ÐÅÏ¢Çå¾²Öܱ¨-2020ÄêµÚ18ÖÜ
Ðû²¼Ê±¼ä 2020-05-06> ±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö
2020Äê04ÔÂ27ÈÕÖÁ05ÔÂ03ÈÕ¹²ÊÕ¼Çå¾²Îó²î70¸ö£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇSaltStack Salt salt-master process ClearFuncs²»×¼È·Ð£ÑéÒªÁìŲÓÃÎó²î; Apache IoTDB 31999¶Ë¿ÚδÊÚȨ»á¼ûÎó²î£»£»£»£»Adobe Bridge¶à¸öÔ½½çд´úÂëÖ´ÐÐÎó²î£»£»£»£»Google OpenThread MeshCoP::Commissioner::GeneratePskc»º³åÇøÒç³öÎó²î£»£»£»£»BMC Control-M/Agent OSÏÂÁî×¢ÈëÎó²î¡£¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇSophos½ôÆÈÐÞ¸´·À»ðǽÖеÄSQL×¢Èë0day£¬£¬£¬£¬£¬Òѱ»Ò°ÍâʹÓ㻣»£»£»ÍøÐŰìµÈ12¸ö²¿·ÖÁªºÏÐû²¼¡¶ÍøÂçÇå¾²Éó²é²½·¥¡·£»£»£»£»AdobeÐû²¼½ôÆÈ²¹¶¡£¬£¬£¬£¬£¬ÐÞ¸´Æä3¿î²úÆ·ÖеÄ35¸öÎó²î£»£»£»£»CNNICÐû²¼¡¶Öйú»¥ÁªÍøÂçÉú³¤×´Ì¬Í³¼Æ±¨¸æ¡·£»£»£»£»¹È¸èÑо¿Ö°Ô±Åû¶ƻ¹ûImage I/OµÄÁãµã»÷Îó²î¡£¡£¡£
ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£
>Ö÷ÒªÇå¾²Îó²îÁбí
1. SaltStack Salt salt-master process ClearFuncs²»×¼È·Ð£ÑéÒªÁìŲÓÃÎó²î
SaltStack Salt salt-master process ClearFuncs²»×¼È·Ð£ÑéÒªÁìŲÓ㬣¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬¿É»ñÈ¡Óû§ÁîÅÆ£¬£¬£¬£¬£¬Î´ÊÚȨ»á¼û²¢Ö´ÐÐÏÂÁî¡£¡£¡£
https://docs.saltstack.com/en/latest/topics/releases/2019.2.4.html
2. Apache IoTDB 31999¶Ë¿ÚδÊÚȨ»á¼ûÎó²î
Apache IoTDB JMX 31999¶Ë¿Ú±£´æÎ´ÊÚȨÎó²î£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬¿ÉδÊÚȨ»á¼û²¢Ö´ÐÐí§Òâ´úÂë¡£¡£¡£
https://lists.apache.org/thread.html/r3d2ff899ead64d2952fdc1fbb1f520ca42011ed2b4c7f786e921f6b9%40%3Cdev.iotdb.apache.org%3E
3. Adobe Bridge¶à¸öÔ½½çд´úÂëÖ´ÐÐÎó²î
Adobe Bridge´¦Öóͷ£Îļþ±£´æÔ½½çдÎó²î£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþÇëÇ󣬣¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬£¬¿ÉʹӦÓóÌÐòÍ߽⻣»£»£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£
https://helpx.adobe.com/security/products/bridge/apsb20-19.html
4. Google OpenThread MeshCoP::Commissioner::GeneratePskc»º³åÇøÒç³öÎó²î
Google OpenThread MeshCoP::Commissioner::GeneratePskc±£´æ»º³åÇøÒç³öÎó²î£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬¿ÉʹӦÓóÌÐòÍ߽⻣»£»£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=19386
5. BMC Control-M/Agent OSÏÂÁî×¢ÈëÎó²î
ʹÓÃTCPÐÒéʱBMC Control-M/Agent±£´æÊäÈëÑéÖ¤Îó²î£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬¿É×¢Èëí§ÒâOSÏÂÁî¡£¡£¡£
