ÐÅÏ¢°²È«Öܱ¨-2020ÄêµÚ17ÖÜ
°ä²¼¹¦·ò 2020-04-28> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
2020Äê04ÔÂ20ÈÕÖÁ26ÈÕ¹²ÊÕ¼°²È«·ì϶54¸ö£¬£¬£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇApple macOS Mail Javascript´úÂëÖ´Ðзì϶; Google Chrome paymentsÄÚ´æÃýÎóÒýÓôúÂëÖ´Ðзì϶£»£»£»£»£»£»Sonatype Nexus Repository ManagerȨÏÞÌáÉý·ì϶£»£»£»£»£»£»ÁéͨOAËÁÒâÓû§µÇ¼·ì϶£»£»£»£»£»£»Contiki-NGÔ½½çд´úÂëÖ´Ðзì϶¡£¡£¡£¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊǼÓÄôó¶ùͯÓÎÏ·ÍøÕ¾Webkinz½ü2300ÍòÓû§Êý¾Ýй¶£»£»£»£»£»£»FPGAоƬStarbleed·ì϶£¬£¬£¬£¬£¬£¬£¬£¬Ó°ÏìÈüÁé˼¶à¸ö²úÆ·£»£»£»£»£»£»CNCERT°ä²¼¡¶2019ÄêÎÒ¹ú»¥ÁªÍøÍøÂç°²È«Ì¬ÊÆ×ÛÊö¡·»ã±¨£»£»£»£»£»£»×êÑÐÈËÔ±Åû¶IBMÆóÒµ°²È«Èí¼þÖеÄ4¸ö0day£»£»£»£»£»£»Î¢Èí°ä²¼´¹Î£¸üУ¬£¬£¬£¬£¬£¬£¬£¬½¨¸´OfficeºÍPaint 3DÖжà¸ö·ì϶¡£¡£¡£¡£¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖС£¡£¡£¡£¡£
>³ÁÒª°²È«·ì϶Áбí
1. Apple macOS Mail Javascript´úÂëÖ´Ðзì϶
Apple macOS Mail´æÔÚ´úÂë×¢Èë·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâJavaScript´úÂë¡£¡£¡£¡£¡£¡£¡£¡£¡£¡£
https://support.apple.com/en-us/HT211100
2. Google Chrome paymentsÄÚ´æÃýÎóÒýÓôúÂëÖ´Ðзì϶
Google Chrome payments´æÔÚ¿ªÊͺóʹÓ÷ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄWEBÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬£¬£¬£¬£¬£¬¿É½øÐлؾø·þÎñ¹¥»÷»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâÂë¡£¡£¡£¡£¡£
https://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop_21.html
3. Sonatype Nexus Repository ManagerȨÏÞÌáÉý·ì϶
Sonatype Nexus Repository ManagerʵÏÖ´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬¿ÉÌáÉýÌØÈ¨£¬£¬£¬£¬£¬£¬£¬£¬½øÐд´½¨£¬£¬£¬£¬£¬£¬£¬£¬Åú¸Ä£¬£¬£¬£¬£¬£¬£¬£¬Ö´Ðй¤×÷¡£¡£¡£¡£¡£
https://support.sonatype.com/hc/en-us/articles/360046233714
4. ÁéͨOAËÁÒâÓû§µÇ¼·ì϶
ÁéͨOAµÇ¼ʵÏÖ´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬Äܹ»ËÁÒâÓû§¸ßµÍÎĵǼ¡£¡£¡£¡£¡£
https://cert.360.cn/warning/detail?id=d2689a877c01a9712d148317c2da21a2
5. Contiki-NGÔ½½çд´úÂëÖ´Ðзì϶
