ENISA EUVD · EUVD-2017-14792Official EUVD mapping0 linked advisory records.
Official EUVD record ↗BSI · German · WID-SEC-2023-2917Xerox FreeFlow Print Server: Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in Xerox FreeFlow Print Server ausnutzen, um die Vertraulichkeit, Verfügbarkeit und Integrität des Systems zu gefährden.
Official advisory ↗BSI · German · WID-SEC-2022-0532Linux Kernel: Mehrere SchwachstellenEin entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um beliebigen Programmcode mit Administratorrechten auszuführen, einen Denial of Service Angriff durchzuführen, Sicherheitsmechanismen zu umgehen, vertrauliche Daten einzusehen oder seine Privilegien zu erweitern.
Official advisory ↗BSI · German · WID-SEC-2024-2008Oracle Virtualization: Mehrere SchwachstellenEin entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Secure Global Desktop und Oracle VM Virtual Box ausnutzen, um die Verfügbarkeit, Vertraulichkeit und Integrität zu gefährden.
Official advisory ↗BSI · German · WID-SEC-2023-0103Meltdown und Spectre: Mehrere SchwachstellenEin entfernter, anonymer Angreifer kann mehrere Schwachstellen in den meisten der aktuellen Prozessoren ausnutzen, um Sicherheitsmechanismen zu umgehen und physikalischen Speicher auszulesen.
Official advisory ↗Canadian Centre for Cyber Security · English · AV18-116Juniper security bulletins0121, CVE-2013-4545, CVE-2014-3707, CVE-2014-8150, CVE-2017-1000099, CVE-2017-1000100, CVE-2017-1000101, CVE-2013-6422, CVE-2014-0015, CVE-2016-3739, CVE-2017-7407, CVE-2016-8615, CVE-2016-8616, CVE-2016-8617, CVE-2016-8618, CVE-2016-8619, CVE-2016-8620, CVE-2016-8621, CVE-2016-8622, CVE-2016-8623, CVE-2016-8624, CVE-2016-8625, CVE-2017-3145, CVE-2018-2579, CVE-2018-2588, CVE-2018-2599, CVE-2018-2603, CVE-2018-2618, CVE-2018-2629, CVE-2018-2633, CVE-2018-2637, CVE-2018-2663, CVE-2018-2678, CVE-2017-12613, CVE-2017-10198, 2017-10281, CVE-2017-10295, CVE-2017-10345, CVE-2017-10355, CVE-2017-10356, CVE-2017-10388, CVE-2017-15896, CVE-2017-5753, CVE-2017-5715, CVE-2017-5754, CVE-2018-0039, CVE-2018-0040, CVE-2018-0042, CVE-2018-0038, CVE-2018-0041, CVE-2018-1000115, CVE-2018-0037, CVE-2018-0034, CVE-2018-0035, CVE-2018-0032, CVE-2018-0031, CVE-2018-0030, CVE-2018-0029, CVE-2018-0027, CVE-2018-0026, CVE-2018-0025, CVE-2018-0024, CVE-2015-7236
Suggested action
CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.
References
https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10803&cat=SIRT_1&actp=LIST
https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10857&cat=SIRT_1&actp=LIST
https://kb.juniper.net/InfoCenter/i
Official advisory ↗Canadian Centre for Cyber Security · English · AV18-084Cisco security updatesCisco released multiple security updates to address vulnerabilities (medium to critical) in various Cisco products.
Affected Products:
Cisco Enterprise NFV Infrastructure Software CLI Command Injection Vulnerability
Cisco Digital Network Architecture Center Authentication Bypass Vulnerability
Cisco Enterprise NFV Infrastructure Software Linux Shell Access Vulnerability
Cisco Enterprise NFV Infrastructure Software Web Management Interface Path Traversal Vulnerability
Cisco IP Phone 7800 Series and 8800 Series Denial of Service Vulnerability
Cisco Firepower Threat Defense Software Policy Bypass Vulnerability
Cisco Identity Services Engine EAP TLS Certificate Denial of Service Vulnerability
Cisco IoT Field Network Director Cross-Site Request Forgery Vulnerability
Cisco Identity Services Engine Logs Cross-Site Scripting Vulnerability
Cisco Digital Network Architecture Center Unauthorized Access Vulnerability
Cisco Identity Services Engine Logs Cross-Site Scripting Vulnerability
Cisco IoT Field Network Director Cross-Site Request Forgery Vulnerability
Cisco Identity Services Engine EAP TLS Certificate Denial of Service Vulnerability
Cisco SocialMiner Notification System Denial of Service Vulnerability
Cisco TelePresence Server Cross-Frame Scripting Vulnerability
Cisco Meeting Server Media Services Denial of Service Vulnerability
CPU Side-Channel Information Disclosure Vulnerabilities
CVE References: CVE-2018-0222, CVE-2018-0268, CVE-2018-0270, CVE-2018-0271, CVE-2018-0277, CVE-2018-0279, CVE-2018-0289, CVE-2018-0290, CVE-2018-0297, CVE-2018-0323, CVE-2018-0324, CVE-2018-0325, CVE-2018-0327, CVE-2018-0328, CVE-2017-5715, CVE-2017-5753, CVE-2017-5754
Official advisory ↗Canadian Centre for Cyber Security · English · AV18-080Android security bulletin – May 2018Number: AV18-080
Date: 11 May 2018
Purpose
The purpose of this advisory is to bring attention to the Android Security Bulletin for May.
Assessment
The Android Security Bulletin addresses security updates for 23 vulnerabilities (2 Critical and 21 High). Successful exploitation could allow for a remote unauthenticated user to gain privilege escalation and allow remote code execution.
CVE References: CVE-2018-3562, CVE-2018-3565, CVE-2018-3578, CVE-2018-3580, CVE-2017-5715, CVE-2017-5754, CVE-2018-5840, CVE-2018-5841, CVE-2018-5845, CVE-2018-5846, CVE-2018-5850, CVE-2017-6289, CVE-2017-6293, CVE-2017-13077, CVE-2017-13309, CVE-2017-13310, CVE-2017-13311, CVE-2017-13312, CVE-2017-13313, CVE-2017-13314, CVE-2017-13315, CVE-2017-16643, CVE-2017-18154
Suggested Action
CCIRC recommends that system administrators check with their respected Android phone vendor and carrier when the update will be available and test and deploy the vendor-released updates to affected devices accordingly.
References:
Android Security Bulletin:
https://source.android.com/security/bulletin/2018-05-01
Official advisory ↗Canadian Centre for Cyber Security · English · AV18-071Microsoft security updates for Spectre v2Two updates have been released by Microsoft in regards to mitigation towards the Spectre Variant 2 “Branch Target Injection” vulnerability. KB4078407 is software-based OS-level mitigation, whereas KB4091666 is for Intel processors only and includes Intel microcode updates needed to mitigate at the hardware level.
