The State of Email, Michael W. Lucas
* note that we are NOT meeting on July 3 but July 10
* MWL will be remote, but many will be onsite to watch him over video
2024-07-10 @ 18:45 EDT (22:45 UTC) - NYU Tandon Engineering Building
(new), 370 Jay St, 7th Floor kitchen area, Brooklyn (directly across Jay
St from National Grid office). Closest subway exits in order are Jay St
- MetroTech Station (A, C, R, & F Trains) Borough Hall (4 & 5 Trains).
Notice: You should RSVP for this meeting at rsvp AT lists.nycbug.org by
July 9th. You should receive an autoresponse email. Your email address
is sufficient verification for entry.
"It's impossible to run your own email!" Not quite. But you must do it
carefully and correctly. This talk discusses the current state of email,
with a focus on the small independent server operator. What do you need
to run your own mail? How can you use protocols like DKIM and DMARC
without wrecking your ability to communicate with the outside world?
Based on Lucas' book "Run Your Own Mail Server." The first chapter is
online at https://mwl.io/archives/22653
Michael W. Lucas' name may ring a bell for some in the BSD community.
He's writt en several shelves of books. But for anyone who has seen him
speak in public dur ing Ante COVID days, it was clear they are mere
transcriptions of his rambling p resentations. For this NYC*BUG meeting,
he is unlikely to edit out any of his ex pected corny jokes we endure
during his conference presentations.
More likely, you know his name from his grotesque horror fiction. In the
same wa y his technical books are just transcriptions of his
presentations, his fictiona al horror is just a simple reflection of
someone who lives in a haunted house fi lled with (pet) rats in Detroit.
Offsite Participation: We plan to stream MWL Zoom call via NYC*BUG
Website. Q&A will be via IRC on Libera.chat channel #nycbug - Please
preface your questions with '[Q]'
_______________________________________________
announce mailing list
announce@lists.nycbug.org
https://lists.nycbug.org:8443/mailman/listinfo/announce
Friday, June 28, 2024
Thursday, June 27, 2024
[USN-5615-3] SQLite vulnerability
-----BEGIN PGP SIGNATURE-----
wsF5BAABCAAjFiEER/Iq56J1QpFyK/CQ9uFA9ts1nlgFAmZ9nUcFAwAAAAAACgkQ9uFA9ts1nljL
SA/9Fq9BZbVWQ9zOIOREfFRwRoz0XeyrxUf4Djm351+LL+2fzRSCKPCq3gIP9spRitdvltghgNhF
7yudv6WzX16yAIJIkj8AMMQEoTTDLoY59rVB+UKJRiPe7YmSLMbw7vfDu0ajdMr4uN64TVFoVjjj
YTVlbUuQNVQIgNNgAWwvp116vwGP9Ql07ckeoEtuamSOlAO/9xFogyJ+0IiBJv2YFERvVLI1bYEJ
g6N0KLYs7iz4R5BoOKRCMIrkcm/419UL6yb4XwiigAHoVGRriT0vSIMrDZ1X+Vwb+BS+gdAWnh11
ff+zdFQQnOpSptuhYdE4+kaLT/tBhTtmRWqIMUTSk9e4pNycMp+HDPpUTPX6NU/wH3YtaOymX8sV
UlemSz3K9N2JoaO4XZDQWh7b8Wqn7WS7Msdmq9JK3Jm0HCgNojA9908r5l1WBP2yDQzdEA9fZDLX
o2LE56oGWMmsjIsClhJsNDOE21+JYN92b++/wvr40J0kma/RAHs/Qbkkw1K3TuHlil9MQzCMhuSp
acAYEkv67Q8YXwsXjIYDUXacfs59NhBGOndQA/jTnjEAk/7AdlwvfeYTpogbBZQUtc7/FRWhD5Cl
q0c/madrsHZYvE69smdh/GAU+1n0Et2nb8KQT91LWhL0RDu024Eu73ML36AndnItc7ibSXWo1dNr
5Ts=
=ogwg
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-5615-3
June 27, 2024
sqlite3 vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 14.04 LTS
Summary:
SQLite could be made to crash or execute arbitrary code.
Software Description:
- sqlite3: C library that implements an SQL database engine
Details:
USN-5615-1 fixed several vulnerabilities in SQLite. This update provides
the corresponding fix for CVE-2020-35525 for Ubuntu 14.04 LTS.
Original advisory details:
It was discovered that SQLite incorrectly handled INTERSEC query
processing. An attacker could use this issue to cause SQLite to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2020-35525)
It was discovered that SQLite incorrectly handled ALTER TABLE for views
that have a nested FROM clause. An attacker could use this issue to cause
SQLite to crash, resulting in a denial of service, or possibly execute
arbitrary code. This issue was only addressed in Ubuntu 20.04 LTS.
(CVE-2020-35527)
It was discovered that SQLite incorrectly handled embedded null characters
when tokenizing certain unicode strings. This issue could result in
incorrect results. This issue only affected Ubuntu 20.04 LTS.
(CVE-2021-20223)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 14.04 LTS
libsqlite3-0 3.8.2-1ubuntu2.2+esm4
Available with Ubuntu Pro
sqlite3 3.8.2-1ubuntu2.2+esm4
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-5615-3
https://ubuntu.com/security/notices/USN-5615-1
CVE-2020-35525
wsF5BAABCAAjFiEER/Iq56J1QpFyK/CQ9uFA9ts1nlgFAmZ9nUcFAwAAAAAACgkQ9uFA9ts1nljL
SA/9Fq9BZbVWQ9zOIOREfFRwRoz0XeyrxUf4Djm351+LL+2fzRSCKPCq3gIP9spRitdvltghgNhF
7yudv6WzX16yAIJIkj8AMMQEoTTDLoY59rVB+UKJRiPe7YmSLMbw7vfDu0ajdMr4uN64TVFoVjjj
YTVlbUuQNVQIgNNgAWwvp116vwGP9Ql07ckeoEtuamSOlAO/9xFogyJ+0IiBJv2YFERvVLI1bYEJ
g6N0KLYs7iz4R5BoOKRCMIrkcm/419UL6yb4XwiigAHoVGRriT0vSIMrDZ1X+Vwb+BS+gdAWnh11
ff+zdFQQnOpSptuhYdE4+kaLT/tBhTtmRWqIMUTSk9e4pNycMp+HDPpUTPX6NU/wH3YtaOymX8sV
UlemSz3K9N2JoaO4XZDQWh7b8Wqn7WS7Msdmq9JK3Jm0HCgNojA9908r5l1WBP2yDQzdEA9fZDLX
o2LE56oGWMmsjIsClhJsNDOE21+JYN92b++/wvr40J0kma/RAHs/Qbkkw1K3TuHlil9MQzCMhuSp
acAYEkv67Q8YXwsXjIYDUXacfs59NhBGOndQA/jTnjEAk/7AdlwvfeYTpogbBZQUtc7/FRWhD5Cl
q0c/madrsHZYvE69smdh/GAU+1n0Et2nb8KQT91LWhL0RDu024Eu73ML36AndnItc7ibSXWo1dNr
5Ts=
=ogwg
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-5615-3
June 27, 2024
sqlite3 vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 14.04 LTS
Summary:
SQLite could be made to crash or execute arbitrary code.
Software Description:
- sqlite3: C library that implements an SQL database engine
Details:
USN-5615-1 fixed several vulnerabilities in SQLite. This update provides
the corresponding fix for CVE-2020-35525 for Ubuntu 14.04 LTS.
Original advisory details:
It was discovered that SQLite incorrectly handled INTERSEC query
processing. An attacker could use this issue to cause SQLite to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2020-35525)
It was discovered that SQLite incorrectly handled ALTER TABLE for views
that have a nested FROM clause. An attacker could use this issue to cause
SQLite to crash, resulting in a denial of service, or possibly execute
arbitrary code. This issue was only addressed in Ubuntu 20.04 LTS.
(CVE-2020-35527)
It was discovered that SQLite incorrectly handled embedded null characters
when tokenizing certain unicode strings. This issue could result in
incorrect results. This issue only affected Ubuntu 20.04 LTS.
