CVE-2019-12900
      • CVE-2019-12625
    • Update to latest upstream version (0.101.4)
    • OOB read when handling crafted BZIP2 and ZIP files - was covered for bzip2 itself in Ubuntu in Episode 38 - vendored in clamav

    Goings on in Ubuntu Security Community

    Alex and Joe talk security and performance trade-offs, snaps and OWASP Top 10 Cloud Security recommendations [07:01]

    • https://snapcraft.io/teamtime
    • https://threatpost.com/intimate-details-healthcare-workers-exposed-cloud-security/149007/
    • https://www.owasp.org/index.php/Category:OWASP_Cloud_%E2%80%90_10_Project

    Alex addresses some concerns with the perceived security of the Snap Store [20:44]

    Get in contact

    • security@ubuntu.com
    • #ubuntu-security on the Libera.Chat IRC network
    • ubuntu-hardened mailing list
    • Security section on discourse.ubuntu.com
    • @ubuntu_sec on twitter

    Episode 47 Oct 03, 2019
    Show notes

    Overview We catch up on details of the past few weeks of security updates, including Python, curl, Linux kernel, Exim and more, plus Alex and Joe discuss the recent Ubuntu Engineering Sprint in Paris and building a HoneyBot for Admin Magazine. This week in Ubuntu Security Updates 93 unique CVEs addressed [USN-4125-1] Memcached vulnerability [00:42] 1 CVEs addressed in Xenial, Bionic, Disco CVE-2019-15026 Possible stack buffer over-read when using UNIX sockets (copies address of UNIX socket using strncpy() which could possibly read past the end of the src buffer) - possible crash -> DoS - fixed to explicitly limit length to smallest of src/dst buffers rather than just size of dest buffer [USN-4126-1] FreeType vulnerability [01:49] 1 CVEs addressed in Precise ESM, Trusty ESM, Xenial CVE-2015-9383 2 CVEs addressed in Precise ESM, Trusty ESM only CVE-2015-9382 CVE-2015-9381 All various heap based buffer over-reads - crash -> DoS [USN-4127-1, USN-4127-2] Python vulnerabilities [02:13] 8 CVEs addressed in Precise ESM, Trusty ESM, Xenial, Bionic, Disco CVE-2019-9948 CVE-2019-9947 CVE-2019-9740 CVE-2019-5010 CVE-2019-10160 CVE-2019-9636 CVE-2018-20852 CVE-2018-20406 4 issues in urllib: would allow to easily open files from local file-system 2 different CRLF injection issues specially crafted URL could cause urllib to send cookies / auth data for wrong host Fixed incorrectly upstream so had a two CVEs assigned http cookiejar wouldn’t validate URL correctly so could also send cookies for another domain Possible NULL ptr deref when parsing X509 certs if had an empty CRL distpoint / URI Possible integer overflow when serializing a tens of hundreds of gigabytes of data via the pickle format - could cause memory exhaustion [USN-4128-1, USN-4128-2] Tomcat vulnerabilities [03:35] 3 CVEs addressed in Xenial, Bionic (tomcat-8) and Bionic, Disco (tomcat-9) CVE-2019-10072 CVE-2019-0199 CVE-2019-0221 HTTP/2 server would accept streams with an excessive number of SETTINGS frames and would permit clients to keep streams open without reading / writing anything - could lead to DoS by causing server-side threads to block Original fix was incomplete - so got a second CVE Possible XSS injection if using SSI printenv command as would echo user provided data without escaping - intended only for debugging so shouldn’t be used in a production website anyway [USN-4120-2] systemd regression [04:45] Affecting Bionic, Disco Episode 46 - systemd-resolved dbus access control - the update was prepared using a pending SRU update - but this contained a regression in networking - re-released the security fix but without this SRU update included. [USN-4115-2] Linux kernel regression [05:18] Affecting Xenial (HWE), Bionic Recent kernel update (Episode 46) could possibly crash on handling fragmented packets [USN-4129-1, USN-4129-2] curl vulnerabilities [05:42] 1 CVEs addressed in Precise ESM, Trusty ESM, Xenial, Bionic, Disco CVE-2019-5482 Heap buffer overflow in TFTP protocol handler 1 extra CVEs addressed in Xenial, Bionic, Disco CVE-2019-5481 Double free in FTP-kerberos code [USN-4130-1] WebKitGTK+ vulnerabilities [06:15] 16 CVEs addressed in Bionic, Disco CVE-2019-8690 CVE-2019-8689 CVE-2019-8688 CVE-2019-8687 CVE-2019-8684 CVE-2019-8683 CVE-2019-8681 CVE-2019-8680 CVE-2019-8678 CVE-2019-8676 CVE-2019-8673 CVE-2019-8669 CVE-2019-8666 CVE-2019-8658 CVE-2019-8649 CVE-2019-8644 Update to latest WebKitGTK upstream release (2.24.4) [USN-4131-1] VLC