Government of the Republic of Trinidad and Tobago
gov.tt

Securing the Nation's Digital Infrastructure

TTCSIRT-282.022620: TT-CSIRT ADVISORY-ADOBE RELEASES SECURITY UPDATES FOR AFTER EFFECTS AND MEDIA ENCODER

Adobe has released security updates to address vulnerabilities in After Effects and Media Encoder. An attacker could exploit these vulnerabilities to take control of an affected system. TT-CSIRT encourages users and administrators to review Adobe Security Bulletins APSB20-09 and APSB20-10 and apply the necessary updates: https://helpx.adobe.com/security/products/after_effects/apsb20-09.html https://helpx.adobe.com/security/products/media-encoder/apsb20-10.html  

TTCSIRT-281.022620: TT-CSIRT ADVISORY- VMWARE RELEASES SECURITY UPDATES FOR VREALIZE OPERATIONS FOR HORIZON ADAPTER

VMware has released security updates to address multiple vulnerabilities in vRealize Operations for Horizon Adapter. A remote attacker could exploit some of these vulnerabilities to take control of an affected system. TT-CSIRT encourages users and administrators to review VMware Security Advisory VMSA-2020-0003 and apply the necessary updates: https://www.vmware.com/security/advisories/VMSA-2020-0003.html  

TTCSIRT-280.021220: TT-CSIRT ADVISORY- INTEL RELEASES SECURITY UPDATES

Intel has released security updates to address vulnerabilities in multiple products. An attacker could exploit these vulnerabilities to gain escalation of privileges. TT-CSIRT encourages users and administrators to review the following Intel advisories and apply the necessary updates. RWC3 Advisory – INTEL-SA-00341 https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00341.html   MPSS Advisory – INTEL-SA-00340 https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00340.html   RWC2 Advisory – INTEL-SA-00339 https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00339.html …

TTCSIRT-279.021220: TT-CSIRT ADVISORY- MICROSOFT RELEASES FEBRUARY 2020 SECURITY UPDATES

Microsoft has released security updates to address multiple vulnerabilities in their software. An attacker could exploit some of these vulnerabilities to take control of an affected system. TT-CSIRT encourages users and administrators to review Microsoft’s February 2020 Security Update Summary and Deployment Information and apply the necessary updates. https://portal.msrc.microsoft.com/en-us/security-guidance/releasenotedetail/2020-Feb https://support.microsoft.com/en-us/help/20200211/security-update-deployment-information-february-11-2020

TTCSIRT-278.021220: TT-CSIRT ADVISORY- MOZILLA RELEASES SECURITY UPDATES FOR MULTIPLE PRODUCTS

Mozilla has released security updates to address vulnerabilities in Firefox, Firefox ESR, and Thunderbird. An attacker could exploit some of these vulnerabilities to take control of an affected system. The Trinidad and Tobago Cyber Security Incident Response Team (CSIRT) encourages users administrators to review the following Mozilla Security Advisories and apply the necessary updates: Firefox …

TTCSIRT-277.021220: TT-CSIRT ADVISORY- ADOBE RELEASES SECURITY UPDATES FOR MULTIPLE PRODUCTS

Adobe has released security updates to address vulnerabilities in multiple Adobe products. An attacker could exploit some of these vulnerabilities to take control of an affected system. The Trinidad and Tobago Cyber Security Incident Response Team (CSIRT) encourages users and administrators to review the following Adobe Security Bulletins and apply the necessary updates: Framemaker APSB20-04 Acrobat …

TTCSIRT-274.012820: TT-CSIRT ADVISORY – MySQL VULNERABILITIES ADVISORY

Multiple security issues were discovered in MySQL and this update includes new upstream MySQL versions to fix these issues. MySQL has been updated to 8.0.19 in Ubuntu 19.10. Ubuntu 16.04 LTS and Ubuntu 18.04 LTS have been updated to MySQL 5.7.29. In addition to security fixes, the updated packages contain bug fixes, new features, and …

TTCSIRT-275.012820: TT-CSIRT ADVISORY- TOMCAT8 VULNERABLITIES ADVISORY

A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.04 LTS Summary: Several security issues were fixed in Tomcat. Software Description: tomcat8 – Servlet and JSP engine Details: It was discovered that Tomcat incorrectly handled the RMI registry when configured with the JMX Remote Lifecycle Listener. A local attacker could possibly use this issue to …

TTCSIRT-273.012720: TT-CSIRT ADVISORY – MULTIPLE VULNERABILITIES IN PHP COULD ALLOW FOR ARBITRARY CODE EXECUTION

Multiple vulnerabilities have been discovered in PHP, the most severe of which could allow for arbitrary code execution. PHP is a programming language originally designed for use in web-based applications with HTML content. PHP supports a wide variety of platforms and is used by numerous web-based software applications. Successfully exploiting the most severe of these …

TTCSIRT-272.012720: TT-CSIRT ADVISORY – CISCO EMAIL SECURITY APPLIANCE CONTENT FILTER BYPASS VULNERABILTY

Cisco has released security updates to address a vulnerability affecting the email message of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA). This could allow an unauthenticated, remote attacker to bypass configured filters on the device. An attacker could exploit this vulnerability by sending a crafted email message to a recipient protected by the …