ÐÅÏ¢Çå¾²Öܱ¨-2020ÄêµÚ17ÖÜ
Ðû²¼Ê±¼ä 2020-04-28> ±¾ÖÜÇ徲̬ÊÆ×ÛÊö
2020Äê04ÔÂ20ÈÕÖÁ26ÈÕ¹²ÊÕ¼Çå¾²Îó²î54¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇApple macOS Mail Javascript´úÂëÖ´ÐÐÎó²î; Google Chrome paymentsÄÚ´æ¹ýʧÒýÓôúÂëÖ´ÐÐÎó²î£»Sonatype Nexus Repository ManagerȨÏÞÌáÉýÎó²î£»Í¨´ïOAí§ÒâÓû§µÇ¼Îó²î£»Contiki-NGÔ½½çд´úÂëÖ´ÐÐÎó²î¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊǼÓÄôó¶ùͯÓÎÏ·ÍøÕ¾Webkinz½ü2300ÍòÓû§Êý¾Ýй¶£»FPGAоƬStarbleedÎó²î£¬Ó°ÏìÈüÁé˼¶à¸ö²úÆ·£»CNCERTÐû²¼¡¶2019ÄêÎÒ¹ú»¥ÁªÍøÍøÂçÇ徲̬ÊÆ×ÛÊö¡·±¨¸æ£»Ñо¿Ö°Ô±Åû¶IBMÆóÒµÇå¾²Èí¼þÖеÄ4¸ö0day£»Î¢ÈíÐû²¼½ôÆȸüУ¬ÐÞ¸´OfficeºÍPaint 3DÖжà¸öÎó²î¡£
ƾ֤ÒÔÉÏ×ÛÊö£¬±¾ÖÜÇå¾²ÍþвΪÖС£
>Ö÷ÒªÇå¾²Îó²îÁбí
1. Apple macOS Mail Javascript´úÂëÖ´ÐÐÎó²î
Apple macOS Mail±£´æ´úÂë×¢ÈëÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§ÒâJavaScript´úÂë¡£¡£
https://support.apple.com/en-us/HT211100
2. Google Chrome paymentsÄÚ´æ¹ýʧÒýÓôúÂëÖ´ÐÐÎó²î
Google Chrome payments±£´æÊͷźóʹÓÃÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄWEBÇëÇó£¬ÓÕʹÓû§ÆÊÎö£¬¿É¾ÙÐоܾø·þÎñ¹¥»÷»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§ÒâÂë¡£
https://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop_21.html
3. Sonatype Nexus Repository ManagerȨÏÞÌáÉýÎó²î
Sonatype Nexus Repository ManagerʵÏÖ±£´æÇå¾²Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉÌáÉýÌØȨ£¬¾ÙÐн¨É裬Ð޸ģ¬Ö´ÐÐʹÃü¡£
https://support.sonatype.com/hc/en-us/articles/360046233714
4. ͨ´ïOAí§ÒâÓû§µÇ¼Îó²î
ͨ´ïOAµÇ¼ʵÏÖ±£´æÇå¾²Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔí§ÒâÓû§ÉÏÏÂÎĵǼ¡£
