ÐÅÏ¢Äþ¾²Öܱ¨-2020ÄêµÚ18ÖÜ

Ðû²¼Ê±¼ä 2020-05-06

> ±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


2020Äê04ÔÂ27ÈÕÖÁ05ÔÂ03ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´70¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇSaltStack Salt salt-master process ClearFuncs²»ÕýȷУÑéÒªÁìµ÷Ó鶴; Apache IoTDB 31999¶Ë¿ÚδÊÚȨ·ÃÎÊ©¶´£»Adobe Bridge¶à¸öÔ½½çд´úÂëÖ´ÐЩ¶´£»Google OpenThread MeshCoP::Commissioner::GeneratePskc»º³åÇøÒç³ö©¶´£»BMC Control-M/Agent OSÃüÁî×¢È멶´¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇSophos½ô¼±ÐÞ¸´·À»ðǽÖеÄSQL×¢Èë0day£¬Òѱ»Ò°ÍâÀûÓã»ÍøÐÅ°ìµÈ12¸ö²¿ÃÅÁªºÏÐû²¼¡¶ÍøÂçÄþ¾²Éó²é´ëÊ©¡·£»AdobeÐû²¼½ô¼±²¹¶¡£¬ÐÞ¸´Æä3¿î²úÎïÖеÄ35¸ö©¶´£»CNNICÐû²¼¡¶Öйú»¥ÁªÍøÂçÉú³¤×´¿öͳ¼Æ³ÂËß¡·£»¹È¸èÑо¿ÈËÔ±Åû¶ƻ¹ûImage I/OµÄÁãµã»÷©¶´¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£


>ÖØÒªÄþ¾²Â©¶´Áбí


1. SaltStack Salt salt-master process ClearFuncs²»ÕýȷУÑéÒªÁìµ÷Ó鶴


SaltStack Salt salt-master process ClearFuncs²»ÕýȷУÑéÒªÁìµ÷Óã¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ɻñÈ¡Óû§ÁîÅÆ£¬Î´ÊÚȨ·ÃÎʲ¢Ö´ÐÐÃüÁî¡£

https://docs.saltstack.com/en/latest/topics/releases/2019.2.4.html


2. Apache IoTDB 31999¶Ë¿ÚδÊÚȨ·ÃÎÊ©¶´


Apache IoTDB JMX 31999¶Ë¿Ú´æÔÚδÊÚȨ©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉδÊÚȨ·ÃÎʲ¢Ö´ÐÐÈÎÒâ´úÂë¡£

https://lists.apache.org/thread.html/r3d2ff899ead64d2952fdc1fbb1f520ca42011ed2b4c7f786e921f6b9%40%3Cdev.iotdb.apache.org%3E


3. Adobe Bridge¶à¸öÔ½½çд´úÂëÖ´ÐЩ¶´


Adobe Bridge´¦ÖÃÎļþ´æÔÚÔ½½ç䩶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÎļþÇëÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£

https://helpx.adobe.com/security/products/bridge/apsb20-19.html


4. Google OpenThread MeshCoP::Commissioner::GeneratePskc»º³åÇøÒç³ö©¶´


Google OpenThread MeshCoP::Commissioner::GeneratePskc´æÔÚ»º³åÇøÒç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£

https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=19386


5. BMC Control-M/Agent OSÃüÁî×¢È멶´


ʹÓÃTCPЭÒéʱBMC Control-M/Agent´æÔÚÊäÈëÑé֤©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿É×¢ÈëÈÎÒâOSÃüÁî¡£

https://herolab.usd.de/security-advisories/usd-2019-0064/


> ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢Sophos½ô¼±ÐÞ¸´·À»ðǽÖеÄSQL×¢Èë0day£¬Òѱ»Ò°ÍâÀûÓÃ


