2023年7月12日星期三

Ubuntu Linux 核心多個漏洞

發佈日期: 2023年07月10日

風險: 中度風險

類型: 操作系統 - LINUX

類型: LINUX

於 Ubuntu 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、遠端執行任意程式碼及洩露敏感資料。


影響

  • 阻斷服務
  • 遠端執行程式碼
  • 資料洩露

受影響之系統或技術

  • Ubuntu 18.04 ESM
  • Ubuntu 20.04 LTS
  • Ubuntu 22.04 LTS
  • Ubuntu 22.10
  • Ubuntu 23.04

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

Ubuntu Linux Kernel Multiple Vulnerabilities

Release Date: 10 Jul 2023

RISK: Medium Risk

TYPE: Operating Systems - Linux

TYPE: Linux

Multiple vulnerabilities were identified in Ubuntu Products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, remote code execution and sensitive information disclosure on the targeted system.


Impact

  • Denial of Service
  • Remote Code Execution
  • Information Disclosure

System / Technologies affected

  • Ubuntu 18.04 ESM
  • Ubuntu 20.04 LTS
  • Ubuntu 22.04 LTS
  • Ubuntu 22.10
  • Ubuntu 23.04

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

2023年7月7日星期五

Debian Linux 內核多個漏洞

發佈日期: 2023年07月07日

風險: 中度風險

類型: 操作系統 - LINUX

類型: LINUX

於 Debian Linux 內核發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、權限提升、遠端執行程式碼及洩露敏感資料。


影響

  • 阻斷服務
  • 權限提升
  • 資料洩露
  • 遠端執行程式碼

受影響之系統或技術

  • Debian  6.1.37-1 以前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

Debian Linux Kernel Multiple Vulnerabilities

Release Date: 7 Jul 2023

RISK: Medium Risk

TYPE: Operating Systems - Linux

TYPE: Linux

Multiple vulnerabilities were identified in Debian Linux Kernel. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, elevation of privilege, remote code execution and sensitive information disclosure on the targeted system.


Impact

  • Denial of Service
  • Elevation of Privilege
  • Information Disclosure
  • Remote Code Execution

System / Technologies affected

  • Debian versions prior to  6.1.37-1

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

三星產品多個漏洞

發佈日期: 2023年07月07日

風險: 高度風險

類型: 操作系統 - 流動裝置及操作系統

類型: 流動裝置及操作系統

於三星產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發權限提升、遠端執行程式碼、篡改及洩露敏感資料。

 

注意:

CVE-2023-2136 可能受到有限的、有針對性的利用。該漏洞影響Android系統中使用的Skia 2D圖形庫。


影響

  • 權限提升
  • 資料洩露
  • 遠端執行程式碼
  • 篡改
  • 繞過保安限制

受影響之系統或技術

  • Android 11, 12, 13

 

有關受影響產品,請參閱以下連結:

https://security.samsungmobile.com/securityUpdate.smsb


解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。


漏洞識別碼

 

資料來源


相關連結

Samsung Products Multiple Vulnerabilities

Release Date: 7 Jul 2023

RISK: High Risk

TYPE: Operating Systems - Mobile & Apps

TYPE: Mobile & Apps

Multiple vulnerabilities were identified in Samsung Products. A remote attacker could exploit some of these vulnerabilities to trigger elevation of privilege, remote code execution, data manipulation and sensitive information disclosure on the targeted system.

 

Note:

CVE-2023-2136 may be under limited, targeted exploitation. The vulnerability is affecting the Skia 2D graphics library used in Android systems.


Impact

  • Elevation of Privilege
  • Information Disclosure
  • Remote Code Execution
  • Data Manipulation
  • Security Restriction Bypass

System / Technologies affected

  • Android 11, 12, 13

 

For affected products, please refer to the link below:

https://security.samsungmobile.com/securityUpdate.smsb


Solutions

Before installation of the software, please visit the vendor web-site for more details.


