Ç徲ͨ¸æ
-
×ÛÊö LinuxµÄÓʼþ´«ÊäÊðÀíExim±»ÆØ³ö±£´æÒ»¸öÎó²î£¨CVE-2018-6789£©¡£¸ÃÎó²îÔ´ÓÚbase64½âÂ뺯ÊýÖеÄÒ»¸ö»º³åÇøÒç³öÎÊÌ⡣ͨÀýÏÂbase64±àÂëºóµÄ×Ö·û´®µÄ³¤¶ÈΪ4µÄ±¶Êý£¬¿ÉÊÇÓпÉÄÜÔÚ´«Êä»òÕß¶ñÒâ½á¹¹µÄÇéÐÎϵ¼Ö³¤¶È²»Îª4µÄ±¶Êý£¬ÖÂʹ³¤¶ÈÅÌËã¹ýʧ¡£Í¨¹ý¸ÃÎó²î£¬¹¥»÷Õß¿ÉÒÔÈÆ¹ý·À»¤»úÖÆÔÚÊÜÓ°ÏìµÄÓ¦ÓóÌÐòÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂë¡£Èô¹¥»÷ʵÑéʧ°ÜÈԿɵ¼Ö¾ܾø·þÎñÌõ¼þ¡£AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨ÖÐÐÄ£¨NTI£©ÏÔʾȫÇòEximÓÃÁ¿Áè¼Ý°ÙÍò¼¶
¸ü¶à -
Ò» Îó²î¸ÅÊö ¿ËÈÕ£¬ApacheÐû²¼Ç徲ͨ¸æ³ÆApache Tomcat 7¡¢8¡¢9¶à¸ö°æ±¾±£´æÇå¾²ÈÆ¹ýÎó²î¡£¹¥»÷Õß¿ÉÒÔʹÓÃÕâ¸öÎÊÌâ£¬ÈÆ¹ýijЩÇå¾²ÏÞÖÆÀ´Ö´ÐÐδ¾ÊÚȨµÄ²Ù×÷£¬Õâ¿ÉÄÜÓÐÖúÓÚ½øÒ»²½¹¥»÷¡£Apache Tomcat servlet ×¢Êͽç˵µÄÇå¾²Ô¼Êø£¬Ö»ÔÚservlet¼ÓÔØºó²ÅÓ¦ÓÃÒ»´Î¡£ÓÉÓÚÒÔÕâÖÖ·½·¨½ç˵µÄÇå¾²Ô¼Êø£¬Ó¦ÓÃÓÚURLģʽ¼°¸ÃµãÏÂÈκÎURL£¬ºÜ¿ÉÄÜÈ¡¾öÓÚservlet¼ÓÔØµÄÐò´Î£¬½«»á½«×ÊԴ̻¶¸øÎ´¾ÊÚȨ»á¼ûËüÃǵÄÓû§¡£ÏêÇéÇë²Î¿¼ÈçÏÂ
¸ü¶à -
×ÛÊö 2018Äê2ÔÂÔÚº«¹ú¾ÙÐÐµÄÆ½²ý¶¬¼¾°ÂÁÖÆ¥¿ËÔ˶¯»áÔâµ½²»Ã÷Éí·ÝµÄºÚ¿Í¹¥»÷¡£Æ¾Ö¤ÏÖÔ򵀮ÊÎöÀ´¿´£¬´Ë´Î¹¥»÷Ö÷ҪĿµÄÎªÆÆË𶬰»áµÄ˳Ëì¾ÙÐУ¬²¢Ã»Óз¢Ã÷ÆäËû¹¦Ð§¡£ÆÊÎöÖ°Ô±ÔÚÆÊÎö¹¥»÷Ñù±¾ºóÌåÏÖ£¬´Ë´Î¹¥»÷µÄËÝÔ´Óë¹¥»÷ÕßÉí·ÝÄÑÒÔ϶¨ÂÛ£¬¹¥»÷ÕßʹÓÃÁ˶à¸öÆäËû¹¥»÷ÕûÌåµÄÌØÕ÷£¬ÒÔ´ËÒÉ»óºÍÎ󵼯ÊÎöÖ°Ô±£¬Ê¹µÃ¹¥»÷ÕßÉí·ÝÄÑÒÔ±»È·¶¨¡£ÆÊÎöÖ°Ô±½«¸Ã¹¥»÷³ÆÎª“Olympic Destroyer”¡£ ²Î¿¼Á´½Ó£ºhttp: blog talosintelligence
