ÐÅÏ¢°²È«Öܱ¨-2020ÄêµÚ18ÖÜ
°ä²¼¹¦·ò 2020-05-06> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
2020Äê04ÔÂ27ÈÕÖÁ05ÔÂ03ÈÕ¹²ÊÕ¼°²È«·ì϶70¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇSaltStack Salt salt-master process ClearFuncs²»ÕýȷУÑé²½ÖèŲÓ÷ì϶; Apache IoTDB 31999¶Ë¿ÚδÊÚȨ½Ó¼û·ì϶£»Adobe Bridge¶à¸öÔ½½çд´úÂëÖ´Ðзì϶£»Google OpenThread MeshCoP::Commissioner::GeneratePskc»º³åÇøÒç¶Âí½Å£»BMC Control-M/Agent OSºÅÁî×¢Èë·ì϶¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇSophos´¹Î£½¨¸´·À»ðǽÖеÄSQL×¢Èë0day£¬Òѱ»Ò°±íÀûÓã»ÍøÐŰìµÈ12¸ö²¿ÃŽáºÏ°ä²¼¡¶ÍøÂ簲ȫÉó²é·¨×Ó¡·£»Adobe°ä²¼´¹Î£²¹¶¡£¬½¨¸´Æä3¿î²úÆ·ÖеÄ35¸ö·ì϶£»CNNIC°ä²¼¡¶Öйú»¥ÁªÍøÂç·¢Õ¹Çé¿öͳ¼Æ»ã±¨¡·£»¹È¸è×êÑÐÈËÔ±Åû¶ƻ¹ûImage I/OµÄÁãµã»÷·ì϶¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖС£
>³ÁÒª°²È«·ì϶Áбí
1. SaltStack Salt salt-master process ClearFuncs²»ÕýȷУÑé²½ÖèŲÓ÷ì϶
SaltStack Salt salt-master process ClearFuncs²»ÕýȷУÑé²½ÖèŲÓã¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ɻñÈ¡Óû§ÁîÅÆ£¬Î´ÊÚȨ½Ó¼û²¢Ö´ÐкÅÁî¡£
https://docs.saltstack.com/en/latest/topics/releases/2019.2.4.html
2. Apache IoTDB 31999¶Ë¿ÚδÊÚȨ½Ó¼û·ì϶
Apache IoTDB JMX 31999¶Ë¿Ú´æÔÚδÊÚȨ·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉδÊÚȨ½Ó¼û²¢Ö´ÐÐËÁÒâ´úÂë¡£
https://lists.apache.org/thread.html/r3d2ff899ead64d2952fdc1fbb1f520ca42011ed2b4c7f786e921f6b9%40%3Cdev.iotdb.apache.org%3E
3. Adobe Bridge¶à¸öÔ½½çд´úÂëÖ´Ðзì϶
Adobe Bridge´¦ÖÃÎļþ´æÔÚÔ½½çд·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£
https://helpx.adobe.com/security/products/bridge/apsb20-19.html
4. Google OpenThread MeshCoP::Commissioner::GeneratePskc»º³åÇøÒç¶Âí½Å
Google OpenThread MeshCoP::Commissioner::GeneratePskc´æÔÚ»º³åÇøÒç¶Âí½Å£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=19386
5. BMC Control-M/Agent OSºÅÁî×¢Èë·ì϶
ʹÓÃTCPºÍ̸ʱBMC Control-M/Agent´æÔÚÊäÈëÑéÖ¤·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿É×¢ÈëËÁÒâOSºÅÁî¡£
