TopPodcast.com
Menu
  • Home
  • Top Charts
  • Top Networks
  • Top Apps
  • Top Independents
  • Top Podfluencers
  • Top Picks
    • Top Business Podcasts
    • Top True Crime Podcasts
    • Top Finance Podcasts
    • Top Comedy Podcasts
    • Top Music Podcasts
    • Top Womens Podcasts
    • Top Kids Podcasts
    • Top Sports Podcasts
    • Top News Podcasts
    • Top Tech Podcasts
    • Top Crypto Podcasts
    • Top Entrepreneurial Podcasts
    • Top Fantasy Sports Podcasts
    • Top Political Podcasts
    • Top Science Podcasts
    • Top Self Help Podcasts
    • Top Sports Betting Podcasts
    • Top Stocks Podcasts
  • Podcast News
  • About Us
  • Podcast Advertising
  • Contact
Not in our directory?
Add Show Here
Podcast Equipment
Center

toppodcastlogoOur TOPPODCAST Picks

  • Comedy
  • Crypto
  • Sports
  • News
  • Politics
  • True Crime
  • Business
  • Finance

Follow Us

toppodcastlogoStay Connected

    View Top 200 Chart
    Back to Rankings Page
    Technology

    Ubuntu Security Podcast

    A fortnightly podcast talking about the latest developments and updates from the Ubuntu Security team, including a summary of recent security vulnerabilities and fixes as well as a discussion on some of the goings on in the wider Ubuntu Security community.

    Advertise

    Copyright: © Copyright 2019 Canonical

    • Apple Podcasts
    • Google Play
    • Spotify

    Latest Episodes:
    Episode 23 Mar 12, 2019
    Show notes

    Overview

    This week we look at security updates for the Linux kernel, PHP and NVIDIA drivers, revealing recent research into GPU based side-channel attacks plus we call for suggestions on hardening features and more.

    This week in Ubuntu Security Updates

    10 unique CVEs addressed

    [USN-3885-2] OpenSSH vulnerability

    • 1 CVEs addressed in Trusty, Xenial, Bionic, Cosmic
      • CVE-2019-6111
    • Originally covered in Episode 20 (malicious server could overwrite local client files)
    • Previous fix was incomplete - missing a patch

    [USN-3901-1, USN-3901-2] Linux kernel vulnerabilities

    • 3 CVEs addressed in Bionic, Trusty & Xenial (Bionic HWE kernel)
      • CVE-2019-6133
      • CVE-2018-19854
      • CVE-2018-18397
    • 2 out of 3 from Jann Horn
      • PolicyKit provides ability to authorise an application to perform privileged actions

      • Pops up dialog for use to authorise via password - PolicyKit then caches that authorisation (5mins)

      • To identify same process in future, would look at both the PID and process start time to guard against PID reuse etc

      • However, fork() system call is not atomic, so attacked could call sys_clone() at same time as real process so it has the same start time. Can then cause kernel to block on returning back to the attacker process, effectively racing against the real process waiting for it to end, in the meantime blocking PID allocation until it has cycled around and end up with the same (reused) PID as the original authorised process (and with same start time) - so can effectively fool PolicyKit into impersonating the real process

      • Fix kernel to make fork() atomic rather than try fix PolicyKit since can’t effectively do this at the process level

      • Kernel fixed to record process start time later in procedure so is much closer to when the process is visible to userspace and after userspace has a chance to delay it to mitigate this

      • Jann also discovered that userfaultfd does not properly handle access control for certain ioctl() - which allowed local users to write data into holes in a tmpfs file, even if the user only had read-only access to the file

    • crypto subsystem would leak uninitialized stack memory to userspace
      • Occurred from a recent change to convert strncpy() to strlcpy() used to copy strings into various crypto buffers
      • strncpy() does not guarantee NULL termination so strlcpy() was used which does - HOWEVER, strncpy() would NULL pad out remaining bytes if buffer was longer than string - whereas strlcpy() would only NULL the first one - and so would have uninitialised bytes remaining
      • Fixed by changing back to strncpy()

    [USN-3903-1, USN-3903-2] Linux kernel vulnerabilities

    • 3 CVEs addressed in Cosmic & Bionic (Cosmic HWE kernel)
      • CVE-2019-6133
      • CVE-2018-18397
      • CVE-2018-16880
    • fork() start time and userfaultfd issues described earlier for the Bionic kernel update
    • Out of bounds write in vhost_net driver used by virtualized guests - allows guest to corrupt host kernel memory -> host crash -> DoS, or possible arbitrary code execution in host kernel

    [USN-3902-1] PHP vulnerabilities

    • 5 CVEs addressed in Trusty, Xenial
      • CVE-2019-9023
      • CVE-2019-9022
      • CVE-2019-9021
      • CVE-2019-9024
      • CVE-2019-9020
    • All allow a remote attacker to crash PHP -> DoS
    • 2 in XML-RPC module - remote procedure call via XML - used for various wiki backends etc - heap OOB read / UAF
    • 1 in PHAR (PHP Archive) module - incorrect handling of filenames - crash via upload of crafted PHAR archive due to a heap based buffer over-read
    • 1 in DNS handling (only affects PHP in Xenial) - remote attacker who can control returned DNS response could crash PHP due to buffer over-read on memcpy()
    • 1 in mbstring regular expression - multiple heap based buffer over-reads in handling of multibyte sequences in regular expressions

    [USN-3904-1] NVIDIA graphics drivers vulnerability

    • 1 CVE addressed in Bionic, Cosmic
      • CVE-2018-6260
    • Recent research into GPU side-channel attacks
      • Rendered Insecure: GPU Side Channel A!acks are Practical
    • Local users could access GPU performance counters without special privileges
    • Allows to characterise the GPU workload to fingerprint websites etc being rendered
    • Now requires administrator privileges to access so unable to be done from a regular user

    Goings on in Ubuntu Security Community

    Ubuntu Hardening Guide

    • Ubuntu tries to offer a usable, hardened approach out of the box
      • No open ports, various kernel and compiler hardening options etc
    • Thinking about publishing a hardening guide that goes beyond the defaults
    • Welcome suggestions from the community

    Hiring

    Ubuntu Security Generalist

    • https://boards.greenhouse.io/canonical/jobs/1548812

    Robotics Security Engineer

    • https://boards.greenhouse.io/canonical/jobs/1550997

    Get in contact

    • security@ubuntu.com
    • #ubuntu-security on the Libera.Chat IRC network
    • @ubuntu_sec on twitter

    Episode 22 Mar 04, 2019
    Show notes

    Overview

    This week we cover security updates including Firefox, Thunderbird, OpenSSL and another Ghostscript regression, plus we look at a recent report from Capsule8 comparing Linux hardening features across various distributions and we answer some listener questions.

    This week in Ubuntu Security Updates

    16 unique CVEs addressed

    [USN-3893-2] Bind vulnerabilities

    • 2 CVEs addressed in Precise ESM
      • CVE-2019-6465
      • CVE-2018-5745
    • Covered last week in Episode 21 for regular Ubuntu releases

    [USN-3866-3] Ghostscript regression

    • Affecting Trusty, Xenial, Bionic, Cosmic
    • Mentioned last week briefly
    • Previous update to Ghostscript introduced a regression (blue background)
      • See later for information

    [USN-3894-1] GNOME Keyring vulnerability

    • 1 CVEs addressed in Trusty, Xenial
      • CVE-2018-20781
    • Already fixed upstream (hence doesn’t apply to Bionic / Cosmic etc)
    • User’s login password kept in memory of child process after pam session is opened
    • Could be dumped by root user or captured in crash dump etc and possibly exposed
      • Other tools exist to try and extract from memory as well (minipenguin etc)
    • Fix is to simply reset this after pam session is opened

    [USN-3895-1] LDB vulnerability

    • 1 CVEs addressed in Trusty, Xenial, Bionic, Cosmic
      • CVE-2019-3824
    • LDAP-like embedded database (used by Samba and others)
    • Authenticated user can cause OOB read when searching LDAP backend of AD DC with a search string containing multiple wildcards - crash -> DoS