Affected Products:
Windows 10 version 1709
Windows Server 2016 Version 1709
Windows 10 Version 1703
Windows 10 Version 1607
Windows Server 2016
Windows Server 2016 Datacenter
Windows Server 2016 Essentials
Windows Server 2016 Standard
Windows 10 with Intel CPU
CVE References: CVE-2017-5715
Official advisory ↗Canadian Centre for Cyber Security · English · AV18-065Oracle Critical Patch update Advisory - April 2018ces: CVE-2013-1768, CVE-2014-0054, CVE-2015-7501, CVE-2015-7940, CVE-2016-0635, CVE-2016-2177, CVE-2016-2178, CVE-2016-2179, CVE-2016-2180, CVE-2016-2181, CVE-2016-2182, CVE-2016-2183, CVE-2016-3092, CVE-2016-3506, CVE-2016-5007, CVE-2016-5019, CVE-2016-6302, CVE-2016-6303, CVE-2016-6304, CVE-2016-6305, CVE-2016-6306, CVE-2016-6307, CVE-2016-6308, CVE-2016-6309, CVE-2016-6814, CVE-2016-7052, CVE-2016-8745, CVE-2016-9878, CVE-2017-1039, CVE-2017-1040, CVE-2017-1261, CVE-2017-1307, CVE-2017-1308, CVE-2017-1509, CVE-2017-1570, CVE-2017-1756, CVE-2017-3735, CVE-2017-3736, CVE-2017-3737, CVE-2017-3738, CVE-2017-5645, CVE-2017-5662, CVE-2017-5664, CVE-2017-5715, CVE-2017-5753, CVE-2017-5754, CVE-2017-7525, CVE-2017-7674, CVE-2017-7805, CVE-2017-9798, CVE-2018-0739, CVE-2018-2563, CVE-2018-2572, CVE-2018-2587, CVE-2018-2628, CVE-2018-2718, CVE-2018-2737, CVE-2018-2738, CVE-2018-2739, CVE-2018-2742, CVE-2018-2746, CVE-2018-2747, CVE-2018-2748, CVE-2018-2749, CVE-2018-2750, CVE-2018-2752, CVE-2018-2753, CVE-2018-2754, CVE-2018-2755, CVE-2018-2756, CVE-2018-2758, CVE-2018-2759, CVE-2018-2760, CVE-2018-2761, CVE-2018-2762, CVE-2018-2763, CVE-2018-2764, CVE-2018-2765, CVE-2018-2766, CVE-2018-2768, CVE-2018-2769, CVE-2018-2770, CVE-2018-2771, CVE-2018-2772, CVE-2018-2773, CVE-2018-2774, CVE-2018-2775, CVE
Official advisory ↗Canadian Centre for Cyber Security · English · AV18-062AMD security update - Microcode for Spectre v2An operating system update released by Microsoft contains Variant 2 (Spectre) mitigations for AMD users running Windows 10 (version 1709).
Affected Products:
- Windows 10 version 1709
CVE References: CVE-2017-5715
Official advisory ↗Canadian Centre for Cyber Security · English · AV18-034Intel security updateIntel has released a security update to address vulnerabilities in Intel-based platforms with microprocessors utilizing speculative execution and indirect branch prediction which may allow unauthorized disclosure of information to a user with local user access via a side-channel analysis.
Products Affected:
Intel® Core™ i3 processor (45nm and 32nm)
Intel® Core™ i5 processor (45nm and 32nm)
Intel® Core™ i7 processor (45nm and 32nm)
Intel® Core™ M processor family (45nm and 32nm)
2nd generation Intel® Core™ processors
3rd generation Intel® Core™ processors
4th generation Intel® Core™ processors
5th generation Intel® Core™ processors
6th generation Intel® Core™ processors
7th generation Intel® Core™ processors
8th generation Intel® Core™ processors
Intel® Core™ X-series Processor Family for Intel® X99 platforms
Intel® Core™ X-series Processor Family for Intel® X299 platforms
Intel® Xeon® processor 3400 series
Intel® Xeon® processor 3600 series
Intel® Xeon® processor 5500 series
Intel® Xeon® processor 5600 series
Intel® Xeon® processor 6500 series
Intel® Xeon® processor 7500 series
Intel® Xeon® Processor E3 Family
Intel® Xeon® Processor E3 v2 Family
Intel® Xeon® Processor E3 v3 Family
Intel® Xeon® Processor E3 v4 Family
Intel® Xeon® Processor E3 v5 Family
Intel® Xeon® Processor E3 v6 Family
Intel® Xeon® Processor E5 Family
Intel® Xeon® Processor E5 v2 Family
Intel® Xeon® Processor E5 v3 Family
Intel® Xeon® Processor E5 v4 Family
Intel® Xeon® Processor E7 Family
Intel® Xeon® Processor E7 v2 Family
Intel® Xeon® Processor E7 v3 Family
Intel® Xeon® Processor E7 v4 Family
Intel® Xeon® Processor Scalable Family
Intel® Xeon Phi™ Processor 3200, 5200, 7200 Series
Intel® Atom™ Processor C Series
Intel® Atom™ Processor E Series
Intel® Atom™ Processor A Series
Intel® Atom™ Processor x3 Series
Intel® Atom™ Processor Z Series
Intel® Celeron® Processor J Series
Intel® Celeron® Processor N Series
Intel® Pentium® Processor J Series
Intel® Pentium® Processor N Series
CVE References: CVE-2017-5715, CVE-2017-5753, CVE-2017-5754
Official advisory ↗Canadian Centre for Cyber Security · English · AV18-020Microsoft security update – Out-of-BandThe summary covers an out-of-band support package deployment addressing issues with recently released microcode meant to address Spectre vulnerability variant 2.
Affected Products:
Windows 7 Service Pack 1
Windows 8.1
Windows 10
Windows 10 Version 1511
Windows 10 Version 1607
Windows 10 Version 1703
Windows 10 version 1709
Windows Server 2008 R2 Standard
Windows Server 2012 R2 Standard
CVE References: CVE-2017-5715
Official advisory ↗Canadian Centre for Cyber Security · English · AV18-012Oracle Critical Patch updates106, CVE-2016-2107, CVE-2016-2109, CVE-2016-2177, CVE-2016-2178, CVE-2016-2179, CVE-2016-2180, CVE-2016-2181, CVE-2016-2182, CVE-2016-2183, CVE-2016-2518, CVE-2016-2550, CVE-2016-4449, CVE-2016-5385, CVE-2016-5387, CVE-2016-6302, CVE-2016-6303, CVE-2016-6304, CVE-2016-6305, CVE-2016-6306, CVE-2016-6307, CVE-2016-6308, CVE-2016-6309, CVE-2016-6814, CVE-2016-7052, CVE-2016-7055, CVE-2016-7977, CVE-2016-8735, CVE-2016-9878, CVE-2017-0781, CVE-2017-0782, CVE-2017-0783, CVE-2017-0785, CVE-2017-3730, CVE-2017-3731, CVE-2017-3732, CVE-2017-3733, CVE-2017-3735, CVE-2017-3736, CVE-2017-3737, CVE-2017-3738, CVE-2017-5461, CVE-2017-5645, CVE-2017-5664, CVE-2017-5715, CVE-2017-9072, CVE-2017-9798, CVE-2017-10068, CVE-2017-10262, CVE-2017-10273, CVE-2017-10282, CVE-2017-10301, CVE-2017-10352, CVE-2017-12617, CVE-2017-13077, CVE-2017-13078, CVE-2017-13079, CVE-2017-13080, CVE-2017-13081, CVE-2017-13082, CVE-2018-2560, CVE-2018-2561, CVE-2018-2562, CVE-2018-2564, CVE-2018-2565, CVE-2018-2566, CVE-2018-2567, CVE-2018-2568, CVE-2018-2569, CVE-2018-2570, CVE-2018-2571, CVE-2018-2573, CVE-2018-2574, CVE-2018-2575, CVE-2018-2576, CVE-2018-2577, CVE-2018-2578, CVE-2018-2579, CVE-2018-2580, CVE-2018-2581, CVE-2018-2582, CVE-2018-2583, CVE-2018-2584, CVE-2018-2585, CVE-2018-2586, CVE-2018-2588, CVE-2018-2589, CVE-2
Official advisory ↗Canadian Centre for Cyber Security · English · AV18-008NVIDIA security advisoryNVIDIA has released product updates addressing multiple security vulnerabilities for multiple products.
Affected Products:
GeForce (All versions)
Quadro, NVS (All versions)
Tesla (All versions)
GRID (All versions)
CVE Reference: CVE-2017-5753, CVE-2017-5715, CVE-2017-5754
Official advisory ↗Canadian Centre for Cyber Security · English · AV18-009VMware security advisoryVMware has released product updates addressing multiple security vulnerabilities in VMware products.
Affected Products:
VMware vCenter Server (VC)
VMware vSphere ESXi (ESXi)
VMware Workstation Pro / Player (Workstation)
VMware Fusion Pro / Fusion (Fusion)
CVE Reference: CVE-2017-5715
Official advisory ↗Canadian Centre for Cyber Security · English · AV18-004Apple security updatesApple has released a support article regarding security vulnerabilities in their products and the relevant iOS, macOS High Sierra, Safari, tvOS, watchOS.
- iOS versions prior to 11.2.2
- macOS versions prior to 10.13.2.