×ðÁú¶¶È¦ - Ϊdu¶øÉú


ÍøÂçÄþ¾²¹«Ë¾SophosÓÚÖÜÁùÐû²¼Á˽ô¼±²¹¶¡ÒÔÐÞ¸´ÒѾ­±»Ò°ÍâÀûÓõÄSQL×¢Èë0day£¬¸Ã©¶´Ó°ÏìÁËÆäXG Firewall²úÎï¡£4ÔÂ22ÈÕÍí£¬Sophos¹«Ë¾·¢ÏÖºÚ¿ÍÀûÓÃXG FirewallÖеÄSQL×¢È멶´ÇÔÈ¡Á˸ÃÉ豸ÖеÄÊý¾Ý£¬°üÂÞ·À»ðǽÉ豸¹ÜÀíÔ±ÕË»§¡¢·À»ðǽÃÅ»§ÍøÕ¾¹ÜÀíÔ±ÕË»§ºÍÔ¶³Ì·ÃÎÊÉ豸ÕË»§ÖеĵÄÓû§ÃûºÍ¹þÏ£ÃÜÂë¡£¸Ã¹«Ë¾ÌåÏִ˴θüÐÂÒѾ­ÐÞ¸´Á˸ÃSQL×¢È멶´£¬¶øÇÒмÓÁËÌØÊâÌáÐѹ¦Ð§Ê¹¿Í»§ÖªµÀÆäÉ豸ÊÇ·ñÊܵ½ÁËÍþв¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/hackers-are-exploiting-a-sophos-firewall-zero-day/


2¡¢ÍøÐÅ°ìµÈ12¸ö²¿ÃÅÁªºÏÐû²¼¡¶ÍøÂçÄþ¾²Éó²é´ëÊ©¡·


×ðÁú¶¶È¦ - Ϊdu¶øÉú


Ô­ÎÄÁ´½Ó£º

http://www.cac.gov.cn/2020-04/27/c_1589535450769077.htm


3¡¢AdobeÐû²¼½ô¼±²¹¶¡£¬ÐÞ¸´Æä3¿î²úÎïÖеÄ35¸ö©¶´


×ðÁú¶¶È¦ - Ϊdu¶øÉú


Èí¼þ¹«Ë¾AdobeÓÚ4ÔÂ28ÈÕÐû²¼½ô¼±Â©¶´²¹¶¡£¬×ܹ²ÐÞ¸´ÁË35¸ö©¶´£¬ÕâЩ©¶´Ó°ÏìµÄ²úÎïÓÐAdobe Illustrator¡¢Adobe BridgeºÍµçÉÌƽ̨Magento¡£´Ë´ÎÄþ¾²¸üÐÂÐÞ¸´ÁËWindows°æ±¾Illustrator 2020ÖеÄ5¸ö´úÂëÖ´ÐЩ¶´£¬Adobe Bridge 10.0.1¼°¸üÔç°æ±¾ÖеÄ17¸ö©¶´£¨14¸ö¿Éµ¼Ö´úÂëÖ´ÐЩ¶´£¬3¸öÓйØÐÅϢй¶ÎÊÌ⣩£¬ÉÌÒµ°æ±¾ºÍ¿ªÔ´°æ±¾µÄMagento CMSÖеÄ13¸ö©¶´¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2020/04/adobe-software-updates.html


4¡¢CNNICÐû²¼¡¶Öйú»¥ÁªÍøÂçÉú³¤×´¿öͳ¼Æ³ÂËß¡·


×ðÁú¶¶È¦ - Ϊdu¶øÉú


Ô­ÎÄÁ´½Ó£º

http://news.china.com.cn/txt/2020-04/28/content_75985166.htm


5¡¢¹È¸èÑо¿ÈËÔ±Åû¶ƻ¹ûImage I/OµÄÁãµã»÷©¶´


×ðÁú¶¶È¦ - Ϊdu¶øÉú


¹È¸èµÄProject Zero ÍŶÓÓÚ±¾ÖܶþÅû¶ÁËApple²Ù×÷ϵͳÖÐÄÚÖõĿò¼ÜImage I/OÖеÄÁãµã»÷©¶´£¬¸Ã¿ò¼Ü±»Ó¦ÓÃÓÚiOS¡¢macOS¡¢tvOSºÍwatchOSÖУ¬ÓÃÀ´´¦ÖÃͼÏñÔªÊý¾Ý¡£Project ZeroÍŶÓÌåÏÖ£¬ËûÃÇ·ÖÎöÁ˸ÿò¼ÜµÄÄ£ºý´¦Öùý³Ì£¬ÒÔÊÓ²ìËüÊÇÈçºÎ´¦Öøñʽ´íÎóµÄͼÏñÎļþ¡£½á¹ûÑо¿ÈËÔ±·¢ÏÖÁË Image I/O ÖдæÔÚ6¸ö©¶´£¬¶øÆ»¹ûÏòµÚÈý·½¹ûÈ»µÄ¸ß¶¯Ì¬·¶Î§£¨HDR£©Í¼ÏñÎļþ¸ñʽ¿ò¼ÜOpenEXRÖдæÔÚ8¸ö©¶´¡£Ä¿Ç°£¬ËùÓЩ¶´¶¼ÒѾ­±»ÐÞ¸´¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/google-discloses-zero-click-bugs-impacting-several-apple-operating-systems/