    [USN-3896-1] Firefox vulnerabilities

    • 3 CVEs addressed in Trusty, Xenial, Bionic, Cosmic
      • CVE-2019-5785
      • CVE-2018-18511
      • CVE-2018-18356
    • Firefox 65
    • Use-after-free and integer overflow in Skia library (vector graphics library, similar to cairo)
    • Cross-origin image theft - able to read from canvas element in violation of same-origin policy using transferFromImageBitmap() method

    [USN-3897-1] Thunderbird vulnerabilities

    • 7 CVEs addressed in Trusty, Xenial, Bionic, Cosmic
      • CVE-2018-18509
      • CVE-2018-18505
      • CVE-2018-18501
      • CVE-2019-5785
      • CVE-2018-18500
      • CVE-2018-18356
      • CVE-2016-5824
    • Thunderbird 60.5.1
    • Use-after-free and integer overflow in Skia library (vector graphics library, similar to cairo)
    • Show messages with an invalid (reused) S/MIME signature as being verified
    • UAF parsing HTML5 stream with custom HTML elements
    • UAF in embedded libical via a crafted ICS file

    [USN-3898-1, USN-3898-2] NSS vulnerability

    • 1 CVEs addressed in Precise ESM, Trusty, Xenial, Bionic, Cosmic
      • CVE-2018-18508
    • Several NULL pointer dereferences -> crash -> DoS

    [USN-3899-1] OpenSSL vulnerability

    • 1 CVEs addressed in Xenial, Bionic, Cosmic
      • CVE-2019-1559
    • Possible padding oracle (an application which uses OpenSSL could behave differently based on whether a record contained valid padding or not)
      • Attacker can learn plaintext by modifying ciphertext and observing different behaviour

    [USN-3900-1] GD vulnerabilities

    • 2 CVEs addressed in Trusty, Xenial, Bionic, Cosmic
      • CVE-2019-6978
      • CVE-2019-6977
    • Double free if failed to properly extract image file - crash -> DoS
    • Heap-based buffer overflow in color matching (able to be triggered by a specially crafted image) - crash -> DoS, possible code execution

    Goings on in Ubuntu Security Community

    Comparison of Linux Hardening across distributions

    • https://capsule8.com/blog/millions-of-binaries-later-a-look-into-linux-hardening-in-the-wild/
    • Analyses binaries from various Linux distributions looking for hardening features (OpenSUSE, Debian, CentOS, RHEL & Ubuntu)
    • Compare kernel configuration vs KSPP recommendations
    • Ubuntu 18.04 ranks highest, due to proactive hardening features baked into toolchain and newer kernel taking advantage of KSPP upstream features
      • gcc is patched so anyone building on Ubuntu gets these features
      • build.snapcraft.io too
      • however is missing stack clash mitigation
    • Plan to add more hardening features for 19.10 (stack clash and control-flow integrity support via gcc) and review kernel options cf. KSPP

    Q&A

    Does numerous bugs and regressions in Ghostscript indicate it is reaching it’s EOL?

    • doc-E-brown via twitter
    • Lots of recent focus -> finds bugs
    • ghostscript codebase is old and gnarly and some fixes have been quite invasive
    • Any new code could introduce new bugs - particularly complicated fixes -> creates more bugs (regressions)
      • (as doc-E-brown suggests, regressions indicate old code-base)
    • Tavis (and others) seem to be looking elsewhere but likely still more bugs to be found
    • Would be great if GS could either be made safer or a safer alternative but no-one is stepping up
    • Sadly No good viable alternative currently

    Hiring

    Ubuntu Security Generalist

    • https://boards.greenhouse.io/canonical/jobs/1548812

    Robotics Security Engineer

    • https://boards.greenhouse.io/canonical/jobs/1550997

    Security Automation Engineer

    • https://boards.greenhouse.io/canonical/jobs/1548632

    Get in contact

    • security@ubuntu.com
    • #ubuntu-security on the Libera.Chat IRC network
    • @ubuntu_sec on twitter

    Episode 21 Feb 21, 2019
    Show notes

    Overview

    Double episode covering the security updates from the last 2 weeks, including snapd (DirtySock), systemd and more, plus we talk responsible disclosure and some open positions on the Ubuntu Security team.

    This week in Ubuntu Security Updates

    15 unique CVEs addressed

    [USN-3886-1] poppler vulnerabilities

    • 2 CVEs addressed in Trusty, Xenial, Bionic, Cosmic
      • CVE-2019-7310
      • CVE-2018-20551
    • Two DoS:
      • Out-of-bounds heap buffer read due to missing check for a negative index -> crash -> DoS
      • Crash due to hitting an assertion -> DoS

    [USN-3888-1] GVfs vulnerability

    • 1 CVEs addressed in Bionic, Cosmic
      • CVE-2019-3827
    • Possible to allow a local user with admin privileges (eg. sudo group) to read arbitrary files without prompting for authorisation IF no policykit agents running
      • Policykit agents run by default so would require user to be running a difffent DE or to have uninstalled / disabled them
      • Also low impact since user has authority anyway

    [USN-3889-1] WebKitGTK+ vulnerabilities

    • 2 CVEs addressed in Bionic, Cosmic
      • CVE-2019-6215
      • CVE-2019-6212
    • Memory corruption and type confusion errors - leading to possible remote code execution

    [USN-3890-1] Django vulnerability

    • 1 CVEs addressed in Xenial, Bionic, Cosmic
      • CVE-2019-6975
    • Could cause Django to consume a large amount of memory when formatting a decimal number with a large number of digits or with a large exponent since it would simply print every single provided character
    • Possible DoS although would need a very large number to be input
    • Fix is to format numbers with more than 200 characters in scientific notation

    [USN-3887-1] snapd vulnerability

    • 1 CVEs addressed in Trusty, Xenial, Bionic, Cosmic
      • CVE-2019-7304
    • ‘DirtySock’ - discovered by Chris Moberly
    • Failed to correctly parse and validate the remote socket address
    • Code had undergone refactoring and introduced this bug
    • Allows to impersonate privileged user and therefore call privileged APIs via the snapd socket

    [USN-3850-2] NSS vulnerabilities

    • 3 CVEs addressed in Precise ESM
      • CVE-2018-12404
      • CVE-2018-12384
      • CVE-2018-0495
    • Covered back in Episode 17

    [USN-3891-1] systemd vulnerability

    • 1 CVEs addressed in Xenial, Bionic, Cosmic
      • CVE-2019-6454
    • Discovered by Ubuntu Security team member Chris Coulson
    • Stack buffer overflow of DBus path field - declared as VLA, but sender could use a value larger than the stack size and therefore jump the entire stack and the guard pages
    • Segmentation violation -> crash -> DoS
      • systemd does not automatically restart so brings down entire system - reboot
    • Possible code execution but unlikely
    • DBus and systemd need to agree on what the maximum size of various elements are - DBus spec says path could be unlimited - but in practice is less than 32MB! (dbus-daemon limits messages to this size) - systemd now limits path to 64KB AND ensures it keeps running after receiving an invalid sized path

    [USN-3892-1] GDM vulnerability

    • 1 CVEs addressed in Bionic, Cosmic
      • CVE-2019-3825
    • Logic error in handing of timed logins (not enabled by default)
    • If screen already locked, select to log in as different user - then select a user which has timed login enabled - after timeout will unlock screen of original user
    • Need administrator privileges to enabled timed login for a given user so low impact

    [USN-3866-2] Ghostscript regression

    • Affecting Trusty, Xenial, Bionic, Cosmic
    • Previous update for Ghostscript (USN-3866-1 - Episode 18) caused a regression in printing 4"x6" (v9.26 - upstream bug)

    [USN-3893-1] Bind vulnerabilities

    • 3 CVEs addressed in Trusty, Xenial, Bionic, Cosmic
      • CVE-2019-6465
      • CVE-2018-5745
      • CVE-2018-5744
    • Fail to properly apply controls to zone transfers - could allow clients to request and receive a zone transfer to a dynamically loadable zone contrary to the allow-transfer ACL
    • Assertion failure if a trust anchor’s keys are replaced with keys using an unsupported algorithm during a key rollover when using the managed-keys feature for DNSSEC validation
    • Remotely triggerable memory leak when processing particular packets - DoS

    Goings on in Ubuntu Security Community

    snapd, systemd and handling of embargoed issues

    • 2 updates involving close communication between Ubuntu Security Team and external stakeholders - embargoed
    • Responsible Disclosure - allows to coordinate a fix in a timely manner and then release update once all parties are ready in a coordinated manner
    • Set CRD with stakeholders (reporter, upstream, other distros etc)
    • Coordinate fix with upstream and other distros
    • Plan coordinated updates to be released with other distros / upstream at CRD

    Hiring

    Ubuntu Security Generalist

    • https://boards.greenhouse.io/canonical/jobs/1548812

    Robotics Security Engineer

    • https://boards.greenhouse.io/canonical/jobs/1550997

    Security Automation Engineer

    • https://boards.greenhouse.io/canonical/jobs/1548632

    Get in contact

    • security@ubuntu.com
    • #ubuntu-security on the Libera.Chat IRC network
    • @ubuntu_sec on twitter

    Episode 20 Feb 11, 2019
    Show notes

    Overview

    This week we look at Linux kernel updates for all releases, OpenSSH, dovecot, curl and more. Plus we answer some frequently asked questions for Ubuntu security, in particular the perennial favourite of why we choose to just backport security fixes instead of doing rolling package version updates to resolve outstanding CVEs.

