ÐÅÏ¢Çå¾²Öܱ¨-2020ÄêµÚ18ÖÜ
Ðû²¼Ê±¼ä 2020-05-06> ±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö
2020Äê04ÔÂ27ÈÕÖÁ05ÔÂ03ÈÕ¹²ÊÕ¼Çå¾²Îó²î70¸ö£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇSaltStack Salt salt-master process ClearFuncs²»×¼È·Ð£ÑéÒªÁìŲÓÃÎó²î; Apache IoTDB 31999¶Ë¿ÚδÊÚȨ»á¼ûÎó²î£»£»£»£»£»£»Adobe Bridge¶à¸öÔ½½çд´úÂëÖ´ÐÐÎó²î£»£»£»£»£»£»Google OpenThread MeshCoP::Commissioner::GeneratePskc»º³åÇøÒç³öÎó²î£»£»£»£»£»£»BMC Control-M/Agent OSÏÂÁî×¢ÈëÎó²î¡£¡£¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇSophos½ôÆÈÐÞ¸´·À»ðǽÖеÄSQL×¢Èë0day£¬£¬£¬£¬Òѱ»Ò°ÍâʹÓ㻣»£»£»£»£»ÍøÐŰìµÈ12¸ö²¿·ÖÁªºÏÐû²¼¡¶ÍøÂçÇå¾²Éó²é²½·¥¡·£»£»£»£»£»£»AdobeÐû²¼½ôÆÈ²¹¶¡£¬£¬£¬£¬ÐÞ¸´Æä3¿î²úÆ·ÖеÄ35¸öÎó²î£»£»£»£»£»£»CNNICÐû²¼¡¶Öйú»¥ÁªÍøÂçÉú³¤×´Ì¬Í³¼Æ±¨¸æ¡·£»£»£»£»£»£»¹È¸èÑо¿Ö°Ô±Åû¶ƻ¹ûImage I/OµÄÁãµã»÷Îó²î¡£¡£¡£¡£
ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£
>Ö÷ÒªÇå¾²Îó²îÁбí
1. SaltStack Salt salt-master process ClearFuncs²»×¼È·Ð£ÑéÒªÁìŲÓÃÎó²î
SaltStack Salt salt-master process ClearFuncs²»×¼È·Ð£ÑéÒªÁìŲÓ㬣¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬¿É»ñÈ¡Óû§ÁîÅÆ£¬£¬£¬£¬Î´ÊÚȨ»á¼û²¢Ö´ÐÐÏÂÁî¡£¡£¡£¡£
https://docs.saltstack.com/en/latest/topics/releases/2019.2.4.html
2. Apache IoTDB 31999¶Ë¿ÚδÊÚȨ»á¼ûÎó²î
Apache IoTDB JMX 31999¶Ë¿Ú±£´æÎ´ÊÚȨÎó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬¿ÉδÊÚȨ»á¼û²¢Ö´ÐÐí§Òâ´úÂë¡£¡£¡£¡£
https://lists.apache.org/thread.html/r3d2ff899ead64d2952fdc1fbb1f520ca42011ed2b4c7f786e921f6b9%40%3Cdev.iotdb.apache.org%3E
3. Adobe Bridge¶à¸öÔ½½çд´úÂëÖ´ÐÐÎó²î
Adobe Bridge´¦Öóͷ£Îļþ±£´æÔ½½çдÎó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþÇëÇ󣬣¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»£»£»£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£
https://helpx.adobe.com/security/products/bridge/apsb20-19.html
4. Google OpenThread MeshCoP::Commissioner::GeneratePskc»º³åÇøÒç³öÎó²î
Google OpenThread MeshCoP::Commissioner::GeneratePskc±£´æ»º³åÇøÒç³öÎó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»£»£»£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=19386
5. BMC Control-M/Agent OSÏÂÁî×¢ÈëÎó²î
ʹÓÃTCPÐÒéʱBMC Control-M/Agent±£´æÊäÈëÑéÖ¤Îó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬¿É×¢Èëí§ÒâOSÏÂÁî¡£¡£¡£¡£
