2024年6月11日星期二

Ubuntu Linux 核心多個漏洞

發佈日期: 2024年06月11日

風險: 中度風險

類型: 操作系統 - LINUX

於 Ubuntu Linux核心發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況及遠端執行任意程式碼。


影響

  • 阻斷服務
  • 遠端執行程式碼

受影響之系統或技術

  • Ubuntu 24.04 LTS

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

Ubuntu Linux Kernel Multiple Vulnerabilities

Release Date: 11 Jun 2024

RISK: Medium Risk

TYPE: Operating Systems - Linux

Multiple vulnerabilities were identified in Ubuntu Linux Kernel. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition and remote code execution on the targeted system.


Impact

  • Denial of Service
  • Remote Code Execution

System / Technologies affected

  • Ubuntu 24.04 LTS

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

PHP 多個漏洞

發佈日期: 2024年06月11日

風險: 極高度風險

類型: 伺服器 - 互聯網應用伺服器

於 PHP 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發遠端執行任意程式碼及繞過保安限制。

 

注意:

CVE-2024-4577 已被廣泛利用。此漏洞允許未經身份驗證的攻擊者在PHP-CGI中進行參數注入。

此漏洞影響 Windows 作業系統上安裝的所有 PHP 版本。請注意,PHP 8.0、PHP 7 和 PHP 5 版本產品生命周期已結束,沒有適用於 PHP 8.0、PHP 7 和 PHP 5 的修補程式。預設設置下,安裝在 Windows 上的所有 XAMPP 版本都受此漏洞影響。


影響

  • 遠端執行程式碼
  • 繞過保安限制

受影響之系統或技術

  • PHP 8.3.8 之前的版本
  • PHP 8.2.20 之前的版本
  • PHP 8.1.29 之前的版本

請注意,PHP 8.0、PHP 7 和 PHP 5 版本產品生命周期已結束,沒有適用於 PHP 8.0、PHP 7 和 PHP 5 的修補程式。


解決方案

在安裝軟體之前,請先瀏覽軟體供應商之網站,以獲得更多詳細資料。

 

供應商已提供修補程式:

  • PHP 8.3.8
  • PHP 8.2.20
  • PHP 8.1.29

漏洞識別碼


資料來源


相關連結

PHP Multiple Vulnerabilities

Release Date: 11 Jun 2024

RISK: Extremely High Risk

TYPE: Servers - Internet App Servers

Multiple vulnerabilities were identified in PHP. A remote attacker could exploit some of these vulnerabilities to trigger remote code execution and security restriction bypass on the targeted system.

 

Note:

The CVE-2024-4577 vulnerability is being exploited in the wild. This vulnerability allows unauthenticated attackers to conduct argument Injection in PHP-CGI.

This vulnerability affects all versions of PHP installed on the Windows operating system. Please note that the PHP 8.0, PHP 7, and PHP 5 are End-of-Life, No patch is available for PHP 8.0, PHP 7, and PHP 5. All versions of XAMPP installations on Windows are vulnerable by default.


Impact

  • Remote Code Execution
  • Security Restriction Bypass

System / Technologies affected

  • PHP version prior to 8.3.8
  • PHP version prior to 8.2.20
  • PHP version prior to 8.1.29

Please note that the PHP 8.0, PHP 7, and PHP 5 are End-of-Life, No patch is available for PHP 8.0, PHP 7, and PHP 5.


Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

 

The vendor has issued a fix: 

  • PHP 8.3.8
  • PHP 8.2.20
  • PHP 8.1.29

Vulnerability Identifier


Source


Related Link

2024年6月8日星期六

Android多個漏洞

發佈日期: 2024年06月04日

風險: 中度風險

類型: 操作系統 - 流動裝置及操作系統

於 Android 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、權限提升及洩露敏感資料。


影響

  • 阻斷服務
  • 權限提升
  • 資料洩露

受影響之系統或技術

  • 2024-06-05 前的 Android 保安更新級別

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。


漏洞識別碼


資料來源


相關連結

Android Multiple Vulnerabilities

Release Date: 4 Jun 2024

RISK: Medium Risk

TYPE: Operating Systems - Mobile & Apps

Multiple vulnerabilities were identified in Android. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, elevation of privilege and sensitive information disclosure on the targeted system.


Impact

  • Denial of Service
  • Elevation of Privilege
  • Information Disclosure

System / Technologies affected

  • Android security patch level prior to 2024-06-05

Solutions

Before installation of the software, please visit the vendor web-site for more details.


Vulnerability Identifier


Source


Related Link

Microsoft Edge 多個漏洞

發佈日期: 2024年06月04日

風險: 中度風險

類型: 用戶端 - 瀏覽器

於 Microsoft Edge 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、遠端執行任意程式碼及洩露敏感資料。

 

Microsoft Edge Multiple Vulnerabilities

Release Date: 4 Jun 2024

RISK: Medium Risk

TYPE: Clients - Browsers

Multiple vulnerabilities were identified in Microsoft Edge. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, remote code execution and sensitive information disclosure on the targeted system.


Debian Linux 內核多個漏洞

發佈日期: 2024年06月03日

風險: 中度風險

類型: 操作系統 - LINUX

於 Debian Linux 內核發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、權限提升及洩露敏感資料。


Debian Linux Kernel Multiple Vulnerabilities

Release Date: 3 Jun 2024

RISK: Medium Risk

TYPE: Operating Systems - Linux

Multiple vulnerabilities were identified in Debian Linux Kernel. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, elevation of privilege and sensitive information disclosure on the targeted system.


2024年6月1日星期六

F5 BIG-IP 遠端執行程式碼漏洞

F5 BIG-IP 遠端執行程式碼漏洞 發佈日期 : 2026 年 09 月 23 日 於 F5 BIG-IP 發現一個漏洞。遠端攻擊者可利用這漏洞,於目標系統觸發遠端執行程式碼狀況。   注意: CVE-2026-94127 正被廣泛利用。此漏洞僅在 B...