CNNICÐû²¼¡¶Öйú»¥ÁªÍøÂçÉú³¤×´Ì¬Í³¼Æ±¨¸æ¡·£»£»¹È¸èÑо¿Ö°Ô±Åû¶ƻ¹ûImage I/OµÄÁãµã»÷Îó²î

Ðû²¼Ê±¼ä 2020-04-30

1.CNNICÐû²¼¡¶Öйú»¥ÁªÍøÂçÉú³¤×´Ì¬Í³¼Æ±¨¸æ¡·


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


4ÔÂ28ÈÕ£¬£¬ £¬£¬£¬Öйú»¥ÁªÍøÂçÐÅÏ¢ÖÐÐÄ£¨CNNIC£©Ðû²¼Á˵Ú45´Î¡¶Öйú»¥ÁªÍøÂçÉú³¤×´Ì¬Í³¼Æ±¨¸æ¡·¡£¡£¡£¡£¡£¡£´Ë±¨¸æÎ§ÈÆ»¥ÁªÍø»ù´¡½¨Éè¡¢ÍøÃñ¹æÄ£¼°½á¹¹¡¢»¥ÁªÍøÓ¦ÓÃÉú³¤¡¢»¥ÁªÍøÕþÎñÉú³¤¡¢¹¤ÒµÓëÊÖÒÕÉú³¤ºÍ»¥ÁªÍøÇå¾²µÈÁù¸ö·½Ã棬£¬ £¬£¬£¬×ۺϷ´Ó¦2019Äê¼°2020ÄêÍ·ÎÒ¹ú»¥ÁªÍøÉú³¤×´Ì¬¡£¡£¡£¡£¡£¡£¡¶±¨¸æ¡·ÏÔʾ£¬£¬ £¬£¬£¬×èÖ¹2020Äê3Ô£¬£¬ £¬£¬£¬ÎÒ¹úÍøÃñ¹æÄ£Îª9.04ÒÚ£¬£¬ £¬£¬£¬ÆäÖÐѧÉúÕ¼±È×î¶à£¬£¬ £¬£¬£¬Îª26.9%¡£¡£¡£¡£¡£¡£    


Ô­ÎÄÁ´½Ó£º

http://news.china.com.cn/txt/2020-04/28/content_75985166.htm


2.¹È¸èÑо¿Ö°Ô±Åû¶ƻ¹ûImage I/OµÄÁãµã»÷Îó²î


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


¹È¸èµÄProject Zero ÍŶÓÓÚ±¾ÖܶþÅû¶ÁËApple²Ù×÷ϵͳÖÐÄÚÖõĿò¼ÜImage I/OÖеÄÁãµã»÷Îó²î£¬£¬ £¬£¬£¬¸Ã¿ò¼Ü±»Ó¦ÓÃÓÚiOS¡¢macOS¡¢tvOSºÍwatchOSÖУ¬£¬ £¬£¬£¬ÓÃÀ´´¦Öóͷ£Í¼ÏñÔªÊý¾Ý¡£¡£¡£¡£¡£¡£Project ZeroÍŶÓÌåÏÖ£¬£¬ £¬£¬£¬ËûÃÇÆÊÎöÁ˸ÿò¼ÜµÄÄ£ºý´¦Öóͷ£Àú³Ì£¬£¬ £¬£¬£¬ÒÔÊÓ²ìËüÊÇÈçÄÇÀïÖÃÃûÌùýʧµÄͼÏñÎļþ¡£¡£¡£¡£¡£¡£Ð§¹ûÑо¿Ö°Ô±·¢Ã÷ÁË Image I/O Öб£´æ6¸öÎó²î£¬£¬ £¬£¬£¬¶øÆ»¹ûÏòµÚÈý·½¹ûÕæµÄ¸ß¶¯Ì¬¹æÄ££¨HDR£©Í¼ÏñÎļþÃûÌÿò¼ÜOpenEXRÖб£´æ8¸öÎó²î¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬ £¬£¬£¬ËùÓÐÎó²î¶¼ÒѾ­±»ÐÞ¸´¡£¡£¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/google-discloses-zero-click-bugs-impacting-several-apple-operating-systems/


