2022年8月18日星期四

蘋果產品多個漏洞

發佈日期: 2022年08月18日

風險: 極高度風險

類型: 操作系統 - 流動裝置及操作系統

類型: 流動裝置及操作系統

於 Apple Products 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發遠端執行程式碼。

 

注意
CVE-2022-32893 及 CVE-2022-32894 漏洞正被廣泛利用。

CVE-2022-32893 漏洞允許惡意網頁內容於目標系統上以運行任意程式碼。

CVE-2022-32894 漏洞允許惡意應用程式於目標系統上以內核權限運行任意程式碼。

 


影響

  • 遠端執行程式碼

受影響之系統或技術

  • macOS Monterey 12.5.1 以前的版本
  • iOS 15.6.1 以前的版本
  • iPadOS 15.6.1 以前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝供應商提供的修補程式:

  • macOS Monterey 12.5.1
  • iOS 15.6.1
  • iPadOS 15.6.1

漏洞識別碼


資料來源


相關連結

Apple Products Multiple Vulnerabilities

Release Date: 18 Aug 2022

RISK: Extremely High Risk

TYPE: Operating Systems - Mobile & Apps

TYPE: Mobile & Apps

Multiple vulnerabilities were identified in Apple Products. A remote attacker could exploit some of these vulnerabilities to trigger remote code execution on the targeted system.

 

Note:
CVE-2022-32893 and CVE-2022-32894 are being exploited in the wild.

CVE-2022-32893 vulnerability can exploit the WebKit that allows crafted web content to run arbitrary code on the targeted system.

CVE-2022-32894 vulnerability can exploit the Kernel that allows malicious apps to run arbitrary code with kernel privileges on the targeted system.

 


Impact

  • Remote Code Execution

System / Technologies affected

  • Versions prior to macOS Monterey 12.5.1
  • Versions prior to iOS 15.6.1
  • Versions prior to iPadOS 15.6.1

Solutions

Before installation of the software, please visit the vendor web-site for more details.

Apply fixes issued by the vendor:
  • macOS Monterey 12.5.1
  • iOS 15.6.1
  • iPadOS 15.6.1

Vulnerability Identifier


Source


Related Link

微軟 Edge 繞過保安限制漏洞

發佈日期: 2022年08月18日

風險: 中度風險

類型: 用戶端 - 瀏覽器

類型: 瀏覽器

於微軟 Edge 發現一個漏洞。攻擊者可利用此漏洞,於目標系統觸發繞過保安限制。

 

注意﹕
CVE-2022-2856 漏洞正被廣泛利用。該漏洞與Intents中不受信任的輸入驗證不足有關。


影響

  • 繞過保安限制

受影響之系統或技術

  • 微軟 Edge 104.0.1293.60 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝軟件供應商提供的修補程式:

  • 更新至 104.0.1293.60 或之後版本

漏洞識別碼


資料來源


相關連結

Microsoft Edge Security Restriction Bypass Vulnerability

Release Date: 18 Aug 2022

RISK: Medium Risk

TYPE: Clients - Browsers

TYPE: Browsers

A vulnerability was identified in Microsoft Edge. Attacker could exploit the vulnerability to trigger security restriction bypass on the targeted system.

 

Note:
CVE-2022-2856 is being exploited in the wild. The vulnerability related to insufficient validation of untrusted input in Intents.


Impact

  • Security Restriction Bypass

System / Technologies affected

  • Microsoft Edge prior to 104.0.1293.60

Solutions

Before installation of the software, please visit the software vendor web-site for more details.

Apply fixes issued by the vendor:

  • Update to version 104.0.1293.60 or later

Vulnerability Identifier


Source


Related Link

2022年8月17日星期三

Google Chrome 多個漏洞

發佈日期: 2022年08月17日

風險: 中度風險

類型: 用戶端 - 瀏覽器

類型: 瀏覽器

於 Google Chrome 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發遠端執行任意程式碼及繞過保安限制。

 

注意﹕
CVE-2022-2856 漏洞正被廣泛利用。該漏洞與Intents中不受信任的輸入驗證不足有關。


影響

  • 遠端執行程式碼
  • 繞過保安限制

受影響之系統或技術

  • Google Chrome 104.0.5112.101 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝軟件供應商提供的修補程式:

  • 更新至 104.0.5112.101 或之後版本

漏洞識別碼


資料來源


相關連結

Google Chrome Multiple Vulnerabilities

Release Date: 17 Aug 2022

RISK: Medium Risk

TYPE: Clients - Browsers

TYPE: Browsers

Multiple vulnerabilities were identified in Google Chrome. A remote attacker could exploit some of these vulnerabilities to trigger remote code execution and security restriction bypass on the targeted system.

