ÐÅÏ¢Çå¾²Öܱ¨-2020ÄêµÚ17ÖÜ
Ðû²¼Ê±¼ä 2020-04-28> ±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö
2020Äê04ÔÂ20ÈÕÖÁ26ÈÕ¹²ÊÕ¼Çå¾²Îó²î54¸ö£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇApple macOS Mail Javascript´úÂëÖ´ÐÐÎó²î; Google Chrome paymentsÄÚ´æ¹ýʧÒýÓôúÂëÖ´ÐÐÎó²î£»£»£»£»£»Sonatype Nexus Repository ManagerȨÏÞÌáÉýÎó²î£»£»£»£»£»Í¨´ïOAí§ÒâÓû§µÇ¼Îó²î£»£»£»£»£»Contiki-NGÔ½½çд´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊǼÓÄôó¶ùͯÓÎÏ·ÍøÕ¾Webkinz½ü2300ÍòÓû§Êý¾Ýй¶£»£»£»£»£»FPGAоƬStarbleedÎó²î£¬£¬£¬Ó°ÏìÈüÁé˼¶à¸ö²úÆ·£»£»£»£»£»CNCERTÐû²¼¡¶2019ÄêÎÒ¹ú»¥ÁªÍøÍøÂçÇå¾²Ì¬ÊÆ×ÛÊö¡·±¨¸æ£»£»£»£»£»Ñо¿Ö°Ô±Åû¶IBMÆóÒµÇå¾²Èí¼þÖеÄ4¸ö0day£»£»£»£»£»Î¢ÈíÐû²¼½ôÆÈ¸üУ¬£¬£¬ÐÞ¸´OfficeºÍPaint 3DÖжà¸öÎó²î¡£¡£¡£¡£¡£¡£¡£¡£
ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£¡£¡£¡£¡£
>Ö÷ÒªÇå¾²Îó²îÁбí
1. Apple macOS Mail Javascript´úÂëÖ´ÐÐÎó²î
Apple macOS Mail±£´æ´úÂë×¢ÈëÎó²î£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§ÒâJavaScript´úÂë¡£¡£¡£¡£¡£¡£¡£¡£¡£¡£¡£¡£¡£¡£¡£¡£
https://support.apple.com/en-us/HT211100
2. Google Chrome paymentsÄÚ´æ¹ýʧÒýÓôúÂëÖ´ÐÐÎó²î
Google Chrome payments±£´æÊͷźóʹÓÃÎó²î£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄWEBÇëÇ󣬣¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬¿É¾ÙÐоܾøÐ§À͹¥»÷»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§ÒâÂë¡£¡£¡£¡£¡£¡£¡£¡£
https://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop_21.html
3. Sonatype Nexus Repository ManagerȨÏÞÌáÉýÎó²î
Sonatype Nexus Repository ManagerʵÏÖ±£´æÇå¾²Îó²î£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬¿ÉÌáÉýÌØÈ¨£¬£¬£¬¾ÙÐн¨É裬£¬£¬Ð޸쬣¬£¬Ö´ÐÐʹÃü¡£¡£¡£¡£¡£¡£¡£¡£
https://support.sonatype.com/hc/en-us/articles/360046233714
4. ͨ´ïOAí§ÒâÓû§µÇ¼Îó²î
ͨ´ïOAµÇ¼ʵÏÖ±£´æÇå¾²Îó²î£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬¿ÉÒÔí§ÒâÓû§ÉÏÏÂÎĵǼ¡£¡£¡£¡£¡£¡£¡£¡£
https://cert.360.cn/warning/detail?id=d2689a877c01a9712d148317c2da21a2
