ÐÅÏ¢Çå¾²Öܱ¨-2020ÄêµÚ18ÖÜ

Ðû²¼Ê±¼ä 2020-05-06

> ±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


2020Äê04ÔÂ27ÈÕÖÁ05ÔÂ03ÈÕ¹²ÊÕ¼Çå¾²Îó²î70¸ö£¬ £¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇSaltStack Salt salt-master process ClearFuncs²»×¼È·Ð£ÑéÒªÁìŲÓÃÎó²î; Apache IoTDB 31999¶Ë¿ÚδÊÚȨ»á¼ûÎó²î£»£»£»£»£»£»£»Adobe Bridge¶à¸öÔ½½çд´úÂëÖ´ÐÐÎó²î£»£»£»£»£»£»£»Google OpenThread MeshCoP::Commissioner::GeneratePskc»º³åÇøÒç³öÎó²î£»£»£»£»£»£»£»BMC Control-M/Agent OSÏÂÁî×¢ÈëÎó²î¡£¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇSophos½ôÆÈÐÞ¸´·À»ðǽÖеÄSQL×¢Èë0day£¬ £¬£¬£¬£¬Òѱ»Ò°ÍâʹÓ㻣»£»£»£»£»£»ÍøÐŰìµÈ12¸ö²¿·ÖÁªºÏÐû²¼¡¶ÍøÂçÇå¾²Éó²é²½·¥¡·£»£»£»£»£»£»£»AdobeÐû²¼½ôÆÈ²¹¶¡£¬ £¬£¬£¬£¬ÐÞ¸´Æä3¿î²úÆ·ÖеÄ35¸öÎó²î£»£»£»£»£»£»£»CNNICÐû²¼¡¶Öйú»¥ÁªÍøÂçÉú³¤×´Ì¬Í³¼Æ±¨¸æ¡·£»£»£»£»£»£»£»¹È¸èÑо¿Ö°Ô±Åû¶ƻ¹ûImage I/OµÄÁãµã»÷Îó²î¡£¡£¡£¡£¡£


ƾ֤ÒÔÉÏ×ÛÊö£¬ £¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£¡£


>Ö÷ÒªÇå¾²Îó²îÁбí


1. SaltStack Salt salt-master process ClearFuncs²»×¼È·Ð£ÑéÒªÁìŲÓÃÎó²î


SaltStack Salt salt-master process ClearFuncs²»×¼È·Ð£ÑéÒªÁìŲÓ㬠£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó£¬ £¬£¬£¬£¬¿É»ñÈ¡Óû§ÁîÅÆ£¬ £¬£¬£¬£¬Î´ÊÚȨ»á¼û²¢Ö´ÐÐÏÂÁî¡£¡£¡£¡£¡£

https://docs.saltstack.com/en/latest/topics/releases/2019.2.4.html


2. Apache IoTDB 31999¶Ë¿ÚδÊÚȨ»á¼ûÎó²î


Apache IoTDB JMX 31999¶Ë¿Ú±£´æÎ´ÊÚȨÎó²î£¬ £¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó£¬ £¬£¬£¬£¬¿ÉδÊÚȨ»á¼û²¢Ö´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£

https://lists.apache.org/thread.html/r3d2ff899ead64d2952fdc1fbb1f520ca42011ed2b4c7f786e921f6b9%40%3Cdev.iotdb.apache.org%3E


3. Adobe Bridge¶à¸öÔ½½çд´úÂëÖ´ÐÐÎó²î


Adobe Bridge´¦Öóͷ£Îļþ±£´æÔ½½çдÎó²î£¬ £¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþÇëÇó£¬ £¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬ £¬£¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»£»£»£»£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£

https://helpx.adobe.com/security/products/bridge/apsb20-19.html


4. Google OpenThread MeshCoP::Commissioner::GeneratePskc»º³åÇøÒç³öÎó²î


Google OpenThread MeshCoP::Commissioner::GeneratePskc±£´æ»º³åÇøÒç³öÎó²î£¬ £¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó£¬ £¬£¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»£»£»£»£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£

https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=19386


5. BMC Control-M/Agent OSÏÂÁî×¢ÈëÎó²î


ʹÓÃTCPЭÒéʱBMC Control-M/Agent±£´æÊäÈëÑéÖ¤Îó²î£¬ £¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó£¬ £¬£¬£¬£¬¿É×¢Èëí§ÒâOSÏÂÁî¡£¡£¡£¡£¡£

https://herolab.usd.de/security-advisories/usd-2019-0064/


> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢Sophos½ôÆÈÐÞ¸´·À»ðǽÖеÄSQL×¢Èë0day£¬ £¬£¬£¬£¬Òѱ»Ò°ÍâʹÓÃ


