2022年10月24日星期一

LibreOffice Remote Code Execution Vulnerability

Release Date: 24 Oct 2022

RISK: Medium Risk

TYPE: Clients - Productivity Products

TYPE: Productivity Products

A vulnerability was identified in LibreOffice. A remote attacker could exploit this vulnerability to trigger remote code execution on the targeted system.


Impact

  • Remote Code Execution

System / Technologies affected

  • LibreOffice Version prior to 7.3.6
  • LibreOffice Version prior to 7.4.1

Solutions

Before installation of the software, please visit the software vendor web-site for more details.

Apply fixes issued by the vendor:

  • Update LibreOffice to version 7.3.6
  • Update LibreOffice to version 7.4.1

Vulnerability Identifier


Source


Related Link

2022年10月22日星期六

思科產品多個漏洞

發佈日期: 2022年10月21日

風險: 中度風險

類型: 保安軟件及應用設備 - 保安軟件及應用設備

類型: 保安軟件及應用設備

於思科產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、洩露敏感資料及繞過保安限制。


Cisco Products Multiple Vulnerabilities

Release Date: 21 Oct 2022

RISK: Medium Risk

TYPE: Security software and application - Security Software & Appliance

TYPE: Security Software & Appliance

Multiple vulnerabilities were identified in Cisco Products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, sensitive information disclosure and security restriction bypass on the targeted system.


F5 產品多個漏洞

發佈日期: 2022年10月21日

風險: 中度風險

類型: 操作系統 - Network

類型: Network

於 F5 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、權限提升、遠端執行任意程式碼、洩露敏感資料及繞過保安限制。


影響

  • 阻斷服務
  • 權限提升
  • 遠端執行程式碼
  • 繞過保安限制
  • 資料洩露

受影響之系統或技術

  • BIG-IP (Advanced WAF, ASM)
  • BIG-IP (AFM)
  • BIG-IP (AFM, PEM)
  • BIG-IP (all modules)
  • BIG-IP (DNS, LTM enabled with DNS Services license)
  • BIG-IQ Centralized Management
  • F5OS-A
  • F5OS-C

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

F5 Products Multiple Vulnerabilities

Release Date: 21 Oct 2022

RISK: Medium Risk

TYPE: Operating Systems - Networks OS

TYPE: Networks OS

Multiple vulnerabilities were identified in F5 Products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, elevation of privilege, remote code execution, sensitive information disclosure and security restriction bypass on the targeted system.


Impact

  • Denial of Service
  • Elevation of Privilege
  • Remote Code Execution
  • Security Restriction Bypass
  • Information Disclosure

System / Technologies affected

  • BIG-IP (Advanced WAF, ASM)
  • BIG-IP (AFM)
  • BIG-IP (AFM, PEM)
  • BIG-IP (all modules)
  • BIG-IP (DNS, LTM enabled with DNS Services license)
  • BIG-IQ Centralized Management
  • F5OS-A
  • F5OS-C

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

思科產品多個漏洞

最後更新 2022年10月21日 發佈日期: 2022年10月06日

風險: 中度風險

類型: 保安軟件及應用設備 - 保安軟件及應用設備

類型: 保安軟件及應用設備

在思科產品發現多個漏洞,遠端攻擊者可利用這些漏洞在目標系統觸發繞過保安限制、遠端執行程式碼、篡改、權限提升及跨網站指令碼。

 

[Updated on 2022-10-21]

注意:CVE-2022-20917 的概念驗證碼已被公開


影響

  • 繞過保安限制
  • 權限提升
  • 遠端執行程式碼
  • 篡改
  • 跨網站指令碼

受影響之系統或技術

  • Cisco Enterprise NFV Infrastructure Software
  • Cisco Expressway Series and Cisco TelePresence Video Communication Server
  • Cisco Touch 10 Devices
  • Cisco Secure Web Appliance Content Encoding Filter
  • Cisco BroadWorks Hosted Thin Receptionist
  • Cisco ATA 190 Series Analog Telephone Adapter Software
  • Cisco Smart Software Manager On-Prem

概念驗證碼已被公開:

  • Cisco Jabber Client Software Extensible Messaging and Presence Protocol

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:

概念驗證碼已被公開:


漏洞識別碼


資料來源


相關連結

Cisco Products Multiple Vulnerabilities

Last Update Date: 21 Oct 2022 Release Date: 6 Oct 2022

RISK: Medium Risk

TYPE: Security software and application - Security Software & Appliance

TYPE: Security Software & Appliance

Multiple vulnerabilities were identified in Cisco Products. A remote attacker could exploit some of these vulnerabilities to security restriction bypass, remote code execution, data manipulation, elevation of privilege and cross-site scripting the targeted system.