https://herolab.usd.de/security-advisories/usd-2019-0064/
> ³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢Sophos´¹Î£½¨¸´·À»ðǽÖеÄSQL×¢Èë0day£¬Òѱ»Ò°±íÀûÓÃ
ÍøÂ簲ȫ¹«Ë¾SophosÓÚÖÜÁù°ä²¼ÁË´¹Î£²¹¶¡ÒÔ½¨¸´ÒѾ±»Ò°±íÀûÓõÄSQL×¢Èë0day£¬¸Ã·ì϶ӰÏìÁËÆäXG Firewall²úÆ·¡£4ÔÂ22ÈÕÍí£¬Sophos¹«Ë¾·¢ÏÖºÚ¿ÍÀûÓÃXG FirewallÖеÄSQL×¢Èë·ì϶ÇÔÈ¡Á˸ÃÉ豸ÖеÄÊý¾Ý£¬Ô̺¬·À»ðǽÉ豸ÖÎÀíÔ¹ØË»§¡¢·À»ðǽÃÅ»§ÍøÕ¾ÖÎÀíÔ¹ØË»§ºÍÔ¶³Ì½Ó¼ûÉ豸ÕË»§ÖеĵÄÓû§ÃûºÍ¹þÏ£ÃÜÂë¡£¸Ã¹«Ë¾°µÊ¾Õâ´Î¸üÐÂÒѾ½¨¸´Á˸ÃSQL×¢Èë·ì϶£¬²¢ÇÒмÓÁËÌØÊâÌáÐÑÖ°ÄÜʹ¿Í»§ÖªÂ·ÆäÉ豸ÊÇ·ñÊܵ½ÁËÍþв¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/hackers-are-exploiting-a-sophos-firewall-zero-day/
2¡¢ÍøÐŰìµÈ12¸ö²¿ÃŽáºÏ°ä²¼¡¶ÍøÂ簲ȫÉó²é·¨×Ó¡·
ÔÎÄÁ´½Ó£º
http://www.cac.gov.cn/2020-04/27/c_1589535450769077.htm
3¡¢Adobe°ä²¼´¹Î£²¹¶¡£¬½¨¸´Æä3¿î²úÆ·ÖеÄ35¸ö·ì϶
Èí¼þ¹«Ë¾AdobeÓÚ4ÔÂ28ÈÕ°ä²¼´¹Î£·ì϶²¹¶¡£¬×ܹ²½¨¸´ÁË35¸ö·ì϶£¬ÕâЩ·ì϶ӰÏìµÄ²úÆ·ÓÐAdobe Illustrator¡¢Adobe BridgeºÍµçÉÌÆ½Ì¨Magento¡£Õâ´Î°²È«¸üн¨¸´ÁËWindows°æ±¾Illustrator 2020ÖеÄ5¸ö´úÂëÖ´Ðзì϶£¬Adobe Bridge 10.0.1¼°¸üÔç°æ±¾ÖеÄ17¸ö·ì϶£¨14¸ö¿Éµ¼Ö´úÂëÖ´Ðзì϶£¬3¸öÓйØÐÅϢй¶ÎÊÌ⣩£¬Ã³Ò×°æ±¾ºÍ¿ªÔ´°æ±¾µÄMagento CMSÖеÄ13¸ö·ì϶¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2020/04/adobe-software-updates.html
4¡¢CNNIC°ä²¼¡¶Öйú»¥ÁªÍøÂç·¢Õ¹Çé¿öͳ¼Æ»ã±¨¡·
ÔÎÄÁ´½Ó£º
http://news.china.com.cn/txt/2020-04/28/content_75985166.htm
5¡¢¹È¸è×êÑÐÈËÔ±Åû¶ƻ¹ûImage I/OµÄÁãµã»÷·ì϶
¹È¸èµÄProject Zero ÍŶÓÓÚ±¾ÖܶþÅû¶ÁËApple²Ù×÷ϵͳÖÐÄÚÖõĿò¼ÜImage I/OÖеÄÁãµã»÷·ì϶£¬¸Ã¿ò¼Ü±»ÀûÓÃÓÚiOS¡¢macOS¡¢tvOSºÍwatchOSÖУ¬ÓÃÀ´´¦ÖÃͼÏñÔªÊý¾Ý¡£Project ZeroÍŶӰµÊ¾£¬ËûÃÇ·ÖÎöÁ˸ÿò¼ÜµÄÍÌÍ´¦Öùý³Ì£¬ÒÔ¹Û²ìËüÊÇÈôºÎ´¦ÖÃÌåʽÃýÎóµÄͼÏñÎļþ¡£Á˾Ö×êÑÐÈËÔ±·¢ÏÖÁË Image I/O ÖдæÔÚ6¸ö·ì϶£¬¶øÆ»¹ûÏòµÚÈý·½¹«¿ªµÄ¸ß¶¯Ì¬ÁìÓò£¨HDR£©Í¼ÏñÎļþÌåʽ¿ò¼ÜOpenEXRÖдæÔÚ8¸ö·ì϶¡£Ä¿Ç°£¬ËùÓзì϶¶¼ÒѾ±»½¨¸´¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/google-discloses-zero-click-bugs-impacting-several-apple-operating-systems/


¾©¹«Íø°²±¸11010802024551ºÅ