(CVE-2021-20223)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 14.04 LTS
libsqlite3-0 3.8.2-1ubuntu2.2+esm4
Available with Ubuntu Pro
sqlite3 3.8.2-1ubuntu2.2+esm4
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-5615-3
https://ubuntu.com/security/notices/USN-5615-1
CVE-2020-35525
[USN-6857-1] Squid vulnerabilities
-----BEGIN PGP SIGNATURE-----
wsB5BAABCAAjFiEE5rkwSLC9ntq84w397Dtram9gyMMFAmZ9i1UFAwAAAAAACgkQ7Dtram9gyMOF
qAgAuW5zZbmtuB5//7JJzsQgyCGZFHq0ntYb0YXdNHs227bq31rEvr6py8Mw5fjYbH28+yRLn0P9
AmTPA0gE9kZSzvUzKk4FIdwHi94/UsGknBRJhHilTk1Hk/tyP+T3Wk9PfCdfatcqhq3f2uESS+Ew
ZGSz9RKp2Nq5xACvxCTxzRkGv+kCIubqxyH3FKOn+W3ctPMAzPw3QqOlhq5XMNlz4nTz3qWkTjvf
kku6oN4T3vwH2iooh1T2X7YWkqTJKsvnxXlFoZV6NOojV4qZ+KP24NPn8JIks+KBNHRaLED/pPfn
W6vUEAUlQ+QmtZr69pDI95qSZGhdkedfQVqGOSB+yA==
=sIoh
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-6857-1
June 27, 2024
squid3 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
Summary:
Several security issues were fixed in Squid.
Software Description:
- squid3: Web proxy cache server
Details:
Joshua Rogers discovered that Squid incorrectly handled requests with the
urn: scheme. A remote attacker could possibly use this issue to cause
Squid to consume resources, leading to a denial of service. This issue
only affected Ubuntu 16.04 LTS. (CVE-2021-28651)
It was discovered that Squid incorrectly handled SSPI and SMB
authentication. A remote attacker could use this issue to cause Squid to
crash, resulting in a denial of service, or possibly obtain sensitive
information. This issue only affected Ubuntu 16.04 LTS. (CVE-2022-41318)
Joshua Rogers discovered that Squid incorrectly handled HTTP message
processing. A remote attacker could possibly use this issue to cause
Squid to crash, resulting in a denial of service. (CVE-2023-49285)
Joshua Rogers discovered that Squid incorrectly handled Helper process
management. A remote attacker could possibly use this issue to cause
Squid to crash, resulting in a denial of service. (CVE-2023-49286)
Joshua Rogers discovered that Squid incorrectly handled HTTP request
parsing. A remote attacker could possibly use this issue to cause
Squid to crash, resulting in a denial of service.
(CVE-2023-50269, CVE-2024-25617)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 18.04 LTS
squid 3.5.27-1ubuntu1.14+esm2
Available with Ubuntu Pro
squid3 3.5.27-1ubuntu1.14+esm2
Available with Ubuntu Pro
Ubuntu 16.04 LTS
squid 3.5.12-1ubuntu7.16+esm3
Available with Ubuntu Pro
squid3 3.5.12-1ubuntu7.16+esm3
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-6857-1
CVE-2021-28651, CVE-2022-41318, CVE-2023-49285, CVE-2023-49286,
CVE-2023-50269, CVE-2024-25617
wsB5BAABCAAjFiEE5rkwSLC9ntq84w397Dtram9gyMMFAmZ9i1UFAwAAAAAACgkQ7Dtram9gyMOF
qAgAuW5zZbmtuB5//7JJzsQgyCGZFHq0ntYb0YXdNHs227bq31rEvr6py8Mw5fjYbH28+yRLn0P9
AmTPA0gE9kZSzvUzKk4FIdwHi94/UsGknBRJhHilTk1Hk/tyP+T3Wk9PfCdfatcqhq3f2uESS+Ew
ZGSz9RKp2Nq5xACvxCTxzRkGv+kCIubqxyH3FKOn+W3ctPMAzPw3QqOlhq5XMNlz4nTz3qWkTjvf
kku6oN4T3vwH2iooh1T2X7YWkqTJKsvnxXlFoZV6NOojV4qZ+KP24NPn8JIks+KBNHRaLED/pPfn
W6vUEAUlQ+QmtZr69pDI95qSZGhdkedfQVqGOSB+yA==
=sIoh
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-6857-1
June 27, 2024
squid3 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
Summary:
Several security issues were fixed in Squid.
Software Description:
- squid3: Web proxy cache server
Details:
Joshua Rogers discovered that Squid incorrectly handled requests with the
urn: scheme. A remote attacker could possibly use this issue to cause
Squid to consume resources, leading to a denial of service. This issue
only affected Ubuntu 16.04 LTS. (CVE-2021-28651)
It was discovered that Squid incorrectly handled SSPI and SMB
authentication. A remote attacker could use this issue to cause Squid to
crash, resulting in a denial of service, or possibly obtain sensitive
information. This issue only affected Ubuntu 16.04 LTS. (CVE-2022-41318)
Joshua Rogers discovered that Squid incorrectly handled HTTP message
processing. A remote attacker could possibly use this issue to cause
Squid to crash, resulting in a denial of service. (CVE-2023-49285)
Joshua Rogers discovered that Squid incorrectly handled Helper process
management. A remote attacker could possibly use this issue to cause
Squid to crash, resulting in a denial of service. (CVE-2023-49286)
Joshua Rogers discovered that Squid incorrectly handled HTTP request
parsing. A remote attacker could possibly use this issue to cause
Squid to crash, resulting in a denial of service.
(CVE-2023-50269, CVE-2024-25617)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 18.04 LTS
squid 3.5.27-1ubuntu1.14+esm2
Available with Ubuntu Pro
squid3 3.5.27-1ubuntu1.14+esm2
Available with Ubuntu Pro
Ubuntu 16.04 LTS
squid 3.5.12-1ubuntu7.16+esm3
Available with Ubuntu Pro
squid3 3.5.12-1ubuntu7.16+esm3
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-6857-1
CVE-2021-28651, CVE-2022-41318, CVE-2023-49285, CVE-2023-49286,
CVE-2023-50269, CVE-2024-25617
[USN-6856-1] FontForge vulnerabilities
-----BEGIN PGP SIGNATURE-----
wsD5BAABCAAjFiEELRdhz3KY7FGicMD8Vjg+NdFTuLIFAmZ9bg8FAwAAAAAACgkQVjg+NdFTuLIG
MQwAr6VYPn9SY5/HjJuscot9oKsKOe2M5/45D93QIOk9w82E2GDujwknMCZAFiP14/3tPIOgYDJh
lmmE7FuuopRAlnsElba6ecn/rHo4FpZSPl7D3TZzKfJ3dtvDvbT5J9vg8Wbu8pBpVlGisCyW00nf
uous0QVay3j91Jk+gbtLYUfFDWgQO4pOfm5qhSZjwXTWwy70InkXiGJLt4vA4sHq2ksGhwYtcSVX
UCWKeLofhwR7oIpl+SBcvE6/K6a77JKxq304ygBmgn1GjgZKIZsLg4XSkPL0BEqEPvEToiLnk/bL
A5zbAInpE3QrFoQH6cqVIIfh6GkG2yM+LmIxaGpes58aGJ9yFdu+pmWfLUoo43fOry0ba5IaCoYS
3zuSUubzJaxXB5oSd0AKpJVAI6WuA5AUz10okseGoRAXUBCiqoPfuiUI+NJZymw6hiMK8khMdiYQ
5gKdpQJ4IO1e3xZdHxpstZkIv+SjycOMizgenBax3Vo/23C/jeL1L/8B88+w
=Jo+C
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-6856-1
June 27, 2024
fontforge vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 23.10
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
Summary:
Several security issues were fixed in FontForge.
Software Description:
- fontforge: Free (libre) font editor for Windows, Mac OS X and GNU+Linux
Details:
It was discovered that FontForge incorrectly handled filenames. If a user or an
automated system were tricked into opening a specially crafted input file, a
remote attacker could possibly use this issue to perform a command injection.
