2023年1月19日星期四

GitLab Remote Code Execution Vulnerabilities

Release Date: 19 Jan 2023

RISK: Medium Risk

TYPE: Servers - Other Servers

TYPE: Other Servers

Multiple vulnerabilities were identified in GitLab. A remote attacker could exploit some of these vulnerabilities to trigger remote code execution on the targeted system.


Impact

  • Remote Code Execution

System / Technologies affected

  • GitLab Community Edition (CE) versions prior to 15.7.5, 15.6.6, and 15.5.9
  • GitLab Enterprise Edition (EE) versions prior to 15.7.5, 15.6.6, and 15.5.9

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

Mozilla Firefox 多個漏洞

發佈日期: 2023年01月19日

風險: 中度風險

類型: 用戶端 - 瀏覽器

類型: 瀏覽器

於 Mozilla Firefox 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發彷冒、遠端執行任意程式碼、洩露敏感資料及繞過保安限制。


影響

  • 仿冒
  • 遠端執行程式碼
  • 資料洩露
  • 繞過保安限制

受影響之系統或技術

以下版本之前的版本﹕

 

  • Firefox 109
  • Firefox ESR 102.7

解決方案

在安裝軟體之前,請先瀏覽供應商之官方網站,以獲得更多詳細資料。

更新至版本:

 

  • Firefox 109
  • Firefox ESR 102.7

漏洞識別碼


資料來源


相關連結

Mozilla Firefox Multiple Vulnerabilities

Release Date: 19 Jan 2023

RISK: Medium Risk

TYPE: Clients - Browsers

TYPE: Browsers

Multiple vulnerabilities were identified in Mozilla Firefox. A remote attacker could exploit some of these vulnerabilities to trigger spoofing, remote code execution, sensitive information disclosure and security restriction bypass on the targeted system.


Impact

  • Spoofing
  • Remote Code Execution
  • Information Disclosure
  • Security Restriction Bypass

System / Technologies affected

Versions prior to:

 

  • Firefox 109
  • Firefox ESR 102.7

Solutions

Before installation of the software, please visit the vendor web-site for more details.

Apply fixes issued by the vendor:

 

  • Firefox 109
  • Firefox ESR 102.7

Vulnerability Identifier


Source


Related Link

Ubuntu Linux 核心多個漏洞

最後更新 2023年01月19日 發佈日期: 2023年01月10日

風險: 中度風險

類型: 操作系統 - LINUX

類型: LINUX

在Ubuntu Linux 核心發現多個漏洞,遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、遠端執行任意程式碼、洩露敏感資料及繞過保安限制。

 

[更新於 2023-01-11] 

更新受影響之系統及相關連結。

 

[更新於 2023-01-12] 

更新解決方案、漏洞識別碼及相關連結。

 

[更新於 2023-01-16] 

更新解決方案及相關連結。

 

[更新於 2023-01-19] 

更新解決方案及相關連結。


影響

  • 阻斷服務
  • 遠端執行程式碼
  • 資料洩露
  • 繞過保安限制

受影響之系統或技術

  • Ubuntu 14.04 ESM
  • Ubuntu 16.04 ESM
  • Ubuntu 18.04 LTS
  • Ubuntu 20.04 LTS
  • Ubuntu 22.04 LTS
  • Ubuntu 22.10

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

Ubuntu Linux Kernel Multiple Vulnerabilities

Last Update Date: 19 Jan 2023 Release Date: 10 Jan 2023

RISK: Medium Risk

TYPE: Operating Systems - Linux

TYPE: Linux

Multiple vulnerabilities have been identified in Ubuntu Linux Kernel. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, remote code execution, sensitive information disclosure and security restriction bypass on the targeted system.

 

[Updated on 2023-01-11] 

Updated System affected and Related Links.

 

[Updated on 2023-01-12] 

Updated Solutions, Vulnerability Identifier and Related Links.

 

[Updated on 2023-01-16] 

Updated Solutions and Related Links.

 

[Updated on 2023-01-19] 

Updated Solutions and Related Links.