Contiki-NG os/net/ipv6/sicslowpan.cÔÚ´¦ÖÃ6LoWPAN·Ô쬳Á×é´æÔÚÔ½½çд·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»£»òÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£
https://github.com/contiki-ng/contiki-ng/pull/972
1¡¢¼ÓÄôó¶ùͯÓÎÏ·ÍøÕ¾Webkinz½ü2300ÍòÓû§Êý¾Ýй¶
¼ÓÄôó³ÛÃûÍæ¾ß¹«Ë¾GanzÆìϵĶùͯÓÎÏ·ÍøÕ¾WebkinzÔâµ½ºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬£¬½ü2300ÍòÍæ¼ÒµÄÓû§ÃûºÍÃÜÂëй¶£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖÐй¶µÄÃÜÂëʹÓÃÁËMD5-CryptËã·¨¼ÓÃÜ¡£¡£¡£¡£¡£¾ÝZDNet±¨Â·£¬£¬£¬£¬£¬£¬£¬£¬ºÚ¿ÍÊÇÀûÓÃÍøÕ¾ÖеÄSQL×¢Èë·ì϶ÈëÇÖÓÎÏ·Êý¾Ý¿âµÄ£¬£¬£¬£¬£¬£¬£¬£¬¾Ý³Æ¸Ã·ì϶µÄϸ½ÚÒÑÔÚºÚ¿ÍÂÛ̳Öд«²¼Á˼¸¸öÔ¡£¡£¡£¡£¡£ºÚ¿Í¿ÉÄÜ»¹µÁÈ¡Á˹þÏ£¼ÓÃܵĵç×ÓÓʼþµØÖ·¡£¡£¡£¡£¡£ÐÂÎÅÈËÊ¿³ÆWebkinzÔ±¹¤ÒѾ½¨¸´Á˺ڿÍʹÓõķì϶£¬£¬£¬£¬£¬£¬£¬£¬µ«GanzÉÐδ¶Ô´ËÊÂÎñ½øÐлØÓ¦¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/hacker-leaks-23-million-usernames-and-passwords-from-webkinz-childrens-game/
2¡¢FPGAоƬStarbleed·ì϶£¬£¬£¬£¬£¬£¬£¬£¬Ó°ÏìÈüÁé˼¶à¸ö²úÆ·
×êÑÐÈËÔ±·¢ÏÖFPGAоƬ´æÔÚStarbleed·ì϶£¬£¬£¬£¬£¬£¬£¬£¬Ó°ÏìÁËÈüÁé˼7ϵÁеÄSpartan¡¢Artix¡¢Kintex¡¢Virtex×ÓϵÁжà¸ö²úÆ·¡£¡£¡£¡£¡£ÓÉÓÚ·ì϶ΪӲ¼þ¼¶±ð·ì϶£¬£¬£¬£¬£¬£¬£¬£¬Òò¶øÖ»ÄÜͨ¹ý¸ü»»Ð¾Æ¬À´½¨¸´·ì϶¡£¡£¡£¡£¡£°²È«×êÑÐÈËÔ±·¢ÏÖÄܹ»Í¨¹ý½âÃܱ»¼ÓÃܵıÈÌØÁ÷À´½Ó¼ûºÍÅú¸ÄÓÃÓÚ±à³ÌµÄÎļþ¡£¡£¡£¡£¡£Òò¶ø£¬£¬£¬£¬£¬£¬£¬£¬ºÚ¿ÍÄܹ»ÀûÓø÷ì϶ÆëÈ«½ÚÔìFPGAоƬ£¬£¬£¬£¬£¬£¬£¬£¬²¢ÇÒ¿ÉÄܵÁÈ¡±ÈÌØÁ÷ÖеÄ֪ʶ²úȨ¡£¡£¡£¡£¡£µÂ¹úMax Planck×êÑÐËùµÄChristof Paar½ÌÊÚ°µÊ¾£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÉõÖÁÄܹ»½øÐÐÔ¶³Ì¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬»òÊÇÏòFPGAоƬֲÈëÓ²¼þľÂí¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.helpnetsecurity.com/2020/04/20/starbleed-vulnerability/
3¡¢CNCERT°ä²¼¡¶2019ÄêÎÒ¹ú»¥ÁªÍøÍøÂç°²È«Ì¬ÊÆ×ÛÊö¡·»ã±¨
¹ú¶È»¥ÁªÍøÓ¦¼±ÖÐÐÄ£¨CNCERT£©ÓÚ2020Äê4ÔÂ20ÈÕ°ä²¼ÁË¡¶2019ÄêÎÒ¹ú»¥ÁªÍøÍøÂç°²È«Ì¬ÊÆ×ÛÊö¡·»ã±¨¡£¡£¡£¡£¡£¸Ã»ã±¨°²ÉíÓÚCNCERTÍøÂ簲ȫºê¹Û¼à²âÊý¾ÝÓ빤×÷ʵ¼Ê»ã±¨£¬£¬£¬£¬£¬£¬£¬£¬Éæ¼°2019ÄêµäÐÍÍøÂ簲ȫÊÂÎñ¡¢ÍøÂ簲ȫÐÂÇ÷Ïò¼°ÈÕ³£ÍøÂ簲ȫÊÂÎñÓ¦¼±´ëÖÃʵ¼ÊµÈÄÚÈÝ¡£¡£¡£¡£¡£»ã±¨ÖØÒªÔ̺¬Ëĸö²¿ÃÅ£¬£¬£¬£¬£¬£¬£¬£¬Ò»ÊÇ×ܽá2019ÄêÎÒ¹ú»¥ÁªÍøÍøÂ簲ȫÇé¿ö£¬£¬£¬£¬£¬£¬£¬£¬¶þÊÇÔ¤²â2020ÄêÍøÂ簲ȫÈȵ㣬£¬£¬£¬£¬£¬£¬£¬ÈýÊǽáºÏÍøÂç°²È«Ì¬ÊÆ·ÖÎöÌá³ö¶Ô²ß½¨Ò飬£¬£¬£¬£¬£¬£¬£¬ËÄÊÇÊáÀíÍøÂ簲ȫ¼à²âÊý¾Ý¡£¡£¡£¡£¡£¸Ã»ã±¨¶ÔÎÒ¹úµ³Õþ»ú¹Ø¡¢ÐÐÒµÆóÒµ¼°È«Éç»áÏàʶÎÒ¹úÍøÂ簲ȫ¾ÖÊÆ£¬£¬£¬£¬£¬£¬£¬£¬Ìá¸ßÍøÂ簲ȫÒâʶ£¬£¬£¬£¬£¬£¬£¬£¬×öºÃÍøÂ簲ȫ¹¤×÷ÌṩÁËÓÐÁ¦²Î¿¼¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
