ÐÅÏ¢Çå¾²Öܱ¨-2020ÄêµÚ18ÖÜ

Ðû²¼Ê±¼ä 2020-05-06

> ±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


2020Äê04ÔÂ27ÈÕÖÁ05ÔÂ03ÈÕ¹²ÊÕ¼Çå¾²Îó²î70¸ö£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇSaltStack Salt salt-master process ClearFuncs²»×¼È·Ð£ÑéÒªÁìŲÓÃÎó²î; Apache IoTDB 31999¶Ë¿ÚδÊÚȨ»á¼ûÎó²î£»£»£»£»£»£»Adobe Bridge¶à¸öÔ½½çд´úÂëÖ´ÐÐÎó²î£»£»£»£»£»£»Google OpenThread MeshCoP::Commissioner::GeneratePskc»º³åÇøÒç³öÎó²î£»£»£»£»£»£»BMC Control-M/Agent OSÏÂÁî×¢ÈëÎó²î¡£¡£ ¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇSophos½ôÆÈÐÞ¸´·À»ðǽÖеÄSQL×¢Èë0day£¬£¬£¬£¬Òѱ»Ò°ÍâʹÓ㻣»£»£»£»£»ÍøÐŰìµÈ12¸ö²¿·ÖÁªºÏÐû²¼¡¶ÍøÂçÇå¾²Éó²é²½·¥¡·£»£»£»£»£»£»AdobeÐû²¼½ôÆÈ²¹¶¡£¬£¬£¬£¬ÐÞ¸´Æä3¿î²úÆ·ÖеÄ35¸öÎó²î£»£»£»£»£»£»CNNICÐû²¼¡¶Öйú»¥ÁªÍøÂçÉú³¤×´Ì¬Í³¼Æ±¨¸æ¡·£»£»£»£»£»£»¹È¸èÑо¿Ö°Ô±Åû¶ƻ¹ûImage I/OµÄÁãµã»÷Îó²î¡£¡£ ¡£¡£


ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£ ¡£¡£


>Ö÷ÒªÇå¾²Îó²îÁбí


1. SaltStack Salt salt-master process ClearFuncs²»×¼È·Ð£ÑéÒªÁìŲÓÃÎó²î


SaltStack Salt salt-master process ClearFuncs²»×¼È·Ð£ÑéÒªÁìŲÓ㬣¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬¿É»ñÈ¡Óû§ÁîÅÆ£¬£¬£¬£¬Î´ÊÚȨ»á¼û²¢Ö´ÐÐÏÂÁî¡£¡£ ¡£¡£

https://docs.saltstack.com/en/latest/topics/releases/2019.2.4.html


2. Apache IoTDB 31999¶Ë¿ÚδÊÚȨ»á¼ûÎó²î


Apache IoTDB JMX 31999¶Ë¿Ú±£´æÎ´ÊÚȨÎó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬¿ÉδÊÚȨ»á¼û²¢Ö´ÐÐí§Òâ´úÂë¡£¡£ ¡£¡£

https://lists.apache.org/thread.html/r3d2ff899ead64d2952fdc1fbb1f520ca42011ed2b4c7f786e921f6b9%40%3Cdev.iotdb.apache.org%3E


3. Adobe Bridge¶à¸öÔ½½çд´úÂëÖ´ÐÐÎó²î


Adobe Bridge´¦Öóͷ£Îļþ±£´æÔ½½çдÎó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþÇëÇ󣬣¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»£»£»£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£ ¡£¡£

https://helpx.adobe.com/security/products/bridge/apsb20-19.html


4. Google OpenThread MeshCoP::Commissioner::GeneratePskc»º³åÇøÒç³öÎó²î


Google OpenThread MeshCoP::Commissioner::GeneratePskc±£´æ»º³åÇøÒç³öÎó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»£»£»£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£ ¡£¡£

https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=19386


5. BMC Control-M/Agent OSÏÂÁî×¢ÈëÎó²î


ʹÓÃTCPЭÒéʱBMC Control-M/Agent±£´æÊäÈëÑéÖ¤Îó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬¿É×¢Èëí§ÒâOSÏÂÁî¡£¡£ ¡£¡£

