2024年12月11日星期三

Adobe 每月保安更新 (2024年12月)

發佈日期: 2024年12月11日

風險: 中度風險

類型: 用戶端 - 辦公室應用

Adobe已為產品提供本月保安更新:

 

受影響產品風險程度影響備註詳情(包括 CVE)
Adobe Experience Manager中度風險 中度風險遠端執行程式碼
跨網站指令碼
繞過保安限制
 APSB24-69
Adobe Acrobat and Reader中度風險 中度風險遠端執行程式碼
阻斷服務
資料洩露
 APSB24-92
Adobe Media Encoder中度風險 中度風險遠端執行程式碼
阻斷服務
 APSB24-93
Adobe Illustrator中度風險 中度風險遠端執行程式碼 APSB24-94
Adobe After Effects中度風險 中度風險資料洩露 APSB24-95
Adobe Animate中度風險 中度風險遠端執行程式碼 APSB24-96
Adobe InDesign中度風險 中度風險遠端執行程式碼
資料洩露
阻斷服務
 APSB24-97
Adobe PDFL Software Development Kit (SDK)中度風險 中度風險遠端執行程式碼 APSB24-98
Adobe Connect中度風險 中度風險跨網站指令碼
遠端執行程式碼
權限提升
繞過保安限制
 APSB24-99
Substance 3D Sampler中度風險 中度風險遠端執行程式碼 APSB24-100
Adobe Photoshop中度風險 中度風險遠端執行程式碼 APSB24-101
Substance 3D Modeler中度風險 中度風險遠端執行程式碼
阻斷服務
 APSB24-102
Adobe Bridge中度風險 中度風險遠端執行程式碼 APSB24-103
Adobe Premiere Pro中度風險 中度風險遠端執行程式碼 APSB24-104
Substance 3D Painter中度風險 中度風險遠端執行程式碼 APSB24-105
Adobe FrameMaker中度風險 中度風險遠端執行程式碼 APSB24-106

 

「極高度風險」產品數目:0

「高度風險」產品數目:0

「中度風險」產品數目:16

「低度風險」產品數目:0

整體「風險程度」評估:中度風險


影響

  • 遠端執行程式碼
  • 跨網站指令碼
  • 繞過保安限制
  • 阻斷服務
  • 資料洩露
  • 權限提升

受影響之系統或技術

  • Adobe Experience Manager (AEM) AEM Cloud Service (CS)
  • Adobe Experience Manager (AEM) 6.5.21 及以前版本
  • Acrobat DC 24.005.20307 及以前版本
  • Acrobat Reader DC 24.005.20307 及以前版本
  • Acrobat 2024 24.001.30213 及以前版本
  • Acrobat 2020 20.005.30730 及以前版本
  • Acrobat Reader 2020 20.005.30730 及以前版本
  • Adobe Media Encoder 24.6.3 及以前版本
  • Adobe Media Encoder 25.0 及以前版本
  • Illustrator 2025 29.0.0 及以前版本
  • Illustrator 2024 28.7.2 及以前版本
  • Adobe After Effects 24.6.2 及以前版本
  • Adobe After Effects 25.0.1 及以前版本
  • Adobe Animate 2023 23.0.8 及以前版本
  • Adobe Animate 2024 24.0.5 及以前版本
  • Adobe InDesign ID19.5 及以前版本
  • Adobe InDesign ID18.5.4 及以前版本
  • Adobe PDFL Software Development Kit (SDK) PDFL SDK 21.0.0.5 及以前版本
  • Adobe Connect 12.6  及以前版本
  • Adobe Connect 11.4.7 及以前版本
  • Adobe Substance 3D Sampler 4.5.1 及以前版本
  • Photoshop 2025 26.0 及以前版本
  • Adobe Substance 3D Modeler 1.14.1 及以前版本
  • Adobe Bridge  14.1.3 及以前版本
  • Adobe Bridge  15.0 及以前版本
  • Adobe Premiere Pro 25.0 及以前版本
  • Adobe Premiere Pro 24.6.3 及以前版本
  • Adobe Substance 3D Painter 10.1.1 及以前版本
  • Adobe FrameMaker 2020 Release Update 7 及以前版本
  • Adobe FrameMaker 2022 Release Update 5 及以前版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

  • 安裝供應商提供的修補程式。個別產品詳情可參考上表「詳情」一欄或執行軟件更新。

漏洞識別碼


資料來源


相關連結

Adobe Monthly Security Update (December 2024)

