Friday, September 22, 2023
[arch-announce] Changes to default password hashing algorithm and umask settings
Furthermore, the `umask` [2] settings are now configured in `/etc/login.defs` instead of `/etc/profile`.
This should not require any manual intervention.
## Reasons for Yescrypt
The password-based key derivation function (KDF) and password hashing scheme **yescrypt** has been chosen due to its adoption (readily available in *libxcrypt*, which is used by *pam* [3]) and its stronger resilience towards password cracking attempts over **SHA512**.
Although the winner of the Password Hashing Competition [4] has been **argon2**, this even more resilient algorithm is not yet available in *libxcrypt* [5][6].
## Configuring yescrypt
The `YESCRYPT_COST_FACTOR` setting in `/etc/login.defs` is currently without effect, until *pam* implements reading its value [7]. If a `YESCRYPT_COST_FACTOR` higher (or lower) than the default (`5`) is needed, it can be set using the `rounds` option of the `pam_unix` [8] module (i.e. in `/etc/pam.d/system-auth`).
## General list of changes
- **yescrypt** is used as default password hashing algorithm, instead of **SHA512**
- *pam* honors the chosen `ENCRYPT_METHOD` in `/etc/login.defs` and does not override the chosen method anymore
- changes in the *filesystem* (>= `2023.09.18`) and *pambase* (>= `20230918`) packages ensure, that `umask` is set centrally in `/etc/login.defs` instead of `/etc/profile`
[1] https://www.openwall.com/yescrypt/
[2] https://man.archlinux.org/man/umask.1p
[3] https://wiki.archlinux.org/title/PAM
[4] https://www.password-hashing.net/
[5] https://github.com/besser82/libxcrypt/pull/113
[6] https://github.com/besser82/libxcrypt/pull/150
[7] https://github.com/linux-pam/linux-pam/issues/607
[8] https://man.archlinux.org/man/pam_unix.8
URL: https://archlinux.org/news/changes-to-default-password-hashing-algorithm-and-umask-settings/
Ubuntu 23.10 (Mantic Minotaur) Beta released
Desktop, Server, and Cloud products.
Ubuntu 23.10, codenamed "Mantic Minotaur", continues Ubuntu's proud
tradition of
integrating the latest and greatest open source technologies into a
high-quality, easy-to-use Linux distribution. The team has been hard at work
through this cycle, introducing new features and fixing bugs.
This Beta release includes images from not only the Ubuntu Desktop,
Server, and
Cloud products, but also the Edubuntu, Kubuntu, Lubuntu, Ubuntu Budgie,
Ubuntu Cinnamon, Ubuntu Kylin, Ubuntu MATE, Ubuntu Studio, Ubuntu Unity, and
Xubuntu flavours.
The Beta images are known to be reasonably free of showstopper image
build or
installer bugs, while representing a very recent snapshot of 23.10 that
should
be representative of the features intended to ship with the final release
expected on October 12, 2023.
Ubuntu, Ubuntu Server, Cloud Images:
Mantic Beta includes updated versions of most of our core set of
packages, including a current 6.5 kernel, and much more.
To upgrade to Ubuntu 23.10 Beta from Ubuntu 23.04, follow these
instructions:
https://help.ubuntu.com/community/ManticUpgrades
The Ubuntu 23.10 Beta images can be downloaded at:
https://releases.ubuntu.com/23.10/ (Ubuntu and Ubuntu Server on x86)
The default Ubuntu Desktop installer is now a Flutter snap backed by
Subiquity.
The legacy installer is still available in case of issues with the
new installer.
This Ubuntu Server image features the next generation Subiquity server
installer, bringing the comfortable live session and speedy install of
the Ubuntu Desktop to server users.
Additional images can be found at the following links:
https://cloud-images.ubuntu.com/daily/server/mantic/current/ (Cloud
Images)
https://cdimage.ubuntu.com/releases/23.10/beta/ (Non-x86)
As fixes will be included in new images between now and release, any
daily cloud image should be considered a Beta image. Bugs found should be
filed against the appropriate packages or, failing that, the cloud-images
project in Launchpad.
