ÐÅÏ¢Çå¾²Öܱ¨-2020ÄêµÚ17ÖÜ

Ðû²¼Ê±¼ä 2020-04-28

> ±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


2020Äê04ÔÂ20ÈÕÖÁ26ÈÕ¹²ÊÕ¼Çå¾²Îó²î54¸ö £¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇApple macOS Mail Javascript´úÂëÖ´ÐÐÎó²î; Google Chrome paymentsÄÚ´æ¹ýʧÒýÓôúÂëÖ´ÐÐÎó²î£»£»£»£»£»Sonatype Nexus Repository ManagerȨÏÞÌáÉýÎó²î£»£»£»£»£»Í¨´ïOAí§ÒâÓû§µÇ¼Îó²î£»£»£»£»£»Contiki-NGÔ½½çд´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£ ¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊǼÓÄôó¶ùͯÓÎÏ·ÍøÕ¾Webkinz½ü2300ÍòÓû§Êý¾Ýй¶£»£»£»£»£»FPGAоƬStarbleedÎó²î £¬£¬£¬Ó°ÏìÈüÁé˼¶à¸ö²úÆ·£»£»£»£»£»CNCERTÐû²¼¡¶2019ÄêÎÒ¹ú»¥ÁªÍøÍøÂçÇå¾²Ì¬ÊÆ×ÛÊö¡·±¨¸æ£»£»£»£»£»Ñо¿Ö°Ô±Åû¶IBMÆóÒµÇå¾²Èí¼þÖеÄ4¸ö0day£»£»£»£»£»Î¢ÈíÐû²¼½ôÆÈ¸üР£¬£¬£¬ÐÞ¸´OfficeºÍPaint 3DÖжà¸öÎó²î¡£¡£¡£¡£¡£¡£ ¡£¡£


ƾ֤ÒÔÉÏ×ÛÊö £¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£¡£¡£ ¡£¡£


>Ö÷ÒªÇå¾²Îó²îÁбí


1. Apple macOS Mail Javascript´úÂëÖ´ÐÐÎó²î


Apple macOS Mail±£´æ´úÂë×¢ÈëÎó²î £¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó £¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§ÒâJavaScript´úÂë¡£¡£¡£¡£¡£¡£ ¡£¡£¡£¡£¡£¡£¡£¡£ ¡£¡£

https://support.apple.com/en-us/HT211100


2. Google Chrome paymentsÄÚ´æ¹ýʧÒýÓôúÂëÖ´ÐÐÎó²î


Google Chrome payments±£´æÊͷźóʹÓÃÎó²î £¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄWEBÇëÇó £¬£¬£¬ÓÕʹÓû§ÆÊÎö £¬£¬£¬¿É¾ÙÐоܾøÐ§À͹¥»÷»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§ÒâÂë¡£¡£¡£¡£¡£¡£ ¡£¡£

https://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop_21.html


3. Sonatype Nexus Repository ManagerȨÏÞÌáÉýÎó²î


Sonatype Nexus Repository ManagerʵÏÖ±£´æÇå¾²Îó²î £¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó £¬£¬£¬¿ÉÌáÉýÌØÈ¨ £¬£¬£¬¾ÙÐн¨Éè £¬£¬£¬ÐÞ¸Ä £¬£¬£¬Ö´ÐÐʹÃü¡£¡£¡£¡£¡£¡£ ¡£¡£

https://support.sonatype.com/hc/en-us/articles/360046233714


4. ͨ´ïOAí§ÒâÓû§µÇ¼Îó²î


ͨ´ïOAµÇ¼ʵÏÖ±£´æÇå¾²Îó²î £¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó £¬£¬£¬¿ÉÒÔí§ÒâÓû§ÉÏÏÂÎĵǼ¡£¡£¡£¡£¡£¡£ ¡£¡£

