CNNIC°ä²¼¡¶Öйú»¥ÁªÍøÂç·¢Õ¹Çé¿öͳ¼Æ»ã±¨¡·£»¹È¸è×êÑÐÈËÔ±Åû¶ƻ¹ûImage I/OµÄÁãµã»÷·ì϶

°ä²¼¹¦·ò 2020-04-30

1.CNNIC°ä²¼¡¶Öйú»¥ÁªÍøÂç·¢Õ¹Çé¿öͳ¼Æ»ã±¨¡·


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


4ÔÂ28ÈÕ£¬Öйú»¥ÁªÍøÂçÐÅÏ¢ÖÐÐÄ£¨CNNIC£©°ä²¼Á˵Ú45´Î¡¶Öйú»¥ÁªÍøÂç·¢Õ¹Çé¿öͳ¼Æ»ã±¨¡·¡£´Ë»ã±¨ÝÓÈÆ»¥ÁªÍø»ù´¡½¨Éè¡¢ÍøÃñ¹æÄ£¼°½á¹¹¡¢»¥ÁªÍøÀûÓ÷¢Õ¹¡¢»¥ÁªÍøÕþÎñ·¢Õ¹¡¢²úÒµÓë¼¼Êõ·¢Õ¹ºÍ»¥ÁªÍø°²È«µÈÁù¸ö·½Ã棬×ۺϷ´Ó³2019Äê¼°2020ËêÊ×ÎÒ¹ú»¥ÁªÍø·¢Õ¹Çé¿ö¡£¡¶»ã±¨¡·ÏÔʾ£¬½ØÖÁ2020Äê3Ô£¬ÎÒ¹úÍøÃñ¹æÄ£Îª9.04ÒÚ£¬ÆäÖÐѧÉúÕ¼±È×î¶à£¬Îª26.9%¡£    


Ô­ÎÄÁ´½Ó£º

http://news.china.com.cn/txt/2020-04/28/content_75985166.htm


2.¹È¸è×êÑÐÈËÔ±Åû¶ƻ¹ûImage I/OµÄÁãµã»÷·ì϶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¹È¸èµÄProject Zero ÍŶÓÓÚ±¾ÖܶþÅû¶ÁËApple²Ù×÷ϵͳÖÐÄÚÖõĿò¼ÜImage I/OÖеÄÁãµã»÷·ì϶£¬¸Ã¿ò¼Ü±»ÀûÓÃÓÚiOS¡¢macOS¡¢tvOSºÍwatchOSÖУ¬ÓÃÀ´´¦ÖÃͼÏñÔªÊý¾Ý¡£Project ZeroÍŶӰµÊ¾£¬ËûÃÇ·ÖÎöÁ˸ÿò¼ÜµÄÍÌÍ´¦Öùý³Ì£¬ÒÔ¹Û²ìËüÊÇÈôºÎ´¦ÖÃÌåʽÃýÎóµÄͼÏñÎļþ¡£Á˾Ö×êÑÐÈËÔ±·¢ÏÖÁË Image I/O ÖдæÔÚ6¸ö·ì϶£¬¶øÆ»¹ûÏòµÚÈý·½¹«¿ªµÄ¸ß¶¯Ì¬ÁìÓò£¨HDR£©Í¼ÏñÎļþÌåʽ¿ò¼ÜOpenEXRÖдæÔÚ8¸ö·ì϶¡£Ä¿Ç°£¬ËùÓзì϶¶¼ÒѾ­±»½¨¸´¡£

 

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/google-discloses-zero-click-bugs-impacting-several-apple-operating-systems/


3.×êÑÐÈËÔ±ÔÚ28¿îɱ¶¾Èí¼þÖз¢ÏÖSymlink race·ì϶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


RACK911 LabµÄ×êÑÐÈËÔ±ÔÚÖ÷Á÷²Ù×÷ϵͳ£¨Windows¡¢MacOSºÍLinux£©ÉϵÄ28¿îɱ¶¾Èí¼þÖз¢ÏÖÁËSymlink race·ì϶¡£×êÑÐÈËÔ±°µÊ¾£¬ÊÇɱ¶¾Èí¼þµÄ¹¤×÷·½Ê½µ¼ÖÂÁËÕâÖÖ·ì϶µÄ´æÔÚ¡£É±¶¾Èí¼þµÄɨÃèÖ°ÄܱØÒªµÚÒ»Á÷±ðȨÏÞ£¬²¢ÇÒÔÚɨÃèºÍɾ³ý¶ñÒâÈí¼þÖ®¼ä´æÔÚ¹¦·ò²î£¬ËùÒÔºÚ¿ÍÄܹ»ÀûÓÃÕâ¶Î¹¦·òÒÔ×î¸ßȨÏÞÖ´ÐжñÒâÈí¼þ¡£ºÚ¿ÍÀûÓÃÕâ¸ö·ì϶Äܹ»É¾³ýÖ÷»úÉϵÄÎļþ£¬Ô̺¬É±¶¾Èí¼þºÍ²Ù×÷ϵͳµÄÎļþ£¬Ê¹ÍÆËã»ú±ÀÀ£¡£ÔÚ×êÑÐÈËԱ֪ͨÕâЩɱ¶¾Èí¼þµÄ¿ª·¢ÈËÔ±ºó£¬¸÷¸ö¹«Ë¾¶¼ÒѾ­ÆðÍ·½¨¸´¸Ã·ì϶¡£


