ÐÅÏ¢°²È«Öܱ¨-2020ÄêµÚ18ÖÜ

°ä²¼¹¦·ò 2020-05-06

> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2020Äê04ÔÂ27ÈÕÖÁ05ÔÂ03ÈÕ¹²ÊÕ¼°²È«·ì϶70¸ö£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇSaltStack Salt salt-master process ClearFuncs²»ÕýȷУÑé²½ÖèŲÓ÷ì϶; Apache IoTDB 31999¶Ë¿ÚδÊÚȨ½Ó¼û·ì϶£»£»£»£»£»£»£»£»Adobe Bridge¶à¸öÔ½½çд´úÂëÖ´Ðзì϶£»£»£»£»£»£»£»£»Google OpenThread MeshCoP::Commissioner::GeneratePskc»º³åÇøÒç¶Âí½Å£»£»£»£»£»£»£»£»BMC Control-M/Agent OSºÅÁî×¢Èë·ì϶¡£¡£¡£¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇSophos´¹Î£½¨¸´·À»ðǽÖеÄSQL×¢Èë0day£¬£¬£¬£¬£¬Òѱ»Ò°±íÀûÓ㻣»£»£»£»£»£»£»ÍøÐŰìµÈ12¸ö²¿ÃŽáºÏ°ä²¼¡¶ÍøÂ簲ȫÉó²é·¨×Ó¡·£»£»£»£»£»£»£»£»Adobe°ä²¼´¹Î£²¹¶¡£¡£¡£¡£¡£¡£¡£¬£¬£¬£¬£¬½¨¸´Æä3¿î²úÆ·ÖеÄ35¸ö·ì϶£»£»£»£»£»£»£»£»CNNIC°ä²¼¡¶Öйú»¥ÁªÍøÂç·¢Õ¹Çé¿öͳ¼Æ»ã±¨¡·£»£»£»£»£»£»£»£»¹È¸è×êÑÐÈËÔ±Åû¶ƻ¹ûImage I/OµÄÁãµã»÷·ì϶¡£¡£¡£¡£¡£¡£¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖÓ×£¡£¡£¡£¡£¡£¡£


>³ÁÒª°²È«·ì϶Áбí


1. SaltStack Salt salt-master process ClearFuncs²»ÕýȷУÑé²½ÖèŲÓ÷ì϶


SaltStack Salt salt-master process ClearFuncs²»ÕýȷУÑé²½ÖèŲÓ㬣¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬¿É»ñÈ¡Óû§ÁîÅÆ£¬£¬£¬£¬£¬Î´ÊÚȨ½Ó¼û²¢Ö´ÐкÅÁî¡£¡£¡£¡£¡£¡£¡£

https://docs.saltstack.com/en/latest/topics/releases/2019.2.4.html


2. Apache IoTDB 31999¶Ë¿ÚδÊÚȨ½Ó¼û·ì϶


Apache IoTDB JMX 31999¶Ë¿Ú´æÔÚδÊÚȨ·ì϶£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬¿ÉδÊÚȨ½Ó¼û²¢Ö´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£

https://lists.apache.org/thread.html/r3d2ff899ead64d2952fdc1fbb1f520ca42011ed2b4c7f786e921f6b9%40%3Cdev.iotdb.apache.org%3E


3. Adobe Bridge¶à¸öÔ½½çд´úÂëÖ´Ðзì϶


Adobe Bridge´¦ÖÃÎļþ´æÔÚÔ½½çд·ì϶£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇ󣬣¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»£»£»£»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£

https://helpx.adobe.com/security/products/bridge/apsb20-19.html


4. Google OpenThread MeshCoP::Commissioner::GeneratePskc»º³åÇøÒç¶Âí½Å


Google OpenThread MeshCoP::Commissioner::GeneratePskc´æÔÚ»º³åÇøÒç¶Âí½Å£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»£»£»£»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£

https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=19386


5. BMC Control-M/Agent OSºÅÁî×¢Èë·ì϶


ʹÓÃTCPºÍ̸ʱBMC Control-M/Agent´æÔÚÊäÈëÑéÖ¤·ì϶£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬¿É×¢ÈëËÁÒâOSºÅÁî¡£¡£¡£¡£¡£¡£¡£

https://herolab.usd.de/security-advisories/usd-2019-0064/


> ³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢Sophos´¹Î£½¨¸´·À»ðǽÖеÄSQL×¢Èë0day£¬£¬£¬£¬£¬Òѱ»Ò°±íÀûÓÃ


