ÐÅÏ¢°²È«Öܱ¨-2020ÄêµÚ17ÖÜ

°ä²¼¹¦·ò 2020-04-28

> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2020Äê04ÔÂ20ÈÕÖÁ26ÈÕ¹²ÊÕ¼°²È«·ì϶54¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇApple macOS Mail Javascript´úÂëÖ´Ðзì϶; Google Chrome paymentsÄÚ´æÃýÎóÒýÓôúÂëÖ´Ðзì϶£»Sonatype Nexus Repository ManagerȨÏÞÌáÉý·ì϶£»ÁéͨOAËÁÒâÓû§µÇ¼·ì϶£»Contiki-NGÔ½½çд´úÂëÖ´Ðзì϶¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊǼÓÄôó¶ùͯÓÎÏ·ÍøÕ¾Webkinz½ü2300ÍòÓû§Êý¾Ýй¶£»FPGAоƬStarbleed·ì϶£¬Ó°ÏìÈüÁé˼¶à¸ö²úÆ·£»CNCERT°ä²¼¡¶2019ÄêÎÒ¹ú»¥ÁªÍøÍøÂç°²È«Ì¬ÊÆ×ÛÊö¡·»ã±¨£»×êÑÐÈËÔ±Åû¶IBMÆóÒµ°²È«Èí¼þÖеÄ4¸ö0day£»Î¢Èí°ä²¼´¹Î£¸üУ¬½¨¸´OfficeºÍPaint 3DÖжà¸ö·ì϶¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖС£


>³ÁÒª°²È«·ì϶Áбí


1. Apple macOS Mail Javascript´úÂëÖ´Ðзì϶


Apple macOS Mail´æÔÚ´úÂë×¢Èë·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâJavaScript´úÂë¡£¡£

https://support.apple.com/en-us/HT211100


2. Google Chrome paymentsÄÚ´æÃýÎóÒýÓôúÂëÖ´Ðзì϶


Google Chrome payments´æÔÚ¿ªÊͺóʹÓ÷ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄWEBÒªÇó£¬ÓÕʹÓû§½âÎö£¬¿É½øÐлؾø·þÎñ¹¥»÷»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâÂë¡£

https://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop_21.html


3. Sonatype Nexus Repository ManagerȨÏÞÌáÉý·ì϶


Sonatype Nexus Repository ManagerʵÏÖ´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉÌáÉýÌØÈ¨£¬½øÐд´½¨£¬Åú¸Ä£¬Ö´Ðй¤×÷¡£

https://support.sonatype.com/hc/en-us/articles/360046233714


4. ÁéͨOAËÁÒâÓû§µÇ¼·ì϶


ÁéͨOAµÇ¼ʵÏÖ´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Äܹ»ËÁÒâÓû§¸ßµÍÎĵǼ¡£

https://cert.360.cn/warning/detail?id=d2689a877c01a9712d148317c2da21a2


5. Contiki-NGÔ½½çд´úÂëÖ´Ðзì϶


Contiki-NG os/net/ipv6/sicslowpan.cÔÚ´¦ÖÃ6LoWPAN·Ô쬳Á×é´æÔÚÔ½½çд·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐËÁÒâ´úÂë¡£

https://github.com/contiki-ng/contiki-ng/pull/972


> ³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢¼ÓÄôó¶ùͯÓÎÏ·ÍøÕ¾Webkinz½ü2300ÍòÓû§Êý¾Ýй¶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¼ÓÄôó³ÛÃûÍæ¾ß¹«Ë¾GanzÆìϵĶùͯÓÎÏ·ÍøÕ¾WebkinzÔâµ½ºÚ¿ÍÈëÇÖ£¬½ü2300ÍòÍæ¼ÒµÄÓû§ÃûºÍÃÜÂëй¶£¬ÆäÖÐй¶µÄÃÜÂëʹÓÃÁËMD5-CryptËã·¨¼ÓÃÜ¡£¾ÝZDNet±¨Â·£¬ºÚ¿ÍÊÇÀûÓÃÍøÕ¾ÖеÄSQL×¢Èë·ì϶ÈëÇÖÓÎÏ·Êý¾Ý¿âµÄ£¬¾Ý³Æ¸Ã·ì϶µÄϸ½ÚÒÑÔÚºÚ¿ÍÂÛ̳Öд«²¼Á˼¸¸öÔ¡£ºÚ¿Í¿ÉÄÜ»¹µÁÈ¡Á˹þÏ£¼ÓÃܵĵç×ÓÓʼþµØÖ·¡£ÐÂÎÅÈËÊ¿³ÆWebkinzÔ±¹¤ÒѾ­½¨¸´Á˺ڿÍʹÓõķì϶£¬µ«GanzÉÐδ¶Ô´ËÊÂÎñ½øÐлØÓ¦¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/hacker-leaks-23-million-usernames-and-passwords-from-webkinz-childrens-game/