https://herolab.usd.de/security-advisories/usd-2019-0064/
> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö
1¡¢Sophos½ôÆÈÐÞ¸´·À»ðǽÖеÄSQL×¢Èë0day£¬£¬£¬£¬Òѱ»Ò°ÍâʹÓÃ
ÍøÂçÇå¾²¹«Ë¾SophosÓÚÖÜÁùÐû²¼Á˽ôÆÈ²¹¶¡ÒÔÐÞ¸´ÒѾ±»Ò°ÍâʹÓõÄSQL×¢Èë0day£¬£¬£¬£¬¸ÃÎó²îÓ°ÏìÁËÆäXG Firewall²úÆ·¡£¡£¡£¡£4ÔÂ22ÈÕÍí£¬£¬£¬£¬Sophos¹«Ë¾·¢Ã÷ºÚ¿ÍʹÓÃXG FirewallÖеÄSQL×¢ÈëÎó²îÇÔÈ¡Á˸Ã×°±¸ÖеÄÊý¾Ý£¬£¬£¬£¬°üÀ¨·À»ðǽװ±¸ÖÎÀíÔ±ÕË»§¡¢·À»ðǽÃÅ»§ÍøÕ¾ÖÎÀíÔ±ÕË»§ºÍÔ¶³Ì»á¼û×°±¸ÕË»§ÖеĵÄÓû§ÃûºÍ¹þÏ£ÃÜÂë¡£¡£¡£¡£¸Ã¹«Ë¾ÌåÏִ˴θüÐÂÒѾÐÞ¸´Á˸ÃSQL×¢ÈëÎó²î£¬£¬£¬£¬²¢ÇÒмÓÁËÌØÊâÌáÐѹ¦Ð§Ê¹¿Í»§ÖªµÀÆä×°±¸ÊÇ·ñÊܵ½ÁËÍþв¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/hackers-are-exploiting-a-sophos-firewall-zero-day/
2¡¢ÍøÐŰìµÈ12¸ö²¿·ÖÁªºÏÐû²¼¡¶ÍøÂçÇå¾²Éó²é²½·¥¡·
ÔÎÄÁ´½Ó£º
http://www.cac.gov.cn/2020-04/27/c_1589535450769077.htm
3¡¢AdobeÐû²¼½ôÆÈ²¹¶¡£¬£¬£¬£¬ÐÞ¸´Æä3¿î²úÆ·ÖеÄ35¸öÎó²î
Èí¼þ¹«Ë¾AdobeÓÚ4ÔÂ28ÈÕÐû²¼½ôÆÈÎó²î²¹¶¡£¬£¬£¬£¬×ܹ²ÐÞ¸´ÁË35¸öÎó²î£¬£¬£¬£¬ÕâЩÎó²îÓ°ÏìµÄ²úÆ·ÓÐAdobe Illustrator¡¢Adobe BridgeºÍµçÉÌÆ½Ì¨Magento¡£¡£¡£¡£´Ë´ÎÇå¾²¸üÐÂÐÞ¸´ÁËWindows°æ±¾Illustrator 2020ÖеÄ5¸ö´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬Adobe Bridge 10.0.1¼°¸üÔç°æ±¾ÖеÄ17¸öÎó²î£¨14¸ö¿Éµ¼Ö´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬3¸öÓйØÐÅϢй¶ÎÊÌ⣩£¬£¬£¬£¬ÉÌÒµ°æ±¾ºÍ¿ªÔ´°æ±¾µÄMagento CMSÖеÄ13¸öÎó²î¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2020/04/adobe-software-updates.html
4¡¢CNNICÐû²¼¡¶Öйú»¥ÁªÍøÂçÉú³¤×´Ì¬Í³¼Æ±¨¸æ¡·
ÔÎÄÁ´½Ó£º
http://news.china.com.cn/txt/2020-04/28/content_75985166.htm
5¡¢¹È¸èÑо¿Ö°Ô±Åû¶ƻ¹ûImage I/OµÄÁãµã»÷Îó²î
¹È¸èµÄProject Zero ÍŶÓÓÚ±¾ÖܶþÅû¶ÁËApple²Ù×÷ϵͳÖÐÄÚÖõĿò¼ÜImage I/OÖеÄÁãµã»÷Îó²î£¬£¬£¬£¬¸Ã¿ò¼Ü±»Ó¦ÓÃÓÚiOS¡¢macOS¡¢tvOSºÍwatchOSÖУ¬£¬£¬£¬ÓÃÀ´´¦Öóͷ£Í¼ÏñÔªÊý¾Ý¡£¡£¡£¡£Project ZeroÍŶÓÌåÏÖ£¬£¬£¬£¬ËûÃÇÆÊÎöÁ˸ÿò¼ÜµÄÄ£ºý´¦Öóͷ£Àú³Ì£¬£¬£¬£¬ÒÔÊÓ²ìËüÊÇÈçÄÇÀïÖÃÃûÌùýʧµÄͼÏñÎļþ¡£¡£¡£¡£Ð§¹ûÑо¿Ö°Ô±·¢Ã÷ÁË Image I/O Öб£´æ6¸öÎó²î£¬£¬£¬£¬¶øÆ»¹ûÏòµÚÈý·½¹ûÕæµÄ¸ß¶¯Ì¬¹æÄ££¨HDR£©Í¼ÏñÎļþÃûÌÿò¼ÜOpenEXRÖб£´æ8¸öÎó²î¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬ËùÓÐÎó²î¶¼ÒѾ±»ÐÞ¸´¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/google-discloses-zero-click-bugs-impacting-several-apple-operating-systems/