Friday, September 28, 2018
[USN-3719-3] Mutt vulnerabilities
Ubuntu Security Notice USN-3719-3
September 28, 2018
mutt vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 16.04 LTS
Summary:
Several security issues were fixed in Mutt.
Software Description:
- mutt: text-based mailreader supporting MIME, GPG, PGP and threading
Details:
USN-3719-1 fixed vulnerabilities in Mutt. Unfortunately, the fixes were
not correctly applied to the packaging for Mutt in Ubuntu 16.04 LTS.
This update corrects the oversight.
We apologize for the inconvenience.
Original advisory details:
It was discovered that Mutt incorrectly handled certain requests.
An attacker could possibly use this to execute arbitrary code.
(CVE-2018-14350, CVE-2018-14352, CVE-2018-14354, CVE-2018-14359,
CVE-2018-14358, CVE-2018-14353 ,CVE-2018-14357)
It was discovered that Mutt incorrectly handled certain inputs.
An attacker could possibly use this to access or expose sensitive
information. (CVE-2018-14355, CVE-2018-14356, CVE-2018-14351,
CVE-2018-14362, CVE-2018-14349)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 16.04 LTS:
mutt 1.5.24-1ubuntu0.2
mutt-patched 1.5.24-1ubuntu0.2
After a standard system update you need to restart mutt to make all the
necessary changes.
References:
https://usn.ubuntu.com/usn/usn-3719-3
https://usn.ubuntu.com/usn/usn-3719-1
CVE-2018-14349, CVE-2018-14350, CVE-2018-14351, CVE-2018-14352,
CVE-2018-14353, CVE-2018-14354, CVE-2018-14355, CVE-2018-14356,
CVE-2018-14357, CVE-2018-14358, CVE-2018-14359, CVE-2018-14362,
https://launchpad.net/bugs/1794278
Package Information:
https://launchpad.net/ubuntu/+source/mutt/1.5.24-1ubuntu0.2
Thursday, September 27, 2018
Ubuntu 18.10 (Cosmic Cuttlefish) Beta released
Ubuntu 18.10 Desktop, Server, and Cloud products.
Codenamed "Cosmic Cuttlefish", 18.10 continues Ubuntu's proud tradition
of integrating the latest and greatest open source technologies into a
high-quality, easy-to-use Linux distribution. The team has been hard
at work through this cycle, introducing new features and fixing bugs.
This beta release includes images from not only the Ubuntu Desktop,
Server, and Cloud products, but also the Kubuntu, Lubuntu, Ubuntu
Budgie, UbuntuKylin, Ubuntu MATE, Ubuntu Studio, and Xubuntu flavours.
The beta images are known to be reasonably free of showstopper CD
build or installer bugs, while representing a very recent snapshot of
18.10 that should be representative of the features intended to ship
with the final release expected on October 18th, 2018.
Ubuntu, Ubuntu Server, Cloud Images:
Cosmic Final Beta includes updated versions of most of our core set
of packages, including a current 4.18 kernel, and much more.
To upgrade to Ubuntu 18.10 Beta from Ubuntu 18.04, follow these
instructions:
https://help.ubuntu.com/community/CosmicUpgrades
The Ubuntu 18.10 Beta images can be downloaded at:
http://releases.ubuntu.com/18.10/ (Ubuntu and Ubuntu Server on x86)
This Ubuntu Server image features the next generation Subiquity server
installer, bringing the comfortable live session and speedy install of the
Ubuntu Desktop to server users at last.
This new installer does not support the same set of installation options
as the previous server installer, so the "debian-installer" image
continues to be made available in parallel. For more information about
the installation options, please see:
https://wiki.ubuntu.com/CosmicCuttlefish/ReleaseNotes#Ubuntu_Server
Additional images can be found at the following links:
http://cloud-images.ubuntu.com/daily/server/cosmic/current/ (Cloud Images)
http://cdimage.ubuntu.com/releases/18.10/beta/ (Non-x86, and d-i Server)
http://cdimage.ubuntu.com/netboot/18.10/ (Netboot)
As fixes will be included in new images between now and release, any
daily cloud image from today or later (i.e. a serial of 20180927 or
higher) should be considered a beta image. Bugs found should be filed
against the appropriate packages or, failing that, the cloud-images
project in Launchpad.
The full release notes for Ubuntu 18.10 Beta can be found at:
https://wiki.ubuntu.com/CosmicCuttlefish/ReleaseNotes
Kubuntu:
Kubuntu is the KDE based flavour of Ubuntu. It uses the Plasma desktop
and includes a wide selection of tools from the KDE project.
The Beta images can be downloaded at:
http://cdimage.ubuntu.com/kubuntu/releases/18.10/beta/
Lubuntu:
Lubuntu is a flavor of Ubuntu which uses the Lightweight Qt Desktop
Environment (LXQt). The project's goal is to provide a lightweight
yet functional Linux distribution based on a rock-solid Ubuntu base.
The Beta images can be downloaded at:
http://cdimage.ubuntu.com/lubuntu/releases/18.10/beta/
Ubuntu Budgie:
Ubuntu Budgie is community developed desktop, integrating Budgie
Desktop Environment with Ubuntu at its core.
The Beta images can be downloaded at:
http://cdimage.ubuntu.com/ubuntu-budgie/releases/18.10/beta/
UbuntuKylin:
UbuntuKylin is a flavor of Ubuntu that is more suitable for Chinese
users.