Release Date: 11 Dec 2024

RISK: Medium Risk

TYPE: Clients - Productivity Products

Adobe has released monthly security update for their products:

 

Vulnerable ProductRisk LevelImpactsNotesDetails (including CVE)
Adobe Experience ManagerMedium Risk Medium RiskRemote Code Execution
Cross-site Scripting
Security Restriction Bypass
 APSB24-69
Adobe Acrobat and ReaderMedium Risk Medium RiskRemote Code Execution
Denial of Service
Information Disclosure
 APSB24-92
Adobe Media EncoderMedium Risk Medium RiskRemote Code Execution
Denial of Service
 APSB24-93
Adobe IllustratorMedium Risk Medium RiskRemote Code Execution APSB24-94
Adobe After EffectsMedium Risk Medium RiskInformation Disclosure APSB24-95
Adobe AnimateMedium Risk Medium RiskRemote Code Execution APSB24-96
Adobe InDesignMedium Risk Medium RiskRemote Code Execution
Information Disclosure
Denial of Service
 APSB24-97
Adobe PDFL Software Development Kit (SDK)Medium Risk Medium RiskRemote Code Execution APSB24-98
Adobe ConnectMedium Risk Medium RiskCross-site Scripting
Remote Code Execution
Elevation of Privilege
Security Restriction Bypass
 APSB24-99
Substance 3D SamplerMedium Risk Medium RiskRemote Code Execution APSB24-100
Adobe PhotoshopMedium Risk Medium RiskRemote Code Execution APSB24-101
Substance 3D ModelerMedium Risk Medium RiskRemote Code Execution
Denial of Service
 APSB24-102
Adobe BridgeMedium Risk Medium RiskRemote Code Execution APSB24-103
Adobe Premiere ProMedium Risk Medium RiskRemote Code Execution APSB24-104
Substance 3D PainterMedium Risk Medium RiskRemote Code Execution APSB24-105
Adobe FrameMakerMedium Risk Medium RiskRemote Code Execution APSB24-106

 

Number of 'Extremely High Risk' product(s): 0

Number of 'High Risk' product(s): 0

Number of 'Medium Risk' product(s): 16

Number of 'Low Risk' product(s): 0

Evaluation of overall 'Risk Level': Medium Risk


Impact

  • Remote Code Execution
  • Cross-Site Scripting
  • Security Restriction Bypass
  • Denial of Service
  • Information Disclosure
  • Elevation of Privilege

System / Technologies affected

  • Adobe Experience Manager (AEM) AEM Cloud Service (CS)
  • Adobe Experience Manager (AEM) 6.5.21 and earlier versions
  • Acrobat DC 24.005.20307 and earlier versions
  • Acrobat Reader DC 24.005.20307 and earlier versions
  • Acrobat 2024 24.001.30213 and earlier versions
  • Acrobat 2020 20.005.30730 and earlier versions
  • Acrobat Reader 2020 20.005.30730 and earlier versions
  • Adobe Media Encoder 24.6.3 and earlier versions
  • Adobe Media Encoder 25.0 and earlier versions
  • Illustrator 2025 29.0.0 and earlier versions
  • Illustrator 2024 28.7.2 and earlier versions
  • Adobe After Effects 24.6.2 and earlier versions
  • Adobe After Effects 25.0.1 and earlier versions
  • Adobe Animate 2023 23.0.8 and earlier versions
  • Adobe Animate 2024 24.0.5 and earlier versions
  • Adobe InDesign ID19.5 and earlier versions
  • Adobe InDesign ID18.5.4 and earlier versions
  • Adobe PDFL Software Development Kit (SDK) PDFL SDK 21.0.0.5 and earlier versions
  • Adobe Connect 12.6  and earlier versions
  • Adobe Connect 11.4.7 and earlier versions
  • Adobe Substance 3D Sampler 4.5.1 and earlier versions
  • Photoshop 2025 26.0 and earlier versions
  • Adobe Substance 3D Modeler 1.14.1 and earlier versions
  • Adobe Bridge  14.1.3 and earlier versions
  • Adobe Bridge  15.0 and earlier versions
  • Adobe Premiere Pro 25.0 and earlier versions
  • Adobe Premiere Pro 24.6.3 and earlier versions
  • Adobe Substance 3D Painter 10.1.1 and earlier versions
  • Adobe FrameMaker 2020 Release Update 7 and earlier versions
  • Adobe FrameMaker 2022 Release Update 5 and earlier versions

Solutions

Before installation of the software, please visit the vendor web-site for more details.

