Friday, September 22, 2023

[arch-announce] Changes to default password hashing algorithm and umask settings

With *shadow* >= `4.14.0`, Arch Linux's default password hashing algorithm changed from **SHA512** to **yescrypt** [1].

Furthermore, the `umask` [2] settings are now configured in `/etc/login.defs` instead of `/etc/profile`.

This should not require any manual intervention.

## Reasons for Yescrypt
The password-based key derivation function (KDF) and password hashing scheme **yescrypt** has been chosen due to its adoption (readily available in *libxcrypt*, which is used by *pam* [3]) and its stronger resilience towards password cracking attempts over **SHA512**.

Although the winner of the Password Hashing Competition [4] has been **argon2**, this even more resilient algorithm is not yet available in *libxcrypt* [5][6].

## Configuring yescrypt
The `YESCRYPT_COST_FACTOR` setting in `/etc/login.defs` is currently without effect, until *pam* implements reading its value [7]. If a `YESCRYPT_COST_FACTOR` higher (or lower) than the default (`5`) is needed, it can be set using the `rounds` option of the `pam_unix` [8] module (i.e. in `/etc/pam.d/system-auth`).

## General list of changes
- **yescrypt** is used as default password hashing algorithm, instead of **SHA512**
- *pam* honors the chosen `ENCRYPT_METHOD` in `/etc/login.defs` and does not override the chosen method anymore
- changes in the *filesystem* (>= `2023.09.18`) and *pambase* (>= `20230918`) packages ensure, that `umask` is set centrally in `/etc/login.defs` instead of `/etc/profile`

[1] https://www.openwall.com/yescrypt/

[2] https://man.archlinux.org/man/umask.1p

[3] https://wiki.archlinux.org/title/PAM

[4] https://www.password-hashing.net/

[5] https://github.com/besser82/libxcrypt/pull/113

[6] https://github.com/besser82/libxcrypt/pull/150

[7] https://github.com/linux-pam/linux-pam/issues/607

[8] https://man.archlinux.org/man/pam_unix.8

URL: https://archlinux.org/news/changes-to-default-password-hashing-algorithm-and-umask-settings/

Ubuntu 23.10 (Mantic Minotaur) Beta released

The Ubuntu team is pleased to announce the Beta release of the Ubuntu 23.10
Desktop, Server, and Cloud products.

Ubuntu 23.10, codenamed "Mantic Minotaur", continues Ubuntu's proud
tradition of
integrating the latest and greatest open source technologies into a
high-quality, easy-to-use Linux distribution. The team has been hard at work
through this cycle, introducing new features and fixing bugs.

This Beta release includes images from not only the Ubuntu Desktop,
Server, and
Cloud products, but also the Edubuntu, Kubuntu, Lubuntu, Ubuntu Budgie,
Ubuntu Cinnamon, Ubuntu Kylin, Ubuntu MATE, Ubuntu Studio, Ubuntu Unity, and
Xubuntu flavours.

The Beta images are known to be reasonably free of showstopper image
build or
installer bugs, while representing a very recent snapshot of 23.10 that
should
be representative of the features intended to ship with the final release
expected on October 12, 2023.

Ubuntu, Ubuntu Server, Cloud Images:
  Mantic Beta includes updated versions of most of our core set of
  packages, including a current 6.5 kernel, and much more.

  To upgrade to Ubuntu 23.10 Beta from Ubuntu 23.04, follow these
  instructions:

  https://help.ubuntu.com/community/ManticUpgrades

  The Ubuntu 23.10 Beta images can be downloaded at:

  https://releases.ubuntu.com/23.10/ (Ubuntu and Ubuntu Server on x86)

  The default Ubuntu Desktop installer is now a Flutter snap backed by
Subiquity.
  The legacy installer is still available in case of issues with the
new installer.

  This Ubuntu Server image features the next generation Subiquity server
  installer, bringing the comfortable live session and speedy install of
  the Ubuntu Desktop to server users.

  Additional images can be found at the following links:

  https://cloud-images.ubuntu.com/daily/server/mantic/current/ (Cloud
Images)
  https://cdimage.ubuntu.com/releases/23.10/beta/ (Non-x86)

  As fixes will be included in new images between now and release, any
  daily cloud image should be considered a Beta image. Bugs found should be
  filed against the appropriate packages or, failing that, the cloud-images
  project in Launchpad.

