ÐÅÏ¢Çå¾²Öܱ¨-2020ÄêµÚ18ÖÜ
Ðû²¼Ê±¼ä 2020-05-06> ±¾ÖÜÇ徲̬ÊÆ×ÛÊö
2020Äê04ÔÂ27ÈÕÖÁ05ÔÂ03ÈÕ¹²ÊÕ¼Çå¾²Îó²î70¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇSaltStack Salt salt-master process ClearFuncs²»×¼È·Ð£ÑéÒªÁìŲÓÃÎó²î; Apache IoTDB 31999¶Ë¿ÚδÊÚȨ»á¼ûÎó²î£»Adobe Bridge¶à¸öÔ½½çд´úÂëÖ´ÐÐÎó²î£»Google OpenThread MeshCoP::Commissioner::GeneratePskc»º³åÇøÒç³öÎó²î£»BMC Control-M/Agent OSÏÂÁî×¢ÈëÎó²î¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇSophos½ôÆÈÐÞ¸´·À»ðǽÖеÄSQL×¢Èë0day£¬Òѱ»Ò°ÍâʹÓã»ÍøÐÅ°ìµÈ12¸ö²¿·ÖÍŽáÐû²¼¡¶ÍøÂçÇå¾²Éó²é²½·¥¡·£»AdobeÐû²¼½ôÆȲ¹¶¡£¬ÐÞ¸´Æä3¿î²úÆ·ÖеÄ35¸öÎó²î£»CNNICÐû²¼¡¶Öйú»¥ÁªÍøÂçÉú³¤×´Ì¬Í³¼Æ±¨¸æ¡·£»¹È¸èÑо¿Ö°Ô±Åû¶ƻ¹ûImage I/OµÄÁãµã»÷Îó²î¡£
ƾ֤ÒÔÉÏ×ÛÊö£¬±¾ÖÜÇå¾²ÍþвΪÖС£
>Ö÷ÒªÇå¾²Îó²îÁбí
1. SaltStack Salt salt-master process ClearFuncs²»×¼È·Ð£ÑéÒªÁìŲÓÃÎó²î
SaltStack Salt salt-master process ClearFuncs²»×¼È·Ð£ÑéÒªÁìŲÓã¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ɻñÈ¡Óû§ÁîÅÆ£¬Î´ÊÚȨ»á¼û²¢Ö´ÐÐÏÂÁî¡£
https://docs.saltstack.com/en/latest/topics/releases/2019.2.4.html
2. Apache IoTDB 31999¶Ë¿ÚδÊÚȨ»á¼ûÎó²î
Apache IoTDB JMX 31999¶Ë¿Ú±£´æδÊÚȨÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉδÊÚȨ»á¼û²¢Ö´ÐÐí§Òâ´úÂë¡£
https://lists.apache.org/thread.html/r3d2ff899ead64d2952fdc1fbb1f520ca42011ed2b4c7f786e921f6b9%40%3Cdev.iotdb.apache.org%3E
3. Adobe Bridge¶à¸öÔ½½çд´úÂëÖ´ÐÐÎó²î
Adobe Bridge´¦Öóͷ£Îļþ±£´æÔ½½çдÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþÇëÇó£¬ÓÕʹÓû§ÆÊÎö£¬¿ÉʹӦÓóÌÐò±ÀÀ£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£
https://helpx.adobe.com/security/products/bridge/apsb20-19.html
4. Google OpenThread MeshCoP::Commissioner::GeneratePskc»º³åÇøÒç³öÎó²î
Google OpenThread MeshCoP::Commissioner::GeneratePskc±£´æ»º³åÇøÒç³öÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉʹӦÓóÌÐò±ÀÀ£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=19386
5. BMC Control-M/Agent OSÏÂÁî×¢ÈëÎó²î