The Beta images can be downloaded at:
http://cdimage.ubuntu.com/ubuntukylin/releases/18.10/beta/
Ubuntu MATE:
Ubuntu MATE is a flavor of Ubuntu featuring the MATE desktop
environment.
The Beta images can be downloaded at:
http://cdimage.ubuntu.com/ubuntu-mate/releases/18.10/beta/
Ubuntu Studio:
Ubuntu Studio is a flavor of Ubuntu that provides a full range of
multimedia content creation applications for each key workflows:
audio, graphics, video, photography and publishing.
The Beta images can be downloaded at:
http://cdimage.ubuntu.com/ubuntustudio/releases/18.10/beta/
Xubuntu:
Xubuntu is a flavor of Ubuntu that comes with Xfce, which is a stable,
light and configurable desktop environment.
The Beta images can be downloaded at:
http://cdimage.ubuntu.com/xubuntu/releases/18.10/beta/
Regular daily images for Ubuntu, and all flavours, can be found at:
http://cdimage.ubuntu.com
Ubuntu is a full-featured Linux distribution for clients, servers and
clouds, with a fast and easy installation and regular releases. A
tightly-integrated selection of excellent applications is included,
and an incredible variety of add-on software is just a few clicks
away.
Professional technical support is available from Canonical Limited and
hundreds of other companies around the world. For more information
about support, visit http://www.ubuntu.com/support
If you would like to help shape Ubuntu, take a look at the list of
ways you can participate at:
http://www.ubuntu.com/community/participate
Your comments, bug reports, patches and suggestions really help us to
improve this and future releases of Ubuntu. Instructions can be
found at: https://help.ubuntu.com/community/ReportingBugs
You can find out more about Ubuntu and about this beta release on our
website, IRC channel and wiki.
To sign up for future Ubuntu announcements, please subscribe to
Ubuntu's very low volume announcement list at:
http://lists.ubuntu.com/mailman/listinfo/ubuntu-announce
On behalf of the Ubuntu Release Team,
... Adam Conrad
--
ubuntu-announce mailing list
ubuntu-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-announce
[FreeBSD-Announce] FreeBSD Errata Notice FreeBSD-EN-18:11.listen
Hash: SHA512
=============================================================================
FreeBSD-EN-18:11.listen Errata Notice
The FreeBSD Project
Topic: Denial of service in listen syscall over IPv6 socket
Category: core
Module: kernel
Announced: 2018-09-27
Credits: Jakub Jirasek, Secunia Research at Flexera
Affects: All supported versions of FreeBSD.
Corrected: 2018-09-27 18:50:10 UTC (stable/11, 11.2-STABLE)
2018-09-27 18:34:42 UTC (releng/11.2, 11.2-RELEASE-p4)
2018-09-27 18:34:42 UTC (releng/11.1, 11.1-RELEASE-p15)
2018-09-27 18:48:50 UTC (stable/10, 10.4-STABLE)
2018-09-27 18:34:42 UTC (releng/10.4, 10.4-RELEASE-p13)
CVE Name: CVE-2018-6925
For general information regarding FreeBSD Errata Notices and Security
Advisories, including descriptions of the fields above, security
branches, and the following sections, please visit
<URL:https://security.FreeBSD.org/>.
I. Background
The protocol control block is a structure that maintains the network layer
state for various sockets. There are various state flags that must be
properly maintained to keep the structure consistent.
II. Problem Description
There are various cases in the IPv6 socket code where the protocol control
block's state flags are modified during a syscall, but are not restored if
the operation fails. This can leave the control block in an inconsistent
state.
III. Impact
A local unprivileged user could exploit the inconsistent state of the
protocol control block to cause the kernel to crash, leading to a denial of
service.
IV. Workaround
No workaround is available.
V. Solution
Perform one of the following:
1) Upgrade your system to a supported FreeBSD stable or release / security
branch (releng) dated after the correction date.
Afterward, reboot the system.
2) To update your system via a binary patch:
Systems running a RELEASE version of FreeBSD on the i386 or amd64
platforms can be updated via the freebsd-update(8) utility:
# freebsd-update fetch
# freebsd-update install
Afterward, reboot the system.
3) To update your system via a source code patch:
The following patches have been verified to apply to the applicable
FreeBSD release branches.
a) Download the relevant patch from the location below, and verify the
detached PGP signature using your PGP utility.
[FreeBSD 11.x]
# fetch https://security.FreeBSD.org/patches/EN-18:11/listen-11.patch
# fetch https://security.FreeBSD.org/patches/EN-18:11/listen-11.patch.asc
# gpg --verify listen-11.patch.asc
[FreeBSD 10.4]
# fetch https://security.FreeBSD.org/patches/EN-18:11/listen-10.patch
# fetch https://security.FreeBSD.org/patches/EN-18:11/listen-10.patch.asc
# gpg --verify listen-10.patch.asc
b) Apply the patch. Execute the following commands as root:
# cd /usr/src
# patch < /path/to/patch
c) Recompile your kernel as described in
<URL:https://www.FreeBSD.org/handbook/kernelconfig.html> and reboot the
system.
VI. Correction details
The following list contains the correction revision numbers for each
affected branch.
