2023年12月12日星期二

Apple Products Multiple Vulnerabilities

Release Date: 12 Dec 2023

RISK: Extremely High Risk

TYPE: Operating Systems - Mobile & Apps

TYPE: Mobile & Apps

Multiple vulnerabilities were identified in Apple Products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, spoofing, remote code execution and information disclosure on the targeted system.

 

Note:

For CVE-2023-42916 and CVE-2023-42917, processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.1.


Impact

  • Remote Code Execution
  • Information Disclosure
  • Spoofing
  • Denial of Service

System / Technologies affected

  • Versions prior to iOS 16.7.3 and iPadOS 16.7.3
  • Versions prior to iOS 17.2 and iPadOS 17.2
  • Versions prior to macOS Monterey 12.7.2
  • Versions prior to macOS Ventura 13.6.3
  • Versions prior to macOS Sonoma 14.2
  • Versions prior to Safari 17.2
  • Versions prior to tvOS 17.2
  • Versions prior to watchOS 10.2

Solutions

Before installation of the software, please visit the vendor web-site for more details.

Apply fixes issued by the vendor:

 

  • iOS 16.7.3 and iPadOS 16.7.3
  • iOS 17.2 and iPadOS 17.2
  • macOS Monterey 12.7.2
  • macOS Ventura 13.6.3
  • macOS Sonoma 14.2
  • Safari 17.2
  • tvOS 17.2
  • watchOS 10.2

Vulnerability Identifier


Source


Related Link

Apache Struts 遠端執行程式碼漏洞

發佈日期: 2023年12月11日

風險: 中度風險

類型: 伺服器 - 網站伺服器

類型: 網站伺服器

於 Apache Struts 發現一個漏洞。遠端使用者可利用此漏洞,於目標系統觸發遠端執行任意程式碼。


影響

  • 遠端執行程式碼

受影響之系統或技術

  • Struts 2.0.0 - Struts 2.3.37 (EOL)
  • Struts 2.5.0 - Struts 2.5.32
  • Struts 6.0.0 - Struts 6.3.0

解決方案

在安裝軟體之前,請先瀏覽軟體供應商之網站,以獲得更多詳細資料。

  • 更新至 Struts 2.5.33, Struts 6.3.0.2 或更高版本

漏洞識別碼


資料來源


相關連結

Apache Struts Remote Code Execution Vulnerability

Release Date: 11 Dec 2023

RISK: Medium Risk

TYPE: Servers - Web Servers

TYPE: Web Servers

A vulnerability has been identified in Apache Struts. A remote user can exploit this vulnerability to trigger remote code execution on the targeted system.


Impact

  • Remote Code Execution

System / Technologies affected

  • Struts 2.0.0 - Struts 2.3.37 (EOL)
  • Struts 2.5.0 - Struts 2.5.32
  • Struts 6.0.0 - Struts 6.3.0

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • Upgrade to Struts 2.5.33, Struts 6.3.0.2 or greater

Vulnerability Identifier


Source


Related Link

ChromeOS 多個漏洞

發佈日期: 2023年12月11日

風險: 中度風險

類型: 操作系統 - 其他操作系統

類型: 其他操作系統

於 ChromeOS 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況及遠端執行任意程式碼。


影響

  • 遠端執行程式碼
  • 阻斷服務

受影響之系統或技術

  • 114.0.5735.343 (平台版本: 15437.81.0) 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式,詳情請參閱以下連結:


漏洞識別碼


資料來源


相關連結

ChromeOS Multiple Vulnerabilities

Release Date: 11 Dec 2023

RISK: Medium Risk

TYPE: Operating Systems - Others OS

TYPE: Others OS

Multiple vulnerabilities were identified in ChromeOS. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition and remote code execution on the targeted system.


Impact

  • Remote Code Execution
  • Denial of Service

System / Technologies affected

  • Version prior to 114.0.5735.343 (Platform Version: 15437.81.0)

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor. For detail, please refer to the link below:


Vulnerability Identifier


Source


Related Link

2023年12月9日星期六

Microsoft Edge 多個漏洞

發佈日期: 2023年12月08日

風險: 中度風險

類型: 用戶端 - 瀏覽器

類型: 瀏覽器

於 Microsoft Edge 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發遠端阻斷服務狀況、權限提升、執行任意程式碼及敏感資料洩露。


Microsoft Edge Multiple Vulnerabilities

Release Date: 8 Dec 2023

RISK: Medium Risk

TYPE: Clients - Browsers

TYPE: Browsers

Multiple vulnerabilities were identified in Microsoft Edge.  A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, elevation of privilege, remote code execution and sensitive information disclosure on the targeted system.


