| Newsgroups |
gmane.linux.lfs.beyond.devel,gmane.linux.lfs.devel,gmane.linux.lfs.support,gmane.linux.lfs.beyond.support |
| Message-ID |
<[email protected]> |
Good evening folks,
I'm hoping this is the last security announcement email of the 12.3
release cycle, as we released LFS 12.3-rc2 earlier this afternoon! Since
the last email though there have been some pretty significant issues
resolved that I'd like to bring attention to.
The following packages have received security updates since the last
time I sent an email:
- GnuTLS (Medium)
- WebKitGTK (Critical)
- Intel Microcode (High)
- Unzip (Low)
- OpenSSL (High)
- Python3 (High)
- vim (Medium)
- PostgreSQL (High)
- Wireshark (High)
- Emacs (Critical)
- Xorg-Server (High)
- Xwayland (High)
- OpenSSH (Medium)
- Exim (High)
- libxml2 (High)
- Exiv2 (Medium)
The first package that we'll discuss is GnuTLS. Last time I sent an
email, we talked about libtasn1. GnuTLS has been updated as a follow up
to that vulnerability, and users who have updated to libtasn1-4.20.0
should also update GnuTLS to 3.8.9. It offers additional protection
against a potential denial of service that occurs when handling
certificates with a very large number of name constraints. Users who
have GnuTLS installed should update to GnuTLS-3.8.9.
Next up we'll talk about WebKitGTK. Four security vulnerabilities were
fixed that could allow for a maliciously crafted webpage to fingerprint
a user, for command injection when copying URLs from the Web inspector,
and for denial of service (unexpected process crashes). The user
fingerprinting problem was fixed by improving access restrictions to the
underlying filesystem, while the URL copying issue was fixed with
improved handling of files. The denial of service issues were fixed with
improved memory handling and state management. I recommend that users
who have WebKitGTK installed update to WebKitGTK-2.46.6 to protect
yourself against the fingerprinting issue.
The next one we'll discuss is the Intel Microcode. In the 20250211
update, twelve security vulnerabilities in Intel hardware were fixed.
There are a large variety of potential impacts, from crashes to
privilege escalation to information disclosure. The oldest CPUs affected
by the microcode update are from the 8th-generation Intel Core CPU
family, so it's recommended that if you have an 8th-generation CPU or
later that you update your microcode. More details can be found in the
security advisory (12.2-083) as it gets very complicated.
Next we'll talk about Unzip. A NULL Pointer Dereference can be triggered
and it will cause a segmentation fault. The bug is located in the code
responsible for handling Unicode strings. After some research, Xi Ruoyao
replaced the unzip package with a symlink from unzip to bsdunzip in the
libarchive page, as the Unzip package has not been maintained for a
number of years. I highly recommend that all users make the symbolic
link to protect themselves if they are unzipping ZIP files.
Next up on the list is OpenSSL. Two security vulnerabilities were fixed
that could allow for a timing side-channel attack when computing ECSDA
signatures (allowing for exfiltration of a private key in an ECDSA
signature), and for RFC7250 handshakes with unauthenticated servers to
not be aborted as expected. That issue in particular causes clients
which use the RFC7250 Raw Public Keys functionality to be vulnerable to
man-in-the-middle attacks, because server authentication failures are
not detected by clients (and then data gets transmitted in plain text).
Thankfully, RPKs are disabled by default in both TLS clients and TLS
servers. Because of the side channel vulnerability it's recommended to
update to OpenSSL-3.4.1 (or 3.3.3). If you upgrade OpenSSL to a new
minor version, you will need to rebuild OpenSSH if it is installed (and
earlier than the 9.4p1 release). If you upgrade OpenSSL from 1.x to 3.x,
you will need to rebuild every package linked against OpenSSL.
There were five vulnerabilities fixed in Python3 that could allow for
hostnames to not be flagged as incorrect when using urlparse, for denial
of service conditions (memory exhaustion and crashes) when processing
Unicode characters, for the asyncio module to malfunction (causing
crashes), for the imaplib module to connect to a malicious server, and
for email header spoofing when using the email module. Only two of those
vulnerabilities were assigned CVEs, but there is additional information
available in the security advisory (SA-12.2-086) for the ones which were
not assigned CVEs. If you are on Python-3.12.x, you should update to
3.12.9, otherwise you should update to Python 3.13.2.
VIM has another security vulnerability that could allow for a heap use
after free, but it requires a user to redirect the output of ':display'
to a register rather than a variable or a file. If you do use that
functionality, you should update VIM to 9.1.1122 or later as soon as
possible, but there is no need to upgrade if you are not using that
functionality.