    This week in Ubuntu Security Updates

    33 unique CVEs addressed

    [USN-3871-3, USN-3871-4, USN-3871-5] Linux kernel vulnerabilities

    • 13 CVEs addressed in Bionic and Xenial (HWE - backport of Bionic kernel to Xenial)
      • CVE-2018-9516
      • CVE-2018-19407
      • CVE-2018-18281
      • CVE-2018-17972
      • CVE-2018-16882
      • CVE-2018-14625
      • CVE-2018-10883
      • CVE-2018-10880
      • CVE-2018-10882
      • CVE-2018-10878
      • CVE-2018-10877
      • CVE-2018-10879
      • CVE-2018-10876
    • Last week (Episode 19) covered kernel update for Bionic in preparation for 18.04.2
      • this is the corresponding update for various platforms using the Bionic kernel
      • (AWS, GCP, KVM, OEM, Raspberry Pi 2) (Azure)

    [USN-3878-1, USN-3878-2] Linux kernel vulnerabilities

    • 4 CVEs addressed in Cosmic
      • CVE-2018-19854
      • CVE-2018-19407
      • CVE-2018-16882
      • CVE-2018-14625
    • Last week (Episode 19) covered kernel update for Bionic in preparation for 18.04.2
      • Included the Cosmic HWE kernel for Bionic as well - this is the corresponding update for Cosmic itself on all supported platforms (physical and cloud etc)

    [USN-3879-1, USN-3879-2] Linux kernel vulnerabilities

    • 5 CVEs addressed in Xenial and Trusty (Xenial HWE)
      • CVE-2018-20169
      • CVE-2018-19824
      • CVE-2018-19407
      • CVE-2018-16862
      • CVE-2018-10883
    • OOB read on reading USB device descriptor - need local physical access to connect a malicious device - crash -> DoS
    • UAF in ALSA via a malicious USB sound device that expose zero interfaces - crash -> DoS, possible code execution
    • Uninitialised ioapics (Episode 19)
    • Cleancache subsystem - after file truncation (removal), wouldn’t properly clear inode so if a new file was created with the same inode might contain leftover pages from cleancache and hence the data from the old file
      • Only affects Ubuntu kernels under Xen with tmem driver
    • ext4 - OOB write via malicious crafted image

    [USN-3880-1, USN-3880-2] Linux kernel vulnerabilities

    • 4 CVEs addressed in Trusty and Precise ESM (Trusty HWE)
      • CVE-2018-9568
      • CVE-2018-18281
      • CVE-2018-17972
      • CVE-2018-1066
    • Possible memory corruption via type confusion when cloning a socket - privilege escalation
    • mremap() issue (covered in Episode 15)
    • procfs stack unwinding to leak kernel stack from other task (covered in Episode 12)
    • NULL pointer dereference in CIFS client in kernel triggered by a malicious server (crash -> DoS)

    [USN-3881-1, USN-3881-2] Dovecot vulnerability

    • 1 CVEs addressed in Precise ESM, Trusty, Xenial, Bionic, Cosmic
      • CVE-2019-3814
    • Interaction of username / password authentication with trusted SSL cert - can configure for user/pass but can also configure for client to present a trusted cert
    • Can configure to take username from cert instead of from explicit username AND also to configure no password if using cert
    • BUT if no username in cert, will use specified username - so could log in as any user

    [USN-3882-1] curl vulnerabilities

    • 3 CVEs addressed in Trusty, Xenial, Bionic, Cosmic
      • CVE-2019-3823
      • CVE-2019-3822
      • CVE-2018-16890
    • OOB read when parsing end of response for SMTP
    • Stack buffer overflow when creating an NTLMv2 type-3 header based on previous received data (size checks were not sufficient since they suffered from an integer overflow)
    • OOB read for NTLM type-2 handling via an integer overflow

    [USN-3883-1] LibreOffice vulnerabilities

    • 5 CVEs addressed in Trusty, Xenial
      • CVE-2018-16858
      • CVE-2018-10583
      • CVE-2018-11790
      • CVE-2018-10120
      • CVE-2018-10119
    • 3 CVEs for mishandling various elements in different document types - UAF, heap-based buffer overflow (write) etc) - crash -> DoS, possible code execution
    • Information disclosure (leak of NTLM hashes) via an embedded link to a remote SMB resource within a document
    • Directory traversal flaw leading to code execution
      • document can links which like HTML, can have attributes such as a script which will get executed without prompting - so onMouseOver() etc
      • and this can refer to a file on the local filesystem outside the document structure itself
      • libreoffice ships with it’s own Python interpreter that contains functions which can be abused to run arbitrary commands
      • so can specify both the path to one of these files AND arguments to pass to it to run

    [USN-3884-1] libarchive vulnerabilities

    • 2 CVEs addressed in Trusty, Xenial, Bionic, Cosmic
      • CVE-2019-1000020
      • CVE-2019-1000019
    • Infinite loop when parsing a specially crafted ISO9660 CD/DVD iso file -> DoS
    • OOB read when decompressing a specially crafted 7z file -> crash -> DoS

    [USN-3885-1] OpenSSH vulnerabilities

    • 3 CVEs addressed in Trusty, Xenial, Bionic, Cosmic
      • CVE-2019-6111
      • CVE-2019-6109
      • CVE-2018-20685
    • Three vulnerabilities in scp able to be triggered via a malicious server (low probability)
      • Fails to validate file names from the remote server match the requested ones - server can overwrite arbitrary files on local side in the target directory
      • Fails to use proper character encoding in progress display, allows server to manipulate output of client to hide output of additional files being sent
      • Fails to check if target filename is . or empty - allows remote server to change permissions of the client local directory
    • Together allow a server to easily overwrite local files on the client side without the client user being aware

    Goings on in Ubuntu Security Community

    FAQs about Ubuntu Security

    What packages are supported?

    • main only (~2.3k source packages in Bionic - cf. universe ~26k source packages)

    What timeframe?

    • lifetime of the release - so from official release date to EOL date
    • LTS: 5 years, non-LTS: 9 months
    • ESM provides security fixes beyond the EOL for LTS releases

    Why do we backport patches instead of just updating to the lastest versions?

    • Users expect high degree of stability
      • changes need caution and good rationale
      • lots of previous regressions from innocent looking changes
      • no change is completely free of risk
    • Only changes which have high impact (security fixes, severe regressions, loss of data etc)
    • More details see SRU page on Ubuntu wiki
    • So security updates must follow suit

    Get in contact

    • security@ubuntu.com
    • #ubuntu-security on the Libera.Chat IRC network
    • @ubuntu_sec on twitter

    Episode 19 Feb 04, 2019
    Show notes

    Overview

    This week we look at updates to the Linux kernel in preparation for the 18.04.2 release, plus updates for Open vSwitch, Firefox, Avahi, LibVNCServer and more. We also revisit and discuss upstream changes to the mincore() system call to thwart page-cache side-channel attacks first discussed in Episode 17.

