TTCSIRT-279.021220: TT-CSIRT ADVISORY- MICROSOFT RELEASES FEBRUARY 2020 SECURITY UPDATES

TTCSIRT-279.021220: TT-CSIRT ADVISORY- MICROSOFT RELEASES FEBRUARY 2020 SECURITY UPDATES

Microsoft has released security updates to address multiple vulnerabilities in their software. An attacker could exploit some of these vulnerabilities to take control of an affected system. TT-CSIRT encourages users and administrators to review Microsoft’s February 2020 Security Update Summary and Deployment Information and apply the necessary updates. https://portal.msrc.microsoft.com/en-us/security-guidance/releasenotedetail/2020-Feb https://support.microsoft.com/en-us/help/20200211/security-update-deployment-information-february-11-2020

TTCSIRT-278.021220: TT-CSIRT ADVISORY- MOZILLA RELEASES SECURITY UPDATES FOR MULTIPLE PRODUCTS

Mozilla has released security updates to address vulnerabilities in Firefox, Firefox ESR, and Thunderbird. An attacker could exploit some of these vulnerabilities to take control of an affected system. The Trinidad and Tobago Cyber Security Incident Response Team (CSIRT) encourages users administrators to review the following Mozilla Security Advisories and apply the necessary updates: Firefox […]

TTCSIRT-277.021220: TT-CSIRT ADVISORY- ADOBE RELEASES SECURITY UPDATES FOR MULTIPLE PRODUCTS

Adobe has released security updates to address vulnerabilities in multiple Adobe products. An attacker could exploit some of these vulnerabilities to take control of an affected system. The Trinidad and Tobago Cyber Security Incident Response Team (CSIRT) encourages users and administrators to review the following Adobe Security Bulletins and apply the necessary updates: Framemaker APSB20-04 Acrobat […]

TTCSIRT-275.012820: TT-CSIRT ADVISORY- TOMCAT8 VULNERABLITIES ADVISORY

A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.04 LTS Summary: Several security issues were fixed in Tomcat. Software Description: tomcat8 – Servlet and JSP engine Details: It was discovered that Tomcat incorrectly handled the RMI registry when configured with the JMX Remote Lifecycle Listener. A local attacker could possibly use this issue to […]

TTCSIRT-273.012720: TT-CSIRT ADVISORY – MULTIPLE VULNERABILITIES IN PHP COULD ALLOW FOR ARBITRARY CODE EXECUTION

Multiple vulnerabilities have been discovered in PHP, the most severe of which could allow for arbitrary code execution. PHP is a programming language originally designed for use in web-based applications with HTML content. PHP supports a wide variety of platforms and is used by numerous web-based software applications. Successfully exploiting the most severe of these […]

TTCSIRT-272.012720: TT-CSIRT ADVISORY – CISCO EMAIL SECURITY APPLIANCE CONTENT FILTER BYPASS VULNERABILTY

Cisco has released security updates to address a vulnerability affecting the email message of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA). This could allow an unauthenticated, remote attacker to bypass configured filters on the device. An attacker could exploit this vulnerability by sending a crafted email message to a recipient protected by the […]

TTCSIRT-271.012720: TT-CSIRT ADVISORY – CISCO RELEASES SECURITY UPDATES

Cisco has released security updates to address a vulnerability affecting Cisco Webex Meetings Suite and Cisco Webex Meetings Online. A remote attacker could exploit this vulnerability to obtain sensitive information. TT-CSIRT encourages users and administrators to review Cisco Security Advisory and apply the necessary updates. https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200124-webex-unauthjoin    

TTCSIRT-270.012120: TT-CSIRT ADVISORY- SAMBA RELEASES SECURITY UPDATES

The Samba Team has released security updates to address vulnerabilities in multiple versions of Samba. An attacker could exploit one of these vulnerabilities to take control of an affected system. The Trinidad and Tobago Cyber Security Incident Response Team (TTCSIRT) encourages users and administrators to review the Samba Security Announcements for CVE-2019-14902, CVE-2019-14907, and CVE-2019-19344 and apply the necessary […]

TTCSIRT-269.012020: TT-CSIRT ADVISORY- CITRIX ADDS SD-WAN WANOP, UPDATED MITIGATIONS TO CVE-2019-19781 ADVISORY

Citrix has released an article with updates on CVE-2019-19781, a vulnerability affecting Citrix Application Delivery Controller (ADC) and Citrix Gateway. This vulnerability also affects Citrix SD-WAN WANOP product versions 10.2.6 and version 11.0.3. The article includes updated mitigations for Citrix ADC and Citrix Gateway Release 12.1 build 50.28. An attacker could exploit CVE-2019-19781 to take […]