2023年12月6日星期三

Google Chrome 多個漏洞

發佈日期: 2023年12月06日

風險: 中度風險

類型: 用戶端 - 瀏覽器

類型: 瀏覽器

於 Google Chrome 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發遠端執行任意程式碼及阻斷服務狀況。

 

影響

  • 遠端執行程式碼
  • 阻斷服務

受影響之系統或技術

  • Google Chrome 120.0.6099.62 (Linux) 之前的版本
  • Google Chrome 120.0.6099.62 (Mac) 之前的版本
  • Google Chrome 120.0.6099.62/.63 (Windows) 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝軟件供應商提供的修補程式:

  • 更新至 120.0.6099.62 (Linux) 或之後版本
  • 更新至 120.0.6099.62 (Mac) 或之後版本
  • 更新至 120.0.6099.62/.63 (Windows) 或之後版本

漏洞識別碼


資料來源


相關連結

Google Chrome Multiple Vulnerabilities

Release Date: 6 Dec 2023

RISK: Medium Risk

TYPE: Clients - Browsers

TYPE: Browsers

Multiple vulnerabilities were identified in Google Chrome.  A remote attacker could exploit some of these vulnerabilities to trigger remote code execution and denial of service condition on the targeted system.


Impact

  • Remote Code Execution
  • Denial of Service

System / Technologies affected

  • Google Chrome prior to 120.0.6099.62 (Linux)
  • Google Chrome prior to 120.0.6099.62 (Mac)
  • Google Chrome prior to 120.0.6099.62/.63 (Windows)

Solutions

Before installation of the software, please visit the software vendor web-site for more details.

Apply fixes issued by the vendor:

  • Update to version 120.0.6099.62 (Linux) or later
  • Update to version 120.0.6099.62 (Mac) or later
  • Update to version 120.0.6099.62/.63 (Windows) or later

Vulnerability Identifier


Source


Related Link

三星產品多個漏洞

發佈日期: 2023年12月06日

風險: 中度風險

類型: 操作系統 - 流動裝置及操作系統

類型: 流動裝置及操作系統

於三星產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發繞過保安限制、權限提升、遠端執行程式碼、篡改及洩露敏感資料。


影響

  • 繞過保安限制
  • 篡改
  • 遠端執行程式碼
  • 權限提升
  • 資料洩露

受影響之系統或技術

  • Android 11, 12, 13, 14

有關受影響產品,請參閱以下連結:

https://security.samsungmobile.com/securityUpdate.smsb


解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。


漏洞識別碼


資料來源


相關連結

Samsung Products Multiple Vulnerabilities

Release Date: 6 Dec 2023

RISK: Medium Risk

TYPE: Operating Systems - Mobile & Apps

TYPE: Mobile & Apps

Multiple vulnerabilities were identified in Samsung Products. A remote attacker could exploit some of these vulnerabilities to trigger security restriction bypass, elevation of privilege, remote code execution, data manipulation and sensitive information disclosure on the targeted system.


Impact

  • Security Restriction Bypass
  • Data Manipulation
  • Remote Code Execution
  • Elevation of Privilege
  • Information Disclosure

System / Technologies affected

  • Android 11, 12, 13, 14

For affected products, please refer to the link below:

https://security.samsungmobile.com/securityUpdate.smsb


Solutions

Before installation of the software, please visit the vendor web-site for more details.


Vulnerability Identifier


Source


Related Link

Android多個漏洞

發佈日期: 2023年12月05日

風險: 中度風險

類型: 操作系統 - 流動裝置及操作系統

類型: 流動裝置及操作系統

於 Android 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、權限提升、遠端執行程式碼及洩露敏感資料。


Android Multiple Vulnerabilities

Release Date: 5 Dec 2023

RISK: Medium Risk

TYPE: Operating Systems - Mobile & Apps

TYPE: Mobile & Apps

Multiple vulnerabilities were identified in Android. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, elevation of privilege, remote code execution and sensitive information disclosure on the targeted system.