(CVE-2024-25081)
It was discovered that FontForge incorrectly handled archives and compressed
files. If a user or an automated system were tricked into opening a specially
crafted input file, a remote attacker could possibly use this issue to perform
command injection. (CVE-2024-25082)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 23.10
fontforge 1:20230101~dfsg-1ubuntu0.1
python3-fontforge 1:20230101~dfsg-1ubuntu0.1
Ubuntu 22.04 LTS
fontforge 1:20201107~dfsg-4+deb11u1build0.22.04.1
python3-fontforge 1:20201107~dfsg-4+deb11u1build0.22.04.1
Ubuntu 20.04 LTS
fontforge 1:20190801~dfsg-4ubuntu0.1
python3-fontforge 1:20190801~dfsg-4ubuntu0.1
Ubuntu 18.04 LTS
fontforge 1:20170731~dfsg-1ubuntu0.1~esm1
Available with Ubuntu Pro
python-fontforge 1:20170731~dfsg-1ubuntu0.1~esm1
Available with Ubuntu Pro
Ubuntu 16.04 LTS
fontforge 20120731.b-7.1ubuntu0.1+esm1
Available with Ubuntu Pro
python-fontforge 20120731.b-7.1ubuntu0.1+esm1
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-6856-1
CVE-2024-25081, CVE-2024-25082
Package Information:
https://launchpad.net/ubuntu/+source/fontforge/1:20230101~dfsg-1ubuntu0.1
https://launchpad.net/ubuntu/+source/fontforge/1:20201107~dfsg-4+deb11u1build0.22.04.1
https://launchpad.net/ubuntu/+source/fontforge/1:20190801~dfsg-4ubuntu0.1
wsD5BAABCAAjFiEELRdhz3KY7FGicMD8Vjg+NdFTuLIFAmZ9bg8FAwAAAAAACgkQVjg+NdFTuLIG
MQwAr6VYPn9SY5/HjJuscot9oKsKOe2M5/45D93QIOk9w82E2GDujwknMCZAFiP14/3tPIOgYDJh
lmmE7FuuopRAlnsElba6ecn/rHo4FpZSPl7D3TZzKfJ3dtvDvbT5J9vg8Wbu8pBpVlGisCyW00nf
uous0QVay3j91Jk+gbtLYUfFDWgQO4pOfm5qhSZjwXTWwy70InkXiGJLt4vA4sHq2ksGhwYtcSVX
UCWKeLofhwR7oIpl+SBcvE6/K6a77JKxq304ygBmgn1GjgZKIZsLg4XSkPL0BEqEPvEToiLnk/bL
A5zbAInpE3QrFoQH6cqVIIfh6GkG2yM+LmIxaGpes58aGJ9yFdu+pmWfLUoo43fOry0ba5IaCoYS
3zuSUubzJaxXB5oSd0AKpJVAI6WuA5AUz10okseGoRAXUBCiqoPfuiUI+NJZymw6hiMK8khMdiYQ
5gKdpQJ4IO1e3xZdHxpstZkIv+SjycOMizgenBax3Vo/23C/jeL1L/8B88+w
=Jo+C
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-6856-1
June 27, 2024
fontforge vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 23.10
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
Summary:
Several security issues were fixed in FontForge.
Software Description:
- fontforge: Free (libre) font editor for Windows, Mac OS X and GNU+Linux
Details:
It was discovered that FontForge incorrectly handled filenames. If a user or an
automated system were tricked into opening a specially crafted input file, a
remote attacker could possibly use this issue to perform a command injection.
(CVE-2024-25081)
It was discovered that FontForge incorrectly handled archives and compressed
files. If a user or an automated system were tricked into opening a specially
crafted input file, a remote attacker could possibly use this issue to perform
command injection. (CVE-2024-25082)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 23.10
fontforge 1:20230101~dfsg-1ubuntu0.1
python3-fontforge 1:20230101~dfsg-1ubuntu0.1
Ubuntu 22.04 LTS
fontforge 1:20201107~dfsg-4+deb11u1build0.22.04.1
python3-fontforge 1:20201107~dfsg-4+deb11u1build0.22.04.1
Ubuntu 20.04 LTS
fontforge 1:20190801~dfsg-4ubuntu0.1
python3-fontforge 1:20190801~dfsg-4ubuntu0.1
Ubuntu 18.04 LTS
fontforge 1:20170731~dfsg-1ubuntu0.1~esm1
Available with Ubuntu Pro
python-fontforge 1:20170731~dfsg-1ubuntu0.1~esm1
Available with Ubuntu Pro
Ubuntu 16.04 LTS
fontforge 20120731.b-7.1ubuntu0.1+esm1
Available with Ubuntu Pro
python-fontforge 20120731.b-7.1ubuntu0.1+esm1
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-6856-1
CVE-2024-25081, CVE-2024-25082
Package Information:
https://launchpad.net/ubuntu/+source/fontforge/1:20230101~dfsg-1ubuntu0.1
https://launchpad.net/ubuntu/+source/fontforge/1:20201107~dfsg-4+deb11u1build0.22.04.1
https://launchpad.net/ubuntu/+source/fontforge/1:20190801~dfsg-4ubuntu0.1
[USN-6852-2] Wget vulnerability
==========================================================================
Ubuntu Security Notice USN-6852-2
June 27, 2024
wget vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
Summary:
Wget could be made to connect to a different host than expected.
Software Description:
- wget: retrieves files from the web
Details:
USN-6852-1 fixed a vulnerability in Wget. This update provides
the corresponding update for Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
Original advisory details:
It was discovered that Wget incorrectly handled semicolons in the userinfo
subcomponent of a URI. A remote attacker could possibly trick a user into
connecting to a different host than expected.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 18.04 LTS
wget 1.19.4-1ubuntu2.2+esm1
Available with Ubuntu Pro
Ubuntu 16.04 LTS
wget 1.17.1-1ubuntu1.5+esm1
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-6852-2
https://ubuntu.com/security/notices/USN-6852-1
CVE-2024-38428
Ubuntu Security Notice USN-6852-2
June 27, 2024
wget vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
Summary:
Wget could be made to connect to a different host than expected.
Software Description:
- wget: retrieves files from the web
Details:
USN-6852-1 fixed a vulnerability in Wget. This update provides
the corresponding update for Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
Original advisory details:
It was discovered that Wget incorrectly handled semicolons in the userinfo
subcomponent of a URI. A remote attacker could possibly trick a user into
connecting to a different host than expected.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 18.04 LTS
wget 1.19.4-1ubuntu2.2+esm1
Available with Ubuntu Pro
Ubuntu 16.04 LTS
wget 1.17.1-1ubuntu1.5+esm1
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-6852-2
https://ubuntu.com/security/notices/USN-6852-1
CVE-2024-38428
Wednesday, June 26, 2024
[USN-6854-1] OpenSSL vulnerability
==========================================================================
Ubuntu Security Notice USN-6854-1
June 27, 2024
openssl vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 22.04 LTS
Summary:
OpenSSL could be made to consume resources and cause long delays if it processed
certain input.
Software Description:
- openssl: Secure Socket Layer (SSL) cryptographic library and tools
Details:
It was discovered that OpenSSL failed to choose an appropriately short
private key size when computing shared-secrets in the Diffie-Hellman Key
Agreement Protocol. A remote attacker could possibly use this issue to cause
OpenSSL to consume resources, resulting in a denial of service.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 22.04 LTS
libssl3 3.0.2-0ubuntu1.16
openssl 3.0.2-0ubuntu1.16
After a standard system update you need to reboot your computer to make all the
necessary changes.
References:
https://ubuntu.com/security/notices/USN-6854-1
CVE-2022-40735
Package Information:
https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.16
--
Alex Murray
Staff Engineer | Security Engineering
Adelaide, Australia (GMT+0930)
Ubuntu Security Notice USN-6854-1
June 27, 2024
openssl vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 22.04 LTS
Summary:
OpenSSL could be made to consume resources and cause long delays if it processed
certain input.
Software Description:
- openssl: Secure Socket Layer (SSL) cryptographic library and tools
Details:
It was discovered that OpenSSL failed to choose an appropriately short
private key size when computing shared-secrets in the Diffie-Hellman Key
Agreement Protocol. A remote attacker could possibly use this issue to cause
OpenSSL to consume resources, resulting in a denial of service.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 22.04 LTS
libssl3 3.0.2-0ubuntu1.16
openssl 3.0.2-0ubuntu1.16
After a standard system update you need to reboot your computer to make all the
necessary changes.