  The full release notes for Ubuntu 23.10 Beta can be found at:

  https://discourse.ubuntu.com/t/mantic-minotaur-release-notes

Edubuntu:
  Edubuntu is a flavor of Ubuntu designed as a free education oriented
  operating system for children of all ages.

  The Beta images can be downloaded at:
  http://cdimage.ubuntu.com/edubuntu/releases/23.10/beta/

Kubuntu:
  Kubuntu is the KDE based flavor of Ubuntu. It uses the Plasma desktop and
  includes a wide selection of tools from the KDE project.

  The Beta images can be downloaded at:
  https://cdimage.ubuntu.com/kubuntu/releases/23.10/beta/

Lubuntu:
  Lubuntu is a flavor of Ubuntu which uses the Lightweight Qt Desktop
  Environment (LXQt). The project's goal is to provide a lightweight yet
  functional Linux distribution based on a rock-solid Ubuntu base.

  The Beta images can be downloaded at:
  https://cdimage.ubuntu.com/lubuntu/releases/23.10/beta/

Ubuntu Budgie:
  Ubuntu Budgie is a community developed desktop, integrating Budgie
Desktop
  Environment with Ubuntu at its core.

  The Beta images can be downloaded at:
  https://cdimage.ubuntu.com/ubuntu-budgie/releases/23.10/beta/

Ubuntu Cinnamon
  Ubuntu Cinnamon is a flavor of Ubuntu featuring the Cinnamon desktop
  environment.

  The Beta images can be downloaded at:
  http://cdimage.ubuntu.com/ubuntucinnamon/releases/23.10/beta/

Ubuntu Kylin:
  Ubuntu Kylin is a flavor of Ubuntu that is more suitable for Chinese
users.

  The Beta images can be downloaded at:
  http://cdimage.ubuntu.com/ubuntukylin/releases/23.10/beta/

Ubuntu MATE:
  Ubuntu MATE is a flavor of Ubuntu featuring the MATE desktop environment.

  The Beta images can be downloaded at:
  https://cdimage.ubuntu.com/ubuntu-mate/releases/23.10/beta/

Ubuntu Studio:
  Ubuntu Studio is a flavor of Ubuntu that provides a full range of
multimedia
  content creation applications for each key category: audio, graphics,
video,
  photography and publishing.

  The Beta images can be downloaded at:
  https://cdimage.ubuntu.com/ubuntustudio/releases/23.10/beta/

Ubuntu Unity:
  Ubuntu Unity is a flavor of Ubuntu featuring the Unity7 desktop
environment.

  The Beta images can be downloaded at:
  https://cdimage.ubuntu.com/ubuntu-unity/releases/23.10/beta/

Xubuntu:
  Xubuntu is a flavor of Ubuntu that comes with Xfce, which is a
stable, light
  and a configurable desktop environment.

  The Beta images can be downloaded at:
  https://cdimage.ubuntu.com/xubuntu/releases/23.10/beta/

Regular daily images for Ubuntu, and all flavours, can be found at:
  https://cdimage.ubuntu.com

Ubuntu is a full-featured Linux distribution for clients, servers and
clouds,
with a fast and easy installation and regular releases. A tightly-integrated
selection of excellent applications is included, and an incredible
variety of
add-on software is just a few clicks away.

Professional technical support is available from Canonical Limited and
hundreds
of other companies around the world. For more information about support,
visit
https://ubuntu.com/support

If you would like to help shape Ubuntu, take a look at the list of ways
you can
participate at:
https://ubuntu.com/community/participate

Your comments, bug reports, patches and suggestions really help us to
improve
this and future releases of Ubuntu. Instructions can be found at:
https://help.ubuntu.com/community/ReportingBugs

You can find out more about Ubuntu and about this Beta release on our
website, IRC channel and wiki.