The full release notes for Ubuntu 23.10 Beta can be found at:
https://discourse.ubuntu.com/t/mantic-minotaur-release-notes
Edubuntu:
Edubuntu is a flavor of Ubuntu designed as a free education oriented
operating system for children of all ages.
The Beta images can be downloaded at:
http://cdimage.ubuntu.com/edubuntu/releases/23.10/beta/
Kubuntu:
Kubuntu is the KDE based flavor of Ubuntu. It uses the Plasma desktop and
includes a wide selection of tools from the KDE project.
The Beta images can be downloaded at:
https://cdimage.ubuntu.com/kubuntu/releases/23.10/beta/
Lubuntu:
Lubuntu is a flavor of Ubuntu which uses the Lightweight Qt Desktop
Environment (LXQt). The project's goal is to provide a lightweight yet
functional Linux distribution based on a rock-solid Ubuntu base.
The Beta images can be downloaded at:
https://cdimage.ubuntu.com/lubuntu/releases/23.10/beta/
Ubuntu Budgie:
Ubuntu Budgie is a community developed desktop, integrating Budgie
Desktop
Environment with Ubuntu at its core.
The Beta images can be downloaded at:
https://cdimage.ubuntu.com/ubuntu-budgie/releases/23.10/beta/
Ubuntu Cinnamon
Ubuntu Cinnamon is a flavor of Ubuntu featuring the Cinnamon desktop
environment.
The Beta images can be downloaded at:
http://cdimage.ubuntu.com/ubuntucinnamon/releases/23.10/beta/
Ubuntu Kylin:
Ubuntu Kylin is a flavor of Ubuntu that is more suitable for Chinese
users.
The Beta images can be downloaded at:
http://cdimage.ubuntu.com/ubuntukylin/releases/23.10/beta/
Ubuntu MATE:
Ubuntu MATE is a flavor of Ubuntu featuring the MATE desktop environment.
The Beta images can be downloaded at:
https://cdimage.ubuntu.com/ubuntu-mate/releases/23.10/beta/
Ubuntu Studio:
Ubuntu Studio is a flavor of Ubuntu that provides a full range of
multimedia
content creation applications for each key category: audio, graphics,
video,
photography and publishing.
The Beta images can be downloaded at:
https://cdimage.ubuntu.com/ubuntustudio/releases/23.10/beta/
Ubuntu Unity:
Ubuntu Unity is a flavor of Ubuntu featuring the Unity7 desktop
environment.
The Beta images can be downloaded at:
https://cdimage.ubuntu.com/ubuntu-unity/releases/23.10/beta/
Xubuntu:
Xubuntu is a flavor of Ubuntu that comes with Xfce, which is a
stable, light
and a configurable desktop environment.
The Beta images can be downloaded at:
https://cdimage.ubuntu.com/xubuntu/releases/23.10/beta/
Regular daily images for Ubuntu, and all flavours, can be found at:
https://cdimage.ubuntu.com
Ubuntu is a full-featured Linux distribution for clients, servers and
clouds,
with a fast and easy installation and regular releases. A tightly-integrated
selection of excellent applications is included, and an incredible
variety of
add-on software is just a few clicks away.
Professional technical support is available from Canonical Limited and
hundreds
of other companies around the world. For more information about support,
visit
https://ubuntu.com/support
If you would like to help shape Ubuntu, take a look at the list of ways
you can
participate at:
https://ubuntu.com/community/participate
Your comments, bug reports, patches and suggestions really help us to
improve
this and future releases of Ubuntu. Instructions can be found at:
https://help.ubuntu.com/community/ReportingBugs
You can find out more about Ubuntu and about this Beta release on our
website, IRC channel and wiki.
