ÐÅÏ¢Çå¾²Öܱ¨-2020ÄêµÚ17ÖÜ
Ðû²¼Ê±¼ä 2020-04-28> ±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö
2020Äê04ÔÂ20ÈÕÖÁ26ÈÕ¹²ÊÕ¼Çå¾²Îó²î54¸ö£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇApple macOS Mail Javascript´úÂëÖ´ÐÐÎó²î; Google Chrome paymentsÄÚ´æ¹ýʧÒýÓôúÂëÖ´ÐÐÎó²î£»£»£»£»£»£»£»Sonatype Nexus Repository ManagerȨÏÞÌáÉýÎó²î£»£»£»£»£»£»£»Í¨´ïOAí§ÒâÓû§µÇ¼Îó²î£»£»£»£»£»£»£»Contiki-NGÔ½½çд´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊǼÓÄôó¶ùͯÓÎÏ·ÍøÕ¾Webkinz½ü2300ÍòÓû§Êý¾Ýй¶£»£»£»£»£»£»£»FPGAоƬStarbleedÎó²î£¬£¬£¬£¬Ó°ÏìÈüÁé˼¶à¸ö²úÆ·£»£»£»£»£»£»£»CNCERTÐû²¼¡¶2019ÄêÎÒ¹ú»¥ÁªÍøÍøÂçÇå¾²Ì¬ÊÆ×ÛÊö¡·±¨¸æ£»£»£»£»£»£»£»Ñо¿Ö°Ô±Åû¶IBMÆóÒµÇå¾²Èí¼þÖеÄ4¸ö0day£»£»£»£»£»£»£»Î¢ÈíÐû²¼½ôÆÈ¸üУ¬£¬£¬£¬ÐÞ¸´OfficeºÍPaint 3DÖжà¸öÎó²î¡£¡£¡£¡£
ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£
>Ö÷ÒªÇå¾²Îó²îÁбí
1. Apple macOS Mail Javascript´úÂëÖ´ÐÐÎó²î
Apple macOS Mail±£´æ´úÂë×¢ÈëÎó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§ÒâJavaScript´úÂë¡£¡£¡£¡£¡£¡£¡£¡£
https://support.apple.com/en-us/HT211100
2. Google Chrome paymentsÄÚ´æ¹ýʧÒýÓôúÂëÖ´ÐÐÎó²î
Google Chrome payments±£´æÊͷźóʹÓÃÎó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄWEBÇëÇ󣬣¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬¿É¾ÙÐоܾøÐ§À͹¥»÷»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§ÒâÂë¡£¡£¡£¡£
https://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop_21.html
3. Sonatype Nexus Repository ManagerȨÏÞÌáÉýÎó²î
Sonatype Nexus Repository ManagerʵÏÖ±£´æÇå¾²Îó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬¿ÉÌáÉýÌØÈ¨£¬£¬£¬£¬¾ÙÐн¨É裬£¬£¬£¬Ð޸쬣¬£¬£¬Ö´ÐÐʹÃü¡£¡£¡£¡£
https://support.sonatype.com/hc/en-us/articles/360046233714
4. ͨ´ïOAí§ÒâÓû§µÇ¼Îó²î
ͨ´ïOAµÇ¼ʵÏÖ±£´æÇå¾²Îó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬¿ÉÒÔí§ÒâÓû§ÉÏÏÂÎĵǼ¡£¡£¡£¡£
