ÐÅÏ¢°²È«Öܱ¨-2020ÄêµÚ18ÖÜ
°ä²¼¹¦·ò 2020-05-06> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
2020Äê04ÔÂ27ÈÕÖÁ05ÔÂ03ÈÕ¹²ÊÕ¼°²È«·ì϶70¸ö£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇSaltStack Salt salt-master process ClearFuncs²»ÕýȷУÑé²½ÖèŲÓ÷ì϶; Apache IoTDB 31999¶Ë¿ÚδÊÚȨ½Ó¼û·ì϶£»£»£»£»£»£»£»£»Adobe Bridge¶à¸öÔ½½çд´úÂëÖ´Ðзì϶£»£»£»£»£»£»£»£»Google OpenThread MeshCoP::Commissioner::GeneratePskc»º³åÇøÒç¶Âí½Å£»£»£»£»£»£»£»£»BMC Control-M/Agent OSºÅÁî×¢Èë·ì϶¡£¡£¡£¡£¡£¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇSophos´¹Î£½¨¸´·À»ðǽÖеÄSQL×¢Èë0day£¬£¬£¬£¬£¬Òѱ»Ò°±íÀûÓ㻣»£»£»£»£»£»£»ÍøÐŰìµÈ12¸ö²¿ÃŽáºÏ°ä²¼¡¶ÍøÂ簲ȫÉó²é·¨×Ó¡·£»£»£»£»£»£»£»£»Adobe°ä²¼´¹Î£²¹¶¡£¡£¡£¡£¡£¡£¡£¬£¬£¬£¬£¬½¨¸´Æä3¿î²úÆ·ÖеÄ35¸ö·ì϶£»£»£»£»£»£»£»£»CNNIC°ä²¼¡¶Öйú»¥ÁªÍøÂç·¢Õ¹Çé¿öͳ¼Æ»ã±¨¡·£»£»£»£»£»£»£»£»¹È¸è×êÑÐÈËÔ±Åû¶ƻ¹ûImage I/OµÄÁãµã»÷·ì϶¡£¡£¡£¡£¡£¡£¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖÓ×£¡£¡£¡£¡£¡£¡£
>³ÁÒª°²È«·ì϶Áбí
1. SaltStack Salt salt-master process ClearFuncs²»ÕýȷУÑé²½ÖèŲÓ÷ì϶
SaltStack Salt salt-master process ClearFuncs²»ÕýȷУÑé²½ÖèŲÓ㬣¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬¿É»ñÈ¡Óû§ÁîÅÆ£¬£¬£¬£¬£¬Î´ÊÚȨ½Ó¼û²¢Ö´ÐкÅÁî¡£¡£¡£¡£¡£¡£¡£
https://docs.saltstack.com/en/latest/topics/releases/2019.2.4.html
2. Apache IoTDB 31999¶Ë¿ÚδÊÚȨ½Ó¼û·ì϶
Apache IoTDB JMX 31999¶Ë¿Ú´æÔÚδÊÚȨ·ì϶£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬¿ÉδÊÚȨ½Ó¼û²¢Ö´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£
https://lists.apache.org/thread.html/r3d2ff899ead64d2952fdc1fbb1f520ca42011ed2b4c7f786e921f6b9%40%3Cdev.iotdb.apache.org%3E
3. Adobe Bridge¶à¸öÔ½½çд´úÂëÖ´Ðзì϶
Adobe Bridge´¦ÖÃÎļþ´æÔÚÔ½½çд·ì϶£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇ󣬣¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»£»£»£»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£
https://helpx.adobe.com/security/products/bridge/apsb20-19.html
4. Google OpenThread MeshCoP::Commissioner::GeneratePskc»º³åÇøÒç¶Âí½Å
Google OpenThread MeshCoP::Commissioner::GeneratePskc´æÔÚ»º³åÇøÒç¶Âí½Å£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»£»£»£»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=19386
5. BMC Control-M/Agent OSºÅÁî×¢Èë·ì϶
