Aspose API¶à¸öRCE 0dayÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-08-23

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-5032 £¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ £¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8 £¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-5033 £¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ £¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8 £¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-5041 £¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ £¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8 £¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


Aspose Aspose.Cells 19.1.0

Aspose Aspose.Words 18.11.0.0


Îó²î¸ÅÊö


Çå¾²Ñо¿Ô±ÔÚ¶à¸öAspose APIÖз¢Ã÷¶à¸öÎó²î £¬£¬£¬£¬£¬¿Éµ¼ÖÂÔ¶³Ì¹¥»÷ÕßÔÚÊÜÓ°Ïì»úеÉÏÖ´ÐдúÂë¡£¡£¡£¡£¡£


AsposeÌṩµÄAPIÖ¼ÔÚ×ÊÖúʹÓò¢×ª»»´ó×ÚÎĵµÃûÌᣡ£¡£¡£¡£ÕâЩÇ徲ȱÏÝÓ°Ïì×ÊÖú´¦Öóͷ£PDF¡¢Î¢ÈíWordµÈ¶àÖÖÎļþÀàÐ͵ÄAPI¡£¡£¡£¡£¡£


ҪʹÓÃÕâЩÎó²î £¬£¬£¬£¬£¬¹¥»÷ÕßÐèÒªÏòÄ¿µÄÓû§·¢ËÍÌØÊâ½á¹¹µÄÎļþ £¬£¬£¬£¬£¬Ö®ºóÓÕÆ­ËûÃÇÔÚʹÓÃÏìÓ¦API֮ʱ·­¿ª¸ÃÎļþ¡£¡£¡£¡£¡£Îó²î¸ÅÊöÈçÏ£º


CVE-2019-5032

ËüÊÇ¿ÉʹÓõĴøÍâ¶ÁÈ¡Îó²î £¬£¬£¬£¬£¬±£´æÓÚAspose.Cells 19.1.0 °æ±¾µÄ LabelSst ¼Í¼ÆÊÎöÆ÷ÖС£¡£¡£¡£¡£Apose. Cells ¿âÓÃÓÚ´ó×ÚÆóÒµ¡¢ÒøÐкÍÕþ¸®×éÖ¯»ú¹¹ÖÐ £¬£¬£¬£¬£¬ÓÃ×÷Êý¾Ý´¦Öóͷ£ºÍת»»µÄÈí¼þ²úÆ·¡£¡£¡£¡£¡£¸ÃÎó²î±£´æÓÚÈÏÕæ´¦Öóͷ£ LabelSst ¼Í¼µÄº¯ÊýÖÐ £¬£¬£¬£¬£¬¿Éµ¼Ö¹¥»÷ÕßʹÓÃÌØÊâ½á¹¹µÄ XLS ÎļþÓ¡·¢´øÍâ¶ÁÈ¡ £¬£¬£¬£¬£¬´Ó¶øµ¼Ö¹¥»÷ÕßÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£¡£


CVE-2019-5033

ËüÊDZ£´æÓÚAspose.Cells 19.1.0 ¿âÖÐ Number ¼Í¼ÆÊÎöÆ÷ÖеÄÒ»¸ö´øÍâ¶ÁÈ¡ÎÊÌâ¡£¡£¡£¡£¡£ºÍCVE-2019-5032 ÀàËÆ £¬£¬£¬£¬£¬ÈôÊÇÔ¶³Ì¹¥»÷ÕßÏòÊܺ¦Õß·¢ËÍ»ûÐÎ XLS Îļþ £¬£¬£¬£¬£¬Ôò¿Éµ¼Ö´úÂëÖ´ÐÐЧ¹û¡£¡£¡£¡£¡£


CVE-2019-5041

ËüÊDZ£´æÓÚAspose.Words ¿â°æ±¾18.11.0.0 ÖÐ FnumMetaInfo º¯ÊýÖеÄÒ»¸ö»ùÓÚÕ»µÄ»º³åÇøÒç³öÎó²î¡£¡£¡£¡£¡£Aspose.Words ¿âÓÃÓÚºÍ DOC(X) ÎļþÏà¹ØµÄ¶àÖÖ²Ù×÷ÖС£¡£¡£¡£¡£ËüºÍ Aspose.Cells Ò»Ñù £¬£¬£¬£¬£¬Ó¦ÓÃÓÚÐí¶à¹«Ë¾¡¢ÒøÐкÍÕþ¸®×éÖ¯»ú¹¹ÖÐ £¬£¬£¬£¬£¬×÷ΪÊý¾Ý´¦Öóͷ£/ת»»Èí¼þ²úÆ·µÄÒ»²¿·Ö¡£¡£¡£¡£¡£¸ÃÎó²î±£´æÓÚÈÏÕæ´¦Öóͷ£ÎĵµÔªÊý¾ÝµÄº¯ÊýÖС£¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓÃÌØÊâ½á¹¹µÄ DOC Îļþ´¥·¢¸ÃÎó²î²¢ÊµÏÖÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌÔÝδÐû²¼ÐÞ¸´²½·¥½â¾ö´ËÇå¾²ÎÊÌâ £¬£¬£¬£¬£¬½¨ÒéʹÓôËÈí¼þµÄÓû§ËæÊ±¹Ø×¢³§ÉÌÖ÷Ò³»ò²Î¿¼ÍøÖ·ÒÔ»ñÈ¡½â¾ö²½·¥£ºhttps://www.aspose.com¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0805