ÐÅÏ¢Äþ¾²Öܱ¨-2020ÄêµÚ17ÖÜ

Ðû²¼Ê±¼ä 2020-04-28

> ±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


2020Äê04ÔÂ20ÈÕÖÁ26ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´54¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇApple macOS Mail Javascript´úÂëÖ´ÐЩ¶´; Google Chrome paymentsÄÚ´æ´íÎóÒýÓôúÂëÖ´ÐЩ¶´£»Sonatype Nexus Repository ManagerȨÏÞÌáÉý©¶´£»Í¨´ïOAÈÎÒâÓû§µÇ¼©¶´£»Contiki-NGÔ½½çд´úÂëÖ´ÐЩ¶´¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊǼÓÄôó¶ùͯÓÎÏ·ÍøÕ¾Webkinz½ü2300ÍòÓû§Êý¾Ýй¶£»FPGAоƬStarbleed©¶´£¬Ó°ÏìÈüÁé˼¶à¸ö²úÎCNCERTÐû²¼¡¶2019ÄêÎÒ¹ú»¥ÁªÍøÍøÂçÄþ¾²Ì¬ÊÆ×ÛÊö¡·³ÂËߣ»Ñо¿ÈËÔ±Åû¶IBMÆóÒµÄþ¾²Èí¼þÖеÄ4¸ö0day£»Î¢ÈíÐû²¼½ô¼±¸üУ¬ÐÞ¸´OfficeºÍPaint 3DÖжà¸ö©¶´¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£


>ÖØÒªÄþ¾²Â©¶´Áбí


1. Apple macOS Mail Javascript´úÂëÖ´ÐЩ¶´


Apple macOS Mail´æÔÚ´úÂë×¢È멶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâJavaScript´úÂë¡£¡£

https://support.apple.com/en-us/HT211100


2. Google Chrome paymentsÄÚ´æ´íÎóÒýÓôúÂëÖ´ÐЩ¶´


Google Chrome payments´æÔÚÊͷźóʹÓ鶴£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄWEBÇëÇó£¬ÓÕʹÓû§½âÎö£¬¿É½øÐоܾø·þÎñ¹¥»÷»òÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâÂë¡£

https://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop_21.html


3. Sonatype Nexus Repository ManagerȨÏÞÌáÉý©¶´


Sonatype Nexus Repository ManagerʵÏÖ´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÌáÉýÌØȨ£¬½øÐд´½¨£¬Ð޸ģ¬Ö´ÐÐÈÎÎñ¡£

https://support.sonatype.com/hc/en-us/articles/360046233714


4. ͨ´ïOAÈÎÒâÓû§µÇ¼©¶´


ͨ´ïOAµÇ¼ʵÏÖ´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÈÎÒâÓû§ÉÏÏÂÎĵǼ¡£

https://cert.360.cn/warning/detail?id=d2689a877c01a9712d148317c2da21a2


5. Contiki-NGÔ½½çд´úÂëÖ´ÐЩ¶´


Contiki-NG os/net/ipv6/sicslowpan.cÔÚ´¦ÖÃ6LoWPAN·ÖƬÖØ×é´æÔÚÔ½½ç䩶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐÈÎÒâ´úÂë¡£

https://github.com/contiki-ng/contiki-ng/pull/972


> ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢¼ÓÄôó¶ùͯÓÎÏ·ÍøÕ¾Webkinz½ü2300ÍòÓû§Êý¾Ýй¶


×ðÁú¶¶È¦ - Ϊdu¶øÉú


¼ÓÄôóÖøÃûÍæ¾ß¹«Ë¾GanzÆìϵĶùͯÓÎÏ·ÍøÕ¾WebkinzÔâµ½ºÚ¿ÍÈëÇÖ£¬½ü2300ÍòÍæ¼ÒµÄÓû§ÃûºÍÃÜÂëй¶£¬ÆäÖÐ鶵ÄÃÜÂëʹÓÃÁËMD5-CryptËã·¨¼ÓÃÜ¡£¾ÝZDNet±¨µÀ£¬ºÚ¿ÍÊÇÀûÓÃÍøÕ¾ÖеÄSQL×¢È멶´ÈëÇÖÓÎÏ·Êý¾Ý¿âµÄ£¬¾Ý³Æ¸Ã©¶´µÄϸ½ÚÒÑÔÚºÚ¿ÍÂÛ̳ÖÐÁ÷´«Á˼¸¸öÔ¡£ºÚ¿Í¿ÉÄÜ»¹ÍµÈ¡Á˹þÏ£¼ÓÃܵĵç×ÓÓʼþµØÖ·¡£ÏûÏ¢ÈËÊ¿³ÆWebkinzÔ±¹¤ÒѾ­ÐÞ¸´Á˺ڿÍʹÓõÄ©¶´£¬µ«GanzÉÐδ¶Ô´Ëʼþ½øÐлØÓ¦¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/hacker-leaks-23-million-usernames-and-passwords-from-webkinz-childrens-game/