5. Contiki-NGÔ½½çд´úÂëÖ´ÐÐÎó²î
Contiki-NG os/net/ipv6/sicslowpan.cÔÚ´¦Öóͷ£6LoWPAN·ÖÆ¬ÖØ×é±£´æÔ½½çдÎó²î£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»£»£»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£
https://github.com/contiki-ng/contiki-ng/pull/972
1¡¢¼ÓÄôó¶ùͯÓÎÏ·ÍøÕ¾Webkinz½ü2300ÍòÓû§Êý¾Ýй¶
¼ÓÄôóÖøÃûÍæ¾ß¹«Ë¾GanzÆìϵĶùͯÓÎÏ·ÍøÕ¾WebkinzÔâµ½ºÚ¿ÍÈëÇÖ£¬£¬£¬½ü2300ÍòÍæ¼ÒµÄÓû§ÃûºÍÃÜÂëй¶£¬£¬£¬ÆäÖÐй¶µÄÃÜÂëʹÓÃÁËMD5-CryptËã·¨¼ÓÃÜ¡£¡£¡£¡£¡£¡£¡£¡£¾ÝZDNet±¨µÀ£¬£¬£¬ºÚ¿ÍÊÇʹÓÃÍøÕ¾ÖеÄSQL×¢ÈëÎó²îÈëÇÖÓÎÏ·Êý¾Ý¿âµÄ£¬£¬£¬¾Ý³Æ¸ÃÎó²îµÄϸ½ÚÒÑÔÚºÚ¿ÍÂÛ̳ÖÐÈö²¥Á˼¸¸öÔ¡£¡£¡£¡£¡£¡£¡£¡£ºÚ¿Í¿ÉÄÜ»¹ÍµÈ¡Á˹þÏ£¼ÓÃܵĵç×ÓÓʼþµØµã¡£¡£¡£¡£¡£¡£¡£¡£ÐÂÎÅÈËÊ¿³ÆWebkinzÔ±¹¤ÒѾÐÞ¸´Á˺ڿÍʹÓõÄÎó²î£¬£¬£¬µ«GanzÉÐδ¶Ô´ËÊÂÎñ¾ÙÐлØÓ¦¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/hacker-leaks-23-million-usernames-and-passwords-from-webkinz-childrens-game/
2¡¢FPGAоƬStarbleedÎó²î£¬£¬£¬Ó°ÏìÈüÁé˼¶à¸ö²úÆ·
Ñо¿Ö°Ô±·¢Ã÷FPGAоƬ±£´æStarbleedÎó²î£¬£¬£¬Ó°ÏìÁËÈüÁé˼7ϵÁеÄSpartan¡¢Artix¡¢Kintex¡¢Virtex×ÓϵÁжà¸ö²úÆ·¡£¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚÎó²îΪӲ¼þ¼¶±ðÎó²î£¬£¬£¬Òò¶øÖ»ÄÜͨ¹ýÌæ»»Ð¾Æ¬À´ÐÞ¸´Îó²î¡£¡£¡£¡£¡£¡£¡£¡£Çå¾²Ñо¿Ö°Ô±·¢Ã÷¿ÉÒÔͨ¹ý½âÃܱ»¼ÓÃܵıÈÌØÁ÷À´»á¼ûºÍÐÞ¸ÄÓÃÓÚ±à³ÌµÄÎļþ¡£¡£¡£¡£¡£¡£¡£¡£Òò´Ë£¬£¬£¬ºÚ¿Í¿ÉÒÔʹÓøÃÎó²îÍêÈ«¿ØÖÆFPGAоƬ£¬£¬£¬²¢ÇÒ¿ÉÄÜ͵ȡ±ÈÌØÁ÷ÖеÄ֪ʶ²úȨ¡£¡£¡£¡£¡£¡£¡£¡£µÂ¹úMax PlanckÑо¿ËùµÄChristof Paar½ÌÊÚÌåÏÖ£¬£¬£¬¹¥»÷ÕßÉõÖÁ¿ÉÒÔ¾ÙÐÐÔ¶³Ì¹¥»÷£¬£¬£¬»òÊÇÏòFPGAоƬֲÈëÓ²¼þľÂí¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.helpnetsecurity.com/2020/04/20/starbleed-vulnerability/
3¡¢CNCERTÐû²¼¡¶2019ÄêÎÒ¹ú»¥ÁªÍøÍøÂçÇå¾²Ì¬ÊÆ×ÛÊö¡·±¨¸æ
¹ú¼Ò»¥ÁªÍøÓ¦¼±ÖÐÐÄ£¨CNCERT£©ÓÚ2020Äê4ÔÂ20ÈÕÐû²¼ÁË¡¶2019ÄêÎÒ¹ú»¥ÁªÍøÍøÂçÇå¾²Ì¬ÊÆ×ÛÊö¡·±¨¸æ¡£¡£¡£¡£¡£¡£¡£¡£¸Ã±¨¸æ×¤×ãÓÚCNCERTÍøÂçÇå¾²ºê¹Û¼à²âÊý¾ÝÓëÊÂÇéʵ¼ù±¨¸æ£¬£¬£¬Éæ¼°2019Äêµä·¶ÍøÂçÇå¾²ÊÂÎñ¡¢ÍøÂçÇå¾²ÐÂÇ÷ÊÆ¼°Ò»Ñùƽ³£ÍøÂçÇå¾²ÊÂÎñÓ¦¼±´¦Öóͷ£Êµ¼ùµÈÄÚÈÝ¡£¡£¡£¡£¡£¡£¡£¡£±¨¸æÖ÷Òª°üÀ¨Ëĸö²¿·Ö£¬£¬£¬Ò»ÊÇ×ܽá2019ÄêÎÒ¹ú»¥ÁªÍøÍøÂçÇ徲״̬£¬£¬£¬¶þÊÇÕ¹Íû2020ÄêÍøÂçÇå¾²ÈÈÃÅ£¬£¬£¬ÈýÊÇÁ¬ÏµÍøÂçÇå¾²Ì¬ÊÆÆÊÎöÌá³ö¶Ô²ß½¨Ò飬£¬£¬ËÄÊÇÊáÀíÍøÂçÇå¾²¼à²âÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£¸Ã±¨¸æ¶ÔÎÒ¹úµ³Õþ»ú¹Ø¡¢ÐÐÒµÆóÒµ¼°È«Éç»áÏàʶÎÒ¹úÍøÂçÇå¾²ÐÎÊÆ£¬£¬£¬Ìá¸ßÍøÂçÇå¾²Òâʶ£¬£¬£¬×öºÃÍøÂçÇå¾²ÊÂÇéÌṩÁËÓÐÁ¦²Î¿¼¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
http://www.cac.gov.cn/2020-04/20/c_1588932297982643.htm
4¡¢Ñо¿Ö°Ô±Åû¶IBMÆóÒµÇå¾²Èí¼þÖеÄ4¸ö0day
Çå¾²Ñо¿Ö°Ô±ÔÚÆÊÎöIBM Data Risk Manager£¨IDRM£©Ê±·¢Ã÷ÁË4¸ö0day£¬£¬£¬»®·ÖΪÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î¡¢ÏÂÁî×¢ÈëÎó²î¡¢²»Çå¾²µÄĬÈÏÃÜÂëÎó²îÒÔ¼°í§ÒâÎļþÏÂÔØÎó²î¡£¡£¡£¡£¡£¡£¡£¡£ÕâЩÎó²î¿ÉÒÔµ¥¶ÀʹÓÃÒ²¿ÉÒÔ×éºÏʹÓ㬣¬£¬×éºÏʹÓÃǰÈý¸öÎó²î¿ÉÒÔʹ¹¥»÷ÕßÒÔrootȨÏÞÔ¶³ÌÖ´ÐдúÂ룬£¬£¬×éºÏʹÓõÚÒ»¸öºÍµÚËĸöÎó²î¿ÉÒÔʹδÊÚȨµÄ¹¥»÷ÕßÏÂÔØí§ÒâÎļþ¡£¡£¡£¡£¡£¡£¡£¡£Îó²îµÄÅû¶ÕßRibeiroÌåÏÖ£¬£¬£¬IDRMÊÇ´¦Öóͷ£Ãô¸ÐÐÅÏ¢µÄÆóÒµÇå¾²²úÆ·£¬£¬£¬ÈôÊÇÆäÔâµ½¹¥»÷»áµ¼Ö¹«Ë¾ÀûÒæÑÏÖØÊÜË𣬣¬£¬Òò´ËÔÚIBM¾Ü¾ø½ÓÊÜÎó²î±¨¸æºóÑ¡Ôñ½«ÆäÐû²¼³öÀ´¡£¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬IBM¹«Ë¾ÐÞ¸´ÁËIDRM2.0.1¼°¸ü¸ß°æ±¾ÖеÄí§ÒâÎļþÏÂÔØÎó²îºÍÏÂÁî×¢ÈëÎó²î£¬£¬£¬²¢ÇÒÕýÔÚÊÓ²ìÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/researcher-discloses-four-ibm-zero-days-after-refusal-to-fix/
5¡¢Î¢ÈíÐû²¼½ôÆÈ¸üУ¬£¬£¬ÐÞ¸´OfficeºÍPaint 3DÖжà¸öÎó²î
MicrosoftÐû²¼Á˽ôÆÈÇå¾²¸üУ¬£¬£¬ÒÔÐÞ¸´Ê¹ÓÃÁËAutodesk FBX¿âµÄMicrosoft²úÆ·£¬£¬£¬°üÀ¨¶à¸ö°æ±¾µÄMicrosoft OfficeºÍWindows 10Ó¦ÓóÌÐòPaint 3D¡£¡£¡£¡£¡£¡£¡£¡£±¾´ÎÐÞ¸´µÄÎó²îΪFBX¿âÖеÄÔ¶³ÌÖ´ÐдúÂëÎó²î£¬£¬£¬¹¥»÷ÕßʹÓôËÎó²î¿ÉÒÔ»ñµÃÓëÍâµØÓû§ÏàͬµÄȨÏÞ£¬£¬£¬AutodeskÔÚ4ÔÂ15ÈÕÍÆ³öÁËÕë¶Ô´ËÎó²îµÄ²¹¶¡³ÌÐò¡£¡£¡£¡£¡£¡£¡£¡£MicrosoftÌåÏÖ£¬£¬£¬ºÚ¿Í±ØÐèÓÕʹÓû§·¿ªÆäÌØÖÆµÄ3DÎļþ²Å¿ÉÒÔÀÖ³ÉʹÓôËÎó²î£¬£¬£¬Òò´Ë£¬£¬£¬ÔÚÇå¾²¸üÐÂ֮ǰÓû§ÐèÒªÔ¶ÀëÄÇЩ¿ÉÒÉÎļþÒÔ°ü¹ÜÇå¾²¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://news.softpedia.com/news/microsoft-releases-emergency-update-for-windows-10-app-microsoft-office-529800.shtml


¾©¹«Íø°²±¸11010802024551ºÅ