    This week in Ubuntu Security Updates

    40 unique CVEs addressed

    [USN-3870-1] Spice vulnerability

    • 1 CVEs addressed in Trusty, Xenial, Bionic, Cosmic
      • CVE-2019-3813
    • Out-of-bounds read - off-by-one - likely crash on segmentation violation but possible code-execution

    [USN-3871-1] Linux kernel vulnerabilities

    • 13 CVEs addressed in Bionic
      • CVE-2018-9516
      • CVE-2018-19407
      • CVE-2018-18281
      • CVE-2018-17972
      • CVE-2018-16882
      • CVE-2018-14625
      • CVE-2018-10883
      • CVE-2018-10880
      • CVE-2018-10882
      • CVE-2018-10878
      • CVE-2018-10877
      • CVE-2018-10879
      • CVE-2018-10876
    • NULL pointer dereference in KVM able to be triggered by a local user (crash -> DoS)
    • mremap() TLB flush leaving stale entries in page cache - covered previously in Episode 15
    • Episode 15 covered CVE-2018-17972 (procfs kernel stack disclosure)
    • UAF in KVM when using nested virtualisation (not enabled by default for Ubuntu kernels) able to be trigered by gust VM to crash host (DoS) or possibly elevate privileges etc.
    • Race condition between connect() and close() in AF_VSOCK (used for communication between guest and host machines) could allow to read 4 bytes of memory (UAF) from host kernel or possibly corrupt other AF_VSOCK messages to other guests - information leak
    • 7 ext4 issues discovered by Wen Xu (fuzzing ext4 with KASAN enabled):
      • OOB write during update of journal metadata when mounting specially crafted ext4 image - crash -> DoS (privilege esc?)
      • OOB write to stack when processing xattrs of specially crafted ext4 image - crash -> DoS
      • OOB write when mounting
      • OOB write unmounting specially crafted ext4 image
      • OOB read when mounting
      • UAF when processing xattrs of renamed file in specially crafted image
      • General UAF when mouting a specially crafted image
      • Reproducers provided in upstream kernel bug reports

    [USN-3872-1] Linux kernel (HWE) vulnerabilities

    • 4 CVEs addressed in Bionic
      • CVE-2018-19854
      • CVE-2018-19407
      • CVE-2018-16882
      • CVE-2018-14625
    • Info leak from crypto subsystem - regression of CVE-2013-2547 - fail to fully initialise structure members copied to userspace - unlike CVE-2013-2547, able to be exploited by a standard user without any capabilities
    • Failure to ensure ioapics were initialised - possible NULL pointer dereference -> crash -> DoS
    • KVM UAF w/ nested virtualisation and AF_VSOCK race condition UAF

    [USN-3873-1] Open vSwitch vulnerabilities

    • 3 CVEs addressed in Xenial, Bionic
      • CVE-2018-17206
      • CVE-2018-17205
      • CVE-2018-17204
    • Remotely triggerable OOB read and 2 different assertion failures -> crash -> DoS

    [USN-3874-1] Firefox vulnerabilities

    • 7 CVEs addressed in Trusty, Xenial, Bionic, Cosmic
      • CVE-2018-18506
      • CVE-2018-18505
      • CVE-2018-18504
      • CVE-2018-18503
      • CVE-2018-18502
      • CVE-2018-18501
      • CVE-2018-18500
    • Firefox 65 for all supported platforms
      • Proxy autoconfig file (PAC) could allow proxy requests to localhost to go via remote proxy - if enabled proxy-autodetection - then possible for remote attacker to conduct attacks against local services etc
      • Various memory safety issues - crash -> DoS, UAF, code execution
      • Sandbox escape via IPC channels due to failure to properly apply authentication to IPC channels in some situations
        • IPC channels used in new multiprocess architecture etc

    [USN-3875-1] OpenJDK vulnerability

    • 1 CVEs addressed in Xenial, Cosmic
      • CVE-2019-2422
    • Info leak from Java SE VM in OpenJDK library subsystem able to be triggered by a remote attacker - possible sandbox bypass as well

    [USN-3876-1, USN-3876-2] Avahi vulnerabilities

    • 2 CVEs addressed in Precise ESM, Trusty, Xenial, Bionic, Cosmic
      • CVE-2018-1000845
      • CVE-2017-6519
    • Both the same vulnerability - duplicate CVE
    • Traffic reflection and amplification - possible to leverage for DDoS attack since avahi-daemon would inadvertently respond to unicast IPv6 queries to source addresses which were not on the local link

    [USN-3877-1] LibVNCServer vulnerabilities

    • 12 CVEs addressed in Trusty, Xenial, Bionic, Cosmic
      • CVE-2018-6307
      • CVE-2018-20750
      • CVE-2018-20749
      • CVE-2018-20748
      • CVE-2018-20024
      • CVE-2018-20023
      • CVE-2018-20022
      • CVE-2018-20021
      • CVE-2018-20020
      • CVE-2018-20019
      • CVE-2018-15127
      • CVE-2018-15126
    • Various memory management issues:
      • Heap UAF -> crash -> DoS, possible RCE in server from malicious client
      • Heap OOB write (incomplete fix for previous CVE-2018-15127) - crash -> DoS, possible RCE
      • Multiple heap OOB writes in client (incomplete fix for previous CVE-2018-20019)
      • NULL pointer dereferences in client -> crash -> DoS
      • Failure to properly initialise structures on stack -> info leak, possible ASLR bypass (disclose stack memory layout)
      • Infinite loop in client -> DoS

    Goings on in Ubuntu Security Community

    An update on mincore()

    • In Episode 17 discussed changes to mincore() mitigate page cache side-channel attack
    • Linus Torvalds committed a change to change the behaviour of mincore() to mitigate the vulnerability
    • Recently reverted that change citing too much breakage to existing users:
      • In particular Netflix have a use-case where they dump page cache across processes to aid in migration of Cassandra workloads across machines
    • Instead an alternate approach to limit cache residency reporting only to processes which have write access to the particular file in question
      • ie. so if a process has write access to a file which it has open for writing it will be able to read back from mincore() which pages are mapped in the cache and which are not - so will still work for the Netflix and others case of databases wanting to know which pages are mapped or not from disk
      • will stop the case of being able to know which pages of shared system libraries etc are mapped and hence stop the original side-channel attack
      • patches not yet submitted for mm tree or others but should be soon

    Get in contact

    • security@ubuntu.com
    • #ubuntu-security on the Libera.Chat IRC network
    • @ubuntu_sec on twitter

    Episode 18 Jan 29, 2019
    Show notes

    Overview

    This week we look at some details of the 46 unique CVEs addressed across the supported Ubuntu releases and take a deep dive into the recent apt security bug.

    This week in Ubuntu Security Updates

    46 unique CVEs addressed

    [USN-3863-1, USN-3863-2] APT vulnerability

    • 1 CVEs addressed in Precise ESM, Trusty, Xenial, Bionic, Cosmic
      • CVE-2019-3462
    • MITM allowing RCE as root in the context of apt
    • Due to mishandling of HTTP redirect which would allow malicious mirror / MITM to inject content and then could allow arbitrary command execution
    • Fixed by simply disallowing control characters in HTTP redirect responses
      • See detailed discussion later in show

    [USN-3864-1] LibTIFF vulnerabilities

    • 7 CVEs addressed in Trusty, Xenial, Bionic, Cosmic
      • CVE-2018-8905
      • CVE-2018-7456
      • CVE-2018-18661
      • CVE-2018-18557
      • CVE-2018-17101
      • CVE-2018-17100
      • CVE-2018-10963
    • Multiple NULL pointer dereferences and assertion failures (crash -> DoS)
    • Multiple heap-based buffer overflows and an integer overflow (crash -> DoS / possible RCE)

    [USN-3865-1] poppler vulnerabilities

    • 2 CVEs addressed in Trusty, Xenial, Bionic, Cosmic
      • CVE-2018-20650
      • CVE-2018-20481
    • Assertion failure and NULL pointer dereference triggered by crafted PDFs (crash -> DoS)

