Telekom Security Updates
-
Apple's macOS Quick Look Vulnerability - Buffer Overflow
A vulnerability has been identified in Apple’s Quick Look feature that affects Apple’s macOS. The vulnerability, classified as a classic buffer overflow, was addressed with improved bounds checking.
Continue Reading -
Critical remote denial of service vulnerability in matrixssl TLSv1.3 server pre-shared-key parsing
A new critical DoS vulnerability (CVE-2023-24609) was discovered in the matrixssl library (versions 4.6.0-4.0.0, github.com/matrixssl/matrixssl) by Security Evaluators of Telekom Security with modern fuzzing methods.View the full advisory
Continue Reading -
Wire Secure Messenger Remote Format String Vulnerability
A Format String vulnerability (CVE-2023-48221) in the Wire AVS library used in Wire Secure Messenger allows an attacker to cause a denial of service (application crash) or possibly execute arbitrary code via voice or video call. This aff...
Continue Reading -
Shining some light on the DarkGate loader
Analysis and Report by Fabian Marquardt (@marqufabi)Recently, Telekom Security CTI was made aware via trust groups in which we are engaged about a new malware campaign that is distributed via phishing emails. The malspam campaign used st...
Continue Reading -
LibreOffice Calc Formula Parsing Vulnerability
A vulnerability in LibreOffice (CVE-2023-0950) allows to trigger an array index underflow that could be exploited by an attacker to execute arbitrary code. To trigger the vulnerability, a victim only needs to open a specially crafted Spr...
Continue Reading -
Mozilla Maintenance Service Write-lock bypass Vulnerability
A vulnerability in the Mozilla Maintenance Service (CVE-2023-29532) allows a local attacker to trick the Mozilla Maintenance Service into applying an unsigned update file by pointing the service to an update file on a malicious SMB serve...
Continue Reading -
USD: One File Format, Many Vulnerabilities
This post covers my project of identifying a series of vulnerabilities (CVE-2020-9878, CVE-2020-9880, CVE-2020-9881, CVE-2020-9882, CVE-2020-9940, CVE-2020-9985) in the processing of USD (Universal Scene Description) files within Apple’s...
Continue Reading -
Critical remote buffer overflow vulnerability in matrixssl TLSv1.3 server message processing
A new critical remote buffer overflow vulnerability (CVE-2022-43974) was discovered in the matrixssl library (versions 4.5.1- 4.0.0, https://github.com/matrixssl/matrixssl) by Security Evaluators of Telekom Security with modern fuzzing m...
Continue Reading