Author Archives: CIRT Team



CIRT Team

in Security Advisories & Alerts

Wireshark ‘dissectors/asn1/ros/packet-ros-template.c’ Denial of Service Vulnerability

Description: In Wireshark 2.2.0 to 2.2.6, the ROS dissector could crash with a NULL pointer dereference. This was addressed in epan/dissectors/asn1/ros/packet-ros-template.c by validating an OID. Impact: Attackers can exploit this issue to crash the affected application, resulting in denial-of-service conditions. Mitigation: Upgrade to Wireshark 2.2.7 or later. Reference URL’s: http://www.securityfocus.com/bid/98800/info http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9347 https://www.wireshark.org/security/wnpa-sec-2017-31.html

0
05 Jun 2017
in Security Advisories & Alerts

Mozilla Network Security Services CVE-2017-5461 Memory Corruption Vulnerability

Description: Mozilla Network Security Services (NSS) before 3.21.4, 3.22.x through 3.28.x before 3.28.4, 3.29.x before 3.29.5, and 3.30.x before 3.30.1 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact by leveraging incorrect base64 operations. Impact: An attacker can exploit this issue to execute arbitrary code in the context of the user running the affected application. Failed exploit...

Read More

0
05 Jun 2017
in Security Advisories & Alerts

Multiple Asterisk Products Denial of Service Vulnerability: CVE-2017-9359

Description: The multi-part body parser in PJSIP, as used in Asterisk Open Source 13.x before 13.15.1 and 14.x before 14.4.1, Certified Asterisk 13.13 before 13.13-cert4, and other products, allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted packet. Impact: Attackers can exploit this issue to crash the affected application, resulting in a denial-of-service condition. Mitigation: Updates are...

Read More

0
05 Jun 2017
Page 123 of 134« First...102030...121122123124125...130...Last »