vulnerabilities [06:38] 11 CVEs addressed in Bionic, Disco CVE-2019-14970 CVE-2019-14778 CVE-2019-14777 CVE-2019-14776 CVE-2019-14535 CVE-2019-14534 CVE-2019-14533 CVE-2019-14498 CVE-2019-14438 CVE-2019-14437 CVE-2019-13962 Update to latest VLC upstream release (3.0.8) [USN-4133-1] Wireshark vulnerabilities [06:48] 2 CVEs addressed in Xenial, Bionic, Disco CVE-2019-13619 CVE-2019-12295 Update to latest upstream release (2.6.10-1) [USN-4132-1, USN-4132-2] Expat vulnerability [06:55] 1 CVEs addressed in Precise ESM, Trusty ESM, Xenial, Bionic, Disco CVE-2019-15903 Crafted XML could fool the parser to switch to document parsing too early (whilst still in DTD) - could then result in a heap-based buffer over-read when looking up current line / column number - possible crash -> DoS [USN-4134-1] IBus vulnerability [07:30] 1 CVEs addressed in Xenial, Bionic, Disco CVE-2019-14822 Failed to apply access controls to D-Bus server socket - could allow another local user to connect to logged in local user’s IBus daemon and snoop on keystrokes etc Attacker needs to know IBus socket address which is randomised and not easily discoverable [USN-4134-2] IBus regression [08:00] Affecting Xenial, Bionic, Disco Regressed for Qt users - Qt seems unable to connect to IBus socket - so reverted [USN-4124-2] Exim vulnerability [08:25] 1 CVEs addressed in Trusty ESM CVE-2019-15846 Episode 46 - high profile possible remote root exploit [USN-4113-2] Apache HTTP Server regression [08:38] Affecting Xenial, Bionic, Disco Episode 45 - HTTP/2 DoS issues - update caused a regression when proxying balance manager connections - fixed by incorporating missing upstream patches [USN-4135-1, USN-4135-2] Linux kernel vulnerabilities [09:01] 3 CVEs addressed in Precise ESM, Trusty ESM, Xenial, Bionic, Disco CVE-2019-15031 CVE-2019-15030 CVE-2019-14835 Possible host privilege escalation from a libvirt guest (guest user needs to be privileged) 2 related info disclosures on PowerPC - local user could possibly read vector registers of other users’ processes either during an interrupt or via a facility unavailable exception [LSN-0056-1] Linux kernel vulnerability [09:51] 1 CVEs addressed in Xenial, Bionic CVE-2019-14835 Livepatch notification of above libvirt host privesc [USN-4136-1, USN-4136-2] wpa_supplicant and hostapd vulnerability [10:06] 1 CVEs addressed in Precise ESM, Trusty ESM, Xenial, Bionic, Disco CVE-2019-16275 Attacker in radio range could cause a station to disconnect by sending a specially crafted management frame (since would not properly validate the source address of the frame) [USN-4137-1] Mosquitto vulnerability [10:44] 1 CVEs addressed in Disco CVE-2019-11779 Stack overflow if a malicious client sends a SUBSCRIBE with a topic of ~65k ‘/’ characters [USN-4138-1] LibreOffice vulnerability [10:56] 1 CVEs addressed in Xenial, Bionic, Disco CVE-2019-9854 Episode 44 - able to bypass protections added to try and stop inclusion of code on local file-system in macros etc via URL encoding [USN-4139-1] File Roller vulnerability [11:18] 1 CVEs addressed in Xenial, Bionic CVE-2019-16680 Path traversal outside of CWD to parent [USN-4140-1] Firefox vulnerability [11:33] 1 CVEs addressed in Xenial, Bionic, Disco CVE-2019-11754 Latest upstream release (69.0.1) - pointer lock able to be enabled without any notification to user - could allow a malicious website to hijack mouse cursor and confuse user [USN-4141-1] Exim vulnerability [11:54] 1 CVEs addressed in Disco CVE-2019-16928 Heap-based buffer overflow - could possibly allow remote code execution - was announced on Saturday 28th - thanks Marc for the quick update :) Goings on in Ubuntu Security Community Joe and Alex talk about the Paris Engineering Sprint and Joe’s recent article in Admin Magazine [12:42] http://www.admin-magazine.com/Articles/Build-a-honeypot-with-real-world-alerts?utm_source=AMTW https://github.com/joemcmanus/honeybot New security category on discourse.ubuntu.com [25:52] https://discourse.ubuntu.com/c/security Created to allow discussion of security relevant Ubuntu topics and issues in a more user-friendly and centralised location Will be used in addition to the existing ubuntu-hardened mailing list and #ubuntu-hardened IRC channel Get in contact security@ubuntu.com #ubuntu-security on the Libera.Chat IRC network ubuntu-hardened mailing list Security section on discourse.ubuntu.com @ubuntu_sec on twitter