https://cert.360.cn/warning/detail?id=d2689a877c01a9712d148317c2da21a2


5. Contiki-NGÔ½½çд´úÂëÖ´ÐÐÎó²î


Contiki-NG os/net/ipv6/sicslowpan.cÔÚ´¦Öóͷ£6LoWPAN·ÖÆ¬ÖØ×é±£´æÔ½½çдÎó²î £¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó £¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»£»£»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£ ¡£¡£

https://github.com/contiki-ng/contiki-ng/pull/972


> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢¼ÓÄôó¶ùͯÓÎÏ·ÍøÕ¾Webkinz½ü2300ÍòÓû§Êý¾Ýй¶


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


¼ÓÄôóÖøÃûÍæ¾ß¹«Ë¾GanzÆìϵĶùͯÓÎÏ·ÍøÕ¾WebkinzÔâµ½ºÚ¿ÍÈëÇÖ £¬£¬£¬½ü2300ÍòÍæ¼ÒµÄÓû§ÃûºÍÃÜÂëй¶ £¬£¬£¬ÆäÖÐй¶µÄÃÜÂëʹÓÃÁËMD5-CryptËã·¨¼ÓÃÜ¡£¡£¡£¡£¡£¡£ ¡£¡£¾ÝZDNet±¨µÀ £¬£¬£¬ºÚ¿ÍÊÇʹÓÃÍøÕ¾ÖеÄSQL×¢ÈëÎó²îÈëÇÖÓÎÏ·Êý¾Ý¿âµÄ £¬£¬£¬¾Ý³Æ¸ÃÎó²îµÄϸ½ÚÒÑÔÚºÚ¿ÍÂÛ̳ÖÐÈö²¥Á˼¸¸öÔ¡£¡£¡£¡£¡£¡£ ¡£¡£ºÚ¿Í¿ÉÄÜ»¹ÍµÈ¡Á˹þÏ£¼ÓÃܵĵç×ÓÓʼþµØµã¡£¡£¡£¡£¡£¡£ ¡£¡£ÐÂÎÅÈËÊ¿³ÆWebkinzÔ±¹¤ÒѾ­ÐÞ¸´Á˺ڿÍʹÓõÄÎó²î £¬£¬£¬µ«GanzÉÐδ¶Ô´ËÊÂÎñ¾ÙÐлØÓ¦¡£¡£¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/hacker-leaks-23-million-usernames-and-passwords-from-webkinz-childrens-game/


2¡¢FPGAоƬStarbleedÎó²î £¬£¬£¬Ó°ÏìÈüÁé˼¶à¸ö²úÆ·


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


Ñо¿Ö°Ô±·¢Ã÷FPGAоƬ±£´æStarbleedÎó²î £¬£¬£¬Ó°ÏìÁËÈüÁé˼7ϵÁеÄSpartan¡¢Artix¡¢Kintex¡¢Virtex×ÓϵÁжà¸ö²úÆ·¡£¡£¡£¡£¡£¡£ ¡£¡£ÓÉÓÚÎó²îΪӲ¼þ¼¶±ðÎó²î £¬£¬£¬Òò¶øÖ»ÄÜͨ¹ýÌæ»»Ð¾Æ¬À´ÐÞ¸´Îó²î¡£¡£¡£¡£¡£¡£ ¡£¡£Çå¾²Ñо¿Ö°Ô±·¢Ã÷¿ÉÒÔͨ¹ý½âÃܱ»¼ÓÃܵıÈÌØÁ÷À´»á¼ûºÍÐÞ¸ÄÓÃÓÚ±à³ÌµÄÎļþ¡£¡£¡£¡£¡£¡£ ¡£¡£Òò´Ë £¬£¬£¬ºÚ¿Í¿ÉÒÔʹÓøÃÎó²îÍêÈ«¿ØÖÆFPGAоƬ £¬£¬£¬²¢ÇÒ¿ÉÄÜ͵ȡ±ÈÌØÁ÷ÖеÄ֪ʶ²úȨ¡£¡£¡£¡£¡£¡£ ¡£¡£µÂ¹úMax PlanckÑо¿ËùµÄChristof Paar½ÌÊÚÌåÏÖ £¬£¬£¬¹¥»÷ÕßÉõÖÁ¿ÉÒÔ¾ÙÐÐÔ¶³Ì¹¥»÷ £¬£¬£¬»òÊÇÏòFPGAоƬֲÈëÓ²¼þľÂí¡£¡£¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.helpnetsecurity.com/2020/04/20/starbleed-vulnerability/


