TTCSIRT-104.032718: TT-CSIRT Advisory – XenServer Security Updates

TTCSIRT-104.032718: TT-CSIRT Advisory – XenServer Security Updates

Citrix has released a security update stating that a number of vulnerabilities have been identified within Citrix XenServer that could, if exploited, allow a malicious administrator of a guest VM to crash the host and for some XenServer versions, allow a remote attacker to compromise the host. Details of the vulnerabilities are as follows: a)CVE-2016-2074: […]

TTCSIRT-103.032718: TT-CSIRT Advisory – FireFox Security Updates

Mozilla has released a security update stating that multiple vulnerabilities have been discovered in Mozilla Firefox and Firefox Extended Support Release (ESR) which could allow for remote code execution. Details of the vulnerabilities are as follows: a) A remote code-execution vulnerability exists because it fails to properly process Vorbis audio data. Specifically, this issue occurs […]

TTCSIRT-102.031618: TT-CSIRT Advisory – VMware Security Updates

VMware has released a security update stating that VMware Workstation and Fusion contain a denial-of-service vulnerability which can be triggered by opening a large number of VNC sessions. In order for the exploitation to take place a VNC must be manually enabled. Further information on this vulnerability and how it can be mitigated can be […]

TTCSIRT-101.031618: TT-CSIRT Advisory – Adobe Security Updates

Adobe has released a security update stating that a vulnerability has been discovered in Adobe Dreamweaver where an OS Command Injection could be inserted into the URI Handler of the application. This could allow the attacker to perform arbitrary remote code execution. Further information on this vulnerability and how it can be fixed can be […]

TTCSIRT-099.031418: TT-CSIRT Advisory – FireFox Security Updates

Mozilla has released a security update stating that the following vulnerabilities have been fixed for FireFox Browser ver 59.0: a) Buffer overflow manipulating SVG animatedPathSegList – CVE-2018-5127 b) Use-after-free manipulating editor selection ranges – CVE-2018-5128 c) Out-of-bounds write with malformed IPC messages – CVE-2018-5129 d) Mismatched RTP payload type can trigger memory corruption – CVE-2018-5130 […]

TTCSIRT-097.031218: TT-CSIRT Advisory – Chrome Security Updates

Google has reported that the following vulnerabilities have been discovered in Google Chrome: a) Use after free in Flash – (CVE-2018-6058, CVE-2018-6059) b) Incorrect permissions on shared memory – (CVE-2018-6057, CVE-2018-6063) c) Use after free in Blink – (CVE-2018-6060) d) Race condition in V8 – (CVE-2018-6061) e) Heap buffer overflow in Skia – (CVE-2018-6062) f) […]

TTCSIRT-096.030718: TT-CSIRT Advisory – Android Security Updates

Google has reported that multiple vulnerabilities have been discovered in Google Android OS, the most severe of which could allow for arbitrary code execution within the context of a privileged process. Details of these vulnerabilities are as follows: a) Multiple elevation of privilege vulnerabilities in Kernel components – (CVE-2017-16525, CVE-2017-16530) b) Multiple information disclosure vulnerabilities […]

TTCSIRT-095.030718: TT-CSIRT Advisory – Linux Security Updates

Red Hat has released a security update stating that it is aware of DDoS (Distributed Denial of Service) amplification attacks being performed by exploiting memcached servers exposed to the public Internet. These attacks take advantage of memcached communication using the UDP protocol for transport. The attack is effective because of the high amplification ratio – […]