Branch/path Revision
- -------------------------------------------------------------------------
stable/10/ r338985
releng/10.4/ r338980
stable/11/ r338986
releng/11.1/ r338980
releng/11.2/ r338980
- -------------------------------------------------------------------------
To see which files were modified by a particular revision, run the
following command, replacing NNNNNN with the revision number, on a
machine with Subversion installed:
# svn diff -cNNNNNN --summarize svn://svn.freebsd.org/base
Or visit the following URL, replacing NNNNNN with the revision number:
<URL:https://svnweb.freebsd.org/base?view=revision&revision=NNNNNN>
VII. References
<URL:https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-6925>
For information about Secunia Research:
<URL:https://www.flexerasoftware.com/enterprise/company/about/secunia-research/>
The latest revision of this advisory is available at
<URL:https://security.FreeBSD.org/advisories/FreeBSD-EN-18:11.listen.asc>
-----BEGIN PGP SIGNATURE-----
iQKTBAEBCgB9FiEE/A6HiuWv54gCjWNV05eS9J6n5cIFAlutKURfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEZD
MEU4NzhBRTVBRkU3ODgwMjhENjM1NUQzOTc5MkY0OUVBN0U1QzIACgkQ05eS9J6n
5cIUEA/+JxBo76dRre8nfvYcN2PJGGFn8i2mWwSG87SWwQUeKlkgpJCV8qMnVEr2
dGz3gwBsxFLKUjQVyl+IwFkaJgKXMbFYkfIqLaS+3a12KLllFAn2Q0dnN+oxFhS2
Wpx4DkDRgBzEyLokxwjUCtg2fd6HPlML2YXCR5SqjXDOoBGAR9GCCXXYNnWSC00y
IYgeC8UpE3ykTlwDH8q+LgLqtnx/oDW1h6UR12alP0ytH8+BldiAqRxjHE3/Wv2E
aU8m8YuAAIW4tHZ4vdqpiFP4grN/0tSf/DEPBTtVIv5FGpXSk61YTBSm4OMIKNN8
QEVEA6n6NEGSKYrbB5BE73KYgCAaeGzcGikX9F4aAlN5GSPBVJ66SEbk16YDzDfB
KimjhityEP5YXh8hVkNo6fq+17dKpqx81390wzcXeDlBTIkANnKLh23gE0RuniNY
dXrPE2HWSpkCnWN6l0BImefDeCgAaF7KZK+z7bbsn2D7UMGFGeHU/XlRM0ze7OOV
ETqwk2M4GuxddHTKktNGBItWVd6EjReAh6QOo1kAA4qMKuNIiDQdRS72x6fUbmlA
ZIOzPNd6TS57aKSnAZlR1SpvRMqo+g9cetMxuJmKnQ+hXaRk2zJVuP2RAJuoFFqf
TmnVAPpDRjoYa0lf2YkOKtYcfF+pBcWI1CVAEFuQG2PheJRYns0=
=jMY6
-----END PGP SIGNATURE-----
_______________________________________________
freebsd-announce@freebsd.org mailing list
https://lists.freebsd.org/mailman/listinfo/freebsd-announce
To unsubscribe, send any mail to "freebsd-announce-unsubscribe@freebsd.org"
[FreeBSD-Announce] FreeBSD Errata Notice FreeBSD-EN-18:10.syscall
Hash: SHA512
=============================================================================
FreeBSD-EN-18:10.syscall Errata Notice
The FreeBSD Project
Topic: NULL pointer dereference in freebsd4_getfsstat system call
Category: core
Module: kernel
Announced: 2018-09-27
Credits: Thomas Barabosch, Fraunhofer FKIE
Affects: FreeBSD 11.x
Corrected: 2018-09-27 18:54:41 UTC (stable/11, 11.1-STABLE)
2018-09-27 18:32:14 UTC (releng/11.2, 11.2-RELEASE-p4)
2018-09-27 18:32:14 UTC (releng/11.1, 11.1-RELEASE-p15)
CVE Name: CVE-2018-17154
For general information regarding FreeBSD Errata Notices and Security
Advisories, including descriptions of the fields above, security
branches, and the following sections, please visit
<URL:https://security.FreeBSD.org/>.
I. Background
The freebsd4_getfsstat system call returns information about all mounted file
systems in a binary format compatible with FreeBSD 4.x. Part of the call
includes passing in a userland allocated buffer for the system call to fill
along with the size of the buffer.
II. Problem Description
Insufficient checking occurs on the buffer when a very large buffer size causes
memory allocation to fail. Resulting code attempts to free the NULL pointer.
III. Impact
A local unprivileged user may cause a denial of service using a specially
crafted binary.
IV. Workaround
No workaround is available.
V. Solution
Perform one of the following:
1) Upgrade your system to a supported FreeBSD stable or release / security
branch (releng) dated after the correction date.
Afterward, reboot the system.
2) To update your system via a binary patch:
Systems running a RELEASE version of FreeBSD on the i386 or amd64
platforms can be updated via the freebsd-update(8) utility:
# freebsd-update fetch
# freebsd-update install
Afterward, reboot the system.
3) To update your system via a source code patch:
The following patches have been verified to apply to the applicable
FreeBSD release branches.
a) Download the relevant patch from the location below, and verify the
detached PGP signature using your PGP utility.
[FreeBSD 11.x]
# fetch https://security.FreeBSD.org/patches/EN-18:10/syscall-11.patch
# fetch https://security.FreeBSD.org/patches/EN-18:10/syscall-11.patch.asc
# gpg --verify syscall-11.patch.asc
b) Apply the patch. Execute the following commands as root:
# cd /usr/src
# patch < /path/to/patch
c) Recompile your kernel as described in
<URL:https://www.FreeBSD.org/handbook/kernelconfig.html> and reboot the
system.
