2022年5月19日星期四

ISC BIND 阻斷服務漏洞

發佈日期: 2022年05月19日

風險: 中度風險

類型: 伺服器 - 網絡管理

類型: 網絡管理

於 BIND 發現一個漏洞,遠端攻擊者可利用此漏洞,於目標系統觸發阻斷服務狀況。


影響

  • 阻斷服務

受影響之系統或技術

  • BIND 9.18.3 以前的版本 (穩定版)
  • BIND 9.19.1 以前的版本 (開發版)

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:

  • BIND 更新到 9.18.3 版本 (穩定版)
  • BIND 更新到 9.19.1 版本 (開發版)

漏洞識別碼


資料來源


相關連結

ISC BIND Denial Of Service Vulnerability

Release Date: 19 May 2022

RISK: Medium Risk

TYPE: Servers - Network Management

TYPE: Network Management

A vulnerability was identified in BIND, a remote attacker could exploit this vulnerability to trigger denial of service condition on the targeted system.


Impact

  • Denial of Service

System / Technologies affected

  • BIND version prior to 9.18.3 (Current Stable)
  • BIND version prior to 9.19.1 (Development)

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:

  • BIND update to version 9.18.3 (Current Stable)
  • BIND update to version 9.19.1 (Development)

Vulnerability Identifier


Source


Related Link

VMWare 產品多個漏洞

發佈日期: 2022年05月19日

風險: 中度風險

類型: 操作系統 - 網絡操作系統

類型: 網絡操作系統

於 VMware 產品發現多個漏洞,攻擊者可利用這些漏洞,於目標系統觸發繞過保安限制及權限提升。


影響

  • 繞過保安限制
  • 權限提升

受影響之系統或技術

  • VMware Workspace ONE Access (Access)
  • VMware Identity Manager (vIDM)
  • VMware vRealize Automation (vRA)
  • VMware Cloud Foundation
  • vRealize Suite Lifecycle Manager

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 


漏洞識別碼


資料來源


相關連結

VMWare Products Multiple Vulnerabilities

Release Date: 19 May 2022

RISK: Medium Risk

TYPE: Operating Systems - VM Ware

TYPE: VM Ware

Multiple vulnerabilities were identified in VMware products. An attacker could exploit some of these vulnerabilities to trigger security restriction bypass and elevation of privilege.


Impact

  • Security Restriction Bypass
  • Elevation of Privilege

System / Technologies affected

  • VMware Workspace ONE Access (Access)
  • VMware Identity Manager (vIDM)
  • VMware vRealize Automation (vRA)
  • VMware Cloud Foundation
  • vRealize Suite Lifecycle Manager

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 


Vulnerability Identifier


Source


Related Link

2022年5月17日星期二

Apache HTTP Server 多個漏洞

最後更新 2022年05月17日 發佈日期: 2022年03月15日

風險: 中度風險

類型: 伺服器 - 網站伺服器

類型: 網站伺服器

於 Apache HTTP Server 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況及繞過保安限制。

 

[更新於 2022-04-25]

更新 QNAP 產品於受影響之系統或技術及解決方案。

 

[更新於 2022-05-17]

更新 F5 產品於受影響之系統或技術及解決方案。


影響

  • 阻斷服務
  • 繞過保安限制

受影響之系統或技術

  • Apache HTTP Server 2.4.53 之前的版本

 

[更新於 2022-04-25]

 

對於QNAP產品

詳情請參閱以下連結:

https://www.qnap.com/en/security-advisory/qsa-22-11

 

 

[更新於 2022-05-17]

 

對於F5產品

詳情請參閱以下連結:

https://support.f5.com/csp/article/K67090077

 


解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:

  • Apache HTTP Server 2.4.53 版本

 

[更新於 2022-04-25]

 

對於QNAP產品

詳情請參閱以下連結:

https://www.qnap.com/en/security-advisory/qsa-22-11

 

[更新於 2022-05-17]

 

對於F5產品

詳情請參閱以下連結:

https://support.f5.com/csp/article/K67090077


漏洞識別碼


資料來源


相關連結

Apache HTTP Server Multiple Vulnerabilities

Last Update Date: 17 May 2022 Release Date: 15 Mar 2022

RISK: Medium Risk

TYPE: Servers - Web Servers

TYPE: Web Servers

Multiple vulnerabilities were identified in Apache HTTP Server. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition and security restriction bypass on the targeted system.

