2022年5月5日星期四

F5 產品多個漏洞

發佈日期: 2022年05月05日

風險: 中度風險

類型: 操作系統 - Network

類型: Network

於 F5 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、權限提升、遠端執行任意程式碼、洩露敏感資料、資料篡改、跨網站指令碼及繞過保安限制。


F5 Products Multiple Vulnerabilities

Release Date: 5 May 2022

RISK: Medium Risk

TYPE: Operating Systems - Networks OS

TYPE: Networks OS

Multiple vulnerabilities were identified in F5 Products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, elevation of privilege, remote code execution, sensitive information disclosure, data manipulation, cross-site scripting and security restriction bypass on the targeted system.


OpenSSL 多個漏洞

發佈日期: 2022年05月05日

風險: 中度風險

類型: 保安軟件及應用設備 - 保安軟件及應用設備

類型: 保安軟件及應用設備

於 OpenSSL 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、遠端執行任意程式碼及繞過保安限制。


影響

  • 阻斷服務
  • 遠端執行程式碼
  • 繞過保安限制

受影響之系統或技術

  • OpenSSL 1.0.2, 1.1.1 及 3.0 版本

解決方案

在安裝軟體之前,請先瀏覽軟體供應商之網站,以獲得更多詳細資料。

更新至:

  • 1.0.2ze 版本
  • 1.1.1o 版本
  • 3.0.3 版本

漏洞識別碼


資料來源


相關連結

OpenSSL Multiple Vulnerabilities

Release Date: 5 May 2022

RISK: Medium Risk

TYPE: Security software and application - Security Software & Appliance

TYPE: Security Software & Appliance

Multiple vulnerabilities were identified in OpenSSL. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, remote code execution and security restriction bypass on the targeted system.


Impact

  • Denial of Service
  • Remote Code Execution
  • Security Restriction Bypass

System / Technologies affected

  • OpenSSL versions 1.0.2, 1.1.1 and 3.0

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

Update to:

  • Version 1.0.2ze
  • Version 1.1.1o
  • Version 3.0.3

Vulnerability Identifier


Source


Related Link

2022年5月4日星期三

Mozilla 產品多個漏洞

最後更新 2022年05月04日 09:05 發佈日期: 2022年05月04日

風險: 中度風險

類型: 用戶端 - 瀏覽器

類型: 瀏覽器

於 Mozilla 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發彷冒、遠端執行任意程式碼、洩露敏感資料及繞過保安限制。


影響

  • 遠端執行程式碼
  • 繞過保安限制
  • 資料洩露
  • 仿冒

受影響之系統或技術

以下版本之前的版本﹕

 

  • Firefox 100
  • Firefox ESR 91.9

解決方案

在安裝軟體之前,請先瀏覽供應商之官方網站,以獲得更多詳細資料。

更新至版本:

 

  • Firefox 100
  • Firefox ESR 91.9

漏洞識別碼


資料來源


相關連結

Mozilla Products Multiple Vulnerabilities

Last Update Date: 4 May 2022 09:00 Release Date: 4 May 2022

RISK: Medium Risk

TYPE: Clients - Browsers

TYPE: Browsers

Multiple vulnerabilities were identified in Mozilla products. A remote attacker could exploit some of these vulnerabilities to trigger spoofing, remote code execution, sensitive information disclosure and security restriction bypass on the targeted system.


Impact

  • Remote Code Execution
  • Security Restriction Bypass
  • Information Disclosure
  • Spoofing

System / Technologies affected

Versions prior to:

 

  • Firefox 100
  • Firefox ESR 91.9

Solutions

Before installation of the software, please visit the vendor web-site for more details.

Apply fixes issued by the vendor:

 

  • Firefox 100
  • Firefox ESR 91.9

Vulnerability Identifier


Source


Related Link

Debian Linux 核心多個漏洞

發佈日期: 2022年05月04日

風險: 中度風險

類型: 操作系統 - LINUX

類型: LINUX

於 Debian Linux 核心發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、權限提升及洩露敏感資料。


影響

  • 阻斷服務
  • 權限提升
  • 資料洩露

受影響之系統或技術

  • Debian Stable Distribution (bullseye) 5.10.113-1 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

Debian Linux Kernel Multiple Vulnerabilities

Release Date: 4 May 2022

RISK: Medium Risk

TYPE: Operating Systems - Linux

TYPE: Linux

Multiple vulnerabilities were identified in Debian Linux Kernel. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, elevation of privilege and sensitive information disclosure on the targeted system.