    [USN-3707-2] NTP vulnerabilities

    • 9 CVEs addressed in Precise ESM
      • CVE-2018-7185
      • CVE-2018-7183
      • CVE-2017-6463
      • CVE-2017-6462
      • CVE-2016-9311
      • CVE-2016-9310
      • CVE-2016-7428
      • CVE-2016-7427
      • CVE-2016-7426
    • NTP updated for Bionic, Artful, Xenial and Trusty in July 2018 - this is the corresponding update for Precise ESM
    • Multiple issues including: RCE in ntpq from a crafted response from the server, various DoS at both protocol level between client and server (disrupt a client talking to server) and at application level (to crash the application)

    [USN-3866-1] Ghostscript vulnerability

    • 1 CVEs addressed in Trusty, Xenial, Bionic, Cosmic
      • CVE-2019-6116
    • Another week, another Ghostscript vulnerability courtesy of Tavis Ormandy (GPZ) (after a random look at the latest GS release 9.26)
      • See Episodes 5, 7, 10, 14 for more
    • Code execution via subroutine operators
      • Patches to fix quite invasive
    • Ghostscript is included in evince, ImageMagick, nautilus, GIMP, even less so able to target various commands to exploit

    [USN-3867-1] MySQL vulnerabilities

    • 15 CVEs addressed in Xenial, Bionic, Cosmic
      • CVE-2019-2537
      • CVE-2019-2534
      • CVE-2019-2532
      • CVE-2019-2531
      • CVE-2019-2529
      • CVE-2019-2528
      • CVE-2019-2510
      • CVE-2019-2507
      • CVE-2019-2503
      • CVE-2019-2486
      • CVE-2019-2482
      • CVE-2019-2481
      • CVE-2019-2455
      • CVE-2019-2434
      • CVE-2019-2420
    • Updated to latest MySQL version (5.7.25) in all releases to fix numerous issues including:
      • Multiple DoS via low privileged attacker, multiple unauthorized access to complete MySQL server data etc

    [USN-3869-1] Subversion vulnerability

    • 1 CVEs addressed in Cosmic
      • CVE-2018-11803
    • DoS against Subversion server (mod_dav_svn) (only affects 1.10.0+ -> Cosmic)
    • Triggered by listing remote recursive directory contents BUT not providing the path to list - NULL pointer dereference -> crash

    [USN-3868-1] Thunderbird vulnerabilities

    • 10 CVEs addressed in Trusty, Xenial, Bionic, Cosmic
      • CVE-2018-18498
      • CVE-2018-18494
      • CVE-2018-18493
      • CVE-2018-18492
      • CVE-2018-17466
      • CVE-2018-12405
      • CVE-2018-12393
      • CVE-2018-12392
      • CVE-2018-12390
      • CVE-2018-12389
    • Latest Thunderbird release (60.4) to resolve multiple issues

    Goings on in Ubuntu Security Community

    apt / apt-get RCE (CVE-2019-3462)

    • Discovered by Max Justicz (provides a detailed write-up on his blog)
    • apt uses worker processes which communicate back to the main process when fetching content
      • workers get told what to download and where to put it and communicate back with parent via stdin/stdout
      • protocol is like HTTP, human readable text
      • can include directives from workers regarding redirects, completion (DONE) etc
      • when handling a HTTP Redirect from the server, apt http worker would append this contents in message sent back to parent
        • expect just a URI as the redirect content but could be anything - so could contain directives in the apt worker protocol which then get interpreted by the main apt process
        • so could signal DONE to parent as well as follow-up directives such as reporting false hashes for debs or even falsifying the location of the deb on the filesystem
        • So could use the Releases.gpg file as the location of the package on the filesystem - and actually inject our malicious package into the start of Releases.gpg - with trusted Releases.gpg content afterwards
        • Releases.gpg will still validate (since it ignores junk at the start) AND apt will still use the package since it will ignore the signature at the end
        • So can get malicious package installed - which due to debian packaging can run scripts on install etc and hence get RCE as root :(
    • Fixed by simply disallowing control characters in HTTP redirect responses
    • If we assume the mirrors are trusted, could have been mitigated via HTTPS
      • Since HTTPS would stop MITM attacks
      • Some Ubuntu mirrors offer HTTPS but this is not enabled by default since not all mirrors offer HTTPS
      • Official mirrors do not currently offer HTTPS - this is being reevaluated but is difficult for a number of reasons
      • Users can still easily enable HTTPS themselves by choosing an appropriate mirror with a HTTPS URI
    • If assume mirrors are untrusted then they could still have exploited this
      • So whilst HTTPS could help in this case is not a panacea

    Get in contact

    • security@ubuntu.com
    • #ubuntu-security on the Libera.Chat IRC network
    • @ubuntu_sec on twitter