 

Note:
CVE-2022-2856 is being exploited in the wild. The vulnerability related to insufficient validation of untrusted input in Intents.


Impact

  • Remote Code Execution
  • Security Restriction Bypass

System / Technologies affected

  • Google Chrome prior to 104.0.5112.101

Solutions

Before installation of the software, please visit the software vendor web-site for more details.

Apply fixes issued by the vendor:

  • Update to version 104.0.5112.101 or later

Vulnerability Identifier


Source


Related Link

2022年8月16日星期二

QNAP NAS 多個漏洞

發佈日期: 2022年08月16日

風險: 中度風險

類型: 伺服器 - 其他伺服器

類型: 其他伺服器

於 QNAP NAS 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、權限提升、遠端執行任意程式碼、洩露敏感資料、跨網站指令碼及繞過保安限制。


影響

  • 阻斷服務
  • 權限提升
  • 遠端執行程式碼
  • 資料洩露
  • 跨網站指令碼
  • 繞過保安限制

受影響之系統或技術

  • QTS 4.2.x
  • QTS 4.3.x
  • QTS 4.5.x/4.4.x
  • QTS 5.0.0
  • QTS 5.0.1
  • QuTS hero h4.5.x
  • QuTS hero h5.0.0
  • QuTS hero h5.0.1
  • QuTScloud c5.0.1

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 


漏洞識別碼


資料來源


相關連結

QNAP NAS Multiple Vulnerabilities

Release Date: 16 Aug 2022

RISK: Medium Risk

TYPE: Servers - Other Servers

TYPE: Other Servers

Multiple vulnerabilities were identified in QNAP NAS. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, elevation of privilege, remote code execution, sensitive information disclosure, cross-site scripting and security restriction bypass on the targeted system.


Impact

  • Denial of Service
  • Elevation of Privilege
  • Remote Code Execution
  • Information Disclosure
  • Cross-Site Scripting
  • Security Restriction Bypass

System / Technologies affected

  • QTS 4.2.x
  • QTS 4.3.x
  • QTS 4.5.x/4.4.x
  • QTS 5.0.0
  • QTS 5.0.1
  • QuTS hero h4.5.x
  • QuTS hero h5.0.0
  • QuTS hero h5.0.1
  • QuTScloud c5.0.1

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 


Vulnerability Identifier


Source


Related Link

SUSE Linux 內核多個漏洞

發佈日期: 2022年08月15日

風險: 中度風險

類型: 操作系統 - LINUX

類型: LINUX

於 SUSE Linux 核心發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、權限提升、遠端執行任意程式碼及洩露敏感資料。


