2022年7月19日星期二

ChromeOS 多個漏洞

發佈日期: 2022年07月19日

風險: 中度風險

類型: 操作系統 - 其他操作系統

類型: 其他操作系統

於 ChromeOS 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況及遠端執行程式碼。


影響

  • 阻斷服務
  • 遠端執行程式碼

受影響之系統或技術

  • LTC (Long Term Support Candidate) channel 102.0.5005.153 版本之前 (平台版本: 14695.114.0)

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

 


漏洞識別碼


資料來源


相關連結

ChromeOS Multiple Vulnerabilities

Release Date: 19 Jul 2022

RISK: Medium Risk

TYPE: Operating Systems - Others OS

TYPE: Others OS

Multiple vulnerabilities were identified in ChromeOS. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition and remote code execution on the targeted system.


Impact

  • Denial of Service
  • Remote Code Execution

System / Technologies affected

  • LTC (Long Term Support Candidate) channel before 102.0.5005.153 (Platform Version: 14695.114.0)

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

 


Vulnerability Identifier


Source


Related Link

2022年7月16日星期六

Juniper Junos OS 多個漏洞

發佈日期: 2022年07月15日

風險: 中度風險

類型: 操作系統 - Network

類型: Network

於 Juniper Junos OS 發現多個漏洞,遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況,資料洩露及遠端執行程式碼。


影響

  • 阻斷服務
  • 資料洩露
  • 遠端執行程式碼

受影響之系統或技術

  • Juniper Junos OS

詳情請參閱以下連結﹕
https://kb.juniper.net/InfoCenter/index?page=content&channel=SECURITY_ADVISORIES


解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 


漏洞識別碼


資料來源


相關連結

Juniper Junos OS Multiple Vulnerabilities

Release Date: 15 Jul 2022

RISK: Medium Risk

TYPE: Operating Systems - Networks OS

TYPE: Networks OS

Multiple vulnerabilities were identified in Juniper Junos OS, a remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, sensitive information disclosure and remote code execution on the targeted system.


Impact

  • Denial of Service
  • Information Disclosure
  • Remote Code Execution

System / Technologies affected

  • Juniper Junos OS

Please refer to the link below for detail:
https://kb.juniper.net/InfoCenter/index?page=content&channel=SECURITY_ADVISORIES


Solutions

Before installation of the software, please visit the vendor web-site for more details.

 


Vulnerability Identifier


Source


Related Link

Linux 核心多個漏洞

發佈日期: 2022年07月15日

風險: 中度風險

類型: 操作系統 - LINUX

類型: LINUX

於 Linux 核心發現多個漏洞。攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、權限提升、洩露敏感資料及遠端執行程式碼。


影響

  • 阻斷服務
  • 權限提升
  • 資料洩露
  • 遠端執行程式碼

受影響之系統或技術

  • openSUSE Leap 15.3
  • SUSE Linux Enterprise Desktop 12-SP5
  • SUSE Linux Enterprise High Availability 12-SP4
  • SUSE Linux Enterprise High Availability 12-SP5
  • SUSE Linux Enterprise High Performance Computing 12-SP4
  • SUSE Linux Enterprise High Performance Computing 12-SP5
  • SUSE Linux Enterprise High Performance Computing 15-SP3
  • SUSE Linux Enterprise Live Patching 12-SP4
  • SUSE Linux Enterprise Live Patching 12-SP5
  • SUSE Linux Enterprise Module for Public Cloud 15-SP3
  • SUSE Linux Enterprise Server 12-SP2-BCL
  • SUSE Linux Enterprise Server 12-SP4
  • SUSE Linux Enterprise Server 12-SP4-LTSS
  • SUSE Linux Enterprise Server 12-SP5
  • SUSE Linux Enterprise Server 15-SP3
  • SUSE Linux Enterprise Server for SAP 12-SP4
  • SUSE Linux Enterprise Server for SAP Applications 12-SP5
  • SUSE Linux Enterprise Server for SAP Applications 15-SP3
  • SUSE Linux Enterprise Software Development Kit 12-SP5
  • SUSE Linux Enterprise Storage 7.1
  • SUSE Linux Enterprise Workstation Extension 12-SP5
  • SUSE Manager Proxy 4.2
  • SUSE Manager Retail Branch Server 4.2
  • SUSE Manager Server 4.2
  • SUSE OpenStack Cloud 9
  • SUSE OpenStack Cloud Crowbar 9
  • Ubuntu 14.04 ESM
  • Ubuntu 16.04 ESM 
  • Ubuntu 18.04 LTS 
  • Ubuntu 20.04 LTS
  • Ubuntu 22.04 LTS

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

對於 SUSE

 

對於 Ubuntu

 


漏洞識別碼


資料來源


相關連結

Linux Kernel Multiple Vulnerabilities

Release Date: 15 Jul 2022

RISK: Medium Risk

TYPE: Operating Systems - Linux

TYPE: Linux

Multiple vulnerabilities were identified in Linux Kernel. A attacker could exploit some of these vulnerabilities to trigger denial of service condition, elevation of privilege, sensitive information disclosure and remote code execution on the targeted system.