2023年12月1日星期五

蘋果產品多個漏洞

發佈日期: 2023年12月01日

風險: 極高度風險

類型: 操作系統 - 流動裝置及操作系統

類型: 流動裝置及操作系統

於蘋果產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發遠端執行任意程式碼及資料洩露。

 

注意:

對於 CVE-2023-42916及CVE-2023-42917,處理網頁內容時可能導致任意代碼執行。蘋果知悉有報告指出,這個問題可能已在 iOS 16.7.1 之前的 iOS 版本中被廣泛利用。

 

影響

  • 遠端執行程式碼
  • 資料洩露

受影響之系統或技術

  • Safari 17.1.2 以前的版本
  • iOS 17.1.2 以前的版本
  • iPadOS 17.1.2 以前的版本
  • macOS Sonoma 14.1.2 以前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝供應商提供的修補程式:

 

  • Safari 17.1.2
  • iOS 17.1.2
  • iPadOS 17.1.2
  • macOS Sonoma 14.1.2
 

漏洞識別碼


資料來源


相關連結

Apple Products Multiple Vulnerabilities

Release Date: 1 Dec 2023

RISK: Extremely High Risk

TYPE: Operating Systems - Mobile & Apps

TYPE: Mobile & Apps

Multiple vulnerabilities were identified in Apple Products. A remote attacker could exploit some of these vulnerabilities to trigger  remote code execution and information disclosure on the targeted system.

 

Note:

For CVE-2023-42916 and CVE-2023-42917, processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.1.


Impact

  • Remote Code Execution
  • Information Disclosure

System / Technologies affected

  • Versions prior to Safari Safari 17.1.2
  • Versions prior to iOS 17.1.2
  • Versions prior to iPadOS 17.1.2
  • Versions prior to macOS Sonoma 14.1.2

Solutions

Before installation of the software, please visit the vendor web-site for more details.

Apply fixes issued by the vendor:

 

  • Safari 17.1.2
  • iOS 17.1.2
  • iPadOS 17.1.2
  • macOS Sonoma 14.1.2

Vulnerability Identifier


Source


Related Link

Ubuntu Linux 核心多個漏洞

發佈日期: 2023年12月01日

風險: 中度風險

類型: 操作系統 - LINUX

類型: LINUX

於 Ubuntu 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、遠端執行任意程式碼、權限提升及敏感資料洩露。

 

影響

  • 阻斷服務
  • 遠端執行程式碼
  • 資料洩露
  • 權限提升

受影響之系統或技術

  • Ubuntu 14.04 ESM
  • Ubuntu 16.04 ESM
  • Ubuntu 18.04 ESM
  • Ubuntu 20.04 LTS
  • Ubuntu 22.04 LTS
  • Ubuntu 23.04
 

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

Ubuntu Linux Kernel Multiple Vulnerabilities

Release Date: 1 Dec 2023

RISK: Medium Risk

TYPE: Operating Systems - Linux

TYPE: Linux

Multiple vulnerabilities were identified in Ubuntu Products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, remote code execution, elevation of privilege and sensitive information disclosure on the targeted system.


Impact

  • Denial of Service
  • Remote Code Execution
  • Information Disclosure
  • Elevation of Privilege

System / Technologies affected

  • Ubuntu 14.04 ESM
  • Ubuntu 16.04 ESM
  • Ubuntu 18.04 ESM
  • Ubuntu 20.04 LTS
  • Ubuntu 22.04 LTS
  • Ubuntu 23.04
 

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

Microsoft Edge 多個漏洞

發佈日期: 2023年11月30日

風險: 極高度風險

類型: 用戶端 - 瀏覽器

類型: 瀏覽器

於 Microsoft Edge 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發繞過保安限制、篡改、遠端執行任意程式碼及阻斷服務狀況。

 

注意:

對於CVE-2023-6345,Skia(開源 2D 圖像函式庫)整數溢出,可以導致遠端執行任意程式碼。Google 獲悉有報告指出此問題可能已被廣泛利用。


影響

  • 遠端執行程式碼
  • 阻斷服務
  • 篡改
  • 繞過保安限制

受影響之系統或技術

  • Microsoft Edge (Stable) 119.0.2151.97 之前的版本
  • Microsoft Edge (Extended Stable) 118.0.2088.122 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝軟件供應商提供的修補程式:

  • 更新至 Microsoft Edge (Stable) 119.0.2151.97 或之後版本
  • 更新至 Microsoft Edge (Extended Stable) 118.0.2088.122 或之後版本

漏洞識別碼


資料來源


相關連結

Microsoft Edge Multiple Vulnerabilities

Release Date: 30 Nov 2023

RISK: Extremely High Risk

TYPE: Clients - Browsers

TYPE: Browsers

Multiple vulnerabilities were identified in Microsoft Edge. A remote attacker could exploit some of these vulnerabilities to trigger security restriction bypass, data manipulation, remote code execution and denial of service condition on the targeted system.

 

Note:

For CVE-2023-6345, Integer overflow in Skia (open-source 2D graphics library), the vulnerability could result in remote code execution. Google is aware of a report that this issue may have been exploited in the wild.


Impact

  • Remote Code Execution
  • Denial of Service
  • Data Manipulation
  • Security Restriction Bypass

System / Technologies affected

  • Microsoft Edge (Stable) prior to 119.0.2151.97
  • Microsoft Edge (Extended Stable) prior to 118.0.2088.122

Solutions

Before installation of the software, please visit the software vendor web-site for more details.

Apply fixes issued by the vendor:

  • Update to Microsoft Edge (Stable) version 119.0.2151.97 or later
  • Update to Microsoft Edge (Extended Stable) version 118.0.2088.122 or later

Vulnerability Identifier


Source


Related Link

Google Chrome 多個漏洞

發佈日期: 2023年11月29日

風險: 極高度風險

類型: 用戶端 - 瀏覽器

類型: 瀏覽器

於 Google Chrome 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發繞過保安限制、篡改、遠端執行任意程式碼及阻斷服務狀況。

 

注意:

對於CVE-2023-6345,Skia(開源 2D 圖像函式庫)整數溢出,可以導致遠端執行任意程式碼。Google在報告指出,這個問題可能已在 119.0.6045.199 之前的 Chrome 版本中被廣泛利用。

 

影響

  • 遠端執行程式碼
  • 阻斷服務
  • 繞過保安限制
  • 篡改

受影響之系統或技術

  • Google Chrome 119.0.6045.199 (Linux) 之前的版本
  • Google Chrome 119.0.6045.199 (Mac) 之前的版本
  • Google Chrome 119.0.6045.199/.200 (Windows) 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝軟件供應商提供的修補程式:

  • 更新至 119.0.6045.199 (Linux) 或之後版本
  • 更新至 119.0.6045.199 (Mac) 或之後版本
  • 更新至 119.0.6045.199/.200 (Windows) 或之後版本

漏洞識別碼


資料來源


相關連結

Google Chrome Multiple Vulnerabilities

Release Date: 29 Nov 2023

RISK: Extremely High Risk

TYPE: Clients - Browsers

TYPE: Browsers

Multiple vulnerabilities were identified in Google Chrome.  A remote attacker could exploit some of these vulnerabilities to trigger security restriction bypass, data manipulation, remote code execution and denial of service condition on the targeted system.

 

Note:

For CVE-2023-6345, Integer overflow in Skia (open-source 2D graphics library), the vulnerability could result in remote code execution. Google is aware of a report that this issue may have been exploited in the wild against versions of Chrome before 119.0.6045.199.


Impact

  • Remote Code Execution
  • Denial of Service
  • Security Restriction Bypass
  • Data Manipulation

System / Technologies affected

  • Google Chrome prior to 119.0.6045.199 (Linux)
  • Google Chrome prior to 119.0.6045.199 (Mac)
  • Google Chrome prior to 119.0.6045.199/.200 (Windows)

Solutions

Before installation of the software, please visit the software vendor web-site for more details.

Apply fixes issued by the vendor:

  • Update to version 119.0.6045.199 (Linux) or later
  • Update to version 119.0.6045.199 (Mac) or later
  • Update to version 119.0.6045.199/.200 (Windows) or later

Vulnerability Identifier


Source


Related Link

Apache Tomcat 多個漏洞

Apache Tomcat 多個漏洞 發佈日期: 2026年08月05日 風險: 中度風險 類型: 伺服器 - 網站伺服器 於 Apache T...