Impact

  • Denial of Service
  • Remote Code Execution
  • Information Disclosure
  • Security Restriction Bypass

System / Technologies affected

  • Ubuntu 14.04 ESM
  • Ubuntu 16.04 ESM
  • Ubuntu 18.04 LTS
  • Ubuntu 20.04 LTS
  • Ubuntu 22.04 LTS
  • Ubuntu 22.10

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

2023年1月18日星期三

甲骨文產品多個漏洞

發佈日期: 2023年01月18日

風險: 中度風險

類型: 伺服器 - 數據庫伺服器

類型: 數據庫伺服器

於甲骨文產品發現多個漏洞,遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、遠端執行程式碼、繞過保安限制、洩露敏感資料及資料篡改。


影響

  • 阻斷服務
  • 遠端執行程式碼
  • 繞過保安限制
  • 資料洩露
  • 篡改

受影響之系統或技術

  • Oracle MySQL
  • Java SE
  • Oracle Database Server
  • VirtualBox

 

有關其他 甲骨文 產品,請參閱以下連結:

https://www.oracle.com/security-alerts/cpujan2023.html


解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:

https://www.oracle.com/security-alerts/cpujan2023.html


漏洞識別碼


資料來源


相關連結

Oracle Products Multiple Vulnerabilities

Release Date: 18 Jan 2023

RISK: Medium Risk

TYPE: Servers - Database Servers

TYPE: Database Servers

Multiple vulnerabilities were identified in Oracle Products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, remote code execution, security restriction bypass, sensitive information disclosure and data manipulation on the targeted system.


Impact

  • Denial of Service
  • Remote Code Execution
  • Security Restriction Bypass
  • Information Disclosure
  • Data Manipulation

System / Technologies affected

  • Oracle MySQL
  • Java SE
  • Oracle Database Server
  • VirtualBox

 

For other Oracle products, please refer to the link below:

https://www.oracle.com/security-alerts/cpujan2023.html


Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:

https://www.oracle.com/security-alerts/cpujan2023.html


Vulnerability Identifier


Source


Related Link

2023年1月16日星期一

ChromeOS 多個漏洞

發佈日期: 2023年01月16日 88 觀看次數

風險: 中度風險

類型: 操作系統 - 其他操作系統

類型: 其他操作系統

於 ChromeOS 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況及遠端執行任意程式碼。


影響

  • 遠端執行程式碼
  • 阻斷服務

受影響之系統或技術

  • 109.0.5414.94 之前的版本(平台版本:15236.66.0)

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

 


漏洞識別碼


資料來源


相關連結

ChromeOS Multiple Vulnerabilities

Release Date: 16 Jan 2023

RISK: Medium Risk

TYPE: Operating Systems - Others OS

TYPE: Others OS

Multiple vulnerabilities were identified in ChromeOS. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition and remote code execution on the targeted system.


Impact

  • Remote Code Execution
  • Denial of Service

System / Technologies affected

  • Version prior to 109.0.5414.94 (Platform version: 15236.66.0)

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

 


Vulnerability Identifier


Source


Related Link

Ubuntu Linux 核心多個漏洞

最後更新 2023年01月16日 發佈日期: 2023年01月10日

風險: 中度風險

類型: 操作系統 - LINUX

類型: LINUX

在Ubuntu Linux 核心發現多個漏洞,遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、遠端執行任意程式碼、洩露敏感資料及繞過保安限制。

 

[更新於 2023-01-11] 

更新受影響之系統及相關連結。

 

[更新於 2023-01-12] 

更新解決方案、漏洞識別碼及相關連結。

 

[更新於 2023-01-16] 

更新解決方案及相關連結。


影響

  • 阻斷服務
  • 遠端執行程式碼
  • 資料洩露
  • 繞過保安限制

受影響之系統或技術

  • Ubuntu 14.04 ESM
  • Ubuntu 16.04 ESM
  • Ubuntu 18.04 LTS
  • Ubuntu 20.04 LTS
  • Ubuntu 22.04 LTS
  • Ubuntu 22.10

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

Ubuntu Linux Kernel Multiple Vulnerabilities

Last Update Date: 16 Jan 2023 Release Date: 10 Jan 2023

RISK: Medium Risk

TYPE: Operating Systems - Linux

TYPE: Linux

Multiple vulnerabilities have been identified in Ubuntu Linux Kernel. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, remote code execution, sensitive information disclosure and security restriction bypass on the targeted system.