https://cert.360.cn/warning/detail?id=d2689a877c01a9712d148317c2da21a2
5. Contiki-NGÔ½½çд´úÂëÖ´ÐÐÎó²î
Contiki-NG os/net/ipv6/sicslowpan.cÔÚ´¦Öóͷ£6LoWPAN·ÖÆ¬ÖØ×é±£´æÔ½½çдÎó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»£»£»£»£»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£
https://github.com/contiki-ng/contiki-ng/pull/972
1¡¢¼ÓÄôó¶ùͯÓÎÏ·ÍøÕ¾Webkinz½ü2300ÍòÓû§Êý¾Ýй¶
¼ÓÄôóÖøÃûÍæ¾ß¹«Ë¾GanzÆìϵĶùͯÓÎÏ·ÍøÕ¾WebkinzÔâµ½ºÚ¿ÍÈëÇÖ£¬£¬£¬£¬½ü2300ÍòÍæ¼ÒµÄÓû§ÃûºÍÃÜÂëй¶£¬£¬£¬£¬ÆäÖÐй¶µÄÃÜÂëʹÓÃÁËMD5-CryptËã·¨¼ÓÃÜ¡£¡£¡£¡£¾ÝZDNet±¨µÀ£¬£¬£¬£¬ºÚ¿ÍÊÇʹÓÃÍøÕ¾ÖеÄSQL×¢ÈëÎó²îÈëÇÖÓÎÏ·Êý¾Ý¿âµÄ£¬£¬£¬£¬¾Ý³Æ¸ÃÎó²îµÄϸ½ÚÒÑÔÚºÚ¿ÍÂÛ̳ÖÐÈö²¥Á˼¸¸öÔ¡£¡£¡£¡£ºÚ¿Í¿ÉÄÜ»¹ÍµÈ¡Á˹þÏ£¼ÓÃܵĵç×ÓÓʼþµØµã¡£¡£¡£¡£ÐÂÎÅÈËÊ¿³ÆWebkinzÔ±¹¤ÒѾÐÞ¸´Á˺ڿÍʹÓõÄÎó²î£¬£¬£¬£¬µ«GanzÉÐδ¶Ô´ËÊÂÎñ¾ÙÐлØÓ¦¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/hacker-leaks-23-million-usernames-and-passwords-from-webkinz-childrens-game/
2¡¢FPGAоƬStarbleedÎó²î£¬£¬£¬£¬Ó°ÏìÈüÁé˼¶à¸ö²úÆ·
Ñо¿Ö°Ô±·¢Ã÷FPGAоƬ±£´æStarbleedÎó²î£¬£¬£¬£¬Ó°ÏìÁËÈüÁé˼7ϵÁеÄSpartan¡¢Artix¡¢Kintex¡¢Virtex×ÓϵÁжà¸ö²úÆ·¡£¡£¡£¡£ÓÉÓÚÎó²îΪӲ¼þ¼¶±ðÎó²î£¬£¬£¬£¬Òò¶øÖ»ÄÜͨ¹ýÌæ»»Ð¾Æ¬À´ÐÞ¸´Îó²î¡£¡£¡£¡£Çå¾²Ñо¿Ö°Ô±·¢Ã÷¿ÉÒÔͨ¹ý½âÃܱ»¼ÓÃܵıÈÌØÁ÷À´»á¼ûºÍÐÞ¸ÄÓÃÓÚ±à³ÌµÄÎļþ¡£¡£¡£¡£Òò´Ë£¬£¬£¬£¬ºÚ¿Í¿ÉÒÔʹÓøÃÎó²îÍêÈ«¿ØÖÆFPGAоƬ£¬£¬£¬£¬²¢ÇÒ¿ÉÄÜ͵ȡ±ÈÌØÁ÷ÖеÄ֪ʶ²úȨ¡£¡£¡£¡£µÂ¹úMax PlanckÑо¿ËùµÄChristof Paar½ÌÊÚÌåÏÖ£¬£¬£¬£¬¹¥»÷ÕßÉõÖÁ¿ÉÒÔ¾ÙÐÐÔ¶³Ì¹¥»÷£¬£¬£¬£¬»òÊÇÏòFPGAоƬֲÈëÓ²¼þľÂí¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.helpnetsecurity.com/2020/04/20/starbleed-vulnerability/
3¡¢CNCERTÐû²¼¡¶2019ÄêÎÒ¹ú»¥ÁªÍøÍøÂçÇå¾²Ì¬ÊÆ×ÛÊö¡·±¨¸æ
¹ú¼Ò»¥ÁªÍøÓ¦¼±ÖÐÐÄ£¨CNCERT£©ÓÚ2020Äê4ÔÂ20ÈÕÐû²¼ÁË¡¶2019ÄêÎÒ¹ú»¥ÁªÍøÍøÂçÇå¾²Ì¬ÊÆ×ÛÊö¡·±¨¸æ¡£¡£¡£¡£¸Ã±¨¸æ×¤×ãÓÚCNCERTÍøÂçÇå¾²ºê¹Û¼à²âÊý¾ÝÓëÊÂÇéʵ¼ù±¨¸æ£¬£¬£¬£¬Éæ¼°2019Äêµä·¶ÍøÂçÇå¾²ÊÂÎñ¡¢ÍøÂçÇå¾²ÐÂÇ÷ÊÆ¼°Ò»Ñùƽ³£ÍøÂçÇå¾²ÊÂÎñÓ¦¼±´¦Öóͷ£Êµ¼ùµÈÄÚÈÝ¡£¡£¡£¡£±¨¸æÖ÷Òª°üÀ¨Ëĸö²¿·Ö£¬£¬£¬£¬Ò»ÊÇ×ܽá2019ÄêÎÒ¹ú»