  • Apply fixes issued by the vendor. Please refer to 'Details' column in the above table for details of individual product update or run software update.

Vulnerability Identifier


Source


Related Link

Google Chrome 多個漏洞

發佈日期: 2024年12月11日

風險: 中度風險

類型: 用戶端 - 瀏覽器

於 Google Chrome 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發遠端執行任意程式碼及阻斷服務狀況。


影響

  • 遠端執行程式碼
  • 阻斷服務

受影響之系統或技術

  • Google Chrome 131.0.6778.139 (Linux) 之前的版本
  • Google Chrome 131.0.6778.139/.140 (Mac) 之前的版本
  • Google Chrome 131.0.6778.139/.140 (Windows) 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝軟件供應商提供的修補程式:

  • 升級 131.0.6778.139 (Linux) 或之後的版本
  • 升級 131.0.6778.139/.140 (Mac) 或之後的版本
  • 升級 131.0.6778.139/.140 (Windows) 或之後的版本

漏洞識別碼


資料來源


相關連結

Google Chrome Multiple Vulnerabilities

Release Date: 11 Dec 2024

RISK: Medium Risk

TYPE: Clients - Browsers

Multiple vulnerabilities were identified in Google Chrome. A remote attacker could exploit some of these vulnerabilities to trigger remote code execution and denial of service condition on the targeted system.


Impact

  • Remote Code Execution
  • Denial of Service

System / Technologies affected

  • Google Chrome prior to 131.0.6778.139 (Linux)
  • Google Chrome prior to 131.0.6778.139/.140 (Mac)
  • Google Chrome prior to 131.0.6778.139/.140 (Windows)

Solutions

Before installation of the software, please visit the software vendor web-site for more details.

Apply fixes issued by the vendor:

  • Update to version 131.0.6778.139 (Linux) or later
  • Update to version 131.0.6778.139/.140 (Mac) or later
  • Update to version 131.0.6778.139/.140 (Windows) or later

Vulnerability Identifier


Source


Related Link

Ivanti 產品多個漏洞

發佈日期: 2024年12月11日

風險: 中度風險

類型: 操作系統 - Network

於 Ivanti 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、遠端執行任意程式碼及繞過保安限制。


影響

  • 阻斷服務
  • 遠端執行程式碼
  • 繞過保安限制

受影響之系統或技術

  • Ivanti Connect Secure (ICS) 版本 22.7R2.3 及更早版本
  • Ivanti Policy Secure (IPS) 版本 22.7R1.1 及更早版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

Ivanti Products Multiple Vulnerabilities

Release Date: 11 Dec 2024

RISK: Medium Risk

TYPE: Operating Systems - Networks OS

Multiple vulnerabilities have been identified in Ivanti Products. A remote attacker could exploit these vulnerability to trigger denial of service condition, remote code execution and security restriction bypass on the targeted system.


Impact

  • Denial of Service
  • Remote Code Execution
  • Security Restriction Bypass

System / Technologies affected

  • Ivanti Connect Secure (ICS) versions 22.7R2.3 and prior
  • Ivanti Policy Secure (IPS) versions 22.7R1.1 and prior

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

微軟每月保安更新 (2024年12月)

發佈日期: 2024年12月11日

風險: 高度風險

類型: 操作系統 - 視窗操作系統

微軟已為產品提供本月保安更新:

 

受影響產品風險程度影響備註
System Center中度風險 中度風險權限提升
仿冒
 
微軟 Office中度風險 中度風險權限提升
資料洩露
遠端執行程式碼
 
視窗高度風險 高度風險權限提升
遠端執行程式碼
資料洩露
阻斷服務
CVE-2024-49138 正被廣泛利用。成功利用此漏洞的攻擊者可以獲得系統權限。
延伸安全性更新 (ESU)高度風險 高度風險權限提升
遠端執行程式碼
阻斷服務
資料洩露
CVE-2024-49138 正被廣泛利用。成功利用此漏洞的攻擊者可以獲得系統權限。
開發者工具中度風險 中度風險遠端執行程式碼 

 