- tvOS versions prior to 11.2.1.
- watchOS versions prior to 4.2.
- Safari versions prior to 11.0.2.
CVE Reference: CVE-2017-5753, CVE-2017-5715
Official advisory ↗Canadian Centre for Cyber Security · English · AL18-001Meltdown and Spectre Side-Channel VulnerabilitiesThese hardware vulnerabilities work on personal computers, mobile devices, and in the cloud. Every Intel processor which implements out-of-order execution is potentially affected by Meltdown. Spectre affects Intel, AMD and ARM processors.
Both Meltdown and Spectre use side-channel to obtain the information from the accessed memory location, termed “Kernel-memory-leaking”. While Meltdown breaks the mechanism that keeps applications from accessing arbitrary system memory, Spectre tricks other applications into accessing arbitrary locations in their memory. Leaked information could include passwords stored in a password manager or browser, personal photos, emails, instant messages and documents.
The exploitation does not leave any traces and it is unlikely that the intrusion would be detected. However, the antivirus may detect malware used in the intrusion. There has not been a confirmation of any active exploitation at this time.
Official advisory ↗Canadian Centre for Cyber Security · English · AV18-002Microsoft security updates – Out-of-Band-based Systems Service Pack 1
Windows 8.1 for x64-based systems
Windows 8.1 for 32-bit systems
Windows 7 for x64-based Systems Service Pack 1
Windows 7 for 32-bit Systems Service Pack 1
Windows 10 Version 1709 for 64-based Systems
Windows 10 Version 1709 for 32-bit Systems
Windows 10 Version 1703 for x64-based Systems
Windows 10 Version 1703 for 32-bit Systems
Windows 10 Version 1607 for x64-based Systems
Windows 10 Version 1607 for 32-bit Systems
Windows 10 Version 1511 for x64-based Systems
Windows 10 Version 1511 for 32-bit Systems
Windows 10 for x64-based Systems
Windows 10 for 32-bit Systems
CVE References: CVE-2017-5754, CVE-2017-5753, CVE-2017-5715, CVE-2018-0818, CVE-2018-0788, CVE-2018-0754, CVE-2018-0750, CVE-2018-0741, CVE-2018-0753, CVE-2018-0746, CVE-2018-0747, CVE-2018-0748, CVE-2018-0751, CVE-2018-0752, CVE-2018-0744, CVE-2018-0745, CVE-2018-0749, CVE-2018-0743, CVE-2018-0762, CVE-2018-0772, CVE-2018-0766, CVE-2018-0773, CVE-2018-0774, CVE-2018-0781, CVE-2018-0800, CVE-2018-0758, CVE-2018-0767, CVE-2018-0768, CVE-2018-0769, CVE-2018-0770, CVE-2018-0775, CVE-2018-0776, CVE-2018-0777, CVE-2018-0778, CVE-2018-0780, CVE-2018-0803
Suggested Action
CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.
References:
Official advisory ↗CERT-FR · French · CERTFR-2023-AVI-0733Multiples vulnérabilités dans les produits Siemens.html
Bulletin de sécurité Siemens SSA-240541 du 12 septembre 2023
https://cert-portal.siemens.com/productcert/html/ssa-957369.html
Bulletin de sécurité Siemens SSA-278349 du 12 septembre 2023
https://cert-portal.siemens.com/productcert/html/ssa-981975.html
Bulletin de sécurité Siemens SSA-711309 du 12 septembre 2023
https://cert-portal.siemens.com/productcert/html/ssa-278349.html
Bulletin de sécurité Siemens SSA-957369 du 12 septembre 2023
https://cert-portal.siemens.com/productcert/html/ssa-240541.html
Bulletin de sécurité Siemens SSA-981975 du 12 septembre 2023
https://cert-portal.siemens.com/productcert/html/ssa-711309.html
Référence CVE CVE-2017-5715
https://www.cve.org/CVERecord?id=CVE-2017-5715
Référence CVE CVE-2021-38578
https://www.cve.org/CVERecord?id=CVE-2021-38578
Référence CVE CVE-2022-24350
https://www.cve.org/CVERecord?id=CVE-2022-24350
Référence CVE CVE-2022-24351
https://www.cve.org/CVERecord?id=CVE-2022-24351
Référence CVE CVE-2022-27405
https://www.cve.org/CVERecord?id=CVE-2022-27405
Référence CVE CVE-2022-29275
https://www.cve.org/CVERecord?id=CVE-2022-29275
Référence CVE CVE-2022-30283
https://www.cve.org/CVERecord?id=CVE-2022-30283
Référence CVE CVE-2022-30772
https://www.cve.org/CVERecord?id=CVE-2022-30772
Référence CVE CVE-2022-32469
https://www.cve.org/CVERecord?id=C
Official advisory ↗CERT-FR · French · CERTFR-2023-AVI-0220Multiples vulnérabilités dans les produits Siemensoductcert/html/ssa-260625.html
Bulletin de sécurité Siemens ssa-320629 du 14 mars 2023
https://cert-portal.siemens.com/productcert/html/ssa-320629.html
Bulletin de sécurité Siemens ssa-419740 du 14 mars 2023
https://cert-portal.siemens.com/productcert/html/ssa-419740.html
Bulletin de sécurité Siemens ssa-565386 du 14 mars 2023
https://cert-portal.siemens.com/productcert/html/ssa-565386.html
Bulletin de sécurité Siemens ssa-726834 du 14 mars 2023
https://cert-portal.siemens.com/productcert/html/ssa-726834.html
Bulletin de sécurité Siemens ssa-851884 du 14 mars 2023
https://cert-portal.siemens.com/productcert/html/ssa-851884.html
Référence CVE CVE-2017-5715
https://www.cve.org/CVERecord?id=CVE-2017-5715
Référence CVE CVE-2018-12886
https://www.cve.org/CVERecord?id=CVE-2018-12886
Référence CVE CVE-2018-25032
https://www.cve.org/CVERecord?id=CVE-2018-25032
Référence CVE CVE-2019-1071
https://www.cve.org/CVERecord?id=CVE-2019-1071
Référence CVE CVE-2019-1073
https://www.cve.org/CVERecord?id=CVE-2019-1073
Référence CVE CVE-2019-1125
https://www.cve.org/CVERecord?id=CVE-2019-1125
Référence CVE CVE-2021-26401
https://www.cve.org/CVERecord?id=CVE-2021-26401
Référence CVE CVE-2021-4034
https://www.cve.org/CVERecord?id=CVE-2021-4034
Référence CVE CVE-2021-4149
https://www.cve.org/CVERecord?id=CVE-2021-4
Official advisory ↗CERT-FR · French · CERTFR-2023-AVI-0067Multiples vulnérabilités dans le noyau Linux de Red HatDe multiples vulnérabilités ont été corrigées dans le noyau Linux de Red Hat . Certaines d'entre elles
permettent à un attaquant de provoquer un déni de service à distance, un
contournement de la politique de sécurité et une atteinte à l'intégrité
des données.
Official advisory ↗CERT-FR · French · CERTFR-2023-AVI-0048Multiples vulnérabilités dans le noyau Linux de Red HatDe multiples vulnérabilités ont été corrigées dans le noyau Linux de Red Hat . Elles permettent à un
attaquant de provoquer un déni de service, une atteinte à la
confidentialité des données et une élévation de privilèges.
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-637Multiples vulnérabilités dans les produits AMDDe multiples vulnérabilités ont été découvertes dans les produits AMD.
Elles permettent à un attaquant de provoquer un contournement de la
politique de sécurité, une atteinte à la confidentialité des données et
une exécution de code arbitraire.