    Episode 17 Jan 22, 2019
    Show notes

    Overview First episode of 2019! This week we look “System Down” in systemd, as well as updates for the Linux kernel, GnuPG, PolicyKit and more, and discuss a recent cache-side channel attack using the mincore() system call. This week in Ubuntu Security Updates 51 unique CVEs addressed across the supported Ubuntu releases. [USN-3846-1, USN-3847-1, USN-3847-2, USN-3847-3] Linux kernel vulnerabilities Kernel updates as part of normal 3-weekly SRU cycle - includes various fixes across the supported releases CVE-2018-18710 (Cosmic, Bionic, Bionic HWE, Xenial, Xenial HWE, Trusty, Trusty HWE) CVE-2018-18690 (Bionic, Bionic HWE, Xenial, Xenial HWE, Trusty, Trusty HWE) CVE-2018-18445 (Bionic, Bionic HWE) CVE-2018-16276 (Bionic, Bionic HWE) CVE-2018-14734 (Bionic, Bionic HWE) CVE-2018-12896 (Bionic, Bionic HWE, Xenial, Xenial HWE, Trusty, Trusty HWE) CVE-2017-18174 (Xenial, Xenial HWE) CVE-2018-10902 (Trusty, Trusty HWE) CVE-2017-2647 (Trusty, Trusty HWE) Info leak in CDROM driver, XFS DoS via writing of extended attributes causing an error condition that leaves the fs in an error state until next mount Bounds check bypass in BPF verifier (mentioned in Episode 15) Incorrect bounds checking in Yurex USB driver (Episode 7) UAF in infiniband -> Crash -> DoS Integer overflow in POSIX timers overrun accounting due to type confusion (int vs 64-bit signed) Double free in AMD GPIO pinctrl driver - DoS / privilege escalation Race condition in midi driver - double free -> privilege escalation NULL pointer dereference in kernel keyring -> crash -> DoS [LSN-0046-1] Linux kernel livepatch for vulnerabilities 10 CVEs addressed in CVE-2018-16658 CVE-2018-16276 CVE-2017-5753 CVE-2018-9363 CVE-2018-18690 CVE-2018-10880 CVE-2018-14734 CVE-2018-18445 CVE-2018-10902 CVE-2018-18710 [USN-3850-1] NSS vulnerabilities 3 CVEs addressed in Trusty, Xenial, Bionic, Cosmic CVE-2018-12404 CVE-2018-12384 CVE-2018-0495 Cache side-channel variant of Bleichenbacher attack (http://cat.eyalro.net/) Responds to SSLv2 ClientHello with a ServerHello with all zero random Cache side-channel attack on ECDSA signatures (Trusty only) [USN-3851-1] Django vulnerability 1 CVEs addressed in Trusty, Xenial, Bionic, Cosmic CVE-2019-3498 Attacker could craft a malicious URL to make spoofed content appear on the generated 404 page [USN-3852-1] Exiv2 vulnerabilities 9 CVEs addressed in Trusty, Xenial, Bionic, Cosmic CVE-2018-17581 CVE-2018-16336 CVE-2017-17669 CVE-2017-14864 CVE-2017-14862 CVE-2017-14859 CVE-2017-11683 CVE-2017-11591 CVE-2017-9239 Infinite recursion leading to stack exhaustion -> crash -> DoS Multiple heap based buffer out-of-bounds reads -> crash -> DoS Multiple invalid pointer dereferences -> crash -> DoS Invalid assertion, NULL pointer dereference -> crash -> DoS [USN-3853-1] GnuPG vulnerability 1 CVEs addressed in Bionic, Cosmic CVE-2018-1000858 GnuPG includes support for Web Key Directories (WKD) to allow easy discovery of public keys via HTTPS Allows a key to be imported from a webserver -> first need to lookup hostname via DNS SRV Fails to sanitize response - so performs an attacker controlled, arbitrary HTTPS GET request Attacker needs to construct a malicious SRV record for the domain in question Possible CSRF, content injection etc Thunderbird will automatically use WKD via GnuPG to lookup missing keys so allows easy exploitation [USN-3854-1] WebKitGTK+ vulnerabilities 1 CVEs addressed in Bionic, Cosmic CVE-2018-4437 Possible RCE via invalid processing of crafted web content (as usual limited details on WebKitGTK vulnerabilities…) [USN-3855-1] systemd vulnerabilities 3 CVEs addressed in Xenial, Bionic, Cosmic CVE-2018-16866 CVE-2018-16865 CVE-2018-16864 “System Down” systemd vulnerabilities Chris Coulson put in a heroic effort and patched quickly - Ubuntu first affected distro to release patched systemd Due to use of variable length arrays on the stack, allows various fields which are attacker controlled to be overflowed If overflow far enough can bypass kernel stack guard pages, and hence corrupt the heap Possible code execution as a result (original advisory contained a PoC for i386 which gained control of the instruction pointer) Can be mitigated via use of the gcc flag -fstack-clash-protection - this is now under review to be used by default in forthcoming Ubuntu releases [USN-3856-1] GNOME Bluetooth vulnerability 1 CVEs addressed in Bionic CVE-2018-10910 BlueZ doesn’t necessarily make bluetooth device undiscoverable automatically after timeout Hence after enabling discovery would then still be discoverable even though user expectation is that is not anymore Actual bug then is really in BlueZ but now added a workaround in GNOME bluetooth to manually disable discovery [USN-3857-1] PEAR vulnerability 1 CVEs addressed in Xenial, Bionic, Cosmic CVE-2018-1000888 PHP Extension and Application Repository - possible RCE when deserialising via PHP object injection Triggered when unpacking a PHAR (PHP ARchive) - also possible to sneak one into a JPEG so easy to exploit - just need image upload (Wordpress etc) [USN-3858-1] HAProxy vulnerabilities 3 CVEs addressed in Xenial, Bionic, Cosmic CVE-2018-20615 CVE-2018-20103 CVE-2018-20102 Popular load balancing reverse proxy (used in OpenStack etc.) Infinite recursion from a pointer referencing itself or from long chains of pointers -> stack exhaustion -> crash -> DoS Out-of-bounds read when validating DNS responses - information disclosure of 16 bytes Fail to ensure valid length of H2 HEADERS when decoding - out-of-bounds read -> crash -> DoS [USN-3859-1] libarchive vulnerabilities 4 CVEs addressed in Trusty, Xenial, Bionic, Cosmic CVE-2017-14502 CVE-2018-1000878 CVE-2018-1000877 CVE-2018-1000880 Out-of-bounds read for UTF-16 names in RAR archives UAF and double free in RAR decoder - crash -> DoS, possible RCE Quasi-infinite runtime and disk usage from a tiny crafted WARC file (Web Archive format for storing results of crawling websites) [USN-3860-1, USN-3860-2] libcaca vulnerabilities 7 CVEs addressed in Precise ESM, Trusty, Xenial, Bionic, Cosmic CVE-2018-20549 CVE-2018-20547 CVE-2018-20546 CVE-2018-20549 CVE-2018-20548 CVE-2018-20545 CVE-2018-20544 Library and utils for handling colour ASCII art (used by various media players to show videos in a terminal etc) Various issues - OOB reads, writes and a floating point exception -> crash -> DoS [USN-3861-1, USN-3861-2] PolicyKit vulnerability 1 CVEs addressed in Precise ESM, Trusty, Xenial, Bionic, Cosmic CVE-2018-19788 Invalid handling of UID > INT_MAX - would allow a user to bypass policy and execute any systemctl command [USN-3862-1] Irssi vulnerability 1 CVEs addressed in Trusty, Xenial, Bionic, Cosmic CVE-2019-5882 UAF when expiring hidden lines from the scroll buffer Goings on in Ubuntu and Linux Security Community New page cache side-channel attack via mincore() Discovered by a team of researchers including some of those who found Spectre / Meltdown https://arxiv.org/pdf/1901.01161.pdf Uses mincore() system call on Linux to determine if pages exist in the page cache or not mincore() returns a bitmask of which pages are mapped in the cache for the requested range Can use this side-channel to either: determine when a process calls a given function in a shared library (since the library will be mapped at the same address in both the attack and victim process) need to first evict the given page from the cache which is difficult but authors propose a new efficient mechanism to do this can then do things like UI redressing etc in response Or can use this is a covert channel to leak information from one process to another Can even use over the network to leak information via an innocent webserver etc Paper also describes an efficient cache eviction strategy Linus directly applied a fix (https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=574823bfab82d9d8fa47f422778043fbb4b4f50e) This changes the behaviour of mincore() to only report pages which have been faulted into the cache by the calling process So at best can now observe when a page is evicted from the cache but can’t see when another process faults in a page Breaks user-space API of mincore() and hence some existing programs (as noted in the commit) Linus’ primary rule is to never break userspace BUT in this case as is a security vulnerability this is okay This might also likely affect other programs that use mincore in Ubuntu etc (fincore, e4defrag, qemu etc) Fix is not in the stable upstream kernel yet as waiting to see what fallout there is and so also has not been applied to Ubuntu kernels yet Also good discussion on LWN https://lwn.net/Articles/776801/ which highlights other avenues for inferring the contents of the page cache and other possible changes to mincore to protect against this attack Will be interesting to see where this all ends up Get in contact security@ubuntu.com #ubuntu-security on the Libera.Chat IRC network @ubuntu_sec on twitter

    Full show notes at the publisher

    Episode 16 Dec 17, 2018
    Show notes

    Overview

    Last episode for 2018! This week we look at CVEs in lxml, CUPS, pixman, FreeRDP & more, plus we discuss the security of home routers as evaluated by C-ITL.

    This week in Ubuntu Security Updates

    21 unique CVEs addressed

    [USN-3841-1, USN-3841-2] lxml vulnerability

    • 1 CVEs addressed in Precise ESM, Trusty, Xenial, Bionic
      • CVE-2018-19787
    • Popular XML/HTML parser for Python
    • Tries to remove clean input document and remove links (to say embedded javascript code) - but doesn’t account for links containing escaped characters - so link could persist
    • Similar to CVE-2014-3146
      • In this case tried to account for whitespace in links but didn’t include all possible whitespace characters

    [USN-3842-1] CUPS vulnerability

    • 1 CVEs addressed in Trusty, Xenial, Bionic, Cosmic
      • CVE-2018-4700
    • Session cookies used for authentication to CUPS web interface used only the current time in seconds as a seed for the relatively predictable PRNG
      • Easy to bruteforce / guess
      • Fix ensures to use current time value including microseconds
      • Still using relatively predictable PRNG - should use /dev/urandom etc

    [USN-3837-2] poppler regression

    • 2 CVEs addressed in Trusty, Xenial, Bionic, Cosmic
      • CVE-2018-19149
      • CVE-2018-16646
    • Previous poppler update (Episode 15) - fix missed a previous commit and so regressed (crash on opening certain PDF files)

    [USN-3843-1, USN-3843-2] pixman vulnerability

    • 1 CVEs addressed in Precise ESM, Trusty
      • CVE-2015-5297
    • Low level library for pixel manipulation (used by X, Wayland, Qemu etc)
    • Pointer overflow leading to stack-based buffer overflow in computing bounds of pixel buffers
      • Did include a check to see if was inside bounds, BUT didn’t account for possible overflow in arithmetic before the check
      • Need to check for possible overflow before doing arithmetic and comparison

    [USN-3844-1] Firefox vulnerabilities

    • 10 CVEs addressed in Trusty, Xenial, Bionic, Cosmic
      • CVE-2018-18497
      • CVE-2018-18495
      • CVE-2018-18498
      • CVE-2018-18494
      • CVE-2018-18493
      • CVE-2018-18492
      • CVE-2018-17466
      • CVE-2018-12407
      • CVE-2018-12406
      • CVE-2018-12405
    • Firefox 64 - multiple security vulnerabilities fixed
      • Buffer overflows, UAFs, same-origin-policy violation, webextensions able to violate restrictions, various memory safety / corruption bugs
      • https://www.mozilla.org/en-US/security/advisories/mfsa2018-29/

