TTCSIRT-170.100818: TT-CSIRT Advisory – VMware Security Updates

TTCSIRT-170.100818: TT-CSIRT Advisory – VMware Security Updates

VMWare has released a security update stating that the VMware Workspace ONE Unified Endpoint Management Console (AirWatch Console) contains a SAML authentication bypass vulnerability which can be leveraged during device enrollment. This issue may allow for a malicious actor to impersonate an authorized SAML session if certificate-based authentication is enabled. Further information on this vulnerability […]

TTCSIRT-168.092818: TT-CSIRT Advisory – Cisco Security Updates

Cisco has released a security update stating that an in the web user interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due to a double-free-in-memory handling by the affected software when specific HTTP requests are processed. An attacker could exploit this […]

TTCSIRT-167.092018: TT-CSIRT Advisory – PHP Security Updates

PHP has released a security update stating that the following vulnerabilities have been discovered in PHP ver 7.2.10 & Version 7.1.22: a) Bug #55146 – (iconv_mime_decode_headers() skips some headers) b) Bug #60494 – (iconv_mime_decode does ignore special characters) c) Bug #63839 – (iconv_mime_decode_headers function is skipping headers) d) Bug #65988 – (Zlib version check fails […]

TTCSIRT-165.091418: TT-CSIRT Advisory – HP Security Updates

HP has released a security update stating that it has discovered a vulnerability in some versions of its inkjet printers where a maliciously crafted file sent to an affected device can cause a stack or static buffer overflow which could allow remote code execution. Further information on this vulnerability and which inkjet printer versions it […]

TTCSIRT-164.091318: TT-CSIRT Advisory – Android Security Updates

Google has released a security update stating that the following issues have been discovered in the Android OS: a) An remote code vulnerability in Android Runtime – (CVE-2018-9466). b) An elevation of privilege vulnerability in Android Runtime – (CVE-2018-9467). c) An information disclosure vulnerability in Framework – (CVE-2018-9468). d) Multiple elevation of privilege vulnerabilities in […]

TTCSIRT-163.091318: TT-CSIRT Advisory – Adobe Security Updates

Adobe has released a security update stating that the following issues have been discovered in Adobe ColdFusion: a) A security bypass vulnerability that could allow for arbitrary folder creation – (CVE-2018-15963). b) A directory listing vulnerability that could allow for information disclosure – (CVE-2018-15962). c) An unrestricted file upload vulnerability that could allow for arbitrary […]