References:
https://ubuntu.com/security/notices/USN-6854-1
CVE-2022-40735
Package Information:
https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.16
--
Alex Murray
Staff Engineer | Security Engineering
Adelaide, Australia (GMT+0930)
[USN-6566-2] SQLite vulnerability
-----BEGIN PGP PUBLIC KEY BLOCK-----
xsFNBGZU5HkBEAC5gtbx2yg8wn9n1x0UKtCSpHCzCL/DDMi+ez8DqaDy2ym8waOh
X6ZeMYxEcRlZMEieo3VfpdioYr/reAs0XViMlSeM7DiMFN1Q6E3yDAaW8Ne/6OwU
6ID8AVV12dooWoa6Xa4hbLLLBMH0XRd8DVw4Zn6s+C18AMweC7Uf3ib62WI7jAxZ
vaRLV+1WWRBQlse5Of7hpvYsqbGuA4l/hzM2LYmWXXDOAsG2DhbSioQdSd89clH9
o1A/fCWNcVC80b7haAG96OaqXSaMny25Vdz5cGWj9SNOcVoXSoGdlu4JFQ/RQo/U
VRk2XTAKVJdIsVW5Fp/4O3z7nLzygDlC10YM0JAfNCuAgcr8pp14Tlz8ExMNqO7z
yhQt0iCn63UD5f/UB0oK2Ix8I5QK4JoHOeOUq8sDZez+bfX+D2KrYLQ4HONWNR2T
7XVnK9YNfWZyztZ7kVZlG3r/WSn1D6ZBj+Aolv2XtzweAn8HNxR3yZZe+1FoHLV3
JnNG1zaQs+WQJFGcQdjzdu5nvKXf4o0TJuakMbhcAh9DmhHGhRvesp9LOrDKxv7C
OXm8ER6G1wRyIh78bPTe6zRfMP49MX1LKUOHf+2T4IRt/7bz4OFXl5vfCWlAOUWN
i6EJ2qImw+2ouEKu9X/9p+I3FDALtOoys1MBKAdQsG/RhDfB2Bt/BRtZ7wARAQAB
zTZPY3RhdmlvIEFkb2xmbyBHYWxsYW5kIDxvY3RhdmlvLmdhbGxhbmRAY2Fub25p
Y2FsLmNvbT7CwZEEEwEKADsWIQRH8irnonVCkXIr8JD24UD22zWeWAUCZlTkeQIb
AwULCQgHAgIiAgYVCgkICwIEFgIDAQIeBwIXgAAKCRD24UD22zWeWNDaEACJOesZ
823ro/m2o9PVvjyw0wKn1/beHamwJFpp1ciDwYTLemsGjJf1e5D2HBVNTGSqmmnh
IZVSeCq6Ni9PbJlGsxJrGlVpaJRS8LBD/3xQNg5KYyT5loSge53oFBZgTAIj2sNX
UmtWZagQlBPdOB982CHqO6+2J/Dbly6qSKp8UUgatUNzbvClVhJmxA9TpV2WumSA
e4zR1JirXZGGgCg5NLhFiGtySnyS4lcl+hjtdYsvD3FDOiAJaSMJfCagW1gmpjX2
znaDhexnT6rXvWeV8ZP5xbMJfS7UxeArdW09uBBohjFteHzaBnqppVxMOwMaId0w
/+TRFsT+sDPMsdMBakJ3Tw6WS4qbfY8pbJGuvKZ4x5ZJlZdXpx9wsVY7EsA2qRqb
GtEFsyy+7zQ4HUTTbSmUc9PATpmcyJpXGM47iaGmN735Qc2gcZZLHYfylEs8bxHo
DeDxnDSDZhw+0E2/ZRRLUOlUzsxxGWW5tsJ+GHe69eceiDQJOdAiomJkSJMXQStv
vfsDd5wmX8Z8Yf+NGwWK0X/KQXBo6a9/6aDRE9HwyadYF+3F87dbr8KY/GlhYn6i
s5YRgGEIynvOVvxfrb3EAXe0f6iJq1TCEyvKAn3zhaw070wZWsVploAPJ8y9PKwi
UaHfH6s9RVZ94Qtz4BwasdGo2mnHJP0NWQcsnc7BTQRmVOR5ARAAuVJlTQ0Me3Fo
N8cVaUnux5nFraEUdLdKM9iD8L5Pj+LCJGHWkb3yGfdcWHkV9eOKTuixSajdJEj7
EKdzYaLRyKItwT0PFPcgNV7C6OGZYGvOd+9jGxMH4P9ENf+3eNurt+Za8SPLboRZ
faprZhn2nIX8JWPqWDzV3YUkq4Oyxo7DJJenuDQLPnG3WtcKogOpIpbw2h0vm04E
O5honjtDY8iwyYabl17/bFmZowL2SOmAgohWsGgzC3+/Zoyr7n80Ayv1nl/6Tecg
hqrRNfWTG8Y2e25p90DSv6D+NUwLWTaFHP1OivVfnvTTyrtQUGrV2rRR5AYzmqaz
NjGlAZ0FzZdKVV1vjgFZNnHH2avyQUALz3miaB3h2GHJbhI9EjhOkv+jVzMR8Pok
w19kS0ewed+O8PG5CecJZfwgDNWaqLL3QGYMFVKC5n8Ekv+XfqNxcgT3un8Zles5
V3ejOhdjvQqvKuV4ey5nZ8he/kzZbW27oGiy58SxK9RMy57bs3ugm8wbKc1B/EOX
2LdLo1kdQqCa3lWDReyb0S2I14ml9qddc3UA/IBtZDy0AfOlNbwzV+V9SW8j8lXh
4KGGNfNfsuRsSoiYNyIzCQEtRCEm9c/SkTwhW2oNTdztRtageji91y9zOPRf3lN9
HpDR05a8AoC1YonHZxxNcxQMScIUHp8AEQEAAcLBdgQYAQoAIBYhBEfyKueidUKR
civwkPbhQPbbNZ5YBQJmVOR5AhsMAAoJEPbhQPbbNZ5Yef0P/AwNuhnujouSKmc/
Nov/pHkcujZaYsn1iIoYEqhmWjpnBQav+m63G+RZ5zjqu36G7uhZkpYILPihLOJZ
X2SuTIrVitnJ+ocXK2QFLbW8gUlvqRi4kP5XbUQ0yAVWzPFlY9BNK6DUrj0LeC5n
4i+llAI9d50MiqlUDp+pdCotsuyE0PuuGDkY943LXWnPRPnHCv96ocOglN/dyVCB
N1fjEStCG4q3xzYO1KX3WnPOdurPh/CDw6Uypfr6VOlU+3BN+7t2wCk2V7tDjaYH
8/pZCzHCH3FDzUdEuVRBE0eB73yNFv1/SgVstqvTUfcYnaOm2EgvtBB14gIC8qBO
GPSjlh/7kMmD7m8ZiJNknUOL04mOFkDufnbcNUxmYEbn33TCbSIWDjt3RxTHVnzB
UZjYdBkUNJU1JcxDRJzoILSMUSLSH69z90UaArMiKMGtRoIQj2vSSQzdUgeGBBKv
vqE74KMQ0kj/qLaX6cCLUBX2kBShMVbQ7igp3Jytqj8hRvpPVo+xoXd42UWmLTCa
ISvwLtKvzrXYT80yYVUHhCx9keJ+zuOloshIPmvdVvfuoVaGVMpf6/gOJniRuUwA
ufUEKoy7Nl7w6e9pNIM7S5k7TqinqALWixkER9AfIOmEYYsmTVTBDLjsSEv0QWyJ
QGrNPtvSWtSzFkAmdaSP92Yi2kr2
=ZpuF
-----END PGP PUBLIC KEY BLOCK-----
-----BEGIN PGP SIGNATURE-----
wsF5BAABCAAjFiEER/Iq56J1QpFyK/CQ9uFA9ts1nlgFAmZ8f98FAwAAAAAACgkQ9uFA9ts1nliS
QQ//YFQgJ52jK3ZyMVzgEa4TSdhJ4gs1orH38OuSkTSxs/KceByOBip3jBq3HojIEe5DWdsbCEhV
+8WR0dvf6ZVzwepjtNsyFwXcgVHmpdCHVVBxwGd/W52Sbx8TAF6LI8n/y61PH3dFwE4+AXSzTD4M
vrbIE+avJbQzgamuqOwxJUoDrxiSEM/DwZGcXuY2Uj5HiLXuy8lQhU/nnPF5VZAzahxAu8O9pa9w
wscRY7AKEVV9TZU8nj4g9Y5b3L7wuGzywcJRT0wzLuu8PRP81sBlri1Fx9ljsscrbLeuKCcF3HlW
cgQhUYu6Evh4iJGu2n7sZbiJwKHRj4iaW1AX2L3yBczgGv1VbkgGzq7Ub/aixBQ8syYsYHuC/ADN
vI180b1p0iGIB4RJHggxo4jEmlb8WobT4niY+u+zd4J0obxayuApAiv2/NskKkC1xGUbbSDBWBb6
JyJfdqm9YR/KXSVFteXJnfjGCpZW4H2tonahticQ/c4b3wT48eXm7/l13CS1FIeoWL8ICh6+MRDM
WqtHygc8Xn+JYj4MYoQzCOw3B90V+PhvHdpUo3Uznil6V3adLtSUx30Rfc7QvloMo0wZfjr9j3K8
CEBDuTtqpSakn2GIMngvB3eRiSAByv5cBU98a08sJHxJz+QP46rqGDruX2Mgr82rJE1Zcdrw5X/z
QM8=
=yIj2
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-6566-2
June 26, 2024
sqlite3 vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 18.04 LTS
Summary:
SQLite could be made to crash if it received specially crafted
input.