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-267Multiples vulnérabilités dans Juniper Networks Junos Spaceorg/CVERecord?id=CVE-2017-18258
Référence CVE CVE-2017-18267
https://www.cve.org/CVERecord?id=CVE-2017-18267
Référence CVE CVE-2017-18551
https://www.cve.org/CVERecord?id=CVE-2017-18551
Référence CVE CVE-2017-2810
https://www.cve.org/CVERecord?id=CVE-2017-2810
Référence CVE CVE-2017-3735
https://www.cve.org/CVERecord?id=CVE-2017-3735
Référence CVE CVE-2017-3736
https://www.cve.org/CVERecord?id=CVE-2017-3736
Référence CVE CVE-2017-3737
https://www.cve.org/CVERecord?id=CVE-2017-3737
Référence CVE CVE-2017-3738
https://www.cve.org/CVERecord?id=CVE-2017-3738
Référence CVE CVE-2017-5130
https://www.cve.org/CVERecord?id=CVE-2017-5130
Référence CVE CVE-2017-5715
https://www.cve.org/CVERecord?id=CVE-2017-5715
Référence CVE CVE-2017-5992
https://www.cve.org/CVERecord?id=CVE-2017-5992
Référence CVE CVE-2017-6462
https://www.cve.org/CVERecord?id=CVE-2017-6462
Référence CVE CVE-2017-6463
https://www.cve.org/CVERecord?id=CVE-2017-6463
Référence CVE CVE-2017-6464
https://www.cve.org/CVERecord?id=CVE-2017-6464
Référence CVE CVE-2017-6519
https://www.cve.org/CVERecord?id=CVE-2017-6519
Référence CVE CVE-2017-7375
https://www.cve.org/CVERecord?id=CVE-2017-7375
Référence CVE CVE-2017-7376
https://www.cve.org/CVERecord?id=CVE-2017-7376
Référence CVE CVE-2017-7555
https://www.cve.org/CVERecord?id=CVE-2017-7555
Ré
Official advisory ↗CERT-FR · French · CERTFR-2021-AVI-456Multiples vulnérabilités dans le noyau Linux d'UbuntuDe multiples vulnérabilités ont été découvertes dans le noyau Linux
d'Ubuntu. Elles permettent à un attaquant de provoquer un contournement
de la politique de sécurité, une atteinte à la confidentialité des
données et une élévation de privilèges.
Official advisory ↗CERT-FR · French · CERTFR-2019-AVI-489Multiples vulnérabilités dans les produits SiemensDe multiples vulnérabilités ont été découvertes dans les produits
Siemens. Elles permettent à un attaquant de provoquer un déni de service
à distance, une atteinte à l'intégrité des données et une atteinte à la
confidentialité des données.
Official advisory ↗CERT-FR · French · CERTFR-2019-AVI-425Multiples vulnérabilités dans Google Androidrrectif de sécurité 2019-09-01
Résumé
De multiples vulnérabilités ont été découvertes dans Google Android.
Certaines d'entre elles permettent à un attaquant de provoquer un
problème de sécurité non spécifié par l'éditeur, une exécution de code
arbitraire à distance et une atteinte à la confidentialité des données.
Solution
Se référer au bulletin de sécurité de l'éditeur pour l'obtention des
correctifs (cf. section Documentation).
Documentation
Bulletin de sécurité Android du 01 septembre 2019
https://source.android.com/security/bulletin/2019-09-01.html
Référence CVE CVE-2017-17768
https://www.cve.org/CVERecord?id=CVE-2017-17768
Référence CVE CVE-2017-5715
https://www.cve.org/CVERecord?id=CVE-2017-5715
Référence CVE CVE-2018-11891
https://www.cve.org/CVERecord?id=CVE-2018-11891
Référence CVE CVE-2018-20669
https://www.cve.org/CVERecord?id=CVE-2018-20669
Référence CVE CVE-2018-6240
https://www.cve.org/CVERecord?id=CVE-2018-6240
Référence CVE CVE-2019-10488
https://www.cve.org/CVERecord?id=CVE-2019-10488
Référence CVE CVE-2019-10491
https://www.cve.org/CVERecord?id=CVE-2019-10491
Référence CVE CVE-2019-10495
https://www.cve.org/CVERecord?id=CVE-2019-10495
Référence CVE CVE-2019-10496
https://www.cve.org/CVERecord?id=CVE-2019-10496
Référence CVE CVE-2019-10504
https://www.cve.org/CVERecord?id=CVE
Official advisory ↗CERT-FR · French · CERTFR-2018-AVI-505Multiples vulnérabilités dans le noyau Linux de SUSEsuse-su-20182344-2 du 18 octobre 2018
https://www.suse.com/support/update/announcement/2018/suse-su-20182344-2/
Bulletin de sécurité SUSE suse-su-20183238-1 du 18 octobre 2018
https://www.suse.com/support/update/announcement/2018/suse-su-20183238-1/
Référence CVE CVE-2017-13305
https://www.cve.org/CVERecord?id=CVE-2017-13305
Référence CVE CVE-2017-18241
https://www.cve.org/CVERecord?id=CVE-2017-18241
Référence CVE CVE-2017-18249
https://www.cve.org/CVERecord?id=CVE-2017-18249
Référence CVE CVE-2017-18257
https://www.cve.org/CVERecord?id=CVE-2017-18257
Référence CVE CVE-2017-18344
https://www.cve.org/CVERecord?id=CVE-2017-18344
Référence CVE CVE-2017-5715
https://www.cve.org/CVERecord?id=CVE-2017-5715
Référence CVE CVE-2018-1000199
https://www.cve.org/CVERecord?id=CVE-2018-1000199
Référence CVE CVE-2018-1000204
https://www.cve.org/CVERecord?id=CVE-2018-1000204
Référence CVE CVE-2018-10087
https://www.cve.org/CVERecord?id=CVE-2018-10087
Référence CVE CVE-2018-10124
https://www.cve.org/CVERecord?id=CVE-2018-10124
Référence CVE CVE-2018-1065
https://www.cve.org/CVERecord?id=CVE-2018-1065
Référence CVE CVE-2018-1087
https://www.cve.org/CVERecord?id=CVE-2018-1087
Référence CVE CVE-2018-1092
https://www.cve.org/CVERecord?id=CVE-2018-1092
Référence CVE CVE-2018-1093
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2018-AVI-371Multiples vulnérabilités dans le noyau Linux de SUSEDe multiples vulnérabilités ont été découvertes dans le noyau Linux de
SUSE. Elles permettent à un attaquant de provoquer un déni de service à
distance et une atteinte à la confidentialité des données.
