ÐÅÏ¢°²È«Öܱ¨-2020ÄêµÚ18ÖÜ

°ä²¼¹¦·ò 2020-05-06

> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2020Äê04ÔÂ27ÈÕÖÁ05ÔÂ03ÈÕ¹²ÊÕ¼°²È«·ì϶70¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇSaltStack Salt salt-master process ClearFuncs²»ÕýȷУÑé²½ÖèŲÓ÷ì϶; Apache IoTDB 31999¶Ë¿ÚδÊÚȨ½Ó¼û·ì϶£»Adobe Bridge¶à¸öÔ½½çд´úÂëÖ´Ðзì϶£»Google OpenThread MeshCoP::Commissioner::GeneratePskc»º³åÇøÒç¶Âí½Å£»BMC Control-M/Agent OSºÅÁî×¢Èë·ì϶¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇSophos´¹Î£½¨¸´·À»ðǽÖеÄSQL×¢Èë0day£¬Òѱ»Ò°±íÀûÓã»ÍøÐŰìµÈ12¸ö²¿ÃŽáºÏ°ä²¼¡¶ÍøÂ簲ȫÉó²é·¨×Ó¡·£»Adobe°ä²¼´¹Î£²¹¶¡£¬½¨¸´Æä3¿î²úÆ·ÖеÄ35¸ö·ì϶£»CNNIC°ä²¼¡¶Öйú»¥ÁªÍøÂç·¢Õ¹Çé¿öͳ¼Æ»ã±¨¡·£»¹È¸è×êÑÐÈËÔ±Åû¶ƻ¹ûImage I/OµÄÁãµã»÷·ì϶¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖС£


>³ÁÒª°²È«·ì϶Áбí


1. SaltStack Salt salt-master process ClearFuncs²»ÕýȷУÑé²½ÖèŲÓ÷ì϶


SaltStack Salt salt-master process ClearFuncs²»ÕýȷУÑé²½ÖèŲÓã¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ɻñÈ¡Óû§ÁîÅÆ£¬Î´ÊÚȨ½Ó¼û²¢Ö´ÐкÅÁî¡£

https://docs.saltstack.com/en/latest/topics/releases/2019.2.4.html


2. Apache IoTDB 31999¶Ë¿ÚδÊÚȨ½Ó¼û·ì϶


Apache IoTDB JMX 31999¶Ë¿Ú´æÔÚδÊÚȨ·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉδÊÚȨ½Ó¼û²¢Ö´ÐÐËÁÒâ´úÂë¡£

https://lists.apache.org/thread.html/r3d2ff899ead64d2952fdc1fbb1f520ca42011ed2b4c7f786e921f6b9%40%3Cdev.iotdb.apache.org%3E


3. Adobe Bridge¶à¸öÔ½½çд´úÂëÖ´Ðзì϶


Adobe Bridge´¦ÖÃÎļþ´æÔÚÔ½½çд·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£

https://helpx.adobe.com/security/products/bridge/apsb20-19.html


4. Google OpenThread MeshCoP::Commissioner::GeneratePskc»º³åÇøÒç¶Âí½Å


Google OpenThread MeshCoP::Commissioner::GeneratePskc´æÔÚ»º³åÇøÒç¶Âí½Å£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£

https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=19386


5. BMC Control-M/Agent OSºÅÁî×¢Èë·ì϶


ʹÓÃTCPºÍ̸ʱBMC Control-M/Agent´æÔÚÊäÈëÑéÖ¤·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿É×¢ÈëËÁÒâOSºÅÁî¡£