To sign up for future Ubuntu announcements, please subscribe to Ubuntu's
very low volume announcement list at:
https://lists.ubuntu.com/mailman/listinfo/ubuntu-announce
On behalf of the Ubuntu Release Team,
Utkarsh Gupta
--
ubuntu-announce mailing list
ubuntu-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-announce
Thursday, September 21, 2023
[USN-6360-2] FLAC vulnerability
Ubuntu Security Notice USN-6360-2
September 22, 2023
flac vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 18.04 LTS (Available with Ubuntu Pro)
- Ubuntu 16.04 LTS (Available with Ubuntu Pro)
- Ubuntu 14.04 LTS (Available with Ubuntu Pro)
Summary:
FLAC could be made to crash or run programs as your login if it opened a
specially crafted file.
Software Description:
- flac: Free Lossless Audio Codec
Details:
USN-6360-1 fixed a vulnerability in FLAC. This update provides the
corresponding update for Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and
Ubuntu 18.04 LTS.
Original advisory details:
It was discovered that FLAC incorrectly handled encoding certain files. A
remote attacker could use this issue to cause FLAC to crash, resulting
in a
denial of service, or possibly execute arbitrary code.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 18.04 LTS (Available with Ubuntu Pro):
flac 1.3.2-1ubuntu0.1+esm1
libflac8 1.3.2-1ubuntu0.1+esm1
Ubuntu 16.04 LTS (Available with Ubuntu Pro):
flac 1.3.1-4ubuntu0.1~esm2
libflac8 1.3.1-4ubuntu0.1~esm2
Ubuntu 14.04 LTS (Available with Ubuntu Pro):
flac 1.3.0-2ubuntu0.14.04.1+esm2
libflac8 1.3.0-2ubuntu0.14.04.1+esm2
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-6360-2
https://ubuntu.com/security/notices/USN-6360-1
CVE-2020-22219
[USN-6395-1] GNOME Shell vulnerability
Ubuntu Security Notice USN-6395-1
September 21, 2023
gnome-shell vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 23.04
Summary:
GNOME Shell could be made to expose sensitive information.
Software Description:
- gnome-shell: graphical shell for the GNOME desktop
Details:
Mickael Karatekin discovered that GNOME Shell incorrectly allowed the
screenshot tool to view open windows when a session was locked. A local
attacker could possibly use this issue to obtain sensitive information.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 23.04:
gnome-shell 44.3-0ubuntu1.1
After a standard system update you need to reboot your computer to make all
the necessary changes.
References:
https://ubuntu.com/security/notices/USN-6395-1
CVE-2023-43090
Package Information:
https://launchpad.net/ubuntu/+source/gnome-shell/44.3-0ubuntu1.1
[USN-6394-1] Python vulnerability
Ubuntu Security Notice USN-6394-1
September 21, 2023
python3.5 vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 16.04 LTS (Available with Ubuntu Pro)
Summary:
Python could be made to execute arbitrary code if it received
a specially crafted script.
Software Description:
- python3.5: An interactive high-level object-oriented language
Details:
It was discovered that Python incorrectly handled certain scripts.
An attacker could possibly use this issue to execute arbitrary code
or cause a crash.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 16.04 LTS (Available with Ubuntu Pro):
python3.5 3.5.2-2ubuntu0~16.04.13+esm10
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-6394-1
CVE-2022-48560
[USN-6393-1] ImageMagick vulnerability
wsD5BAABCAAjFiEEcxdv4gCCE8W9nrt5a1+PL+d1/EgFAmUMX4oFAwAAAAAACgkQa1+PL+d1/Ejj
RQv/eiorQgyUQZefZmEp+jtOSy0CvvzBEVg9iqdwEP/gpYr1UE9PhBAoF0gr9/brP0WJdwF3d4ei
LtgjpHtNETJgh4WQsKJJDjtr7VKWhnvtxQSnxqX/hpj74gFk2YWAaDTL/dXZAKBDvTSBa85Ame7j
dxrIuscNe6VkNVtsHBPb1r8f4+dsY1vJ5uwuLmdSe5A00jdi8L2JR4Lz4gQ0c29hZkAp2AOgtG3x
RYEN6CXvGMutYO4/jE9b7E7EeS9OnNnHM8x4iPD7MXqo7XpoUvcn8sjfBAnTVFXNZvCp8QsSouKT
zaSUsfs/AT2r/xijk2C66P1lTKx5PCA6SyHPHhAIWEAG5IniCJbJtRHW4xn4qH3v3tcddjIbZqc5
Qi6rMlP2h3eeeDNVTRNrqYO5pHj14a5bg2Ue2ODGVKf1eQGfDX0Bm1NNPprDhjlYfkkXqxGw1CMx
moCLscIU0MAxUJ/4YT5WNBSe9mFv/xsSKobTsiSUDZ36GVkB4DMLeUiJlW/l
=5yJK
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-6393-1
September 21, 2023
imagemagick vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 20.04 LTS (Available with Ubuntu Pro)
- Ubuntu 18.04 LTS (Available with Ubuntu Pro)
- Ubuntu 16.04 LTS (Available with Ubuntu Pro)
- Ubuntu 14.04 LTS (Available with Ubuntu Pro)
Summary:
ImageMagick could be made to crash when processing the -help option.