影響

  • 阻斷服務
  • 權限提升
  • 遠端執行程式碼
  • 資料洩露

受影響之系統或技術

  • openSUSE Leap 15.3
  • openSUSE Leap 15.4
  • SUSE Linux Enterprise Desktop 12-SP5
  • SUSE Linux Enterprise High Availability 12-SP5
  • SUSE Linux Enterprise High Availability 15
  • SUSE Linux Enterprise High Performance Computing 12-SP5
  • SUSE Linux Enterprise High Performance Computing 15
  • SUSE Linux Enterprise High Performance Computing 15-ESPOS
  • SUSE Linux Enterprise High Performance Computing 15-LTSS
  • SUSE Linux Enterprise High Performance Computing 15-SP1
  • SUSE Linux Enterprise High Performance Computing 15-SP2
  • SUSE Linux Enterprise High Performance Computing 15-SP3
  • SUSE Linux Enterprise High Performance Computing 15-SP4
  • SUSE Linux Enterprise Live Patching 12-SP4
  • SUSE Linux Enterprise Live Patching 12-SP5
  • SUSE Linux Enterprise Micro 5.1
  • SUSE Linux Enterprise Module for Live Patching 15
  • SUSE Linux Enterprise Module for Live Patching 15-SP1
  • SUSE Linux Enterprise Module for Live Patching 15-SP2
  • SUSE Linux Enterprise Module for Live Patching 15-SP3
  • SUSE Linux Enterprise Module for Public Cloud 15-SP3
  • SUSE Linux Enterprise Module for Public Cloud 15-SP4
  • SUSE Linux Enterprise Server 12-SP2-BCL
  • SUSE Linux Enterprise Server 12-SP5
  • SUSE Linux Enterprise Server 15
  • SUSE Linux Enterprise Server 15-LTSS
  • SUSE Linux Enterprise Server 15-SP1
  • SUSE Linux Enterprise Server 15-SP2
  • SUSE Linux Enterprise Server 15-SP3
  • SUSE Linux Enterprise Server 15-SP4
  • SUSE Linux Enterprise Server for SAP 15
  • SUSE Linux Enterprise Server for SAP Applications 12-SP5
  • SUSE Linux Enterprise Server for SAP Applications 15
  • SUSE Linux Enterprise Server for SAP Applications 15-SP1
  • SUSE Linux Enterprise Server for SAP Applications 15-SP2
  • SUSE Linux Enterprise Server for SAP Applications 15-SP3
  • SUSE Linux Enterprise Server for SAP Applications 15-SP4
  • SUSE Linux Enterprise Software Development Kit 12-SP5
  • SUSE Linux Enterprise Storage 7.1
  • SUSE Linux Enterprise Workstation Extension 12-SP5
  • SUSE Manager Proxy 4.2
  • SUSE Manager Proxy 4.3
  • SUSE Manager Retail Branch Server 4.2
  • SUSE Manager Retail Branch Server 4.3
  • SUSE Manager Server 4.2
  • SUSE Manager Server 4.3

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

SUSE Linux Kernel Multiple Vulnerabilities

Release Date: 15 Aug 2022

RISK: Medium Risk

TYPE: Operating Systems - Linux

TYPE: Linux

Multiple vulnerabilities were identified in SUSE Linux Kernel. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, elevation of privilege, remote code execution and sensitive information disclosure on the targeted system.


Impact

  • Denial of Service
  • Elevation of Privilege
  • Remote Code Execution
  • Information Disclosure

System / Technologies affected

  • openSUSE Leap 15.3
  • openSUSE Leap 15.4
  • SUSE Linux Enterprise Desktop 12-SP5
  • SUSE Linux Enterprise High Availability 12-SP5
  • SUSE Linux Enterprise High Availability 15
  • SUSE Linux Enterprise High Performance Computing 12-SP5
  • SUSE Linux Enterprise High Performance Computing 15
  • SUSE Linux Enterprise High Performance Computing 15-ESPOS
  • SUSE Linux Enterprise High Performance Computing 15-LTSS
  • SUSE Linux Enterprise High Performance Computing 15-SP1
  • SUSE Linux Enterprise High Performance Computing 15-SP2
  • SUSE Linux Enterprise High Performance Computing 15-SP3
  • SUSE Linux Enterprise High Performance Computing 15-SP4
  • SUSE Linux Enterprise Live Patching 12-SP4
  • SUSE Linux Enterprise Live Patching 12-SP5
  • SUSE Linux Enterprise Micro 5.1
  • SUSE Linux Enterprise Module for Live Patching 15
  • SUSE Linux Enterprise Module for Live Patching 15-SP1
  • SUSE Linux Enterprise Module for Live Patching 15-SP2
  • SUSE Linux Enterprise Module for Live Patching 15-SP3
  • SUSE Linux Enterprise Module for Public Cloud 15-SP3
  • SUSE Linux Enterprise Module for Public Cloud 15-SP4
  • SUSE Linux Enterprise Server 12-SP2-BCL
  • SUSE Linux Enterprise Server 12-SP5
  • SUSE Linux Enterprise Server 15
  • SUSE Linux Enterprise Server 15-LTSS
  • SUSE Linux Enterprise Server 15-SP1
  • SUSE Linux Enterprise Server 15-SP2
  • SUSE Linux Enterprise Server 15-SP3
  • SUSE Linux Enterprise Server 15-SP4
  • SUSE Linux Enterprise Server for SAP 15
  • SUSE Linux Enterprise Server for SAP Applications 12-SP5
  • SUSE Linux Enterprise Server for SAP Applications 15
  • SUSE Linux Enterprise Server for SAP Applications 15-SP1
  • SUSE Linux Enterprise Server for SAP Applications 15-SP2
  • SUSE Linux Enterprise Server for SAP Applications 15-SP3
  • SUSE Linux Enterprise Server for SAP Applications 15-SP4
  • SUSE Linux Enterprise Software Development Kit 12-SP5
  • SUSE Linux Enterprise Storage 7.1
  • SUSE Linux Enterprise Workstation Extension 12-SP5
  • SUSE Manager Proxy 4.2
  • SUSE Manager Proxy 4.3
  • SUSE Manager Retail Branch Server 4.2
  • SUSE Manager Retail Branch Server 4.3
  • SUSE Manager Server 4.2
  • SUSE Manager Server 4.3