3¡¢CNCERTÐû²¼¡¶2019ÄêÎÒ¹ú»¥ÁªÍøÍøÂçÇå¾²Ì¬ÊÆ×ÛÊö¡·±¨¸æ


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


¹ú¼Ò»¥ÁªÍøÓ¦¼±ÖÐÐÄ£¨CNCERT£©ÓÚ2020Äê4ÔÂ20ÈÕÐû²¼ÁË¡¶2019ÄêÎÒ¹ú»¥ÁªÍøÍøÂçÇå¾²Ì¬ÊÆ×ÛÊö¡·±¨¸æ¡£¡£¡£¡£¡£¡£ ¡£¡£¸Ã±¨¸æ×¤×ãÓÚCNCERTÍøÂçÇå¾²ºê¹Û¼à²âÊý¾ÝÓëÊÂÇéʵ¼ù±¨¸æ £¬£¬£¬Éæ¼°2019Äêµä·¶ÍøÂçÇå¾²ÊÂÎñ¡¢ÍøÂçÇå¾²ÐÂÇ÷ÊÆ¼°Ò»Ñùƽ³£ÍøÂçÇå¾²ÊÂÎñÓ¦¼±´¦Öóͷ£Êµ¼ùµÈÄÚÈÝ¡£¡£¡£¡£¡£¡£ ¡£¡£±¨¸æÖ÷Òª°üÀ¨Ëĸö²¿·Ö £¬£¬£¬Ò»ÊÇ×ܽá2019ÄêÎÒ¹ú»¥ÁªÍøÍøÂçÇ徲״̬ £¬£¬£¬¶þÊÇÕ¹Íû2020ÄêÍøÂçÇå¾²ÈÈÃÅ £¬£¬£¬ÈýÊÇÁ¬ÏµÍøÂçÇå¾²Ì¬ÊÆÆÊÎöÌá³ö¶Ô²ß½¨Òé £¬£¬£¬ËÄÊÇÊáÀíÍøÂçÇå¾²¼à²âÊý¾Ý¡£¡£¡£¡£¡£¡£ ¡£¡£¸Ã±¨¸æ¶ÔÎÒ¹úµ³Õþ»ú¹Ø¡¢ÐÐÒµÆóÒµ¼°È«Éç»áÏàʶÎÒ¹úÍøÂçÇå¾²ÐÎÊÆ £¬£¬£¬Ìá¸ßÍøÂçÇå¾²Òâʶ £¬£¬£¬×öºÃÍøÂçÇå¾²ÊÂÇéÌṩÁËÓÐÁ¦²Î¿¼¡£¡£¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