Software Description:
- imagemagick: Image manipulation programs and library
Details:
It was discovered that ImageMagick did not properly handle memory when
processing the -help option. An attacker could potentially use this
issue to cause a crash.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 20.04 LTS (Available with Ubuntu Pro):
imagemagick 8:6.9.10.23+dfsg-2.1ubuntu11.9+esm1
imagemagick-6.q16 8:6.9.10.23+dfsg-2.1ubuntu11.9+esm1
imagemagick-6.q16hdri 8:6.9.10.23+dfsg-2.1ubuntu11.9+esm1
Ubuntu 18.04 LTS (Available with Ubuntu Pro):
imagemagick 8:6.9.7.4+dfsg-16ubuntu6.15+esm2
imagemagick-6.q16 8:6.9.7.4+dfsg-16ubuntu6.15+esm2
imagemagick-6.q16hdri 8:6.9.7.4+dfsg-16ubuntu6.15+esm2
Ubuntu 16.04 LTS (Available with Ubuntu Pro):
imagemagick 8:6.8.9.9-7ubuntu5.16+esm9
imagemagick-6.q16 8:6.8.9.9-7ubuntu5.16+esm9
Ubuntu 14.04 LTS (Available with Ubuntu Pro):
imagemagick 8:6.7.7.10-6ubuntu3.13+esm6
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-6393-1
CVE-2022-48541
[USN-6391-2] CUPS vulnerability
Ubuntu Security Notice USN-6391-2
September 21, 2023
cups vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 18.04 LTS (Available with Ubuntu Pro)
- Ubuntu 16.04 LTS (Available with Ubuntu Pro)
Summary:
CUPS could be made to crash or run programs if it opened a specially
crafted file.
Software Description:
- cups: Common UNIX Printing System(tm)
Details:
USN-6391-1 fixed a vulnerability in CUPS. This update provides
the corresponding update for Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
Original advisory details:
It was discovered that CUPS incorrectly parsed certain Postscript objects.
If a user or automated system were tricked into printing a specially
crafted document, a remote attacker could use this issue to cause CUPS to
crash, resulting in a denial of service, or possibly execute arbitrary
code.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 18.04 LTS (Available with Ubuntu Pro):
cups 2.2.7-1ubuntu2.10+esm2
Ubuntu 16.04 LTS (Available with Ubuntu Pro):
cups 2.1.3-4ubuntu0.11+esm4
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-6391-2
https://ubuntu.com/security/notices/USN-6391-1
CVE-2023-4504
Wednesday, September 20, 2023
OpenBSD Errata: September 21, 2023 (npppd)
Binary updates for the amd64, arm64 and i386 platform are available
via the syspatch utility. Source code patches can be found on the
respective errata page:
https://www.openbsd.org/errata72.html
https://www.openbsd.org/errata73.html
[USN-6392-1] libppd vulnerability
Ubuntu Security Notice USN-6392-1
September 20, 2023
libppd vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 23.04
Summary:
libppd could be made to crash or run programs if it opened a specially
crafted file.