There was a very severe vulnerability fixed in PostgreSQL recently, and
this one is a bit special. The vulnerability allows for SQL Injection
and arbitrary code execution. It occurs because of how PostgreSQL's
string escaping routines handle invalid UTF-8 characters, in combination
with how invalid byte sequences within the invalid UTF-8 characters are
processed by the 'psql' utility. The vulnerability was used to
compromise the United States Treasury around the end of last year, and
was discovered by Rapid7. This was a bit of a rare situation as
emergency security updates were released by PostgreSQL for all of their
supported lines, but a critical regression was immediately found which
caused quoting functions to not honor their string length parameters,
which led to crashes and other strange behavior. Upstream took 7 days to
release that update, so we didn't advise users to update to the original
patched version of PostgreSQL because of the severity of the regression.
That being said - **IF YOU USE POSTGRESQL AS A DATABASE SERVER, YOU NEED
TO UPDATE TO POSTGRESQL-17.4 IMMEDIATELY**. If you are just using it for
the client libraries, you are unaffected by this vulnerability. For
anyone curious about the attack vector, please read
https://www.rapid7.com/blog/post/2025/02/13/cve-2025-1094-postgresql-psql-sql-injection-fixed/
Wireshark had a security vulnerability fixed which could allow for a
remotely exploitable crash when processing Bundle Protocol or CBOR
packets using their respective dissectors. If you aren't operating
Wireshark on a network with those kinds of packets going across it, or
opening untrusted packet capture files, you should be safe to skip this
update. If you are impacted, update to Wireshark-4.4.4 or later.
Emacs had two security vulnerabilities fixed that could allow for shell
injection and arbitrary code execution. The shell injection
vulnerability occurs in the man.el function, which allows remote
unauthenticated attackers to execute arbitrary shell commands on a
vulnerable system. The arbitrary code execution vulnerability occurs
when a user invokes elisp-completion-at-point (which is used for code
completion), on untrusted Emacs LISP source code. This can trigger
unsafe LISP macro expansion, which then allows for arbitrary code
execution. However, it's also exploitable if you enable
on-the-fly-diagnostics, which will compile the impacted code to
determine if there are any syntax errors. If you have Emacs installed,
it's highly recommended to update to Emacs 30.1, especially due to the
man.el vulnerability.
Xorg-Server and XWayland had eight security vulnerabilities fixed
recently which could allow for denial of service or arbitrary code
execution. They occur due to a variety of buffer overflows,
use-after-frees, out-of-bounds writes, and the usage of an uninitialized
pointer in a variety of different functions. Because of the potential
impacts, it's highly recommended that you update Xorg-Server to 21.1.16,
and XWayland-24.1.6. It's especially paramount if you use SSH X
Forwarding as that opens the door to remote code execution. At the same
time, you should update TigerVNC if you have it installed so that the
new version of Xorg-Server is implemented.
OpenSSH had two vulnerabilities fixed that allow for man-in-the-middle
attacks to impersonate any server, and for a denial of service condition
(memory exhaustion). Upstream has rated the issues as Medium though, as
they are very complicated to exploit. In order to be exploited by the
man-in-the-middle attack, you must have the VerifyHostKeyDNS option
enabled, and your system's memory resources must be exhausted. At the
same time, the attacker must be on your path to the server. If this
happens though, OpenSSH will be unable to properly verify the server's
host key. Updating to OpenSSH-9.9p2 is recommended if you have the
VerifyHostKeyDNS option enabled.
Exim had a security vulnerability fixed which is pretty severe on the
surface, but thankfully does not impact users of the default BLFS
configuration. The vulnerability is a SQL Injection vulnerability. If
you have deviated by the configuration by doing the following, you are
impacted and should update to Exim-4.98.1 **immediately**:
- Built Exim with SQLite support instead of using GDBM
- Enabled ETRN
- Enforced ETRN serialization
If you run a publicly-accessible mail server and have the following
deviations, you should check your server for indicators of compromise,
including unauthorized file creation and unrecognized mails or entries
in your logs, and update Exim to 4.98.1. If you do use Exim but haven't
deviated from the default configuration in BLFS, you can skip this
update safely.
In libxml2, three security vulnerabilities were fixed that could allow
for remote code execution, arbitrary code execution, and denial of
service conditions (application crashes). The first of the three
vulnerabilities occurs due to a stack buffer overflow in the
xmlSnprintfElements function, and the second vulnerability happens due
to a use-after--free in the xmlSchemaItemListAdd function. libxml2 is
used in many places in BLFS, and in several different contexts, from
generating documentation to just parsing XML files and browsing web
documents written in XHTML. Because of the severity of the
vulnerabilities, **ALL** BLFS users who have libxml2 installed need to
update to libxml2-2.13.6 immediately.
The last update that I'd like to bring up here is Exiv2. In
Exiv2-0.28.5, a security vulnerability was fixed that allows for
arbitrary code execution. In order to exploit it, a user needs to run
Exiv2 on a crafted TIFF image file and write metadata to the image. It's
a rather uncommon operation, but users who might be modifying metadata
in TIFF images should update to 0.28.5 as soon as possible.
Thank you all, and I'll talk to you about security vulnerabilities after
the release of LFS/BLFS 12.3 if all goes well.
- Doug
--
http://lists.linuxfromscratch.org/sympa/info/blfs-dev
Unsubscribe: See the above information page