Software Description:
- sqlite3: C library that implements an SQL database engine
Details:
USN-6566-1 fixed several vulnerabilities in SQLite. This update provides
the corresponding fix for CVE-2023-7104 for Ubuntu 18.04 LTS.
Original advisory details:
It was discovered that SQLite incorrectly handled certain memory operations
in the sessions extension. A remote attacker could possibly use this issue
to cause SQLite to crash, resulting in a denial of service.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 18.04 LTS
libsqlite3-0 3.22.0-1ubuntu0.7+esm1
Available with Ubuntu Pro
libsqlite3-dev 3.22.0-1ubuntu0.7+esm1
Available with Ubuntu Pro
libsqlite3-tcl 3.22.0-1ubuntu0.7+esm1
Available with Ubuntu Pro
sqlite3 3.22.0-1ubuntu0.7+esm1
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-6566-2
https://ubuntu.com/security/notices/USN-6566-1
CVE-2023-7104
xsFNBGZU5HkBEAC5gtbx2yg8wn9n1x0UKtCSpHCzCL/DDMi+ez8DqaDy2ym8waOh
X6ZeMYxEcRlZMEieo3VfpdioYr/reAs0XViMlSeM7DiMFN1Q6E3yDAaW8Ne/6OwU
6ID8AVV12dooWoa6Xa4hbLLLBMH0XRd8DVw4Zn6s+C18AMweC7Uf3ib62WI7jAxZ
vaRLV+1WWRBQlse5Of7hpvYsqbGuA4l/hzM2LYmWXXDOAsG2DhbSioQdSd89clH9
o1A/fCWNcVC80b7haAG96OaqXSaMny25Vdz5cGWj9SNOcVoXSoGdlu4JFQ/RQo/U
VRk2XTAKVJdIsVW5Fp/4O3z7nLzygDlC10YM0JAfNCuAgcr8pp14Tlz8ExMNqO7z
yhQt0iCn63UD5f/UB0oK2Ix8I5QK4JoHOeOUq8sDZez+bfX+D2KrYLQ4HONWNR2T
7XVnK9YNfWZyztZ7kVZlG3r/WSn1D6ZBj+Aolv2XtzweAn8HNxR3yZZe+1FoHLV3
JnNG1zaQs+WQJFGcQdjzdu5nvKXf4o0TJuakMbhcAh9DmhHGhRvesp9LOrDKxv7C
OXm8ER6G1wRyIh78bPTe6zRfMP49MX1LKUOHf+2T4IRt/7bz4OFXl5vfCWlAOUWN
i6EJ2qImw+2ouEKu9X/9p+I3FDALtOoys1MBKAdQsG/RhDfB2Bt/BRtZ7wARAQAB
zTZPY3RhdmlvIEFkb2xmbyBHYWxsYW5kIDxvY3RhdmlvLmdhbGxhbmRAY2Fub25p
Y2FsLmNvbT7CwZEEEwEKADsWIQRH8irnonVCkXIr8JD24UD22zWeWAUCZlTkeQIb
AwULCQgHAgIiAgYVCgkICwIEFgIDAQIeBwIXgAAKCRD24UD22zWeWNDaEACJOesZ
823ro/m2o9PVvjyw0wKn1/beHamwJFpp1ciDwYTLemsGjJf1e5D2HBVNTGSqmmnh
IZVSeCq6Ni9PbJlGsxJrGlVpaJRS8LBD/3xQNg5KYyT5loSge53oFBZgTAIj2sNX
UmtWZagQlBPdOB982CHqO6+2J/Dbly6qSKp8UUgatUNzbvClVhJmxA9TpV2WumSA
e4zR1JirXZGGgCg5NLhFiGtySnyS4lcl+hjtdYsvD3FDOiAJaSMJfCagW1gmpjX2
znaDhexnT6rXvWeV8ZP5xbMJfS7UxeArdW09uBBohjFteHzaBnqppVxMOwMaId0w
/+TRFsT+sDPMsdMBakJ3Tw6WS4qbfY8pbJGuvKZ4x5ZJlZdXpx9wsVY7EsA2qRqb
GtEFsyy+7zQ4HUTTbSmUc9PATpmcyJpXGM47iaGmN735Qc2gcZZLHYfylEs8bxHo
DeDxnDSDZhw+0E2/ZRRLUOlUzsxxGWW5tsJ+GHe69eceiDQJOdAiomJkSJMXQStv
vfsDd5wmX8Z8Yf+NGwWK0X/KQXBo6a9/6aDRE9HwyadYF+3F87dbr8KY/GlhYn6i
s5YRgGEIynvOVvxfrb3EAXe0f6iJq1TCEyvKAn3zhaw070wZWsVploAPJ8y9PKwi
UaHfH6s9RVZ94Qtz4BwasdGo2mnHJP0NWQcsnc7BTQRmVOR5ARAAuVJlTQ0Me3Fo
N8cVaUnux5nFraEUdLdKM9iD8L5Pj+LCJGHWkb3yGfdcWHkV9eOKTuixSajdJEj7
EKdzYaLRyKItwT0PFPcgNV7C6OGZYGvOd+9jGxMH4P9ENf+3eNurt+Za8SPLboRZ
faprZhn2nIX8JWPqWDzV3YUkq4Oyxo7DJJenuDQLPnG3WtcKogOpIpbw2h0vm04E
O5honjtDY8iwyYabl17/bFmZowL2SOmAgohWsGgzC3+/Zoyr7n80Ayv1nl/6Tecg
hqrRNfWTG8Y2e25p90DSv6D+NUwLWTaFHP1OivVfnvTTyrtQUGrV2rRR5AYzmqaz
NjGlAZ0FzZdKVV1vjgFZNnHH2avyQUALz3miaB3h2GHJbhI9EjhOkv+jVzMR8Pok
w19kS0ewed+O8PG5CecJZfwgDNWaqLL3QGYMFVKC5n8Ekv+XfqNxcgT3un8Zles5
V3ejOhdjvQqvKuV4ey5nZ8he/kzZbW27oGiy58SxK9RMy57bs3ugm8wbKc1B/EOX
2LdLo1kdQqCa3lWDReyb0S2I14ml9qddc3UA/IBtZDy0AfOlNbwzV+V9SW8j8lXh
4KGGNfNfsuRsSoiYNyIzCQEtRCEm9c/SkTwhW2oNTdztRtageji91y9zOPRf3lN9
HpDR05a8AoC1YonHZxxNcxQMScIUHp8AEQEAAcLBdgQYAQoAIBYhBEfyKueidUKR
civwkPbhQPbbNZ5YBQJmVOR5AhsMAAoJEPbhQPbbNZ5Yef0P/AwNuhnujouSKmc/
Nov/pHkcujZaYsn1iIoYEqhmWjpnBQav+m63G+RZ5zjqu36G7uhZkpYILPihLOJZ
X2SuTIrVitnJ+ocXK2QFLbW8gUlvqRi4kP5XbUQ0yAVWzPFlY9BNK6DUrj0LeC5n
4i+llAI9d50MiqlUDp+pdCotsuyE0PuuGDkY943LXWnPRPnHCv96ocOglN/dyVCB
N1fjEStCG4q3xzYO1KX3WnPOdurPh/CDw6Uypfr6VOlU+3BN+7t2wCk2V7tDjaYH
8/pZCzHCH3FDzUdEuVRBE0eB73yNFv1/SgVstqvTUfcYnaOm2EgvtBB14gIC8qBO
GPSjlh/7kMmD7m8ZiJNknUOL04mOFkDufnbcNUxmYEbn33TCbSIWDjt3RxTHVnzB
UZjYdBkUNJU1JcxDRJzoILSMUSLSH69z90UaArMiKMGtRoIQj2vSSQzdUgeGBBKv
vqE74KMQ0kj/qLaX6cCLUBX2kBShMVbQ7igp3Jytqj8hRvpPVo+xoXd42UWmLTCa
ISvwLtKvzrXYT80yYVUHhCx9keJ+zuOloshIPmvdVvfuoVaGVMpf6/gOJniRuUwA
ufUEKoy7Nl7w6e9pNIM7S5k7TqinqALWixkER9AfIOmEYYsmTVTBDLjsSEv0QWyJ
QGrNPtvSWtSzFkAmdaSP92Yi2kr2
=ZpuF
-----END PGP PUBLIC KEY BLOCK-----
-----BEGIN PGP SIGNATURE-----
wsF5BAABCAAjFiEER/Iq56J1QpFyK/CQ9uFA9ts1nlgFAmZ8f98FAwAAAAAACgkQ9uFA9ts1nliS
QQ//YFQgJ52jK3ZyMVzgEa4TSdhJ4gs1orH38OuSkTSxs/KceByOBip3jBq3HojIEe5DWdsbCEhV
+8WR0dvf6ZVzwepjtNsyFwXcgVHmpdCHVVBxwGd/W52Sbx8TAF6LI8n/y61PH3dFwE4+AXSzTD4M
vrbIE+avJbQzgamuqOwxJUoDrxiSEM/DwZGcXuY2Uj5HiLXuy8lQhU/nnPF5VZAzahxAu8O9pa9w
wscRY7AKEVV9TZU8nj4g9Y5b3L7wuGzywcJRT0wzLuu8PRP81sBlri1Fx9ljsscrbLeuKCcF3HlW
cgQhUYu6Evh4iJGu2n7sZbiJwKHRj4iaW1AX2L3yBczgGv1VbkgGzq7Ub/aixBQ8syYsYHuC/ADN
vI180b1p0iGIB4RJHggxo4jEmlb8WobT4niY+u+zd4J0obxayuApAiv2/NskKkC1xGUbbSDBWBb6
JyJfdqm9YR/KXSVFteXJnfjGCpZW4H2tonahticQ/c4b3wT48eXm7/l13CS1FIeoWL8ICh6+MRDM
WqtHygc8Xn+JYj4MYoQzCOw3B90V+PhvHdpUo3Uznil6V3adLtSUx30Rfc7QvloMo0wZfjr9j3K8
CEBDuTtqpSakn2GIMngvB3eRiSAByv5cBU98a08sJHxJz+QP46rqGDruX2Mgr82rJE1Zcdrw5X/z
QM8=
=yIj2
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-6566-2
June 26, 2024
sqlite3 vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 18.04 LTS
Summary:
SQLite could be made to crash if it received specially crafted
input.
Software Description:
- sqlite3: C library that implements an SQL database engine
Details:
USN-6566-1 fixed several vulnerabilities in SQLite. This update provides