 

[Updated on 2022-10-21]

Notes: Proof Of Concept Exploit Code Is Publicly Available for CVE-2022-20917


Impact

  • Security Restriction Bypass
  • Elevation of Privilege
  • Remote Code Execution
  • Data Manipulation
  • Cross-Site Scripting

System / Technologies affected

  • Cisco Enterprise NFV Infrastructure Software
  • Cisco Expressway Series and Cisco TelePresence Video Communication Server
  • Cisco Touch 10 Devices
  • Cisco Secure Web Appliance Content Encoding Filter
  • Cisco BroadWorks Hosted Thin Receptionist
  • Cisco ATA 190 Series Analog Telephone Adapter Software
  • Cisco Smart Software Manager On-Prem

Proof Of Concept Exploit Code Is Publicly Available:

  • Cisco Jabber Client Software Extensible Messaging and Presence Protocol

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:

Proof Of Concept Exploit Code Is Publicly Available:


Vulnerability Identifier


Source


Related Link

2022年10月21日星期五

Mozilla Firefox 多個漏洞

發佈日期: 2022年10月20日

風險: 中度風險

類型: 用戶端 - 瀏覽器

類型: 瀏覽器

於 Mozilla Firefox 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、遠端執行任意程式碼、洩露敏感資料。


影響

  • 遠端執行程式碼
  • 資料洩露
  • 阻斷服務

受影響之系統或技術

以下版本之前的版本﹕

 

  • Firefox 106
  • Firefox ESR 102.4

解決方案

在安裝軟體之前,請先瀏覽供應商之官方網站,以獲得更多詳細資料。

更新至版本:

 

  • Firefox 106
  • Firefox ESR 102.4

漏洞識別碼


資料來源


相關連結

Mozilla Firefox Multiple Vulnerabilities

Release Date: 20 Oct 2022

RISK: Medium Risk

TYPE: Clients - Browsers

TYPE: Browsers

Multiple vulnerabilities were identified in Mozilla Firefox. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, remote code execution and sensitive information disclosure on the targeted system.


Impact

  • Remote Code Execution
  • Information Disclosure
  • Denial of Service

System / Technologies affected

Versions prior to:

 

  • Firefox 106
  • Firefox ESR 102.4

Solutions

Before installation of the software, please visit the vendor web-site for more details.

Apply fixes issued by the vendor:

 

  • Firefox 106
  • Firefox ESR 102.4

Vulnerability Identifier


Source


Related Link

Linux 內核多個漏洞

最後更新 2022年10月20日 發佈日期: 2022年10月18日

風險: 中度風險

類型: 操作系統 - LINUX

類型: LINUX

於Linux 內核發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、權限提升、遠端執行任意程式碼、洩露敏感資料及繞過保安限制。

 

[更新於 2022-10-20] 