 

[Updated on 2022-04-25]

Added QNAP products to the "System / Technologies affected" and "Solution" sections

 

[Updated on 2022-05-17]

Added F5 products to the "System / Technologies affected" and "Solution" sections


Impact

  • Denial of Service
  • Security Restriction Bypass

System / Technologies affected

  • Apache HTTP Server versions prior to 2.4.53

[Updated on 2022-04-25]

 

For QNAP Products

For detail, please refer to the links below:

https://www.qnap.com/en/security-advisory/qsa-22-11

 

[Updated on 2022-05-17]

 

For F5 Products

For detail, please refer to the links below:

https://support.f5.com/csp/article/K67090077


Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:

  • Apache HTTP Server versions 2.4.53

[Updated on 2022-04-25]

 

For QNAP Products

For detail, please refer to the links below:

https://www.qnap.com/en/security-advisory/qsa-22-11

 

[Updated on 2022-05-17]

 

For F5 Products

For detail, please refer to the links below:

https://support.f5.com/csp/article/K67090077


Vulnerability Identifier


Source


Related Link

Apache Tomcat 資料洩露漏洞

發佈日期: 2022年05月17日

風險: 中度風險

類型: 伺服器 - 網站伺服器

類型: 網站伺服器

於 Apache Tomcat 發現一個漏洞,遠端使用者可利用此漏洞,於目標系統觸發資料洩露。


影響

  • 資料洩露

受影響之系統或技術

  • Apache Tomcat version 9.0.0.M1 to 9.0.20
  • Apache Tomcat version 8.5.0 to 8.5.75

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:

  • Apache Tomcat 9.0.21 或之後版本
  • Apache Tomcat 8.5.76 或之後版本

漏洞識別碼


資料來源


相關連結

Apache Tomcat Information Disclosure Vulnerability

Release Date: 17 May 2022

RISK: Medium Risk

TYPE: Servers - Web Servers

TYPE: Web Servers

A vulnerability has been identified in Apache Tomcat. A remote user can exploit this vulnerability to trigger information disclosure on the targeted system.


Impact

  • Information Disclosure

System / Technologies affected

  • Apache Tomcat version 9.0.0.M1 to 9.0.20
  • Apache Tomcat version 8.5.0 to 8.5.75

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:

  • Apache Tomcat version 9.0.21 or later
  • Apache Tomcat version 8.5.76 or later

Vulnerability Identifier


Source


Related Link

蘋果產品多個漏洞

發佈日期: 2022年05月17日

風險: 極高度風險

類型: 操作系統 - 流動裝置及操作系統

類型: 流動裝置及操作系統

於 Apple Products 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發資料洩露、遠端執行程式碼、繞過保安限制、權限提升、阻斷服務狀況及篡改。

 

注意
CVE-2022-22675 漏洞正被廣泛利用。

該漏洞與 AppleAVD (音訊及視訊解碼的內核擴充) 有關。該漏洞允許惡意應用程式於目標系統上以內核權限運行任意代碼。


影響

  • 資料洩露
  • 遠端執行程式碼
  • 權限提升
  • 繞過保安限制
  • 篡改
  • 阻斷服務

受影響之系統或技術

  • Safari 15.5 以前的版本
  • tvOS 15.5 以前的版本
  • Xcode 13.4 以前的版本
  • macOS Catalina 安全更新 2202-004 以前的版本
  • macOS Big Sur 11.6.6 以前的版本
  • macOS Monterey 12.4 以前的版本
  • iOS 15.5 以前的版本
  • iPadOS 15.5 以前的版本
  • watchOS 8.6 以前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝供應商提供的修補程式:

  • Safari 15.5
  • tvOS 15.5
  • Xcode 13.4
  • macOS Catalina 安全更新 2202-004
  • macOS Big Sur 11.6.6
  • macOS Monterey 12.4
  • iOS 15.5
  • iPadOS 15.5
  • watchOS 8.6

漏洞識別碼


資料來源


相關連結

Apple Products Multiple Vulnerabilities

Release Date: 17 May 2022

RISK: Extremely High Risk

TYPE: Operating Systems - Mobile & Apps

TYPE: Mobile & Apps

Multiple vulnerabilities were identified in Apple Products. A remote attacker could exploit some of these vulnerabilities to trigger information disclosure, remote code execution, security restriction bypass, elevation of privilege, denial of service and data manipulation on the targeted system.

 

Note:
CVE-2022-22675 is being exploited in the wild.

