A huge number of CVEs fixed in the various Ubuntu releases, including for
PHP, Git, Thunderbird, GNU binutils and more, plus Joe McManus discusses
ROS with Sid Faber.
Show Notes
Overview
A huge number of CVEs fixed in the various Ubuntu releases, including for
PHP, Git, Thunderbird, GNU binutils and more, plus Joe McManus discusses
ROS with Sid Faber.
get_headers() would silently truncate a URL containing a NUL terminator
(\0) - so if used with user-supplied URL could get wrong details from the
server
stack overflow in mb_strtolower() when handling UTF32-LE encoding
1 byte buffer overread in handling EXIF data - info leak / crash
PHAR archives created with world readable permissions
NULL pointer dereference on file upload in certain situations -> crash
Similar to CVE-2020-5260 from Episode 71 - due to an incomplete fix for
that where some credentials may still be leaked but the attacker cannot
control which ones
Huge update covering many issues - thanks Marc Deslauriers - mostly in
low severity issues like memory leaks in functions / utilities which are
used only once or which are assumed to process trusted input.
Often requested by customers who run vuln scanners - finds many open
issues but doesn’t consider low severity - only 3 out of 44 had medium
severity
Goings on in Ubuntu Security Community
Joe McManus talks ROS & ROS2 with Sid Faber from the Ubuntu Security Team [06:26]