the corresponding fix for CVE-2023-7104 for Ubuntu 18.04 LTS.
Original advisory details:
It was discovered that SQLite incorrectly handled certain memory operations
in the sessions extension. A remote attacker could possibly use this issue
to cause SQLite to crash, resulting in a denial of service.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 18.04 LTS
libsqlite3-0 3.22.0-1ubuntu0.7+esm1
Available with Ubuntu Pro
libsqlite3-dev 3.22.0-1ubuntu0.7+esm1
Available with Ubuntu Pro
libsqlite3-tcl 3.22.0-1ubuntu0.7+esm1
Available with Ubuntu Pro
sqlite3 3.22.0-1ubuntu0.7+esm1
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-6566-2
https://ubuntu.com/security/notices/USN-6566-1
CVE-2023-7104
Planned Outage - fedorapeople.org - 2024-06-27 21:00 UTC
There will be an outage starting at 2024-06-27 21:00 UTC,
which will last approximately 1 hour.
To convert UTC to your local time, take a look at
http://fedoraproject.org/wiki/Infrastructure/UTCHowto
or run:
date -d '2024-06-27 21:00 UTC'
Reason for outage:
We will be moving the fedorapeople.org vm to a RHEL9 install. During the outage repos and access to the server will be unavailable as we sync data from the old vm.
Additionally, we will be pointing fedoraplanet.org to a new application that pulls rss feeds from the fedora account system instead of using .planet files.
Please make sure your rss feed(s) are set in your account to continue sindicating them on fedoraplanet.org
Affected Services:
fedorapeople.org and all data stored there.
Ticket Link:
https://pagure.io/fedora-infrastructure/issue/12008
Please join #fedora-admin or #fedora-noc on irc.libera.chat
or #admin:fedoraproject.org / #noc:fedoraproject.org on matrix.
Please add comments to the ticket for this outage above.
Updated status for this outage may be available at
https://www.fedorastatus.org/
which will last approximately 1 hour.
To convert UTC to your local time, take a look at
http://fedoraproject.org/wiki/Infrastructure/UTCHowto
or run:
date -d '2024-06-27 21:00 UTC'
Reason for outage:
We will be moving the fedorapeople.org vm to a RHEL9 install. During the outage repos and access to the server will be unavailable as we sync data from the old vm.
Additionally, we will be pointing fedoraplanet.org to a new application that pulls rss feeds from the fedora account system instead of using .planet files.
Please make sure your rss feed(s) are set in your account to continue sindicating them on fedoraplanet.org
Affected Services:
fedorapeople.org and all data stored there.
Ticket Link:
https://pagure.io/fedora-infrastructure/issue/12008
Please join #fedora-admin or #fedora-noc on irc.libera.chat
or #admin:fedoraproject.org / #noc:fedoraproject.org on matrix.
Please add comments to the ticket for this outage above.
Updated status for this outage may be available at
https://www.fedorastatus.org/
OpenBGPD 8.5 released
We have released OpenBGPD 8.5, which will be arriving in the
OpenBGPD directory of your local OpenBSD mirror soon.
This release includes the following changes to the previous release:
* Include OpenBSD 7.5 errata 004:
Repair a withdraw desyncronization problem in bgpd(8).
Affected are OpenBGPD 8.2, 8.3 and 8.4.
* Fix Linux TCP MD5 autoconf detection and improve the code to work
in all cases.
* Double peer description length to 64 characters.
* Improve handling of bgpd AFI IPv4 sessions over IPv6 only links.
* Sessions over IPv6 link-local addresses are now always considered
to be connected.
* Allow operators to enforce the presence of certain capabilities.
* Improve capability negotiation and remove 'announce capabilities'.
The 'announce capabilities [yes|no]' neighbor config option needs to be
removed from configuration files. Instead individual capabilities
need to be disabled.
* Improve negotiation of the multi-protocol capability and the fallback
to IPv4 only mode.
* Mark RTR and IPv6 BGP packets with DSCP CS6 (network control).
* Increase RTR PDU limit to 48k and limit number of SPAS to 10'000.
* Convert the remaining session engine parsers to the new ibuf API.
* Various changes to autoconf and portable headers for NetBSD support.
OpenBGPD-portable is known to compile and run on FreeBSD and the
Linux distributions Alpine, Debian, Fedora, RHEL/CentOS and Ubuntu.
It is our hope that packagers take interest and help adapt OpenBGPD-portable
to more distributions.
We welcome feedback and improvements from the broader community.
Thanks to all of the contributors who helped make this release
possible.
OpenBGPD directory of your local OpenBSD mirror soon.
This release includes the following changes to the previous release:
* Include OpenBSD 7.5 errata 004:
Repair a withdraw desyncronization problem in bgpd(8).
Affected are OpenBGPD 8.2, 8.3 and 8.4.
* Fix Linux TCP MD5 autoconf detection and improve the code to work
in all cases.
* Double peer description length to 64 characters.
* Improve handling of bgpd AFI IPv4 sessions over IPv6 only links.
* Sessions over IPv6 link-local addresses are now always considered
to be connected.
* Allow operators to enforce the presence of certain capabilities.
* Improve capability negotiation and remove 'announce capabilities'.
