Author Archives: CIRT Team



CIRT Team

in Security Advisories & Alerts

Cisco IOS and IOS XE Software Multiple Denial of Service Vulnerabilities

Description: These vulnerabilities are due to improper parsing of crafted EnergyWise packets destined to an affected device. An attacker could exploit these vulnerabilities by sending crafted EnergyWise packets to be processed by an affected device. An exploit could allow the attacker to cause a buffer overflow condition or a reload of the affected device, leading to a DoS condition. Related CVE ID(s): CVE-2017-3860, CVE-2017-3861, CVE-2017-3862,...

Read More

0
23 Apr 2017
in Security Advisories & Alerts

Microsoft Windows Graphics CVE-2017-0005 Local Privilege Escalation Vulnerability

Description: The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows local users to gain privileges via a crafted application, aka “Windows GDI Elevation of Privilege Vulnerability.” This vulnerability is different from those described in CVE-2017-0001,...

Read More

0
12 Apr 2017
in Security Advisories & Alerts

Microsoft Internet Explorer CVE-2017-0149 Remote Memory Corruption Vulnerability

Description: Microsoft Internet Explorer 9 through 11 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka “Internet Explorer Memory Corruption Vulnerability.” This vulnerability is different from those described in CVE-2017-0018 and CVE-2017-0037. Internet Explorer 9, 10 and 11 are vulnerable. Impact: Attackers can exploit this issue to execute arbitrary code in the context...

Read More

0
12 Apr 2017
in Security Advisories & Alerts

Microsoft Office RTF documents that leverage CVE-2017-0199 vulnerability

Description: This vulnerability allows a malicious actor to download and execute a Visual Basic script containing PowerShell commands when a user opens a document containing an embedded exploit. The vulnerability affects Microsoft Office, including the latest Office 2016 edition running on Windows 10. Impact: Researchers has observed Office documents exploiting CVE-2017-0199 that download and execute malware payloads from different well-known malware families. Mitigation: Updates are...

Read More

0
12 Apr 2017
MoU between the Indian Computer Emergency Response Team (CERT-In) and BGD e-GOV CIRT
in Articles, English articles, News

MoU between the Indian Computer Emergency Response Team (CERT-In) and BGD e-GOV CIRT

At the end of a bilateral meeting between Sheikh Hasina, Prime Minister of Bangladesh and Narendra Modi, Prime Minister of India; 22 agreements and memorandum of understanding (Mou) have been signed at Hayadrarabad house in New Delhi between India and Bangladesh. After the meeting; defense, financial, information technology, power and energy related agreements and MoU was signed by the two countries officials. To enhance cooperation in...

Read More

0
09 Apr 2017
in Security Advisories & Alerts

Cisco Wireless LAN Controller IPv6 UDP Denial of Service Vulnerability: CVE-2016-9219

Description: The vulnerability is due to incomplete IPv6 UDP header validation. An attacker could exploit this vulnerability by sending a crafted IPv6 UDP packet to a specific port on the targeted device. An exploit could allow the attacker to impact the availability of the device as it could unexpectedly reload. Impact:  Attackers can exploit this issue to cause denial-of-service conditions. Mitigation: Cisco has released software...

Read More

0
06 Apr 2017
in Security Advisories & Alerts

Cisco Aironet 1830 Series and 1850 Series Access Points Mobility Express Default Credential Vulnerability: CVE-2017-3834

Description: The vulnerability is due to the existence of default credentials for an affected device that is running Cisco Mobility Express Software, regardless of whether the device is configured as a master, subordinate, or standalone access point. An attacker who has layer 3 connectivity to an affected device could use Secure Shell (SSH) to log in to the device with elevated privileges. A successful exploit...

Read More

0
06 Apr 2017
in Security Advisories & Alerts

Cisco Wireless LAN Controller Management GUI Denial of Service Vulnerability: CVE-2017-3832

Description: The vulnerability is due to a missing internal handler for the specific request. An attacker could exploit this vulnerability by accessing a specific hidden URL on the web management interface. A successful exploit could allow the attacker to cause a reload of the device, resulting in a DoS condition. Impact: Attackers can exploit this issue to reload the affected device, denying service to legitimate...

Read More

0
06 Apr 2017
in Security Advisories & Alerts

Linux Kernel CVE-2017-7184 Local Privilege Escalation Vulnerability

Description: The xfrm_replay_verify_len function in net/xfrm/xfrm_user.c in the Linux kernel through 4.10.6 does not validate certain size data after an XFRM_MSG_NEWAE update, which allows local users to obtain root privileges or cause a denial of service (heap-based out-of-bounds access) by leveraging the CAP_NET_ADMIN capability, as demonstrated during a Pwn2Own competition at CanSecWest 2017 for the Ubuntu 16.10 linux-image-* package 4.8.0.41.52. Impact: Local attackers may exploit...

Read More

0
06 Apr 2017
in Uncategorized

DECLARATION 2017 ON STRENGTHENING CYBERSECURITY

ENDORSED AT THE INTERNATIONAL CYBERSECURITY CONFERENCE HELD ON 9 MARCH 2017  The participants of the International cybersecurity conference meeting at Bangladesh Computer Council in Dhaka, Bangladesh, on 9 March 2017, REAFFIRMING the commitments set out in the ‘Vision 2021’ to build Digital Bangladesh and transform Bangladesh into a fast developing Middle Income Country by 2021 and to mainstream ICTs as a pro-poor tool to eradicate...

Read More

0
05 Apr 2017
Page 131 of 134« First...102030...129130131132133...Last »