2024年1月27日星期六

Google Chrome 多個漏洞

發佈日期: 2024年01月25日

風險: 中度風險

類型: 用戶端 - 瀏覽器

類型: 瀏覽器

於 Google Chrome 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發繞過保安限制、仿冒、資料洩露、遠端執行任意程式碼及阻斷服務狀況。

 

影響

  • 遠端執行程式碼
  • 阻斷服務
  • 繞過保安限制
  • 仿冒
  • 資料洩露

受影響之系統或技術

  • Google Chrome 121.0.6167.85 (Linux) 之前的版本
  • Google Chrome 121.0.6167.85 (Mac) 之前的版本
  • Google Chrome 121.0.6167.85/.86 (Windows) 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝軟件供應商提供的修補程式:

  • 更新至 121.0.6167.85 (Linux) 或之後版本
  • 更新至 121.0.6167.85 (Mac) 或之後版本
  • 更新至 121.0.6167.85/.86 (Windows) 或之後版本

漏洞識別碼


資料來源


相關連結

Google Chrome Multiple Vulnerabilities

Release Date: 25 Jan 2024

RISK: Medium Risk

TYPE: Clients - Browsers

TYPE: Browsers

Multiple vulnerabilities were identified in Google Chrome.  A remote attacker could exploit some of these vulnerabilities to trigger security restriction bypass, spoofing, information disclosure, remote code execution and denial of service condition on the targeted system.


Impact

  • Remote Code Execution
  • Denial of Service
  • Security Restriction Bypass
  • Spoofing
  • Information Disclosure

System / Technologies affected

  • Google Chrome prior to 121.0.6167.85 (Linux)
  • Google Chrome prior to 121.0.6167.85 (Mac)
  • Google Chrome prior to 121.0.6167.85/.86 (Windows)

Solutions

Before installation of the software, please visit the software vendor web-site for more details.

Apply fixes issued by the vendor:

  • Update to version 121.0.6167.85 (Linux) or later
  • Update to version 121.0.6167.85 (Mac) or later
  • Update to version 121.0.6167.85/.86 (Windows) or later

Vulnerability Identifier


Source


Related Link

Mozilla 產品多個漏洞

發佈日期: 2024年01月24日

風險: 中度風險

類型: 用戶端 - 瀏覽器

類型: 瀏覽器

於 Mozilla 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、彷冒、遠端執行任意程式碼、洩露敏感資料、權限提升及繞過保安限制。

 

影響

  • 阻斷服務
  • 遠端執行程式碼
  • 繞過保安限制
  • 仿冒
  • 權限提升

受影響之系統或技術

以下版本之前的版本﹕

 

  • Firefox ESR 115.7
  • Firefox 122
  • Thunderbird 115.7
 

解決方案

在安裝軟體之前,請先瀏覽供應商之官方網站,以獲得更多詳細資料。

更新至版本:

 

  • Firefox ESR 115.7
  • Firefox 122
  • Thunderbird 115.7
 

漏洞識別碼


資料來源


相關連結

Mozilla Products Multiple Vulnerabilities

Release Date: 24 Jan 2024

RISK: Medium Risk

TYPE: Clients - Browsers

TYPE: Browsers

Multiple vulnerabilities were identified in Mozilla Products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, spoofing, remote code execution, elevation of privilege and security restriction bypass on the targeted system.


Impact

  • Denial of Service
  • Remote Code Execution
  • Security Restriction Bypass
  • Spoofing
  • Elevation of Privilege

System / Technologies affected

Versions prior to:

 

  • Firefox ESR 115.7
  • Firefox 122
  • Thunderbird 115.7
 

Solutions

Before installation of the software, please visit the vendor web-site for more details.

Apply fixes issued by the vendor:

 

  • Firefox ESR 115.7
  • Firefox 122
  • Thunderbird 115.7

Vulnerability Identifier


Source


Related Link

2024年1月23日星期二

蘋果產品多個漏洞

發佈日期: 2024年01月23日

風險: 極高度風險

類型: 操作系統 - 流動裝置及操作系統

類型: 流動裝置及操作系統

於蘋果產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發權限提升、遠端執行任意程式碼、洩露敏感資料及繞過保安限制。

 

注意:

對於 CVE-2024-23222,處理網頁內容時可能導致任意代碼執行。蘋果知悉有報告指出,這個漏洞可能已被廣泛利用。


影響

  • 遠端執行程式碼
  • 繞過保安限制
  • 資料洩露
  • 權限提升

受影響之系統或技術

  • iOS 16.7.5 及 iPadOS 16.7.5 以前的版本
  • iOS 17.3 及 iPadOS 17.3 以前的版本
  • macOS Monterey 12.7.3 以前的版本
  • macOS Ventura 13.6.4 以前的版本
  • macOS Sonoma 14.3 以前的版本
  • Safari 17.3 以前的版本
  • tvOS 17.3 以前的版本
  • watchOS 10.3 以前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝供應商提供的修補程式:

 

  • iOS 16.7.5 及 iPadOS 16.7.5
  • iOS 17.3 及 iPadOS 17.3
  • macOS Monterey 12.7.3
  • macOS Ventura 13.6.4
  • macOS Sonoma 14.3
  • Safari 17.3
  • tvOS 17.3
  • watchOS 10.3
 

漏洞識別碼


資料來源


相關連結

Apple Products Multiple Vulnerabilities

Release Date: 23 Jan 2024

RISK: Extremely High Risk

TYPE: Operating Systems - Mobile & Apps

TYPE: Mobile & Apps

Multiple vulnerabilities were identified in Apple Products. A remote attacker could exploit some of these vulnerabilities to trigger elevation of privilege, remote code execution, sensitive information disclosure and security restriction bypass on the targeted system.

 

Note:

For CVE-2024-23222, processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited.


Impact

  • Remote Code Execution
  • Security Restriction Bypass
  • Information Disclosure
  • Elevation of Privilege

System / Technologies affected

  • Versions prior to iOS 16.7.5 and iPadOS 16.7.5
  • Versions prior to iOS 17.3 and iPadOS 17.3
  • Versions prior to macOS Monterey 12.7.3
  • Versions prior to macOS Ventura 13.6.4
  • Versions prior to macOS Sonoma 14.3
  • Versions prior to Safari 17.3
  • Versions prior to tvOS 17.3
  • Versions prior to watchOS 10.3

Solutions

Before installation of the software, please visit the vendor web-site for more details.

Apply fixes issued by the vendor:

 

  • iOS 16.7.5 and iPadOS 16.7.5
  • iOS 17.3 and iPadOS 17.3
  • macOS Monterey 12.7.3
  • macOS Ventura 13.6.4
  • macOS Sonoma 14.3
  • Safari 17.3
  • tvOS 17.3
  • watchOS 10.3

Vulnerability Identifier


Source


Related Link

Splunk 產品多個漏洞

發佈日期: 2024年01月23日

風險: 中度風險

類型: 伺服器 - 其他伺服器

類型: 其他伺服器

於 Splunk 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發洩露敏感資料及繞過保安限制。

 

影響

  • 繞過保安限制
  • 資料洩露

受影響之系統或技術

  • Splunk Cloud Platform: Splunk Web 9.1.2308.200 以前版本
  • Splunk Cloud Platform: Splunk Web 9.0.2208 以前版本
  • Splunk Enterprise: Splunk Web version 9.0.0 至 9.0.7 版本
  • Splunk Enterprise: Splunk Web version 9.1.0 至 9.1.2 版本
  • Splunk Cloud Platform: Splunk REST API 9.1.2312.100 以前版本
  • Splunk Enterprise: Splunk REST API 9.0.0 至 9.0.7 版本
  • Splunk Enterprise: Splunk REST API 9.1.0 至 9.1.2 版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

Splunk Products Multiple Vulnerabilities

Release Date: 23 Jan 2024

RISK: Medium Risk

TYPE: Servers - Other Servers

TYPE: Other Servers

Multiple vulnerabilities were identified in Splunk products. A remote attacker could exploit some of these vulnerabilities to trigger sensitive information disclosure and security restriction bypass on the targeted system.


Impact

  • Security Restriction Bypass
  • Information Disclosure

System / Technologies affected

  • Splunk Cloud Platform: Splunk Web versions below 9.1.2308.200
  • Splunk Cloud Platform: Splunk Web versions below 9.0.2208
  • Splunk Enterprise: Splunk Web version 9.0.0 to 9.0.7
  • Splunk Enterprise: Splunk Web version 9.1.0 to 9.1.2
  • Splunk Cloud Platform: Splunk REST API versions below 9.1.2312.100
  • Splunk Enterprise: Splunk REST API version 9.0.0 to 9.0.7 
  • Splunk Enterprise: Splunk REST API version 9.1.0 to 9.1.2

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

蘋果產品多個漏洞

最後更新 2024年01月23日

風險: 極高度風險

類型: 操作系統 - 流動裝置及操作系統

類型: 流動裝置及操作系統

於蘋果產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、彷冒、遠端執行任意程式碼及資料洩露。

 

注意:

