2023年9月6日星期三

ASUS 路由器多個漏洞

發佈日期: 2023年09月06日

風險: 中度風險

類型: 操作系統 - Network

類型: Network

在 ASUS 路由器發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發遠端執行任意程式碼及阻斷服務狀況。

 

影響

  • 阻斷服務
  • 遠端執行程式碼

受影響之系統或技術

  • RT-AX55: 3.0.0.4.386_50460
  • RT-AX56U_V2: 3.0.0.4.386_50460
  • RT-AC86U: 3.0.0.4_386_51529

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝供應商提供的修補程式:

 

  • RT-AX55: 更新至 3.0.0.4.386_51948或之後版本
  • RT-AX56U_V2: 更新至 3.0.0.4.386_51948或之後版本
  • RT-AC86U: 更新至 3.0.0.4.386_51915或之後版本

漏洞識別碼


資料來源


相關連結

ASUS Router Multiple Vulnerabilities

Release Date: 6 Sep 2023

RISK: Medium Risk

TYPE: Operating Systems - Networks OS

TYPE: Networks OS

Multiple vulnerabilities were identified in ASUS Router. A remote attacker could exploit some of these vulnerabilities to trigger remote code execution and denial of service condition on the targeted system.


Impact

  • Denial of Service
  • Remote Code Execution

System / Technologies affected

  • RT-AX55: 3.0.0.4.386_50460
  • RT-AX56U_V2: 3.0.0.4.386_50460
  • RT-AC86U: 3.0.0.4_386_51529

Solutions

Before installation of the software, please visit the vendor web-site for more details.

Apply fixes issued by the vendor:

 

  • RT-AX55: Update to version 3.0.0.4.386_51948 or later
  • RT-AX56U_V2: Update to version 3.0.0.4.386_51948 or later
  • RT-AC86U: Update to version 3.0.0.4.386_51915 or later

Vulnerability Identifier


Source


Related Link

Google Chrome 多個漏洞

發佈日期: 2023年09月06日

風險: 中度風險

類型: 用戶端 - 瀏覽器

類型: 瀏覽器

於 Google Chrome 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發繞過保安限制、資料篡改、遠端執行任意程式碼及阻斷服務狀況。

 

影響

  • 遠端執行程式碼
  • 阻斷服務
  • 篡改
  • 繞過保安限制

受影響之系統或技術

  • Google Chrome 116.0.5845.179 (Linux) 之前的版本
  • Google Chrome 116.0.5845.179 (Mac) 之前的版本
  • Google Chrome 116.0.5845.179/.180 (Windows) 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝軟件供應商提供的修補程式:

  • 更新至 116.0.5845.179 (Linux) 或之後版本
  • 更新至 116.0.5845.179 (Mac) 或之後版本
  • 更新至 116.0.5845.179/.180 (Windows) 或之後版本

漏洞識別碼


資料來源


相關連結

Google Chrome Multiple Vulnerabilities

Release Date: 6 Sep 2023

RISK: Medium Risk

TYPE: Clients - Browsers

TYPE: Browsers

Multiple vulnerabilities were identified in Google Chrome.  A remote attacker could exploit some of these vulnerabilities to trigger security restriction bypass, data manipulation, remote code execution and denial of service condition on the targeted system.


Impact

  • Remote Code Execution
  • Denial of Service
  • Data Manipulation
  • Security Restriction Bypass

System / Technologies affected

  • Google Chrome prior to 116.0.5845.179 (Linux)
  • Google Chrome prior to 116.0.5845.179 (Mac)
  • Google Chrome prior to 116.0.5845.179/.180 (Windows)

Solutions

Before installation of the software, please visit the software vendor web-site for more details.

