Government of the Republic of Trinidad and Tobago

Securing the Nation's Digital Infrastructure

TTCSIRT-028.073117: TT-CSIRT Advisory – McAfee Security Updates

McAfee has released a security bulletin to address multiple vulnerabilities in Web Gateway: a) CVE-2012-6706 – a VMSF_DELTA memory corruption was discovered in unrar before 5.5.5, as used in Sophos Anti-Virus Threat Detection Engine before 3.37.2 and other products, that can lead to arbitrary code execution. b) CVE-2017-1000364 – an issue was discovered in the …

TTCSIRT-027.072717: TT-CSIRT Advisory – Chrome Security Updates

Google has released Chrome version 60.0.3112.78 for Windows, Mac, and Linux. This version addresses multiple vulnerabilities that, if exploited, may allow an attacker to take control of an affected system. Further information on these vulnerabilities can be seen on the Google Chrome Website at

TTCSIRT-026.072717: TT-CSIRT Advisory – Joomla Security Updates

Joomla has released version 3.7.4 of its Content Management System software to address several security vulnerabilities in its previous versions: a) Lack of Ownership Verification affecting Joomla! 1.0.0 through Joomla 3.7.3 b) XSS Vulnerability affecting Joomla! 1.5.0 through Joomla! 3.7.3 For further information on this security update, view the Joomla Website at

TTCSIRT-025.072517: TT-CSIRT Advisory – IBM Security Updates

IBM has issued a high severity security alert stating that the IBM Cisco MDS Series Switches have a vulnerability that could allow an unauthenticated, remote attacker to log in to the administrative console of a DCNM server by using an account that has a default, static password. The account could be granted root or system-level …

TTCSIRT-024.072017: TT-CSIRT Advisory – Apple Security Updates

Apple has released security updates to address vulnerabilities in many of its products including iTunes, iCloud & the tvOS. TTCSIRT encourages users and administrators to review Apple security pages for the following products and apply the necessary updates: tvOS iTunes for Windows iCloud for Windows Safari macOS Sierra, Security Updates iOS watchOS

TTCSIRT-023.072017: TT-CSIRT Advisory – Oracle Security Updates

Oracle has released its Critical Patch Update for July 2017 to address 308 vulnerabilities across multiple products. Exploitation of some of these vulnerabilities may allow a remote attacker to take control of an affected system. Users and administrators are encouraged to review the Oracle July 2017 Critical Patch Update at

TTCSIRT-022.071717: TT-CSIRT Advisory – CISCO Security Updates

The Simple Network Management Protocol subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. An attacker could exploit these vulnerabilities by sending a crafted SNMP packet to an affected system via …

TTCSIRT-021.071717: TT-CSIRT Advisory – Juniper Security Updates

A security researcher testing a Juniper NetScreen Firewall + VPN found multiple stored cross-site scripting vulnerabilities that could be used to elevate privileges through the NetScreen WebUI. A user with the ‘security’ role can inject HTML/JavaScript content into the management session of other users including the administrator. This enables the lower-privileged user to effectively execute …

TTCSIRT-020.071717: TT-CSIRT Advisory – Samba Security Updates

The Samba Team has reported a critical vulnerability in all versions of Samba from 4.0.0 onward using embedded Heimdal Kerberos. A Man-In-The-Middle Attacker may impersonate a trusted server and thus gain elevated access to the domain by returning malicious replication or authorization data. A patch addressing this defect has been posted to while Samba …

TTCSIRT-019.070617: TT-CSIRT Advisory – CISCO Security Updates

Cisco has released updates to address vulnerabilities affecting multiple products. A remote attacker could exploit one of these vulnerabilities to take control of a system. Users and administrators are encouraged to review the following Cisco Security Advisories and apply the necessary updates: a) Elastic Services Controller Unauthorized Access Vulnerability – cisco-sa-20170705-esc2 b) Ultra Services Framework …