Ç徲ͨ¸æ
-
µØÊ±¼ä2017Äê4ÔÂ17ÈÕ£¨±±¾©Ê±¼ä2017Äê4ÔÂ18ÈÕ£©£¬HP¹Ù·½Ðû²¼Ç徲ͨ¸æ£¬Åû¶ÁËÒ»¸öÓÉFortinetÌṩµÄ¹ØÓÚHPE Vertica Analytics Platform²úÆ·±£´æÔ¶³ÌÌØÈ¨»á¼ûµÄÎó²î£¬CVE±àºÅΪCVE-2017-5802¡£ CVSSÆÀ·ÖÈçÏ£º Õë¶Ô±¾´ÎÇå¾²ÎÊÌ⣬HP¹Ù·½ÒѾÐû²¼Ð°汾£¬¹Ù·½ÍøÕ¾ÈçÏ£º https: h20564 www2 hpe com hpsc doc public display?docId=emr_na-hpesbgn03734en_us HPE Vertica Analytics Platform ´Ë²úƷΪÆóÒµÃæÏò¼¯
¸ü¶à -
2017-04-18
±±¾©Ê±¼ä18ÈÕÇåÔ磬Apache Log4j ±»ÆØ³ö±£´æÒ»¸ö·´ÐòÁл¯Îó²î(CVE-2017-5645)¡£¹¥»÷Õß¿ÉÒÔͨ¹ý·¢ËÍÒ»¸öÌØÊâÖÆ×÷µÄ2½øÖÆpayload£¬ÔÚ×é¼þ½«×Ö½Ú·´ÐòÁл¯Îª¹¤¾ßʱ£¬´¥·¢²¢Ö´ÐнṹµÄpayload´úÂë¡£ ¸ÃÎó²îÖ÷ÒªÊÇÓÉÓÚÔÚ´¦Öóͷ£ObjectInputStreamʱ£¬ÎüÊÕÆ÷¹ØÓÚ²»¿É¿¿ÈªÔ´µÄinputûÓйýÂË¡£¿ÉÒÔͨ¹ý¸øTcpSocketServerºÍUdpSocketServerÌí¼Ó¿ÉÉèÖõĹýÂ˹¦Ð§ÒÔ¼°Ò»Ð©Ïà¹ØÉèÖ㬿ÉÒÔÓÐÓõĽâ¾ö¸ÃÎó²î¡£ÏÖÔÚLog4j¹Ù·½ÒѾÐû²¼Ð°汾ÐÞ¸´
¸ü¶à -
Jackson¿ò¼ÜJava·´ÐòÁл¯Ô¶³Ì´úÂëÖ´ÐÐÎó²î
2017-04-18
±±¾©Ê±¼ä4ÔÂ15ÈÕ£¬Jackson¿ò¼Ü±»·¢Ã÷±£´æÒ»¸ö·´ÐòÁл¯´úÂëÖ´ÐÐÎó²î¡£¸ÃÎó²î±£´æÓÚJackson¿ò¼ÜϵÄenableDefaultTypingÒªÁ죬ͨ¹ý¸ÃÎó²î£¬¹¥»÷Õß¿ÉÒÔÔ¶³ÌÔÚ·þÎñÆ÷Ö÷»úÉÏԽȨִÐÐí§Òâ´úÂ룬´Ó¶øÈ¡µÃ¸ÃÍøÕ¾·þÎñÆ÷µÄ¿ØÖÆÈ¨¡£ JacksonÊÇÒ»¸ö¿ªÔ´µÄJavaÐòÁл¯Óë·´ÐòÁл¯¹¤¾ß£¬¿ÉÒÔ½«java¹¤¾ßÐòÁл¯Îªxml»òjsonÃûÌõÄ×Ö·û´®£¬»òÕß·´ÐòÁл¯»Ø¶ÔÓ¦µÄ¹¤¾ß£¬ÓÉÓÚÆäʹÓüòÆÓ£¬ËÙÂʽϿ죬ÇÒ²»ÒÀÀµ³ýJDKÍâµÄÆäËû¿â£¬±»ÖÚ¶àÓû§ËùʹÓá£Jacks
¸ü¶à -
·½³Ìʽ×éÖ¯×ß©´ó×ÚÕë¶ÔWindows¹¥»÷¹¤¾ßÍþв