To sign up for future Ubuntu announcements, please subscribe to Ubuntu's
very low volume announcement list at:

  https://lists.ubuntu.com/mailman/listinfo/ubuntu-announce


On behalf of the Ubuntu Release Team,
Utkarsh Gupta


--
ubuntu-announce mailing list
ubuntu-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-announce

Thursday, September 21, 2023

[USN-6360-2] FLAC vulnerability

==========================================================================
Ubuntu Security Notice USN-6360-2
September 22, 2023

flac vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 18.04 LTS (Available with Ubuntu Pro)
- Ubuntu 16.04 LTS (Available with Ubuntu Pro)
- Ubuntu 14.04 LTS (Available with Ubuntu Pro)

Summary:

FLAC could be made to crash or run programs as your login if it opened a
specially crafted file.

Software Description:
- flac: Free Lossless Audio Codec

Details:

USN-6360-1 fixed a vulnerability in FLAC. This update provides the
corresponding update for Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and
Ubuntu 18.04 LTS.

Original advisory details:

 It was discovered that FLAC incorrectly handled encoding certain files. A
 remote attacker could use this issue to cause FLAC to crash, resulting
in a
 denial of service, or possibly execute arbitrary code.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.04 LTS (Available with Ubuntu Pro):
  flac                            1.3.2-1ubuntu0.1+esm1
  libflac8                        1.3.2-1ubuntu0.1+esm1

Ubuntu 16.04 LTS (Available with Ubuntu Pro):
  flac                            1.3.1-4ubuntu0.1~esm2
  libflac8                        1.3.1-4ubuntu0.1~esm2

Ubuntu 14.04 LTS (Available with Ubuntu Pro):
  flac                            1.3.0-2ubuntu0.14.04.1+esm2
  libflac8                        1.3.0-2ubuntu0.14.04.1+esm2

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-6360-2
  https://ubuntu.com/security/notices/USN-6360-1
  CVE-2020-22219

[USN-6395-1] GNOME Shell vulnerability

==========================================================================
Ubuntu Security Notice USN-6395-1
September 21, 2023

gnome-shell vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 23.04

Summary:

GNOME Shell could be made to expose sensitive information.

Software Description:
- gnome-shell: graphical shell for the GNOME desktop

Details:

Mickael Karatekin discovered that GNOME Shell incorrectly allowed the
screenshot tool to view open windows when a session was locked. A local
attacker could possibly use this issue to obtain sensitive information.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 23.04:
gnome-shell 44.3-0ubuntu1.1

After a standard system update you need to reboot your computer to make all
the necessary changes.

References:
https://ubuntu.com/security/notices/USN-6395-1
CVE-2023-43090

Package Information:
https://launchpad.net/ubuntu/+source/gnome-shell/44.3-0ubuntu1.1

[USN-6394-1] Python vulnerability

==========================================================================
Ubuntu Security Notice USN-6394-1
September 21, 2023

python3.5 vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.04 LTS (Available with Ubuntu Pro)

Summary:

Python could be made to execute arbitrary code if it received
a specially crafted script.

Software Description:
- python3.5: An interactive high-level object-oriented language

Details:

It was discovered that Python incorrectly handled certain scripts.
An attacker could possibly use this issue to execute arbitrary code
or cause a crash.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 LTS (Available with Ubuntu Pro):
python3.5 3.5.2-2ubuntu0~16.04.13+esm10

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-6394-1
CVE-2022-48560

[USN-6393-1] ImageMagick vulnerability

-----BEGIN PGP SIGNATURE-----

wsD5BAABCAAjFiEEcxdv4gCCE8W9nrt5a1+PL+d1/EgFAmUMX4oFAwAAAAAACgkQa1+PL+d1/Ejj
RQv/eiorQgyUQZefZmEp+jtOSy0CvvzBEVg9iqdwEP/gpYr1UE9PhBAoF0gr9/brP0WJdwF3d4ei
LtgjpHtNETJgh4WQsKJJDjtr7VKWhnvtxQSnxqX/hpj74gFk2YWAaDTL/dXZAKBDvTSBa85Ame7j
dxrIuscNe6VkNVtsHBPb1r8f4+dsY1vJ5uwuLmdSe5A00jdi8L2JR4Lz4gQ0c29hZkAp2AOgtG3x
RYEN6CXvGMutYO4/jE9b7E7EeS9OnNnHM8x4iPD7MXqo7XpoUvcn8sjfBAnTVFXNZvCp8QsSouKT
zaSUsfs/AT2r/xijk2C66P1lTKx5PCA6SyHPHhAIWEAG5IniCJbJtRHW4xn4qH3v3tcddjIbZqc5
Qi6rMlP2h3eeeDNVTRNrqYO5pHj14a5bg2Ue2ODGVKf1eQGfDX0Bm1NNPprDhjlYfkkXqxGw1CMx
moCLscIU0MAxUJ/4YT5WNBSe9mFv/xsSKobTsiSUDZ36GVkB4DMLeUiJlW/l
=5yJK
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-6393-1
September 21, 2023

