ISC BIND 阻斷服務漏洞
風險: 中度風險
類型: 伺服器 - 網絡管理

於 BIND 發現一個漏洞,遠端攻擊者可利用此漏洞,於目標系統觸發阻斷服務狀況。
影響
- 阻斷服務
受影響之系統或技術
- BIND 9.18.3 以前的版本 (穩定版)
- BIND 9.19.1 以前的版本 (開發版)
解決方案
在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。
安裝供應商提供的修補程式:
- BIND 更新到 9.18.3 版本 (穩定版)
- BIND 更新到 9.19.1 版本 (開發版)
RISK: Medium Risk
TYPE: Servers - Network Management

A vulnerability was identified in BIND, a remote attacker could exploit this vulnerability to trigger denial of service condition on the targeted system.
Before installation of the software, please visit the vendor web-site for more details.
Apply fixes issued by the vendor:
風險: 中度風險
類型: 操作系統 - 網絡操作系統

於 VMware 產品發現多個漏洞,攻擊者可利用這些漏洞,於目標系統觸發繞過保安限制及權限提升。
在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。
RISK: Medium Risk
TYPE: Operating Systems - VM Ware

Multiple vulnerabilities were identified in VMware products. An attacker could exploit some of these vulnerabilities to trigger security restriction bypass and elevation of privilege.
Before installation of the software, please visit the vendor web-site for more details.
風險: 中度風險
類型: 伺服器 - 網站伺服器

於 Apache HTTP Server 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況及繞過保安限制。
[更新於 2022-04-25]
更新 QNAP 產品於受影響之系統或技術及解決方案。
[更新於 2022-05-17]
更新 F5 產品於受影響之系統或技術及解決方案。
[更新於 2022-04-25]
對於QNAP產品
詳情請參閱以下連結:
https://www.qnap.com/en/security-advisory/qsa-22-11
[更新於 2022-05-17]
對於F5產品
詳情請參閱以下連結:
https://support.f5.com/csp/article/K67090077
在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。
安裝供應商提供的修補程式:
[更新於 2022-04-25]
對於QNAP產品
詳情請參閱以下連結:
https://www.qnap.com/en/security-advisory/qsa-22-11
[更新於 2022-05-17]
對於F5產品
詳情請參閱以下連結:
https://support.f5.com/csp/article/K67090077
RISK: Medium Risk
TYPE: Servers - Web Servers

Multiple vulnerabilities were identified in Apache HTTP Server. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition and security restriction bypass on the targeted system.
[Updated on 2022-04-25]
Added QNAP products to the "System / Technologies affected" and "Solution" sections
[Updated on 2022-05-17]
Added F5 products to the "System / Technologies affected" and "Solution" sections
[Updated on 2022-04-25]
For QNAP Products
For detail, please refer to the links below:
https://www.qnap.com/en/security-advisory/qsa-22-11
[Updated on 2022-05-17]
For F5 Products
For detail, please refer to the links below:
https://support.f5.com/csp/article/K67090077
Before installation of the software, please visit the vendor web-site for more details.
Apply fixes issued by the vendor:
[Updated on 2022-04-25]
For QNAP Products
For detail, please refer to the links below:
https://www.qnap.com/en/security-advisory/qsa-22-11
[Updated on 2022-05-17]
For F5 Products
For detail, please refer to the links below:
https://support.f5.com/csp/article/K67090077
風險: 中度風險
類型: 伺服器 - 網站伺服器

於 Apache Tomcat 發現一個漏洞,遠端使用者可利用此漏洞,於目標系統觸發資料洩露。
在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。
安裝供應商提供的修補程式:
RISK: Medium Risk
TYPE: Servers - Web Servers

A vulnerability has been identified in Apache Tomcat. A remote user can exploit this vulnerability to trigger information disclosure on the targeted system.
Before installation of the software, please visit the vendor web-site for more details.
Apply fixes issued by the vendor:
風險: 極高度風險
類型: 操作系統 - 流動裝置及操作系統

於 Apple Products 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發資料洩露、遠端執行程式碼、繞過保安限制、權限提升、阻斷服務狀況及篡改。
注意﹕
CVE-2022-22675 漏洞正被廣泛利用。
該漏洞與 AppleAVD (音訊及視訊解碼的內核擴充) 有關。該漏洞允許惡意應用程式於目標系統上以內核權限運行任意代碼。
在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。
安裝供應商提供的修補程式:
RISK: Extremely High Risk
TYPE: Operating Systems - Mobile & Apps

Multiple vulnerabilities were identified in Apple Products. A remote attacker could exploit some of these vulnerabilities to trigger information disclosure, remote code execution, security restriction bypass, elevation of privilege, denial of service and data manipulation on the targeted system.
Note:
CVE-2022-22675 is being exploited in the wild.
The vulnerability is related to the AppleAVD (a kernel extension for audio and video decoding). The vulnerability can exploit the AppleAVD that allows malicious apps to run arbitrary code with kernel privileges on the targeted system.
Before installation of the software, please visit the vendor web-site for more details.
風險: 中度風險
類型: 操作系統 - LINUX

於 SUSE Linux Kernel 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、遠端執行程式碼、權限提升及洩露敏感資料。
在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。
RISK: Medium Risk
TYPE: Operating Systems - Linux

Multiple vulnerabilities were identified in SUSE Linux Kernel. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, remote code execution, elevation of privilege and sensitive information disclosure on the targeted system.
Before installation of the software, please visit the vendor web-site for more details.
風險: 中度風險
類型: 操作系統 - LINUX

在Ubuntu Linux 核心發現多個漏洞,遠端攻擊者可利用這些漏洞,於目標系統觸發遠端執行程式碼、阻斷服務、繞過保安限制及資料洩露。
詳情請參閱以下連結﹕
在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。
安裝供應商提供的修補程式:
RISK: Medium Risk
TYPE: Operating Systems - Linux

Multiple vulnerabilities have been identified in Ubuntu Linux Kernal. A remote attacker could exploit some of these vulnerabilities to trigger remote code execution, denial of service, security restriction bypass and information disclosure on the targeted system.
Please refer to the links below for detail:
Before installation of the software, please visit the vendor web-site for more details.
Apply fixes issued by the vendor:
風險: 中度風險
類型: 操作系統 - LINUX

於 Red Hat 內核發現多個漏洞,遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務、遠端執行程式碼、洩露敏感資料及權限提升。
RISK: Medium Risk
TYPE: Operating Systems - Linux

Multiple vulnerabilities have been identified in Red Hat Kernel. A remote attacker can exploit these vulnerabilities to trigger denial of service, remote code execution, sensitive information disclosure and elevation of privilege on the targeted system.
Before installation of the software, please visit the vendor web-site for more details.
風險: 中度風險
類型: 用戶端 - 辦公室應用

Adobe已為產品提供本月保安更新:
「極高度風險」產品數目:0
「高度風險」產品數目:0
「中度風險」產品數目:5
「低度風險」產品數目:0
整體「風險程度」評估:中度風險
在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。
思科產品多個漏洞 於思科產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況,資料篡改及繞過保安限制。 影響 阻斷服務 繞過保安限制 篡改 受影響之系統或技術 Cisco IOS Cisco IOS XE 請參考供應商發佈的連結以了解受影響的版本: https:...