對於 CVE-2023-42916及CVE-2023-42917,處理網頁內容時可能導致任意代碼執行。蘋果知悉有報告指出,這個問題可能已在 iOS 16.7.1 之前的 iOS 版本中被廣泛利用。

 

[更新於 2024-01-23]

更新受影響之系統或技術、解決方案及相關連結。

 

蘋果於同日亦發佈了最新針對iOS, macOS, Safari, tvOS和 WatchOS的保安公告,詳情請參閱 https://www.hkcert.org/tc/security-bulletin/apple-products-multiple-vulnerabilities_20240123


影響

  • 遠端執行程式碼
  • 資料洩露
  • 仿冒
  • 阻斷服務

受影響之系統或技術

  • iOS 15.8.1 及 iPadOS 15.8.1 以前的版本
  • iOS 16.7.3 及 iPadOS 16.7.3 以前的版本
  • iOS 17.2 及 iPadOS 17.2 以前的版本
  • macOS Monterey 12.7.2 以前的版本
  • macOS Ventura 13.6.3 以前的版本
  • macOS Sonoma 14.2 以前的版本
  • Safari 17.2 以前的版本
  • tvOS 17.2 以前的版本
  • watchOS 10.2 以前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝供應商提供的修補程式:

 

  • iOS 15.8.1 及 iPadOS 15.8.1
  • iOS 16.7.3 及 iPadOS 16.7.3
  • iOS 17.2 及 iPadOS 17.2
  • macOS Monterey 12.7.2
  • macOS Ventura 13.6.3
  • macOS Sonoma 14.2
  • Safari 17.2
  • tvOS 17.2
  • watchOS 10.2
 

漏洞識別碼


資料來源


相關連結

Apple Products Multiple Vulnerabilities

Last Update Date: 23 Jan 2024

RISK: Extremely High Risk

TYPE: Operating Systems - Mobile & Apps

TYPE: Mobile & Apps

Multiple vulnerabilities were identified in Apple Products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, spoofing, remote code execution and information disclosure on the targeted system.

 

Note:

For CVE-2023-42916 and CVE-2023-42917, processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.1.

 

[Updated on 2024-01-23] 

Updated System / Technologies affected, Solutions and Related Links.

 

Apple also released the latest security bulletins for iOS, macOS, Safari, tvOS and WatchOS today. For details, please refer to  https://www.hkcert.org/security-bulletin/apple-products-multiple-vulnerabilities_20240123


Impact

  • Remote Code Execution
  • Information Disclosure
  • Spoofing
  • Denial of Service

System / Technologies affected

  • Versions prior to iOS 15.8.1 and iPadOS 15.8.1
  • Versions prior to iOS 16.7.3 and iPadOS 16.7.3
  • Versions prior to iOS 17.2 and iPadOS 17.2
  • Versions prior to macOS Monterey 12.7.2
  • Versions prior to macOS Ventura 13.6.3
  • Versions prior to macOS Sonoma 14.2
  • Versions prior to Safari 17.2
  • Versions prior to tvOS 17.2
  • Versions prior to watchOS 10.2

Solutions

Before installation of the software, please visit the vendor web-site for more details.

Apply fixes issued by the vendor:

 

  • iOS 15.8.1 and iPadOS 15.8.1
  • iOS 16.7.3 and iPadOS 16.7.3
  • iOS 17.2 and iPadOS 17.2
  • macOS Monterey 12.7.2
  • macOS Ventura 13.6.3
  • macOS Sonoma 14.2
  • Safari 17.2
  • tvOS 17.2
  • watchOS 10.2

Vulnerability Identifier


Source


Related Link

2024年1月22日星期一

Apache Tomcat 資料洩露漏洞

發佈日期: 2024年01月22日

風險: 中度風險

類型: 伺服器 - 網站伺服器

類型: 網站伺服器

於 Apache Tomcat 發現一個漏洞。遠端攻擊者可利用此漏洞,於目標系統觸發敏感資料洩露。


影響

  • 資料洩露

受影響之系統或技術

  • Apache Tomcat 9.0.0-M11 至 9.0.43 版本
  • Apache Tomcat 8.5.7 至 8.5.63 版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:

 

  • Apache Tomcat 9.0.44 或之後版本
  • Apache Tomcat 8.5.64 或之後版本

漏洞識別碼


資料來源


相關連結

F5 BIG-IP 遠端執行程式碼漏洞

F5 BIG-IP 遠端執行程式碼漏洞 發佈日期 : 2026 年 09 月 23 日 於 F5 BIG-IP 發現一個漏洞。遠端攻擊者可利用這漏洞,於目標系統觸發遠端執行程式碼狀況。   注意: CVE-2026-94127 正被廣泛利用。此漏洞僅在 B...