¿­Ê±K66¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÍøÂçÇå¾²¹«Ë¾SophosÓÚÖÜÁùÐû²¼Á˽ôÆÈ²¹¶¡ÒÔÐÞ¸´ÒѾ­±»Ò°ÍâʹÓõÄSQL×¢Èë0day£¬ £¬£¬£¬£¬¸ÃÎó²îÓ°ÏìÁËÆäXG Firewall²úÆ·¡£¡£¡£¡£¡£4ÔÂ22ÈÕÍí£¬ £¬£¬£¬£¬Sophos¹«Ë¾·¢Ã÷ºÚ¿ÍʹÓÃXG FirewallÖеÄSQL×¢ÈëÎó²îÇÔÈ¡Á˸Ã×°±¸ÖеÄÊý¾Ý£¬ £¬£¬£¬£¬°üÀ¨·À»ðǽװ±¸ÖÎÀíÔ±ÕË»§¡¢·À»ðǽÃÅ»§ÍøÕ¾ÖÎÀíÔ±ÕË»§ºÍÔ¶³Ì»á¼û×°±¸ÕË»§ÖеĵÄÓû§ÃûºÍ¹þÏ£ÃÜÂë¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÌåÏִ˴θüÐÂÒѾ­ÐÞ¸´Á˸ÃSQL×¢ÈëÎó²î£¬ £¬£¬£¬£¬²¢ÇÒмÓÁËÌØÊâÌáÐѹ¦Ð§Ê¹¿Í»§ÖªµÀÆä×°±¸ÊÇ·ñÊܵ½ÁËÍþв¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/hackers-are-exploiting-a-sophos-firewall-zero-day/


2¡¢ÍøÐŰìµÈ12¸ö²¿·ÖÁªºÏÐû²¼¡¶ÍøÂçÇå¾²Éó²é²½·¥¡·


¿­Ê±K66¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ô­ÎÄÁ´½Ó£º

http://www.cac.gov.cn/2020-04/27/c_1589535450769077.htm


3¡¢AdobeÐû²¼½ôÆÈ²¹¶¡£¬ £¬£¬£¬£¬ÐÞ¸´Æä3¿î²úÆ·ÖеÄ35¸öÎó²î


¿­Ê±K66¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Èí¼þ¹«Ë¾AdobeÓÚ4ÔÂ28ÈÕÐû²¼½ôÆÈÎó²î²¹¶¡£¬ £¬£¬£¬£¬×ܹ²ÐÞ¸´ÁË35¸öÎó²î£¬ £¬£¬£¬£¬ÕâЩÎó²îÓ°ÏìµÄ²úÆ·ÓÐAdobe Illustrator¡¢Adobe BridgeºÍµçÉÌÆ½Ì¨Magento¡£¡£¡£¡£¡£´Ë´ÎÇå¾²¸üÐÂÐÞ¸´ÁËWindows°æ±¾Illustrator 2020ÖеÄ5¸ö´úÂëÖ´ÐÐÎó²î£¬ £¬£¬£¬£¬Adobe Bridge 10.0.1¼°¸üÔç°æ±¾ÖеÄ17¸öÎó²î£¨14¸ö¿Éµ¼Ö´úÂëÖ´ÐÐÎó²î£¬ £¬£¬£¬£¬3¸öÓйØÐÅϢй¶ÎÊÌ⣩£¬ £¬£¬£¬£¬ÉÌÒµ°æ±¾ºÍ¿ªÔ´°æ±¾µÄMagento CMSÖеÄ13¸öÎó²î¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2020/04/adobe-software-updates.html


4¡¢CNNICÐû²¼¡¶Öйú»¥ÁªÍøÂçÉú³¤×´Ì¬Í³¼Æ±¨¸æ¡·


¿­Ê±K66¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ô­ÎÄÁ´½Ó£º

http://news.china.com.cn/txt/2020-04/28/content_75985166.htm


5¡¢¹È¸èÑо¿Ö°Ô±Åû¶ƻ¹ûImage I/OµÄÁãµã»÷Îó²î


¿­Ê±K66¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¹È¸èµÄProject Zero ÍŶÓÓÚ±¾ÖܶþÅû¶ÁËApple²Ù×÷ϵͳÖÐÄÚÖõĿò¼ÜImage I/OÖеÄÁãµã»÷Îó²î£¬ £¬£¬£¬£¬¸Ã¿ò¼Ü±»Ó¦ÓÃÓÚiOS¡¢macOS¡¢tvOSºÍwatchOSÖУ¬ £¬£¬£¬£¬ÓÃÀ´´¦Öóͷ£Í¼ÏñÔªÊý¾Ý¡£¡£¡£¡£¡£Project ZeroÍŶÓÌåÏÖ£¬ £¬£¬£¬£¬ËûÃÇÆÊÎöÁ˸ÿò¼ÜµÄÄ£ºý´¦Öóͷ£Àú³Ì£¬ £¬£¬£¬£¬ÒÔÊÓ²ìËüÊÇÈçÄÇÀïÖÃÃûÌùýʧµÄͼÏñÎļþ¡£¡£¡£¡£¡£Ð§¹ûÑо¿Ö°Ô±·¢Ã÷ÁË Image I/O Öб£´æ6¸öÎó²î£¬ £¬£¬£¬£¬¶øÆ»¹ûÏòµÚÈý·½¹ûÕæµÄ¸ß¶¯Ì¬¹æÄ££¨HDR£©Í¼ÏñÎļþÃûÌÿò¼ÜOpenEXRÖб£´æ8¸öÎó²î¡£¡£¡£¡£¡£ÏÖÔÚ£¬ £¬£¬£¬£¬ËùÓÐÎó²î¶¼ÒѾ­±»ÐÞ¸´¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/google-discloses-zero-click-bugs-impacting-several-apple-operating-systems/