2017-04-15
±±¾©Ê±¼ä4ÔÂ14ÈÕÍí¼ä£¬Shadow Brokers×éÖ¯Ðû²¼ÁË´ËǰÇÔÈ¡µÄ²¿·Ö·½³Ìʽ£¨Equation Group£©×éÖ¯µÄÉñÃØÎļþ¡£Õⲿ·Ö±»¹ûÕæµÄÎļþÒ»¾±»Shadow Brokers×éÖ¯ÒÔÊýÒÚÃÀ½ðÅÄÂô£¬ÓÉÓÚÕⲿ·ÖÎļþ°üÀ¨ÁËÊý¸öÁîÈËÕ𺳵ĺڿ͹¤¾ß£¬ÓÃÀ´¹¥»÷°üÀ¨WindowsÔÚÄڵĶà¸öϵͳÎó²î¡£´Ë´Î×ß©µÄÎļþ°üÀ¨Èý²¿·Ö£ºWindows SwiftÒÔ¼°Odd¡£ ÆäÖÐWindowsĿ¼Ïµĺڿ͹¤¾ß°üÀ¨ÁËIIS 6 0Ô¶³ÌÎó²îµÄʹÓã»SMB1µÄÖØÁ¿¼¶Ê¹Ó㬿ÉÒÔÓÃÀ´¹¥»÷¿ª·ÅÁË445¶Ë¿ÚµÄ
¸ü¶à -
LinuxÄں˶þ´ÎУÑéÅÌËãÔ¶³Ì´úÂëÖ´ÐÐÎó²î
2017-04-14
¿ËÈÕ£¬LinuxÄں˱¬³öÒ»Ôò¸ßΣÎó²î£¨CVE-2016-10229£¬CNNVD-201703-210£©£¬ÔÚLinux 4 5֮ǰµÄϵͳÄÚºËÖУ¬µ±recvÒÔMSG_PEEK±ê¼Çλ±»Å²ÓÃʱ£¬¹¥»÷Õß¿ÉÒÔͨ¹ýUDPÀ´´¥·¢Ò»¸ö²»Çå¾²µÄ¶þ´ÎУÑéºÍÅÌË㣬ÒÔ´ËÀ´Ô¶³ÌÖ´ÐдúÂ룬¿ÉÄܵ¼ÖÂϵͳ±»¿ØÖÆ»òÕßÔì³É¾Ü¾ø·þÎñ¹¥»÷¡£ Ïà¹ØµØµã£º https: cve mitre org cgi-bin cvename cgi?name=CVE-2016-10229 https: git kernel org pub scm linux kernel git torvalds linux git commit ?id
¸ü¶à -
ISC BIND 9¶à¸öÔ¶³Ì¾Ü¾ø·þÎñÎó²î
2017-04-14
ÍâµØÊ±¼ä12ÈÕ£¨±±¾©Ê±¼ä13ÈÕ£©£¬ISCÐû²¼DNSÈí¼þBIND 9¸üУ¬ÐÞ¸´ÁË3¸öÔ¶³Ì¾Ü¾ø·þÎñ£¨DOS£©Îó²î¡£CVE±àºÅ£º CVE-2017-3136£¬ CVE-2017-3137£¬ CVE-2017-3138¡£ Ïà¹ØµØµã£º https: kb isc org article AA-01471 0 https: kb isc org article AA-01466 0 https: kb isc org article AA-01465 0 Îó²îÐÎòÈçÏ£º ÊÜÓ°ÏìµÄ°æ±¾ ?CVE-2017-3136Ó°ÏìµÄ°æ±¾£ºBIND 9 Version 9 8 0 -> 9 8 8-P1 BIND 9 Versi
¸ü¶à








