4.9 • 696 Ratings
🗓️ 5 January 2024
⏱️ 5 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello and welcome to the Friday, January 5th, 2020, |
0:04.5 | for edition of the Sands and its Storm Center's Stormcast, |
0:08.3 | my name is Johannes Ulrich, |
0:09.8 | and today I'm recording from Jacksonville, Florida. |
0:13.2 | Today's episode is a little bit heavy on patches, |
0:16.6 | starting with patches for Wyrshark. |
0:20.2 | Wireshark released updates for all three currently |
0:23.3 | supported versions. These updates fix a number of security vulnerabilities. All of these security |
0:30.3 | vulnerabilities are classified as a denial of service. If your Wireshark instance is parsing a grafted packet, it may crash. Of course, |
0:41.4 | there's always a small chance that some of them could potentially be used for code execution, |
0:47.9 | but none of the advisories for these vulnerabilities indicate that. And Google released updates for Android as well as Chrome. |
0:59.0 | Nothing really sort of out of the ordinary here. |
1:01.0 | The Android patches fix about 50 different vulnerabilities. |
1:05.0 | The only critical vulnerabilities are in close source Qualcomm components components. And actually, the majority of the |
1:13.8 | vulnerabilities are in these Qualcomm closed-source components, also some open-source components |
1:21.6 | that are interacting with Qualcomm chips. And the Google Chrome update does not fix any serenadeys, so nothing really too much to worry about. |
1:32.8 | Just make sure that the auto update works. |
1:36.2 | So once they keep reminding yourself to restart Google Chrome or any other browser you're using. |
1:44.9 | Not quite as widely used as Chrome or Android, but nevertheless important and |
1:51.5 | frequently exploited in the past is Ivanti's EPM, their endpoint management software. |
1:59.4 | Yvanti released an update, update 5 for version 22, that fixes a single vulnerability, |
2:06.7 | CVE 2020339366. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.