http://www.cac.gov.cn/2020-04/20/c_1588932297982643.htm
4¡¢×êÑÐÈËÔ±Åû¶IBMÆóÒµ°²È«Èí¼þÖеÄ4¸ö0day
°²È«×êÑÐÈËÔ±ÔÚ·ÖÎöIBM Data Risk Manager£¨IDRM£©Ê±·¢ÏÖÁË4¸ö0day£¬£¬£¬£¬£¬£¬£¬£¬±ðÀëΪÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶¡¢ºÅÁî×¢Èë·ì϶¡¢²»°²È«µÄĬÈÏÃÜÂë·ì϶ÒÔ¼°ËÁÒâÎļþÏÂÔØ·ì϶¡£¡£¡£¡£¡£ÕâЩ·ì϶Äܹ»µ¥¶ÀʹÓÃÒ²Äܹ»×éºÏʹÓ㬣¬£¬£¬£¬£¬£¬£¬×éºÏʹÓÃǰÈý¸ö·ì϶Äܹ»Ê¹¹¥»÷ÕßÒÔrootȨÏÞÔ¶³ÌÖ´ÐдúÂ룬£¬£¬£¬£¬£¬£¬£¬×éºÏʹÓõÚÒ»¸öºÍµÚËĸö·ì϶Äܹ»Ê¹Î´ÊÚȨµÄ¹¥»÷ÕßÏÂÔØËÁÒâÎļþ¡£¡£¡£¡£¡£·ì϶µÄÅû¶ÕßRibeiro°µÊ¾£¬£¬£¬£¬£¬£¬£¬£¬IDRMÊÇ´¦ÖÃÃô¸ÐÐÅÏ¢µÄÆóÒµ°²È«²úÆ·£¬£¬£¬£¬£¬£¬£¬£¬ÈôÊÇÆäÔâµ½¹¥»÷»áµ¼Ö¹«Ë¾ÀûÒæÑϳÁÊÜË𣬣¬£¬£¬£¬£¬£¬£¬Òò¶øÔÚIBM»Ø¾ø½ÓÊÜ·ì϶»ã±¨ºóÑ¡Ôñ½«Æä°ä²¼³öÀ´¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬£¬£¬IBM¹«Ë¾½¨¸´ÁËIDRM2.0.1¼°¸ü¸ß°æ±¾ÖеÄËÁÒâÎļþÏÂÔØ·ì϶ºÍºÅÁî×¢Èë·ì϶£¬£¬£¬£¬£¬£¬£¬£¬²¢ÇÒÔÚµ÷²éÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/researcher-discloses-four-ibm-zero-days-after-refusal-to-fix/
5¡¢Î¢Èí°ä²¼´¹Î£¸üУ¬£¬£¬£¬£¬£¬£¬£¬½¨¸´OfficeºÍPaint 3DÖжà¸ö·ì϶
Microsoft°ä²¼ÁË´¹Î£°²È«¸üУ¬£¬£¬£¬£¬£¬£¬£¬ÒÔ½¨¸´Ê¹ÓÃÁËAutodesk FBX¿âµÄMicrosoft²úÆ·£¬£¬£¬£¬£¬£¬£¬£¬Ô̺¬¶à¸ö°æ±¾µÄMicrosoft OfficeºÍWindows 10ÀûÓ÷¨Ê½Paint 3D¡£¡£¡£¡£¡£±¾´Î½¨¸´µÄ·ì϶ΪFBX¿âÖеÄÔ¶³ÌÖ´ÐдúÂë·ì϶£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÀûÓô˷ì϶Äܹ»»ñµÃÓë±¾µØÓû§Ò»ÑùµÄȨÏÞ£¬£¬£¬£¬£¬£¬£¬£¬AutodeskÔÚ4ÔÂ15ÈÕÍÆ³öÁËÕë¶Ô´Ë·ì϶µÄ²¹¶¡·¨Ê½¡£¡£¡£¡£¡£Microsoft°µÊ¾£¬£¬£¬£¬£¬£¬£¬£¬ºÚ¿Í±ØÐëÓÕʹÓû§´ò¿ªÆäÌØÔìµÄ3DÎļþÄÜÁ¦¹»³É¹¦ÀûÓô˷ì϶£¬£¬£¬£¬£¬£¬£¬£¬Òò¶ø£¬£¬£¬£¬£¬£¬£¬£¬ÔÚ°²È«¸üÐÂ֮ǰÓû§±ØÒªÔ¶ÀëÄÇЩ¿ÉÒÉÎļþÒÔ±£Õϰ²È«¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://news.softpedia.com/news/microsoft-releases-emergency-update-for-windows-10-app-microsoft-office-529800.shtml


¾©¹«Íø°²±¸11010802024551ºÅ