Official advisory ↗CERT-FR · French · CERTFR-2018-AVI-362Multiples vulnérabilités dans le noyau Linux de SUSEllet 2018
https://www.suse.com/support/update/announcement/2018/suse-su-20182108-1/
Bulletin de sécurité SUSE SUSE-SU-20182110-1 du 27 juillet 2018
https://www.suse.com/support/update/announcement/2018/suse-su-20182110-1/
Bulletin de sécurité SUSE SUSE-SU-20182111-1 du 27 juillet 2018
https://www.suse.com/support/update/announcement/2018/suse-su-20182111-1/
Bulletin de sécurité SUSE SUSE-SU-20182114-1 du 27 juillet 2018
https://www.suse.com/support/update/announcement/2018/suse-su-20182114-1/
Bulletin de sécurité SUSE SUSE-SU-20182115-1 du 27 juillet 2018
https://www.suse.com/support/update/announcement/2018/suse-su-20182115-1/
Référence CVE CVE-2017-5715
https://www.cve.org/CVERecord?id=CVE-2017-5715
Référence CVE CVE-2017-5753
https://www.cve.org/CVERecord?id=CVE-2017-5753
Référence CVE CVE-2018-1000200
https://www.cve.org/CVERecord?id=CVE-2018-1000200
Référence CVE CVE-2018-1000204
https://www.cve.org/CVERecord?id=CVE-2018-1000204
Référence CVE CVE-2018-10087
https://www.cve.org/CVERecord?id=CVE-2018-10087
Référence CVE CVE-2018-10124
https://www.cve.org/CVERecord?id=CVE-2018-10124
Référence CVE CVE-2018-1092
https://www.cve.org/CVERecord?id=CVE-2018-1092
Référence CVE CVE-2018-1093
https://www.cve.org/CVERecord?id=CVE-2018-1093
Référence CVE CVE-2018-1094
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2018-AVI-339Multiples vulnérabilités dans les produits Juniperecord?id=CVE-2017-10295
Référence CVE CVE-2017-10345
https://www.cve.org/CVERecord?id=CVE-2017-10345
Référence CVE CVE-2017-10355
https://www.cve.org/CVERecord?id=CVE-2017-10355
Référence CVE CVE-2017-10356
https://www.cve.org/CVERecord?id=CVE-2017-10356
Référence CVE CVE-2017-10388
https://www.cve.org/CVERecord?id=CVE-2017-10388
Référence CVE CVE-2017-12613
https://www.cve.org/CVERecord?id=CVE-2017-12613
Référence CVE CVE-2017-15896
https://www.cve.org/CVERecord?id=CVE-2017-15896
Référence CVE CVE-2017-3145
https://www.cve.org/CVERecord?id=CVE-2017-3145
Référence CVE CVE-2017-3737
https://www.cve.org/CVERecord?id=CVE-2017-3737
Référence CVE CVE-2017-5715
https://www.cve.org/CVERecord?id=CVE-2017-5715
Référence CVE CVE-2017-5753
https://www.cve.org/CVERecord?id=CVE-2017-5753
Référence CVE CVE-2017-5754
https://www.cve.org/CVERecord?id=CVE-2017-5754
Référence CVE CVE-2017-7407
https://www.cve.org/CVERecord?id=CVE-2017-7407
Référence CVE CVE-2017-8816
https://www.cve.org/CVERecord?id=CVE-2017-8816
Référence CVE CVE-2017-8817
https://www.cve.org/CVERecord?id=CVE-2017-8817
Référence CVE CVE-2017-8818
https://www.cve.org/CVERecord?id=CVE-2017-8818
Référence CVE CVE-2017-9502
https://www.cve.org/CVERecord?id=CVE-2017-9502
Référence CVE CVE-2018-0024
https://www.cve.org/CVERecord?id=CVE-2018-0024
Ré
Official advisory ↗CERT-FR · French · CERTFR-2018-AVI-256Multiples vulnérabilités dans le noyau Linux de SUSEDe multiples vulnérabilités ont été découvertes dans le noyau Linux de
SUSE. Elles permettent à un attaquant de provoquer un déni de service,
une atteinte à la confidentialité des données et une élévation de
privilèges.
Official advisory ↗CERT-FR · French · CERTFR-2018-AVI-216Multiples vulnérabilités dans Google Androidd?id=CVE-2017-15832
Référence CVE CVE-2017-15842
https://www.cve.org/CVERecord?id=CVE-2017-15842
Référence CVE CVE-2017-15843
https://www.cve.org/CVERecord?id=CVE-2017-15843
Référence CVE CVE-2017-15854
https://www.cve.org/CVERecord?id=CVE-2017-15854
Référence CVE CVE-2017-15857
https://www.cve.org/CVERecord?id=CVE-2017-15857
Référence CVE CVE-2017-16643
https://www.cve.org/CVERecord?id=CVE-2017-16643
Référence CVE CVE-2017-18070
https://www.cve.org/CVERecord?id=CVE-2017-18070
Référence CVE CVE-2017-18153
https://www.cve.org/CVERecord?id=CVE-2017-18153
Référence CVE CVE-2017-18154
https://www.cve.org/CVERecord?id=CVE-2017-18154
Référence CVE CVE-2017-5715
https://www.cve.org/CVERecord?id=CVE-2017-5715
Référence CVE CVE-2017-5754
https://www.cve.org/CVERecord?id=CVE-2017-5754
Référence CVE CVE-2017-6289
https://www.cve.org/CVERecord?id=CVE-2017-6289
Référence CVE CVE-2017-6293
https://www.cve.org/CVERecord?id=CVE-2017-6293
Référence CVE CVE-2018-3562
https://www.cve.org/CVERecord?id=CVE-2018-3562
Référence CVE CVE-2018-3565
https://www.cve.org/CVERecord?id=CVE-2018-3565
Référence CVE CVE-2018-3571
https://www.cve.org/CVERecord?id=CVE-2018-3571
Référence CVE CVE-2018-3572
https://www.cve.org/CVERecord?id=CVE-2018-3572
Référence CVE CVE-2018-3576
https://www.cve.org/CVERecord?id=CVE-2018-3576
Ré
Official advisory ↗CERT-FR · French · CERTFR-2018-AVI-208Vulnérabilité dans Microsoft WindowsUne vulnérabilité a été découverte dans Microsoft Windows. Elle permet à
un attaquant de provoquer une atteinte à la confidentialité des données.
Official advisory ↗CERT-FR · French · CERTFR-2018-AVI-206Multiples vulnérabilités dans le noyau Linux de SUSEDe multiples vulnérabilités ont été découvertes dans le noyau Linux de
SUSE. Certaines d'entre elles permettent à un attaquant de provoquer une
exécution de code arbitraire, un déni de service et une atteinte à la
confidentialité des données.
Official advisory ↗CERT-FR · French · CERTFR-2018-AVI-205Multiples vulnérabilités dans le noyau Linux de RedHatDe multiples vulnérabilités ont été découvertes dans le noyau Linux de
RedHat. Elles permettent à un attaquant de provoquer une atteinte à
l'intégrité des données et une atteinte à la confidentialité des
données.
Official advisory ↗CERT-FR · French · CERTFR-2018-AVI-196Multiples vulnérabilités dans le noyau Linux de SUSEDe multiples vulnérabilités ont été découvertes dans le noyau Linux de
SUSE . Certaines d'entre elles permettent à un attaquant de provoquer un
problème de sécurité non spécifié par l'éditeur, une exécution de code
arbitraire et un déni de service à distance.
Official advisory ↗CERT-FR · French · CERTFR-2018-AVI-175Multiples vulnérabilités dans le noyau Linux de RedHatDe multiples vulnérabilités ont été découvertes dans le noyau Linux de
RedHat. Elles permettent à un attaquant de provoquer un déni de service,
une atteinte à l'intégrité des données et une atteinte à la
confidentialité des données.
Official advisory ↗CERT-FR · French · CERTFR-2018-AVI-170Multiples vulnérabilités dans le noyau Linux d'Ubuntud?id=CVE-2017-17741
Référence CVE CVE-2017-17805
https://www.cve.org/CVERecord?id=CVE-2017-17805
Référence CVE CVE-2017-17806
https://www.cve.org/CVERecord?id=CVE-2017-17806
Référence CVE CVE-2017-17807
https://www.cve.org/CVERecord?id=CVE-2017-17807
Référence CVE CVE-2017-17862
https://www.cve.org/CVERecord?id=CVE-2017-17862
Référence CVE CVE-2017-18075
https://www.cve.org/CVERecord?id=CVE-2017-18075
Référence CVE CVE-2017-18203
https://www.cve.org/CVERecord?id=CVE-2017-18203
Référence CVE CVE-2017-18204
https://www.cve.org/CVERecord?id=CVE-2017-18204
Référence CVE CVE-2017-18208
https://www.cve.org/CVERecord?id=CVE-2017-18208
Référence CVE CVE-2017-5715
https://www.cve.org/CVERecord?id=CVE-2017-5715
Référence CVE CVE-2017-7518
https://www.cve.org/CVERecord?id=CVE-2017-7518
Référence CVE CVE-2018-1000026
https://www.cve.org/CVERecord?id=CVE-2018-1000026
Référence CVE CVE-2018-5332
https://www.cve.org/CVERecord?id=CVE-2018-5332
Référence CVE CVE-2018-5333
https://www.cve.org/CVERecord?id=CVE-2018-5333
Référence CVE CVE-2018-5344
https://www.cve.org/CVERecord?id=CVE-2018-5344
Référence CVE CVE-2018-6927
https://www.cve.org/CVERecord?id=CVE-2018-6927
Référence CVE CVE-2018-7492
https://www.cve.org/CVERecord?id=CVE-2018-7492
Référence CVE CVE-2018-8043
https://www.cve.org/CVERecord?id=CVE-2018-8
Official advisory ↗CERT-FR · French · CERTFR-2018-AVI-161Multiples vulnérabilités dans le noyau Linux de SUSEd?id=CVE-2017-16912
Référence CVE CVE-2017-16913
https://www.cve.org/CVERecord?id=CVE-2017-16913
Référence CVE CVE-2017-16914
https://www.cve.org/CVERecord?id=CVE-2017-16914
Référence CVE CVE-2017-17741
https://www.cve.org/CVERecord?id=CVE-2017-17741
Référence CVE CVE-2017-18017
https://www.cve.org/CVERecord?id=CVE-2017-18017
Référence CVE CVE-2017-18079
https://www.cve.org/CVERecord?id=CVE-2017-18079
Référence CVE CVE-2017-18204
https://www.cve.org/CVERecord?id=CVE-2017-18204
Référence CVE CVE-2017-18208
https://www.cve.org/CVERecord?id=CVE-2017-18208
Référence CVE CVE-2017-18221
https://www.cve.org/CVERecord?id=CVE-2017-18221
Référence CVE CVE-2017-5715
https://www.cve.org/CVERecord?id=CVE-2017-5715
Référence CVE CVE-2018-1000004
https://www.cve.org/CVERecord?id=CVE-2018-1000004
Référence CVE CVE-2018-1066
https://www.cve.org/CVERecord?id=CVE-2018-1066
Référence CVE CVE-2018-1068
https://www.cve.org/CVERecord?id=CVE-2018-1068
Référence CVE CVE-2018-5332
https://www.cve.org/CVERecord?id=CVE-2018-5332
Référence CVE CVE-2018-5333
https://www.cve.org/CVERecord?id=CVE-2018-5333
Référence CVE CVE-2018-6927
https://www.cve.org/CVERecord?id=CVE-2018-6927
Référence CVE CVE-2018-7566
https://www.cve.org/CVERecord?id=CVE-2018-7566
Gestion détaillée du document
le 30 mars 2018
Version initiale
Alertes
Official advisory ↗CERT-FR · French · CERTFR-2018-AVI-134Multiples vulnérabilités dans le noyau Linux d'UbuntuDe multiples vulnérabilités ont été corrigées dans le noyau Linux d'Ubuntu . Elles permettent à un
attaquant de provoquer une atteinte à la confidentialité des données.
