Artwork

Alex Murray and Ubuntu Security Team에서 제공하는 콘텐츠입니다. 에피소드, 그래픽, 팟캐스트 설명을 포함한 모든 팟캐스트 콘텐츠는 Alex Murray and Ubuntu Security Team 또는 해당 팟캐스트 플랫폼 파트너가 직접 업로드하고 제공합니다. 누군가가 귀하의 허락 없이 귀하의 저작물을 사용하고 있다고 생각되는 경우 여기에 설명된 절차를 따르실 수 있습니다 https://ko.player.fm/legal.
Player FM -팟 캐스트 앱
Player FM 앱으로 오프라인으로 전환하세요!

Episode 108

11:48
 
공유
 

Manage episode 287773536 series 2423058
Alex Murray and Ubuntu Security Team에서 제공하는 콘텐츠입니다. 에피소드, 그래픽, 팟캐스트 설명을 포함한 모든 팟캐스트 콘텐츠는 Alex Murray and Ubuntu Security Team 또는 해당 팟캐스트 플랫폼 파트너가 직접 업로드하고 제공합니다. 누군가가 귀하의 허락 없이 귀하의 저작물을 사용하고 있다고 생각되는 경우 여기에 설명된 절차를 따르실 수 있습니다 https://ko.player.fm/legal.

Overview

This week we start preparing for 16.04 LTS to transition to Extended Security Maintenance, plus we look at security updates for OpenSSH, Python, the Linux kernel and more, as well as some currently open positions on our team.

This week in Ubuntu Security Updates

28 unique CVEs addressed

[USN-4762-1] OpenSSH vulnerability [00:54]

  • 1 CVEs addressed in Focal (20.04 LTS), Groovy (20.10)
  • Double free in ssh-agent - so only affects openssh-client and where the ssh-agent socket is able to be accessed by other users etc - on moderns systems the socket is only accessible by the owner so would need to have forwarded the ssh-agent to an attacker controlled host perhaps to be vulnerable..

[USN-4763-1] Pillow vulnerabilities [01:50]

[USN-4754-3] Python vulnerabilities [02:50]

[USN-4764-1] GLib vulnerability [04:57]

  • 1 CVEs addressed in Xenial (16.04 LTS), Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10)
  • g_file_replace() on a dangling symlink would also create the target of the symlink as an empty file (but only if did not already exist)

[USN-4876-1] Linux kernel vulnerabilities [05:49]

[USN-4877-1] Linux kernel vulnerabilities

[USN-4878-1] Linux kernel vulnerabilities

[USN-4879-1] Linux kernel vulnerabilities

  • 2 CVEs addressed in Focal (20.04 LTS), Groovy (20.10)
  • 5.8
  • Marvell wifi driver buffer overflow - could be triggered by a malicious remote device sending a overly long ad-hoc SSID value - DoS, RCE

[USN-4880-1] OpenJPEG vulnerabilities [07:00]

Goings on in Ubuntu Security Community

Preparing for 16.04 ESM transition [07:35]

Hiring [10:17]

AppArmor Security Engineer

Ubuntu Security Engineer

Security Engineer - Ubuntu

Get in contact

  continue reading

231 에피소드

Artwork

Episode 108

Ubuntu Security Podcast

138 subscribers

published

icon공유
 
Manage episode 287773536 series 2423058
Alex Murray and Ubuntu Security Team에서 제공하는 콘텐츠입니다. 에피소드, 그래픽, 팟캐스트 설명을 포함한 모든 팟캐스트 콘텐츠는 Alex Murray and Ubuntu Security Team 또는 해당 팟캐스트 플랫폼 파트너가 직접 업로드하고 제공합니다. 누군가가 귀하의 허락 없이 귀하의 저작물을 사용하고 있다고 생각되는 경우 여기에 설명된 절차를 따르실 수 있습니다 https://ko.player.fm/legal.

Overview

This week we start preparing for 16.04 LTS to transition to Extended Security Maintenance, plus we look at security updates for OpenSSH, Python, the Linux kernel and more, as well as some currently open positions on our team.

This week in Ubuntu Security Updates

28 unique CVEs addressed

[USN-4762-1] OpenSSH vulnerability [00:54]

  • 1 CVEs addressed in Focal (20.04 LTS), Groovy (20.10)
  • Double free in ssh-agent - so only affects openssh-client and where the ssh-agent socket is able to be accessed by other users etc - on moderns systems the socket is only accessible by the owner so would need to have forwarded the ssh-agent to an attacker controlled host perhaps to be vulnerable..

[USN-4763-1] Pillow vulnerabilities [01:50]

[USN-4754-3] Python vulnerabilities [02:50]

[USN-4764-1] GLib vulnerability [04:57]

  • 1 CVEs addressed in Xenial (16.04 LTS), Bionic (18.04 LTS), Focal (20.04 LTS), Groovy (20.10)
  • g_file_replace() on a dangling symlink would also create the target of the symlink as an empty file (but only if did not already exist)

[USN-4876-1] Linux kernel vulnerabilities [05:49]

[USN-4877-1] Linux kernel vulnerabilities

[USN-4878-1] Linux kernel vulnerabilities

[USN-4879-1] Linux kernel vulnerabilities

  • 2 CVEs addressed in Focal (20.04 LTS), Groovy (20.10)
  • 5.8
  • Marvell wifi driver buffer overflow - could be triggered by a malicious remote device sending a overly long ad-hoc SSID value - DoS, RCE

[USN-4880-1] OpenJPEG vulnerabilities [07:00]

Goings on in Ubuntu Security Community

Preparing for 16.04 ESM transition [07:35]

Hiring [10:17]

AppArmor Security Engineer

Ubuntu Security Engineer

Security Engineer - Ubuntu

Get in contact

  continue reading

231 에피소드

모든 에피소드

×
 
Loading …

플레이어 FM에 오신것을 환영합니다!

플레이어 FM은 웹에서 고품질 팟캐스트를 검색하여 지금 바로 즐길 수 있도록 합니다. 최고의 팟캐스트 앱이며 Android, iPhone 및 웹에서도 작동합니다. 장치 간 구독 동기화를 위해 가입하세요.

 

빠른 참조 가이드