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ÍøÂ簲ȫ¹«Ë¾SophosÓÚÖÜÁù°ä²¼ÁË´¹Î£²¹¶¡ÒÔ½¨¸´ÒѾ­±»Ò°±íÀûÓõÄSQL×¢Èë0day£¬£¬£¬£¬£¬¸Ã·ì϶ӰÏìÁËÆäXG Firewall²úÆ·¡£¡£¡£¡£¡£¡£¡£4ÔÂ22ÈÕÍí£¬£¬£¬£¬£¬Sophos¹«Ë¾·¢ÏÖºÚ¿ÍÀûÓÃXG FirewallÖеÄSQL×¢Èë·ì϶ÇÔÈ¡Á˸ÃÉ豸ÖеÄÊý¾Ý£¬£¬£¬£¬£¬Ô̺¬·À»ðǽÉ豸ÖÎÀíÔ¹ØË»§¡¢·À»ðǽÃÅ»§ÍøÕ¾ÖÎÀíÔ¹ØË»§ºÍÔ¶³Ì½Ó¼ûÉ豸ÕË»§ÖеĵÄÓû§ÃûºÍ¹þÏ£ÃÜÂë¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾°µÊ¾Õâ´Î¸üÐÂÒѾ­½¨¸´Á˸ÃSQL×¢Èë·ì϶£¬£¬£¬£¬£¬²¢ÇÒмÓÁËÌØÊâÌáÐÑÖ°ÄÜʹ¿Í»§ÖªÂ·ÆäÉ豸ÊÇ·ñÊܵ½ÁËÍþв¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/hackers-are-exploiting-a-sophos-firewall-zero-day/


2¡¢ÍøÐŰìµÈ12¸ö²¿ÃŽáºÏ°ä²¼¡¶ÍøÂ簲ȫÉó²é·¨×Ó¡·


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Ô­ÎÄÁ´½Ó£º

http://www.cac.gov.cn/2020-04/27/c_1589535450769077.htm


3¡¢Adobe°ä²¼´¹Î£²¹¶¡£¡£¡£¡£¡£¡£¡£¬£¬£¬£¬£¬½¨¸´Æä3¿î²úÆ·ÖеÄ35¸ö·ì϶


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Èí¼þ¹«Ë¾AdobeÓÚ4ÔÂ28ÈÕ°ä²¼´¹Î£·ì϶²¹¶¡£¡£¡£¡£¡£¡£¡£¬£¬£¬£¬£¬×ܹ²½¨¸´ÁË35¸ö·ì϶£¬£¬£¬£¬£¬ÕâЩ·ì϶ӰÏìµÄ²úÆ·ÓÐAdobe Illustrator¡¢Adobe BridgeºÍµçÉÌÆ½Ì¨Magento¡£¡£¡£¡£¡£¡£¡£Õâ´Î°²È«¸üн¨¸´ÁËWindows°æ±¾Illustrator 2020ÖеÄ5¸ö´úÂëÖ´Ðзì϶£¬£¬£¬£¬£¬Adobe Bridge 10.0.1¼°¸üÔç°æ±¾ÖеÄ17¸ö·ì϶£¨14¸ö¿Éµ¼Ö´úÂëÖ´Ðзì϶£¬£¬£¬£¬£¬3¸öÓйØÐÅϢй¶ÎÊÌ⣩£¬£¬£¬£¬£¬Ã³Ò×°æ±¾ºÍ¿ªÔ´°æ±¾µÄMagento CMSÖеÄ13¸ö·ì϶¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2020/04/adobe-software-updates.html


4¡¢CNNIC°ä²¼¡¶Öйú»¥ÁªÍøÂç·¢Õ¹Çé¿öͳ¼Æ»ã±¨¡·


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Ô­ÎÄÁ´½Ó£º

http://news.china.com.cn/txt/2020-04/28/content_75985166.htm


5¡¢¹È¸è×êÑÐÈËÔ±Åû¶ƻ¹ûImage I/OµÄÁãµã»÷·ì϶


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


¹È¸èµÄProject Zero ÍŶÓÓÚ±¾ÖܶþÅû¶ÁËApple²Ù×÷ϵͳÖÐÄÚÖõĿò¼ÜImage I/OÖеÄÁãµã»÷·ì϶£¬£¬£¬£¬£¬¸Ã¿ò¼Ü±»ÀûÓÃÓÚiOS¡¢macOS¡¢tvOSºÍwatchOSÖУ¬£¬£¬£¬£¬ÓÃÀ´´¦ÖÃͼÏñÔªÊý¾Ý¡£¡£¡£¡£¡£¡£¡£Project ZeroÍŶӰµÊ¾£¬£¬£¬£¬£¬ËûÃÇ·ÖÎöÁ˸ÿò¼ÜµÄÍÌÍ´¦Öùý³Ì£¬£¬£¬£¬£¬ÒÔ¹Û²ìËüÊÇÈôºÎ´¦ÖÃÌåʽÃýÎóµÄͼÏñÎļþ¡£¡£¡£¡£¡£¡£¡£Á˾Ö×êÑÐÈËÔ±·¢ÏÖÁË Image I/O ÖдæÔÚ6¸ö·ì϶£¬£¬£¬£¬£¬¶øÆ»¹ûÏòµÚÈý·½¹«¿ªµÄ¸ß¶¯Ì¬ÁìÓò£¨HDR£©Í¼ÏñÎļþÌåʽ¿ò¼ÜOpenEXRÖдæÔÚ8¸ö·ì϶¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬ËùÓзì϶¶¼ÒѾ­±»½¨¸´¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/google-discloses-zero-click-bugs-impacting-several-apple-operating-systems/