The 'announce capabilities [yes|no]' neighbor config option needs to be
removed from configuration files. Instead individual capabilities
need to be disabled.
* Improve negotiation of the multi-protocol capability and the fallback
to IPv4 only mode.
* Mark RTR and IPv6 BGP packets with DSCP CS6 (network control).
* Increase RTR PDU limit to 48k and limit number of SPAS to 10'000.
* Convert the remaining session engine parsers to the new ibuf API.
* Various changes to autoconf and portable headers for NetBSD support.
OpenBGPD-portable is known to compile and run on FreeBSD and the
Linux distributions Alpine, Debian, Fedora, RHEL/CentOS and Ubuntu.
It is our hope that packagers take interest and help adapt OpenBGPD-portable
to more distributions.
We welcome feedback and improvements from the broader community.
Thanks to all of the contributors who helped make this release
possible.
[USN-6851-1] Netplan vulnerabilities
==========================================================================
Ubuntu Security Notice USN-6851-1
June 26, 2024
netplan.io vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 24.04 LTS
- Ubuntu 23.10
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
Summary:
Netplan could reveal secrets or execute commands with specially crafted
configuration file.
Software Description:
- netplan.io: Declarative network configuration for various backends
Details:
Andreas Hasenack discovered that netplan incorrectly handled the permissions
for netdev files containing wireguard configuration. An attacker could use this to obtain
wireguard secret keys.
It was discovered that netplan configuration could be manipulated into injecting
arbitrary commands while setting up network interfaces. An attacker could
use this to execute arbitrary commands or escalate privileges.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 24.04 LTS
libnetplan1 1.0-2ubuntu1.1
netplan-generator 1.0-2ubuntu1.1
netplan.io 1.0-2ubuntu1.1
Ubuntu 23.10
libnetplan0 0.107-5ubuntu0.3
netplan-generator 0.107-5ubuntu0.3
netplan.io 0.107-5ubuntu0.3
Ubuntu 22.04 LTS
libnetplan0 0.106.1-7ubuntu0.22.04.3
netplan.io 0.106.1-7ubuntu0.22.04.3
Ubuntu 20.04 LTS
libnetplan0 0.104-0ubuntu2~20.04.5
netplan.io 0.104-0ubuntu2~20.04.5
After a standard system update you need to reboot your computer to make
all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-6851-1
CVE-2022-4968, https://launchpad.net/bugs/1987842, https://launchpad.net/bugs/2065738, https://launchpad.net/bugs/2066258
Package Information:
https://launchpad.net/ubuntu/+source/netplan.io/1.0-2ubuntu1.1
https://launchpad.net/ubuntu/+source/netplan.io/0.107-5ubuntu0.3
https://launchpad.net/ubuntu/+source/netplan.io/0.106.1-7ubuntu0.22.04.3
https://launchpad.net/ubuntu/+source/netplan.io/0.104-0ubuntu2~20.04.5
Ubuntu Security Notice USN-6851-1
June 26, 2024
netplan.io vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 24.04 LTS
- Ubuntu 23.10
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
Summary:
Netplan could reveal secrets or execute commands with specially crafted
configuration file.
Software Description:
- netplan.io: Declarative network configuration for various backends
Details:
Andreas Hasenack discovered that netplan incorrectly handled the permissions
for netdev files containing wireguard configuration. An attacker could use this to obtain
wireguard secret keys.
It was discovered that netplan configuration could be manipulated into injecting
arbitrary commands while setting up network interfaces. An attacker could
use this to execute arbitrary commands or escalate privileges.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 24.04 LTS
libnetplan1 1.0-2ubuntu1.1
netplan-generator 1.0-2ubuntu1.1
netplan.io 1.0-2ubuntu1.1
Ubuntu 23.10
libnetplan0 0.107-5ubuntu0.3
netplan-generator 0.107-5ubuntu0.3
netplan.io 0.107-5ubuntu0.3
Ubuntu 22.04 LTS
libnetplan0 0.106.1-7ubuntu0.22.04.3
netplan.io 0.106.1-7ubuntu0.22.04.3
Ubuntu 20.04 LTS
libnetplan0 0.104-0ubuntu2~20.04.5
netplan.io 0.104-0ubuntu2~20.04.5
After a standard system update you need to reboot your computer to make
all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-6851-1
CVE-2022-4968, https://launchpad.net/bugs/1987842, https://launchpad.net/bugs/2065738, https://launchpad.net/bugs/2066258
Package Information:
https://launchpad.net/ubuntu/+source/netplan.io/1.0-2ubuntu1.1
https://launchpad.net/ubuntu/+source/netplan.io/0.107-5ubuntu0.3
https://launchpad.net/ubuntu/+source/netplan.io/0.106.1-7ubuntu0.22.04.3
https://launchpad.net/ubuntu/+source/netplan.io/0.104-0ubuntu2~20.04.5
[USN-6853-1] Ruby vulnerability
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAmZ8MMUACgkQZWnYVadE
vpNVhBAAkIc/YyZDnCx5ajXvDXRDLV8Fk2L5mls//9UpjMEEz39xTGb1w8b5Ze6u
IfV1l1ztGy11NYFGbo3/67dWrSZIQ+ml8cEGx24lSn8fdQJLFXXTV+JxIMhKjW3F
FiDy8fmonbw/38tDg5MH1Hf+SMT/Vx9YrPu6ssuudCGXz42XmoSzEZvO5ArdSOAY
Bu2kEPDPWafBqzHVpEFLAnWQtBWrdqjOL8684PvtkMmKzLTBC+qAXdFBPE04Q/7N
XTOaOWagR0xg5HoRXwKzreBFwtp1vmevepBfRTaKSaOTO63lNDAh2WInRMkK+9vU
bWR8KB3H4PneZOT4pnJToXVrLk2PPd2mmI1+hh56ZbV25g/tXS7HOt+keg97EiRu
nRaqicMKOzH1xgvvXR9cHLtEnrup2IEacATPlP0aAzoRvF3ATMypIeqzcnJxMMi4
PuxnWgr8NlQLT12m/Ci6gQkUEVqnF97TW4HjnRcTh4NnW5VlQrOKHp/4C4E7Vttt
y1t/a0QMcec9nUH609BJMeSQgUQzlkI3G1ai+4qJrPcPf4l51aI8fjjd4yJcZIJ4
mln3fMjpCz7MAtnTeFD3YMdY4qUupVlCjdaaZ1ytSFPK/UUNamC+OYa1qSohiN2v
QF1N8eIqRiUMZgS6xP9yMd400uwWnt2wcm2qpvmmbbm4Uno4rDU=
=m/EH
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-6853-1
June 26, 2024
ruby2.7, ruby3.0, ruby3.1 vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 23.10
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
Summary:
Ruby could be made to crash or expose sensitive information login if it
processed certain strings.
Software Description:
- ruby3.1: Object-oriented scripting language
- ruby3.0: Object-oriented scripting language
- ruby2.7: Object-oriented scripting language
Details:
It was discovered that Ruby incorrectly handled the ungetbyte and ungetc
methods. A remote attacker could use this issue to cause Ruby to crash,
resulting in a denial of service, or possibly obtain sensitive information.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 23.10
libruby3.1 3.1.2-7ubuntu3.3
ruby3.1 3.1.2-7ubuntu3.3
Ubuntu 22.04 LTS
libruby3.0 3.0.2-7ubuntu2.7
ruby3.0 3.0.2-7ubuntu2.7
Ubuntu 20.04 LTS
libruby2.7 2.7.0-5ubuntu1.14
ruby2.7 2.7.0-5ubuntu1.14
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-6853-1
CVE-2024-27280
Package Information:
https://launchpad.net/ubuntu/+source/ruby3.1/3.1.2-7ubuntu3.3
https://launchpad.net/ubuntu/+source/ruby3.0/3.0.2-7ubuntu2.7
https://launchpad.net/ubuntu/+source/ruby2.7/2.7.0-5ubuntu1.14
iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAmZ8MMUACgkQZWnYVadE
vpNVhBAAkIc/YyZDnCx5ajXvDXRDLV8Fk2L5mls//9UpjMEEz39xTGb1w8b5Ze6u
IfV1l1ztGy11NYFGbo3/67dWrSZIQ+ml8cEGx24lSn8fdQJLFXXTV+JxIMhKjW3F
FiDy8fmonbw/38tDg5MH1Hf+SMT/Vx9YrPu6ssuudCGXz42XmoSzEZvO5ArdSOAY
Bu2kEPDPWafBqzHVpEFLAnWQtBWrdqjOL8684PvtkMmKzLTBC+qAXdFBPE04Q/7N
XTOaOWagR0xg5HoRXwKzreBFwtp1vmevepBfRTaKSaOTO63lNDAh2WInRMkK+9vU
bWR8KB3H4PneZOT4pnJToXVrLk2PPd2mmI1+hh56ZbV25g/tXS7HOt+keg97EiRu
nRaqicMKOzH1xgvvXR9cHLtEnrup2IEacATPlP0aAzoRvF3ATMypIeqzcnJxMMi4
PuxnWgr8NlQLT12m/Ci6gQkUEVqnF97TW4HjnRcTh4NnW5VlQrOKHp/4C4E7Vttt
y1t/a0QMcec9nUH609BJMeSQgUQzlkI3G1ai+4qJrPcPf4l51aI8fjjd4yJcZIJ4
mln3fMjpCz7MAtnTeFD3YMdY4qUupVlCjdaaZ1ytSFPK/UUNamC+OYa1qSohiN2v
QF1N8eIqRiUMZgS6xP9yMd400uwWnt2wcm2qpvmmbbm4Uno4rDU=
=m/EH
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-6853-1
June 26, 2024
ruby2.7, ruby3.0, ruby3.1 vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 23.10
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
Summary:
Ruby could be made to crash or expose sensitive information login if it
processed certain strings.
