TTCSIRT-090.021618: TT-CSIRT Advisory – Microsoft Security Updates

TTCSIRT-089.021618: TT-CSIRT Advisory – Adobe Security Updates

Adobe has released a security update stating that Multiple vulnerabilities have been discovered in Adobe Acrobat and Reader, the most severe of which could allow for arbitrary code execution. Details are as follows: a) One security mitigation bypass vulnerability that could allow for privilege escalation (CVE-2018-4872) b) Four heap overflow vulnerabilities that could allow for […]

TTCSIRT-088.020818: TT-CSIRT Advisory – Android Security Updates

Multiple vulnerabilities have been discovered in Google Android OS, the most severe of which could allow for remote code execution within the context of a privileged process. Details are as follows: a) Multiple remote code execution vulnerabilities in Media Framework (CVE-2017-13228, CVE-2017-13230) b) An information disclosure vulnerability in Media Framework (CVE-2017-13232) c) An elevation of […]

TTCSIRT-087.020818: TT-CSIRT Advisory – Linux Security Updates

A vulnerability has been discovered in the GNU C Library of all Linux Distributions which could allow for arbitrary code execution. It is caused due to internal memalign() and malloc() functions in glibc failing to properly report allocation errors. This vulnerability can be exploited when the system processes maliciously crafted data. Successful exploitation could result […]

TTCSIRT-086.020518: TT-CSIRT Advisory – Adobe Security Updates

Adobe reports that a vulnerability has been discovered in Adobe Flash Player that could allow for remote code execution. This vulnerability occurs due to a use-after-free error (CVE-2018-4878). Depending on the privileges associated with this application, an attacker could then install programs, view, change, or delete data or create new accounts with full user rights. […]

TTCSIRT-085.020518: TT-CSIRT Advisory – HP Security Updates

HP has reported that a vulnerability has been discovered in HP printers which could allow for arbitrary code execution. Depending on the printer’s placement on the network, an attacker could potentially install programs; view, change, or delete data; or create new accounts with full user rights. HP states that a directory traversal attack could allow […]

TTCSIRT-084.013018: TT-CSIRT Advisory – CISCO Security Updates

Cisco has released a security update stating that a vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause a reload of the affected system or to remotely execute code. The vulnerability is due to an attempt to double free […]

TTCSIRT-082.012418: TT-CSIRT Advisory – KRACK Security Update

WPA2 Key Reinstallation Attacks (KRACKs) Date first published: 23/1/2018   1.0 Introduction TT-CSIRT wishes to advise that weaknesses have been discovered in the Wi-Fi Protected Access 2 (WPA2) protocol used to secure wireless networks. An attacker within range of a victim can exploit these weaknesses using key reinstallation attacks (KRACKs). Attackers can use these exploits […]

TTCSIRT-081.012418: TT-CSIRT Advisory – Apple Security Updates

Apple has released security updates stating that the following vulnerabilities have been discovered in Safari, watchOS, iOS, High Sierra, Sierra, El Capitan, and tvOS: a) A certificate evaluation issue existed in the handling of name constraints – (CVE-2018-4086) b) An application may be able to execute arbitrary code with kernel privileges – (CVE-2018-4097) c) A […]