VI. Correction details
The following list contains the correction revision numbers for each
affected branch.
Branch/path Revision
- -------------------------------------------------------------------------
stable/11/ r338987
releng/11.1/ r338979
releng/11.2/ r338979
- -------------------------------------------------------------------------
To see which files were modified by a particular revision, run the
following command, replacing NNNNNN with the revision number, on a
machine with Subversion installed:
# svn diff -cNNNNNN --summarize svn://svn.freebsd.org/base
Or visit the following URL, replacing NNNNNN with the revision number:
<URL:https://svnweb.freebsd.org/base?view=revision&revision=NNNNNN>
VII. References
<URL:https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-17154>
The latest revision of this advisory is available at
<URL:https://security.FreeBSD.org/advisories/FreeBSD-EN-18:10.syscall.asc>
-----BEGIN PGP SIGNATURE-----
iQKSBAEBCgB9FiEE/A6HiuWv54gCjWNV05eS9J6n5cIFAlutKT9fFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEZD
MEU4NzhBRTVBRkU3ODgwMjhENjM1NUQzOTc5MkY0OUVBN0U1QzIACgkQ05eS9J6n
5cJMqQ/4ycdylBNCX0cqFDYrtDU0OJO0mEi2LKqCM31YzOCLbKLtVSq06rxOj/E9
0okWag0NxaGIo2+7+b/hykDwL+1Rwpa5YNdODESRYQeW0OVdnmy/JSB/8q2I2BwX
PrqMc38sc9YuCz202B7tj4CQRKyhe2/qWRXANzh4jolC8zIuP7zAH6bMO+jc4XJS
9qe2YdvChWiwLJXOSXaqZf1xY1jY08+lRGDx03n13OLRN8PZdbIoDEmOd2/vxhcV
YRcDH0axLJSyngknPE9gU8iVZDunxpNBool5hJYDd8rBbAfypXWSDZ7wJGUn7tUZ
3Cj/NPmZ9auMTGLgpRJB/bhgCnn3mZQ5QjR1egonZf3uIlTWZ+0C9GhJjh5cw+2p
3hF+202uJicNm5TSkO6QpavVVvQNFcuCR54ZvXEICv3YNam3yDupGWsbjHloxoCw
7A/wmBBcbtAJ7ujzgPm4+yN5Vno4dcPmkIfW9bz0fwXzYF1VEaF5pZZu7a9bjdI0
xHBk2v77NIRBxC5i1KK5R5Guj0UY0EvkclBTF4Twh3TP0SAPN+5sqpmBRQwPGEdp
9v5TPQv5DJn0KTJwkdrrP+70WIYkfcUVJ9hJYbXAMXseN1q3mTggS/ypF9ckTP0Z
D1hQuUySz07GInHlJ+znS8CzVSj/iWqsxThBBbwgy1a4haxr5A==
=HCqG
-----END PGP SIGNATURE-----
_______________________________________________
freebsd-announce@freebsd.org mailing list
https://lists.freebsd.org/mailman/listinfo/freebsd-announce
To unsubscribe, send any mail to "freebsd-announce-unsubscribe@freebsd.org"
[FreeBSD-Announce] FreeBSD Errata Notice FreeBSD-EN-18:12.mem
Hash: SHA512
=============================================================================
FreeBSD-EN-18:12.mem Errata Notice
The FreeBSD Project
Topic: Small kernel memory disclosures in two system calls
Category: core
Module: kernel
Announced: 2018-09-27
Credits: Thomas Barabosch, Fraunhofer FKIE
Affects: All supported versions of FreeBSD.
Corrected: 2018-09-27 18:42:40 UTC (stable/11, 11.2-STABLE)
2018-09-27 18:36:30 UTC (releng/11.2, 11.2-RELEASE-p4)
2018-09-27 18:36:30 UTC (releng/11.1, 11.1-RELEASE-p15)
2018-09-27 18:44:40 UTC (stable/10, 10.4-STABLE)
2018-09-27 18:36:30 UTC (releng/10.4, 10.4-RELEASE-p13)
CVE Name: CVE-2018-17155
For general information regarding FreeBSD Errata Notices and Security
Advisories, including descriptions of the fields above, security
branches, and the following sections, please visit
<URL:https://security.FreeBSD.org/>.
I. Background
The kernel provides an interface for userland programs via system calls. Two
of these system calls are named getcontext and swapcontext.
II. Problem Description
Due to insufficient initialization of memory copied to userland in the
getcontext and swapcontext system calls, small amounts of kernel memory may
be disclosed to userland processes.
III. Impact
An unprivileged local user may be able to create a specific program to read
the contents of small portions of kernel memory.
Such memory might contain sensitive information, such as portions of the file
cache or terminal buffers. This information might be directly useful, or it
might be leveraged to obtain elevated privileges in some way; for example,
a terminal buffer might include a user-entered password.
IV. Workaround
No workaround is available.
V. Solution
Perform one of the following:
1) Upgrade your system to a supported FreeBSD stable or release / security
branch (releng) dated after the correction date.
Afterward, reboot the system.
