ÐÅÏ¢Äþ¾²Öܱ¨-2020ÄêµÚ17ÖÜ

Ðû²¼Ê±¼ä 2020-04-28

> ±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


2020Äê04ÔÂ20ÈÕÖÁ26ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´54¸ö  £¬ÖµµÃ¹Ø×¢µÄÊÇApple macOS Mail Javascript´úÂëÖ´ÐЩ¶´; Google Chrome paymentsÄÚ´æ´íÎóÒýÓôúÂëÖ´ÐЩ¶´£»Sonatype Nexus Repository ManagerȨÏÞÌáÉý©¶´£»Í¨´ïOAÈÎÒâÓû§µÇ¼©¶´£»Contiki-NGÔ½½çд´úÂëÖ´ÐЩ¶´ ¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊǼÓÄôó¶ùͯÓÎÏ·ÍøÕ¾Webkinz½ü2300ÍòÓû§Êý¾Ýй¶£»FPGAоƬStarbleed©¶´  £¬Ó°ÏìÈüÁé˼¶à¸ö²úÎCNCERTÐû²¼¡¶2019ÄêÎÒ¹ú»¥ÁªÍøÍøÂçÄþ¾²Ì¬ÊÆ×ÛÊö¡·³ÂËߣ»Ñо¿ÈËÔ±Åû¶IBMÆóÒµÄþ¾²Èí¼þÖеÄ4¸ö0day£»Î¢ÈíÐû²¼½ô¼±¸üР £¬ÐÞ¸´OfficeºÍPaint 3DÖжà¸ö©¶´ ¡£


ƾ¾ÝÒÔÉÏ×ÛÊö  £¬±¾ÖÜÄþ¾²ÍþвΪÖÐ ¡£


>ÖØÒªÄþ¾²Â©¶´Áбí


1. Apple macOS Mail Javascript´úÂëÖ´ÐЩ¶´


Apple macOS Mail´æÔÚ´úÂë×¢È멶´  £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó  £¬¿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâJavaScript´úÂë ¡£ ¡£

https://support.apple.com/en-us/HT211100


2. Google Chrome paymentsÄÚ´æ´íÎóÒýÓôúÂëÖ´ÐЩ¶´


Google Chrome payments´æÔÚÊͷźóʹÓ鶴  £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄWEBÇëÇó  £¬ÓÕʹÓû§½âÎö  £¬¿É½øÐоܾø·þÎñ¹¥»÷»òÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâÂë ¡£

https://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop_21.html


3. Sonatype Nexus Repository ManagerȨÏÞÌáÉý©¶´


Sonatype Nexus Repository ManagerʵÏÖ´æÔÚÄþ¾²Â©¶´  £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó  £¬¿ÉÌáÉýÌØȨ  £¬½øÐд´½¨  £¬ÐÞ¸Ä  £¬Ö´ÐÐÈÎÎñ ¡£

https://support.sonatype.com/hc/en-us/articles/360046233714


4. ͨ´ïOAÈÎÒâÓû§µÇ¼©¶´


ͨ´ïOAµÇ¼ʵÏÖ´æÔÚÄþ¾²Â©¶´  £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó  £¬¿ÉÒÔÈÎÒâÓû§ÉÏÏÂÎĵǼ ¡£

https://cert.360.cn/warning/detail?id=d2689a877c01a9712d148317c2da21a2


5. Contiki-NGÔ½½çд´úÂëÖ´ÐЩ¶´


Contiki-NG os/net/ipv6/sicslowpan.cÔÚ´¦ÖÃ6LoWPAN·ÖƬÖØ×é´æÔÚÔ½½ç䩶´  £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó  £¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐÈÎÒâ´úÂë ¡£

https://github.com/contiki-ng/contiki-ng/pull/972


> ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢¼ÓÄôó¶ùͯÓÎÏ·ÍøÕ¾Webkinz½ü2300ÍòÓû§Êý¾Ýй¶


