ÐÅÏ¢Çå¾²Öܱ¨-2020ÄêµÚ17ÖÜ

Ðû²¼Ê±¼ä 2020-04-28

> ±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


2020Äê04ÔÂ20ÈÕÖÁ26ÈÕ¹²ÊÕ¼Çå¾²Îó²î54¸ö£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇApple macOS Mail Javascript´úÂëÖ´ÐÐÎó²î; Google Chrome paymentsÄÚ´æ¹ýʧÒýÓôúÂëÖ´ÐÐÎó²î£»£»£»£» £»Sonatype Nexus Repository ManagerȨÏÞÌáÉýÎó²î£»£»£»£» £»Í¨´ïOAí§ÒâÓû§µÇ¼Îó²î£»£»£»£» £»Contiki-NGÔ½½çд´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊǼÓÄôó¶ùͯÓÎÏ·ÍøÕ¾Webkinz½ü2300ÍòÓû§Êý¾Ýй¶£»£»£»£» £»FPGAоƬStarbleedÎó²î£¬£¬£¬£¬£¬Ó°ÏìÈüÁé˼¶à¸ö²úÆ·£»£»£»£» £»CNCERTÐû²¼¡¶2019ÄêÎÒ¹ú»¥ÁªÍøÍøÂçÇå¾²Ì¬ÊÆ×ÛÊö¡·±¨¸æ£»£»£»£» £»Ñо¿Ö°Ô±Åû¶IBMÆóÒµÇå¾²Èí¼þÖеÄ4¸ö0day£»£»£»£» £»Î¢ÈíÐû²¼½ôÆÈ¸üУ¬£¬£¬£¬£¬ÐÞ¸´OfficeºÍPaint 3DÖжà¸öÎó²î¡£¡£¡£¡£¡£¡£¡£


ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£¡£¡£¡£


>Ö÷ÒªÇå¾²Îó²îÁбí


1. Apple macOS Mail Javascript´úÂëÖ´ÐÐÎó²î


Apple macOS Mail±£´æ´úÂë×¢ÈëÎó²î£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§ÒâJavaScript´úÂë¡£¡£¡£¡£¡£¡£¡£¡£¡£¡£¡£¡£¡£¡£

https://support.apple.com/en-us/HT211100


2. Google Chrome paymentsÄÚ´æ¹ýʧÒýÓôúÂëÖ´ÐÐÎó²î


Google Chrome payments±£´æÊͷźóʹÓÃÎó²î£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄWEBÇëÇ󣬣¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬£¬¿É¾ÙÐоܾøÐ§À͹¥»÷»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§ÒâÂë¡£¡£¡£¡£¡£¡£¡£

https://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop_21.html


3. Sonatype Nexus Repository ManagerȨÏÞÌáÉýÎó²î


Sonatype Nexus Repository ManagerʵÏÖ±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬¿ÉÌáÉýÌØÈ¨£¬£¬£¬£¬£¬¾ÙÐн¨É裬£¬£¬£¬£¬Ð޸쬣¬£¬£¬£¬Ö´ÐÐʹÃü¡£¡£¡£¡£¡£¡£¡£

https://support.sonatype.com/hc/en-us/articles/360046233714


4. ͨ´ïOAí§ÒâÓû§µÇ¼Îó²î


ͨ´ïOAµÇ¼ʵÏÖ±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬¿ÉÒÔí§ÒâÓû§ÉÏÏÂÎĵǼ¡£¡£¡£¡£¡£¡£¡£

https://cert.360.cn/warning/detail?id=d2689a877c01a9712d148317c2da21a2


5. Contiki-NGÔ½½çд´úÂëÖ´ÐÐÎó²î


Contiki-NG os/net/ipv6/sicslowpan.cÔÚ´¦Öóͷ£6LoWPAN·ÖÆ¬ÖØ×é±£´æÔ½½çдÎó²î£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬¿ÉʹӦÓóÌÐòÍ߽⻣»£»£» £»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£

https://github.com/contiki-ng/contiki-ng/pull/972


> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢¼ÓÄôó¶ùͯÓÎÏ·ÍøÕ¾Webkinz½ü2300ÍòÓû§Êý¾Ýй¶


