2022年6月10日星期五

Ubuntu Linux Kernel Multiple Vulnerabilities

Release Date: 10 Jun 2022

RISK: Medium Risk

TYPE: Operating Systems - Linux

TYPE: Linux

Multiple vulnerabilities have been identified in Ubuntu Linux Kernel. A remote attacker could exploit some of these vulnerabilities to trigger denial of service, elevation of privilege, remote code execution, security restriction bypass and information disclosure on the targeted system.


Impact

  • Denial of Service
  • Elevation of Privilege
  • Remote Code Execution
  • Security Restriction Bypass
  • Information Disclosure

System / Technologies affected

  • Ubuntu 14.04 ESM
  • Ubuntu 16.04 ESM
  • Ubuntu 18.04 LTS
  • Ubuntu 20.04 LTS
  • Ubuntu 21.10
  • Ubuntu 22.04 LTS

 

Please refer to the links below for detail:

 


Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:

 


Vulnerability Identifier


Source


Related Link

2022年6月9日星期四

Fortinet 產品多個漏洞

發佈日期: 2022年06月09日

風險: 中度風險

類型: 操作系統 - Network

類型: Network

於 Fortinet 產品發現多個漏洞,遠端攻擊者可利用這些漏洞,於目標系統觸發遠端執行任意程式碼、洩露敏感資料、仿冒及跨網站指令碼。


影響

  • 遠端執行程式碼
  • 資料洩露
  • 仿冒
  • 跨網站指令碼

受影響之系統或技術

  • FortiAnalyzer 7.0.2 及之前的版本
  • FortiAnalyzer 6.4.7 及之前的版本
  • FortiAP-U 6.2.0 至 6.2.3 版本
  • FortiAP-U 6.0.0 至 6.0.4 版本
  • FortiAP-U 5.4.0 至 5.4.6 版本
  • FortiAuthenticator Agent for Microsoft OWA 2.1 版本
  • FortiAuthenticator Agent for Microsoft OWA 2.2 版本
  • FortiClientWindows 6.0.0 至 6.0.10 版本
  • FortiClientWindows 6.2.0 至 6.2.9 版本
  • FortiClientWindows 6.4.0 至 6.4.7 版本
  • FortiClientWindows 7.0.0 至 7.0.3 版本
  • FortiDDoS 5.5.0 至 5.5.1 版本
  • FortiDDoS 5.4.0 至 5.4.2 版本
  • FortiDDoS 5.3.0 至 5.3.1 版本
  • FortiDDoS 5.2.0 版本
  • FortiDDoS 5.1.0 版本
  • FortiOS 6.2.x 版本
  • FortiOS 6.0.x 版本
  • FortiManager 7.0.1 及之前的版本
  • FortiManager 6.4.6 及之前的版本
  • FortiSandbox 4.0.x 版本
  • FortiSandbox 3.2.x 版本
  • FortiSandbox 3.1.5 及之前的版本
  • FortiTokenMobile for Android v5.0.3 及之前的版本
  • FortiTokenMobile for iOS v5.2.0 及之前的版本
  • FortiTokenMobile for Windows v4.0.3 及之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 


漏洞識別碼


資料來源


相關連結

Fortinet Products Multiple Vulnerabilities

Release Date: 9 Jun 2022

RISK: Medium Risk

TYPE: Operating Systems - Networks OS

TYPE: Networks OS

Multiple vulnerabilities were identified in Fortinet Products, a remote attacker could exploit some of these vulnerabilities to trigger remote code execution, sensitive information disclosure, spoofing and cross-site scripting on the targeted system.


Impact

  • Remote Code Execution
  • Information Disclosure
  • Spoofing
  • Cross-Site Scripting