3.Ñо¿Ö°Ô±ÔÚ28¿îɱ¶¾Èí¼þÖз¢Ã÷Symlink raceÎó²î


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


RACK911 LabµÄÑо¿Ö°Ô±ÔÚÖ÷Á÷²Ù×÷ϵͳ£¨Windows¡¢MacOSºÍLinux£©ÉϵÄ28¿îɱ¶¾Èí¼þÖз¢Ã÷ÁËSymlink raceÎó²î¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÌåÏÖ£¬£¬ £¬£¬£¬ÊÇɱ¶¾Èí¼þµÄÊÂÇé·½·¨µ¼ÖÂÁËÕâÖÖÎó²îµÄ±£´æ¡£¡£¡£¡£¡£¡£É±¶¾Èí¼þµÄɨÃ蹦ЧÐèÒª×î¸ß¼¶±ðȨÏÞ£¬£¬ £¬£¬£¬²¢ÇÒÔÚɨÃèºÍɾ³ý¶ñÒâÈí¼þÖ®¼ä±£´æÊ±¼ä²î£¬£¬ £¬£¬£¬ÒÔÊǺڿͿÉÒÔʹÓÃÕâ¶Îʱ¼äÒÔ×î¸ßȨÏÞÖ´ÐжñÒâÈí¼þ¡£¡£¡£¡£¡£¡£ºÚ¿ÍʹÓÃÕâ¸öÎó²î¿ÉÒÔɾ³ýÖ÷»úÉϵÄÎļþ£¬£¬ £¬£¬£¬°üÀ¨É±¶¾Èí¼þºÍ²Ù×÷ϵͳµÄÎļþ£¬£¬ £¬£¬£¬Ê¹ÅÌËã»úÍ߽⡣¡£¡£¡£¡£¡£ÔÚÑо¿Ö°Ô±Í¨ÖªÕâЩɱ¶¾Èí¼þµÄ¿ª·¢Ö°Ô±ºó£¬£¬ £¬£¬£¬¸÷¸ö¹«Ë¾¶¼ÒѾ­×îÏÈÐÞ¸´¸ÃÎó²î¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://latesthackingnews.com/2020/04/29/researchers-found-symlink-race-bugs-in-popular-antivirus-software/


4.Á½¼ÒUsenetЧÀ͹«Ë¾±¬·¢Êý¾Ýй¶²¢¹éÒòÓÚÏàÖúͬ°é


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


Á½¼ÒUsenetЧÀ͹«Ë¾UseNeXTºÍUsenet.nlÓÚ4ÔÂ29ÈÕÅû¶ÁËÆäÏàÖú¹«Ë¾±£´æÇå¾²Îó²î£¬£¬ £¬£¬£¬²¢ÇÒ¸ÃÎó²îµ¼ÖÂÁËÊý¾Ýй¶µÄÎÊÌâ,ÏÖÔÚÁ½¼Ò¹«Ë¾¶¼Î´Ö¸³ö±£´æÇå¾²Îó²îµÄ¹«Ë¾¡£¡£¡£¡£¡£¡£¾ÝÁ½¼Ò¹«Ë¾³Æ£¬£¬ £¬£¬£¬´Ë´Îй¶Êý¾Ý°üÀ¨Óû§ÐÕÃû¡¢µØµã¡¢Ö§¸¶ÐÅÏ¢£¨IBANºÍÕ˺ţ©ÒÔ¼°Óû§ÔÚ½¨ÉèÕÊ»§µÄÀú³ÌʹÓõ½µÄÐÅÏ¢¡£¡£¡£¡£¡£¡£UseNeXTºÍUsenet.nl¹«Ë¾ÌåÏÖ£¬£¬ £¬£¬£¬Óû§ÐèÒªÒªÔÚÍøÕ¾»Ö¸´ºóÖØÖÃÕÊ»§ÃÜÂ룬£¬ £¬£¬£¬²¢Éó²éËùÓÐUsenetÕÊ»§ÉèÖÃÒÔ·ÀÓÐδ¾­ÊÚȨµÄ¸ü¸Ä¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/two-usenet-providers-blame-data-breaches-on-partner-company/