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


¼ÓÄôóÖøÃûÍæ¾ß¹«Ë¾GanzÆìϵĶùͯÓÎÏ·ÍøÕ¾WebkinzÔâµ½ºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬½ü2300ÍòÍæ¼ÒµÄÓû§ÃûºÍÃÜÂëй¶£¬£¬£¬£¬£¬ÆäÖÐй¶µÄÃÜÂëʹÓÃÁËMD5-CryptËã·¨¼ÓÃÜ¡£¡£¡£¡£¡£¡£¡£¾ÝZDNet±¨µÀ£¬£¬£¬£¬£¬ºÚ¿ÍÊÇʹÓÃÍøÕ¾ÖеÄSQL×¢ÈëÎó²îÈëÇÖÓÎÏ·Êý¾Ý¿âµÄ£¬£¬£¬£¬£¬¾Ý³Æ¸ÃÎó²îµÄϸ½ÚÒÑÔÚºÚ¿ÍÂÛ̳ÖÐÈö²¥Á˼¸¸öÔ¡£¡£¡£¡£¡£¡£¡£ºÚ¿Í¿ÉÄÜ»¹ÍµÈ¡Á˹þÏ£¼ÓÃܵĵç×ÓÓʼþµØµã¡£¡£¡£¡£¡£¡£¡£ÐÂÎÅÈËÊ¿³ÆWebkinzÔ±¹¤ÒѾ­ÐÞ¸´Á˺ڿÍʹÓõÄÎó²î£¬£¬£¬£¬£¬µ«GanzÉÐδ¶Ô´ËÊÂÎñ¾ÙÐлØÓ¦¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/hacker-leaks-23-million-usernames-and-passwords-from-webkinz-childrens-game/


2¡¢FPGAоƬStarbleedÎó²î£¬£¬£¬£¬£¬Ó°ÏìÈüÁé˼¶à¸ö²úÆ·


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Ñо¿Ö°Ô±·¢Ã÷FPGAоƬ±£´æStarbleedÎó²î£¬£¬£¬£¬£¬Ó°ÏìÁËÈüÁé˼7ϵÁеÄSpartan¡¢Artix¡¢Kintex¡¢Virtex×ÓϵÁжà¸ö²úÆ·¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚÎó²îΪӲ¼þ¼¶±ðÎó²î£¬£¬£¬£¬£¬Òò¶øÖ»ÄÜͨ¹ýÌæ»»Ð¾Æ¬À´ÐÞ¸´Îó²î¡£¡£¡£¡£¡£¡£¡£Çå¾²Ñо¿Ö°Ô±·¢Ã÷¿ÉÒÔͨ¹ý½âÃܱ»¼ÓÃܵıÈÌØÁ÷À´»á¼ûºÍÐÞ¸ÄÓÃÓÚ±à³ÌµÄÎļþ¡£¡£¡£¡£¡£¡£¡£Òò´Ë£¬£¬£¬£¬£¬ºÚ¿Í¿ÉÒÔʹÓøÃÎó²îÍêÈ«¿ØÖÆFPGAоƬ£¬£¬£¬£¬£¬²¢ÇÒ¿ÉÄÜ͵ȡ±ÈÌØÁ÷ÖеÄ֪ʶ²úȨ¡£¡£¡£¡£¡£¡£¡£µÂ¹úMax PlanckÑо¿ËùµÄChristof Paar½ÌÊÚÌåÏÖ£¬£¬£¬£¬£¬¹¥»÷ÕßÉõÖÁ¿ÉÒÔ¾ÙÐÐÔ¶³Ì¹¥»÷£¬£¬£¬£¬£¬»òÊÇÏòFPGAоƬֲÈëÓ²¼þľÂí¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.helpnetsecurity.com/2020/04/20/starbleed-vulnerability/


3¡¢CNCERTÐû²¼¡¶2019ÄêÎÒ¹ú»¥ÁªÍøÍøÂçÇå¾²Ì¬ÊÆ×ÛÊö¡·±¨¸æ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


¹ú¼Ò»¥ÁªÍøÓ¦¼±ÖÐÐÄ£¨CNCERT£©ÓÚ2020Äê4ÔÂ20ÈÕÐû²¼ÁË¡¶2019ÄêÎÒ¹ú»¥ÁªÍøÍøÂçÇå¾²Ì¬ÊÆ×ÛÊö¡·±¨¸æ¡£¡£¡£¡£¡£¡£¡£¸Ã±¨¸æ×¤×ãÓÚCNCERTÍøÂçÇå¾²ºê¹Û¼à²âÊý¾ÝÓëÊÂÇéʵ¼ù±¨¸æ£¬£¬£¬£¬£¬Éæ¼°2019Äêµä·¶ÍøÂçÇå¾²ÊÂÎñ¡¢ÍøÂçÇå¾²ÐÂÇ÷ÊÆ¼°Ò»Ñùƽ³£ÍøÂçÇå¾²ÊÂÎñÓ¦¼±´¦Öóͷ£Êµ¼ùµÈÄÚÈÝ¡£¡£¡£¡£¡£¡£¡£±¨¸æÖ÷Òª°üÀ¨Ëĸö²¿·Ö£¬£¬£¬£¬£¬Ò»ÊÇ×ܽá2019ÄêÎÒ¹ú»¥ÁªÍøÍøÂçÇ徲״̬£¬£¬£¬£¬£¬¶þÊÇÕ¹Íû2020ÄêÍøÂçÇå¾²ÈÈÃÅ£¬£¬£¬£¬£¬ÈýÊÇÁ¬ÏµÍøÂçÇå¾²Ì¬ÊÆÆÊÎöÌá³ö¶Ô²ß½¨Ò飬£¬£¬£¬£¬ËÄÊÇÊáÀíÍøÂçÇå¾²¼à²âÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¸Ã±¨¸æ¶ÔÎÒ¹úµ³Õþ»ú¹Ø¡¢ÐÐÒµÆóÒµ¼°È«Éç»áÏàʶÎÒ¹úÍøÂçÇå¾²ÐÎÊÆ£¬£¬£¬£¬£¬Ìá¸ßÍøÂçÇå¾²Òâʶ£¬£¬£¬£¬£¬×öºÃÍøÂçÇå¾²ÊÂÇéÌṩÁËÓÐÁ¦²Î¿¼¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