https://herolab.usd.de/security-advisories/usd-2019-0064/


> ³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢Sophos´¹Î£½¨¸´·À»ðǽÖеÄSQL×¢Èë0day£¬Òѱ»Ò°±íÀûÓÃ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÍøÂ簲ȫ¹«Ë¾SophosÓÚÖÜÁù°ä²¼ÁË´¹Î£²¹¶¡ÒÔ½¨¸´ÒѾ­±»Ò°±íÀûÓõÄSQL×¢Èë0day£¬¸Ã·ì϶ӰÏìÁËÆäXG Firewall²úÆ·¡£4ÔÂ22ÈÕÍí£¬Sophos¹«Ë¾·¢ÏÖºÚ¿ÍÀûÓÃXG FirewallÖеÄSQL×¢Èë·ì϶ÇÔÈ¡Á˸ÃÉ豸ÖеÄÊý¾Ý£¬Ô̺¬·À»ðǽÉ豸ÖÎÀíÔ¹ØË»§¡¢·À»ðǽÃÅ»§ÍøÕ¾ÖÎÀíÔ¹ØË»§ºÍÔ¶³Ì½Ó¼ûÉ豸ÕË»§ÖеĵÄÓû§ÃûºÍ¹þÏ£ÃÜÂë¡£¸Ã¹«Ë¾°µÊ¾Õâ´Î¸üÐÂÒѾ­½¨¸´Á˸ÃSQL×¢Èë·ì϶£¬²¢ÇÒмÓÁËÌØÊâÌáÐÑÖ°ÄÜʹ¿Í»§ÖªÂ·ÆäÉ豸ÊÇ·ñÊܵ½ÁËÍþв¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/hackers-are-exploiting-a-sophos-firewall-zero-day/


2¡¢ÍøÐŰìµÈ12¸ö²¿ÃŽáºÏ°ä²¼¡¶ÍøÂ簲ȫÉó²é·¨×Ó¡·


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ô­ÎÄÁ´½Ó£º

http://www.cac.gov.cn/2020-04/27/c_1589535450769077.htm


3¡¢Adobe°ä²¼´¹Î£²¹¶¡£¬½¨¸´Æä3¿î²úÆ·ÖеÄ35¸ö·ì϶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Èí¼þ¹«Ë¾AdobeÓÚ4ÔÂ28ÈÕ°ä²¼´¹Î£·ì϶²¹¶¡£¬×ܹ²½¨¸´ÁË35¸ö·ì϶£¬ÕâЩ·ì϶ӰÏìµÄ²úÆ·ÓÐAdobe Illustrator¡¢Adobe BridgeºÍµçÉÌÆ½Ì¨Magento¡£Õâ´Î°²È«¸üн¨¸´ÁËWindows°æ±¾Illustrator 2020ÖеÄ5¸ö´úÂëÖ´Ðзì϶£¬Adobe Bridge 10.0.1¼°¸üÔç°æ±¾ÖеÄ17¸ö·ì϶£¨14¸ö¿Éµ¼Ö´úÂëÖ´Ðзì϶£¬3¸öÓйØÐÅϢй¶ÎÊÌ⣩£¬Ã³Ò×°æ±¾ºÍ¿ªÔ´°æ±¾µÄMagento CMSÖеÄ13¸ö·ì϶¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2020/04/adobe-software-updates.html


4¡¢CNNIC°ä²¼¡¶Öйú»¥ÁªÍøÂç·¢Õ¹Çé¿öͳ¼Æ»ã±¨¡·


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ô­ÎÄÁ´½Ó£º

http://news.china.com.cn/txt/2020-04/28/content_75985166.htm


5¡¢¹È¸è×êÑÐÈËÔ±Åû¶ƻ¹ûImage I/OµÄÁãµã»÷·ì϶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¹È¸èµÄProject Zero ÍŶÓÓÚ±¾ÖܶþÅû¶ÁËApple²Ù×÷ϵͳÖÐÄÚÖõĿò¼ÜImage I/OÖеÄÁãµã»÷·ì϶£¬¸Ã¿ò¼Ü±»ÀûÓÃÓÚiOS¡¢macOS¡¢tvOSºÍwatchOSÖУ¬ÓÃÀ´´¦ÖÃͼÏñÔªÊý¾Ý¡£Project ZeroÍŶӰµÊ¾£¬ËûÃÇ·ÖÎöÁ˸ÿò¼ÜµÄÍÌÍ´¦Öùý³Ì£¬ÒÔ¹Û²ìËüÊÇÈôºÎ´¦ÖÃÌåʽÃýÎóµÄͼÏñÎļþ¡£Á˾Ö×êÑÐÈËÔ±·¢ÏÖÁË Image I/O ÖдæÔÚ6¸ö·ì϶£¬¶øÆ»¹ûÏòµÚÈý·½¹«¿ªµÄ¸ß¶¯Ì¬ÁìÓò£¨HDR£©Í¼ÏñÎļþÌåʽ¿ò¼ÜOpenEXRÖдæÔÚ8¸ö·ì϶¡£Ä¿Ç°£¬ËùÓзì϶¶¼ÒѾ­±»½¨¸´¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/google-discloses-zero-click-bugs-impacting-several-apple-operating-systems/