Software Description:
- libppd: OpenPrinting libppd
Details:
It was discovered that libppd incorrectly parsed certain Postscript
objects. If a user or automated system were tricked into printing a
specially crafted document, a remote attacker could use this issue to cause
libppd to crash, resulting in a denial of service, or possibly execute
arbitrary code.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 23.04:
libppd2 2:2.0~rc1-0ubuntu1.2
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-6392-1
CVE-2023-4504
Package Information:
https://launchpad.net/ubuntu/+source/libppd/2:2.0~rc1-0ubuntu1.2
[USN-6390-1] Bind vulnerabilities
Ubuntu Security Notice USN-6390-1
September 20, 2023
bind9 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 23.04
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
Summary:
Bind could be made to crash if it received specially crafted network
traffic.
Software Description:
- bind9: Internet Domain Name Server
Details:
It was discovered that Bind incorrectly handled certain control channel
messages. A remote attacker with access to the control channel could
possibly use this issue to cause Bind to crash, resulting in a denial of
service. (CVE-2023-3341)
Robert Story discovered that Bind incorrectly handled certain DNS-over-TLS
queries. A remote attacker could possibly use this issue to cause Bind to
crash, resulting in a denial of service. This issue only affected Ubuntu
22.04 LTS, and Ubuntu 23.04. (CVE-2023-4236)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 23.04:
bind9 1:9.18.12-1ubuntu1.2
Ubuntu 22.04 LTS:
bind9 1:9.18.12-0ubuntu0.22.04.3
Ubuntu 20.04 LTS:
bind9 1:9.16.1-0ubuntu2.16
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-6390-1
CVE-2023-3341, CVE-2023-4236
Package Information:
https://launchpad.net/ubuntu/+source/bind9/1:9.18.12-1ubuntu1.2
https://launchpad.net/ubuntu/+source/bind9/1:9.18.12-0ubuntu0.22.04.3
https://launchpad.net/ubuntu/+source/bind9/1:9.16.1-0ubuntu2.16
[USN-6391-1] CUPS vulnerability
Ubuntu Security Notice USN-6391-1
September 20, 2023
cups vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 23.04
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
Summary:
CUPS could be made to crash or run programs if it opened a specially
crafted file.
Software Description:
- cups: Common UNIX Printing System(tm)
Details:
It was discovered that CUPS incorrectly parsed certain Postscript objects.
If a user or automated system were tricked into printing a specially
crafted document, a remote attacker could use this issue to cause CUPS to
crash, resulting in a denial of service, or possibly execute arbitrary
code.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 23.04:
cups 2.4.2-3ubuntu2.5
Ubuntu 22.04 LTS:
cups 2.4.1op1-1ubuntu4.7
Ubuntu 20.04 LTS:
cups 2.3.1-9ubuntu1.6
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-6391-1
CVE-2023-4504
Package Information:
https://launchpad.net/ubuntu/+source/cups/2.4.2-3ubuntu2.5
https://launchpad.net/ubuntu/+source/cups/2.4.1op1-1ubuntu4.7
https://launchpad.net/ubuntu/+source/cups/2.3.1-9ubuntu1.6
[USN-6389-1] Indent vulnerability
Ubuntu Security Notice USN-6389-1
September 20, 2023
indent vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 23.04
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
Summary:
Indent could be made to crash or run programs if it opened a specially
crafted file.
Software Description:
- indent: C language source code formatting program
Details:
It was discovered that Indent incorrectly handled parsing certain source
files. If a user or automated system were tricked into processing a
specially crafted source file, a remote attacker could use this issue to
cause Indent to crash, resulting in a denial of service, or possibly
execute arbitrary code.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 23.04:
indent 2.2.12-4ubuntu0.1
Ubuntu 22.04 LTS:
indent 2.2.12-1ubuntu0.22.04.1
Ubuntu 20.04 LTS:
indent 2.2.12-1ubuntu0.20.04.1
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-6389-1
CVE-2023-40305
Package Information:
https://launchpad.net/ubuntu/+source/indent/2.2.12-4ubuntu0.1
https://launchpad.net/ubuntu/+source/indent/2.2.12-1ubuntu0.22.04.1
https://launchpad.net/ubuntu/+source/indent/2.2.12-1ubuntu0.20.04.1