Ô­ÎÄÁ´½Ó£º

https://latesthackingnews.com/2020/04/29/researchers-found-symlink-race-bugs-in-popular-antivirus-software/


4.Á½¼ÒUsenet·þÎñ¹«Ë¾²úÉúÊý¾Ýй¶²¢¹éÒòÓÚºÏ×÷ͬ°é


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Á½¼ÒUsenet·þÎñ¹«Ë¾UseNeXTºÍUsenet.nlÓÚ4ÔÂ29ÈÕÅû¶ÁËÆäºÏ×÷¹«Ë¾´æÔÚ°²È«·ì϶£¬²¢ÇҸ÷ì϶µ¼ÖÂÁËÊý¾Ýй¶µÄÎÊÌâ,ĿǰÁ½¼Ò¹«Ë¾¶¼Î´Ö¸³ö´æÔÚ°²È«·ì϶µÄ¹«Ë¾¡£¾ÝÁ½¼Ò¹«Ë¾³Æ£¬Õâ´Îй¶Êý¾ÝÔ̺¬Óû§ÐÕÃû¡¢µØÖ·¡¢Ö§¸¶ÐÅÏ¢£¨IBANºÍÕ˺ţ©ÒÔ¼°Óû§ÔÚ´´½¨ÕÊ»§µÄ¹ý³ÌʹÓõ½µÄÐÅÏ¢¡£UseNeXTºÍUsenet.nl¹«Ë¾°µÊ¾£¬Óû§±ØÒªÒªÔÚÍøÕ¾¸´Ô­ºó³ÁÖÃÕÊ»§ÃÜÂ룬²¢²é¿´ËùÓÐUsenetÕÊ»§ÉèÖÃÒÔ·ÀÓÐδ¾­ÊÚȨµÄ¸ü¸Ä¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/two-usenet-providers-blame-data-breaches-on-partner-company/


5.Ó¢¹ú×Ô¶¯³µÅƼø±ðϵͳй¶½ü900Íò¹«ÃñÐгµÊý¾Ý


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ó¢¹úл·Æ¶ûµÂÊеÄ×Ô¶¯³µÅÆÏµÍ³£¨ANPR£©Ð¹Â¶ÁË860ÍòÌõ¹«Â·Ðгµ¼Í¼£¬¸ÃÎÊÌâ¿É±»ºÚ¿ÍÀûÓÃαÔìÌØ¶¨³µÁ¾µÄÐгÌ¡£ANPRµÄÄÚ²¿ÖÎÀí½çÃæÄܹ»Í¨¹ýÔÚä¯ÀÀÆ÷ÖÐÊäÈëIPµØÖ·½Ó¼û£¬²¢ÇÒ²»±ØÒªÈκεǼºÍÑéÖ¤ÐÅÏ¢£¬¼´¿É²é¿´ºÍËÑË÷ʵʱÊý¾Ý¡£¶øºÚ¿ÍÄܹ»Í¨¹ý´Û¸ÄϵͳÖеÄÉãÏñÍ·Ãû³Æ¡¢µØÎ»µÈ¹Ø¼üÐÅÏ¢À´Î±Ôì³µÁ¾ÐгÌ¡£Ð»·Æ¶ûµÂÊÐÒé»áÔÚ¸ÃÊÂÎñ²úÉúºóµ±¼´²ÉÈ¡ÁËÓ¦¼±´ëÊ©£¬²¢½«¸ÃϵͳÍÑ»úά½¨¡£


Ô­ÎÄÁ´½Ó£º

https://www.theregister.co.uk/2020/04/28/anpr_sheffield_council/


6.ÓÃÓÚSD-WAN·ÓÉÆ÷µÄµÄCiscoÈí¼þIOS XE´æÔÚ·ì϶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÓÃÓÚSD-WAN·ÓÉÆ÷µÄµÄCiscoÈí¼þIOS XE´æÔÚÊäÈëÑéÖ¤²»¼°·ì϶£¨CVE-2019-16011£¬CVSS 3.0ÆÀ·ÖΪ7.8£©£¬¸Ã·ì϶Äܹ»Ê¹±¾µØµÄ¡¢¾­¹ýÉí·ÝÑéÖ¤µÄ¹¥»÷ÕßÒÔrootȨÏÞÖ´ÐÐËÁÒâºÅÁî¡£´Ë·ì϶´æÔÚÓÚLinux°æ±¾µÄSD-WAN·ÓÉÆ÷ÖУ¬Ó°ÏìÁ˾ۺϷþÎñ·ÓÉÆ÷£¨ASR£©1000ϵÁУ¬¼¯³É·þÎñ·ÓÉÆ÷£¨ISR£©1000ϵÁУ¬ISR 4000ϵÁкÍÔÆ·þÎñ·ÓÉ1000VϵÁУ¬ÕâЩ·ÓÉÆ÷Ŀǰ¶¼ÊÇÓ×ÐÍÆóÒµÔÚʹÓ᣸÷ì϶λÓÚÅäÖÃÍøÂçÉ豸µÄCisco IOX XEºÅÁîÐнçÃæ£¨CLI£©ÖУ¬Ô­ÒòÊÇCLIûÓгä·ÖÑéÖ¤ÊäÈëºÅÁî¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/cisco-ios-xe-flaw-sd-wan-routers/155319/