    Full show notes at the publisher

    Episode 46 Sep 12, 2019
    Show notes

    Overview A massive 85 CVEs addressed this week, including updates for Exim, the Linux Kernel, Samba, systemd and more, plus we discuss hacking BMCs via remote USB devices and password stashes. This week in Ubuntu Security Updates 85 unique CVEs addressed [USN-4124-1] Exim vulnerability [00:49] 1 CVEs addressed in Xenial, Bionic, Disco CVE-2019-15846 When doing TLS negotiation, parses the Server Name Indication headers - would try and handle escape sequences in this string. Does so by looking at the character after a backslash to determine what escape sequence is (\b etc) and then returns that actual value (in string_interpret_escape()) This gets called by the function string_unprinting() which is used to translate escaped characters into their proper form in a new string - and this will run over the bounds of the original string if it ends with a backslash - since string_interpret_escape() would assume there was contents afterwards to interpret Qualsys were able to develop a PoC which leverages this OOB behaviour into a remote root exploit (since this part of the code runs as root and they were able to use a combination of heap corruption and OOB writes to get code execution) Fixed to first check if reached end of string (NUL) before trying to handle the escaped character Able to be mitigated by setting ACLs to deny connections which contain a trailing backslash in the SNI field - see CVE-2019-15846 in the Ubuntu CVE Tracker Lots of press coverage: https://www.zdnet.com/article/millions-of-exim-servers-vulnerable-to-root-granting-exploit/ https://threatpost.com/critical-exim-flaw-opens-millions-of-servers-to-takeover/148108/ https://www.theregister.co.uk/2019/09/06/exim_vulnerability_patch/ https://www.bleepingcomputer.com/news/security/critical-exim-tls-flaw-lets-attackers-remotely-execute-commands-as-root/ [USN-4114-1] Linux kernel vulnerabilities [03:49] 5 CVEs addressed in Bionic (HWE), Disco CVE-2019-3900 Infinite loop in virtio network driver - guest VM cause host DoS by stalling vhost_net kernel thread CVE-2019-14284 Divide by zero in floppy driver ioctl() handler (created by default by qemu) CVE-2019-14283 Integer overflow and OOB read in floppy driver CVE-2019-13648 DoS for PowerPC if user calls sigreturn() with crafted signal stack frame - exception and system crash (requires transactional memory to be disabled) CVE-2019-10638 Kernel tries to randomise IP ID values (used for de-fragmentation of IP packets) for connection-less protocols to avoid tracking Is meant to be random across source + dest address + protocol But if an attacker can observe traffic to multiple hosts, can infer the hashing key used to generate the ID values And then can associate different streams of packets back to the same source host and hence can track devices Fixed to used an actual random value for the base of the hash and use a better hashing