imagemagick vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 20.04 LTS (Available with Ubuntu Pro)
- Ubuntu 18.04 LTS (Available with Ubuntu Pro)
- Ubuntu 16.04 LTS (Available with Ubuntu Pro)
- Ubuntu 14.04 LTS (Available with Ubuntu Pro)

Summary:

ImageMagick could be made to crash when processing the -help option.

Software Description:
- imagemagick: Image manipulation programs and library

Details:

It was discovered that ImageMagick did not properly handle memory when
processing the -help option. An attacker could potentially use this
issue to cause a crash.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.04 LTS (Available with Ubuntu Pro):
  imagemagick 8:6.9.10.23+dfsg-2.1ubuntu11.9+esm1
  imagemagick-6.q16 8:6.9.10.23+dfsg-2.1ubuntu11.9+esm1
  imagemagick-6.q16hdri 8:6.9.10.23+dfsg-2.1ubuntu11.9+esm1

Ubuntu 18.04 LTS (Available with Ubuntu Pro):
  imagemagick 8:6.9.7.4+dfsg-16ubuntu6.15+esm2
  imagemagick-6.q16 8:6.9.7.4+dfsg-16ubuntu6.15+esm2
  imagemagick-6.q16hdri           8:6.9.7.4+dfsg-16ubuntu6.15+esm2

Ubuntu 16.04 LTS (Available with Ubuntu Pro):
  imagemagick                        8:6.8.9.9-7ubuntu5.16+esm9
  imagemagick-6.q16               8:6.8.9.9-7ubuntu5.16+esm9

Ubuntu 14.04 LTS (Available with Ubuntu Pro):
  imagemagick                        8:6.7.7.10-6ubuntu3.13+esm6

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-6393-1
  CVE-2022-48541

[USN-6391-2] CUPS vulnerability

==========================================================================
Ubuntu Security Notice USN-6391-2
September 21, 2023

cups vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 18.04 LTS (Available with Ubuntu Pro)
- Ubuntu 16.04 LTS (Available with Ubuntu Pro)

Summary:

CUPS could be made to crash or run programs if it opened a specially
crafted file.

Software Description:
- cups: Common UNIX Printing System(tm)

Details:

USN-6391-1 fixed a vulnerability in CUPS. This update provides
the corresponding update for Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.

Original advisory details:

It was discovered that CUPS incorrectly parsed certain Postscript objects.
If a user or automated system were tricked into printing a specially
crafted document, a remote attacker could use this issue to cause CUPS to
crash, resulting in a denial of service, or possibly execute arbitrary
code.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.04 LTS (Available with Ubuntu Pro):
cups 2.2.7-1ubuntu2.10+esm2

Ubuntu 16.04 LTS (Available with Ubuntu Pro):
cups 2.1.3-4ubuntu0.11+esm4

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-6391-2
https://ubuntu.com/security/notices/USN-6391-1
CVE-2023-4504

Wednesday, September 20, 2023

OpenBSD Errata: September 21, 2023 (npppd)

Errata patches for npppd have been released for OpenBSD 7.2 and 7.3.

Binary updates for the amd64, arm64 and i386 platform are available
via the syspatch utility. Source code patches can be found on the
respective errata page:

https://www.openbsd.org/errata72.html
https://www.openbsd.org/errata73.html

[USN-6392-1] libppd vulnerability

==========================================================================
Ubuntu Security Notice USN-6392-1
September 20, 2023

libppd vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 23.04

Summary:

libppd could be made to crash or run programs if it opened a specially
crafted file.