新增 Redhat 漏洞到以下部份。


影響

  • 阻斷服務
  • 權限提升
  • 資料洩露
  • 繞過保安限制
  • 遠端執行程式碼

受影響之系統或技術

  • openSUSE Leap 15.3
  • openSUSE Leap 15.4
  • SUSE Linux Enterprise Desktop 12-SP5
  • SUSE Linux Enterprise High Availability 12-SP4
  • SUSE Linux Enterprise High Availability 12-SP5
  • SUSE Linux Enterprise High Performance Computing 12-SP4
  • SUSE Linux Enterprise High Performance Computing 12-SP5
  • SUSE Linux Enterprise High Performance Computing 15-SP2
  • SUSE Linux Enterprise High Performance Computing 15-SP3
  • SUSE Linux Enterprise High Performance Computing 15-SP4
  • SUSE Linux Enterprise Live Patching 12-SP4
  • SUSE Linux Enterprise Live Patching 12-SP5
  • SUSE Linux Enterprise Micro 5.1
  • SUSE Linux Enterprise Module for Live Patching 15-SP2
  • SUSE Linux Enterprise Module for Live Patching 15-SP3
  • SUSE Linux Enterprise Module for Live Patching 15-SP4
  • SUSE Linux Enterprise Module for Public Cloud 15-SP3
  • SUSE Linux Enterprise Module for Public Cloud 15-SP4
  • SUSE Linux Enterprise Server 12-SP3-BCL
  • SUSE Linux Enterprise Server 12-SP4
  • SUSE Linux Enterprise Server 12-SP4-LTSS
  • SUSE Linux Enterprise Server 12-SP5
  • SUSE Linux Enterprise Server 15-SP2
  • SUSE Linux Enterprise Server 15-SP3
  • SUSE Linux Enterprise Server 15-SP4
  • SUSE Linux Enterprise Server for SAP 12-SP4
  • SUSE Linux Enterprise Server for SAP Applications 12-SP5
  • SUSE Linux Enterprise Server for SAP Applications 15-SP2
  • SUSE Linux Enterprise Server for SAP Applications 15-SP3
  • SUSE Linux Enterprise Server for SAP Applications 15-SP4
  • SUSE Linux Enterprise Software Development Kit 12-SP5
  • SUSE Linux Enterprise Storage 7.1
  • SUSE Linux Enterprise Workstation Extension 12-SP5
  • SUSE Manager Proxy 4.2
  • SUSE Manager Proxy 4.3
  • SUSE Manager Retail Branch Server 4.2
  • SUSE Manager Retail Branch Server 4.3
  • SUSE Manager Server 4.2
  • SUSE Manager Server 4.3
  • SUSE OpenStack Cloud 9
  • SUSE OpenStack Cloud Crowbar 9
  • Ubuntu 14.04 ESM
  • Ubuntu 16.04 ESM 
  • Ubuntu 18.04 LTS
  • Ubuntu 20.04 LTS
  • Ubuntu 22.04 LTS
  • Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 8.4 aarch64
  • Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 8.4 ppc64le
  • Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 8.4 x86_64
  • Red Hat Enterprise Linux for ARM 64 - Extended Update Support 8.4 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 8.4 s390x
  • Red Hat Enterprise Linux for Power, little endian - Extended Update Support 8.4 ppc64le
  • Red Hat Enterprise Linux for Real Time - Telecommunications Update Service 8.4 x86_64
  • Red Hat Enterprise Linux for Real Time for NFV - Telecommunications Update Service 8.4 x86_64
  • Red Hat Enterprise Linux for x86_64 - Extended Update Support 8.4 x86_64
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.4 x86_64
  • Red Hat Enterprise Linux Server - AUS 8.4 x86_64
  • Red Hat Enterprise Linux Server - TUS 8.4 x86_64
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.4 ppc64le

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

For SUSE

安裝供應商提供的修補程式:

 

For Ubuntu

安裝供應商提供的修補程式:

 

For Redhat

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

Linux Kernel Multiple Vulnerabilities

Last Update Date: 20 Oct 2022 Release Date: 18 Oct 2022

RISK: Medium Risk

TYPE: Operating Systems - Linux

TYPE: Linux

Multiple vulnerabilities were identified in Linux Kernel. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, elevation of privilege, remote code execution, sensitive information disclosure and security restriction bypass on the targeted system.

 

[Updated on 2022-10-20]

Added Redhat vulnerabilities to the below sections.


Impact

  • Denial of Service
  • Elevation of Privilege
  • Information Disclosure
  • Security Restriction Bypass
  • Remote Code Execution

System / Technologies affected

  • openSUSE Leap 15.3
  • openSUSE Leap 15.4
  • SUSE Linux Enterprise Desktop 12-SP5
  • SUSE Linux Enterprise High Availability 12-SP4
  • SUSE Linux Enterprise High Availability 12-SP5
  • SUSE Linux Enterprise High Performance Computing 12-SP4
  • SUSE Linux Enterprise High Performance Computing 12-SP5
  • SUSE Linux Enterprise High Performance Computing 15-SP2
  • SUSE Linux Enterprise High Performance Computing 15-SP3
  • SUSE Linux Enterprise High Performance Computing 15-SP4
  • SUSE Linux Enterprise Live Patching 12-SP4
  • SUSE Linux Enterprise Live Patching 12-SP5
  • SUSE Linux Enterprise Micro 5.1
  • SUSE Linux Enterprise Module for Live Patching 15-SP2
  • SUSE Linux Enterprise Module for Live Patching 15-SP3
  • SUSE Linux Enterprise Module for Live Patching 15-SP4
  • SUSE Linux Enterprise Module for Public Cloud 15-SP3
  • SUSE Linux Enterprise Module for Public Cloud 15-SP4
  • SUSE Linux Enterprise Server 12-SP3-BCL
  • SUSE Linux Enterprise Server 12-SP4
  • SUSE Linux Enterprise Server 12-SP4-LTSS
  • SUSE Linux Enterprise Server 12-SP5
  • SUSE Linux Enterprise Server 15-SP2
  • SUSE Linux Enterprise Server 15-SP3
  • SUSE Linux Enterprise Server 15-SP4
  • SUSE Linux Enterprise Server for SAP 12-SP4
  • SUSE Linux Enterprise Server for SAP Applications 12-SP5
  • SUSE Linux Enterprise Server for SAP Applications 15-SP2
  • SUSE Linux Enterprise Server for SAP Applications 15-SP3
  • SUSE Linux Enterprise Server for SAP Applications 15-SP4
  • SUSE Linux Enterprise Software Development Kit 12-SP5
  • SUSE Linux Enterprise Storage 7.1
  • SUSE Linux Enterprise Workstation Extension 12-SP5
  • SUSE Manager Proxy 4.2
  • SUSE Manager Proxy 4.3
  • SUSE Manager Retail Branch Server 4.2
  • SUSE Manager Retail Branch Server 4.3
  • SUSE Manager Server 4.2
  • SUSE Manager Server 4.3
  • SUSE OpenStack Cloud 9
  • SUSE OpenStack Cloud Crowbar 9
  • Ubuntu 14.04 ESM
  • Ubuntu 16.04 ESM 
  • Ubuntu 18.04 LTS
  • Ubuntu 20.04 LTS
  • Ubuntu 22.04 LTS
  • Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 8.4 aarch64
  • Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 8.4 ppc64le
  • Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 8.4 x86_64
  • Red Hat Enterprise Linux for ARM 64 - Extended Update Support 8.4 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 8.4 s390x
  • Red Hat Enterprise Linux for Power, little endian - Extended Update Support 8.4 ppc64le
  • Red Hat Enterprise Linux for Real Time - Telecommunications Update Service 8.4 x86_64
  • Red Hat Enterprise Linux for Real Time for NFV - Telecommunications Update Service 8.4 x86_64
  • Red Hat Enterprise Linux for x86_64 - Extended Update Support 8.4 x86_64
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.4 x86_64
  • Red Hat Enterprise Linux Server - AUS 8.4 x86_64
  • Red Hat Enterprise Linux Server - TUS 8.4 x86_64
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.4 ppc64le

