Ç徲ͨ¸æ
-
×ÛÊö ±±¾©Ê±¼ä2017Äê11ÔÂ2ÈÕ£¬JacksonÕë¶Ô·´ÐòÁл¯Îó²î£¨CVE-2017-7525£©±£´æÒÅÁôÎÊÌ⣬Ðû²¼ÁËjackson-databind·´ÐòÁл¯Îó²î(CVE-2017-15095)¼°ÆäÏà¹ØÐÅÏ¢£¬¸ÃÎó²î×÷ΪCVE-2017-7525µÄºóÐø£¬ÐÎòÁ˸ü¶àÕë¶Ôjackson-databindµÄ·´ÐòÁл¯Îó²î¹¥»÷¡£ 7Ô·ݣ¬AG¹«Ë¾¿Æ¼¼Ñо¿Ô±·¢Ã÷·´ÐòÁл¯Â© ¶´£¨CVE-2017-7525£©Ó°Ïìjackson-databind£¬¸ÃÎó²î½«Î£ÏÕµÄÀà¼ÓÈëºÚÃûµ¥¿ÉÒÔ»ñµÃ»º½â£¬¹Ù·½ËæºóÐû²¼Í¨¸æ£¬²¢Ðû²¼ÁËJackson2 8 9°æ±¾¡£ µ«
¸ü¶à -
Tinysvcmdns¶à±êÇ©DNS¶ÑÒç³öÎó²î
2017-11-01
×ÛÊöÍâµØÊ±¼ä2017Äê10ÔÂ31ÈÕ£¬TalosÐû²¼ÁËÒ»Ìõ¹ØÓÚTinysvcmdnsµÄÎó²î¡£¸Ã¶ÑÒç³öÎó²îÔ´ÓÚTinysvcmdnsµÄ¿â°æ±¾2016-07-18ÖС£Í¨¹ýÒ»¸öÌØÖÆµÄÊý¾Ý°ü£¬¸Ã¿â¿ÉÒÔÈù¥»÷ÕßʹÓÃ×Ô¼º¿ØÖƵÄÊý¾ÝÀ´ÁýÕÖ¶ÑÉϵÄí§ÒâÊý¾Ý¡£¹¥»÷ÕßÐèÒª·¢ËÍÒ»¸ödnsÊý¾Ý°üÀ´´¥·¢´ËÎó²î¡£CVSS 3 0ÆÀ·ÖΪ10 0£¨CVSS:3 0 AV:N AC:L PR:N UI:N S:C C:H I:H A:H£©¡£Ïà¹ØÁ´½Ó£ºhttps: www talosintelligence com vulnerability_reports TALOS-2017-0439ÊÜÓ°ÏìµÄ°æ±¾
¸ü¶à -
×ÛÊö¿ËÈÕ£¬HP¹Ù·½Ðû²¼Ç徲ͨ¸æ£¬ÔÚHPEÖÇÄÜÖÎÀíÖÐÐÄ£¨iMC£©PLATÖз¢Ã÷ÁËDZÔÚµÄÇå¾²Îó²î¡£ÕâЩÎó²î¿ÉÒÔÔ¶³ÌʹÓã¬ÒÔÔÊÐí´úÂëÖ´ÐУ¬CVE±àºÅΪCVE-2017-8962CVE-2017-8963£¬CVE-2017-8964£¬CVE-2017-8965£¬CVE-2017-8966£¬CVE-2017-8967£¬CVSSÆÀ·ÖÈçÏ£ºCVEV3±ê×¼V3ÆÀ·ÖV2±ê×¼V2ÆÀ·ÖCVE-2017-8962CVSS:3 0 AV:N AC:L PR:N UI:R S:U C:H I:H A:H8 8(AV:N AC:L Au:S C:C I:C A:C)9 0CVE-2017-8963CVSS:3 0 AV:N AC:L PR:N UI:R S:U C
¸ü¶à -
×ÛÊö ÍâµØÊ±¼ä2017Äê10ÔÂ31ÈÕ£¬TalosÐû²¼ÁËһϵÁйØÓÚCircle with Disney²úÆ·µÄÎó²îͨ¸æ£¬º¸Ç°üÀ¨Ô¶³Ì´úÂëÖ´ÐУ¬ÏÂÁî×¢È룬¾Ü¾ø·þÎñµÈÔÚÄÚµÄ22¸ö²î±ðµÄÎó²îÇÒ²¿·ÖÎó²îCVSS3 0ÆÀ·ÖµÖ´ï¸ßΣµÄ9 9ÒÔ¼°10·Ö¡£Ê¹ÓøòúÆ·µÄÓû§Ó¦ÊµÊ±Éý¼¶À´·À»¤¡£ Ïà¹ØÁ´½Ó£º https: www talosintelligence com vulnerability_reports disclosed ¹ØÓÚCircle with Disney Circle withDisneyÊÇÒ»¿î¼Ò³¤ÖÎÀíÓëÍøÂç¹ýÂ˵IJúÆ·¡£Circle»áÎÞ
¸ü¶à -
2017-11-01
×ÛÊö ÍâµØÊ±¼ä2017Äê10ÔÂ31ÈÕ£¬TalosÍŶÓÐû²¼Á˶à¸ö¹ØÓÚCesanta MongooseµÄÎó²îͨ¸æ£¬º¸Ç´úÂëÖ´ÐУ¬¾Ü¾ø·þÎñµÈ¹²8¸öÎó²î£¬ÆäÖаüÀ¨¶à¸öCVSS 3 0ÆÀ·ÖΪ9 8·ÖµÄ¸ßΣÎó²î¡£Mongoose±»³ÆÎªGitHubÉÏ×îÊܽӴýµÄǶÈëÊ½ÍøÂç·þÎñÆ÷£¬ÏÖÔÚMongooseÒѾ¸üÐÂÐÞ¸´ÁËÏà¹ØÎó²î¡£ Ïà¹ØÁ´½Ó£º https: cesanta com https: www talosintelligence com vulnerability_reports disclosed ÊÜÓ°ÏìµÄ°æ±¾ l Cesanta Mongoose 6 8 ²»
¸ü¶à -
2017-11-01
×ÛÊö ÍâµØÊ±¼ä2017Äê10ÔÂ31ÈÕ£¬WordPress¹Ù·½Ðû²¼ÁË4 8 3Çå¾²¸üУ¬ÐÞ¸´ÁËÒ»¸ö±£´æÓÚ֮ǰȫ°æ±¾µÄSQL×¢ÈëÎó²î¡£¸ÃÎó²îÔ´ÓÚ$wpdb->prepare()¿ÉÒÔÌìÉúΣÏÕµÄÅÌÎÊÏÂÁµ¼ÖÂDZÔÚµÄSQL×¢Èë¡£WordPress½¹µã²¢½ûÖ¹Ò×Ö±½ÓÊܵ½¸ÃÎó²îÓ°Ï죬µ«WordPress¹Ù·½Ò²ÔöÇ¿Á˲å¼þºÍÖ÷ÌâµÄÇå¾²ÒÔ±ÜÃâ¸ÃÎó²î±»´¥·¢¡£ Ïà¹ØÁ´½Ó£º https: wordpress org news 2017 10 wordpress-4-8-3-security-release ÊÜÓ°ÏìµÄ°æ±¾ WordPress <= 4 8 2
¸ü¶à