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

2022年8月12日星期五

思科產品多個漏洞

發佈日期: 2022年08月12日

風險: 中度風險

類型: 保安軟件及應用設備 - 保安軟件及應用設備

類型: 保安軟件及應用設備

在思科產品發現多個漏洞,遠端攻擊者可利用這些漏洞在目標系統觸發跨網站指令碼、權限提升、遠端執行程式碼及敏感資料洩露。


影響

  • 跨網站指令碼
  • 權限提升
  • 遠端執行程式碼
  • 資料洩露

受影響之系統或技術

詳情請參閱以下連結﹕

 


解決方案


漏洞識別碼


資料來源


相關連結

Cisco Products Multiple Vulnerabilities

Release Date: 12 Aug 2022

RISK: Medium Risk

TYPE: Security software and application - Security Software & Appliance

TYPE: Security Software & Appliance

Multiple vulnerabilities were identified in Cisco Products. A remote attacker could exploit some of these vulnerabilities to trigger cross-site scripting, elevation of privilege, remote code execution and sensitive information disclosure on the targeted system.


Impact

  • Cross-Site Scripting
  • Elevation of Privilege
  • Remote Code Execution
  • Information Disclosure

System / Technologies affected

Please refer to the link below for detail:

 

 


Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

2022年8月11日星期四

Palo Alto PAN-OS 阻斷服務狀況漏洞

發佈日期: 2022年08月11日

風險: 中度風險

類型: 保安軟件及應用設備 - 保安軟件及應用設備

類型: 保安軟件及應用設備

在 Palo Alto PAN-OS 發現一個漏洞。遠端攻擊者可利用此漏洞,於目標系統觸發阻斷服務狀況。


影響

  • 阻斷服務

受影響之系統或技術

  • PAN-OS 8.1.23-h1 之前的版本
  • PAN-OS 9.0.16-h3 之前的版本
  • PAN-OS 9.1.14-h4 之前的版本
  • PAN-OS 10.0.11-h1 之前的版本
  • PAN-OS 10.1.6-h6 之前的版本
  • PAN-OS 10.2.2-h2 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

  • 安裝供應商提供的修補程式:
    更新到 PAN-OS 8.1.23-h1, PAN-OS 9.0.16-h3, PAN-OS 9.1.14-h4, PAN-OS 10.0.11-h1, PAN-OS 10.1.6-h6, PAN-OS 10.2.2-h2 或所有更高的 PAN-OS 版本
  • 詳情請參閱以下連結:
    https://security.paloaltonetworks.com/CVE-2022-0028

漏洞識別碼


資料來源


相關連結

Palo Alto PAN-OS Denial Of Service Vulnerability

Release Date: 11 Aug 2022

RISK: Medium Risk

TYPE: Security software and application - Security Software & Appliance

TYPE: Security Software & Appliance

A vulnerability has been identified in Palo Alto PAN-OS. A remote attacker can exploit this vulnerability to trigger denial of service condition on the targeted system.