2) To update your system via a binary patch:
Systems running a RELEASE version of FreeBSD on the i386 or amd64
platforms can be updated via the freebsd-update(8) utility:
# freebsd-update fetch
# freebsd-update install
Afterward, reboot the system.
3) To update your system via a source code patch:
The following patches have been verified to apply to the applicable
FreeBSD release branches.
a) Download the relevant patch from the location below, and verify the
detached PGP signature using your PGP utility.
# fetch https://security.FreeBSD.org/patches/EN-18:12/mem.patch
# fetch https://security.FreeBSD.org/patches/EN-18:12/mem.patch.asc
# gpg --verify mem.patch.asc
b) Apply the patch. Execute the following commands as root:
# cd /usr/src
# patch < /path/to/patch
c) Recompile your kernel as described in
<URL:https://www.FreeBSD.org/handbook/kernelconfig.html> and reboot the
system.
VI. Correction details
The following list contains the correction revision numbers for each
affected branch.
Branch/path Revision
- -------------------------------------------------------------------------
stable/10/ r339984
releng/10.4/ r338981
stable/11/ r339983
releng/11.1/ r338981
releng/11.2/ r338981
- -------------------------------------------------------------------------
To see which files were modified by a particular revision, run the
following command, replacing NNNNNN with the revision number, on a
machine with Subversion installed:
# svn diff -cNNNNNN --summarize svn://svn.freebsd.org/base
Or visit the following URL, replacing NNNNNN with the revision number:
<URL:https://svnweb.freebsd.org/base?view=revision&revision=NNNNNN>
VII. References
<URL:https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-17155>
The latest revision of this advisory is available at
<URL:https://security.FreeBSD.org/advisories/FreeBSD-EN-18:12.mem.asc>
-----BEGIN PGP SIGNATURE-----
iQKSBAEBCgB9FiEE/A6HiuWv54gCjWNV05eS9J6n5cIFAlutKU5fFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEZD
MEU4NzhBRTVBRkU3ODgwMjhENjM1NUQzOTc5MkY0OUVBN0U1QzIACgkQ05eS9J6n
5cJfGA/3XLR2dunxnQZYQvdpA8k9HA1zHfKFUMbTJqESIZPofvLnFJiw7gwDl0mF
pMC5LCi+k+LIIsXPLzRk/7BUmoCt/hCbD7BOVuiYXhIZy0VgKhaOggSvOXYOsjNl
JTJa5zGsKm4BUNhAkxcJtCO9i+gOShZ2fxiJ9SU7bO/gVl5HoMh56KWTLUBXX2jD
vZfEvxJvllbvk6ST68jb7C0Ix47+idRO2hdfxVLyZfD1PsILIy6JThqKqsbGgqbA
+ma7OnCigxwI0bds4nusi7vNu3IiFuzjBLfV9exW8kcRgyotOsmCfCjSOlOcEJvR
gKcmqZccf1SMGFR336YwGB66xL56QwpgN+UZ/QhmBX15mqI/oAekd0W3fb3OmfvW
bMiDo0MHmtZqiSnQyUOcCPRW5s0l8EHeWCVbjKX1ViqY6e4NdQajrjRUyXnOqcM5
vtTWAJ+BCc3Acg1V4nkjF7HNCUyGObKZcbDqK7M7p5+i/CFxJkCdKu0x8dsZRHL8
7V4SL1sb9OkPWjBxyzHuiQNGJfTgknDsIxvBYcdPVukTtGzrWH1skhdWL2O0CNvQ
Quk2YQePQ/X4ICPIB3s+Yao5N8t0FoEM4Hus6nSCpNRyP5XpCaBISHbhG8Ay7yJr
1p0YkV22eQ5KXiNY6Qmof7S0S1p8IZlomO8J8I/yGuwqh2mkkQ==
=uZtl
-----END PGP SIGNATURE-----
_______________________________________________
freebsd-announce@freebsd.org mailing list
https://lists.freebsd.org/mailman/listinfo/freebsd-announce
To unsubscribe, send any mail to "freebsd-announce-unsubscribe@freebsd.org"
[FreeBSD-Announce] FreeBSD Errata Notice FreeBSD-EN-18:09.ip
Hash: SHA512
=============================================================================
FreeBSD-EN-18:09.ip Errata Notice
The FreeBSD Project
Topic: IP fragment remediation causes IPv6 fragment
reassembly failure
Category: core
Module: kernel
Announced: 2018-09-27
Credits: Kristof Provost
Affects: FreeBSD 11.1 and FreeBSD 11.2
Corrected: 2018-09-27 18:29:55 UTC (releng/11.2, 11.2-RELEASE-p4)
2018-09-27 18:29:55 UTC (releng/11.1, 11.1-RELEASE-p15)
For general information regarding FreeBSD Errata Notices and Security
Advisories, including descriptions of the fields above, security
branches, and the following sections, please visit
<URL:https://security.FreeBSD.org/>.
I. Background
The recent security advisory titled SA-18:10.ip resolved an issue in the IPv4
and IPv6 fragment reassembly code.
II. Problem Description
As a result of fixing the issue describe in SA-18:10.ip, a regression was
introduced in the IPv6 fragment hashing code which could cause reassembly to
fail.
III. Impact
Received IPv6 packets requiring fragment reassembly may be dropped instead of
properly reassembled and delivered.
IV. Workaround
Disable IPv6 fragment reassembly, using these commands:
% sysctl net.inet6.ip6.maxfrags=0
On systems compiled with VIMAGE, these sysctls will need to be
executed for each VNET.