algorithm (siphash) for ID generation [USN-4115-1] Linux kernel vulnerabilities [06:42] 28 CVEs addressed in Xenial (HWE), Bionic 5 negligible (not enabled by default), 11 low (very unlikely to trigger - module unload after proc initialization failure etc), 12 medium CVE-2019-3819 CVE-2019-3701 CVE-2019-15221 CVE-2019-15218 CVE-2019-15216 CVE-2019-9506 Bluetooth KNOB attack CVE-2019-3900 Infinite loop in virtio net driver (guest VM cause host DoS) CVE-2019-15292 CVE-2019-15220 CVE-2019-15215 CVE-2019-15214 CVE-2019-15212 CVE-2019-15211 CVE-2019-15090 OOB read in debug functions of QLogic QEDI iSCSI Initiator Driver (allows to read kernel memory - KASLR defeat?) CVE-2019-14763 CVE-2019-14284 See above (Divide by zero in floppy driver) CVE-2019-14283 See above (Integer overflow and OOB read in floppy driver) CVE-2019-13648 See above (PowerPC DoS on sigreturn()) CVE-2019-13631 CVE-2019-11810 CVE-2019-11599 Core dump race (Episode 41) CVE-2019-11487 CVE-2019-10639 Related to CVE-2019-10638 - since used base address of kernel structure in memory as hash base, could allow attacker to infer this address and so defeat KASLR CVE-2019-10638 See above (IP ID randomisation) CVE-2019-10207 NULL pointer address execution (call function pointer which is NULL since is not initializated) - Ubuntu defaults to a non-zero mmap_min_addr value which means can’t map a page at 0 address so this is just a NULL pointer dereference in default config (otherwise is arbitrary kernel code execution) CVE-2019-0136 Intel Wifi Driver Tunneled Direct Link Setup (allows devices to communicate directly with one-another on the same network without going via AP) - flaw allows a peer to cause wifi disconnection (DoS) CVE-2018-20784 Infinite loop in CFS schedular - DoS CVE-2018-19985 [USN-4116-1] Linux kernel vulnerabilities [09:12] 6 CVEs addressed in Xenial CVE-2019-3900 Infinite loop in virtio net driver (guest VM cause host DoS) CVE-2019-14284 See above (Divide by zero in floppy driver) CVE-2019-14283 See above (Integer overflow and OOB read in floppy driver) CVE-2019-13648 See above (PowerPC DoS on sigreturn()) CVE-2019-10638 See above (IP ID randomisation) CVE-2018-20856 UAF in block-layer under particular failure conditions [USN-4117-1] Linux kernel (AWS) vulnerabilities [09:43] 9 CVEs addressed in Disco CVE-2019-3900 Infinite loop in virtio net driver (guest VM cause host DoS) CVE-2019-3846 Marvell Wifi OOB write (Episode 43) CVE-2019-10126 Marvell Wifi OOB write (Episode 43) CVE-2019-14284 See above (Divide by zero in floppy driver) CVE-2019-14283 See above (Integer overflow and OOB read in floppy driver) CVE-2019-13272 ptrace race (Episode 43) CVE-2019-13233 UAF in handling of x86 LDT entries (Episode 43) CVE-2019-12984 NULL ptr dereference in NFC subsystem (Episode 43) CVE-2019-10638 See above (IP ID randomisation) [USN-4118-1] Linux kernel (AWS) vulnerabilities [10:17] 61 CVEs addressed in Xenial, Bionic CVE-2019-3819 CVE-2019-3701 