The vulnerability is related to the AppleAVD (a kernel extension for audio and video decoding). The vulnerability can exploit the AppleAVD that allows malicious apps to run arbitrary code with kernel privileges on the targeted system.


Impact

  • Information Disclosure
  • Remote Code Execution
  • Elevation of Privilege
  • Security Restriction Bypass
  • Data Manipulation
  • Denial of Service

System / Technologies affected

  • Versions prior to Safari 15.5
  • Versions prior to tvOS 15.5
  • Versions prior to Xcode 13.4
  • Versions prior to macOS Catalina Security Update 2022-004
  • Versions prior to macOS Big Sur 11.6.6
  • Versions prior to macOS Monterey 12.4
  • Versions prior to iOS 15.5
  • Versions prior to iPadOS 15.5
  • Versions prior to watchOS 8.6

Solutions

Before installation of the software, please visit the vendor web-site for more details.

Apply fixes issued by the vendor:
  • Safari 15.5
  • tvOS 15.5
  • Xcode 13.4
  • macOS Catalina Security Update 2022-004
  • macOS Big Sur 11.6.6
  • macOS Monterey 12.4
  • iOS 15.5
  • iPadOS 15.5
  • watchOS 8.6

Vulnerability Identifier


Source


Related Link

SUSE Linux 內核多個漏洞

發佈日期: 2022年05月17日

風險: 中度風險

類型: 操作系統 - LINUX

類型: LINUX

於 SUSE Linux Kernel 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、遠端執行程式碼、權限提升及洩露敏感資料。


影響

  • 阻斷服務
  • 繞過保安限制
  • 遠端執行程式碼
  • 資料洩露

受影響之系統或技術

  • SUSE Linux Enterprise Server 12-SP5

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 


漏洞識別碼


資料來源


相關連結

SUSE Linux Kernel Multiple Vulnerabilities

Release Date: 17 May 2022

RISK: Medium Risk

TYPE: Operating Systems - Linux

TYPE: Linux

Multiple vulnerabilities were identified in SUSE Linux Kernel. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, remote code execution, elevation of privilege and sensitive information disclosure on the targeted system.


Impact

  • Denial of Service
  • Security Restriction Bypass
  • Remote Code Execution
  • Information Disclosure

System / Technologies affected

  • SUSE Linux Enterprise Server 12-SP5

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 


Vulnerability Identifier


Source


Related Link

Ubuntu Linux 核心多個漏洞

發佈日期: 2022年05月16日

風險: 中度風險

類型: 操作系統 - LINUX

類型: LINUX

在Ubuntu Linux 核心發現多個漏洞,遠端攻擊者可利用這些漏洞,於目標系統觸發遠端執行程式碼、阻斷服務、繞過保安限制及資料洩露。


影響

  • 阻斷服務
  • 遠端執行程式碼
  • 繞過保安限制
  • 資料洩露

受影響之系統或技術

  • Ubuntu 14.04 ESM
  • Ubuntu 16.04 ESM
  • Ubuntu 18.04 LTS
  • Ubuntu 20.04 LTS
  • Ubuntu 21.10

 

詳情請參閱以下連結﹕

 


解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:

 


漏洞識別碼


資料來源


相關連結

Ubuntu Linux Kernel Multiple Vulnerabilities

Release Date: 16 May 2022

RISK: Medium Risk

TYPE: Operating Systems - Linux

TYPE: Linux

Multiple vulnerabilities have been identified in Ubuntu Linux Kernal. A remote attacker could exploit some of these vulnerabilities to trigger remote code execution, denial of service, security restriction bypass and information disclosure on the targeted system.


Impact

  • Denial of Service
  • Remote Code Execution
  • Security Restriction Bypass
  • Information Disclosure

System / Technologies affected

  • Ubuntu 14.04 ESM
  • Ubuntu 16.04 ESM
  • Ubuntu 18.04 LTS
  • Ubuntu 20.04 LTS
  • Ubuntu 21.10

 

Please refer to the links below for detail:

 


Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:

 


Vulnerability Identifier


Source


Related Link

2022年5月11日星期三

Red Hat 內核多個漏洞

發佈日期: 2022年05月11日

風險: 中度風險

類型: 操作系統 - LINUX

類型: LINUX

於 Red Hat 內核發現多個漏洞,遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務、遠端執行程式碼、洩露敏感資料及權限提升。