Impact

  • Denial of Service
  • Elevation of Privilege
  • Information Disclosure
  • Remote Code Execution

System / Technologies affected

  • openSUSE Leap 15.3
  • SUSE Linux Enterprise Desktop 12-SP5
  • SUSE Linux Enterprise High Availability 12-SP4
  • SUSE Linux Enterprise High Availability 12-SP5
  • SUSE Linux Enterprise High Performance Computing 12-SP4
  • SUSE Linux Enterprise High Performance Computing 12-SP5
  • SUSE Linux Enterprise High Performance Computing 15-SP3
  • SUSE Linux Enterprise Live Patching 12-SP4
  • SUSE Linux Enterprise Live Patching 12-SP5
  • SUSE Linux Enterprise Module for Public Cloud 15-SP3
  • SUSE Linux Enterprise Server 12-SP2-BCL
  • SUSE Linux Enterprise Server 12-SP4
  • SUSE Linux Enterprise Server 12-SP4-LTSS
  • SUSE Linux Enterprise Server 12-SP5
  • SUSE Linux Enterprise Server 15-SP3
  • SUSE Linux Enterprise Server for SAP 12-SP4
  • SUSE Linux Enterprise Server for SAP Applications 12-SP5
  • SUSE Linux Enterprise Server for SAP Applications 15-SP3
  • SUSE Linux Enterprise Software Development Kit 12-SP5
  • SUSE Linux Enterprise Storage 7.1
  • SUSE Linux Enterprise Workstation Extension 12-SP5
  • SUSE Manager Proxy 4.2
  • SUSE Manager Retail Branch Server 4.2
  • SUSE Manager Server 4.2
  • SUSE OpenStack Cloud 9
  • SUSE OpenStack Cloud Crowbar 9
  • Ubuntu 14.04 ESM
  • Ubuntu 16.04 ESM 
  • Ubuntu 18.04 LTS 
  • Ubuntu 20.04 LTS
  • Ubuntu 22.04 LTS

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

For SUSE

 

For Ubuntu

 


Vulnerability Identifier


Source


Related Link

F5 產品阻斷服務漏洞

發佈日期: 2022年07月14日

風險: 中度風險

類型: 操作系統 - Network

類型: Network

於 F5 產品發現一個漏洞,遠端攻擊者可利用這漏洞,於目標系統觸發阻斷服務狀況。

 


影響

  • 阻斷服務

受影響之系統或技術

BIG-IP (all modules)

 

  • 16.1.0 - 16.1.2
  • 15.1.0 - 15.1.5    
  • 14.1.0 - 14.1.4    
  • 13.1.0 - 13.1.4    

BIG-IP SPK

 

  • 1.5.0

BIG-IQ Centralized Management

 

  • 8.0.0-8.1.0
  • 7.0.0-7.1.0

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

F5 Products Denial of Service Vulnerability

Release Date: 14 Jul 2022

RISK: Medium Risk

TYPE: Operating Systems - Networks OS

TYPE: Networks OS

A vulnerability was identified in F5 products. A remote attacker could exploit this vulnerability to trigger denial of service condition on the targeted system.

 


Impact

  • Denial of Service

System / Technologies affected

BIG-IP (all modules)

 

  • 16.1.0 - 16.1.2
  • 15.1.0 - 15.1.5    
  • 14.1.0 - 14.1.4    
  • 13.1.0 - 13.1.4    

BIG-IP SPK

 

  • 1.5.0

BIG-IQ Centralized Management

 

  • 8.0.0-8.1.0
  • 7.0.0-7.1.0

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

2022年7月13日星期三

Adobe 每月保安更新 (2022年7月)

發佈日期: 2022年07月13日

風險: 中度風險

類型: 用戶端 - 辦公室應用

類型: 辦公室應用

Adobe已為產品提供本月保安更新:

 

受影響產品風險程度影響備註詳情(包括 CVE)
RoboHelp中度風險 中度風險跨網站指令碼
遠端執行程式碼
 APSB22-10
Adobe Acrobat and Reader中度風險 中度風險遠端執行程式碼
資料洩露
 APSB22-32
Adobe Character Animator中度風險 中度風險遠端執行程式碼 APSB22-34
Adobe Photoshop中度風險 中度風險遠端執行程式碼
資料洩露
 APSB22-35

 

「極高度風險」產品數目:0

「高度風險」產品數目:0

「中度風險」產品數目:4

「低度風險」產品數目:0

整體「風險程度」評估:中度風險


影響

  • 跨網站指令碼
  • 遠端執行程式碼
  • 資料洩露

受影響之系統或技術

  • RoboHelp RH2020.0.7 及以前版本
  • Acrobat DC 22.001.20142 及以前版本
  • Acrobat Reader DC 22.001.20142 及以前版本
  • Acrobat 2020 20.005.30334 及以前版本 (Win)
  • Acrobat 2020 20.005.30331 及以前版本 (Mac)
  • Acrobat Reader 2020 20.005.30334 及以前版本 (Win)
  • Acrobat Reader 2020 20.005.30331 及以前版本 (Mac)
  • Acrobat 2017 17.012.30229 及以前版本 (Win)
  • Acrobat 2017 17.012.30227 及以前版本 (Mac)
  • Acrobat Reader 2017  17.012.30229 及以前版本 (Win)
  • Acrobat Reader 2017  17.012.30227 及以前版本 (Mac)
  • Character Animator 2021 4.4.7 and earlier versions  
  • Character Animator 2022 22.4 及以前版本
  • Photoshop 2021 22.5.7 及以前版本
  • Photoshop 2022 23.3.2 及以前版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