¸ü¶à -
×ÛÊö ÍâµØÊ±¼ä2ÔÂ1ÈÕ£¬±±¾©Ê±¼ä2ÔÂ2ÈÕ£¬Adobe Flash Player±»·¢Ã÷±£´æÒ»¸ö0-dayÎó²î£¨CVE-2018-4878£©£¬²¢ÇÒÒѱ»¹¥»÷ÕßʹÓ㬸ÃÎó²îÓ°ÏìÏÖÔÚËùÓа汾¡£¹¥»÷Õß¿ÉÒÔÓÕʹÓû§·¿ª°üÀ¨¶ñÒâFlash´úÂëµÄMicrosoft OfficeÎĵµ£¬ÍøÒ³£¬À¬»øµç×ÓÓʼþµÈ¡£¶ñÒâ´úÂë±»ÒÔΪÊÇǶÈëÔÚMS WordÎĵµÖеÄFlash SWFÎļþÖС£AdobeÒ²Ðû²¼Í¨¸æÌåÏÖCVE-2018-4878µÄÎó²îʹÓÃÒѾ±£´æ£¬½«ÔÚ2ÔÂ5ÈյIJ¹¶¡ÖÐÐÞ¸´¸ÃÎó²î¡£Ïà¹ØÁ´½Ó£ºhttps: www bleepi
¸ü¶à -
×ÛÊö ¿ËÈÕ£¬Ê¹ÓÃ×Ô½ç˵ÐÒé´¦Öóͷ£³ÌÐò£¨custom protocol handlers£©µÄElectronÓ¦ÓóÌÐò±»·¢Ã÷±£´æÒ»¸öÔ¶³ÌÖ´ÐдúÂëÎó²î¡£¸ÃÎó²îÔ´ÓÚÓ¦ÓóÌÐòÔÚÉè¼ÆÊ±£¬½«×ÔÉí×¢²áΪÐÒéµÄĬÈÏ´¦Öóͷ£³ÌÐò£¨ÀýÈçmyapp: £©£¬ÎÞÂÛÐÒéÊÇÔõÑù×¢²áµÄ£¬ÀýÈç±¾»ú´úÂ룬Windows×¢²á±í»òÕßElectronµÄapp setAsDefaultProtocolClientµÄAPI£¬¶¼»áÊܵ½Ó°Ïì¡£ Ïà¹ØÁ´½Ó£º https: electronjs org blog protocol-handler-fixÊÜÓ°ÏìµÄ°æ±¾ ?Electron vers
¸ü¶à -
RedHatÇå¾²¸üÐÂÐÞ¸´OpenJDK1.8.0°æ±¾Îó²î
2018-01-19
×ÛÊö RedHatÐû²¼Çå¾²²¹¶¡Í¨¸æ£¬ÐÞ¸´Á˶à¸öjava-1 8 0-openjdkµÄÇå¾²ÎÊÌâ¡£Ïà¹ØÁ´½Ó£ºhttps: access redhat com errata RHSA-2018:0095 Îó²î¸ÅÊö ?ÔÚOpenJDKµÄHotspotºÍAWT×é¼þÖз¢Ã÷Á˶à¸öȱÏÝ¡£²»¿ÉÐŵÄJavaÓ¦ÓóÌÐò»òС³ÌÐò¿ÉÒÔʹÓÃÕâЩÎó²îÈÆ¹ýijЩJavaɳÏäÏÞÖÆ¡££¨CVE-2018-2582£¬CVE-2018-2641£©?OpenJDKµÄJNDI×é¼þÖеÄLDAPCertStoreÀàδÄÜÇå¾²µØ´¦Öóͷ£LDAPÒýÓ᣹¥»÷Õß¿ÉÄÜʹÓÃÕâ¸öÎó²î»ñȡ֤ÊéÊý¾Ý¡££¨CVE-2018-263
¸ü¶à