2¡¢FPGAоƬStarbleed©¶´£¬Ó°ÏìÈüÁé˼¶à¸ö²úÎï


×ðÁú¶¶È¦ - Ϊdu¶øÉú


Ñо¿ÈËÔ±·¢ÏÖFPGAоƬ´æÔÚStarbleed©¶´£¬Ó°ÏìÁËÈüÁé˼7ϵÁеÄSpartan¡¢Artix¡¢Kintex¡¢Virtex×ÓϵÁжà¸ö²úÎï¡£ÓÉÓÚ©¶´ÎªÓ²¼þ¼¶±ð©¶´£¬Òò¶øÖ»ÄÜͨ¹ý¸ü»»Ð¾Æ¬À´ÐÞ¸´Â©¶´¡£Äþ¾²Ñо¿ÈËÔ±·¢ÏÖ¿ÉÒÔͨ¹ý½âÃܱ»¼ÓÃܵıÈÌØÁ÷À´·ÃÎʺÍÐÞ¸ÄÓÃÓÚ±à³ÌµÄÎļþ¡£Òò´Ë£¬ºÚ¿Í¿ÉÒÔÀûÓø鶴ÍêÈ«¿ØÖÆFPGAоƬ£¬¶øÇÒ¿ÉÄÜ͵ȡ±ÈÌØÁ÷ÖеÄ֪ʶ²úȨ¡£µÂ¹úMax PlanckÑо¿ËùµÄChristof Paar½ÌÊÚÌåÏÖ£¬¹¥»÷ÕßÉõÖÁ¿ÉÒÔ½øÐÐÔ¶³Ì¹¥»÷£¬»òÊÇÏòFPGAоƬֲÈëÓ²¼þľÂí¡£


Ô­ÎÄÁ´½Ó£º

https://www.helpnetsecurity.com/2020/04/20/starbleed-vulnerability/


3¡¢CNCERTÐû²¼¡¶2019ÄêÎÒ¹ú»¥ÁªÍøÍøÂçÄþ¾²Ì¬ÊÆ×ÛÊö¡·³ÂËß


×ðÁú¶¶È¦ - Ϊdu¶øÉú


¹ú¼Ò»¥ÁªÍøÓ¦¼±ÖÐÐÄ£¨CNCERT£©ÓÚ2020Äê4ÔÂ20ÈÕÐû²¼ÁË¡¶2019ÄêÎÒ¹ú»¥ÁªÍøÍøÂçÄþ¾²Ì¬ÊÆ×ÛÊö¡·³ÂËß¡£¸Ã³ÂËßÁ¢×ãÓÚCNCERTÍøÂçÄþ¾²ºê¹Û¼à²âÊý¾ÝÓëÊÂÇéʵ¼ù³ÂËߣ¬Éæ¼°2019ÄêµäÐÍÍøÂçÄþ¾²Ê¼þ¡¢ÍøÂçÄþ¾²ÐÂÇ÷ÊƼ°ÈÕ³£ÍøÂçÄþ¾²Ê¼þÓ¦¼±´¦ÖÃʵ¼ùµÈÄÚÈÝ¡£³ÂËßÖ÷Òª°üÂÞËĸö²¿ÃÅ£¬Ò»ÊÇ×ܽá2019ÄêÎÒ¹ú»¥ÁªÍøÍøÂçÄþ¾²×´¿ö£¬¶þÊÇÔ¤²â2020ÄêÍøÂçÄþ¾²Èȵ㣬ÈýÊǽáºÏÍøÂçÄþ¾²Ì¬ÊÆ·ÖÎöÌá³ö¶Ô²ß½¨Ò飬ËÄÊÇÊáÀíÍøÂçÄþ¾²¼à²âÊý¾Ý¡£¸Ã³ÂË߶ÔÎÒ¹úµ³Õþ»ú¹Ø¡¢ÐÐÒµÆóÒµ¼°È«Éç»áÁ˽âÎÒ¹úÍøÂçÄþ¾²ÐÎÊÆ£¬Ìá¸ßÍøÂçÄþ¾²Òâʶ£¬×öºÃÍøÂçÄþ¾²ÊÂÇéÌṩÁËÓÐÁ¦²Î¿¼¡£