https://cert.360.cn/warning/detail?id=d2689a877c01a9712d148317c2da21a2
5. Contiki-NGÔ½½çд´úÂëÖ´ÐÐÎó²î
Contiki-NG os/net/ipv6/sicslowpan.cÔÚ´¦Öóͷ£6LoWPAN·ÖƬÖØ×é±£´æÔ½½çдÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉʹӦÓóÌÐò±ÀÀ£»òÖ´ÐÐí§Òâ´úÂë¡£
https://github.com/contiki-ng/contiki-ng/pull/972
1¡¢¼ÓÄôó¶ùͯÓÎÏ·ÍøÕ¾Webkinz½ü2300ÍòÓû§Êý¾Ýй¶
¼ÓÄôóÖøÃûÍæ¾ß¹«Ë¾GanzÆìϵĶùͯÓÎÏ·ÍøÕ¾WebkinzÔâµ½ºÚ¿ÍÈëÇÖ£¬½ü2300ÍòÍæ¼ÒµÄÓû§ÃûºÍÃÜÂëй¶£¬ÆäÖÐ鶵ÄÃÜÂëʹÓÃÁËMD5-CryptËã·¨¼ÓÃÜ¡£¾ÝZDNet±¨µÀ£¬ºÚ¿ÍÊÇʹÓÃÍøÕ¾ÖеÄSQL×¢ÈëÎó²îÈëÇÖÓÎÏ·Êý¾Ý¿âµÄ£¬¾Ý³Æ¸ÃÎó²îµÄϸ½ÚÒÑÔÚºÚ¿ÍÂÛ̳ÖÐÈö²¥Á˼¸¸öÔ¡£ºÚ¿Í¿ÉÄÜ»¹ÍµÈ¡Á˹þÏ£¼ÓÃܵĵç×ÓÓʼþµØµã¡£ÐÂÎÅÈËÊ¿³ÆWebkinzÔ±¹¤ÒѾÐÞ¸´Á˺ڿÍʹÓõÄÎó²î£¬µ«GanzÉÐδ¶Ô´ËÊÂÎñ¾ÙÐлØÓ¦¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/hacker-leaks-23-million-usernames-and-passwords-from-webkinz-childrens-game/
2¡¢FPGAоƬStarbleedÎó²î£¬Ó°ÏìÈüÁé˼¶à¸ö²úÆ·
Ñо¿Ö°Ô±·¢Ã÷FPGAоƬ±£´æStarbleedÎó²î£¬Ó°ÏìÁËÈüÁé˼7ϵÁеÄSpartan¡¢Artix¡¢Kintex¡¢Virtex×ÓϵÁжà¸ö²úÆ·¡£ÓÉÓÚÎó²îΪӲ¼þ¼¶±ðÎó²î£¬Òò¶øÖ»ÄÜͨ¹ýÌ滻оƬÀ´ÐÞ¸´Îó²î¡£Çå¾²Ñо¿Ö°Ô±·¢Ã÷¿ÉÒÔͨ¹ý½âÃܱ»¼ÓÃܵıÈÌØÁ÷À´»á¼ûºÍÐÞ¸ÄÓÃÓÚ±à³ÌµÄÎļþ¡£Òò´Ë£¬ºÚ¿Í¿ÉÒÔʹÓøÃÎó²îÍêÈ«¿ØÖÆFPGAоƬ£¬²¢ÇÒ¿ÉÄÜ͵ȡ±ÈÌØÁ÷ÖеÄ֪ʶ²úȨ¡£µÂ¹úMax PlanckÑо¿ËùµÄChristof Paar½ÌÊÚÌåÏÖ£¬¹¥»÷ÕßÉõÖÁ¿ÉÒÔ¾ÙÐÐÔ¶³Ì¹¥»÷£¬»òÊÇÏòFPGAоƬֲÈëÓ²¼þľÂí¡£
ÔÎÄÁ´½Ó£º
https://www.helpnetsecurity.com/2020/04/20/starbleed-vulnerability/
3¡¢CNCERTÐû²¼¡¶2019ÄêÎÒ¹ú»¥ÁªÍøÍøÂçÇ徲̬ÊÆ×ÛÊö¡·±¨¸æ