「極高度風險」產品數目:0

「高度風險」產品數目:2

「中度風險」產品數目:3

「低度風險」產品數目:0

整體「風險程度」評估:高度風險


影響

  • 權限提升
  • 仿冒
  • 資料洩露
  • 遠端執行程式碼
  • 阻斷服務

受影響之系統或技術

  • System Center
  • 微軟 Office
  • 視窗
  • 延伸安全性更新 (ESU)
  • 開發者工具

解決方案

在安裝軟體之前,請先瀏覽軟體供應商之網站,以獲得更多詳細資料。

  • 安裝軟件供應商提供的修補程式。
 

漏洞識別碼


資料來源


相關連結

Microsoft Monthly Security Update (December 2024)

Release Date: 11 Dec 2024

RISK: High Risk

TYPE: Operating Systems - Windows OS

Microsoft has released monthly security update for their products:

 

Vulnerable ProductRisk LevelImpactsNotes
System CenterMedium Risk Medium RiskElevation of Privilege
Spoofing
 
Microsoft OfficeMedium Risk Medium RiskElevation of Privilege
Information Disclosure
Remote Code Execution
 
WindowsHigh Risk High RiskElevation of Privilege
Remote Code Execution
Information Disclosure
Denial of Service
CVE-2024-49138 is being exploited in the wild. An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
Extended Security Updates (ESU)High Risk High RiskElevation of Privilege
Remote Code Execution
Denial of Service
Information Disclosure
CVE-2024-49138 is being exploited in the wild. An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
Developer ToolsMedium Risk Medium RiskRemote Code Execution 

 

Number of 'Extremely High Risk' product(s): 0

Number of 'High Risk' product(s): 2

Number of 'Medium Risk' product(s): 3

Number of 'Low Risk' product(s): 0

Evaluation of overall 'Risk Level': High Risk


Impact

  • Elevation of Privilege
  • Spoofing
  • Information Disclosure
  • Remote Code Execution
  • Denial of Service

System / Technologies affected

  • System Center
  • Microsoft Office
  • Windows
  • Extended Security Updates (ESU)
  • Developer Tools

Solutions

Before installation of the software, please visit the vendor web-site for more details.

  •  Apply fixes issued by the vendor.

Vulnerability Identifier


Source


Related Link

2024年12月9日星期一

QNAP NAS 多個漏洞

發佈日期: 2024年12月09日

風險: 中度風險

類型: 伺服器 - 其他伺服器

於 QNAP NAS 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發繞過保安限制、阻斷服務狀況、遠端執行任意程式碼、洩露敏感資料及資料篡改。


影響

  • 遠端執行程式碼
  • 阻斷服務
  • 資料洩露
  • 篡改
  • 繞過保安限制

受影響之系統或技術

  • QTS 5.1.x
  • QuTS hero h5.1.x
  • QTS 5.2.x
  • QuTS hero h5.2.x

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

QNAP NAS Multiple Vulnerabilities

Release Date: 9 Dec 2024

RISK: Medium Risk

TYPE: Servers - Other Servers

Multiple vulnerabilities were identified in QNAP NAS. A remote attacker could exploit some of these vulnerabilities to trigger security restriction bypass, denial of service condition, remote code execution, sensitive information disclosure and data manipulation on the targeted system.


Impact

  • Remote Code Execution
  • Denial of Service
  • Information Disclosure
  • Data Manipulation
  • Security Restriction Bypass

System / Technologies affected

  • QTS 5.1.x
  • QuTS hero h5.1.x
  • QTS 5.2.x
  • QuTS hero h5.2.x

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

2024年12月6日星期五

Microsoft Edge 多個漏洞

發佈日期: 2024年12月06日

風險: 中度風險

類型: 用戶端 - 瀏覽器

於 Microsoft Edge 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發彷冒及遠端執行任意程式碼。


影響

  • 遠端執行程式碼
  • 仿冒

受影響之系統或技術

  • Microsoft Edge (Stable) 131.0.2903.86 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝軟件供應商提供的修補程式:

  • 更新至 Microsoft Edge (Stable) 131.0.2903.86 或之後的版本

漏洞識別碼


資料來源


相關連結

Microsoft Edge Multiple Vulnerabilities

Release Date: 6 Dec 2024

RISK: Medium Risk

TYPE: Clients - Browsers

Multiple vulnerabilities were identified in Microsoft Edge. A remote attacker could exploit some of these vulnerabilities to trigger spoofing and remote code execution on the targeted system.


Impact

  • Remote Code Execution
  • Spoofing

System / Technologies affected

  • Microsoft Edge (Stable) version prior to 131.0.2903.86

Solutions

Before installation of the software, please visit the software vendor web-site for more details.