Official advisory ↗CERT-FR · French · CERTFR-2018-AVI-124Multiples vulnérabilités dans le noyau Linux de RedHatDe multiples vulnérabilités ont été découvertes dans le noyau Linux de
RedHat. Elles permettent à un attaquant de provoquer un déni de service
et une atteinte à la confidentialité des données.
Official advisory ↗CERT-FR · French · CERTFR-2018-AVI-118Vulnérabilité dans le noyau Linux d'UbuntuUne vulnérabilité a été découverte dans le noyau Linux d'Ubuntu. Elle
permet à un attaquant de provoquer une atteinte à la confidentialité des
données.
Official advisory ↗CERT-FR · French · CERTFR-2018-AVI-119Multiples vulnérabilités dans le noyau Linux de SUSEDe multiples vulnérabilités ont été découvertes dans le noyau Linux de
SUSE. Certaines d'entre elles permettent à un attaquant de provoquer un
problème de sécurité non spécifié par l'éditeur, un déni de service à
distance et un déni de service.
Official advisory ↗CERT-FR · French · CERTFR-2018-AVI-104Multiples vulnérabilités dans le noyau Linux de SUSEDe multiples vulnérabilités ont été découvertes dans le noyau Linux de
SUSE. Certaines d'entre elles permettent à un attaquant de provoquer un
déni de service à distance, un déni de service et une atteinte à la
confidentialité des données.
Official advisory ↗CERT-FR · French · CERTFR-2018-AVI-094Multiples vulnérabilités dans le noyau Linux d'Ubuntuord?id=CVE-2017-15115
Référence CVE CVE-2017-15274
https://www.cve.org/CVERecord?id=CVE-2017-15274
Référence CVE CVE-2017-15868
https://www.cve.org/CVERecord?id=CVE-2017-15868
Référence CVE CVE-2017-16525
https://www.cve.org/CVERecord?id=CVE-2017-16525
Référence CVE CVE-2017-17450
https://www.cve.org/CVERecord?id=CVE-2017-17450
Référence CVE CVE-2017-17712
https://www.cve.org/CVERecord?id=CVE-2017-17712
Référence CVE CVE-2017-17806
https://www.cve.org/CVERecord?id=CVE-2017-17806
Référence CVE CVE-2017-18017
https://www.cve.org/CVERecord?id=CVE-2017-18017
Référence CVE CVE-2017-5669
https://www.cve.org/CVERecord?id=CVE-2017-5669
Référence CVE CVE-2017-5715
https://www.cve.org/CVERecord?id=CVE-2017-5715
Référence CVE CVE-2017-5753
https://www.cve.org/CVERecord?id=CVE-2017-5753
Référence CVE CVE-2017-5754
https://www.cve.org/CVERecord?id=CVE-2017-5754
Référence CVE CVE-2017-7542
https://www.cve.org/CVERecord?id=CVE-2017-7542
Référence CVE CVE-2017-7889
https://www.cve.org/CVERecord?id=CVE-2017-7889
Référence CVE CVE-2017-8824
https://www.cve.org/CVERecord?id=CVE-2017-8824
Référence CVE CVE-2018-5333
https://www.cve.org/CVERecord?id=CVE-2018-5333
Référence CVE CVE-2018-5344
https://www.cve.org/CVERecord?id=CVE-2018-5344
Gestion détaillée du document
le 22 février 2018
Version initiale
le 23 févri
Official advisory ↗CERT-FR · French · CERTFR-2018-AVI-095Multiples vulnérabilités dans SCADA les produits SiemensDe multiples vulnérabilités ont été découvertes dans SCADA les produits
Siemens . Certaines d'entre elles permettent à un attaquant de provoquer
une exécution de code arbitraire à distance, une exécution de code
arbitraire et une atteinte à l'intégrité des données.
Official advisory ↗CERT-FR · French · CERTFR-2018-AVI-091Multiples vulnérabilités dans le noyau Linux de SUSEDe multiples vulnérabilités ont été découvertes dans le noyau Linux de
SUSE . Certaines d'entre elles permettent à un attaquant de provoquer un
problème de sécurité non spécifié par l'éditeur, une exécution de code
arbitraire et un déni de service à distance.
Official advisory ↗CERT-FR · French · CERTFR-2018-AVI-083Multiples vulnérabilités dans le noyau Linux de SUSEDe multiples vulnérabilités ont été découvertes dans le noyau Linux de
SUSE . Certaines d'entre elles permettent à un attaquant de provoquer un
problème de sécurité non spécifié par l'éditeur, une exécution de code
arbitraire et un déni de service.
Official advisory ↗CERT-FR · French · CERTFR-2018-AVI-080Multiples vulnérabilités dans le noyau Linux de SUSEDe multiples vulnérabilités ont été découvertes dans le noyau Linux de
SUSE . Certaines d'entre elles permettent à un attaquant de provoquer un
problème de sécurité non spécifié par l'éditeur, une exécution de code
arbitraire et un déni de service à distance.
Official advisory ↗CERT-FR · French · CERTFR-2018-AVI-079Multiples vulnérabilités dans le noyau Linux de RedHatDe multiples vulnérabilités ont été découvertes dans le noyau Linux de
RedHat . Elles permettent à un attaquant de provoquer une atteinte à la
confidentialité des données.
Official advisory ↗CERT-FR · French · CERTFR-2018-AVI-075Multiples vulnérabilités dans le noyau Linux de SUSEDe multiples vulnérabilités ont été découvertes dans le noyau Linux de
SUSE. Certaines d'entre elles permettent à un attaquant de provoquer une
exécution de code arbitraire, un déni de service à distance et un déni
de service.
Official advisory ↗CERT-FR · French · CERTFR-2018-AVI-077Multiples vulnérabilités dans les produits VMwareDe multiples vulnérabilités ont été découvertes dans les produits VMware
. Elles permettent à un attaquant de provoquer une atteinte à la
confidentialité des données.
Official advisory ↗CERT-FR · French · CERTFR-2018-AVI-059Multiples vulnérabilités dans le noyau Linux d'UbuntuDe multiples vulnérabilités ont été découvertes dans le noyau Linux
d'Ubuntu . Elles permettent à un attaquant de provoquer une exécution de
code arbitraire, une atteinte à la confidentialité des données et un
déni de service.
