This week we cover security updates for Apache, Twisted, Vim a kernel
livepatch and more, plus Alex and Joe discuss OVAL data feeds and the
cvescan snap for vulnerability awareness.
Show Notes
Overview
This week we cover security updates for Apache, Twisted, Vim a kernel
livepatch and more, plus Alex and Joe discuss OVAL data feeds and the
cvescan snap for vulnerability awareness.
All low / negligible since requires a user to use vim to source a crafted
file (ie a list of commands / settings for vim) or crafted undo /
spelling dictionary etc
Integer overflows -> heap overflows -> DoS / RCE etc
Episode 47 - implements it’s own private DBus server which clients
connect to - original vuln allowed any user who knew address of this bus
to connect to it - update fixed this by checking the connecting user was
the same as the owning user - but caused a regression in Qt clients -
would fail to be able to properly connect to ibus - was reverted - this
has seen been fixed by fixing the GDBusServer implementation in libglib2
since it was actually incorrect - and so now we have re-fixed in ibus
Goings on in Ubuntu Security Community
Alex and Joe discuss Ubuntu Security OVAL feeds and cvescan [06:47]