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¼ÓÄôóÖøÃûÍæ¾ß¹«Ë¾GanzÆìϵĶùͯÓÎÏ·ÍøÕ¾WebkinzÔâµ½ºÚ¿ÍÈëÇÖ  £¬½ü2300ÍòÍæ¼ÒµÄÓû§ÃûºÍÃÜÂëй¶  £¬ÆäÖÐ鶵ÄÃÜÂëʹÓÃÁËMD5-CryptËã·¨¼ÓÃÜ ¡£¾ÝZDNet±¨µÀ  £¬ºÚ¿ÍÊÇÀûÓÃÍøÕ¾ÖеÄSQL×¢È멶´ÈëÇÖÓÎÏ·Êý¾Ý¿âµÄ  £¬¾Ý³Æ¸Ã©¶´µÄϸ½ÚÒÑÔÚºÚ¿ÍÂÛ̳ÖÐÁ÷´«Á˼¸¸öÔ ¡£ºÚ¿Í¿ÉÄÜ»¹ÍµÈ¡Á˹þÏ£¼ÓÃܵĵç×ÓÓʼþµØÖ· ¡£ÏûÏ¢ÈËÊ¿³ÆWebkinzÔ±¹¤ÒѾ­ÐÞ¸´Á˺ڿÍʹÓõÄ©¶´  £¬µ«GanzÉÐδ¶Ô´Ëʼþ½øÐлØÓ¦ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/hacker-leaks-23-million-usernames-and-passwords-from-webkinz-childrens-game/


2¡¢FPGAоƬStarbleed©¶´  £¬Ó°ÏìÈüÁé˼¶à¸ö²úÎï


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ñо¿ÈËÔ±·¢ÏÖFPGAоƬ´æÔÚStarbleed©¶´  £¬Ó°ÏìÁËÈüÁé˼7ϵÁеÄSpartan¡¢Artix¡¢Kintex¡¢Virtex×ÓϵÁжà¸ö²úÎï ¡£ÓÉÓÚ©¶´ÎªÓ²¼þ¼¶±ð©¶´  £¬Òò¶øÖ»ÄÜͨ¹ý¸ü»»Ð¾Æ¬À´ÐÞ¸´Â©¶´ ¡£Äþ¾²Ñо¿ÈËÔ±·¢ÏÖ¿ÉÒÔͨ¹ý½âÃܱ»¼ÓÃܵıÈÌØÁ÷À´·ÃÎʺÍÐÞ¸ÄÓÃÓÚ±à³ÌµÄÎļþ ¡£Òò´Ë  £¬ºÚ¿Í¿ÉÒÔÀûÓø鶴ÍêÈ«¿ØÖÆFPGAоƬ  £¬¶øÇÒ¿ÉÄÜ͵ȡ±ÈÌØÁ÷ÖеÄ֪ʶ²úȨ ¡£µÂ¹úMax PlanckÑо¿ËùµÄChristof Paar½ÌÊÚÌåÏÖ  £¬¹¥»÷ÕßÉõÖÁ¿ÉÒÔ½øÐÐÔ¶³Ì¹¥»÷  £¬»òÊÇÏòFPGAоƬֲÈëÓ²¼þľÂí ¡£


Ô­ÎÄÁ´½Ó£º

https://www.helpnetsecurity.com/2020/04/20/starbleed-vulnerability/


3¡¢CNCERTÐû²¼¡¶2019ÄêÎÒ¹ú»¥ÁªÍøÍøÂçÄþ¾²Ì¬ÊÆ×ÛÊö¡·³ÂËß


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¹ú¼Ò»¥ÁªÍøÓ¦¼±ÖÐÐÄ£¨CNCERT£©ÓÚ2020Äê4ÔÂ20ÈÕÐû²¼ÁË¡¶2019ÄêÎÒ¹ú»¥ÁªÍøÍøÂçÄþ¾²Ì¬ÊÆ×ÛÊö¡·³ÂËß ¡£¸Ã³ÂËßÁ¢×ãÓÚCNCERTÍøÂçÄþ¾²ºê¹Û¼à²âÊý¾ÝÓëÊÂÇéʵ¼ù³ÂËß  £¬Éæ¼°2019ÄêµäÐÍÍøÂçÄþ¾²Ê¼þ¡¢ÍøÂçÄþ¾²ÐÂÇ÷ÊƼ°ÈÕ³£ÍøÂçÄþ¾²Ê¼þÓ¦¼±´¦ÖÃʵ¼ùµÈÄÚÈÝ ¡£³ÂËßÖ÷Òª°üÂÞËĸö²¿ÃÅ  £¬Ò»ÊÇ×ܽá2019ÄêÎÒ¹ú»¥ÁªÍøÍøÂçÄþ¾²×´¿ö  £¬¶þÊÇÔ¤²â2020ÄêÍøÂçÄþ¾²Èȵã  £¬ÈýÊǽáºÏÍøÂçÄþ¾²Ì¬ÊÆ·ÖÎöÌá³ö¶Ô²ß½¨Òé  £¬ËÄÊÇÊáÀíÍøÂçÄþ¾²¼à²âÊý¾Ý ¡£¸Ã³ÂË߶ÔÎÒ¹úµ³Õþ»ú¹Ø¡¢ÐÐÒµÆóÒµ¼°È«Éç»áÁ˽âÎÒ¹úÍøÂçÄþ¾²ÐÎÊÆ  £¬Ìá¸ßÍøÂçÄþ¾²Òâʶ  £¬×öºÃÍøÂçÄþ¾²ÊÂÇéÌṩÁËÓÐÁ¦²Î¿¼ ¡£