Official advisory ↗CERT-FR · French · CERTFR-2018-AVI-056Multiples vulnérabilités dans le noyau Linux de SUSEd?id=CVE-2017-16645
Référence CVE CVE-2017-16646
https://www.cve.org/CVERecord?id=CVE-2017-16646
Référence CVE CVE-2017-16939
https://www.cve.org/CVERecord?id=CVE-2017-16939
Référence CVE CVE-2017-16994
https://www.cve.org/CVERecord?id=CVE-2017-16994
Référence CVE CVE-2017-17448
https://www.cve.org/CVERecord?id=CVE-2017-17448
Référence CVE CVE-2017-17449
https://www.cve.org/CVERecord?id=CVE-2017-17449
Référence CVE CVE-2017-17450
https://www.cve.org/CVERecord?id=CVE-2017-17450
Référence CVE CVE-2017-17805
https://www.cve.org/CVERecord?id=CVE-2017-17805
Référence CVE CVE-2017-17806
https://www.cve.org/CVERecord?id=CVE-2017-17806
Référence CVE CVE-2017-5715
https://www.cve.org/CVERecord?id=CVE-2017-5715
Référence CVE CVE-2017-5753
https://www.cve.org/CVERecord?id=CVE-2017-5753
Référence CVE CVE-2017-5754
https://www.cve.org/CVERecord?id=CVE-2017-5754
Référence CVE CVE-2017-7482
https://www.cve.org/CVERecord?id=CVE-2017-7482
Référence CVE CVE-2017-8824
https://www.cve.org/CVERecord?id=CVE-2017-8824
Gestion détaillée du document
le 26 janvier 2018
Version initiale
Alertes
Avis
Bulletins d’actualités
Mentions légales
Conditions générales
À propos
Contact
cyber.gouv.fr
service-public.fr
legifrance.gouv.fr
info.gouv.fr
france.fr
info.gouv.fr/risques
Premier Ministre / Secrétariat Général de la Défen
Official advisory ↗CERT-FR · French · CERTFR-2018-AVI-051Multiples vulnérabilités dans le noyau Linux de SUSEd?id=CVE-2017-16536
Référence CVE CVE-2017-16537
https://www.cve.org/CVERecord?id=CVE-2017-16537
Référence CVE CVE-2017-16538
https://www.cve.org/CVERecord?id=CVE-2017-16538
Référence CVE CVE-2017-16649
https://www.cve.org/CVERecord?id=CVE-2017-16649
Référence CVE CVE-2017-16939
https://www.cve.org/CVERecord?id=CVE-2017-16939
Référence CVE CVE-2017-17450
https://www.cve.org/CVERecord?id=CVE-2017-17450
Référence CVE CVE-2017-17558
https://www.cve.org/CVERecord?id=CVE-2017-17558
Référence CVE CVE-2017-17805
https://www.cve.org/CVERecord?id=CVE-2017-17805
Référence CVE CVE-2017-17806
https://www.cve.org/CVERecord?id=CVE-2017-17806
Référence CVE CVE-2017-5715
https://www.cve.org/CVERecord?id=CVE-2017-5715
Référence CVE CVE-2017-5753
https://www.cve.org/CVERecord?id=CVE-2017-5753
Référence CVE CVE-2017-5754
https://www.cve.org/CVERecord?id=CVE-2017-5754
Référence CVE CVE-2017-7472
https://www.cve.org/CVERecord?id=CVE-2017-7472
Référence CVE CVE-2017-8824
https://www.cve.org/CVERecord?id=CVE-2017-8824
Gestion détaillée du document
le 24 janvier 2018
Version initiale
Alertes
Avis
Bulletins d’actualités
Mentions légales
Conditions générales
À propos
Contact
cyber.gouv.fr
service-public.fr
legifrance.gouv.fr
info.gouv.fr
france.fr
info.gouv.fr/risques
Premier Ministre / Secrétariat Général de la Défen
Official advisory ↗CERT-FR · French · CERTFR-2018-AVI-049Multiples vulnérabilités dans le noyau Linux d'UbuntuDe multiples vulnérabilités ont été découvertes dans le noyau Linux
d'Ubuntu. Elles permettent à un attaquant de provoquer une atteinte à la
confidentialité des données.
Official advisory ↗CERT-FR · French · CERTFR-2018-AVI-048Multiples vulnérabilités dans le noyau Linux de SUSEDe multiples vulnérabilités ont été découvertes dans le noyau Linux de
SUSE. Elles permettent à un attaquant de provoquer une atteinte à la
confidentialité des données.
Official advisory ↗CERT-FR · French · CERTFR-2018-AVI-044Multiples vulnérabilités dans les produits MoxaDe multiples vulnérabilités ont été découvertes dans les produits Moxa .
Elles permettent à un attaquant de provoquer une atteinte à la
confidentialité des données.
Official advisory ↗CERT-FR · French · CERTFR-2018-AVI-039Multiples vulnérabilités dans Oracle VirtualizationDe multiples vulnérabilités ont été découvertes dans Oracle
Virtualization. Elles permettent à un attaquant de provoquer une
exécution de code arbitraire à distance, une atteinte à l'intégrité des
données et une atteinte à la confidentialité des données.
Official advisory ↗CERT-FR · French · CERTFR-2018-AVI-038Multiples vulnérabilités dans Oracle Sun Systems Products SuiteDe multiples vulnérabilités ont été découvertes dans Oracle Sun Systems
Products Suite. Elles permettent à un attaquant de provoquer une
exécution de code arbitraire à distance, une atteinte à l'intégrité des
données et une atteinte à la confidentialité des données.
Official advisory ↗CERT-FR · French · CERTFR-2018-AVI-032Multiples vulnérabilités dans le noyau Linux de SUSEDe multiples vulnérabilités ont été découvertes dans le noyau Linux de
SUSE . Certaines d'entre elles permettent à un attaquant de provoquer un
problème de sécurité non spécifié par l'éditeur, un déni de service et
un contournement de la politique de sécurité.
Official advisory ↗CERT-FR · French · CERTFR-2018-AVI-030Vulnérabilité dans le microgiciel Intel pour UbuntuUne vulnérabilité a été découverte dans le microgiciel Intel pour
Ubuntu. Elle permet à un attaquant de provoquer une atteinte à la
confidentialité des données.
Official advisory ↗CERT-FR · French · CERTFR-2018-AVI-029Multiples vulnérabilités dans le noyau Linux de SUSEDe multiples vulnérabilités ont été découvertes dans le noyau Linux de
SUSE. Elles permettent à un attaquant de provoquer une atteinte à la
confidentialité des données.
Official advisory ↗CERT-FR · French · CERTFR-2018-AVI-028Vulnérabilité dans le microgiciel Intel pour SUSEUne vulnérabilité a été découverte dans le microgiciel Intel pour SUSE.
Elle permet à un attaquant de provoquer une atteinte à la
confidentialité des données.
Official advisory ↗CERT-FR · French · CERTFR-2018-AVI-027Multiples vulnérabilités dans les produits NVIDIADe multiples vulnérabilités ont été découvertes dans les produits
NVIDIA. Elles permettent à un attaquant de provoquer une atteinte à la
confidentialité des données.
Official advisory ↗CERT-FR · French · CERTFR-2018-AVI-040Vulnérabilité dans le micrologiciel processeur pour Red HatUne vulnérabilité a été découverte dans le micrologiciel processeur pour
Red Hat . Elle permet à un attaquant de provoquer une atteinte à la
confidentialité des données.
Official advisory ↗CERT-FR · French · CERTFR-2018-AVI-016Vulnérabilité dans les produits VMwareUne vulnérabilité a été découverte dans les produits VMware. Elle permet
à un attaquant de provoquer une atteinte à la confidentialité des
données.
Official advisory ↗CERT-FR · French · CERTFR-2018-AVI-013Multiples vulnérabilités dans les produits AppleDe multiples vulnérabilités ont été découvertes dans les produits Apple.