https://herolab.usd.de/security-advisories/usd-2019-0064/


> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢Sophos½ôÆÈÐÞ¸´·À»ðǽÖеÄSQL×¢Èë0day£¬£¬£¬£¬Òѱ»Ò°ÍâʹÓÃ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ÍøÂçÇå¾²¹«Ë¾SophosÓÚÖÜÁùÐû²¼Á˽ôÆÈ²¹¶¡ÒÔÐÞ¸´ÒѾ­±»Ò°ÍâʹÓõÄSQL×¢Èë0day£¬£¬£¬£¬¸ÃÎó²îÓ°ÏìÁËÆäXG Firewall²úÆ·¡£¡£ ¡£¡£4ÔÂ22ÈÕÍí£¬£¬£¬£¬Sophos¹«Ë¾·¢Ã÷ºÚ¿ÍʹÓÃXG FirewallÖеÄSQL×¢ÈëÎó²îÇÔÈ¡Á˸Ã×°±¸ÖеÄÊý¾Ý£¬£¬£¬£¬°üÀ¨·À»ðǽװ±¸ÖÎÀíÔ±ÕË»§¡¢·À»ðǽÃÅ»§ÍøÕ¾ÖÎÀíÔ±ÕË»§ºÍÔ¶³Ì»á¼û×°±¸ÕË»§ÖеĵÄÓû§ÃûºÍ¹þÏ£ÃÜÂë¡£¡£ ¡£¡£¸Ã¹«Ë¾ÌåÏִ˴θüÐÂÒѾ­ÐÞ¸´Á˸ÃSQL×¢ÈëÎó²î£¬£¬£¬£¬²¢ÇÒмÓÁËÌØÊâÌáÐѹ¦Ð§Ê¹¿Í»§ÖªµÀÆä×°±¸ÊÇ·ñÊܵ½ÁËÍþв¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/hackers-are-exploiting-a-sophos-firewall-zero-day/


2¡¢ÍøÐŰìµÈ12¸ö²¿·ÖÁªºÏÐû²¼¡¶ÍøÂçÇå¾²Éó²é²½·¥¡·


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Ô­ÎÄÁ´½Ó£º

http://www.cac.gov.cn/2020-04/27/c_1589535450769077.htm


3¡¢AdobeÐû²¼½ôÆÈ²¹¶¡£¬£¬£¬£¬ÐÞ¸´Æä3¿î²úÆ·ÖеÄ35¸öÎó²î


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Èí¼þ¹«Ë¾AdobeÓÚ4ÔÂ28ÈÕÐû²¼½ôÆÈÎó²î²¹¶¡£¬£¬£¬£¬×ܹ²ÐÞ¸´ÁË35¸öÎó²î£¬£¬£¬£¬ÕâЩÎó²îÓ°ÏìµÄ²úÆ·ÓÐAdobe Illustrator¡¢Adobe BridgeºÍµçÉÌÆ½Ì¨Magento¡£¡£ ¡£¡£´Ë´ÎÇå¾²¸üÐÂÐÞ¸´ÁËWindows°æ±¾Illustrator 2020ÖеÄ5¸ö´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬Adobe Bridge 10.0.1¼°¸üÔç°æ±¾ÖеÄ17¸öÎó²î£¨14¸ö¿Éµ¼Ö´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬3¸öÓйØÐÅϢй¶ÎÊÌ⣩£¬£¬£¬£¬ÉÌÒµ°æ±¾ºÍ¿ªÔ´°æ±¾µÄMagento CMSÖеÄ13¸öÎó²î¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2020/04/adobe-software-updates.html


4¡¢CNNICÐû²¼¡¶Öйú»¥ÁªÍøÂçÉú³¤×´Ì¬Í³¼Æ±¨¸æ¡·


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Ô­ÎÄÁ´½Ó£º

http://news.china.com.cn/txt/2020-04/28/content_75985166.htm


5¡¢¹È¸èÑо¿Ö°Ô±Åû¶ƻ¹ûImage I/OµÄÁãµã»÷Îó²î


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


¹È¸èµÄProject Zero ÍŶÓÓÚ±¾ÖܶþÅû¶ÁËApple²Ù×÷ϵͳÖÐÄÚÖõĿò¼ÜImage I/OÖеÄÁãµã»÷Îó²î£¬£¬£¬£¬¸Ã¿ò¼Ü±»Ó¦ÓÃÓÚiOS¡¢macOS¡¢tvOSºÍwatchOSÖУ¬£¬£¬£¬ÓÃÀ´´¦Öóͷ£Í¼ÏñÔªÊý¾Ý¡£¡£ ¡£¡£Project ZeroÍŶÓÌåÏÖ£¬£¬£¬£¬ËûÃÇÆÊÎöÁ˸ÿò¼ÜµÄÄ£ºý´¦Öóͷ£Àú³Ì£¬£¬£¬£¬ÒÔÊÓ²ìËüÊÇÈçÄÇÀïÖÃÃûÌùýʧµÄͼÏñÎļþ¡£¡£ ¡£¡£Ð§¹ûÑо¿Ö°Ô±·¢Ã÷ÁË Image I/O Öб£´æ6¸öÎó²î£¬£¬£¬£¬¶øÆ»¹ûÏòµÚÈý·½¹ûÕæµÄ¸ß¶¯Ì¬¹æÄ££¨HDR£©Í¼ÏñÎļþÃûÌÿò¼ÜOpenEXRÖб£´æ8¸öÎó²î¡£¡£ ¡£¡£ÏÖÔÚ£¬£¬£¬£¬ËùÓÐÎó²î¶¼ÒѾ­±»ÐÞ¸´¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/google-discloses-zero-click-bugs-impacting-several-apple-operating-systems/