¹ú¼Ò»¥ÁªÍøÓ¦¼±ÖÐÐÄ£¨CNCERT£©ÓÚ2020Äê4ÔÂ20ÈÕÐû²¼ÁË¡¶2019ÄêÎÒ¹ú»¥ÁªÍøÍøÂçÇ徲̬ÊÆ×ÛÊö¡·±¨¸æ¡£¸Ã±¨¸æפ×ãÓÚCNCERTÍøÂçÇå¾²ºê¹Û¼à²âÊý¾ÝÓëÊÂÇéʵ¼ù±¨¸æ£¬Éæ¼°2019Äêµä·¶ÍøÂçÇå¾²ÊÂÎñ¡¢ÍøÂçÇå¾²ÐÂÇ÷ÊƼ°Ò»Ñùƽ³£ÍøÂçÇå¾²ÊÂÎñÓ¦¼±´¦Öóͷ£Êµ¼ùµÈÄÚÈÝ¡£±¨¸æÖ÷Òª°üÀ¨Ëĸö²¿·Ö£¬Ò»ÊÇ×ܽá2019ÄêÎÒ¹ú»¥ÁªÍøÍøÂçÇ徲״̬£¬¶þÊÇÕ¹Íû2020ÄêÍøÂçÇå¾²ÈÈÃÅ£¬ÈýÊÇÍŽáÍøÂçÇ徲̬ÊÆÆÊÎöÌá³ö¶Ô²ß½¨Ò飬ËÄÊÇÊáÀíÍøÂçÇå¾²¼à²âÊý¾Ý¡£¸Ã±¨¸æ¶ÔÎÒ¹úµ³Õþ»ú¹Ø¡¢ÐÐÒµÆóÒµ¼°È«Éç»áÏàʶÎÒ¹úÍøÂçÇå¾²ÐÎÊÆ£¬Ìá¸ßÍøÂçÇå¾²Òâʶ£¬×öºÃÍøÂçÇå¾²ÊÂÇéÌṩÁËÓÐÁ¦²Î¿¼¡£
ÔÎÄÁ´½Ó£º
http://www.cac.gov.cn/2020-04/20/c_1588932297982643.htm
4¡¢Ñо¿Ö°Ô±Åû¶IBMÆóÒµÇå¾²Èí¼þÖеÄ4¸ö0day
Çå¾²Ñо¿Ö°Ô±ÔÚÆÊÎöIBM Data Risk Manager£¨IDRM£©Ê±·¢Ã÷ÁË4¸ö0day£¬»®·ÖΪÉí·ÝÑéÖ¤ÈƹýÎó²î¡¢ÏÂÁî×¢ÈëÎó²î¡¢²»Çå¾²µÄĬÈÏÃÜÂëÎó²îÒÔ¼°í§ÒâÎļþÏÂÔØÎó²î¡£ÕâЩÎó²î¿ÉÒÔµ¥¶ÀʹÓÃÒ²¿ÉÒÔ×éºÏʹÓã¬×éºÏʹÓÃÇ°Èý¸öÎó²î¿ÉÒÔʹ¹¥»÷ÕßÒÔrootȨÏÞÔ¶³ÌÖ´ÐдúÂ룬×éºÏʹÓõÚÒ»¸öºÍµÚËĸöÎó²î¿ÉÒÔʹδÊÚȨµÄ¹¥»÷ÕßÏÂÔØí§ÒâÎļþ¡£Îó²îµÄÅû¶ÕßRibeiroÌåÏÖ£¬IDRMÊÇ´¦Öóͷ£Ãô¸ÐÐÅÏ¢µÄÆóÒµÇå¾²²úÆ·£¬ÈôÊÇÆäÔâµ½¹¥»÷»áµ¼Ö¹«Ë¾ÀûÒæÑÏÖØÊÜËð£¬Òò´ËÔÚIBM¾Ü¾ø½ÓÊÜÎó²î±¨¸æºóÑ¡Ôñ½«ÆäÐû²¼³öÀ´¡£ÏÖÔÚ£¬IBM¹«Ë¾ÐÞ¸´ÁËIDRM2.0.1¼°¸ü¸ß°æ±¾ÖеÄí§ÒâÎļþÏÂÔØÎó²îºÍÏÂÁî×¢ÈëÎó²î£¬²¢ÇÒÕýÔÚÊÓ²ìÉí·ÝÑéÖ¤ÈƹýÎó²î¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/researcher-discloses-four-ibm-zero-days-after-refusal-to-fix/
5¡¢Î¢ÈíÐû²¼½ôÆȸüУ¬ÐÞ¸´OfficeºÍPaint 3DÖжà¸öÎó²î
MicrosoftÐû²¼Á˽ôÆÈÇå¾²¸üУ¬ÒÔÐÞ¸´Ê¹ÓÃÁËAutodesk FBX¿âµÄMicrosoft²úÆ·£¬°üÀ¨¶à¸ö°æ±¾µÄMicrosoft OfficeºÍWindows 10Ó¦ÓóÌÐòPaint 3D¡£±¾´ÎÐÞ¸´µÄÎó²îΪFBX¿âÖеÄÔ¶³ÌÖ´ÐдúÂëÎó²î£¬¹¥»÷ÕßʹÓôËÎó²î¿ÉÒÔ»ñµÃÓëÍâµØÓû§ÏàͬµÄȨÏÞ£¬AutodeskÔÚ4ÔÂ15ÈÕÍƳöÁËÕë¶Ô´ËÎó²îµÄ²¹¶¡³ÌÐò¡£MicrosoftÌåÏÖ£¬ºÚ¿Í±ØÐèÓÕʹÓû§·¿ªÆäÌØÖƵÄ3DÎļþ²Å¿ÉÒÔÀÖ³ÉʹÓôËÎó²î£¬Òò´Ë£¬ÔÚÇå¾²¸üÐÂ֮ǰÓû§ÐèÒªÔ¶ÀëÄÇЩ¿ÉÒÉÎļþÒÔ°ü¹ÜÇå¾²¡£
ÔÎÄÁ´½Ó£º
https://news.softpedia.com/news/microsoft-releases-emergency-update-for-windows-10-app-microsoft-office-529800.shtml