V. Solution
Perform one of the following:
1) Upgrade your system to a supported FreeBSD stable or release / security
branch (releng) dated after the correction date.
Afterward, reboot the system.
2) To update your system via a binary patch:
Systems running a RELEASE version of FreeBSD on the i386 or amd64
platforms can be updated via the freebsd-update(8) utility:
# freebsd-update fetch
# freebsd-update install
Afterward, reboot the system.
3) To update your system via a source code patch:
The following patches have been verified to apply to the applicable
FreeBSD release branches.
a) Download the relevant patch from the location below, and verify the
detached PGP signature using your PGP utility.
[FreeBSD 11.x]
# fetch https://security.FreeBSD.org/patches/EN-18:09/ip.patch
# fetch https://security.FreeBSD.org/patches/EN-18:09/ip.patch.asc
# gpg --verify ip.patch.asc
b) Apply the patch. Execute the following commands as root:
# cd /usr/src
# patch < /path/to/patch
c) Recompile your kernel as described in
<URL:https://www.FreeBSD.org/handbook/kernelconfig.html> and reboot the
system.
VI. Correction details
The following list contains the correction revision numbers for each
affected branch.
Branch/path Revision
- -------------------------------------------------------------------------
releng/11.1/ r338978
releng/11.2/ r338978
- -------------------------------------------------------------------------
To see which files were modified by a particular revision, run the
following command, replacing NNNNNN with the revision number, on a
machine with Subversion installed:
# svn diff -cNNNNNN --summarize svn://svn.freebsd.org/base
Or visit the following URL, replacing NNNNNN with the revision number:
<URL:https://svnweb.freebsd.org/base?view=revision&revision=NNNNNN>
VII. References
The security advisory that introduced the regression is available at
<URL:https://www.freebsd.org/security/advisories/FreeBSD-SA-18:10.ip.asc>
<URL:https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=231045>
The latest revision of this advisory is available at
<URL:https://security.FreeBSD.org/advisories/FreeBSD-EN-18:09.ip.asc>
-----BEGIN PGP SIGNATURE-----
iQKTBAEBCgB9FiEE/A6HiuWv54gCjWNV05eS9J6n5cIFAlutKTVfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEZD
MEU4NzhBRTVBRkU3ODgwMjhENjM1NUQzOTc5MkY0OUVBN0U1QzIACgkQ05eS9J6n
5cKagRAAh4AnkPqG5hNnpilNct2cjY6GrU+Ex0hmbDbv36RR5Cj/Xi6FrdjGdF6/
sA5/KYC1fOe07S2JJDgh2b5f1E3NBtfCCXQL3Fq46LRu8KJUifReY23kxNw74pev
86WmxtctkJ62gc3EUhaTx5tgvIqHRnLrNbJqAJ9VEZkV5aa33yT/5zDTq0TLJPsK
LfgwIWw7KAecH28cHx9KH+QyeLEsKoQPj5PIpQih7aZE/8cVLIMxKepExzPFx0s8
SV1BFVQqJaRK4frv7tHZIEjTrseKVhF6SCqbtSVP6ZBtOAaaNGobq9bQNzPPxls7
tTIGC6JVacUNNzJY+uv+DyHwCcEqyU5HQKOaJGqcQ4rxccXdWLBQOA55sRuiCZSy
SxRzs+4JNo2XDACnSECUFFos05HXxOWm8lqt8juR6fnq9Auej/PmktQYHaIXI3us
hYOlHu7Oo6sSGERBE92I1B4Y0L2BzXgroFN+rKmzlLGmM3vQYDxt2o0/GpMRf0wf
I+plRLC9osYTc/QFJzqt6dGJj+46xWyCw8aGcRhtQGPWUcB3DtYRjJxi1x6YjBkN
Cw3nepcW4rwJpmJZyGuNhsyKFZlhhz2+GV1lxsoe5TC6rRbEo30O3aU1zh5+fljo
KR9WSfy6bNoTX4NhbCJ+j9fdD6AxiqWtmB8h4Vp7ykrM/VJLUzc=
=1FtK
-----END PGP SIGNATURE-----
_______________________________________________
freebsd-announce@freebsd.org mailing list
https://lists.freebsd.org/mailman/listinfo/freebsd-announce
To unsubscribe, send any mail to "freebsd-announce-unsubscribe@freebsd.org"
fedora-tagger and statscache sunset
As previously announced [0][1] fedora-tagger and statscache will be retired next Tuesday Oct 02 2018 at 21.00 UTC.
