TTCSIRT-198.020419: TT-CSIRT Advisory – FireFox Security Updates

TTCSIRT-197.012319: TT-CSIRT Advisory – Apple Security Updates

Apple has released a security update stating that the following vulnerabilities were patched in iCloud, Safari, watchOS, tvOS, Mojave, High Sierra, Sierra, and iOS: a) A buffer overflow issue was addressed with improved memory handling – (CVE-2019-6224). b) A cross-site scripting issue existed in Safari. This issue was addressed with improved URL validation – (CVE-2019-6228). […]

TTCSIRT-196.012319: TT-CSIRT Advisory – Drupal Security Updates

Drupal has released a security update stating that a remote code execution vulnerability exists in PHP’s built-in phar stream wrapper when performing file operations on an untrusted phar:// URI. Some Drupal code (core, contrib, and custom) may be performing file operations on insufficiently validated user input, thereby being exposed to this vulnerability. This issue is […]

TTCSIRT-195.011119: TT-CSIRT Advisory – PHP Security Updates

PHP has released a security update stating that the following vulnerabilities have been discovered in the following versions of PHP: Version 5.6.40 Bug #77242 (heap out of bounds read in xmlrpc_decode()). Bug #77247 (heap buffer overflow in phar_detect_phar_fname_ext). Bug #77269 (efree() on uninitialized Heap data in imagescale leads to Bug #77270 (imagecolormatch Out Of Bounds […]

TTCSIRT-194.011119: TT-CSIRT Advisory – Android Security Updates

Google has released a security update stating that the following vulnerabilities have been discovered in the Android Operating System: a) An elevation of privilege vulnerability in Framework – (CVE-2018-9582). b) A remote code execution vulnerability in System – (CVE-2018-9583). c) Multiple elevation of privilege vulnerabilities in System – (CVE-2018-9584). d) Multiple information disclosure vulnerabilities in […]

TTCSIRT-193.010419: TT-CSIRT Advisory – Cisco Security Updates

Cisco has released a security update stating that an issue in the authorization subsystem of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated but unprivileged, (levels 0 and 1), remote attacker to perform privileged actions by using the web management interface. The vulnerability is due to improper validation of user privileges when using […]

TTCSIRT-192.010419: TT-CSIRT Advisory – Adobe Security Updates

Adobe has released a security update stating that the following issues have been discovered in Adobe Acrobat & Reader: a) Multiple security bypass privilege escalation – (CVE-2018-16018). b) Multiple use after free arbitrary code execution (CVE-2018-16011). Successful exploitation of these vulnerabilities could result in the attacker gaining control of the affected system and depending on […]

TTCSIRT-190.122718: TT-CSIRT Advisory – Chrome Security Updates

Google has released a security update stating that an use-after-free issue in PDFium could allow for arbitrary code execution (CVE-2018-17481). Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code through the browser and depending on the privileges associated with the application, an attacker could install programs view, change, delete data or […]

TTCSIRT-189.121318: TT-CSIRT Advisory – Mozilla Security Updates

Mozilla has released a security update stating that it has discovered the following issues with Microsoft FireFox ver 64.0: a) A buffer overflow occurs when drawing and validating elements with the ANGLE graphics library, used for WebGL content, when working with the VertexBuffer11 module. b) A use-after-free vulnerability can occur after deleting a selection element […]