http://www.cac.gov.cn/2020-04/20/c_1588932297982643.htm


4¡¢Ñо¿Ö°Ô±Åû¶IBMÆóÒµÇå¾²Èí¼þÖеÄ4¸ö0day


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Çå¾²Ñо¿Ö°Ô±ÔÚÆÊÎöIBM Data Risk Manager£¨IDRM£©Ê±·¢Ã÷ÁË4¸ö0day£¬£¬£¬£¬£¬»®·ÖΪÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î¡¢ÏÂÁî×¢ÈëÎó²î¡¢²»Çå¾²µÄĬÈÏÃÜÂëÎó²îÒÔ¼°í§ÒâÎļþÏÂÔØÎó²î¡£¡£¡£¡£¡£¡£¡£ÕâЩÎó²î¿ÉÒÔµ¥¶ÀʹÓÃÒ²¿ÉÒÔ×éºÏʹÓ㬣¬£¬£¬£¬×éºÏʹÓÃǰÈý¸öÎó²î¿ÉÒÔʹ¹¥»÷ÕßÒÔrootȨÏÞÔ¶³ÌÖ´ÐдúÂ룬£¬£¬£¬£¬×éºÏʹÓõÚÒ»¸öºÍµÚËĸöÎó²î¿ÉÒÔʹδÊÚȨµÄ¹¥»÷ÕßÏÂÔØí§ÒâÎļþ¡£¡£¡£¡£¡£¡£¡£Îó²îµÄÅû¶ÕßRibeiroÌåÏÖ£¬£¬£¬£¬£¬IDRMÊÇ´¦Öóͷ£Ãô¸ÐÐÅÏ¢µÄÆóÒµÇå¾²²úÆ·£¬£¬£¬£¬£¬ÈôÊÇÆäÔâµ½¹¥»÷»áµ¼Ö¹«Ë¾ÀûÒæÑÏÖØÊÜË𣬣¬£¬£¬£¬Òò´ËÔÚIBM¾Ü¾ø½ÓÊÜÎó²î±¨¸æºóÑ¡Ôñ½«ÆäÐû²¼³öÀ´¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬IBM¹«Ë¾ÐÞ¸´ÁËIDRM2.0.1¼°¸ü¸ß°æ±¾ÖеÄí§ÒâÎļþÏÂÔØÎó²îºÍÏÂÁî×¢ÈëÎó²î£¬£¬£¬£¬£¬²¢ÇÒÕýÔÚÊÓ²ìÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/researcher-discloses-four-ibm-zero-days-after-refusal-to-fix/


5¡¢Î¢ÈíÐû²¼½ôÆÈ¸üУ¬£¬£¬£¬£¬ÐÞ¸´OfficeºÍPaint 3DÖжà¸öÎó²î


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


MicrosoftÐû²¼Á˽ôÆÈÇå¾²¸üУ¬£¬£¬£¬£¬ÒÔÐÞ¸´Ê¹ÓÃÁËAutodesk FBX¿âµÄMicrosoft²úÆ·£¬£¬£¬£¬£¬°üÀ¨¶à¸ö°æ±¾µÄMicrosoft OfficeºÍWindows 10Ó¦ÓóÌÐòPaint 3D¡£¡£¡£¡£¡£¡£¡£±¾´ÎÐÞ¸´µÄÎó²îΪFBX¿âÖеÄÔ¶³ÌÖ´ÐдúÂëÎó²î£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓôËÎó²î¿ÉÒÔ»ñµÃÓëÍâµØÓû§ÏàͬµÄȨÏÞ£¬£¬£¬£¬£¬AutodeskÔÚ4ÔÂ15ÈÕÍÆ³öÁËÕë¶Ô´ËÎó²îµÄ²¹¶¡³ÌÐò¡£¡£¡£¡£¡£¡£¡£MicrosoftÌåÏÖ£¬£¬£¬£¬£¬ºÚ¿Í±ØÐèÓÕʹÓû§·­¿ªÆäÌØÖÆµÄ3DÎļþ²Å¿ÉÒÔÀÖ³ÉʹÓôËÎó²î£¬£¬£¬£¬£¬Òò´Ë£¬£¬£¬£¬£¬ÔÚÇå¾²¸üÐÂ֮ǰÓû§ÐèÒªÔ¶ÀëÄÇЩ¿ÉÒÉÎļþÒÔ°ü¹ÜÇå¾²¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://news.softpedia.com/news/microsoft-releases-emergency-update-for-windows-10-app-microsoft-office-529800.shtml