Impact

  • Denial of Service
  • Elevation of Privilege
  • Information Disclosure

System / Technologies affected

  • Debian Stable Distribution (bullseye) prior to 5.10.113-1 

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

F5 產品多個漏洞

發佈日期: 2022年05月04日

風險: 中度風險

類型: 操作系統 - Network

類型: Network

於 F5 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況及遠端執行程式碼。


影響

  • 阻斷服務
  • 遠端執行程式碼

受影響之系統或技術

F5OS-A

  • 版本 1.0.0 - 1.0.1

 

F5OS-C

  • 版本 1.1.0 - 1.4.0

 

BIG-IP ASM

  • 版本 17.0.0
  • 版本 16.1.0 - 16.1.2
  • 版本 15.1.0 - 15.1.5
  • 版本 14.1.0 - 14.1.4
  • 版本 13.1.0 - 13.1.5
  • 版本 12.1.0 - 12.1.6
  • 版本 11.6.1 - 11.6.5

 

BIG-IP DNS

  • 版本 17.0.0
  • 版本 16.1.0 - 16.1.2
  • 版本 15.1.0 - 15.1.5
  • 版本 14.1.0 - 14.1.4
  • 版本 13.1.0 - 13.1.5
  • 版本 12.1.0 - 12.1.6
  • 版本 11.6.1 - 11.6.5

 

BIG-IP (all other modules)

  • 版本 17.0.0
  • 版本 16.1.0 - 16.1.2
  • 版本 15.1.0 - 15.1.5
  • 版本 14.1.0 - 14.1.4
  • 版本 13.1.0 - 13.1.5
  • 版本 12.1.0 - 12.1.6
  • 版本 11.6.1 - 11.6.5

 

BIG-IQ Centralized Management

  • 版本 8.0.0 - 8.2.0
  • 版本 7.0.0 - 7.1.0

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

F5 Products Multiple Vulnerabilities

Release Date: 4 May 2022

RISK: Medium Risk

TYPE: Operating Systems - Networks OS

TYPE: Networks OS

Multiple vulnerabilities were identified in F5 Products . A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition and remote code execution on the targeted system.


Impact

  • Denial of Service
  • Remote Code Execution

System / Technologies affected

F5OS-A

  • version 1.0.0 - 1.0.1

 

F5OS-C

  • version 1.1.0 - 1.4.0

 

BIG-IP ASM

  • version 17.0.0
  • version 16.1.0 - 16.1.2
  • version 15.1.0 - 15.1.5
  • version 14.1.0 - 14.1.4
  • version 13.1.0 - 13.1.5
  • version 12.1.0 - 12.1.6
  • version 11.6.1 - 11.6.5

 

BIG-IP DNS

  • version 17.0.0
  • version 16.1.0 - 16.1.2
  • version 15.1.0 - 15.1.5
  • version 14.1.0 - 14.1.4
  • version 13.1.0 - 13.1.5
  • version 12.1.0 - 12.1.6
  • version 11.6.1 - 11.6.5

 

BIG-IP (all other modules)

  • version 17.0.0
  • version 16.1.0 - 16.1.2
  • version 15.1.0 - 15.1.5
  • version 14.1.0 - 14.1.4
  • version 13.1.0 - 13.1.5
  • version 12.1.0 - 12.1.6
  • version 11.6.1 - 11.6.5

 

BIG-IQ Centralized Management

  • version 8.0.0 - 8.2.0
  • version 7.0.0 - 7.1.0

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

GitLab 多個漏洞

發佈日期: 2022年05月04日

風險: 中度風險

類型: 伺服器 - 其他伺服器

類型: 其他伺服器

於 GitLab 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、洩露敏感資料、資料洩露、繞過保安限制及跨網站指令碼。


影響

  • 阻斷服務
  • 資料洩露
  • 繞過保安限制
  • 跨網站指令碼
  • 篡改

受影響之系統或技術

  • GitLab Community Edition (CE) 14.10.1, 14.9.4 及 14.8.6 以前的版本
  • GitLab Enterprise Edition (EE) 14.10.1, 14.9.4 及 14.8.6 以前的版本


解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。


漏洞識別碼


資料來源


相關連結

GitLab Multiple Vulnerabilities

Release Date: 4 May 2022

RISK: Medium Risk

TYPE: Servers - Other Servers

TYPE: Other Servers

Multiple vulnerabilities were identified in GitLab. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, sensitive information disclosure, data manipulation, security restriction bypass and cross-site scripting on the targeted system.