System / Technologies affected

  • FortiAnalyzer 7.0.2 and prior versions
  • FortiAnalyzer 6.4.7 and prior versions
  • FortiAP-U versions 6.2.0 to 6.2.3
  • FortiAP-U versions 6.0.0 to 6.0.4
  • FortiAP-U versions 5.4.0 to 5.4.6
  • FortiAuthenticator Agent for Microsoft OWA version 2.1
  • FortiAuthenticator Agent for Microsoft OWA version 2.2
  • FortiClientWindows versions 6.0.0 to 6.0.10
  • FortiClientWindows versions 6.2.0 to 6.2.9
  • FortiClientWindows versions 6.4.0 to 6.4.7
  • FortiClientWindows versions 7.0.0 to 7.0.3
  • FortiDDoS versions 5.5.0 to 5.5.1
  • FortiDDoS versions 5.4.0 to 5.4.2
  • FortiDDoS versions 5.3.0 to 5.3.1
  • FortiDDoS version 5.2.0
  • FortiDDoS version 5.1.0
  • FortiOS versions 6.2.x
  • FortiOS versions 6.0.x
  • FortiManager 7.0.1 and prior versions
  • FortiManager 6.4.6 and prior versions
  • FortiSandbox versions 4.0.x
  • FortiSandbox versions 3.2.x
  • FortiSandbox 3.1.5 and prior versions
  • FortiTokenMobile for Android v5.0.3 and prior versions
  • FortiTokenMobile for iOS v5.2.0 and prior versions
  • FortiTokenMobile for Windows v4.0.3 and prior versions

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 


Vulnerability Identifier


Source


Related Link

2022年6月8日星期三

Android多個漏洞

發佈日期: 2022年06月08日

風險: 中度風險

類型: 操作系統 - 流動裝置及操作系統

類型: 流動裝置及操作系統

於 Android 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發資料洩露、權限提升、遠端執行程式碼及阻斷服務狀況。


Android Multiple Vulnerabilities

Release Date: 8 Jun 2022

RISK: Medium Risk

TYPE: Operating Systems - Mobile & Apps

TYPE: Mobile & Apps

Multiple vulnerabilities were identified in Android. A remote attacker could exploit some of these vulnerabilities to trigger information disclosure, elevation of privilege, remote code execution and denial of service condition on the targeted system.


SUSE Linux 內核多個漏洞

最後更新 2022年06月07日 發佈日期: 2022年06月06日

風險: 中度風險

類型: 操作系統 - LINUX

類型: LINUX

於 SUSE Products 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發權限提升及繞過保安限制。

 

[更新於 2022-06-07]

更新受影響之系統或技術,解決方案及相關連結。


影響

  • 權限提升
  • 繞過保安限制

受影響之系統或技術

  • SUSE Linux Enterprise High Performance Computing 15
  • SUSE Linux Enterprise High Performance Computing 15-SP1
  • SUSE Linux Enterprise High Performance Computing 15-SP2
  • SUSE Linux Enterprise High Performance Computing 15-SP3
  • SUSE Linux Enterprise Live Patching 12-SP4
  • SUSE Linux Enterprise Live Patching 12-SP5
  • SUSE Linux Enterprise Micro 5.1
  • SUSE Linux Enterprise Module for Live Patching 15
  • SUSE Linux Enterprise Module for Live Patching 15-SP1
  • SUSE Linux Enterprise Module for Live Patching 15-SP2
  • SUSE Linux Enterprise Module for Live Patching 15-SP3
  • SUSE Linux Enterprise Server 15
  • SUSE Linux Enterprise Server 15-SP1
  • SUSE Linux Enterprise Server 15-SP2
  • SUSE Linux Enterprise Server 15-SP3
  • SUSE Linux Enterprise Server for SAP Applications 15
  • SUSE Linux Enterprise Server for SAP Applications 15-SP1
  • SUSE Linux Enterprise Server for SAP Applications 15-SP2
  • SUSE Linux Enterprise Server for SAP Applications 15-SP3

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

SUSE Linux Kernel Multiple Vulnerabilities

Last Update Date: 7 Jun 2022 Release Date: 6 Jun 2022

RISK: Medium Risk

TYPE: Operating Systems - Linux

TYPE: Linux

Multiple vulnerabilities were identified in SUSE Products. A remote attacker could exploit some of these vulnerabilities to trigger elevation of privilege and security restriction bypass on the targeted system.

 

[Updated on 2022-06-07]

Updated System / Technologies affected, Solutions and Related Links.


