Ç徲ͨ¸æ
-
΢ÈíÐû²¼9Ô²¹¶¡ÐÞ¸´64¸öÇå¾²ÎÊÌâ Çå¾²Íþвͨ¸æ
2018-09-14
×ÛÊö΢ÈíÓÚÖܶþÐû²¼ÁË9ÔÂÇå¾²¸üв¹¶¡£¬ÐÞ¸´ÁË64¸ö´Ó¼òÆÓµÄÓÕÆ¹¥»÷µ½Ô¶³ÌÖ´ÐдúÂëµÄÇå¾²ÎÊÌ⣬²úÆ·Éæ¼° NET Core¡¢ NET Framework¡¢Adobe Flash Player¡¢Azure¡¢Device Guard¡¢InternetExplorer¡¢Microsoft Edge¡¢Microsoft Graphics Component¡¢Microsoft Identity Services¡¢Microsoft JET Database Engine¡¢Microsoft Office¡¢Microsoft scripting Engine¡¢Microsoft Windows¡¢Microsoft XML Core Ser
¸ü¶à -
¿ËÈÕ£¬IBMÐû²¼Ç徲ͨ¸æ³ÆÐÞ¸´ÁËÒ»¸öWebSphere Application ServerÖÐÒ»¸öDZÔÚµÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2018-1567£©¡£¹¥»÷Õß¿ÉÒԽṹһ¸ö¶ñÒâµÄÐòÁл¯¹¤¾ß£¬Ëæºóͨ¹ýSOAPÅþÁ¬Æ÷À´Ö´ÐÐí§ÒâJAVA´úÂë¡£ÏêϸÐÅÏ¢¿É²Î¿¼£ºhttps: www-01 ibm com support docview wss?uid=swg22016254 ÊÜÓ°ÏìµÄ°æ±¾IBM WebSphere Application Server:lVersion 9 0lVersion 8 5lVersion 8 0lVersion 7 0²»ÊÜÓ°ÏìµÄ°æ±¾lVersion >= 9 0 0 10
¸ü¶à -
×ÛÊö ±±¾©Ê±¼ä2018Äê8ÔÂ22ÈÕ£¬Apache¹Ù·½Ðû²¼Í¨¸æÐû²¼ÁËStruts2ÖÐÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2018-11776£¬CNVD-2018-15894£¬CNNVD-201808-740£©¡£¸ÃÎó²îÔÚÁ½ÖÖÇéÐÎϱ£´æ£¬µÚÒ»£¬µ±xmlÉèÖÃÖÐδÉèÖÃnamespaceÖµ£¬ÇÒÉϲãÐж¯ÉèÖã¨action(s) configurations£©ÖÐδÉèÖûòʹÓÃͨÅä·ûnamespaceֵʱ£¬¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐÎó²îµÄ±¬·¢¡£µÚ¶þ£¬Ê¹ÓÃδÉèÖÃvalueºÍactionÖµµÄurl±êÇ©£¬ÇÒÉϲãÐж¯ÉèÖÃÖÐδÉèÖûòʹÓÃͨÅä·ûnamespaceÖµ£¬
¸ü¶à -
×ÛÊö ¿ËÈÕ£¬Ghostscript±»±¬³ö°üÀ¨¶à¸ö-dSAFERɳÏäÈÆ¹ýÎó²î¡£-dSAFERÊÇGhostscriptÓÃÓÚ±ÜÃâ²»Çå¾²Postscript²Ù×÷µÄÇ徲ɳÏä¡£´ËÎó²îÓë2016Äê·ºÆðµÄɳÏäÈÆ¹ýÎó²î£¨CVE-2016-3714£©ÀàËÆ£¬Ô¶³Ìδ¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿Éͨ¹ý¶àÖÖPostscript²Ù×÷À´Èƹý-dSAFERÌṩµÄ±£»¤£¬ÔÚÒ×Êܹ¥»÷µÄϵͳÉÏÖ´ÐÐí§ÒâÏÂÁî¡£ImageMagickµÈĬÈÏʹÓÃGhostscriptÀ´´¦Öóͷ£PostscriptÄÚÈݵÄÓ¦Ó㬽«Êܵ½´ËÎó²îÓ°Ïì¡£ÏêϸÐÅÏ¢¿É²Î¿¼£ºhttps: www kb cert org
¸ü¶à -
Ò» Îó²î¸ÅÊö ±±¾©Ê±¼ä8ÔÂ22ÈÕ£¬Struts¹Ù·½¹ûÕæÁËÎó²îS2-057£¨CVE-2018-11776£©¡£¸ÃÎó²î¿ÉÄÜÔÚÁ½ÖÖÇéÐÎϱ»´¥·¢£¬µÚÒ»£¬µ±Ã»ÓÐΪµ×²ãxmlÉèÖÃÖнç˵µÄЧ¹ûÉèÖÃnamespaceÖµ£¬²¢ÇÒÆäÉϲ¿²Ù×÷ÉèÖÃûÓÐnamespace»òͨÅänamespaceʱ£¬¿ÉÄÜ×é³ÉRCE¹¥»÷¡£µÚ¶þ£¬µ±Ê¹ÓÃûÓÐvalueºÍaction¼¯µÄurl±êǩʱ£¬²¢ÇÒÆäÉϲã²Ù×÷ÉèÖÃûÓлòͨÅänamespaceʱ£¬Ò²¿ÉÄÜ×é³ÉRCE¹¥»÷¡£²Î¿¼Á´½Ó£º https: cwiki apache org confluence display WW S2-0
¸ü¶à -
×ÛÊö ±±¾©Ê±¼ä8ÔÂ22ÈÕ13ʱ£¬Apache¹Ù·½Ðû²¼Í¨¸æÐû²¼ÁËStruts2ÖÐÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2018-11776£©¡£¸ÃÎó²îÔÚÁ½ÖÖÇéÐÎϱ£´æ£¬µÚÒ»£¬ÔÚxmlÉèÖÃÖÐδÉèÖÃnamespaceÖµ£¬ÇÒÉϲãÐж¯ÉèÖã¨upper action(s)configurations£©ÖÐδÉèÖûòÓÃͨÅä·ûnamespaceÖµ¡£µÚ¶þ£¬Ê¹ÓÃδÉèÖÃvalueºÍactionÖµµÄurl±êÇ©£¬ÇÒÉϲãÐж¯ÉèÖã¨upper action(s) configurations£©ÖÐδÉèÖûòÓÃͨÅä·ûnamespaceÖµ¡£ÏêϸÐÅÏ¢¿É²Î¿¼£ºhttps: cwiki apac
¸ü¶à








