Ç徲ͨ¸æ
-
×ÛÊö ¿ËÈÕ£¬Apache SynapseÐû²¼ÁËа汾ÐÞ¸´ÁËÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2017-15708£©¡£¸ÃÎó²îÔ´ÓÚApache Commons Collections×é¼þ£¬¹¥»÷Õß¿ÉÒÔͨ¹ý×¢ÈëÌØÖÆµÄÐòÁл¯¹¤¾ßÀ´Ô¶³ÌÖ´ÐдúÂë¡£Ïà¹ØÁ´½Ó£º http: www openwall com lists oss-security 2017 12 10 4?from=timeline https: commons apache org proper commons-collections security-reports html ÊÜÓ°ÏìµÄ°æ±¾ ApacheSynapse version < 3 0 1 ²»ÊÜ
¸ü¶à -
Fastjson autotype Ô¶³Ì´úÂëÖ´ÐÐÎó²î
2017-12-11
×ÛÊöFastjsonÓÚ½ñÄê3ÔÂ·ÝÆØ³öÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬¹Ù·½Ëæºóͨ¹ýĬÈϹرÕautotype¹¦Ð§ºÍ¿ªÆôºÚÃûµ¥½â¾öÁ˸ÃÎó²î£¬µ«¿ËÈÕÓÐÑо¿Ö°Ô±·¢Ã÷¸ÃºÚÃûµ¥±£´æÒ»¶¨ÏÞÖÆ£¬ÔÚ¿ªÆôautotype¹¦Ð§ºó¿ÉÒÔͨ¹ý¸Ä±äÏà¹ØÀàÃûÀ´ÈƹýºÚÃûµ¥£¬´Ó¶øÊµÏÖÔ¶³Ì´úÂëÖ´ÐС£Ïà¹ØÁ´½Ó£ºhttps: mp weixin qq com s Um28TlF6tLuPXP-PfgkpNwhttps: github com alibaba fastjson wiki security_update_20170315ÊÜÓ°ÏìµÄ°æ±¾Èôautotype¹¦Ð§¿ªÆô£¬ÔòÈ«°æ±¾¾ùÊÜÓ°
¸ü¶à -
×ÛÊö ±±¾©Ê±¼ä12ÔÂ7ÈÕ£¬Î¢Èí¹Ù·½Ðû²¼ÁËÒ»Ôòͨ¸æÌåÏÖÆä¶ñÒâÈí¼þ·À»¤ÒýÇæ£¨Malware Protection Engine£©±£´æÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2017-11937£©¡£¸ÃÎó²îÔ´ÓÚ·À»¤ÒýÇæÃ»ÓÐ׼ȷɨÃèÌØÖÆµÄÎļþ£¬µ¼ÖÂÄÚ´æË𻵡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔÚLocalSystemÕÊ»§µÄÇå¾²ÇéÐÎÖÐÖ´ÐÐí§Òâ´úÂë²¢¿ØÖÆÏµÍ³¡£ Ëæºó¹¥»÷Õß¿ÉÒÔ×°ÖóÌÐò;Éó²é£¬¸ü¸Ä»òɾ³ýÊý¾Ý;»òÕß½¨Éè¾ßÓÐÍêÕûÓû§È¨ÏÞµÄÐÂÕÊ»§¡£ Ïà¹ØÁ´½Ó£º https: portal msrc mic
¸ü¶à -
×ÛÊö ±±¾©Ê±¼ä12ÔÂ7ÈÕ£¬Apple¹Ù·½Ðû²¼ÁËÇ徲ͨ¸æÐÎòÁ˹ØÓÚmacOS High Sierra 10 13 2£¬Çå¾²¸üÐÂ2017-002 SierraºÍÇå¾²¸üÐÂ2017-005 El CapitanµÄÇå¾²¸üÐÂÄÚÈÝ£¬ÆäÖÐÉæ¼°Èô¸ÉԽȨ»á¼ûÒÔ¼°´úÂëÖ´ÐеÄÎó²î¡£Ïà¹ØÁ´½Ó£ºhttps: support apple com en-us HT208331¸üÐÂÏêÇélApache CVE-2017-9798ÊÊÓÃÓÚ£ºmacOS High Sierra 10 13 1£¬macOS Sierra 10 12 6£¬OS X El Capitan 10 11 6Ó°Ï죺´¦Öóͷ£¶ñÒâÖÆ×÷µÄApacheÉèÖÃ
¸ü¶à -
¶à¸öCisco WebExÍøÂçÂ¼ÖÆ²¥·ÅÆ÷Îó²î
2017-12-07
×ÛÊö ¿ËÈÕ£¬ÓÃÓڸ߼¶¼Í¼ÃûÌã¨ARF£©ºÍWebEx¼Í¼ÃûÌã¨WRF£©ÎļþµÄCisco WebExÍøÂçÂ¼ÖÆ²¥·ÅÆ÷Öб»·¢Ã÷±£´æ¶à¸öÎó²î¡£Ô¶³Ì¹¥»÷Õß¿ÉÒÔͨ¹ýµç×ÓÓʼþ»òURLÏòÓû§Ìṩ¶ñÒâµÄARF»òWRFÎļþ²¢ÓÕʹÓû§Æô¶¯Îļþ£¬´Ó¶øÊ¹ÓÃÕâЩÎó²î¡£ ʹÓÃÕâЩÎó²î¿ÉÄܻᵼÖÂÊÜÓ°ÏìµÄ²¥·ÅÆ÷Í߽⣬²¢ÇÒÔÚijЩÇéÐÎÏ£¬¿ÉÄÜÔÊÐíÔÚÄ¿µÄÓû§µÄϵͳÉÏÖ´ÐÐí§Òâ´úÂë¡£ Îó²îÐÅÏ¢ÈçÏ£º Title CVE ID Cisco Bug ID Cisco WebEx Network Recording
¸ü¶à -
Struts2 REST²å¼þÎó²î´¦Öóͷ£ÊÖ²á
2017-12-05
Îó²î¸ÅÊö ±±¾©Ê±¼ä2017Äê12ÔÂ1ÈÕÏÂÖ磬Struts¹Ù·½¹ûÕæÁËREST ²å¼þµÄÎó²îS2-054£¨CVE-2017-15707£©ºÍS2-055£¨CVE-2017-7525£©¡£ S2-054£º¸ÃÎó²îÔ´ÓÚREST²å¼þÒýÓõÄÒ»¸ö¹ýʱµÄJSON-lib¿â£¬µ±ÇëÇóÖаüÀ¨ÓÐÌØÖÆµÄJSON payload£¬·þÎñÆ÷¶Ëͨ¹ýJSON-lib¶ÔÊý¾ÝÆÊÎöʱ£¬¿ÉÔì³É¾Ü¾ø·þÎñ¹¥»÷¡£ S2-055£ºÓÉÓÚStruts2 ¿ò¼ÜÒýÓõı£´æ·´ÐòÁл¯Îó²îµÄJackson×é¼þ£¬¹¥»÷Õß¿ÉÔÚÌá½»µÄjsonÊý¾ÝÖÐǶÈë¶ñÒâ´úÂ룬·þÎñÆ÷¶Ëͨ¹ýJackson×é¼þ¶Ôjs
¸ü¶à








