4 ms·
How can you tell if an Ubuntu 20.04 server has this fix?
by SiVal 6y ago
How can you tell if an Ubuntu 20.04 server has this fix?
- severino 6y agoYou can use "apt-cache policy", for example. This way you can see the current installed version of a package in your system, and also if there's a newer version you can install (the candidate). $ apt-cache policy accountsservice accountsservice: Installed: 0.6.40-2ubuntu11.6 Candidate: 0.6.40-2ubuntu11.6 If the installed version reported by the utility is the version that Ubuntu states the problem has been fixed for your release, then presumably your system is safe (for this bug).
- Forbo 6y agoThe article states that server isn't affected, because it requires access to a graphical desktop session. Edit with direct quote from the article: > Disclaimer: For someone to exploit this vulnerability, they need access to the graphical desktop session of the system, so this issue affects desktop users only. Am I wrong?
- hitpointdrew 6y agoOnly if the server has no GUI installed. I worked a place where the Network Admin, had a bunch of older RedHat servers with GUI's. I had to become the "bad guy" because on the newer boxes I was in charge of I refused to install a GUI, a bunch of devs pissed and moaned because they couldn't use xterm to connect to the new servers. It was pretty backwards place.
- freedomben 6y agoAt the risk of igniting an irrelevant flame war, this is one of the primary reasons why I use Vim and only Vim as my IDE. I don't have to care about lack of graphical environments ;-)
- jdhawk 6y agoside note, long time - and still current vim developer who also uses JetBrains IDE products... I'd pay similar money to have a similarly robust VIM plugin from a supported vendor with great support and sane keybindings OOTB. man, its easy to get spoiled with tons of ram and a great IDE.
- freedomben 6y agoYes, I don't know if anybody will ever see this, but I agree! I would gladly pay similar for a robust VIM plugin setup that gave me similar features on a range of languages.
- tinco 6y agoWe run some machine learning systems on Ubuntu server, and it's really easy to accidentily install the full desktop environment while installing random graphics driver related packages. While figuring out how to set things up (before I formalized in an ansible script) one of the servers ended up with the desktop packages installed. Weird to look at the IPMI overview and between all the white on black kernel log outputs suddenly seeing a full Ubuntu desktop boot screen.
- zeta0134 6y agoIt's somewhat common to install a graphical environment on server machines, particularly if they need to run certain (Oracle) enterprise software, for which GUI tools are either the only option, or by far the most expected and documented solution. Of course in theory you could install the bare minimum to run the utility using X-forwarding, in practice anyone doing this usually installs a full environment because it's much simpler to manage. Plus, there are a few admins out there who simply prefer to use VNC over a straight terminal. I'm not here to judge; while this is uncommon, it's certainly not unheard of. Personally I would rather not have that much attack surface on my servers, but there are a few legitimate use cases here and there.
- Twirrim 6y ago> It's somewhat common to install a graphical environment on server machines It's really not that common. Yes there's the odd cases of servers that use enterprise software that have to have GUIs, but most linux boxes run headless. GUIs are just a waste of processing power and resources for the large majority of the things that servers are used for. That said, I'm not happy that Canonical are entirely discounting the possibility that customers will have desktop environments installed on servers. It's not common, but it does happen.
- dannyw 6y agoOne thing to note is that depending on how your network is structured and firewalled, if _one_ server has a graphical env of some sort (maybe a ML/image processing server that has graphical environments installed)... root access could be nasty nonetheless. I never install GUIs on my servers, but when deploying a image processing server, while installing another package to debug CUDA/drivers, I've unintentionally added a full windowing system without realising it.
- woodson 6y agoUnfortunately, nvidia-settings requires xorg to be installed and running (even when run in cli mode), and it's pretty much the only way to control fan speeds on consumer GPUs.
- Denvercoder9 6y agoCheck if the installed version is equal to or higher than one of the listed fixed versions. Likely it isn't even installed on a server edition.
- e12e 6y agoAssuming the server can reach the normal apt repos - you could: sudo apt update; apt list upgradable And grep for this package. Otherwise sudo apt update /usr/lib/update-notifier/apt-check --human-readable Will list number of pending security updates. (part of update-notifier-common, and in task:server along with various desktop-tasks) Beyond that, you might want to look at https://vuls.io https://vuls.io or other auditing packages. Or perhaps: sudo snap install cvescan cvescan Seems it could use some exposure - I wasn't aware of it: https://github.com/canonical/sec-cvescan https://github.com/canonical/sec-cvescan