Vulnerability Identifier

 

Source


Related Link

2023年7月6日星期四

Android多個漏洞

發佈日期: 2023年07月06日

風險: 高度風險

類型: 操作系統 - 流動裝置及操作系統

類型: 流動裝置及操作系統

於 Android 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、權限提升、遠端執行任意程式碼及洩露敏感資料。

 

注意:

CVE-2023-2136 可能受到有限的、有針對性的利用。該漏洞影響Android系統中使用的Skia 2D圖形庫。


Android Multiple Vulnerabilities

Release Date: 6 Jul 2023

RISK: High Risk

TYPE: Operating Systems - Mobile & Apps

TYPE: Mobile & Apps

Multiple vulnerabilities were identified in Android. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, elevation of privilege, remote code execution and sensitive information disclosure on the targeted system.

 

Note:

CVE-2023-2136 may be under limited, targeted exploitation. The vulnerability is affecting the Skia 2D graphics library used in Android systems.


Impact

  • Denial of Service
  • Remote Code Execution
  • Elevation of Privilege
  • Information Disclosure

System / Technologies affected

  • Android security patch level prior to 2023-07-05

Solutions

Before installation of the software, please visit the vendor web-site for more details.


Vulnerability Identifier


Source


Related Link

2023年7月5日星期三

Mozilla 產品多個漏洞

發佈日期: 2023年07月05日

風險: 中度風險

類型: 用戶端 - 瀏覽器

類型: 瀏覽器

於 Mozilla 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發仿冒、資料篡改、阻斷服務、遠端執行任意程式碼及繞過保安限制。

 

影響

  • 遠端執行程式碼
  • 繞過保安限制
  • 阻斷服務
  • 仿冒
  • 篡改

受影響之系統或技術

以下版本之前的版本﹕

 

  • Firefox 115
  • Firefox ESR 102.13
  • Thunderbird 102.13
 

解決方案

在安裝軟體之前,請先瀏覽供應商之官方網站,以獲得更多詳細資料。

更新至版本:

 

  • Firefox 115
  • Firefox ESR 102.13
  • Thunderbird 102.13
 

漏洞識別碼


資料來源


相關連結

Mozilla Products Multiple Vulnerabilities

Release Date: 5 Jul 2023

RISK: Medium Risk

TYPE: Clients - Browsers

TYPE: Browsers

Multiple vulnerabilities were identified in Mozilla Products. A remote attacker could exploit some of these vulnerabilities to trigger spoofing, data manipulation, denial of service, remote code execution and security restriction bypass on the targeted system.


Impact

  • Remote Code Execution
  • Security Restriction Bypass
  • Denial of Service
  • Spoofing
  • Data Manipulation

System / Technologies affected

Versions prior to:

 

  • Firefox 115
  • Firefox ESR 102.13
  • Thunderbird 102.13
 

Solutions

Before installation of the software, please visit the vendor web-site for more details.

Apply fixes issued by the vendor:

 

  • Firefox 115
  • Firefox ESR 102.13
  • Thunderbird 102.13

Vulnerability Identifier


Source


Related Link

2023年7月3日星期一

GitLab 多個漏洞

發佈日期: 2023年07月03日

風險: 中度風險

類型: 伺服器 - 其他伺服器

類型: 其他伺服器

於 GitLab 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、遠端執行任意程式碼、洩露敏感資料、資料篡改及繞過保安限制。

 

影響

  • 資料洩露
  • 遠端執行程式碼
  • 繞過保安限制
  • 阻斷服務
  • 篡改

受影響之系統或技術

  • GitLab Community Edition (CE) 16.1.1, 16.0.6 及 15.11.10 以前的版本
  • GitLab Enterprise Edition (EE) 16.1.1, 16.0.6 及 15.11.10 以前的版本
 

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

GitLab Multiple Vulnerabilities

Release Date: 3 Jul 2023

RISK: Medium Risk

TYPE: Servers - Other Servers

TYPE: Other Servers

Multiple vulnerabilities were identified in GitLab. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, remote code execution, sensitive information disclosure, data manipulation and security restriction bypass on the targeted system.