  • 安裝供應商提供的修補程式。個別產品詳情可參考上表「詳情」一欄或執行軟件更新。

漏洞識別碼


資料來源


相關連結

Adobe Monthly Security Update (July 2022)

Release Date: 13 Jul 2022

RISK: Medium Risk

TYPE: Clients - Productivity Products

TYPE: Productivity Products

Adobe has released monthly security update for their products:

 

Vulnerable ProductRisk LevelImpactsNotesDetails (including CVE)
RoboHelpMedium Risk Medium RiskCross-site Scripting
Remote Code Execution
 APSB22-10
Adobe Acrobat and ReaderMedium Risk Medium RiskRemote Code Execution
Information Disclosure
 APSB22-32
Adobe Character AnimatorMedium Risk Medium RiskRemote Code Execution APSB22-34
Adobe PhotoshopMedium Risk Medium RiskRemote Code Execution
Information Disclosure
 APSB22-35

 

Number of 'Extremely High Risk' product(s): 0

Number of 'High Risk' product(s): 0

Number of 'Medium Risk' product(s): 4

Number of 'Low Risk' product(s): 0

Evaluation of overall 'Risk Level': Medium Risk


Impact

  • Cross-Site Scripting
  • Remote Code Execution
  • Information Disclosure

System / Technologies affected

  • RoboHelp RH2020.0.7 and earlier versions
  • Acrobat DC 22.001.20142 and earlier versions
  • Acrobat Reader DC 22.001.20142 and earlier versions
  • Acrobat 2020 20.005.30334 and earlier versions (Win)
  • Acrobat 2020 20.005.30331 and earlier versions (Mac)
  • Acrobat Reader 2020 20.005.30334 and earlier versions (Win)
  • Acrobat Reader 2020 20.005.30331 and earlier versions (Mac)
  • Acrobat 2017 17.012.30229 and earlier versions (Win)
  • Acrobat 2017 17.012.30227 and earlier versions  (Mac)
  • Acrobat Reader 2017  17.012.30229 and earlier versions (Win)
  • Acrobat Reader 2017 17.012.30227 and earlier versions (Mac)
  • Character Animator 2021 4.4.7 and earlier versions  
  • Character Animator 2022 22.4 and earlier versions
  • Photoshop 2021 22.5.7 and earlier versions
  • Photoshop 2022 23.3.2 and earlier versions

Solutions

Before installation of the software, please visit the vendor web-site for more details.

  • Apply fixes issued by the vendor. Please refer to 'Details' column in the above table for details of individual product update or run software update

Vulnerability Identifier


Source


Related Link

微軟每月保安更新 (2022年7月)

發佈日期: 2022年07月13日

風險: 高度風險

類型: 操作系統 - 視窗操作系統

類型: 視窗操作系統

微軟已為產品提供本月保安更新:

 

受影響產品風險程度影響備註
視窗高度風險 高度風險資料洩露
權限提升
繞過保安限制
阻斷服務
遠端執行程式碼
篡改
CVE-2022-22047 正被廣泛利用
延伸安全性更新 (ESU)中度風險 中度風險資料洩露
權限提升
繞過保安限制
阻斷服務
遠端執行程式碼
 
Azure中度風險 中度風險權限提升
資料洩露
遠端執行程式碼
 
System Center中度風險 中度風險篡改 
微軟 Dynamics中度風險 中度風險資料洩露 
微軟 Office中度風險 中度風險繞過保安限制
遠端執行程式碼
 

 

「極高度風險」產品數目:0

「高度風險」產品數目:1

「中度風險」產品數目:5

「低度風險」產品數目:0

整體「風險程度」評估:高度風險


影響

  • 阻斷服務
  • 權限提升
  • 遠端執行程式碼
  • 繞過保安限制
  • 資料洩露
  • 篡改

受影響之系統或技術

  • 視窗
  • 延伸安全性更新 (ESU)
  • Azure
  • System Center
  • 微軟 Dynamics
  • 微軟 Office

解決方案

在安裝軟體之前,請先瀏覽軟體供應商之網站,以獲得更多詳細資料。

  • 安裝軟件供應商提供的修補程式。

漏洞識別碼


資料來源


相關連結

F5 BIG-IP 阻斷服務漏洞

F5 BIG-IP 阻斷服務漏洞 發佈日期 : 2026 年 09 月 21 日 風險 : 高度風險 於 F5 BIG-IP 發現一個漏洞。遠端攻擊者可利用這漏洞,於目標系統觸發阻斷服務狀況。   注意: 暫無可修補  CVE-2026-11622  的...