Impact

  • Elevation of Privilege
  • Security Restriction Bypass

System / Technologies affected

  • SUSE Linux Enterprise High Performance Computing 15
  • SUSE Linux Enterprise High Performance Computing 15-SP1
  • SUSE Linux Enterprise High Performance Computing 15-SP2
  • SUSE Linux Enterprise High Performance Computing 15-SP3
  • SUSE Linux Enterprise Live Patching 12-SP4
  • SUSE Linux Enterprise Live Patching 12-SP5
  • SUSE Linux Enterprise Micro 5.1
  • SUSE Linux Enterprise Module for Live Patching 15
  • SUSE Linux Enterprise Module for Live Patching 15-SP1
  • SUSE Linux Enterprise Module for Live Patching 15-SP2
  • SUSE Linux Enterprise Module for Live Patching 15-SP3
  • SUSE Linux Enterprise Server 15
  • SUSE Linux Enterprise Server 15-SP1
  • SUSE Linux Enterprise Server 15-SP2
  • SUSE Linux Enterprise Server 15-SP3
  • SUSE Linux Enterprise Server for SAP Applications 15
  • SUSE Linux Enterprise Server for SAP Applications 15-SP1
  • SUSE Linux Enterprise Server for SAP Applications 15-SP2
  • SUSE Linux Enterprise Server for SAP Applications 15-SP3

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

2022年6月6日星期一

NetApp 產品多個漏洞

發佈日期: 2022年06月06日

風險: 中度風險

類型: 伺服器 - 其他伺服器

類型: 其他伺服器

於 NetApp 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、洩露敏感資料及資料篡改。


影響

  • 阻斷服務
  • 資料洩露
  • 篡改

受影響之系統或技術

  • AFF Baseboard Management Controller (BMC) - A700s
  • Active IQ Unified Manager for VMware vSphere
  • Clustered Data ONTAP
  • Clustered Data ONTAP Antivirus Connector
  • FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400
  • FAS/AFF Baseboard Management Controller (BMC) - A250/500f
  • NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S
  • NetApp HCI Baseboard Management Controller (BMC) - H410C
  • NetApp HCI Compute Node (Bootstrap OS)
  • NetApp SANtricity SMI-S Provider
  • NetApp SMI-S Provider
  • NetApp SolidFire & HCI Management Node
  • NetApp SolidFire, Enterprise SDS & HCI Storage Node (Element Software)
  • SnapManager for Hyper-V

解決方案


漏洞識別碼


資料來源


相關連結

NetApp Products Multiple Vulnerabilities

Release Date: 6 Jun 2022

RISK: Medium Risk

TYPE: Servers - Other Servers

TYPE: Other Servers

Multiple vulnerabilities were identified in NetApp Products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, sensitive information disclosure and data manipulation on the targeted system.


Impact

  • Denial of Service
  • Information Disclosure
  • Data Manipulation

System / Technologies affected

  • AFF Baseboard Management Controller (BMC) - A700s
  • Active IQ Unified Manager for VMware vSphere
  • Clustered Data ONTAP
  • Clustered Data ONTAP Antivirus Connector
  • FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400
  • FAS/AFF Baseboard Management Controller (BMC) - A250/500f
  • NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S
  • NetApp HCI Baseboard Management Controller (BMC) - H410C
  • NetApp HCI Compute Node (Bootstrap OS)
  • NetApp SANtricity SMI-S Provider
  • NetApp SMI-S Provider
  • NetApp SolidFire & HCI Management Node
  • NetApp SolidFire, Enterprise SDS & HCI Storage Node (Element Software)
  • SnapManager for Hyper-V

Solutions


Vulnerability Identifier


Source


Related Link

SUSE Linux 內核多個漏洞

發佈日期: 2022年06月06日

風險: 中度風險

類型: 操作系統 - LINUX

類型: LINUX

於 SUSE Products 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發權限提升及繞過保安限制。


SUSE Linux Kernel Multiple Vulnerabilities

Release Date: 6 Jun 2022

RISK: Medium Risk

TYPE: Operating Systems - Linux

TYPE: Linux

Multiple vulnerabilities were identified in SUSE Products. A remote attacker could exploit some of these vulnerabilities to trigger elevation of privilege and security restriction bypass on the targeted system.


2022年6月2日星期四

GitLab 多個漏洞

發佈日期: 2022年06月02日

風險: 中度風險

類型: 伺服器 - 其他伺服器

類型: 其他伺服器

於 GitLab 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發權限提升、洩露敏感資料、繞過保安限制及跨網站指令碼。


影響

  • 權限提升
  • 資料洩露
  • 繞過保安限制
  • 跨網站指令碼

受影響之系統或技術

  • GitLab Community Edition (CE) 5.0.1, 14.10.4, 及 14.9.5 以前的版本
  • GitLab Enterprise Edition (CE) 5.0.1, 14.10.4, 及 14.9.5 以前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。


漏洞識別碼


資料來源


相關連結

GitLab Multiple Vulnerabilities

Release Date: 2 Jun 2022

RISK: Medium Risk

TYPE: Servers - Other Servers

TYPE: Other Servers

Multiple vulnerabilities were identified in GitLab. A remote attacker could exploit some of these vulnerabilities to trigger elevation of privilege, sensitive information disclosure, security restriction bypass and cross-site scripting on the targeted system.


