2024年7月2日星期二

Debian Linux 內核多個漏洞

發佈日期: 2024年07月02日

風險: 中度風險

類型: 操作系統 - LINUX

於 Debian Linux 內核發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、權限提升及洩露敏感資料。

 


影響

  • 權限提升
  • 資料洩露
  • 阻斷服務

受影響之系統或技術

  • Debian 10 buster  5.10.218-1 以前的版本
  • Debian 10 buster 4.19.316-1 以前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

Debian Linux Kernel Multiple Vulnerabilities

Release Date: 2 Jul 2024

RISK: Medium Risk

TYPE: Operating Systems - Linux

Multiple vulnerabilities were identified in Debian Linux Kernel. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, elevation of privilege and sensitive information disclosure on the targeted system.

 


Impact

  • Elevation of Privilege
  • Information Disclosure
  • Denial of Service

System / Technologies affected

  • Debian 10 buster versions prior to 5.10.218-1
  • Debian 10 buster versions prior to 4.19.316-1

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

三星產品多個漏洞

發佈日期: 2024年07月02日

風險: 中度風險

類型: 操作系統 - 流動裝置及操作系統

於三星產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、權限提升、遠端執行任意程式碼、洩露敏感資料、資料篡改及繞過保安限制。


影響

  • 遠端執行程式碼
  • 阻斷服務
  • 權限提升
  • 資料洩露
  • 繞過保安限制
  • 篡改

受影響之系統或技術

  • Exynos 9820, Exynos 9825, Exynos 980, Exynos 990, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 9110, Exynos W920, Exynos W930, Exynos Modem 5123, Exynos Modem 5300

有關受影響產品,請參閱以下連結:

https://semiconductor.samsung.com/support/quality-support/product-security-updates/


解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。


漏洞識別碼


資料來源


相關連結

Samsung Products Multiple Vulnerabilities

Release Date: 2 Jul 2024

RISK: Medium Risk

TYPE: Operating Systems - Mobile & Apps

Multiple vulnerabilities were identified in Samsung Products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, elevation of privilege, remote code execution, sensitive information disclosure, data manipulation and security restriction bypass on the targeted system.


Impact

  • Remote Code Execution
  • Denial of Service
  • Elevation of Privilege
  • Information Disclosure
  • Security Restriction Bypass
  • Data Manipulation

System / Technologies affected

  • Exynos 9820, Exynos 9825, Exynos 980, Exynos 990, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 9110, Exynos W920, Exynos W930, Exynos Modem 5123, Exynos Modem 5300

For affected products, please refer to the link below:

https://semiconductor.samsung.com/support/quality-support/product-security-updates/


Solutions

Before installation of the software, please visit the vendor web-site for more details.


Vulnerability Identifier


Source


Related Link

2024年7月1日星期一

GitLab 多個漏洞

發佈日期: 2024年06月28日

風險: 中度風險

類型: 伺服器 - 其他伺服器

於 GitLab 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、權限提升、遠端執行任意程式碼、洩露敏感資料、資料篡改、跨網站指令碼及繞過保安限制。

 

影響

  • 遠端執行程式碼
  • 阻斷服務
  • 資料洩露
  • 權限提升
  • 繞過保安限制
  • 篡改
  • 跨網站指令碼

受影響之系統或技術

  • GitLab Community Edition (CE) 17.1.1, 17.0.3 及 16.11.5 以前的版本
  • GitLab Enterprise Edition (EE) 17.1.1, 17.0.3 及 16.11.5 以前的版本
 

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

GitLab Multiple Vulnerabilities

Release Date: 28 Jun 2024

RISK: Medium Risk

TYPE: Servers - Other Servers

Multiple vulnerabilities were identified in GitLab. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, elevation of privilege, remote code execution, sensitive information disclosure, data manipulation, cross-site scripting and security restriction bypass on the targeted system.


Impact

  • Remote Code Execution
  • Denial of Service
  • Information Disclosure
  • Elevation of Privilege
  • Security Restriction Bypass
  • Data Manipulation
  • Cross-Site Scripting

System / Technologies affected

  • GitLab Community Edition (CE) versions prior to 17.1.1, 17.0.3, and 16.11.5
  • GitLab Enterprise Edition (EE) versions prior to 17.1.1, 17.0.3, and 16.11.5

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

Microsoft Edge 多個漏洞

發佈日期: 2024年06月28日

風險: 中度風險

類型: 用戶端 - 瀏覽器

於 Microsoft Edge 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況及遠端執行任意程式碼。


影響

  • 遠端執行程式碼
  • 阻斷服務

受影響之系統或技術

  • Microsoft Edge (Stable) 126.0.2592.81 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝軟件供應商提供的修補程式:

  • 更新至 Microsoft Edge (Stable) 126.0.2592.81 或之後版本

漏洞識別碼


資料來源


相關連結

Microsoft Edge Multiple Vulnerabilities

Release Date: 28 Jun 2024

RISK: Medium Risk

TYPE: Clients - Browsers

Multiple vulnerabilities were identified in Microsoft Edge. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition and remote code execution on the targeted system.