CVE-2019-15221 CVE-2019-15218 CVE-2019-15216 CVE-2018-20511 CVE-2019-9506 CVE-2019-3900 CVE-2019-3846 CVE-2019-2101 CVE-2019-2024 CVE-2019-15292 CVE-2019-15220 CVE-2019-15215 CVE-2019-15214 CVE-2019-15212 CVE-2019-15211 CVE-2019-15090 CVE-2019-14763 CVE-2019-14284 CVE-2019-14283 CVE-2019-13631 CVE-2019-13272 CVE-2019-13233 CVE-2019-12984 CVE-2019-12819 CVE-2019-12818 CVE-2019-11884 CVE-2019-11833 CVE-2019-11815 CVE-2019-11810 CVE-2019-11599 CVE-2019-11487 CVE-2019-11085 CVE-2019-10639 CVE-2019-10638 CVE-2019-10207 CVE-2019-10126 CVE-2019-0136 CVE-2018-5383 CVE-2018-20856 CVE-2018-20784 CVE-2018-20169 CVE-2018-19985 CVE-2018-16862 CVE-2018-14617 CVE-2018-14613 CVE-2018-14612 CVE-2018-14611 CVE-2018-14610 CVE-2018-14609 CVE-2018-14616 CVE-2018-14615 CVE-2018-14614 CVE-2018-13100 CVE-2018-13099 CVE-2018-13098 CVE-2018-13097 CVE-2018-13096 CVE-2018-13093 CVE-2018-13053 [USN-3934-2] PolicyKit vulnerability [10:36] 1 CVEs addressed in Precise ESM CVE-2019-6133 Episode 27 - PolicyKit could get confused via PID reuse - fix was 2 parts - 1 kernel to ensure can’t race kernel on PID assignment, and second was in PolicyKit itself to check on PID, UID and start time. [USN-4119-1] Irssi vulnerability [11:23] 1 CVEs addressed in Disco CVE-2019-15717 UAF if server sends two CAP commands (used by client and server to negotiate capabilities - ie sasl support etc) [USN-4121-1] Samba vulnerability [11:52] 1 CVEs addressed in Disco CVE-2019-10197 Possible directory share escape by unauthenticated users - allows attackers to gain access to the host filesystem outside the share root (limited as per underlying file-system permissions) Needs the server to have explicitly enabled ‘wide links’ and not be using ‘unix extensions’ OR to have also set ‘allow insecure wide links’ [USN-4120-1] systemd vulnerability [12:40] 1 CVEs addressed in Bionic, Disco CVE-2019-15718 systemd-resolved failed to properly setup access controls on its DBus server socket, whic allows unprivileged users to execute DBus methods that should only be executable by privileged users - such as changing the systems DNS resolver settings [USN-4122-1] Firefox vulnerabilities [13:10] 17 CVEs addressed in Xenial, Bionic, Disco CVE-2019-11747 CVE-2019-11741 CVE-2019-9812 CVE-2019-11752 CVE-2019-11750 CVE-2019-11749 CVE-2019-11748 CVE-2019-11746 CVE-2019-11744 CVE-2019-11743 CVE-2019-11742 CVE-2019-11740 CVE-2019-11738 CVE-2019-11737 CVE-2019-11735 CVE-2019-11734 CVE-2019-5849 Upstream Firefox 69.0 release https://www.mozilla.org/en-US/security/advisories/mfsa2019-25/ [USN-4123-1] npm/fstream vulnerability [13:29] 1 CVEs addressed in Bionic, Disco CVE-2019-13173 Goings on in Ubuntu Security Community Joe and Alex discuss hacking BMCs via a remote USN attack [13:53] https://thehackernews.com/2019/09/hacking-bmc-server.html Joe and Alex also discuss password stashes [20:33] Get in contact security@ubuntu.com #ubuntu-security on the Libera.Chat IRC network @ubuntu_sec on twitter