Impact

  • Elevation of Privilege
  • Information Disclosure
  • Security Restriction Bypass
  • Cross-Site Scripting

System / Technologies affected

  • GitLab Community Edition (CE) versions prior to 15.0.1, 14.10.4, and 14.9.5
  • GitLab Enterprise Edition (CE) versions prior to 15.0.1, 14.10.4, and 14.9.5

Solutions

Before installation of the software, please visit the software vendor web-site for more details.


Vulnerability Identifier


Source


Related Link

Microsoft Edge 多個漏洞

發佈日期: 2022年06月02日

風險: 中度風險

類型: 用戶端 - 瀏覽器

類型: 瀏覽器

於 Microsoft Edge 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發權限提升、遠端執行任意程式碼、洩露敏感資料、繞過保安限制及仿冒。


影響

  • 權限提升
  • 遠端執行程式碼
  • 資料洩露
  • 繞過保安限制
  • 仿冒

受影響之系統或技術

  • Microsoft Edge 102.0.1245.30 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝軟件供應商提供的修補程式:

  • 更新至 102.0.1245.30 版本

漏洞識別碼


資料來源


相關連結

Microsoft Edge Multiple Vulnerabilities

Release Date: 2 Jun 2022

RISK: Medium Risk

TYPE: Clients - Browsers

TYPE: Browsers

Multiple vulnerabilities were identified in Microsoft Edge. A remote attacker could exploit some of these vulnerabilities to trigger elevation of privilege, remote code execution, sensitive information disclosure, security restriction bypass and spoofing on the targeted system.


Impact

  • Elevation of Privilege
  • Remote Code Execution
  • Information Disclosure
  • Security Restriction Bypass
  • Spoofing

System / Technologies affected

  • Microsoft Edge prior to 102.0.1245.30

Solutions

Before installation of the software, please visit the software vendor web-site for more details.

Apply fixes issued by the vendor:

  • Update to version 102.0.1245.30

Vulnerability Identifier


Source


Related Link

Mozilla 產品多個漏洞

發佈日期: 2022年06月01日

風險: 中度風險

類型: 用戶端 - 瀏覽器

類型: 瀏覽器

於 Mozilla 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、彷冒、遠端執行任意程式碼、洩露敏感資料、資料篡改及繞過保安限制。


影響

  • 遠端執行程式碼
  • 繞過保安限制
  • 資料洩露
  • 仿冒
  • 阻斷服務
  • 篡改

受影響之系統或技術

以下版本之前的版本﹕

 

  • Firefox 101
  • Firefox ESR 91.10
  • Thunderbird 91.10

解決方案

在安裝軟體之前,請先瀏覽供應商之官方網站,以獲得更多詳細資料。

更新至版本:

 

  • Firefox 101
  • Firefox ESR 91.10
  • Thunderbird 91.10

漏洞識別碼


資料來源


相關連結

Mozilla Products Multiple Vulnerabilities

Release Date: 1 Jun 2022

RISK: Medium Risk

TYPE: Clients - Browsers

TYPE: Browsers

Multiple vulnerabilities were identified in Mozilla Products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, spoofing, remote code execution, sensitive information disclosure, data manipulation and security restriction bypass on the targeted system.


Impact

  • Remote Code Execution
  • Security Restriction Bypass
  • Information Disclosure
  • Spoofing
  • Denial of Service
  • Data Manipulation

System / Technologies affected

Versions prior to:

 

  • Firefox 101
  • Firefox ESR 91.10
  • Thunderbird 91.10

Solutions

Before installation of the software, please visit the vendor web-site for more details.

Apply fixes issued by the vendor:

 

  • Firefox 101
  • Firefox ESR 91.10
  • Thunderbird 91.10

Vulnerability Identifier


Source


Related Link

Apache Tomcat 多個漏洞

Apache Tomcat 多個漏洞 發佈日期: 2026年08月05日 風險: 中度風險 類型: 伺服器 - 網站伺服器 於 Apache T...