¥ÁªÍøÍøÂçÇ徲״̬£¬£¬£¬£¬¶þÊÇÕ¹Íû2020ÄêÍøÂçÇå¾²ÈÈÃÅ£¬£¬£¬£¬ÈýÊÇÁ¬ÏµÍøÂçÇå¾²Ì¬ÊÆÆÊÎöÌá³ö¶Ô²ß½¨Ò飬£¬£¬£¬ËÄÊÇÊáÀíÍøÂçÇå¾²¼à²âÊý¾Ý¡£¡£¡£¡£¸Ã±¨¸æ¶ÔÎÒ¹úµ³Õþ»ú¹Ø¡¢ÐÐÒµÆóÒµ¼°È«Éç»áÏàʶÎÒ¹úÍøÂçÇå¾²ÐÎÊÆ£¬£¬£¬£¬Ìá¸ßÍøÂçÇå¾²Òâʶ£¬£¬£¬£¬×öºÃÍøÂçÇå¾²ÊÂÇéÌṩÁËÓÐÁ¦²Î¿¼¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
http://www.cac.gov.cn/2020-04/20/c_1588932297982643.htm
4¡¢Ñо¿Ö°Ô±Åû¶IBMÆóÒµÇå¾²Èí¼þÖеÄ4¸ö0day
Çå¾²Ñо¿Ö°Ô±ÔÚÆÊÎöIBM Data Risk Manager£¨IDRM£©Ê±·¢Ã÷ÁË4¸ö0day£¬£¬£¬£¬»®·ÖΪÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î¡¢ÏÂÁî×¢ÈëÎó²î¡¢²»Çå¾²µÄĬÈÏÃÜÂëÎó²îÒÔ¼°í§ÒâÎļþÏÂÔØÎó²î¡£¡£¡£¡£ÕâЩÎó²î¿ÉÒÔµ¥¶ÀʹÓÃÒ²¿ÉÒÔ×éºÏʹÓ㬣¬£¬£¬×éºÏʹÓÃǰÈý¸öÎó²î¿ÉÒÔʹ¹¥»÷ÕßÒÔrootȨÏÞÔ¶³ÌÖ´ÐдúÂ룬£¬£¬£¬×éºÏʹÓõÚÒ»¸öºÍµÚËĸöÎó²î¿ÉÒÔʹδÊÚȨµÄ¹¥»÷ÕßÏÂÔØí§ÒâÎļþ¡£¡£¡£¡£Îó²îµÄÅû¶ÕßRibeiroÌåÏÖ£¬£¬£¬£¬IDRMÊÇ´¦Öóͷ£Ãô¸ÐÐÅÏ¢µÄÆóÒµÇå¾²²úÆ·£¬£¬£¬£¬ÈôÊÇÆäÔâµ½¹¥»÷»áµ¼Ö¹«Ë¾ÀûÒæÑÏÖØÊÜË𣬣¬£¬£¬Òò´ËÔÚIBM¾Ü¾ø½ÓÊÜÎó²î±¨¸æºóÑ¡Ôñ½«ÆäÐû²¼³öÀ´¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬IBM¹«Ë¾ÐÞ¸´ÁËIDRM2.0.1¼°¸ü¸ß°æ±¾ÖеÄí§ÒâÎļþÏÂÔØÎó²îºÍÏÂÁî×¢ÈëÎó²î£¬£¬£¬£¬²¢ÇÒÕýÔÚÊÓ²ìÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/researcher-discloses-four-ibm-zero-days-after-refusal-to-fix/
5¡¢Î¢ÈíÐû²¼½ôÆÈ¸üУ¬£¬£¬£¬ÐÞ¸´OfficeºÍPaint 3DÖжà¸öÎó²î
MicrosoftÐû²¼Á˽ôÆÈÇå¾²¸üУ¬£¬£¬£¬ÒÔÐÞ¸´Ê¹ÓÃÁËAutodesk FBX¿âµÄMicrosoft²úÆ·£¬£¬£¬£¬°üÀ¨¶à¸ö°æ±¾µÄMicrosoft OfficeºÍWindows 10Ó¦ÓóÌÐòPaint 3D¡£¡£¡£¡£±¾´ÎÐÞ¸´µÄÎó²îΪFBX¿âÖеÄÔ¶³ÌÖ´ÐдúÂëÎó²î£¬£¬£¬£¬¹¥»÷ÕßʹÓôËÎó²î¿ÉÒÔ»ñµÃÓëÍâµØÓû§ÏàͬµÄȨÏÞ£¬£¬£¬£¬AutodeskÔÚ4ÔÂ15ÈÕÍÆ³öÁËÕë¶Ô´ËÎó²îµÄ²¹¶¡³ÌÐò¡£¡£¡£¡£MicrosoftÌåÏÖ£¬£¬£¬£¬ºÚ¿Í±ØÐèÓÕʹÓû§·¿ªÆäÌØÖÆµÄ3DÎļþ²Å¿ÉÒÔÀÖ³ÉʹÓôËÎó²î£¬£¬£¬£¬Òò´Ë£¬£¬£¬£¬ÔÚÇå¾²¸üÐÂ֮ǰÓû§ÐèÒªÔ¶ÀëÄÇЩ¿ÉÒÉÎļþÒÔ°ü¹ÜÇå¾²¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://news.softpedia.com/news/microsoft-releases-emergency-update-for-windows-10-app-microsoft-office-529800.shtml