TTCSIRT-143.071618: TT-CSIRT Advisory – Microsoft Security Updates

TTCSIRT-143.071618: TT-CSIRT Advisory – Microsoft Security Updates

Microsoft has released a security update stating that multiple vulnerabilities have been discovered in the following products: a) Microsoft Windows 7, 8.1, RT 8.1, and 10 b) Microsoft Windows Server 2008, 2008 R2, 2012, 2012 R2, 2016 c) Microsoft Windows Server Core Installation 2008, 2008 R2, 2012, 2012 R2, 2016 d) Microsoft Office 2010, 2013, […]

TTCSIRT-142.071218: TT-CSIRT Advisory – DHCP Security Updates

The Internet Systems Consortium (ISC) has released a security update stating that Kea DHCP 1.4.0 may fail to release memory after temporarily storing client network packets. This causes a constant increase in memory consumption that can cause server resources to become exhausted, leading to loss of DHCP server functionality. An attacker who is within the […]

TTCSIRT-141.071218: TT-CSIRT Advisory – Adobe Security Updates

Adobe has released a security update stating that it has discovered the following issues in Adobe Flash Player: a) A type confusion vulnerability that could allow for arbitrary code execution – (CVE-2018-5007). b) An out-of-bounds read vulnerability that could lead to information disclosure – (CVE-2018-5008). Successful exploitation of the most severe of these vulnerabilities could […]

TTCSIRT-140.070618: TT-CSIRT Advisory – Android Security Updates

Google has released a security update stating that the following issues have been discovered in the Android OS: a) A remote code execution vulnerability in Framework – (CVE-2018-9433). b) Multiple remote code execution vulnerabilities in Qualcomm components – (CVE-2018-3586, CVE-2018-5872). c) A remote code execution vulnerability in System – (CVE-2018-9365). d) An information disclosure vulnerability […]

TTCSIRT-139.070618: TT-CSIRT Advisory – VMware Security Updates

VMware has released a security update stating that ESXi, Workstation, and Fusion contain an out-of-bounds read vulnerability in their shader translator. Successful exploitation of this issue may lead to information disclosure or may allow attackers with normal user privileges to crash their VMs. Further information on this vulnerability and how it can be mitigated can […]

TTCSIRT-138.062918: TT-CSIRT Advisory – Mozilla Security Updates

Mozilla has released a security update stating that it has discovered the following vulnerabilities Firefox ESR 52.9: a) Buffer overflow using computed size of canvas element – CVE-2018-12359. b) Use-after-free when using focus() – CVE-2018-12360. c) Integer overflow in SSSE3 scaler – CVE-2018-12362. Successful exploitation of the most severe of these vulnerabilities could allow for […]

TTCSIRT-137.062918: TT-CSIRT Advisory – SSDP Security Updates

NETSCOUT Arbor has released a security update stating that the Simple Service Discovery Protocol (SSDP) can be exploited to launch a new type of distributed denial of service (DDoS) attack where devices respond with a non-standard port. SSDP, which was designed for service discovery over a local network, uses text-based HTTP messages over UDP (also […]

TTCSIRT-136.062618: TT-CSIRT Advisory – PHP Security Updates

PHP Security Consortium has released a security update stating that the following vulnerabilities have been discovered in PHP Ver 7.1.19 & 7.2.7: a) Bug #76174 – openssl extension fails to build with LibreSSL 2.7. b) Bug #76296 – openssl_pkey_get_public does not respect open_basedir. c) Bug #76333 – PHP built-in server does not find files if […]

TTCSIRT-135.062618: TT-CSIRT Advisory – Microsoft Security Updates

Microsoft has released a security update stating that the following vulnerabilities have been discovered within the Oracle Outside In Technology Module being utilized by Microsoft Exchange Server: a) A remote user can exploit a flaw in the Oracle Outside In Technology Outside In Filters component to access data and cause partial denial of service conditions […]

TTCSIRT-134.062018: TT-CSIRT Advisory – macOS Security Updates

Apple has released a security update stating that a vulnerability has been discovered in Xcode for macOS High Sierra where an attacker can bypass security restrictions. This is due to multiple issues existing in versions of git prior to 2.15.2. Further information on this vulnerability and how it can be mitigated can be found at […]