5.Ó¢¹ú×Ô¶¯³µÅÆÊ¶±ðϵͳй¶½ü900Íò¹«ÃñÐгµÊý¾Ý


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


Ó¢¹úл·Æ¶ûµÂÊеÄ×Ô¶¯³µÅÆÏµÍ³£¨ANPR£©Ð¹Â¶ÁË860ÍòÌõ¹«Â·Ðгµ¼Í¼£¬£¬ £¬£¬£¬¸ÃÎÊÌâ¿É±»ºÚ¿ÍʹÓÃαÔìÌØ¶¨³µÁ¾µÄÐг̡£¡£¡£¡£¡£¡£ANPRµÄÄÚ²¿ÖÎÀí½çÃæ¿ÉÒÔͨ¹ýÔÚä¯ÀÀÆ÷ÖÐÊäÈëIPµØµã»á¼û£¬£¬ £¬£¬£¬²¢ÇÒ²»ÐèÒªÈκεǼºÍÑéÖ¤ÐÅÏ¢£¬£¬ £¬£¬£¬¼´¿ÉÉó²éºÍËÑË÷ʵʱÊý¾Ý¡£¡£¡£¡£¡£¡£¶øºÚ¿Í¿ÉÒÔͨ¹ý¸Ä¶¯ÏµÍ³ÖеÄÉãÏñÍ·Ãû³Æ¡¢Î»ÖõÈÒªº¦ÐÅÏ¢À´Î±Ôì³µÁ¾Ðг̡£¡£¡£¡£¡£¡£Ð»·Æ¶ûµÂÊÐÒé»áÔÚ¸ÃÊÂÎñ±¬·¢ºóÁ¬Ã¦½ÓÄÉÁËÓ¦¼±²½·¥£¬£¬ £¬£¬£¬²¢½«¸ÃϵͳÍÑ»úάÐÞ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.theregister.co.uk/2020/04/28/anpr_sheffield_council/


6.ÓÃÓÚSD-WAN·ÓÉÆ÷µÄµÄCiscoÈí¼þIOS XE±£´æÎó²î


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


ÓÃÓÚSD-WAN·ÓÉÆ÷µÄµÄCiscoÈí¼þIOS XE±£´æÊäÈëÑé֤ȱ·¦Îó²î£¨CVE-2019-16011£¬£¬ £¬£¬£¬CVSS 3.0ÆÀ·ÖΪ7.8£©£¬£¬ £¬£¬£¬¸ÃÎó²î¿ÉÒÔʹÍâµØµÄ¡¢¾­ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷ÕßÒÔrootȨÏÞÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£¡£´ËÎó²î±£´æÓÚLinux°æ±¾µÄSD-WAN·ÓÉÆ÷ÖУ¬£¬ £¬£¬£¬Ó°ÏìÁ˾ۺÏЧÀÍ·ÓÉÆ÷£¨ASR£©1000ϵÁУ¬£¬ £¬£¬£¬¼¯³ÉЧÀÍ·ÓÉÆ÷£¨ISR£©1000ϵÁУ¬£¬ £¬£¬£¬ISR 4000ϵÁкÍÔÆÐ§ÀÍ·ÓÉ1000VϵÁУ¬£¬ £¬£¬£¬ÕâЩ·ÓÉÆ÷ÏÖÔÚ¶¼ÊÇСÐÍÆóÒµÔÚʹÓᣡ£¡£¡£¡£¡£¸ÃÎó²îλÓÚÉèÖÃÍøÂç×°±¸µÄCisco IOX XEÏÂÁîÐнçÃæ£¨CLI£©ÖУ¬£¬ £¬£¬£¬Ôµ¹ÊÔ­ÓÉÊÇCLIûÓгä·ÖÑéÖ¤ÊäÈëÏÂÁî¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/cisco-ios-xe-flaw-sd-wan-routers/155319/