2¡¢FPGAоƬStarbleed·ì϶£¬Ó°ÏìÈüÁé˼¶à¸ö²úÆ·


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


×êÑÐÈËÔ±·¢ÏÖFPGAоƬ´æÔÚStarbleed·ì϶£¬Ó°ÏìÁËÈüÁé˼7ϵÁеÄSpartan¡¢Artix¡¢Kintex¡¢Virtex×ÓϵÁжà¸ö²úÆ·¡£ÓÉÓÚ·ì϶ΪӲ¼þ¼¶±ð·ì϶£¬Òò¶øÖ»ÄÜͨ¹ý¸ü»»Ð¾Æ¬À´½¨¸´·ì϶¡£°²È«×êÑÐÈËÔ±·¢ÏÖÄܹ»Í¨¹ý½âÃܱ»¼ÓÃܵıÈÌØÁ÷À´½Ó¼ûºÍÅú¸ÄÓÃÓÚ±à³ÌµÄÎļþ¡£Òò¶ø£¬ºÚ¿ÍÄܹ»ÀûÓø÷ì϶ÆëÈ«½ÚÔìFPGAоƬ£¬²¢ÇÒ¿ÉÄܵÁÈ¡±ÈÌØÁ÷ÖеÄ֪ʶ²úȨ¡£µÂ¹úMax Planck×êÑÐËùµÄChristof Paar½ÌÊÚ°µÊ¾£¬¹¥»÷ÕßÉõÖÁÄܹ»½øÐÐÔ¶³Ì¹¥»÷£¬»òÊÇÏòFPGAоƬֲÈëÓ²¼þľÂí¡£


Ô­ÎÄÁ´½Ó£º

https://www.helpnetsecurity.com/2020/04/20/starbleed-vulnerability/


3¡¢CNCERT°ä²¼¡¶2019ÄêÎÒ¹ú»¥ÁªÍøÍøÂç°²È«Ì¬ÊÆ×ÛÊö¡·»ã±¨


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¹ú¶È»¥ÁªÍøÓ¦¼±ÖÐÐÄ£¨CNCERT£©ÓÚ2020Äê4ÔÂ20ÈÕ°ä²¼ÁË¡¶2019ÄêÎÒ¹ú»¥ÁªÍøÍøÂç°²È«Ì¬ÊÆ×ÛÊö¡·»ã±¨¡£¸Ã»ã±¨°²ÉíÓÚCNCERTÍøÂ簲ȫºê¹Û¼à²âÊý¾ÝÓ빤×÷ʵ¼Ê»ã±¨£¬Éæ¼°2019ÄêµäÐÍÍøÂ簲ȫÊÂÎñ¡¢ÍøÂ簲ȫÐÂÇ÷Ïò¼°ÈÕ³£ÍøÂ簲ȫÊÂÎñÓ¦¼±´ëÖÃʵ¼ÊµÈÄÚÈÝ¡£»ã±¨ÖØÒªÔ̺¬Ëĸö²¿ÃÅ£¬Ò»ÊÇ×ܽá2019ÄêÎÒ¹ú»¥ÁªÍøÍøÂ簲ȫÇé¿ö£¬¶þÊÇÔ¤²â2020ÄêÍøÂ簲ȫÈȵ㣬ÈýÊǽáºÏÍøÂç°²È«Ì¬ÊÆ·ÖÎöÌá³ö¶Ô²ß½¨Ò飬ËÄÊÇÊáÀíÍøÂ簲ȫ¼à²âÊý¾Ý¡£¸Ã»ã±¨¶ÔÎÒ¹úµ³Õþ»ú¹Ø¡¢ÐÐÒµÆóÒµ¼°È«Éç»áÏàʶÎÒ¹úÍøÂ簲ȫ¾ÖÊÆ£¬Ìá¸ßÍøÂ簲ȫÒâʶ£¬×öºÃÍøÂ簲ȫ¹¤×÷ÌṩÁËÓÐÁ¦²Î¿¼¡£


