Episode 234

Episode 234

Update: 2024-08-09
Share

Description

Overview


This week we take a deep dive behind-the-scenes look into how the team handled a
recent report from Snyk’s Security Lab of a local privilege escalation
vulnerability in wpa_supplicant plus we cover security updates in Prometheus
Alertmanager, OpenSSL, Exim, snapd, Gross, curl and more.


This week in Ubuntu Security Updates


185 unique CVEs addressed


[USN-6935-1] Prometheus Alertmanager vulnerability (01:08 )



  • 1 CVEs addressed in Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS)


  • Stored XSS via the Alertmanager UI - alerts API allows to specify a URL which
    should be able to be called interactively by the user from the UI - an
    attacker instead could POST to this with arbitrary JavaScript which would then
    get included in the generated HTML and hence run on users when viewing the UI

  • Fixed to validate this field is actually a URL before including in the
    generated UI page


[USN-6938-1] Linux kernel vulnerabilities (02:05 )



[USN-6922-2] Linux kernel vulnerabilities



[USN-6926-2] Linux kernel vulnerabilities



[USN-6895-4] Linux kernel vulnerabilities


Comments 
In Channel
Episode 243

Episode 243

2024-12-2024:00

Episode 242

Episode 242

2024-11-2919:40

Episode 241

Episode 241

2024-11-1418:16

Episode 240

Episode 240

2024-10-3136:22

Episode 239

Episode 239

2024-10-1839:16

Episode 238

Episode 238

2024-10-0431:39

Episode 237

Episode 237

2024-09-2016:16

Episode 236

Episode 236

2024-09-0618:23

Episode 235

Episode 235

2024-08-2317:40

Episode 234

Episode 234

2024-08-0929:11

Episode 233

Episode 233

2024-08-0224:07

Episode 232

Episode 232

2024-07-0529:20

Episode 231

Episode 231

2024-06-2819:00

Episode 230

Episode 230

2024-06-2021:12

Episode 229

Episode 229

2024-05-3113:22

Episode 228

Episode 228

2024-05-2415:33

Episode 227

Episode 227

2024-05-0324:41

Episode 226

Episode 226

2024-04-1923:59

Episode 225

Episode 225

2024-04-1219:42

Episode 224

Episode 224

2024-04-0528:49

loading
00:00
00:00
x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

Episode 234

Episode 234

Ubuntu Security Team