Apply fixes issued by the vendor:

  • Update to version 116.0.5845.179 (Linux) or later
  • Update to version 116.0.5845.179 (Mac) or later
  • Update to version 116.0.5845.179/.180 (Windows) or later

Vulnerability Identifier


Source


Related Link

2023年9月5日星期二

Ubuntu Linux 核心多個漏洞

發佈日期: 2023年09月05日

風險: 中度風險

類型: 操作系統 - LINUX

類型: LINUX

於 Ubuntu 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、遠端執行任意程式碼及敏感資料洩露。

 

影響

  • 阻斷服務
  • 遠端執行程式碼
  • 資料洩露

受影響之系統或技術

  • Ubuntu 16.04 ESM
  • Ubuntu 18.04 ESM
  • Ubuntu 20.04 LTS
  • Ubuntu 22.04 LTS
  • Ubuntu 23.04
 

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

Ubuntu Linux Kernel Multiple Vulnerabilities

Release Date: 5 Sep 2023

RISK: Medium Risk

TYPE: Operating Systems - Linux

TYPE: Linux

Multiple vulnerabilities were identified in Ubuntu Products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, remote code execution and sensitive information disclosure on the targeted system.


Impact

  • Denial of Service
  • Remote Code Execution
  • Information Disclosure

System / Technologies affected

  • Ubuntu 16.04 ESM
  • Ubuntu 18.04 ESM
  • Ubuntu 20.04 LTS
  • Ubuntu 22.04 LTS
  • Ubuntu 23.04
 

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

Microsoft Edge 遠端執行程式碼漏洞

發佈日期: 2023年09月04日

風險: 中度風險

類型: 用戶端 - 瀏覽器

類型: 瀏覽器

於 Microsoft Edge 發現一個漏洞。遠端攻擊者可利用這個漏洞,於目標系統觸發遠端執行任意程式碼。

 

影響

  • 遠端執行程式碼

受影響之系統或技術

  • Microsoft Edge 116.0.1938.69 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝軟件供應商提供的修補程式:

  • 更新至 116.0.1938.69 或之後版本

漏洞識別碼


資料來源


相關連結

Microsoft Edge Remote Code Execution Vulnerability

Release Date: 4 Sep 2023

RISK: Medium Risk

TYPE: Clients - Browsers

TYPE: Browsers

A vulnerability was identified in Microsoft Edge.  A remote attacker could exploit this vulnerability to trigger remote code execution on the targeted system.


Impact

  • Remote Code Execution

System / Technologies affected

  • Microsoft Edge prior to 116.0.1938.69

Solutions

Before installation of the software, please visit the software vendor web-site for more details.

Apply fixes issued by the vendor:

  • Update to version 116.0.1938.69 or later

Vulnerability Identifier


Source


Related Link

Splunk 產品多個漏洞

發佈日期: 2023年09月04日

風險: 中度風險

類型: 伺服器 - 其他伺服器

類型: 其他伺服器

於 Splunk 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發遠端執行任意程式碼、權限提升、阻斷服務及跨網站指令碼。

 

Splunk Products Multiple Vulnerabilities

Release Date: 4 Sep 2023

RISK: Medium Risk

TYPE: Servers - Other Servers

TYPE: Other Servers

Multiple vulnerabilities were identified in Splunk Products. A remote attacker could exploit some of these vulnerabilities to trigger remote code execution, elevation of privilege, denial of service and cross-site scripting on the targeted system.


2023年8月31日星期四

Juniper Junos OS 阻斷服務漏洞

發佈日期: 2023年08月31日

風險: 中度風險

類型: 操作系統 - Network

類型: Network

於 Juniper Junos OS 發現一個漏洞。遠端攻擊者可利用這個漏洞,於目標系統觸發阻斷服務狀況。


影響

  • 阻斷服務

受影響之系統或技術

Juniper Networks Junos OS

  • 23.4R1 之前的版本

Juniper Networks Junos OS Evolved

  • 23.4R1-EVO 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

F5 BIG-IP 遠端執行程式碼漏洞

F5 BIG-IP 遠端執行程式碼漏洞 發佈日期 : 2026 年 09 月 23 日 於 F5 BIG-IP 發現一個漏洞。遠端攻擊者可利用這漏洞,於目標系統觸發遠端執行程式碼狀況。   注意: CVE-2026-94127 正被廣泛利用。此漏洞僅在 B...