Ô­ÎÄÁ´½Ó£º

http://www.cac.gov.cn/2020-04/20/c_1588932297982643.htm


4¡¢×êÑÐÈËÔ±Åû¶IBMÆóÒµ°²È«Èí¼þÖеÄ4¸ö0day


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


°²È«×êÑÐÈËÔ±ÔÚ·ÖÎöIBM Data Risk Manager£¨IDRM£©Ê±·¢ÏÖÁË4¸ö0day£¬±ðÀëΪÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶¡¢ºÅÁî×¢Èë·ì϶¡¢²»°²È«µÄĬÈÏÃÜÂë·ì϶ÒÔ¼°ËÁÒâÎļþÏÂÔØ·ì϶¡£ÕâЩ·ì϶Äܹ»µ¥¶ÀʹÓÃÒ²Äܹ»×éºÏʹÓã¬×éºÏʹÓÃǰÈý¸ö·ì϶Äܹ»Ê¹¹¥»÷ÕßÒÔrootȨÏÞÔ¶³ÌÖ´ÐдúÂ룬×éºÏʹÓõÚÒ»¸öºÍµÚËĸö·ì϶Äܹ»Ê¹Î´ÊÚȨµÄ¹¥»÷ÕßÏÂÔØËÁÒâÎļþ¡£·ì϶µÄÅû¶ÕßRibeiro°µÊ¾£¬IDRMÊÇ´¦ÖÃÃô¸ÐÐÅÏ¢µÄÆóÒµ°²È«²úÆ·£¬ÈôÊÇÆäÔâµ½¹¥»÷»áµ¼Ö¹«Ë¾ÀûÒæÑϳÁÊÜËð£¬Òò¶øÔÚIBM»Ø¾ø½ÓÊÜ·ì϶»ã±¨ºóÑ¡Ôñ½«Æä°ä²¼³öÀ´¡£Ä¿Ç°£¬IBM¹«Ë¾½¨¸´ÁËIDRM2.0.1¼°¸ü¸ß°æ±¾ÖеÄËÁÒâÎļþÏÂÔØ·ì϶ºÍºÅÁî×¢Èë·ì϶£¬²¢ÇÒÔÚµ÷²éÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/researcher-discloses-four-ibm-zero-days-after-refusal-to-fix/


5¡¢Î¢Èí°ä²¼´¹Î£¸üУ¬½¨¸´OfficeºÍPaint 3DÖжà¸ö·ì϶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Microsoft°ä²¼ÁË´¹Î£°²È«¸üУ¬ÒÔ½¨¸´Ê¹ÓÃÁËAutodesk FBX¿âµÄMicrosoft²úÆ·£¬Ô̺¬¶à¸ö°æ±¾µÄMicrosoft OfficeºÍWindows 10ÀûÓ÷¨Ê½Paint 3D¡£±¾´Î½¨¸´µÄ·ì϶ΪFBX¿âÖеÄÔ¶³ÌÖ´ÐдúÂë·ì϶£¬¹¥»÷ÕßÀûÓô˷ì϶Äܹ»»ñµÃÓë±¾µØÓû§Ò»ÑùµÄȨÏÞ£¬AutodeskÔÚ4ÔÂ15ÈÕÍÆ³öÁËÕë¶Ô´Ë·ì϶µÄ²¹¶¡·¨Ê½¡£Microsoft°µÊ¾£¬ºÚ¿Í±ØÐëÓÕʹÓû§´ò¿ªÆäÌØÔìµÄ3DÎļþÄÜÁ¦¹»³É¹¦ÀûÓô˷ì϶£¬Òò¶ø£¬ÔÚ°²È«¸üÐÂ֮ǰÓû§±ØÒªÔ¶ÀëÄÇЩ¿ÉÒÉÎļþÒÔ±£Õϰ²È«¡£


Ô­ÎÄÁ´½Ó£º

https://news.softpedia.com/news/microsoft-releases-emergency-update-for-windows-10-app-microsoft-office-529800.shtml