In the final episode of 2019, we look at security updates for RabbitMQ,
GraphicsMagick, OpenJDK and more, plus Joe and Alex discuss a typical
day-in-the-life of a Ubuntu Security Team member.
Show Notes
Overview
In the final episode of 2019, we look at security updates for RabbitMQ,
GraphicsMagick, OpenJDK and more, plus Joe and Alex discuss a typical
day-in-the-life of a Ubuntu Security Team member.
Possible integer overflow when handling the CONNECTION_STATE_HEADER
frame - rogue server could return a malicious frame header which is then
processed by the client and leads to a smaller target_size value due to
integer overflow - then when the frame data is copied in via memcpy()
this would overwrite past the bounds of the heap allocation, and with
attacker controlled data
Latest upstream micro-release for openjdk 8 and openjdk 11
Various mix of issues (buffer overflows, NULL pointer dereferences and
various denial of service issues on application crashes in different
scenarios) - see the full USN for details
Goings on in Ubuntu Security Community
Joe and Alex discuss a day-in-the-life of a Ubuntu Security Team member [03:50]