ÐÅÏ¢°²È«Öܱ¨-2020ÄêµÚ21ÖÜ

°ä²¼¹¦·ò 2020-05-26

> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2020Äê05ÔÂ18ÈÕÖÁ05ÔÂ24ÈÕ¹²ÊÕ¼°²È«·ì϶60¸ö£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇCisco Unified Contact Center Express·´ÐòÁл¯´úÂëÖ´Ðзì϶; Apache Tomcat session·´ÐòÁл¯´úÂëÖ´Ðзì϶£»£»£»£»£» £» £»£»Google Chrome reader modeÄÚ´æÃýÎóÒýÓôúÂëÖ´Ðзì϶£»£»£»£»£» £» £»£»Emerson Electric OpenEnterprisÔ¶³Ì´úÂëÖ´Ðзì϶£»£»£»£»£» £» £»£»Centreon main.get.php OSºÅÁî×¢Èë·ì϶¡£ ¡£ ¡£¡£ ¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇiPhoneÓʼþÀûÓÃEdison Mail´æÔÚ·ì϶£¬£¬£¬£¬£¬Ð¹Â¶Óû§ÐÅÏ¢£»£»£»£»£» £» £»£»°Ä´óÀûÑǹ«Ë¾BlueScopeÔâµ½¹¥»÷µ¼Ö²¿ÃÅÒµÎñÖжÏ£»£»£»£»£» £» £»£»Daimler 580¶à¸öGit´æ´¢¿â¶³ö£¬£¬£¬£¬£¬±¼ÌÚ×é¼þOLUÔ´´úÂëй¶£»£»£»£»£» £» £»£»Adobe°ä²¼´¹Î£´ø±í¸üУ¬£¬£¬£¬£¬½¨¸´Ô¶³ÌÖ´ÐдúÂë·ì϶£»£»£»£»£» £» £»£»ºÚ¿ÍµÁÈ¡WishboneÖÐ4000ÍòÌõÓû§ÐÅÏ¢£¬£¬£¬£¬£¬²¢ÔÚ°µÍø±ê¼ÛÏúÊÛ¡£ ¡£ ¡£¡£ ¡£¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖÓ×£ ¡£ ¡£¡£ ¡£¡£


>³ÁÒª°²È«·ì϶Áбí


1. Cisco Unified Contact Center Express·´ÐòÁл¯´úÂëÖ´Ðзì϶


Cisco Unified Contact Center Express JavaÔ¶³ÌÖÎÀí½çÃæ´æÔÚ·´ÐòÁл¯·ì϶£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬Äܹ»rootȨÏÞÖ´ÐÐËÁÒâ´úÂë¡£ ¡£ ¡£¡£ ¡£¡£

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-uccx-rce-GMSC6RKN


2. Apache Tomcat session·´ÐòÁл¯´úÂëÖ´Ðзì϶


Apache Tomcat´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬µ±Ê¹ÓÃtomcatʱ£¬£¬£¬£¬£¬ÈôÊÇʹÓÃÁËtomcatÌṩµÄsessionÓÆ¾Ã»¯Ö°ÄÜ£¬£¬£¬£¬£¬ÈôÊÇ´æÔÚÎļþÉÏ´«Ö°ÄÜ£¬£¬£¬£¬£¬¶ñÒâÒªÇóÕßͨ¹ýÒ»¸öÁ÷³Ì£¬£¬£¬£¬£¬½«ÄÜÌáÒéÒ»¸ö¶ñÒâÒªÇóÔì³É·þÎñ¶ËÔ¶³ÌºÅÁîÖ´ÐÓ×£ ¡£ ¡£¡£ ¡£¡£

https://lists.apache.org/thread.html/r77eae567ed829da9012cadb29af17f2df8fa23bf66faf88229857bb1%40%3Cannounce.tomcat.apache.org%3E


3. Google Chrome reader modeÄÚ´æÃýÎóÒýÓôúÂëÖ´Ðзì϶


Google Chrome reader mode´æÔÚ¿ªÊͺóʹÓ÷ì϶£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄWEBÒªÇ󣬣¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£» £» £»£»òÕßÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£ ¡£ ¡£¡£ ¡£¡£

https://chromereleases.googleblog.com/2020/05/stable-channel-update-for-desktop_19.html


4. Emerson Electric OpenEnterprisÔ¶³Ì´úÂëÖ´Ðзì϶


Emerson Electric OpenEnterpriseijͨÕÛ·þÎñ´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬¿ÉÖ´ÐÐËÁÒâ´úÂë¡£ ¡£ ¡£¡£ ¡£¡£

https://www.us-cert.gov/ics/advisories/icsa-20-140-02


5. Centreon main.get.php OSºÅÁî×¢Èë·ì϶


Centreon main.get.php´¦ÖÃRRDdatabase_status_path²ÎÊý´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬¿É×¢ÈëËÁÒâOSºÅÁî¡£ ¡£ ¡£¡£ ¡£¡£

https://github.com/centreon/centreon/pull/8467



> ³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢iPhoneÓʼþÀûÓÃEdison Mail´æÔÚ·ì϶£¬£¬£¬£¬£¬Ð¹Â¶Óû§ÐÅÏ¢


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Ô­ÎÄÁ´½Ó£º

https://news.softpedia.com/news/iphone-email-app-bug-caused-users-messages-to-show-up-on-other-phones-530003.shtml


2¡¢°Ä´óÀûÑǹ«Ë¾BlueScopeÔâµ½¹¥»÷µ¼Ö²¿ÃÅÒµÎñÖжÏ


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/bluescope-reports-cyber-incident-affecting-australian-operations/


3¡¢Daimler 580¶à¸öGit´æ´¢¿â¶³ö£¬£¬£¬£¬£¬±¼ÌÚ×é¼þOLUÔ´´úÂëй¶


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/mercedes-benz-onboard-logic-unit-olu-source-code-leaks-online/


4¡¢Adobe°ä²¼´¹Î£´ø±í¸üУ¬£¬£¬£¬£¬½¨¸´Ô¶³ÌÖ´ÐдúÂë·ì϶


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/adobe-releases-critical-out-of-band-security-update/


5¡¢ºÚ¿ÍµÁÈ¡WishboneÖÐ4000ÍòÌõÓû§ÐÅÏ¢£¬£¬£¬£¬£¬²¢ÔÚ°µÍø±ê¼ÛÏúÊÛ


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/hacker-selling-40-million-user-records-from-popular-wishbone-app/