 

[Updated on 2023-01-11] 

Updated System affected and Related Links.

 

[Updated on 2023-01-12] 

Updated Solutions, Vulnerability Identifier and Related Links.

 

[Updated on 2023-01-16] 

Updated Solutions and Related Links.


Impact

  • Denial of Service
  • Remote Code Execution
  • Information Disclosure
  • Security Restriction Bypass

System / Technologies affected

  • Ubuntu 14.04 ESM
  • Ubuntu 16.04 ESM
  • Ubuntu 18.04 LTS
  • Ubuntu 20.04 LTS
  • Ubuntu 22.04 LTS
  • Ubuntu 22.10

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

2023年1月13日星期五

思科產品多個漏洞

發佈日期: 2023年01月13日

風險: 中度風險

類型: 保安軟件及應用設備 - 保安軟件及應用設備

類型: 保安軟件及應用設備

於思科產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、遠端執行任意程式碼、洩露敏感資料、資料篡改、跨網站指令碼及繞過保安限制。


影響

  • 遠端執行程式碼
  • 跨網站指令碼
  • 繞過保安限制
  • 資料洩露
  • 阻斷服務
  • 篡改

受影響之系統或技術

  • Cisco BroadWorks Application Delivery Platform Device Management Software
  • Cisco BroadWorks Application Server
  • Cisco BroadWorks Xtended Services Platform
  • Cisco CX Cloud Agent
  • Cisco IND
  • Cisco NSO
  • IP Phone 7800 Series
  • IP Phone 8800 Series
  • Packaged Contact Center Enterprise (CCE)
  • RoomOS Software in cloud-aware on-premises operation, which is cloud based
  • RV160 VPN Routers
  • RV160W Wireless-AC VPN Routers
  • RV260 VPN Routers
  • RV260P VPN Routers with PoE
  • RV260W Wireless-AC VPN Routers
  • RV340 Dual WAN Gigabit VPN Routers
  • RV340W Dual WAN Gigabit Wireless-AC VPN Routers
  • RV345 Dual WAN Gigabit VPN Routers
  • RV345P Dual WAN Gigabit POE VPN Routers
  • TelePresence CE Software
  • Unified CCE
  • Unified Contact Center Express (CCX)
  • Webex Room Phone
  • Webex Share

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

Cisco Products Multiple Vulnerabilities

Release Date: 13 Jan 2023

RISK: Medium Risk

TYPE: Security software and application - Security Software & Appliance

TYPE: Security Software & Appliance

Multiple vulnerabilities were identified in Cisco Products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, remote code execution, sensitive information disclosure, data manipulation, cross-site scripting and security restriction bypass on the targeted system.


Impact

  • Remote Code Execution
  • Cross-Site Scripting
  • Security Restriction Bypass
  • Information Disclosure
  • Denial of Service
  • Data Manipulation

System / Technologies affected

  • Cisco BroadWorks Application Delivery Platform Device Management Software
  • Cisco BroadWorks Application Server
  • Cisco BroadWorks Xtended Services Platform
  • Cisco CX Cloud Agent
  • Cisco IND
  • Cisco NSO
  • IP Phone 7800 Series
  • IP Phone 8800 Series
  • Packaged Contact Center Enterprise (CCE)
  • RoomOS Software in cloud-aware on-premises operation, which is cloud based
  • RV160 VPN Routers
  • RV160W Wireless-AC VPN Routers
  • RV260 VPN Routers
  • RV260P VPN Routers with PoE
  • RV260W Wireless-AC VPN Routers
  • RV340 Dual WAN Gigabit VPN Routers
  • RV340W Dual WAN Gigabit Wireless-AC VPN Routers
  • RV345 Dual WAN Gigabit VPN Routers
  • RV345P Dual WAN Gigabit POE VPN Routers
  • TelePresence CE Software
  • Unified CCE
  • Unified Contact Center Express (CCX)
  • Webex Room Phone
  • Webex Share

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

Apache Tomcat 多個漏洞

Apache Tomcat 多個漏洞 發佈日期: 2026年08月05日 風險: 中度風險 類型: 伺服器 - 網站伺服器 於 Apache T...