Apply fixes issued by the vendor:

  • Update to Microsoft Edge (Stable) version 131.0.2903.86 or later

Vulnerability Identifier


Source


Related Link

2024年12月5日星期四

RedHat Linux 核心多個漏洞

發佈日期: 2024年12月05日

風險: 中度風險

類型: 操作系統 - LINUX

於 RedHat Linux核心發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發遠端執行任意程式碼、洩露敏感資料、阻斷服務狀況及權限提升。

 

 

 


影響

  • 阻斷服務
  • 遠端執行程式碼
  • 資料洩露
  • 權限提升

受影響之系統或技術

  • Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.4 x86_64
  • Red Hat Enterprise Linux Server - AUS 9.4 x86_64
  • Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.4 s390x
  • Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.4 ppc64le
  • Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.4 aarch64
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.4 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.4 x86_64
  • Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 9.4 x86_64
  • Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 9.4 ppc64le
  • Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 9.4 s390x
  • Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 9.4 aarch64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.4 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.4 s390x
  • Red Hat Enterprise Linux for Real Time for x86_64 - 4 years of updates 9.4 x86_64
  • Red Hat Enterprise Linux for Real Time for NFV for x86_64 - 4 years of updates 9.4 x86_64
  • Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.2 x86_64
  • Red Hat Enterprise Linux Server - AUS 9.2 x86_64
  • Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.2 s390x
  • Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.2 ppc64le
  • Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.2 aarch64
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.2 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.2 x86_64
  • Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 9.2 x86_64
  • Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 9.2 ppc64le
  • Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 9.2 s390x
  • Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 9.2 aarch64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.2 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.2 s390x
  • Red Hat Enterprise Linux for Real Time for x86_64 - 4 years of updates 9.2 x86_64
  • Red Hat Enterprise Linux for Real Time for NFV for x86_64 - 4 years of updates 9.2 x86_64

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

RedHat Linux Kernel Multiple Vulnerabilities

Release Date: 5 Dec 2024

RISK: Medium Risk

TYPE: Operating Systems - Linux

Multiple vulnerabilities were identified in RedHat Linux Kernel. A remote attacker could exploit some of these vulnerabilities to trigger remote code execution, sensitive information disclosure, denial of service condition and elevation of privilege on the targeted system.

 

 


Impact

  • Denial of Service
  • Remote Code Execution
  • Information Disclosure
  • Elevation of Privilege

System / Technologies affected

  • Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.4 x86_64
  • Red Hat Enterprise Linux Server - AUS 9.4 x86_64
  • Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.4 s390x
  • Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.4 ppc64le
  • Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.4 aarch64
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.4 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.4 x86_64
  • Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 9.4 x86_64
  • Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 9.4 ppc64le
  • Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 9.4 s390x
  • Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 9.4 aarch64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.4 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.4 s390x
  • Red Hat Enterprise Linux for Real Time for x86_64 - 4 years of updates 9.4 x86_64
  • Red Hat Enterprise Linux for Real Time for NFV for x86_64 - 4 years of updates 9.4 x86_64
  • Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.2 x86_64
  • Red Hat Enterprise Linux Server - AUS 9.2 x86_64
  • Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.2 s390x
  • Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.2 ppc64le
  • Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.2 aarch64
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.2 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.2 x86_64
  • Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 9.2 x86_64
  • Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 9.2 ppc64le
  • Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 9.2 s390x
  • Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 9.2 aarch64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.2 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.2 s390x
  • Red Hat Enterprise Linux for Real Time for x86_64 - 4 years of updates 9.2 x86_64
  • Red Hat Enterprise Linux for Real Time for NFV for x86_64 - 4 years of updates 9.2 x86_64

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

2024年12月4日星期三

Google Chrome 遠端執行程式碼漏洞

發佈日期: 2024年12月04日

風險: 中度風險

類型: 用戶端 - 瀏覽器

於 Google Chrome 發現一個漏洞。遠端攻擊者可利用這個漏洞,於目標系統觸發遠端執行程式碼。


影響

  • 遠端執行程式碼

受影響之系統或技術

  • Google Chrome 131.0.6778.108 (Linux) 之前的版本
  • Google Chrome 131.0.6778.108/.109 (Mac) 之前的版本
  • Google Chrome 131.0.6778.108/.109 (Windows) 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝軟件供應商提供的修補程式:

  • 更新至 131.0.6778.108 (Linux) 或之後版本
  • 更新至 131.0.6778.108/.109 (Mac) 或之後版本
  • 更新至 131.0.6778.108/.109 (Windows) 或之後版本

漏洞識別碼


資料來源


相關連結

Google Chrome Remote Code Execution Vulnerability

Release Date: 4 Dec 2024

RISK: Medium Risk

TYPE: Clients - Browsers

A vulnerability was identified in Google Chrome. A remote attacker could exploit this vulnerability to trigger remote code execution on the targeted system.