Elles permettent à un attaquant de provoquer une atteinte à la
confidentialité des données.
Official advisory ↗CERT-FR · French · CERTFR-2018-AVI-014Multiples vulnérabilités dans le noyau Linux de SUSEd?id=CVE-2017-16536
Référence CVE CVE-2017-16537
https://www.cve.org/CVERecord?id=CVE-2017-16537
Référence CVE CVE-2017-16538
https://www.cve.org/CVERecord?id=CVE-2017-16538
Référence CVE CVE-2017-16649
https://www.cve.org/CVERecord?id=CVE-2017-16649
Référence CVE CVE-2017-16939
https://www.cve.org/CVERecord?id=CVE-2017-16939
Référence CVE CVE-2017-17450
https://www.cve.org/CVERecord?id=CVE-2017-17450
Référence CVE CVE-2017-17558
https://www.cve.org/CVERecord?id=CVE-2017-17558
Référence CVE CVE-2017-17805
https://www.cve.org/CVERecord?id=CVE-2017-17805
Référence CVE CVE-2017-17806
https://www.cve.org/CVERecord?id=CVE-2017-17806
Référence CVE CVE-2017-5715
https://www.cve.org/CVERecord?id=CVE-2017-5715
Référence CVE CVE-2017-5753
https://www.cve.org/CVERecord?id=CVE-2017-5753
Référence CVE CVE-2017-5754
https://www.cve.org/CVERecord?id=CVE-2017-5754
Référence CVE CVE-2017-7472
https://www.cve.org/CVERecord?id=CVE-2017-7472
Référence CVE CVE-2017-8824
https://www.cve.org/CVERecord?id=CVE-2017-8824
Gestion détaillée du document
le 09 janvier 2018
Version initiale
le 10 janvier 2018
Ajout d'un bulletin et mise à jour des systèmes affectés
Alertes
Avis
Bulletins d’actualités
Mentions légales
Conditions générales
À propos
Contact
cyber.gouv.fr
service-public.fr
legifrance.gouv.fr
info.gouv.fr
franc
Official advisory ↗CERT-FR · French · CERTFR-2018-AVI-009Multiples vulnérabilités dans le noyau Linux de SUSEDe multiples vulnérabilités ont été découvertes dans le noyau Linux de
SUSE . Certaines d'entre elles permettent à un attaquant de provoquer un
déni de service, un contournement de la politique de sécurité et une
atteinte à la confidentialité des données.
Official advisory ↗CERT-FR · French · CERTFR-2018-AVI-006Multiples vulnérabilités dans les produits VMwareDe multiples vulnérabilités ont été découvertes dans les produits VMware
. Elles permettent à un attaquant de provoquer une atteinte à la
confidentialité des données.
Official advisory ↗CERT-FR · French · CERTFR-2018-AVI-012Vulnérabilité dans les microgiciels Intel et AMD pour les systèmes RedHatUne vulnérabilité a été découverte dans les microgiciels Intel et AMD
pour les systèmes RedHat. Elle permet à un attaquant de provoquer une
atteinte à la confidentialité des données.
Official advisory ↗CERT-FR · French · CERTFR-2018-AVI-004Multiples vulnérabilités dans le noyau Linux de RedHatDe multiples vulnérabilités ont été découvertes dans le noyau Linux de
RedHat . Elles permettent à un attaquant de provoquer une atteinte à la
confidentialité des données.
Official advisory ↗CERT-FR · French · CERTFR-2018-AVI-005Multiples vulnérabilités dans le noyau Linux de SUSEDe multiples vulnérabilités ont été découvertes dans le noyau Linux de
SUSE . Certaines d'entre elles permettent à un attaquant de provoquer un
problème de sécurité non spécifié par l'éditeur, un déni de service et
une atteinte à la confidentialité des données.
Official advisory ↗JVN iPedia · Japanese · JVNDB-2018-001001CPU に対するサイドチャネル攻撃投機的実行機能やアウトオブオーダー実行機能を持つ CPU に対してサイドチャネル攻撃を行う手法が複数の研究者によって報告されています。 投機的実行機能やアウトオブオーダー実行機能を持つ CPU に対してサイドチャネル攻撃を行う手法 (Spectre および Meltdown) が報告されています。 詳細については、Google Project Zero のブログ記事("Reading privileged memory with a side-channel")や Graz University of Technology (TU Graz) の研究者による情報("Meltdown and Spectre")を参照してください。 "Reading privileged memory with a side-channel" https://googleprojectzero.blogspot.jp/2018/01/reading-privileged-memory-with-side.html "Meltdown and Spectre" https://meltdownattack.com/
Official advisory ↗JVN iPedia · Japanese · JVNDB-2018-003386投機的実行機能を持つ CPU に対するキャッシュサイドチャネル攻撃投機的実行機能を持つ CPU はキャッシュサイドチャネル攻撃に対して脆弱性があります。"Variant 4" あるいは "SpectreNG" と呼ばれています。 投機的実行機能を持つ CPU に対してキャッシュタイミングサイドチャネル攻撃を行う下記の脆弱性が報告されています。 * CVE-2018-3639 (Variant 4 "SpectreNG") : Speculative Store Bypass (SSB) * CVE-2018-3640 (Variant 3a) : Rogue System Register Read (RSRE) 詳細については、Project Zero bug report 、Intel security advisory INTEL-SA-00115 および ARM whitepaper を参照してください。 本脆弱性は、過去に公表された 脆弱性 CVE-2017-5753 (Variant 1 "Spectre")、 CVE-2017-5715 (Variant 2 "Spectre")、 CVE-2017-5754 (Variant 3 "Meltdown") と類似するため "SpectreNG" という名称で報じられています。
Official advisory ↗KISA KrCERT/CC · Korean · KNVD-4870MS Spectre 변종 취약점 보안 업데이트 권고CPU의 부채널 공격(side channel attack)으로 인해 캐시 메모리의 저장된 정보가 노출되는 취약점(CVE-2017-5715)
Official advisory ↗KISA KrCERT/CC · Korean · KNVD-4825CPU 칩셋 취약점 보안 업데이트 권고#### CPU 칩셋 취약점 보안 업데이트 권고 2018.01.04
최신 업데이트 내용 추가 : 2018-01-29
##### □ 개요
o Google社 Project Zero는 Intel社, AMD社, ARM社 CPU 제품의 취약점을 발표 [1]
o 영향 받는 버전 사용자는 해결방안에 따라 최신버전으로 업데이트 권고
##### □ 내용
o CPU의 부채널 공격(side channel attack)으로 인해 캐시 메모리의 저장된 정보가 노출되는 취약점
- 스펙터(Spectre, CVE-2017-5753, CVE-2017-5715)
- 멜트다운(Meltdown, CVE-2017-5754)
##### □ 해결 방안
o 아래 칩셋 제조사 및 OS 개발사를 확인하여 최신 업데이트 적용
※ 최신 업데이트가 미 제공된 제품을 사용할 경우 패치 예정일을 확인하여 신속하게 패치 하는 것을 권고
제조사
패치 현황
배포 여부
Amazone
패치 버전 배포(‘18.1.14)[2]
배포완료
AMD
장비 제조사 및 OS 개발사를 통해 패치 권고 [3]
배포중
Apple
iOS, macOS 등 멜트다운 취약점에 대한 패치버전 배포(’17.12.7)
배포중
iOS, macOS 등 스펙터 취약점에 대한 패치버전 배포 예정 [4]
※ Apple Safari, WebKit 는 패치 완료('18.1.9)
배포예정
ARM
패치 버전 배포(’18.1.4) [5]
배포중
CentOS
패치 버전 배포(‘18.1.6) [6]
배포중
Chromium
패치버전 배포 예정(‘18.1.24) [7]
배포예정
Cisco
패치 버전 배포(‘18.1.4) [8]
배포중
Citrix
패치 버전 배포(’18.1.6) [9]
배포중
Debian
패치 버전 배포(’18.1.4) [10]
배포중
Dragonfly
BSD
패치 버전 배포(’18.1.6) [11]
배포중
F5
패치 버전 배포(’18.1.6) [12]
배포중
Fedora
Official advisory ↗