Government of the Republic of Trinidad and Tobago
gov.tt

Securing the Nation's Digital Infrastructure

TTCSIRT-131.061418: TT-CSIRT Advisory – VMware Security Updates

VMware has released a security update stating that VMware AirWatch Agent for Android and Windows Mobile devices contain a remote code execution vulnerability in real time File Manager capabilities. This may allow for unauthorized creation and execution of files in the Agent sandbox and other publicly accessible directories such as those on the SD card …

TTCSIRT-130.061218: TT-CSIRT Advisory – Cisco Security Updates

Cisco has released a security update stating that a vulnerability has been discovered in Cisco Adaptive Security Appliance (ASA) which could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This is due to lack of proper input validation of the HTTP URL. …

TTCSIRT-129.061218: TT-CSIRT Advisory – Android Security Updates

Google has released a security update stating that the following vulnerabilities have been discovered in the Android OS: a) Multiple information disclosure vulnerabilities in Framework – (CVE-2017-13227, CVE-2018-9340). b) Multiple elevation of privilege vulnerabilities in Framework – (CVE-2018-9338, CVE-2018-9339). c) Multiple elevation of privilege vulnerabilities in Kernel components – (CVE-2017-17558, CVE-2017-17806, CVE-2017-17807, CVE-2018-9363). d) An …

TTCSIRT-128.060818: TT-CSIRT Advisory – Mozilla Security Updates

Mozilla has released a security update stating that a vulnerability in the Mozilla Firefox Browser exists where a heap buffer overflow can occur in the Skia library when rasterizing paths using a maliciously crafted SVG file. This results in a potentially exploitable crash and a remote attacker could exploit these vulnerabilities to take control of …

TTCSIRT-127.060818: TT-CSIRT Advisory – Adobe Security Updates

Adobe has released a security update stating that Adobe Flash Player is prone to the following vulnerabilities: a) A stack-based buffer overflow that could allow for arbitrary code execution – (CVE-2018-5002). b) A type confusion that could allow for arbitrary code execution – (CVE-2018-4945). c) An integer overflow that could lead to information disclosure – …

TTCSIRT-126.060418: TT-CSIRT Advisory – Chrome Security Updates

Google has released a security state stating that the following vulnerabilities have been discovered in Google Chrome: a) Heap buffer overflow in Skia – (CVE-2018-6141, CVE-2018-6126) b) Incorrect escaping of MathML in Blink – (CVE-2018-6145) c) Incorrect mutability protection in WebAssembly – (CVE-2018-6131) d) Leak of visited status of page in Blink – (CVE-2018-6137) e) …

TTCSIRT-125.060418: TT-CSIRT Advisory – Apple Security Updates

Apple has released a security update stating that it has discovered the following vulnerabilities in the macOS High Sierra 10.13.5: a) Accessibility Framework – a malicious application may be able to execute arbitrary code with system privileges (CVE-2018-4196). b) AMD – a local user may be able to read kernel memory (CVE-2018-4253). c) Bluetooth – …

TTCSIRT-124.052518: TT-CSIRT Advisory – Malware Security Updates

Talos has reported that a sophisticated modular malware system known as VPNFilter has a destructive capability that can make the affected device unusable. Devices known to be affected by VPNFilter include Linksys, MikroTik, NETGEAR, and TP-Link networking equipment as well as QNAP network-attached storage (NAS) devices. In addition, compromised devices may be vulnerable to the …

TTCSIRT-123.052518: TT-CSIRT Advisory – Cisco Security Updates

Cisco has released a security update stating that a vulnerability in Cisco Digital Network Architecture (DNA) Center which could allow an unauthenticated, remote attacker to log in to an affected system by using an administrative account that has default, static user credentials.This is due to the presence of undocumented, static user credentials for the default …

TTCSIRT-122.052118: TT-CSIRT Advisory – Thunderbird Security Updates

Mozilla has released a security update stating that multiple vulnerabilities have been identified in Mozilla Thunderbird: a) Multiple memory corruption vulnerabilities which could result in arbitrary code execution – (CVE-2018-5150). b) A use-after-free vulnerability can occur while enumerating attributes during SVG animations with clip paths. This results in a potentially exploitable crash – (CVE-2018-5154). c) …