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

For SUSE

Apply fixes issued by the vendor:

 

For Ubuntu

Apply fixes issued by the vendor:

 

For Redhat

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

2022年10月19日星期三

甲骨文產品多個漏洞

發佈日期: 2022年10月19日

風險: 中度風險

類型: 伺服器 - 數據庫伺服器

類型: 數據庫伺服器

於甲骨文產品發現多個漏洞,遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、遠端執行程式碼、繞過保安限制、洩露敏感資料及資料篡改。


影響

  • 阻斷服務
  • 遠端執行程式碼
  • 繞過保安限制
  • 資料洩露
  • 篡改

受影響之系統或技術

  • Oracle MySQL
  • Java SE
  • Oracle Database Server
  • VirtualBox

 

有關其他 甲骨文 產品,請參閱以下連結:

https://www.oracle.com/security-alerts/cpuoct2022.html


解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:

甲骨文 Critical Patch Update Advisory


漏洞識別碼


資料來源


相關連結

Oracle Products Multiple Vulnerabilities

Release Date: 19 Oct 2022

RISK: Medium Risk

TYPE: Servers - Database Servers

TYPE: Database Servers

Multiple vulnerabilities were identified in Oracle Products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, remote code execution, security restriction bypass, sensitive information disclosure and data manipulation on the targeted system.


Impact

  • Denial of Service
  • Remote Code Execution
  • Security Restriction Bypass
  • Information Disclosure
  • Data Manipulation

System / Technologies affected

  • Oracle MySQL
  • Java SE
  • Oracle Database Server
  • VirtualBox

 

For other Oracle products, please refer to the link below:

https://www.oracle.com/security-alerts/cpuoct2022.html


Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:

Oracle Critical Patch Update Advisory


Vulnerability Identifier


Source


Related Link

2022年10月18日星期二

Apache Commons Text 遠端執行程式碼漏洞

發佈日期: 2022年10月18日

風險: 高度風險

類型: 伺服器 - 網站伺服器

類型: 網站伺服器

於 Apache Commons Text 發現一個漏洞,遠端使用者可利用這些漏洞,於目標系統觸發遠端執行任意程式碼。

 

注意:CVE-2022-42889 的概念驗證碼已被公開


影響

  • 遠端執行程式碼

受影響之系統或技術

  • Apache Commons Text 1.10.0 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:

  • Apache Commons Text 1.10.0 或之後版本

漏洞識別碼


資料來源


相關連結

Apache Commons Text Remote Code Execution Vulnerabilities

Release Date: 18 Oct 2022

RISK: High Risk

TYPE: Servers - Web Servers

TYPE: Web Servers

A vulnerability has been identified in Apache Commons Text. A remote user can exploit some of these vulnerabilities to trigger remote code execution on the targeted system. 

 

Notes: Proof Of Concept Exploit Code Is Publicly Available for CVE-2022-42889


Impact

  • Remote Code Execution

System / Technologies affected

  • Apache Commons Text prior to 1.10.0

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:

  • Apache Commons Text 1.10.0 or later

Vulnerability Identifier


Source


Related Link

Apache Tomcat 多個漏洞

Apache Tomcat 多個漏洞 發佈日期: 2026年08月05日 風險: 中度風險 類型: 伺服器 - 網站伺服器 於 Apache T...