Wednesday, September 26, 2018
[USN-3772-1] UDisks vulnerability
iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAlur0EgACgkQZWnYVadE
vpNExA//flwpvbNlugh9kpCls3VnAyHHSGAK4aiUUqgiWkwat+OXGopM2VMKckuV
zDRCvslNgkV1t8orKrvTdUPLuS7R6eh1GxKC6CiMzpl3Oz81UEFQolk9Vik5kU6J
pphAyaYNXFt/crEiF1kLyr797ERh3i2qJljySQfFmlgSeUzZvUnmgKKyvbUefNOo
FFNcNb0BH8dmF5T7YPqsTOz2MqsSSOpfTC/Qb8+UC21qO0SKiNit06J2IFN1jCAk
ujIpvXW7an7Q6dgxOR4Z/Dnqb/ac/fJzH76ktiTav/4+32ErxRrbGlQrX920zOP5
vXF4Cf7XG68LYKyA8owT/GZcj7d7pyVJjJbQ2IaXJ3kflRfGMJfHH0Ly4Hi6ovLD
PJK6mnZv8ObDZR3oRQquP2JSOCw6Ye3z39EXijc5UpVfThqeQ//ahufW80LpxqCF
JQZRsDMxflx1/oWLLb0rwNOk4D/aj3Nt1dMWYrV/1I5c1OblPcsv9sNsx2N72fQE
Va88bpb/m+yLmbIPy9pEX92dIe1QSDDfLjBqr6s0++G0rtTNPYVXG7GKqJVoHp7B
ohVH8axrC8cmyDy8WGmXO05RxL+J+h/HWNyaxdZBEXhI7aSwUlm0LlvoVek+3k6H
iBn4El1FoThhX2gyqZWxDF9afe0n1EqNBr/STwzrcqeJs9bxeDs=
=Z9ba
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-3772-1
September 26, 2018
udisks2 vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 18.04 LTS
Summary:
Udisks could be made to crash or expose sensitive information.
Software Description:
- udisks2: service to access and manipulate storage devices
Details:
It was discovered that UDisks incorrectly handled format strings when
logging. A local attacker could possibly use this issue to cause a denial
of service or obtain sensitive information.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 18.04 LTS:
udisks2 2.7.6-3ubuntu0.2
After a standard system update you need to reboot your computer to make
all the necessary changes.
References:
https://usn.ubuntu.com/usn/usn-3772-1
CVE-2018-17336
Package Information:
https://launchpad.net/ubuntu/+source/udisks2/2.7.6-3ubuntu0.2
Planned Outage - Fedora Production Openshift - 2018-09-27 21:00 UTC
iQIzBAEBCgAdFiEESz7rprBJHpbnMnrQSzew2A/7u14FAluruowACgkQSzew2A/7
u17oPhAAl9Q+4dy+OK/TBKNVAR5ottE+b5liP76sGMvMLUK0F7qgUvWmpQwXNJZY
blJOlg28QmdWrDlgO8qhdSUR/co1fh9agMhhowRoRI7qemkUeZs5dVSkJsuREBhG
xa90q6WfLsPacNnzNstJ9gb1ScLzfIQFb0mzxNHndpPVPShELw1jDwgxW05hwXLB
sHnTh1oVBd5uBKhM/Rot0cmD5GXxGZDV3JYvevLc6KMhbjGFbtnXFLQFFTnKI4mQ
29N8hwOHiIwDe0u/vkBdHsSMwSi16AHfn51P0fuUAAQPdcxZ7sCbIh6kzK2CpO8F
Vriwd7mtwi3raJ59ZQXIXdBxa4TdydqQSy5DNshMrhvaJFgJDoJ9e31ITpfKrEgB
SOqz9uK+i5yP9zA4a0NlqbW8n+obr7WGTw2/NohvcF6/DvgKz/B6IK0o9UQ8LCgK
/i+K1XfV9cO3dDqpQ80osgH1HZ7XBt2D0hXCXI5OoXA62tCN7FJJ8wsNsfApFwbs
DxOeLe1AuBGcUuulgub03M0+wXCaeBViqhTrKtLQpofB00u5UiBNMyV/w/f14lX7
2JfVvzf3Ene3qWNVtLuRG2Yc19jFPXqVCR5U3Rp7CKYUjIcrLcg3KUhUPqtUp01e
pwakYW1mIhG2RBWzd75r3QP0yRXNLlg+NYDRbYzCb/BMl880AKY=
=p6vC
-----END PGP SIGNATURE-----
Planned Outage - Fedora Production Openshift - 2018-09-27 21:00 UTC
There will be an outage starting at 2018-09-27 21:00 UTC,
which will last approximately 4 hours.
To convert UTC to your local time, take a look at
http://fedoraproject.org/wiki/Infrastructure/UTCHowto
or run:
date -d '2018-09-27 21:00 UTC'
Reason for outage:
We will be redeploying our production openshift with more compute nodes,
and a number of new features enabled.
Affected Services:
https://bodhi.fedoraproject.org
https://coreos.fedoraproject.org
https://greenwave.fedoraproject.org
https://waiverdb.fedoraproject.org
https://silverblue.fedoraproject.org
Ticket Link:
https://pagure.io/fedora-infrastructure/issue/7264
Please join #fedora-admin or #fedora-noc on irc.freenode.net
or add comments to the ticket for this outage above.
LibreSSL 2.8.1 Released
LibreSSL directory of your local OpenBSD mirror soon.
This is the second development release from the 2.8 series, which will
eventually be part of OpenBSD 6.4. It includes the following changes:
* Added Wycheproof test vectors for ECDH, RSASSA-PSS, AES-GCM,
AES-CMAC, AES-CCM, AES-CBC-PKCS5, DSA, ChaCha20-Poly1305, ECDSA,
X25519, and applied appropriate fixes for errors uncovered by tests.
* Simplified key exchange signature generation and verification.
* Fixed a one-byte buffer overrun in callers of EVP_read_pw_string
* Converted more code paths to use CBB/CBS. All handshake messages are
now created by CBB.
* Fixed various memory leaks found by Coverity.
* Simplfied session ticket parsing and handling, inspired by
BoringSSL.