ʹÓÃTCPÐÒéʱBMC Control-M/Agent±£´æÊäÈëÑéÖ¤Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿É×¢Èëí§ÒâOSÏÂÁî¡£
https://herolab.usd.de/security-advisories/usd-2019-0064/
> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö
1¡¢Sophos½ôÆÈÐÞ¸´·À»ðǽÖеÄSQL×¢Èë0day£¬Òѱ»Ò°ÍâʹÓÃ
ÍøÂçÇå¾²¹«Ë¾SophosÓÚÖÜÁùÐû²¼Á˽ôÆȲ¹¶¡ÒÔÐÞ¸´ÒѾ±»Ò°ÍâʹÓõÄSQL×¢Èë0day£¬¸ÃÎó²îÓ°ÏìÁËÆäXG Firewall²úÆ·¡£4ÔÂ22ÈÕÍí£¬Sophos¹«Ë¾·¢Ã÷ºÚ¿ÍʹÓÃXG FirewallÖеÄSQL×¢ÈëÎó²îÇÔÈ¡Á˸Ã×°±¸ÖеÄÊý¾Ý£¬°üÀ¨·À»ðǽװ±¸ÖÎÀíÔ±ÕË»§¡¢·À»ðǽÃÅ»§ÍøÕ¾ÖÎÀíÔ±ÕË»§ºÍÔ¶³Ì»á¼û×°±¸ÕË»§ÖеĵÄÓû§ÃûºÍ¹þÏ£ÃÜÂë¡£¸Ã¹«Ë¾ÌåÏִ˴θüÐÂÒѾÐÞ¸´Á˸ÃSQL×¢ÈëÎó²î£¬²¢ÇÒмÓÁËÌØÊâÌáÐѹ¦Ð§Ê¹¿Í»§ÖªµÀÆä×°±¸ÊÇ·ñÊܵ½ÁËÍþв¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/hackers-are-exploiting-a-sophos-firewall-zero-day/
2¡¢ÍøÐÅ°ìµÈ12¸ö²¿·ÖÍŽáÐû²¼¡¶ÍøÂçÇå¾²Éó²é²½·¥¡·
ÔÎÄÁ´½Ó£º
http://www.cac.gov.cn/2020-04/27/c_1589535450769077.htm
3¡¢AdobeÐû²¼½ôÆȲ¹¶¡£¬ÐÞ¸´Æä3¿î²úÆ·ÖеÄ35¸öÎó²î
Èí¼þ¹«Ë¾AdobeÓÚ4ÔÂ28ÈÕÐû²¼½ôÆÈÎó²î²¹¶¡£¬×ܹ²ÐÞ¸´ÁË35¸öÎó²î£¬ÕâЩÎó²îÓ°ÏìµÄ²úÆ·ÓÐAdobe Illustrator¡¢Adobe BridgeºÍµçÉÌƽ̨Magento¡£´Ë´ÎÇå¾²¸üÐÂÐÞ¸´ÁËWindows°æ±¾Illustrator 2020ÖеÄ5¸ö´úÂëÖ´ÐÐÎó²î£¬Adobe Bridge 10.0.1¼°¸üÔç°æ±¾ÖеÄ17¸öÎó²î£¨14¸ö¿Éµ¼Ö´úÂëÖ´ÐÐÎó²î£¬3¸öÓйØÐÅϢй¶ÎÊÌ⣩£¬ÉÌÒµ°æ±¾ºÍ¿ªÔ´°æ±¾µÄMagento CMSÖеÄ13¸öÎó²î¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2020/04/adobe-software-updates.html
4¡¢CNNICÐû²¼¡¶Öйú»¥ÁªÍøÂçÉú³¤×´Ì¬Í³¼Æ±¨¸æ¡·
ÔÎÄÁ´½Ó£º
http://news.china.com.cn/txt/2020-04/28/content_75985166.htm
5¡¢¹È¸èÑо¿Ö°Ô±Åû¶ƻ¹ûImage I/OµÄÁãµã»÷Îó²î
¹È¸èµÄProject Zero ÍŶÓÓÚ±¾ÖܶþÅû¶ÁËApple²Ù×÷ϵͳÖÐÄÚÖõĿò¼ÜImage I/OÖеÄÁãµã»÷Îó²î£¬¸Ã¿ò¼Ü±»Ó¦ÓÃÓÚiOS¡¢macOS¡¢tvOSºÍwatchOSÖУ¬ÓÃÀ´´¦Öóͷ£Í¼ÏñÔªÊý¾Ý¡£Project ZeroÍŶÓÌåÏÖ£¬ËûÃÇÆÊÎöÁ˸ÿò¼ÜµÄÄ£ºý´¦Öóͷ£Àú³Ì£¬ÒÔÊÓ²ìËüÊÇÈçÄÇÀïÖÃÃûÌùýʧµÄͼÏñÎļþ¡£Ð§¹ûÑо¿Ö°Ô±·¢Ã÷ÁË Image I/O Öб£´æ6¸öÎó²î£¬¶øÆ»¹ûÏòµÚÈý·½¹ûÕæµÄ¸ß¶¯Ì¬¹æÄ££¨HDR£©Í¼ÏñÎļþÃûÌÿò¼ÜOpenEXRÖб£´æ8¸öÎó²î¡£ÏÖÔÚ£¬ËùÓÐÎó²î¶¼ÒѾ±»ÐÞ¸´¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/google-discloses-zero-click-bugs-impacting-several-apple-operating-systems/