Impact

  • Remote Code Execution

System / Technologies affected

  • Google Chrome prior to 131.0.6778.108 (Linux)
  • Google Chrome prior to 131.0.6778.108/.109 (Mac)
  • Google Chrome prior to 131.0.6778.108/.109 (Windows)

Solutions

Before installation of the software, please visit the software vendor web-site for more details.

Apply fixes issued by the vendor:

  • Update to version 131.0.6778.108 (Linux) or later
  • Update to version 131.0.6778.108/.109 (Mac) or later
  • Update to version 131.0.6778.108/.109 (Windows) or later

Vulnerability Identifier


Source


Related Link

2024年12月3日星期二

Android 多個漏洞

發佈日期: 2024年12月03日

風險: 中度風險

類型: 操作系統 - 流動裝置及操作系統

於 Android 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發權限提升及遠端執行程式碼。

 


影響

  • 權限提升
  • 遠端執行程式碼

受影響之系統或技術

  • 2024-12-01 前的 Android 保安更新級別

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。


漏洞識別碼


資料來源


相關連結

Android Multiple Vulnerabilities

Release Date: 3 Dec 2024

RISK: Medium Risk

TYPE: Operating Systems - Mobile & Apps

Multiple vulnerabilities were identified in Android. A remote attacker could exploit some of these vulnerabilities to trigger elevation of privilege and remote code execution on the targeted system.


Impact

  • Elevation of Privilege
  • Remote Code Execution

System / Technologies affected

  • Android security patch level prior to 2024-12-01

Solutions

Before installation of the software, please visit the vendor web-site for more details.


Vulnerability Identifier


Source


Related Link

三星產品多個漏洞

發佈日期: 2024年12月03日

風險: 中度風險

類型: 操作系統 - 流動裝置及操作系統

於三星產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、權限提升、遠端執行程式碼、繞過保安限制、篡改及敏感資料洩露。

 

注意:

有跡象表明,CVE-2024-43047 可能受到有限的、有針對性的利用。對於 CVE-2024-43047,此漏洞存在於 DSP 服務。當維護 HLOS 記憶體的記憶體映射時,會導致記憶體損毀。本機應用程式可執行任意程式碼。該漏洞需要運行本地程序。因此,風險等級被評為中等風險。


影響

  • 阻斷服務
  • 權限提升
  • 資料洩露
  • 遠端執行程式碼
  • 繞過保安限制
  • 篡改

受影響之系統或技術

  • Galaxy Watch running Android Watch 13, 14
  • Samsung mobile devices running Android 12, 13, 14

有關受影響產品,請參閱以下連結:

https://security.samsungmobile.com/securityUpdate.smsb

https://semiconductor.samsung.com/support/quality-support/product-security-updates/


解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。


漏洞識別碼


資料來源


相關連結

Samsung Products Multiple Vulnerabilities

Release Date: 3 Dec 2024

RISK: Medium Risk

TYPE: Operating Systems - Mobile & Apps

Multiple vulnerabilities were identified in Samsung Products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, elevation of privilege, remote code execution, security restriction bypass, data manipulation and sensitive information disclosure on the targeted system.

 

Note:


Impact

  • Denial of Service
  • Elevation of Privilege
  • Information Disclosure
  • Remote Code Execution
  • Security Restriction Bypass
  • Data Manipulation

System / Technologies affected

  • Galaxy Watch running Android Watch 13, 14
  • Samsung mobile devices running Android 12, 13, 14

For affected products, please refer to the link below:

https://security.samsungmobile.com/securityUpdate.smsb

https://semiconductor.samsung.com/support/quality-support/product-security-updates/


Solutions

Before installation of the software, please visit the vendor web-site for more details.


Vulnerability Identifier


Source


Related Link

Apache Tomcat 多個漏洞

Apache Tomcat 多個漏洞 發佈日期: 2026年08月05日 風險: 中度風險 類型: 伺服器 - 網站伺服器 於 Apache T...