    [USN-3845-1] FreeRDP vulnerabilities

    • 6 CVEs addressed in Trusty, Xenial, Bionic, Cosmic
      • CVE-2018-8789
      • CVE-2018-8788
      • CVE-2018-8787
      • CVE-2018-8786
      • CVE-2018-8785
      • CVE-2018-8784
    • Eyal Itkin discovered multiple vulnerabilities in FreeRDP - not all affect all releases (some too old to contain affected code)
    • Various heap-based buffer overflows (crash -> DoS / RCE?)
    • Out-of-bounds read (crash -> DoS)

    Goings on in Linux Security Community

    Linux on MIPS and home routers

    • Cyber-ITL (Independent Testing Lab) analysed a number of home routers for basic security hardening features
      • ASLR, DEP (non-executable stack), RELRO
      • Mix of MIPS and ARM devices
      • Compared against Ubuntu 16.04 LTS x86_64 (general hardening)
      • Most found to have minimal hardening features enabled
      • https://cyber-itl.org/assets/papers/2018/build_safety_of_software_in_28_popular_home_routers.pdf
      • Also found Linux kernel on MIPS either has executable stack (until 2016) due to FP emulation code, or since then has no executable stack but has a RWX segment at a fixed location, which can be used to bypass DEP / ASLR
        • Ubuntu does not support MIPS

    Final episode for 2018

    • This is the last episode for 2018, on leave for the next 3 weeks
    • Next episode will be from Cape Town in 2019 during week of 14th January with some special guests… :)

    Get in contact

    • security@ubuntu.com
    • #ubuntu-security on the Libera.Chat IRC network
    • @ubuntu_sec on twitter

    Episode 15 Dec 10, 2018
    Show notes

    Overview

    Security updates for 29 CVEs including Perl, the kernel, OpenSSL (PortSmash) and more, plus in response to some listener questions, we discuss how to make sure you always have the latest security updates by using unattended-upgrades.

    This week in Ubuntu Security Updates

    29 unique CVEs addressed

    [USN-3834-1, USN-3834-2] Perl vulnerabilities

    • 4 CVEs addressed in Precise ESM, Trusty, Xenial, Bionic, Cosmic
      • CVE-2018-18314
      • CVE-2018-18313
      • CVE-2018-18312
      • CVE-2018-18311
    • Perl regex engine fuzzed with valgrind to detect memory errors
      • 2 different heap based buffer overflow in regex engine
      • Heap-based read past end of buffer in regex engine
    • Integer overflow from environment variables
      • uses untrusted input from environment variables (length of values to calculate memory to allocate)
      • heap buffer overflow

    [USN-3835-1, USN-3836-1, USN-3836-2] Linux kernel vulnerabilities

    • 6 CVEs addressed in Cosmic, 2 in Bionic and Xenial

      • CVE-2018-6559
      • CVE-2018-18955
      • CVE-2018-18653
      • CVE-2018-18445
      • CVE-2018-18281
      • CVE-2018-17972
    • Episode 14 covered CVE-2018-6559 (overlayfs / user namespace directory names disclosure)

      • Also fixed for Bionic and Xenial
    • Episode 12 covered CVE-2018-17972 (procfs kernel stack disclosure)

    • 3 CVEs discovered by Jann Horn (and one inadvertently caused by Jann too)

      • mremap() system call - used to expand or shrink an existing memory mapping and possibly move it - doesn’t properly flush TLB - could leave pages in page cache for a short time which can then be raced to obtain access afterwards and possible DoS crash or information disclosure etc depending on target memory
      • Previous fix for CVE-2017-17852 (BPF verifier) discovered and also fixed by Jann, introduced a new vulnerability which would allow BPF programs to access memory out-of-bounds
      • Nested user namespaces with more than 5 UID or GID mappings could allow processes with CAP_SYS_ADMIN within the namespace to access resources outside the namespace as the kernel would get confused on which UID to check against outside the namespace
        • Also fixed in Bionic and Xenial
    • Vulnerability specific to the Ubuntu kernel used in Cosmic (18.10)

      • 2 bugs discovered as a result of using the secure boot lockdown patchset
        • Module signatures not properly enforced for UEFI Secure Boot - we had enabled the option to do this via IMA but had not then included the IMA policy to ensure this was enforced
          • Fixed by turning off option to verify modules using IMA
        • Secondary kernel keyring (ie where UEFI MOK goes from shim - used by DKMS) not trusted - so modules signed with it wouldn’t work (except they do due to above)
          • Fixed to trust keys in secondary keyring for module signing

    [USN-3837-1] poppler vulnerabilities

    • 5 CVEs addressed in Trusty, Xenial, Bionic, Cosmic
      • CVE-2018-19149
      • CVE-2018-19060
      • CVE-2018-19059
      • CVE-2018-19058
      • CVE-2018-16646
    • NULL pointer dereference when PDF references an embedded file that does not actually exist (crash -> DoS)
    • Possible infinite recursion - DoS
    • Exit on abort - DoS
    • 2 for pdfdetach - CLI util to list / extract embedded files from PDFs
      • Out of bounds read due to fail to validate embedded files
      • NULL pointer dereference if embedded file names are invalid

    [USN-3811-3] SpamAssassin vulnerabilities

    • 2 CVEs addressed in Precise ESM
      • CVE-2018-11781
      • CVE-2018-11780
    • SpamAssassin was updated to latest version for Trusty, Xenial and Bionic previously (Episode 11)
    • This is the corresponding update for Precise ESM

    [USN-3838-1] LibRaw vulnerabilities

    • 7 CVEs addressed in Trusty, Xenial, Bionic
      • CVE-2018-5816
      • CVE-2018-5815
      • CVE-2018-5813
      • CVE-2018-5812
      • CVE-2018-5811
      • CVE-2018-5810
      • CVE-2018-5807
    • Few OOB read -> crash -> DoS
    • NULL pointer dereference -> crash -> DoS
    • Integer overflow -> infinite loop -> DoS
    • Integer overflow -> divide by zero -> crash -> DoS
    • Heap-based buffer overflow -> crash -> DoS (possible code execution?)

    [USN-3839-1] WavPack vulnerabilities

    • 2 CVEs addressed in Trusty, Xenial, Bionic, Cosmic
      • CVE-2018-19841
      • CVE-2018-19840
    • Infinite loop if WAV file specifies a sample rate of 0 - DoS
    • OOB read of heap allocated buffer - crash -> DoS

    [USN-3840-1] OpenSSL vulnerabilities

    • 3 CVEs addressed in Trusty, Xenial, Bionic, Cosmic
      • CVE-2018-5407
      • CVE-2018-0735
      • CVE-2018-0734
    • PortSmash (Episode 11) - purported new Intel CPU side-channel vulnerability - but really more an issue in OpenSSL due to needing crypto code to be both constant time and execution flow independent of secret key
    • Timing side-channels in ECDSA and DSA signature algorithms found by Samuel Weiser
      • Usual thing - variations in time-to-sign can be measured by attacker to recover private signing key

    [USN-3831-2] Ghostscript regression

    • Affecting Trusty, Xenial, Bionic, Cosmic
    • Latest GS updates (Episode 14) -> regression
      • when converting PDFs via ghostscript, would crash when using FirstPage and LastPage options
      • used by imagemagick (convert) util and others
      • backported addition fix from upstream to resolve this regression

    Goings on in Ubuntu Security Community

    Feedback

    • Question regarding how to ensure latest updates applied?
      • https://help.ubuntu.com/community/AutomaticSecurityUpdates
      • If regularly update system (apt upgrade / software updater etc) will already have latest security updates
      • Can make this automatic with unattended-upgrades
        • Is automatically installed and configured for Ubuntu 18.04 Bionic and newer to install new updates daily
        • If want to manually
          • sudo apt install unattended-upgrades
          • sudo dpkg-reconfigure unattended-upgrades
      • Canonical Livepatch Service
        • https://www.ubuntu.com/livepatch

    Get in contact

    • security@ubuntu.com
    • #ubuntu-security on the Libera.Chat IRC network
    • @ubuntu_sec on twitter

    Episode 14 Dec 03, 2018
    Show notes

    Overview

    This week we look at some details of the 32 unique CVEs addressed across the supported Ubuntu releases and talk open source software supply chain integrity and how this relates to Ubuntu compared to the recent npm event-stream compromise.