Impact

  • Information Disclosure
  • Remote Code Execution
  • Security Restriction Bypass
  • Denial of Service
  • Data Manipulation

System / Technologies affected

  • GitLab Community Edition (CE) versions prior to 16.1.1, 16.0.6, and 15.11.10
  • GitLab Enterprise Edition (EE) versions prior to 16.1.1, 16.0.6, and 15.11.10

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

SUSE Linux 內核多個漏洞

發佈日期: 2023年07月03日

風險: 中度風險

類型: 操作系統 - LINUX

類型: LINUX

於 SUSE Linux 內核發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、權限提升、遠端執行任意程式碼及資料篡改。

 

影響

  • 阻斷服務
  • 權限提升
  • 遠端執行程式碼
  • 篡改

受影響之系統或技術

  • SUSE Linux Enterprise High Performance Computing 15 SP2
  • SUSE Linux Enterprise High Performance Computing 15 SP3
  • SUSE Linux Enterprise High Performance Computing 12 SP4
  • SUSE Linux Enterprise Live Patching 12-SP4
  • SUSE Linux Enterprise Live Patching 15-SP2
  • SUSE Linux Enterprise Live Patching 15-SP3
  • SUSE Linux Enterprise Micro 5.1
  • SUSE Linux Enterprise Micro 5.2
  • SUSE Linux Enterprise Server 12 SP4
  • SUSE Linux Enterprise Server 15 SP2
  • SUSE Linux Enterprise Server 15 SP3
  • SUSE Linux Enterprise Server for SAP Applications 12 SP4
  • SUSE Linux Enterprise Server for SAP Applications 15 SP2
  • SUSE Linux Enterprise Server for SAP Applications 15 SP3

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

SUSE Linux Kernel Multiple Vulnerabilities

Release Date: 3 Jul 2023

RISK: Medium Risk

TYPE: Operating Systems - Linux

TYPE: Linux

Multiple vulnerabilities were identified in SUSE Linux Kernel. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, elevation of privilege, remote code execution and data manipulation on the targeted system.


Impact

  • Denial of Service
  • Elevation of Privilege
  • Remote Code Execution
  • Data Manipulation

System / Technologies affected

  • SUSE Linux Enterprise High Performance Computing 15 SP2
  • SUSE Linux Enterprise High Performance Computing 15 SP3
  • SUSE Linux Enterprise High Performance Computing 12 SP4
  • SUSE Linux Enterprise Live Patching 12-SP4
  • SUSE Linux Enterprise Live Patching 15-SP2
  • SUSE Linux Enterprise Live Patching 15-SP3
  • SUSE Linux Enterprise Micro 5.1
  • SUSE Linux Enterprise Micro 5.2
  • SUSE Linux Enterprise Server 12 SP4
  • SUSE Linux Enterprise Server 15 SP2
  • SUSE Linux Enterprise Server 15 SP3
  • SUSE Linux Enterprise Server for SAP Applications 12 SP4
  • SUSE Linux Enterprise Server for SAP Applications 15 SP2
  • SUSE Linux Enterprise Server for SAP Applications 15 SP3

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

Synology 產品多個漏洞

發佈日期: 2023年07月03日

風險: 中度風險

類型: 伺服器 - 其他伺服器

類型: 其他伺服器

於 Synology 產品發現多個漏洞,遠端攻擊者可利用這些漏洞,於目標系統觸發遠端執行任意程式碼。

 

影響

  • 遠端執行程式碼

受影響之系統或技術

  • Mail Station for DSM 7.2
  • Mail Station for DSM 7.1
  • Mail Station for DSM 7.0
  • Mail Station for DSM 6.2
 

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼

  • N/A
 

資料來源


相關連結

Synology Products Multiple Vulnerabilities

Release Date: 3 Jul 2023

RISK: Medium Risk

TYPE: Servers - Other Servers

TYPE: Other Servers

Multiple vulnerabilities were identified in Synology products. A remote attacker could exploit some of these vulnerabilities to trigger remote code execution on the targeted system.


Impact

  • Remote Code Execution

System / Technologies affected

  • Mail Station for DSM 7.2
  • Mail Station for DSM 7.1
  • Mail Station for DSM 7.0
  • Mail Station for DSM 6.2

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier

  • N/A
 

Source


Related Link

Apache Tomcat 多個漏洞

Apache Tomcat 多個漏洞 發佈日期: 2026年08月05日 風險: 中度風險 類型: 伺服器 - 網站伺服器 於 Apache T...