Impact

  • Denial of Service

System / Technologies affected

  • PAN-OS 8.1 versions earlier than PAN-OS 8.1.23-h1
  • PAN-OS 9.0 versions earlier than PAN-OS 9.0.16-h3
  • PAN-OS 9.1 versions earlier than PAN-OS 9.1.14-h4
  • PAN-OS 10.0 versions earlier than PAN-OS 10.0.11-h1
  • PAN-OS 10.1 versions earlier than PAN-OS 10.1.6-h6
  • PAN-OS 10.2 versions earlier than PAN-OS 10.2.2-h2

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

  • Apply fixes issued by the vendor:
    Update to PAN-OS 8.1.23-h1, PAN-OS 9.0.16-h3, PAN-OS 9.1.14-h4, PAN-OS 10.0.11-h1, PAN-OS 10.1.6-h6, PAN-OS 10.2.2-h2, and all later PAN-OS versions
  • For detail, please refer to the link below:
    https://security.paloaltonetworks.com/CVE-2022-0028

Vulnerability Identifier


Source


Related Link

Ubuntu Linux 核心多個漏洞

發佈日期: 2022年08月11日

風險: 中度風險

類型: 操作系統 - LINUX

類型: LINUX

在Ubuntu Linux 核心發現多個漏洞,攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、權限提升、遠端執行任意程式碼及洩露敏感資料。


Ubuntu Linux Kernel Multiple Vulnerabilities

Release Date: 11 Aug 2022

RISK: Medium Risk

TYPE: Operating Systems - Linux

TYPE: Linux

Multiple vulnerabilities have been identified in Ubuntu Linux Kernel. An attacker could exploit some of these vulnerabilities to trigger denial of service condition, elevation of privilege, remote code execution and sensitive information disclosure on the targeted system.


2022年8月10日星期三

Adobe 每月保安更新 (2022年8月)

發佈日期: 2022年08月10日

風險: 中度風險

類型: 用戶端 - 辦公室應用

類型: 辦公室應用

Adobe已為產品提供本月保安更新:

 

受影響產品風險程度影響備註詳情(包括 CVE)
Adobe Commerce中度風險 中度風險遠端執行程式碼
權限提升
跨網站指令碼
繞過保安限制
 APSB22-38
Adobe Acrobat and Reader中度風險 中度風險遠端執行程式碼
資料洩露
 APSB22-39
Adobe Illustrator中度風險 中度風險遠端執行程式碼
資料洩露
 APSB22-41
Adobe Framemaker中度風險 中度風險資料洩露
遠端執行程式碼
 APSB22-42
Adobe Premiere Elements中度風險 中度風險權限提升 APSB22-43

 

「極高度風險」產品數目:0

「高度風險」產品數目:0

「中度風險」產品數目:5

「低度風險」產品數目:0

整體「風險程度」評估:中度風險


影響

  • 跨網站指令碼
  • 遠端執行程式碼
  • 資料洩露
  • 權限提升
  • 繞過保安限制

受影響之系統或技術

  • Acrobat 2017 17.012.30249 及以前版本
  • Acrobat 2020 20.005.30362 及以前版本
  • Acrobat DC 22.001.20169 及以前版本
  • Acrobat Reader 2017 17.012.30249 及以前版本
  • Acrobat Reader 2020 20.005.30362 及以前版本
  • Acrobat Reader DC 22.001.20169 及以前版本
  • Adobe Commerce 2.3.7-p3 及以前版本
  • Adobe Commerce 2.4.3-p2 及以前版本
  • Adobe Commerce 2.4.4 及以前版本
  • Adobe FrameMaker 2019 Release Update 8 及以前版本
  • Adobe FrameMaker 2020 Release Update 4 及以前版本
  • Adobe Premiere Elements 2022 (Version 20.0)
  • Illustrator 2021 25.4.6 及以前版本
  • Illustrator 2022 26.3.1 及以前版本
  • Magento Open Source 2.3.7-p3 及以前版本
  • Magento Open Source 2.4.3-p2 及以前版本
  • Magento Open Source 2.4.4 及以前版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

  • 安裝供應商提供的修補程式。個別產品詳情可參考上表「詳情」一欄或執行軟件更新。

漏洞識別碼


資料來源


相關連結

蘋果 macOS 繞過保安限制漏洞

蘋果 macOS 繞過保安限制漏洞 發佈日期: 2026年08月07日 於蘋果 macOS 發現一個漏洞。遠端攻擊者可利用此漏洞,於目標系統觸發繞過保安限制。 影響 繞過保安限制 受影響之系統或技術 macOS Sequoia 15.7.9 以前的版本 macOS Sonoma ...