    Full show notes at the publisher

    Episode 45 Sep 04, 2019
    Show notes

    Overview

    This week we look at security updates for Dovecot, Ghostscript, a livepatch update for the Linux kernel, Ceph and Apache, plus Alex and Joe discuss recent Wordpress plugin vulnerabilities and the Hostinger breach, and more.

    This week in Ubuntu Security Updates

    22 unique CVEs addressed

    [USN-4110-1, USN-4110-2] Dovecot vulnerability [00:52]

    • 1 CVEs addressed in Precise ESM, Trusty ESM, Xenial, Bionic, Disco
      • CVE-2019-11500
    • IMAP and ManageSieve protocol parsers would not check for embedded NUL bytes in strings
      • When parsing these strings, would return indexes outside the normal string bounds as the first character which needed unescaping
      • Would then go and try to unescape the string from this index, which rewrites the string on the fly, and so would then go and rewrite outside the bounds of the string
      • Fixed to disallow embedded NUL bytes AND to not try and skip up to first unescaped character but instead loop over the whole string in unescaping

    [USN-4110-3, USN-4110-4] Dovecot regression [02:08]

    • 1 CVEs addressed in Precise ESM, Trusty ESM, Xenial, Bionic, Disco
      • CVE-2019-11500
    • Original patch used pre-release version of the fix from upstream which contained an error such that the checking of NUL bytes was skipped - re-released with correct final upstream fix

    [LSN-0054-1] Linux kernel vulnerability [02:38]

    • 9 CVEs addressed in Xenial, Bionic
      • CVE-2018-1129
      • CVE-2019-13272
      • CVE-2019-12984
      • CVE-2019-12819
      • CVE-2019-12818
      • CVE-2019-12614
      • CVE-2019-10126
      • CVE-2019-3846
      • CVE-2019-2101
    • Livepatch for CVEs addressed in regular kernel updates (Episode 43)
      • ptrace credentials race, Marvell Wifi heap-buffer overflows, NULL pointer dereferences

    [USN-4111-1] Ghostscript vulnerabilities [03:20]

    • 4 CVEs addressed in Xenial, Bionic, Disco
      • CVE-2019-14817
      • CVE-2019-14813
      • CVE-2019-14812
      • CVE-2019-14811
    • Four more -dSAFER sandbox bypasses (see Episode 43 for the last one)
    • All variations on the theme of using the .forceput operator to escape the sandbox

    [USN-4112-1] Ceph vulnerability [04:01]

    • 1 CVEs addressed in Bionic, Disco
      • CVE-2019-10222
    • DoS - unauthenticated clients can crash the rados gateway by disconnecting at certain time (triggering a NULL pointer deference when looking up the remote address for a connected client)
      • Older versions are not affected since this is in the beast RGW frontend - which is not in the versions in trusty / xenial - and only in the bionic version as an experimental feature

    [USN-4113-1] Apache HTTP Server vulnerabilities [04:41]

    • 7 CVEs addressed in Xenial, Bionic, Disco

      • CVE-2019-9517
      • CVE-2019-10098
      • CVE-2019-10097
      • CVE-2019-10092
      • CVE-2019-10082
      • CVE-2019-10081
      • CVE-2019-0197
    • HTTP/2 DoS issue (Internal Data Buffering) - Episode 43 for nginx

      • https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/http2
    • Open redirect in mod_rewrite if have self-referential redirects

    • Stack buffer overflow + NULL pointer dereference in mod_remoteip

    • Possible XSS in mod_proxy where the link shown on error pages could be controlled by an attacker - but only possible where configured with proxying enable but misconfigured so that Proxy Error page is shown.