* Modified signature of CRYPTO_mem_leaks_* to return -1. This function
is a no-op in LibreSSL, so this function returns an error to not
indicate the (non-)existence of memory leaks.
* SSL_copy_session_id, PEM_Sign, EVP_EncodeUpdate, BIO_set_cipher,
X509_OBJECT_up_ref_count now return an int for error handling,
matching OpenSSL.
* Converted a number of #defines into proper functions, matching
OpenSSL's ABI.
* Added X509_get0_serialNumber from OpenSSL.
* Removed EVP_PKEY2PKCS8_broken and PKCS8_set_broken, while adding
PKCS8_pkey_add1_attr_by_NID and PKCS8_pkey_get0_attrs, matching
OpenSSL.
* Removed broken pkcs8 formats from openssl(1).
* Converted more functions in public API to use const arguments.
* Stopped handing AES-GCM in ssl_cipher_get_evp, since they use the
EVP_AEAD interface.
* Stopped using composite EVP_CIPHER AEADs.
* Added timing-safe compares for checking results of signature
verification. There are no known attacks, this is just inexpensive
prudence.
* Correctly clear the current cipher state, when changing cipher state.
This fixed an issue where renegotion of cipher suites would fail
when switched from AEAD to non-AEAD or vice-versa.
Issue reported by Bernard Spil.
* Added more cipher tests to appstest.sh, including all TLSv1.2
ciphers.
* Added RSA_meth_get_finish() RSA_meth_set1_name() from OpenSSL.
* Added new EVP_CIPHER_CTX_(get|set)_iv() API that allows the IV to be
retrieved and set with appropriate validation.
The LibreSSL project continues improvement of the codebase to reflect modern,
safe programming practices. We welcome feedback and improvements from the
broader community. Thanks to all of the contributors who helped make this
release possible.
Tuesday, September 25, 2018
Fedora 29 Beta Release Announcement
[USN-3771-1] strongSwan vulnerabilities
iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAluqQTQACgkQZWnYVadE
vpN3DBAAkn02+PYjun7g/3g8cKwkxTzzc+WoGEHDwfeG1zj9EDe9fcWmiXFFr07a
fK94ZveGz1cbIHL5e+CvSXFlGXa2AvWlsYRfcXdUYgGdSZoFwNbccWiQ3UecMiz5
Xh6iht3cpBq7tmlKhEFgxh6Ag1vFhIHAUP3lff1/RDiGUhRTvPjCpYL3UqIW8b9P
imnpqZrriEkEJ+UDiBVMH0nYu5DV4cnOdIbyPNPIcF/wJZVr2kavKkSXn3buCFUf
6C+EgdZqexm7lsau5U70Gt2XzzF32W/MaFRwZbk5dwvmkR+N829kzQmedtXQFN9z
+3fbunPGkIKMeB+q8TwciWx7AqfSuvWUgvIE7QHGVafCjiHfbUiON8h/oiTFZmY8
9byXZhp0pa3puaGNJV2HbCiSjV7B1R0sbyVSof4qNCl9rlCWgMKhOZgi3dnK27a4
UimxPNVVia++U8EfQ5N8PnxeAz9DFRGG0WykBJjACgCmVw5q7mDfZhOY6YFVYcxy
YOzTfdTl8EPeKY4IRgTHIC1B/K1S7iNYm98jrRyJZtO2OI7QvE4TouXFfOwm2YWt
dWWF4XPVVTB14vWhvXc3JxrAatkf8SsAmNUro8F9uCTqb2UcOf98EMyuzK5GA/vO
sYo+dP0nJwlfUFIAXSDs6MmlCT5ZrC6qOPw9y/wtg5m/2v2/u7E=
=Srf5
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-3771-1
September 25, 2018
strongswan vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS
Summary:
Several security issues were fixed in strongSwan.
Software Description:
- strongswan: IPsec VPN solution
Details:
It was discovered that strongSwan incorrectly handled IKEv2 key derivation.
A remote attacker could possibly use this issue to cause strongSwan to
crash, resulting in a denial of service. (CVE-2018-10811)
Sze Yiu Chau discovered that strongSwan incorrectly handled parsing OIDs in
the gmp plugin. A remote attacker could possibly use this issue to bypass
authorization. (CVE-2018-16151)
Sze Yiu Chau discovered that strongSwan incorrectly handled certain
parameters fields in the gmp plugin. A remote attacker could possibly use
this issue to bypass authorization. (CVE-2018-16152)
It was discovered that strongSwan incorrectly handled the stroke plugin. A
local administrator could use this issue to cause a denial of service, or
possibly execute arbitrary code. (CVE-2018-5388)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 18.04 LTS:
libstrongswan 5.6.2-1ubuntu2.2
strongswan 5.6.2-1ubuntu2.2
Ubuntu 16.04 LTS:
libstrongswan 5.3.5-1ubuntu3.7
strongswan 5.3.5-1ubuntu3.7
Ubuntu 14.04 LTS:
libstrongswan 5.1.2-0ubuntu2.10
strongswan 5.1.2-0ubuntu2.10
In general, a standard system update will make all the necessary changes.
References:
https://usn.ubuntu.com/usn/usn-3771-1
CVE-2018-10811, CVE-2018-16151, CVE-2018-16152, CVE-2018-5388
Package Information:
https://launchpad.net/ubuntu/+source/strongswan/5.6.2-1ubuntu2.2
https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.7
https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.10