Ô­ÎÄÁ´½Ó£º

http://www.cac.gov.cn/2020-04/20/c_1588932297982643.htm


4¡¢Ñо¿ÈËÔ±Åû¶IBMÆóÒµÄþ¾²Èí¼þÖеÄ4¸ö0day


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Äþ¾²Ñо¿ÈËÔ±ÔÚ·ÖÎöIBM Data Risk Manager£¨IDRM£©Ê±·¢ÏÖÁË4¸ö0day  £¬·Ö±ðΪÉí·ÝÑéÖ¤Èƹý©¶´¡¢ÃüÁî×¢È멶´¡¢²»Äþ¾²µÄĬÈÏÃÜÂ멶´ÒÔ¼°ÈÎÒâÎļþÏÂÔØ©¶´ ¡£ÕâЩ©¶´¿ÉÒÔµ¥¶ÀʹÓÃÒ²¿ÉÒÔ×éºÏʹÓà  £¬×éºÏʹÓÃÇ°Èý¸ö©¶´¿ÉÒÔʹ¹¥»÷ÕßÒÔrootȨÏÞÔ¶³ÌÖ´ÐдúÂë  £¬×éºÏʹÓõÚÒ»¸öºÍµÚËĸö©¶´¿ÉÒÔʹδÊÚȨµÄ¹¥»÷ÕßÏÂÔØÈÎÒâÎļþ ¡£Â©¶´µÄÅû¶ÕßRibeiroÌåÏÖ  £¬IDRMÊÇ´¦ÖÃÃô¸ÐÐÅÏ¢µÄÆóÒµÄþ¾²²úÎï  £¬Èç¹ûÆäÔâµ½¹¥»÷»áµ¼Ö¹«Ë¾ÀûÒæÑÏÖØÊÜËð  £¬Òò´ËÔÚIBM¾Ü¾ø½ÓÊÜ©¶´³ÂËߺóÑ¡Ôñ½«ÆäÐû²¼³öÀ´ ¡£Ä¿Ç°  £¬IBM¹«Ë¾ÐÞ¸´ÁËIDRM2.0.1¼°¸ü¸ß°æ±¾ÖеÄÈÎÒâÎļþÏÂÔØ©¶´ºÍÃüÁî×¢È멶´  £¬¶øÇÒÕýÔÚÊÓ²ìÉí·ÝÑéÖ¤Èƹý©¶´ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/researcher-discloses-four-ibm-zero-days-after-refusal-to-fix/


5¡¢Î¢ÈíÐû²¼½ô¼±¸üР £¬ÐÞ¸´OfficeºÍPaint 3DÖжà¸ö©¶´


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


MicrosoftÐû²¼Á˽ô¼±Äþ¾²¸üР £¬ÒÔÐÞ¸´Ê¹ÓÃÁËAutodesk FBX¿âµÄMicrosoft²úÎï  £¬°üÂÞ¶à¸ö°æ±¾µÄMicrosoft OfficeºÍWindows 10Ó¦Ó÷¨Ê½Paint 3D ¡£±¾´ÎÐÞ¸´µÄ©¶´ÎªFBX¿âÖеÄÔ¶³ÌÖ´ÐдúÂ멶´  £¬¹¥»÷ÕßÀûÓôË©¶´¿ÉÒÔ»ñµÃÓëµ±µØÓû§ÏàͬµÄȨÏÞ  £¬AutodeskÔÚ4ÔÂ15ÈÕÍƳöÁËÕë¶Ô´Ë©¶´µÄ²¹¶¡·¨Ê½ ¡£MicrosoftÌåÏÖ  £¬ºÚ¿Í±ØÐëÓÕʹÓû§´ò¿ªÆäÌØÖƵÄ3DÎļþ²Å¿ÉÒÔÀÖ³ÉÀûÓôË©¶´  £¬Òò´Ë  £¬ÔÚÄþ¾²¸üÐÂ֮ǰÓû§ÐèÒªÔ¶ÀëÄÇЩ¿ÉÒÉÎļþÒÔ±£Ö¤Äþ¾² ¡£


Ô­ÎÄÁ´½Ó£º

https://news.softpedia.com/news/microsoft-releases-emergency-update-for-windows-10-app-microsoft-office-529800.shtml