    • UAF (read) during HTTP/2 connection shutdown

    • HTTP/2 push - allows server to send resources to a client before it requests them - could overwrite memory of the server’s request pool - this is preconfigured and not under control of client but could cause a crash etc.

    • HTTP/2 upgrade - can configure to automatically upgrade HTTP/1.1 requests to HTTP/2 - but if this was not the first request on the connection could lead to crash

    Goings on in Ubuntu Security Community

    Alex and Joe talk Wordpress plugin vulnerabiliies and Hostinger password breach [07:03]

    • https://threatpost.com/wordpress-plugins-exploited-in-ongoing-attack-researchers-warn/147671/
    • https://www.zdnet.com/article/hostinger-resets-customer-passwords-after-security-incident/
    • https://www.nccgroup.trust/us/about-us/newsroom-and-events/blog/2009/july/if-youre-typing-the-letters-a-e-s-into-your-code-youre-doing-it-wrong/

    OpenSSL 1.1.1 with TLS 1.3 support complete for Ubuntu 18.04 LTS (Bionic) [17:29]

    • OpenSSL upgraded to version 1.1.1 in Ubuntu 18.04 LTS - supports TLS 1.3 - now published via -updates and -security

    Get in contact

    • security@ubuntu.com
    • #ubuntu-security on the Libera.Chat IRC network
    • @ubuntu_sec on twitter

    Episode 44 Aug 26, 2019
    Show notes

    Overview

    This week Joe and Alex discuss a recently disclosed backdoor in Webmin, plus we cover security updates from the past week, including for Nova, KDE, LibreOffice, Docker, CUPS and more.

    This week in Ubuntu Security Updates

    21 unique CVEs addressed

    [USN-4100-1] KConfig and KDE libraries vulnerabilities [00:46]

    • 2 CVEs addressed in Xenial, Bionic, Disco
      • CVE-2016-6232
      • CVE-2019-14744
    • Directory traversal in KArchive via ../
    • RCE via malicious .desktop file - contianed extra functionality outside of XDG spec, where could contain shell commands that would get expanded - so if you view a .desktop file in Dolphin, and the Icon property contained shell commands, this would get evaluated - so wouldn’t need to interact at all - upstream now removed this ‘feature’

    [USN-4102-1] LibreOffice vulnerabilities [02:45]

    • 3 CVEs addressed in Xenial, Bionic, Disco
      • CVE-2019-9852
      • CVE-2019-9851
      • CVE-2019-9850
    • Docs can have macros & scripts on action - document-open, mouse-over
      • Should only be for scripts shipped in libreoffice itself
      • Path bypass in CVE-2018-16858 - so added more protections
      • Could be bypassed again with URL encoding - so fix again
    • Second LibreLogo issue (Episode 40) - could bypass previous protections again - was fixed upstream but found to still be inadequate - hence 2 CVEs for this (incomplete fix the first time around)

    [USN-4078-2] OpenLDAP vulnerabilities [04:26]

    • 2 CVEs addressed in Precise ESM, Trusty ESM
      • CVE-2019-13565
      • CVE-2019-13057
    • Episode 41 for regular releases - now ESM as well

    [USN-4103-1, USN-4103-2] docker-credential-helpers and Docker vulnerabilities [04:52]

    • 1 CVEs addressed in Disco (docker-credential-helpers)
    • 1 CVEs addressed in Xenial, Bionic, Disco (docker)
      • CVE-2019-1020014
    • golang-docker-credentials package had a double-free which could be triggered via a local user -> crash, DoS
    • Bundled with docker.io package so update both

    [USN-4104-1] Nova vulnerability [05:28]