影響

  • 阻斷服務
  • 遠端執行程式碼
  • 資料洩露
  • 權限提升

受影響之系統或技術

  • Red Hat CodeReady Linux Builder for ARM 64 8 aarch64
  • Red Hat CodeReady Linux Builder for Power, little endian 8 ppc64le
  • Red Hat CodeReady Linux Builder for x86_64 8 x86_64
  • Red Hat Enterprise Linux for ARM 64 8 aarch64
  • Red Hat Enterprise Linux for IBM z Systems 8 s390x
  • Red Hat Enterprise Linux for Power, little endian 8 ppc64le
  • Red Hat Enterprise Linux for Real Time 8 x86_64
  • Red Hat Enterprise Linux for Real Time for NFV 8 x86_64
  • Red Hat Enterprise Linux for x86_64 8 x86_64
  • Red Hat Virtualization Host 4 for RHEL 8 x86_64

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

漏洞識別碼


資料來源


相關連結

Red Hat Kernel Multiple Vulnerabilities

Release Date: 11 May 2022

RISK: Medium Risk

TYPE: Operating Systems - Linux

TYPE: Linux

Multiple vulnerabilities have been identified in Red Hat Kernel. A remote attacker can exploit these vulnerabilities to trigger denial of service, remote code execution, sensitive information disclosure and elevation of privilege on the targeted system.


Impact

  • Denial of Service
  • Remote Code Execution
  • Information Disclosure
  • Elevation of Privilege

System / Technologies affected

  • Red Hat CodeReady Linux Builder for ARM 64 8 aarch64
  • Red Hat CodeReady Linux Builder for Power, little endian 8 ppc64le
  • Red Hat CodeReady Linux Builder for x86_64 8 x86_64
  • Red Hat Enterprise Linux for ARM 64 8 aarch64
  • Red Hat Enterprise Linux for IBM z Systems 8 s390x
  • Red Hat Enterprise Linux for Power, little endian 8 ppc64le
  • Red Hat Enterprise Linux for Real Time 8 x86_64
  • Red Hat Enterprise Linux for Real Time for NFV 8 x86_64
  • Red Hat Enterprise Linux for x86_64 8 x86_64
  • Red Hat Virtualization Host 4 for RHEL 8 x86_64

Solutions

Before installation of the software, please visit the vendor web-site for more details.


Vulnerability Identifier


Source


Related Link

Adobe 每月保安更新 (2022年5月)

發佈日期: 2022年05月11日

風險: 中度風險

類型: 用戶端 - 辦公室應用

類型: 辦公室應用

Adobe已為產品提供本月保安更新:

 

受影響產品風險程度影響備註詳情(包括 CVE)
Adobe Character Animator中度風險 中度風險遠端執行程式碼 APSB22-21
Adobe ColdFusion中度風險 中度風險跨網站指令碼
遠端執行程式碼
 APSB22-22
Adobe InDesign中度風險 中度風險遠端執行程式碼 APSB22-23
Adobe Framemaker中度風險 中度風險遠端執行程式碼
資料洩露
 APSB22-27
Adobe InCopy中度風險 中度風險遠端執行程式碼 APSB22-28

 

「極高度風險」產品數目:0

「高度風險」產品數目:0

「中度風險」產品數目:5

「低度風險」產品數目:0

整體「風險程度」評估:中度風險


影響

  • 跨網站指令碼
  • 遠端執行程式碼
  • 資料洩露

受影響之系統或技術

  • Adobe Character Animator 2021 4.4.2 及以前版本
  • Adobe Character Animator 2022 22.3 及以前版本
  • Adobe ColdFusion 2018 Update 13 及以前版本
  • Adobe ColdFusion 2021 Version 3 及以前版本
  • Adobe InDesign 17.1 及以前版本
  • Adobe InDesign 16.4.1 及以前版本
  • Adobe Framemaker 2019 Release Update 8 及以前版本
  • Adobe Framemaker 2020 Release Update 4 及以前版本
  • Adobe InCopy  17.1 及以前版本
  • Adobe InCopy  16.4.1 及以前版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

  • 安裝供應商提供的修補程式。個別產品詳情可參考上表「詳情」一欄或執行軟件更新。

漏洞識別碼


資料來源


相關連結

思科產品多個漏洞

思科產品多個漏洞 於思科產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況,資料篡改及繞過保安限制。 影響 阻斷服務 繞過保安限制 篡改 受影響之系統或技術 Cisco IOS Cisco IOS XE 請參考供應商發佈的連結以了解受影響的版本: https:...