Telekom Security Updates
-
Critical remote denial of service vulnerability in matrixssl TLSv1.3 server pre-shared-key parsing
A new critical DoS vulnerability (CVE-2023-24609) was discovered in the matrixssl library (versions 4.6.0-4.0.0, github.com/matrixssl/matrixssl) by Security Evaluators of Telekom Security with modern fuzzing methods.View the full advisory
Continue Reading -
Wire Secure Messenger Remote Format String Vulnerability
A Format String vulnerability (CVE-2023-48221) in the Wire AVS library used in Wire Secure Messenger allows an attacker to cause a denial of service (application crash) or possibly execute arbitrary code via voice or video call. This aff...
Continue Reading -
Shining some light on the DarkGate loader
Analysis and Report by Fabian Marquardt (@marqufabi)Recently, Telekom Security CTI was made aware via trust groups in which we are engaged about a new malware campaign that is distributed via phishing emails. The malspam campaign used st...
Continue Reading -
LibreOffice Calc Formula Parsing Vulnerability
A vulnerability in LibreOffice (CVE-2023-0950) allows to trigger an array index underflow that could be exploited by an attacker to execute arbitrary code. To trigger the vulnerability, a victim only needs to open a specially crafted Spr...
Continue Reading -
Mozilla Maintenance Service Write-lock bypass Vulnerability
A vulnerability in the Mozilla Maintenance Service (CVE-2023-29532) allows a local attacker to trick the Mozilla Maintenance Service into applying an unsigned update file by pointing the service to an update file on a malicious SMB serve...
Continue Reading -
USD: One File Format, Many Vulnerabilities
This post covers my project of identifying a series of vulnerabilities (CVE-2020-9878, CVE-2020-9880, CVE-2020-9881, CVE-2020-9882, CVE-2020-9940, CVE-2020-9985) in the processing of USD (Universal Scene Description) files within Appleās...
Continue Reading -
Critical remote buffer overflow vulnerability in matrixssl TLSv1.3 server message processing
A new critical remote buffer overflow vulnerability (CVE-2022-43974) was discovered in the matrixssl library (versions 4.5.1- 4.0.0, https://github.com/matrixssl/matrixssl) by Security Evaluators of Telekom Security with modern fuzzing m...
Continue Reading -
Apple's iOS & macOS Contacts Vulnerability - Privacy Preferences Bypass
A vulnerability has been identified in iOS/iPadOS < 15.7 / < 16.0 and macOS Big Sur < 11.7 that allows an app to bypass Privacy preferences, posing a significant risk. The vulnerability, classified as Improper Input Validation a...
Continue Reading