    • 1 CVEs addressed in Xenial, Bionic, Disco
      • CVE-2019-14433
    • API requests which end in fault conditions from authenticated users could result in keys or other details being leaked / returned in responses to further API requests (not just any error / fault but say if tried to hard-reboot and this fails) - fixed to sanitize any possible details out of faults

    [USN-4105-1] CUPS vulnerabilities [06:30]

    • 2 CVEs addressed in Xenial, Bionic, Disco
      • CVE-2019-8675
      • CVE-2019-8696
    • SNMP backend - parses ASN.1 encoded data - can be used to automatically get status from printers etc - would not do bounds checking on actual encoded ASN.1 data vs the description of it - so could easily get a stack buffer overflow - fixed to add bounds checking
    • Also includes some other upstream fixes for potential security issues (without CVEs), including a CPU based DoS if a cups client unexpectedly disconnected

    [USN-4106-1] NLTK vulnerability [07:37]

    • 1 CVEs addressed in Xenial, Bionic, Disco
      • CVE-2019-14751
    • Python Natural Language Toolkit - downloads datasets as ZIP compressed
    • Mike Salvatore - ZipSlip
    • https://salvatoresecurity.com/zip-slip-in-nltk-cve-2019-14751/
    • Fixed to use inbuilt python zipfile handling to unzip rather than custom implementation

    [USN-4107-1] GIFLIB vulnerabilities [08:35]

    • 3 CVEs addressed in Xenial, Bionic, Disco
      • CVE-2019-15133
      • CVE-2018-11490
      • CVE-2016-3977
    • Common library used for handling GIF images (openjdk, ffmpeg, gstreamer, kde)
    • Divide-by-zero
    • 2 different heap based buffer overflows - one was originally fixed in Debian but the patch for it got dropped in a later release - so we have repatched that

    [USN-4108-1] Zstandard vulnerability [09:20]

    • 1 CVEs addressed in Bionic
      • CVE-2019-11922
    • Common library (maintained by Facebook) for handling the zstd compression algorithm
    • Race condition when using single-pass compression, might allow attacker to get OOB write IF the caller had provided a smaller output buffer than the recommended size
    • So likely won’t affect all packages which use zstd (there are many) - should always follow best practice

    [USN-4109-1] OpenJPEG vulnerabilities [10:11]

    • 5 CVEs addressed in Bionic
      • CVE-2018-6616
      • CVE-2018-5785
      • CVE-2018-18088
      • CVE-2018-14423
      • CVE-2017-17480
    • 4 different DoS issues:
      • 2 in BMP handling:
        • CPU based DoS due to inefficient algorithm implementation
        • Integer overflow -> OOB read -> DoS
      • NULL pointer dereference when converting to PNM
      • Divide by zero
    • Stack based buffer overflow when handling JP3D encoded data - OOB write - DoS / RCE

    Goings on in Ubuntu Security Community

    Joe and Alex discuss webmin backdoor [11:21]

    • http://www.webmin.com/exploit.html

    Get in contact [21:45]

    • security@ubuntu.com
    • #ubuntu-security on the Libera.Chat IRC network
    • @ubuntu_sec on twitter

    Previous 1 18 19 20 21 22 25 Next

    Related Podcasts

    Reply All

    1

    Reply All Games & Hobbies
    Inside VR & AR

    2

    Inside VR & AR Gadgets
    Note to Self

    3

    Note to Self News
    BrainStuff

    4

    BrainStuff Natural Sciences
    This Week in Tech (Audio)

    5

    This Week in Tech (Audio) News
    Hands-On Tech (Audio)

    6

    Hands-On Tech (Audio) Technology
    footer-logo

    Contact Us

    Toll Free: 844-670-7747

    Links

    • Home
    • Top Charts
    • Networks
    • Apps
    • Independents Podcasts
    • Podcast Advertising
    • Podcast News
    • Contact Us
    • About Us
    • Analytics & Insights

    Stay Connected

      Privacy, Terms of Use & Our Code of Ethics Protecting Content Creators Copyrights