Impact

  • Remote Code Execution
  • Denial of Service

System / Technologies affected

  • Microsoft Edge (Stable) prior to 126.0.2592.81

Solutions

Before installation of the software, please visit the software vendor web-site for more details.

Apply fixes issued by the vendor:

  • Update to Microsoft Edge (Stable) version 126.0.2592.81 or later

Vulnerability Identifier


Source


Related Link

ChromeOS 多個漏洞

發佈日期: 2024年06月27日

風險: 中度風險

類型: 操作系統 - 其他操作系統

於 ChromeOS 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、遠端執行任意程式碼及洩露敏感資料。


影響

  • 遠端執行程式碼
  • 阻斷服務
  • 資料洩露

受影響之系統或技術

  • 120.0.6099.315 (平台版本: 15662.112) 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式,詳情請參閱以下連結:


漏洞識別碼


資料來源


相關連結

ChromeOS Multiple Vulnerabilities

Release Date: 27 Jun 2024

RISK: Medium Risk

TYPE: Operating Systems - Others OS

Multiple vulnerabilities were identified in ChromeOS. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, remote code execution and sensitive information disclosure on the targeted system.


Impact

  • Remote Code Execution
  • Denial of Service
  • Information Disclosure

System / Technologies affected

  • Version prior to 120.0.6099.315 (Platform Version: 15662.112)

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor. For detail, please refer to the link below:


Vulnerability Identifier


Source


Related Link

MOVEit 產品繞過保安限制漏洞

發佈日期: 2024年06月27日

風險: 中度風險

類型: 用戶端 - 辦公室應用

於MOVEit產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發繞過保安限制。

 

注意:

CVE-2024-5806的概念驗證碼已被公開。CVE-2024-5806 漏洞需要攻擊者必須知道受攻擊系統上的有效用戶。因此,整體風險程度為中度風險。

 

影響

  • 繞過保安限制

受影響之系統或技術

  • MOVEit Gateway 2024.0.0
  • MOVEit Transfer 從 2023.0.0 至 2023.0.11 之前
  • MOVEit Transfer 從 2023.1.0 至 2023.1.6 之前
  • MOVEit Transfer 從 2024.0.0 至 2024.0.2 之前

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝軟件供應商提供的修補程式:

  • 更新至 MOVEit Gateway 2024.0.1
  • 更新至 MOVEit Transfer 2023.0.11
  • 更新至 MOVEit Transfer 2023.1.6
  • 更新至 MOVEit Transfer 2024.0.2
 

漏洞識別碼


資料來源


相關連結

MOVEit Products Security Restriction Bypass Vulnerabilities

Release Date: 27 Jun 2024

RISK: Medium Risk

TYPE: Clients - Productivity Products

Multiple vulnerabilities were identified in MOVEit Products. A remote attacker could exploit some of these vulnerabilities to trigger security restriction bypass on the targeted system.

 

Note:

Proof of concept exploit for CVE-2024-5806 exists on the internet.

To exploit the vulnerability, attackers must have knowledge of a valid users on the vulnerable system. Hence, the risk level is rated to Medium Risk.


Impact

  • Security Restriction Bypass

System / Technologies affected

  • MOVEit Gateway 2024.0.0
  • MOVEit Transfer from 2023.0.0 before 2023.0.11
  • MOVEit Transfer from 2023.1.0 before 2023.1.6
  • MOVEit Transfer from 2024.0.0 before 2024.0.2

Solutions

Before installation of the software, please visit the software vendor web-site for more details.

Apply fixes issued by the vendor:

  • Update to version MOVEit Gateway 2024.0.1
  • Update to version MOVEit Transfer 2023.0.11
  • Update to version MOVEit Transfer 2023.1.6
  • Update to version MOVEit Transfer 2024.0.2
 

Vulnerability Identifier


Source


Related Link

Apache Tomcat 多個漏洞

Apache Tomcat 多個漏洞 發佈日期: 2026年08月05日 風險: 中度風險 類型: 伺服器 - 網站伺服器 於 Apache T...