2024年6月14日星期五

SUSE Linux Kernel Multiple Vulnerabilities

Release Date: 14 Jun 2024

RISK: Medium Risk

TYPE: Operating Systems - Linux

Multiple vulnerabilities were identified in SUSE Linux Kernel. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, elevation of privilege, remote code execution, sensitive information disclosure and security restriction bypass on the targeted system.


Impact

  • Remote Code Execution
  • Denial of Service
  • Information Disclosure
  • Security Restriction Bypass
  • Elevation of Privilege

System / Technologies affected

  • openSUSE Leap 15.4
  • openSUSE Leap 15.5
  • openSUSE Leap Micro 5.3
  • openSUSE Leap Micro 5.4
  • Public Cloud Module 15-SP5
  • SUSE Linux Enterprise Desktop 15 SP4 LTSS 15-SP4
  • SUSE Linux Enterprise High Performance Computing 15 SP4
  • SUSE Linux Enterprise High Performance Computing 15 SP5
  • SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
  • SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
  • SUSE Linux Enterprise Live Patching 15-SP5
  • SUSE Linux Enterprise Micro 5.1
  • SUSE Linux Enterprise Micro 5.2
  • SUSE Linux Enterprise Micro 5.3
  • SUSE Linux Enterprise Micro 5.4
  • SUSE Linux Enterprise Micro 5.5
  • SUSE Linux Enterprise Micro for Rancher 5.2
  • SUSE Linux Enterprise Micro for Rancher 5.3
  • SUSE Linux Enterprise Micro for Rancher 5.4
  • SUSE Linux Enterprise Real Time 15 SP5
  • SUSE Linux Enterprise Server 15 SP4
  • SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4
  • SUSE Linux Enterprise Server 15 SP5
  • SUSE Linux Enterprise Server for SAP Applications 15 SP4
  • SUSE Linux Enterprise Server for SAP Applications 15 SP5
  • SUSE Manager Proxy 4.3
  • SUSE Manager Retail Branch Server 4.3
  • SUSE Manager Server 4.3
  • SUSE Real Time Module 15-SP5

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

2024年6月13日星期四

Fortinet 產品多個漏洞

發佈日期: 2024年06月13日

風險: 中度風險

類型: 操作系統 - Network

於 Fortinet Products 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發遠端執行任意程式碼及繞過保安限制。

 

 

影響

  • 繞過保安限制
  • 遠端執行程式碼

受影響之系統或技術

  • FortiOS 7.2.0至7.2.7
  • FortiOS 7.0.0至7.0.14
  • FortiOS 6.4所有版本
  • FortiOS 6.2所有版本
  • FortiOS 6.0所有版本
  • FortiPAM 1.2所有版本
  • FortiPAM 1.1所有版本
  • FortiPAM 1.0所有版本
  • FortiProxy 7.4.0至7.4.3
  • FortiProxy 7.2.0至7.2.9
  • FortiProxy 7.0.0至7.0.16
  • FortiProxy 2.0所有版本
  • FortiProxy 1.2所有版本
  • FortiProxy 1.1所有版本
  • FortiProxy 1.0所有版本
  • FortiSwitchManager 7.2.0至7.2.3
  • FortiSwitchManager 7.0.1至7.0.3
  • FortiClientWindows (SSL-VPN)所有版本
  • FortiClientWindows (IPsec VPN)所有版本
  • FortiClientMac所有版本
  • FortiClientLinux所有版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

Fortinet Products Multiple Vulnerabilities

Release Date: 13 Jun 2024

RISK: Medium Risk

TYPE: Operating Systems - Networks OS

Multiple vulnerabilities were identified in Fortinet Products. A remote attacker could exploit some of these vulnerabilities to trigger remote code execution and security restriction bypass on the targeted system.

 


Impact

  • Security Restriction Bypass
  • Remote Code Execution

System / Technologies affected

  • FortiOS version 7.2.0 through 7.2.7
  • FortiOS version 7.0.0 through 7.0.14
  • FortiOS version 6.4 all versions
  • FortiOS version 6.2 all versions
  • FortiOS version 6.0 all versions
  • FortiPAM version 1.2 all versions
  • FortiPAM version 1.1 all versions
  • FortiPAM version 1.0 all versions
  • FortiProxy version 7.4.0 through 7.4.3
  • FortiProxy version 7.2.0 through 7.2.9
  • FortiProxy version 7.0.0 through 7.0.16
  • FortiProxy version 2.0 all versions
  • FortiProxy version 1.2 all versions
  • FortiProxy version 1.1 all versions
  • FortiProxy version 1.0 all versions
  • FortiSwitchManager version 7.2.0 through 7.2.3
  • FortiSwitchManager version 7.0.1 through 7.0.3
  • FortiClientWindows (SSL-VPN) All versions
  • FortiClientWindows (IPsec VPN) All versions
  • FortiClientMac All versions
  • FortiClientLinux All versions

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

Mozilla Firefox 多個漏洞

發佈日期: 2024年06月13日

風險: 中度風險

類型: 用戶端 - 瀏覽器

於 Mozilla Firefox 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、遠端執行任意程式碼、資料洩露、仿冒及繞過保安限制。

 

影響

  • 阻斷服務
  • 遠端執行程式碼
  • 繞過保安限制
  • 資料洩露
  • 仿冒

受影響之系統或技術

以下版本之前的版本﹕

 

  • Firefox 127
  • Firefox ESR 115.12

解決方案

在安裝軟體之前,請先瀏覽供應商之官方網站,以獲得更多詳細資料。

更新至版本:

 

  • Firefox 127
  • Firefox ESR 115.12
 

漏洞識別碼


資料來源


相關連結

思科產品多個漏洞

思科產品多個漏洞 於思科產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況,資料篡改及繞過保安限制。 影響 阻斷服務 繞過保安限制 篡改 受影響之系統或技術 Cisco IOS Cisco IOS XE 請參考供應商發佈的連結以了解受影響的版本: https:...