http://www.cac.gov.cn/2020-04/20/c_1588932297982643.htm


4¡¢Ñо¿Ö°Ô±Åû¶IBMÆóÒµÇå¾²Èí¼þÖеÄ4¸ö0day


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


Çå¾²Ñо¿Ö°Ô±ÔÚÆÊÎöIBM Data Risk Manager£¨IDRM£©Ê±·¢Ã÷ÁË4¸ö0day £¬£¬£¬»®·ÖΪÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î¡¢ÏÂÁî×¢ÈëÎó²î¡¢²»Çå¾²µÄĬÈÏÃÜÂëÎó²îÒÔ¼°í§ÒâÎļþÏÂÔØÎó²î¡£¡£¡£¡£¡£¡£ ¡£¡£ÕâЩÎó²î¿ÉÒÔµ¥¶ÀʹÓÃÒ²¿ÉÒÔ×éºÏʹÓà £¬£¬£¬×éºÏʹÓÃǰÈý¸öÎó²î¿ÉÒÔʹ¹¥»÷ÕßÒÔrootȨÏÞÔ¶³ÌÖ´ÐдúÂë £¬£¬£¬×éºÏʹÓõÚÒ»¸öºÍµÚËĸöÎó²î¿ÉÒÔʹδÊÚȨµÄ¹¥»÷ÕßÏÂÔØí§ÒâÎļþ¡£¡£¡£¡£¡£¡£ ¡£¡£Îó²îµÄÅû¶ÕßRibeiroÌåÏÖ £¬£¬£¬IDRMÊÇ´¦Öóͷ£Ãô¸ÐÐÅÏ¢µÄÆóÒµÇå¾²²úÆ· £¬£¬£¬ÈôÊÇÆäÔâµ½¹¥»÷»áµ¼Ö¹«Ë¾ÀûÒæÑÏÖØÊÜË𠣬£¬£¬Òò´ËÔÚIBM¾Ü¾ø½ÓÊÜÎó²î±¨¸æºóÑ¡Ôñ½«ÆäÐû²¼³öÀ´¡£¡£¡£¡£¡£¡£ ¡£¡£ÏÖÔÚ £¬£¬£¬IBM¹«Ë¾ÐÞ¸´ÁËIDRM2.0.1¼°¸ü¸ß°æ±¾ÖеÄí§ÒâÎļþÏÂÔØÎó²îºÍÏÂÁî×¢ÈëÎó²î £¬£¬£¬²¢ÇÒÕýÔÚÊÓ²ìÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î¡£¡£¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/researcher-discloses-four-ibm-zero-days-after-refusal-to-fix/


5¡¢Î¢ÈíÐû²¼½ôÆÈ¸üР£¬£¬£¬ÐÞ¸´OfficeºÍPaint 3DÖжà¸öÎó²î


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


MicrosoftÐû²¼Á˽ôÆÈÇå¾²¸üР£¬£¬£¬ÒÔÐÞ¸´Ê¹ÓÃÁËAutodesk FBX¿âµÄMicrosoft²úÆ· £¬£¬£¬°üÀ¨¶à¸ö°æ±¾µÄMicrosoft OfficeºÍWindows 10Ó¦ÓóÌÐòPaint 3D¡£¡£¡£¡£¡£¡£ ¡£¡£±¾´ÎÐÞ¸´µÄÎó²îΪFBX¿âÖеÄÔ¶³ÌÖ´ÐдúÂëÎó²î £¬£¬£¬¹¥»÷ÕßʹÓôËÎó²î¿ÉÒÔ»ñµÃÓëÍâµØÓû§ÏàͬµÄȨÏÞ £¬£¬£¬AutodeskÔÚ4ÔÂ15ÈÕÍÆ³öÁËÕë¶Ô´ËÎó²îµÄ²¹¶¡³ÌÐò¡£¡£¡£¡£¡£¡£ ¡£¡£MicrosoftÌåÏÖ £¬£¬£¬ºÚ¿Í±ØÐèÓÕʹÓû§·­¿ªÆäÌØÖÆµÄ3DÎļþ²Å¿ÉÒÔÀÖ³ÉʹÓôËÎó²î £¬£¬£¬Òò´Ë £¬£¬£¬ÔÚÇå¾²¸üÐÂ֮ǰÓû§ÐèÒªÔ¶ÀëÄÇЩ¿ÉÒÉÎļþÒÔ°ü¹ÜÇå¾²¡£¡£¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://news.softpedia.com/news/microsoft-releases-emergency-update-for-windows-10-app-microsoft-office-529800.shtml