https://herolab.usd.de/security-advisories/usd-2019-0064/
> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö
1¡¢Sophos½ôÆÈÐÞ¸´·À»ðǽÖеÄSQL×¢Èë0day£¬£¬£¬£¬£¬Òѱ»Ò°ÍâʹÓÃ
ÍøÂçÇå¾²¹«Ë¾SophosÓÚÖÜÁùÐû²¼Á˽ôÆÈ²¹¶¡ÒÔÐÞ¸´ÒѾ±»Ò°ÍâʹÓõÄSQL×¢Èë0day£¬£¬£¬£¬£¬¸ÃÎó²îÓ°ÏìÁËÆäXG Firewall²úÆ·¡£¡£¡£4ÔÂ22ÈÕÍí£¬£¬£¬£¬£¬Sophos¹«Ë¾·¢Ã÷ºÚ¿ÍʹÓÃXG FirewallÖеÄSQL×¢ÈëÎó²îÇÔÈ¡Á˸Ã×°±¸ÖеÄÊý¾Ý£¬£¬£¬£¬£¬°üÀ¨·À»ðǽװ±¸ÖÎÀíÔ±ÕË»§¡¢·À»ðǽÃÅ»§ÍøÕ¾ÖÎÀíÔ±ÕË»§ºÍÔ¶³Ì»á¼û×°±¸ÕË»§ÖеĵÄÓû§ÃûºÍ¹þÏ£ÃÜÂë¡£¡£¡£¸Ã¹«Ë¾ÌåÏִ˴θüÐÂÒѾÐÞ¸´Á˸ÃSQL×¢ÈëÎó²î£¬£¬£¬£¬£¬²¢ÇÒмÓÁËÌØÊâÌáÐѹ¦Ð§Ê¹¿Í»§ÖªµÀÆä×°±¸ÊÇ·ñÊܵ½ÁËÍþв¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/hackers-are-exploiting-a-sophos-firewall-zero-day/
2¡¢ÍøÐŰìµÈ12¸ö²¿·ÖÁªºÏÐû²¼¡¶ÍøÂçÇå¾²Éó²é²½·¥¡·
ÔÎÄÁ´½Ó£º
http://www.cac.gov.cn/2020-04/27/c_1589535450769077.htm
3¡¢AdobeÐû²¼½ôÆÈ²¹¶¡£¬£¬£¬£¬£¬ÐÞ¸´Æä3¿î²úÆ·ÖеÄ35¸öÎó²î
Èí¼þ¹«Ë¾AdobeÓÚ4ÔÂ28ÈÕÐû²¼½ôÆÈÎó²î²¹¶¡£¬£¬£¬£¬£¬×ܹ²ÐÞ¸´ÁË35¸öÎó²î£¬£¬£¬£¬£¬ÕâЩÎó²îÓ°ÏìµÄ²úÆ·ÓÐAdobe Illustrator¡¢Adobe BridgeºÍµçÉÌÆ½Ì¨Magento¡£¡£¡£´Ë´ÎÇå¾²¸üÐÂÐÞ¸´ÁËWindows°æ±¾Illustrator 2020ÖеÄ5¸ö´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬£¬Adobe Bridge 10.0.1¼°¸üÔç°æ±¾ÖеÄ17¸öÎó²î£¨14¸ö¿Éµ¼Ö´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬£¬3¸öÓйØÐÅϢй¶ÎÊÌ⣩£¬£¬£¬£¬£¬ÉÌÒµ°æ±¾ºÍ¿ªÔ´°æ±¾µÄMagento CMSÖеÄ13¸öÎó²î¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2020/04/adobe-software-updates.html
4¡¢CNNICÐû²¼¡¶Öйú»¥ÁªÍøÂçÉú³¤×´Ì¬Í³¼Æ±¨¸æ¡·
ÔÎÄÁ´½Ó£º
http://news.china.com.cn/txt/2020-04/28/content_75985166.htm
5¡¢¹È¸èÑо¿Ö°Ô±Åû¶ƻ¹ûImage I/OµÄÁãµã»÷Îó²î
¹È¸èµÄProject Zero ÍŶÓÓÚ±¾ÖܶþÅû¶ÁËApple²Ù×÷ϵͳÖÐÄÚÖõĿò¼ÜImage I/OÖеÄÁãµã»÷Îó²î£¬£¬£¬£¬£¬¸Ã¿ò¼Ü±»Ó¦ÓÃÓÚiOS¡¢macOS¡¢tvOSºÍwatchOSÖУ¬£¬£¬£¬£¬ÓÃÀ´´¦Öóͷ£Í¼ÏñÔªÊý¾Ý¡£¡£¡£Project ZeroÍŶÓÌåÏÖ£¬£¬£¬£¬£¬ËûÃÇÆÊÎöÁ˸ÿò¼ÜµÄÄ£ºý´¦Öóͷ£Àú³Ì£¬£¬£¬£¬£¬ÒÔÊÓ²ìËüÊÇÈçÄÇÀïÖÃÃûÌùýʧµÄͼÏñÎļþ¡£¡£¡£Ð§¹ûÑо¿Ö°Ô±·¢Ã÷ÁË Image I/O Öб£´æ6¸öÎó²î£¬£¬£¬£¬£¬¶øÆ»¹ûÏòµÚÈý·½¹ûÕæµÄ¸ß¶¯Ì¬¹æÄ££¨HDR£©Í¼ÏñÎļþÃûÌÿò¼ÜOpenEXRÖб£´æ8¸öÎó²î¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬ËùÓÐÎó²î¶¼ÒѾ±»ÐÞ¸´¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/google-discloses-zero-click-bugs-impacting-several-apple-operating-systems/


¾©¹«Íø°²±¸11010802024551ºÅ