Ô­ÎÄÁ´½Ó£º

http://www.cac.gov.cn/2020-04/20/c_1588932297982643.htm


4¡¢Ñо¿ÈËÔ±Åû¶IBMÆóÒµÄþ¾²Èí¼þÖеÄ4¸ö0day


×ðÁú¶¶È¦ - Ϊdu¶øÉú


Äþ¾²Ñо¿ÈËÔ±ÔÚ·ÖÎöIBM Data Risk Manager£¨IDRM£©Ê±·¢ÏÖÁË4¸ö0day£¬·Ö±ðΪÉí·ÝÑéÖ¤Èƹý©¶´¡¢ÃüÁî×¢È멶´¡¢²»Äþ¾²µÄĬÈÏÃÜÂ멶´ÒÔ¼°ÈÎÒâÎļþÏÂÔØ©¶´¡£ÕâЩ©¶´¿ÉÒÔµ¥¶ÀʹÓÃÒ²¿ÉÒÔ×éºÏʹÓã¬×éºÏʹÓÃÇ°Èý¸ö©¶´¿ÉÒÔʹ¹¥»÷ÕßÒÔrootȨÏÞÔ¶³ÌÖ´ÐдúÂ룬×éºÏʹÓõÚÒ»¸öºÍµÚËĸö©¶´¿ÉÒÔʹδÊÚȨµÄ¹¥»÷ÕßÏÂÔØÈÎÒâÎļþ¡£Â©¶´µÄÅû¶ÕßRibeiroÌåÏÖ£¬IDRMÊÇ´¦ÖÃÃô¸ÐÐÅÏ¢µÄÆóÒµÄþ¾²²úÎÈç¹ûÆäÔâµ½¹¥»÷»áµ¼Ö¹«Ë¾ÀûÒæÑÏÖØÊÜËð£¬Òò´ËÔÚIBM¾Ü¾ø½ÓÊÜ©¶´³ÂËߺóÑ¡Ôñ½«ÆäÐû²¼³öÀ´¡£Ä¿Ç°£¬IBM¹«Ë¾ÐÞ¸´ÁËIDRM2.0.1¼°¸ü¸ß°æ±¾ÖеÄÈÎÒâÎļþÏÂÔØ©¶´ºÍÃüÁî×¢È멶´£¬¶øÇÒÕýÔÚÊÓ²ìÉí·ÝÑéÖ¤Èƹý©¶´¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/researcher-discloses-four-ibm-zero-days-after-refusal-to-fix/


5¡¢Î¢ÈíÐû²¼½ô¼±¸üУ¬ÐÞ¸´OfficeºÍPaint 3DÖжà¸ö©¶´


×ðÁú¶¶È¦ - Ϊdu¶øÉú


MicrosoftÐû²¼Á˽ô¼±Äþ¾²¸üУ¬ÒÔÐÞ¸´Ê¹ÓÃÁËAutodesk FBX¿âµÄMicrosoft²úÎ°üÂÞ¶à¸ö°æ±¾µÄMicrosoft OfficeºÍWindows 10Ó¦Ó÷¨Ê½Paint 3D¡£±¾´ÎÐÞ¸´µÄ©¶´ÎªFBX¿âÖеÄÔ¶³ÌÖ´ÐдúÂ멶´£¬¹¥»÷ÕßÀûÓôË©¶´¿ÉÒÔ»ñµÃÓëµ±µØÓû§ÏàͬµÄȨÏÞ£¬AutodeskÔÚ4ÔÂ15ÈÕÍƳöÁËÕë¶Ô´Ë©¶´µÄ²¹¶¡·¨Ê½¡£MicrosoftÌåÏÖ£¬ºÚ¿Í±ØÐëÓÕʹÓû§´ò¿ªÆäÌØÖƵÄ3DÎļþ²Å¿ÉÒÔÀÖ³ÉÀûÓôË©¶´£¬Òò´Ë£¬ÔÚÄþ¾²¸üÐÂ֮ǰÓû§ÐèÒªÔ¶ÀëÄÇЩ¿ÉÒÉÎļþÒÔ±£Ö¤Äþ¾²¡£


Ô­ÎÄÁ´½Ó£º

https://news.softpedia.com/news/microsoft-releases-emergency-update-for-windows-10-app-microsoft-office-529800.shtml