Software Description:
- ruby3.1: Object-oriented scripting language
- ruby3.0: Object-oriented scripting language
- ruby2.7: Object-oriented scripting language
Details:
It was discovered that Ruby incorrectly handled the ungetbyte and ungetc
methods. A remote attacker could use this issue to cause Ruby to crash,
resulting in a denial of service, or possibly obtain sensitive information.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 23.10
libruby3.1 3.1.2-7ubuntu3.3
ruby3.1 3.1.2-7ubuntu3.3
Ubuntu 22.04 LTS
libruby3.0 3.0.2-7ubuntu2.7
ruby3.0 3.0.2-7ubuntu2.7
Ubuntu 20.04 LTS
libruby2.7 2.7.0-5ubuntu1.14
ruby2.7 2.7.0-5ubuntu1.14
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-6853-1
CVE-2024-27280
Package Information:
https://launchpad.net/ubuntu/+source/ruby3.1/3.1.2-7ubuntu3.3
https://launchpad.net/ubuntu/+source/ruby3.0/3.0.2-7ubuntu2.7
https://launchpad.net/ubuntu/+source/ruby2.7/2.7.0-5ubuntu1.14
[USN-6852-1] Wget vulnerability
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAmZ8MKYACgkQZWnYVadE
vpPpiBAAq8X2cCPbP9unXBdAJJ6UMQweGzHEfv5ljURmacX6fstKftz96yolGyNO
PSLC5vmrVbr7grtUuh++ul0IbLhxah4fTLwreyuMpCIBOEN/CVBYdcSQ7yKj19UC
fKlN6sg8baWwO5Gvr9fFrz0deKMzYJLlBe1UTMun6xKAx6jq4vFPOmmq3Zbb+YWa
APKsV+3Zzl02oAwA0niZ6pgnxFvNdEk7FQfZWAeD0Ajg2v5h9mhKQszpaTlpXA/g
zoLMaamJpA+lJt/8cxXIAS1uJH7oTjT18EvrEZbjsLWpaqMaYlWMchKf+PSjLE1+
okFECojBfkt9NqGmUpfCzaLtXy9lVhy5AVJc8iTMEdPLJniDC+yXar1I+KZTlyJR
6n7tnVUUdBW/PX4xWmvtcxWUbq/vxkdxECbse1XeNE873hVRJhOf6JKoZ4WA+UVi
O8eFpYckY0Ft7aJwidrBKFEV7OPXk5Bvr8nUVIwvITizUPCPdfD4cpY2Mh1YBVsg
nvVwA4chwJZ3Dv0DmOy4WbAAu27TryKvco3JlkI3NnkIeplDwNl7vVSostKHHGws
c+UPDT23dhGRCiBPPzMzs/WqP7z9RsVZ3AASKxaoBoUemosnBH1xO5wFQKL4/jZl
WPU1tuDU1xEPHdD1LtbnACOjegi4ax188a6kbkvgdN/DuuasrQE=
=bUZU
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-6852-1
June 26, 2024
wget vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 24.04 LTS
- Ubuntu 23.10
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
Summary:
Wget could be made to connect to a different host than expected.
Software Description:
- wget: retrieves files from the web
Details:
It was discovered that Wget incorrectly handled semicolons in the userinfo
subcomponent of a URI. A remote attacker could possibly trick a user into
connecting to a different host than expected.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 24.04 LTS
wget 1.21.4-1ubuntu4.1
Ubuntu 23.10
wget 1.21.3-1ubuntu1.1
Ubuntu 22.04 LTS
wget 1.21.2-2ubuntu1.1
Ubuntu 20.04 LTS
wget 1.20.3-1ubuntu2.1
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-6852-1
CVE-2024-38428
Package Information:
https://launchpad.net/ubuntu/+source/wget/1.21.4-1ubuntu4.1
https://launchpad.net/ubuntu/+source/wget/1.21.3-1ubuntu1.1
https://launchpad.net/ubuntu/+source/wget/1.21.2-2ubuntu1.1
https://launchpad.net/ubuntu/+source/wget/1.20.3-1ubuntu2.1
iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAmZ8MKYACgkQZWnYVadE
vpPpiBAAq8X2cCPbP9unXBdAJJ6UMQweGzHEfv5ljURmacX6fstKftz96yolGyNO
PSLC5vmrVbr7grtUuh++ul0IbLhxah4fTLwreyuMpCIBOEN/CVBYdcSQ7yKj19UC
fKlN6sg8baWwO5Gvr9fFrz0deKMzYJLlBe1UTMun6xKAx6jq4vFPOmmq3Zbb+YWa
APKsV+3Zzl02oAwA0niZ6pgnxFvNdEk7FQfZWAeD0Ajg2v5h9mhKQszpaTlpXA/g
zoLMaamJpA+lJt/8cxXIAS1uJH7oTjT18EvrEZbjsLWpaqMaYlWMchKf+PSjLE1+
okFECojBfkt9NqGmUpfCzaLtXy9lVhy5AVJc8iTMEdPLJniDC+yXar1I+KZTlyJR
6n7tnVUUdBW/PX4xWmvtcxWUbq/vxkdxECbse1XeNE873hVRJhOf6JKoZ4WA+UVi
O8eFpYckY0Ft7aJwidrBKFEV7OPXk5Bvr8nUVIwvITizUPCPdfD4cpY2Mh1YBVsg
nvVwA4chwJZ3Dv0DmOy4WbAAu27TryKvco3JlkI3NnkIeplDwNl7vVSostKHHGws
c+UPDT23dhGRCiBPPzMzs/WqP7z9RsVZ3AASKxaoBoUemosnBH1xO5wFQKL4/jZl
WPU1tuDU1xEPHdD1LtbnACOjegi4ax188a6kbkvgdN/DuuasrQE=
=bUZU
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-6852-1
June 26, 2024
wget vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 24.04 LTS
- Ubuntu 23.10
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
Summary:
Wget could be made to connect to a different host than expected.
Software Description:
- wget: retrieves files from the web
Details:
It was discovered that Wget incorrectly handled semicolons in the userinfo
subcomponent of a URI. A remote attacker could possibly trick a user into
connecting to a different host than expected.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 24.04 LTS
wget 1.21.4-1ubuntu4.1
Ubuntu 23.10
wget 1.21.3-1ubuntu1.1
Ubuntu 22.04 LTS
wget 1.21.2-2ubuntu1.1
Ubuntu 20.04 LTS
wget 1.20.3-1ubuntu2.1
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-6852-1
CVE-2024-38428
Package Information:
https://launchpad.net/ubuntu/+source/wget/1.21.4-1ubuntu4.1
https://launchpad.net/ubuntu/+source/wget/1.21.3-1ubuntu1.1
https://launchpad.net/ubuntu/+source/wget/1.21.2-2ubuntu1.1
https://launchpad.net/ubuntu/+source/wget/1.20.3-1ubuntu2.1
Subscribe to:
Posts (Atom)