ʹÓÃTCPºÍ̸ʱBMC Control-M/Agent´æÔÚÊäÈëÑéÖ¤·ì϶£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬¿É×¢ÈëËÁÒâOSºÅÁî¡£¡£¡£¡£¡£¡£¡£
https://herolab.usd.de/security-advisories/usd-2019-0064/
> ³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢Sophos´¹Î£½¨¸´·À»ðǽÖеÄSQL×¢Èë0day£¬£¬£¬£¬£¬Òѱ»Ò°±íÀûÓÃ
ÍøÂ簲ȫ¹«Ë¾SophosÓÚÖÜÁù°ä²¼ÁË´¹Î£²¹¶¡ÒÔ½¨¸´ÒѾ±»Ò°±íÀûÓõÄSQL×¢Èë0day£¬£¬£¬£¬£¬¸Ã·ì϶ӰÏìÁËÆäXG Firewall²úÆ·¡£¡£¡£¡£¡£¡£¡£4ÔÂ22ÈÕÍí£¬£¬£¬£¬£¬Sophos¹«Ë¾·¢ÏÖºÚ¿ÍÀûÓÃXG FirewallÖеÄSQL×¢Èë·ì϶ÇÔÈ¡Á˸ÃÉ豸ÖеÄÊý¾Ý£¬£¬£¬£¬£¬Ô̺¬·À»ðǽÉ豸ÖÎÀíÔ¹ØË»§¡¢·À»ðǽÃÅ»§ÍøÕ¾ÖÎÀíÔ¹ØË»§ºÍÔ¶³Ì½Ó¼ûÉ豸ÕË»§ÖеĵÄÓû§ÃûºÍ¹þÏ£ÃÜÂë¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾°µÊ¾Õâ´Î¸üÐÂÒѾ½¨¸´Á˸ÃSQL×¢Èë·ì϶£¬£¬£¬£¬£¬²¢ÇÒмÓÁËÌØÊâÌáÐÑÖ°ÄÜʹ¿Í»§ÖªÂ·ÆäÉ豸ÊÇ·ñÊܵ½ÁËÍþв¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/hackers-are-exploiting-a-sophos-firewall-zero-day/
2¡¢ÍøÐŰìµÈ12¸ö²¿ÃŽáºÏ°ä²¼¡¶ÍøÂ簲ȫÉó²é·¨×Ó¡·
ÔÎÄÁ´½Ó£º
http://www.cac.gov.cn/2020-04/27/c_1589535450769077.htm
3¡¢Adobe°ä²¼´¹Î£²¹¶¡£¡£¡£¡£¡£¡£¡£¬£¬£¬£¬£¬½¨¸´Æä3¿î²úÆ·ÖеÄ35¸ö·ì϶
Èí¼þ¹«Ë¾AdobeÓÚ4ÔÂ28ÈÕ°ä²¼´¹Î£·ì϶²¹¶¡£¡£¡£¡£¡£¡£¡£¬£¬£¬£¬£¬×ܹ²½¨¸´ÁË35¸ö·ì϶£¬£¬£¬£¬£¬ÕâЩ·ì϶ӰÏìµÄ²úÆ·ÓÐAdobe Illustrator¡¢Adobe BridgeºÍµçÉÌÆ½Ì¨Magento¡£¡£¡£¡£¡£¡£¡£Õâ´Î°²È«¸üн¨¸´ÁËWindows°æ±¾Illustrator 2020ÖеÄ5¸ö´úÂëÖ´Ðзì϶£¬£¬£¬£¬£¬Adobe Bridge 10.0.1¼°¸üÔç°æ±¾ÖеÄ17¸ö·ì϶£¨14¸ö¿Éµ¼Ö´úÂëÖ´Ðзì϶£¬£¬£¬£¬£¬3¸öÓйØÐÅϢй¶ÎÊÌ⣩£¬£¬£¬£¬£¬Ã³Ò×°æ±¾ºÍ¿ªÔ´°æ±¾µÄMagento CMSÖеÄ13¸ö·ì϶¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2020/04/adobe-software-updates.html
4¡¢CNNIC°ä²¼¡¶Öйú»¥ÁªÍøÂç·¢Õ¹Çé¿öͳ¼Æ»ã±¨¡·
ÔÎÄÁ´½Ó£º
http://news.china.com.cn/txt/2020-04/28/content_75985166.htm
5¡¢¹È¸è×êÑÐÈËÔ±Åû¶ƻ¹ûImage I/OµÄÁãµã»÷·ì϶
¹È¸èµÄProject Zero ÍŶÓÓÚ±¾ÖܶþÅû¶ÁËApple²Ù×÷ϵͳÖÐÄÚÖõĿò¼ÜImage I/OÖеÄÁãµã»÷·ì϶£¬£¬£¬£¬£¬¸Ã¿ò¼Ü±»ÀûÓÃÓÚiOS¡¢macOS¡¢tvOSºÍwatchOSÖУ¬£¬£¬£¬£¬ÓÃÀ´´¦ÖÃͼÏñÔªÊý¾Ý¡£¡£¡£¡£¡£¡£¡£Project ZeroÍŶӰµÊ¾£¬£¬£¬£¬£¬ËûÃÇ·ÖÎöÁ˸ÿò¼ÜµÄÍÌÍ´¦Öùý³Ì£¬£¬£¬£¬£¬ÒÔ¹Û²ìËüÊÇÈôºÎ´¦ÖÃÌåʽÃýÎóµÄͼÏñÎļþ¡£¡£¡£¡£¡£¡£¡£Á˾Ö×êÑÐÈËÔ±·¢ÏÖÁË Image I/O ÖдæÔÚ6¸ö·ì϶£¬£¬£¬£¬£¬¶øÆ»¹ûÏòµÚÈý·½¹«¿ªµÄ¸ß¶¯Ì¬ÁìÓò£¨HDR£©Í¼ÏñÎļþÌåʽ¿ò¼ÜOpenEXRÖдæÔÚ8¸ö·ì϶¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬ËùÓзì϶¶¼ÒѾ±»½¨¸´¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/google-discloses-zero-click-bugs-impacting-several-apple-operating-systems/


¾©¹«Íø°²±¸11010802024551ºÅ