Software Description:
- libppd: OpenPrinting libppd

Details:

It was discovered that libppd incorrectly parsed certain Postscript
objects. If a user or automated system were tricked into printing a
specially crafted document, a remote attacker could use this issue to cause
libppd to crash, resulting in a denial of service, or possibly execute
arbitrary code.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 23.04:
libppd2 2:2.0~rc1-0ubuntu1.2

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-6392-1
CVE-2023-4504

Package Information:
https://launchpad.net/ubuntu/+source/libppd/2:2.0~rc1-0ubuntu1.2

[USN-6390-1] Bind vulnerabilities

==========================================================================
Ubuntu Security Notice USN-6390-1
September 20, 2023

bind9 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 23.04
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS

Summary:

Bind could be made to crash if it received specially crafted network
traffic.

Software Description:
- bind9: Internet Domain Name Server

Details:

It was discovered that Bind incorrectly handled certain control channel
messages. A remote attacker with access to the control channel could
possibly use this issue to cause Bind to crash, resulting in a denial of
service. (CVE-2023-3341)

Robert Story discovered that Bind incorrectly handled certain DNS-over-TLS
queries. A remote attacker could possibly use this issue to cause Bind to
crash, resulting in a denial of service. This issue only affected Ubuntu
22.04 LTS, and Ubuntu 23.04. (CVE-2023-4236)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 23.04:
bind9 1:9.18.12-1ubuntu1.2

Ubuntu 22.04 LTS:
bind9 1:9.18.12-0ubuntu0.22.04.3

Ubuntu 20.04 LTS:
bind9 1:9.16.1-0ubuntu2.16

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-6390-1
CVE-2023-3341, CVE-2023-4236

Package Information:
https://launchpad.net/ubuntu/+source/bind9/1:9.18.12-1ubuntu1.2
https://launchpad.net/ubuntu/+source/bind9/1:9.18.12-0ubuntu0.22.04.3
https://launchpad.net/ubuntu/+source/bind9/1:9.16.1-0ubuntu2.16

[USN-6391-1] CUPS vulnerability

==========================================================================
Ubuntu Security Notice USN-6391-1
September 20, 2023

cups vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 23.04
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS

Summary:

CUPS could be made to crash or run programs if it opened a specially
crafted file.

Software Description:
- cups: Common UNIX Printing System(tm)

Details:

It was discovered that CUPS incorrectly parsed certain Postscript objects.
If a user or automated system were tricked into printing a specially
crafted document, a remote attacker could use this issue to cause CUPS to
crash, resulting in a denial of service, or possibly execute arbitrary
code.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 23.04:
cups 2.4.2-3ubuntu2.5

Ubuntu 22.04 LTS:
cups 2.4.1op1-1ubuntu4.7

Ubuntu 20.04 LTS:
cups 2.3.1-9ubuntu1.6

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-6391-1
CVE-2023-4504

Package Information:
https://launchpad.net/ubuntu/+source/cups/2.4.2-3ubuntu2.5
https://launchpad.net/ubuntu/+source/cups/2.4.1op1-1ubuntu4.7
https://launchpad.net/ubuntu/+source/cups/2.3.1-9ubuntu1.6

[USN-6389-1] Indent vulnerability

==========================================================================
Ubuntu Security Notice USN-6389-1
September 20, 2023

indent vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 23.04
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS

Summary:

Indent could be made to crash or run programs if it opened a specially
crafted file.

Software Description:
- indent: C language source code formatting program

Details:

It was discovered that Indent incorrectly handled parsing certain source
files. If a user or automated system were tricked into processing a
specially crafted source file, a remote attacker could use this issue to
cause Indent to crash, resulting in a denial of service, or possibly
execute arbitrary code.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 23.04:
indent 2.2.12-4ubuntu0.1

Ubuntu 22.04 LTS:
indent 2.2.12-1ubuntu0.22.04.1

Ubuntu 20.04 LTS:
indent 2.2.12-1ubuntu0.20.04.1

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-6389-1
CVE-2023-40305

Package Information:
https://launchpad.net/ubuntu/+source/indent/2.2.12-4ubuntu0.1
https://launchpad.net/ubuntu/+source/indent/2.2.12-1ubuntu0.22.04.1
https://launchpad.net/ubuntu/+source/indent/2.2.12-1ubuntu0.20.04.1