    This week in Ubuntu Security Updates

    32 unique CVEs addressed

    [USN-3826-1] QEMU vulnerabilities

    • 10 CVEs addressed in Trusty, Xenial, Bionic, Cosmic
      • CVE-2018-19364
      • CVE-2018-18954
      • CVE-2018-18849
      • CVE-2018-17963
      • CVE-2018-17962
      • CVE-2018-17958
      • CVE-2018-16847
      • CVE-2018-12617
      • CVE-2018-11806
      • CVE-2018-10839
    • 7 medium, 3 low priority
      • Integer overflow in virtual network interface driver, able to be triggered by user process in guest -> crash -> DoS
      • Heap based buffer overflow in SLiRP, user-based networking stack (default) during reassembly of fragmented datagrams
      • Integer overflow when reading large blocks from files - nice PoC on github
      • NVMe emulator missing checks on read / write parameters - OOB heap buffer r/w - guest user/process could trigger -> DoS (crash) or possible arbitrary code execution on host as qemu process
      • Integer type mismatch in rtl8139 and pcnet drivers - (from size_t to int) - unsigned to signed - INT_MAX -> -ve -> OOB read - crash / DoS
        • Copy-pasta?

    [USN-3827-1, USN-3827-2] Samba vulnerabilities

    • 4 CVEs addressed in Precise ESM, Trusty, Xenial, Bionic, Cosmic
      • CVE-2018-16851
      • CVE-2018-1685
      • CVE-2018-16841
      • CVE-2018-14629
    • CNAME records could point to themselves - infinite recursion in internal AD DNS server
      • Users can add CNAME records -> user triggerable
      • Fix ensures CNAMEs can’t refer to themselves
    • If using smartcard authentication for AD, double free could occur due to mismatch in certificate vs authentication request parameters
      • talloc - robust against heap corruption - assert() fail - exit - DoS
    • Null pointer dereference when reading more than 256MB of LDAP entries - DoS crash

    [USN-3828-1] WebKitGTK+ vulnerabilities

    • 3 CVEs addressed in Bionic, Cosmic
      • CVE-2018-4386
      • CVE-2018-4372
      • CVE-2018-4345
    • Minimal details provided by upstream webkit regarding these advisories:
      • XSS due to improper URL validation
      • Multiple memory corruption issues which could lead to arbitrary code execution

    [USN-3816-3] systemd regression

    • 3 CVEs addressed in Xenial
      • CVE-2018-15687
      • CVE-2018-15686
      • CVE-2018-6954
    • Episode 12 & 13 - backport of large upstream patches to better handle symlink resolution in systemd-tmpfiles
    • New code uses openat with O_PATH flag internally
    • O_PATH was only introduced in Linux kernel 2.6.39
    • Fails on pre-2.6.39 kernels - eg. OpenVZ
    • So if running an Ubuntu Xenial kernel on OpenVZ systemd would fail to work correctly
    • OpenVZ have released updated kernel as well to support O_PATH

    [USN-3829-1] Git vulnerabilities

    • 2 CVEs addressed in Trusty, Xenial, Bionic, Cosmic
      • CVE-2018-19486
      • CVE-2017-15298
    • Previously would execute commands from CWD, rather than from PATH
      • Could allow arbitrary code execution if using a malicious repository
    • DoS due to large memory usage (Git Bomb) with specially crafted repository
      • Small repo with only 12 unique objects inside but that which are duplicated across the repo tree
      • Git would usually crash due to running out of memory BUT if did manage to survive and write to disk could consume a lot of disk space too
      • Only Trusty and Xenial affected (fixed already in Bionic etc)

    [USN-3830-1] OpenJDK regression

    • Recent OpenJDK update (Episode 10) add stricter checking for JAR files
      • As a result, failed to find JAR files during build resulting in failed project builds
    • New option should have been disabled by default to give time for other packages to be updated etc to deal wth new behaviour
      • Is now :)

    [USN-3831-1] Ghostscript vulnerabilities

    • 4 CVEs addressed in Trusty, Xenial, Bionic, Cosmic
      • CVE-2018-19477
      • CVE-2018-19476
      • CVE-2018-19475
      • CVE-2018-19409
    • Even more gs - (Episode 10, 7, 5)

    [USN-3795-3] libssh regression

    • CVE-2018-10933 - covered in Episode 8
    • Upstream fix introduced a regression which broke server-side keyboard authentication
    • Server-side, not client-side
      • Not a common scenario used so unlikely to affect many users as need to use multiple interactive keyboard-based prompts to trigger (say password and token)
      • Server would be stuck
    • Backport upstream fix

    [USN-3832-1, USN-3833-1] Linux kernel (AWS) vulnerabilities

    • 6 CVEs addressed in Cosmic, first 2 in Bionic as well
      • CVE-2018-6559
      • CVE-2018-18955
      • CVE-2018-18653
      • CVE-2018-18445
      • CVE-2018-18281
      • CVE-2018-17972
    • Philipp Wendler discovered Ubuntu specific flaw in the way user namespaces interact with overlayfs
    • Allows regular users to list contents of directories which they do not have read-access to (ie could list /root)
    • Create a user and a mount namespace and then mount an overlay via overlayfs within it
      • Within the overlayed mount, if say contained “root” and was mounted at the filesystem root (/), overlayfs would get confused about which permissions to use when running and would not use the real underlying permissions but would instead use the user supplied ones from the overlayed fs
    • Relates to the fix for a previous CVE (CVE-2015-1328)
      • This fix got dropped during Bionic development cycle so reintroduced this similar vulnerability
      • New test added to Ubuntu kernel test suite to ensure this does not regress again in the future

    Open Source Software Supply Chain Integrity

    • NPM package (event-stream) got hijacked to inject code to target users of copay (Bitcoin wallet)
    • Author of event-stream had lost interest, was emailed by a small contributor to take over maintenance and gave them ownership of the repo
      • Pushed a small change to add a new dependency to the package
      • This then contained code to try and bundle itself with target application - copay-dash
      • Targetted software supply chain at 2 points - event-stream repo / package AND getting into the build-system for copay-dash as a result
        • So would bundle bitcoin wallet stealing code into copay-dash
    • 2 software supply chain attacks
      • Hard to fix first one since maintainers can lost interest and hand over to anyone
        • New owner may not have trust the old one did
        • npm doesn’t care - is uncurated
      • Copay bundled and distributed dependencies so perhaps should have some responsibility to check those etc
    • Ubuntu is based on Debian and both are curated repos
      • Packages are maintained by trusted developers
      • Much harder to mount a similar attach on Ubuntu / Debian archives due to barrier to entry as a trusted developer
      • Smaller dependency chains as well compared to npm so harder to hide such an attack as well
    • Snap store is a different story though
    • Bottom line - have to trust your software suppliers
      • Ubuntu - Canonical / trusted maintainers
      • Snap store - individual publishers

    Get in contact

    • security@ubuntu.com
    • #ubuntu-security on the Libera.Chat IRC network
    • @ubuntu_sec on twitter

    Previous 1 21 22 23 24 25 Next

    Related Podcasts

    Reply All

    1

    Reply All Games & Hobbies
    Inside VR & AR

    2

    Inside VR & AR Gadgets
    Note to Self

    3

    Note to Self News
    BrainStuff

    4

    BrainStuff Natural Sciences
    This Week in Tech (Audio)

    5

    This Week in Tech (Audio) News
    Hands-On Tech (Audio)

    6

    Hands-On Tech (Audio) Technology
    footer-logo

    Contact Us

    Toll Free: 844-670-7747

    Links

    • Home
    • Top Charts
    • Networks
    • Apps
    • Independents Podcasts
    • Podcast Advertising
    • Podcast News
    • Contact Us
    • About Us
    • Analytics & Insights

    Stay Connected

      Privacy, Terms of Use & Our Code of Ethics Protecting Content Creators Copyrights