Impact

  • Denial of Service
  • Information Disclosure
  • Security Restriction Bypass
  • Cross-Site Scripting
  • Data Manipulation

System / Technologies affected

  • GitLab Community Edition (CE) versions prior to 14.10.1, 14.9.4 and 14.8.6
  • GitLab Enterprise Edition (EE) versions prior to 14.10.1, 14.9.4 and 14.8.6


Solutions

Before installation of the software, please visit the software vendor web-site for more details.


Vulnerability Identifier


Source


Related Link

2022年5月3日星期二

Android多個漏洞

發佈日期: 2022年05月03日

風險: 中度風險

類型: 操作系統 - 流動裝置及操作系統

類型: 流動裝置及操作系統

於 Android 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發資料洩露、權限提升及阻斷服務狀況。


Android Multiple Vulnerabilities

Release Date: 3 May 2022

RISK: Medium Risk

TYPE: Operating Systems - Mobile & Apps

TYPE: Mobile & Apps

Multiple vulnerabilities were identified in Android. A remote attacker could exploit some of these vulnerabilities to trigger information disclosure, elevation of privilege and denial of service condition on the targeted system.


思科產品多個漏洞

發佈日期: 2022年05月03日

風險: 中度風險

類型: 保安軟件及應用設備 - 保安軟件及應用設備

類型: 保安軟件及應用設備

於思科產品發現多個漏洞,遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、跨網站指令碼、篡改及繞過保安限制。


影響

  • 阻斷服務
  • 跨網站指令碼
  • 繞過保安限制
  • 篡改

受影響之系統或技術

  • Cisco Adaptive Security Appliance
  • Cisco Firepower Management Center
  • Cisco Firepower Threat Defense Software

詳情請參閱以下連結﹕

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-ipsec-mitm-CKnLr4

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-FTD-snort3-DOS-Aq38LVdM

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asafdt-webvpn-dos-tzPSYern

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-dos-JnnJm4wB

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-xss-SfpEcvGT

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-amp-local-dos-CUfwRJXT

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-dos-nJVAwOeq

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-sidns-bypass-3PzA5pO

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-snort-dos-hd2hFgM

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asa-dos-tL4uA4AA

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-tcp-dos-kM9SHhOu


解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

Cisco Products Multiple Vulnerabilities

Release Date: 3 May 2022

RISK: Medium Risk

TYPE: Security software and application - Security Software & Appliance

TYPE: Security Software & Appliance

Multiple vulnerabilities were identified in Cisco Products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, cross site scripting, data manipulation and security restriction bypass on the targeted system.


Impact

  • Denial of Service
  • Cross-Site Scripting
  • Security Restriction Bypass
  • Data Manipulation

System / Technologies affected

  • Cisco Adaptive Security Appliance
  • Cisco Firepower Management Center
  • Cisco Firepower Threat Defense Software

Please refer to the link below for detail:

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-ipsec-mitm-CKnLr4

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-FTD-snort3-DOS-Aq38LVdM

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asafdt-webvpn-dos-tzPSYern

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-dos-JnnJm4wB

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-xss-SfpEcvGT

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-amp-local-dos-CUfwRJXT

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-dos-nJVAwOeq

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-sidns-bypass-3PzA5pO

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-snort-dos-hd2hFgM

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asa-dos-tL4uA4AA

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-tcp-dos-kM9SHhOu


Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

Synology 產品多個漏洞

發佈日期: 2022年05月03日

風險: 中度風險

類型: 伺服器 - 其他伺服器

類型: 其他伺服器

於 Synology 產品發現多個漏洞,遠端攻擊者可利用這些漏洞,於目標系統觸發遠端執行任意程式碼及洩露敏感資料。


影響

  • 遠端執行程式碼
  • 資料洩露

受影響之系統或技術

  • Synology DiskStation Manager 7.1
  • Synology DiskStation Manager 7.0
  • Synology DiskStation Manager 6.2
  • Synology Router Manager 1.2
  • VS Firmware 2.3

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

Synology Products Multiple Vulnerabilities

Release Date: 3 May 2022

RISK: Medium Risk

TYPE: Servers - Other Servers

TYPE: Other Servers

Multiple vulnerabilities were identified in Synology products. A remote attacker could exploit some of these vulnerabilities to trigger remote code execution and sensitive information disclosure on the targeted system.


Impact

  • Remote Code Execution
  • Information Disclosure

System / Technologies affected

  • Synology DiskStation Manager 7.1
  • Synology DiskStation Manager 7.0
  • Synology DiskStation Manager 6.2
  • Synology Router Manager 1.2
  • VS Firmware 2.3

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

Apache Tomcat 多個漏洞

Apache Tomcat 多個漏洞 發佈日期: 2026年08月05日 風險: 中度風險 類型: 伺服器 - 網站伺服器 於 Apache T...