

Rewterz Threat Advisory – CVE-2019-1845 – Cisco Unified Communications Manager IM&P Service, Cisco TelePresence VCS, and Cisco Expressway Series Denial of Service Vulnerability
June 26, 2019
Rewterz Threat Alert – Echobot Botnet Acquiring Unauthorized System Access
June 26, 2019
Rewterz Threat Advisory – CVE-2019-1845 – Cisco Unified Communications Manager IM&P Service, Cisco TelePresence VCS, and Cisco Expressway Series Denial of Service Vulnerability
June 26, 2019
Rewterz Threat Alert – Echobot Botnet Acquiring Unauthorized System Access
June 26, 2019Severity
High
Analysis Summary
CVE-2019-11708
Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process opening web content chosen by a compromised child process. When combined with
additional vulnerabilities this could result in executing arbitrary code on the user’s computer.
CVE-2019-11707
A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for
an exploitable crash.
Impact
- System access
- Security Bypass
Affected Vendors
RedHat
Affected Products
- Red Hat Enterprise Linux Desktop 6
- Red Hat Enterprise Linux HPC Node 6
- Red Hat Enterprise Linux Server 6
- Red Hat Enterprise Linux Workstation 6
Remediation
CVE-2019-11707 Mozilla: BZ – 1721789
CVE-2019-11708 Mozilla: BZ – 1722673