Ç徲ͨ¸æ
-
Siemens ¶à¸ö²úÆ·Îó²îÍþвԤ¾¯Í¨¸æ
2019-04-10
¸ßΣÎó²î¸ÅÊö Ó°ÏìSIMATIC WinCC OAµÄÎó²îCVE-2018-3991ÊÇÓÉÓÚ22347 TCP¶Ë¿ÚµÄ»á¼û¿ØÖƲ»µ±¶ø±¬·¢£¬ÀÖ³ÉʹÓøÃÎó²î¿ÉÄܻᵼÖ¶ÑÒç³ö£¬´Ó¶øÒý·¢Ç±ÔÚµÄÔ¶³Ì´úÂëÖ´ÐС£ÊÜÓ°Ïì°æ±¾:SIMATIC WinCC OA Version 3 14 < P025SIMATIC WinCC OA Version 3 15 < P018SIMATIC WinCC OA Version 3 16 < P007²»ÊÜÓ°Ïì°æ±¾:SIMATIC WinCC OA Version 3 14 PO25SIMATIC WinCC OA Version 3 15 PO18SIMATIC Win
¸ü¶à -
΢ÈíÐû²¼4Ô²¹¶¡ÐÞ¸´76¸öÇå¾²ÎÊÌâÇå¾²Íþвͨ¸æ
2019-04-10
΢ÈíÓÚÖܶþÐû²¼ÁË4ÔÂÇå¾²¸üв¹¶¡£¬ÐÞ¸´ÁË76¸ö´Ó¼òÆÓµÄÓÕÆ¹¥»÷µ½Ô¶³ÌÖ´ÐдúÂëµÄÇå¾²ÎÊÌ⣬²úÆ·Éæ¼° NET Core¡¢Adobe Flash Player¡¢CSRSS¡¢Microsoft Browsers¡¢Microsoft Edge¡¢Microsoft Exchange Server¡¢Microsoft Graphics Component¡¢Microsoft JET Database Engine¡¢Microsoft Office¡¢Microsoft Office SharePoint¡¢Microsoft scripting Engine¡¢Microsoft Windows¡¢Microsoft XML¡¢Open Source
¸ü¶à -
¿ËÈÕ£¬Confluence¹Ù·½Ðû²¼ÁËSSRFÎó²î£¨CVE-2019-3395£©¼°Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2019-3396£©µÄÇ徲ͨ¸æ£¬¹¥»÷ÕßʹÓÃÎó²î¿ÉʵÏÖÔ¶³Ì´úÂëÖ´ÐС¢·þÎñÆ÷¶ËÇëÇóαÔì¡£´Ë´Îͨ¸æµÄÎó²î»®·Ö±£´æÓÚWebDAV¡¢¼°WidgetÅþÁ¬Æ÷ÖС£Îó²î¸ÅÊö¿ËÈÕ£¬Confluence¹Ù·½Ðû²¼ÁËSSRFÎó²î£¨CVE-2019-3395£©¼°Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2019-3396£©µÄÇ徲ͨ¸æ£¬¹¥»÷ÕßʹÓÃÎó²î¿ÉʵÏÖÔ¶³Ì´úÂëÖ´ÐС¢·þÎñÆ÷¶ËÇëÇóαÔì¡£´Ë´Îͨ¸æµÄÎó²î»®·Ö±£´æÓÚWebDAV¡¢¼°Widg
¸ü¶à -
ÏÖÔÚ×îа汾µÄIEºÍEdgeä¯ÀÀÆ÷¾ùÊÜÓ°Ïì×èÖ¹±¾Í¨¸æÐû²¼Ê±£¬Microsoft¹Ù·½»¹Î´ÐÞ¸´ÉÏÊöÎó²î¡£ÉùÃ÷±±¾©ÉñÖݾÅÓÎÀϸçÐÅÏ¢Çå¾²¿Æ¼¼¹É·ÝÓÐÏÞ¹«Ë¾£¨¼ò³Æ¾ÅÓÎÀÏ¸ç¿Æ¼¼£©½¨ÉèÓÚ2000Äê4Ô£¬×ܲ¿Î»ÓÚ±±¾©¡£ÔÚº£ÄÚÍâÉèÓÐ30¶à¸ö·ÖÖ§»ú¹¹£¬ÎªÕþ¸®¡¢ÔËÓªÉÌ¡¢½ðÈÚ¡¢ÄÜÔ´¡¢»¥ÁªÍøÒÔ¼°½ÌÓý¡¢Ò½ÁƵÈÐÐÒµÓû§£¬Ìṩ¾ßÓн¹µã¾ºÕùÁ¦µÄÇå¾²²úÆ·¼°½â¾ö¼Æ»®£¬×ÊÖú¿Í»§ÊµÏÖÓªÒµµÄÇ徲˳³©ÔËÐС£±±¾©ÉñÖݾÅÓÎÀϸçÐÅÏ¢Çå¾²¿Æ¼¼¹É·ÝÓÐÏÞ¹«Ë¾ÓÚ2014Äê1ÔÂ29ÈÕÆðÔÚÉîÛÚ֤ȯ
¸ü¶à -
¿ËÈÕ£¬¹Ù·½¹ûÕæÁËApache Tomcat HTTP 2¾Ü¾ø·þÎñÎó²î£¬¸ÃÎó²îÊÇÓÉÓÚÓ¦Ó÷þÎñÔÊÐíÎüÊÕ´ó×ÚµÄÉèÖÃÁ÷Á¿£¬²¢ÇÒ¿Í»§¶ËÔÚûÓжÁдÇëÇóµÄÇéÐÎÏ¿ÉÒÔ³¤Ê±¼ä¼á³ÖÅþÁ¬¶øµ¼Ö¡£ÈôÊÇÀ´×Ô¿Í»§¶ËµÄÅþÁ¬ÇëÇó¹ý¶à£¬×îÖտɵ¼Ö·þÎñ¶ËÏ̺߳ľ¡£¬¹¥»÷ÕßÀÖ³ÉʹÓôËÎó²î¿ÉʵÏÖ¶ÔÄ¿µÄµÄ¾Ü¾ø·þÎñ¹¥»÷¡£ÊÜÓ°Ïì°æ±¾²»ÊÜÓ°Ïì°æ±¾Ó°ÏìÅŲéͨ³£ÔÚApache Tomcat¹ÙÍøÏÂÔØµÄ×°ÖðüÃû³ÆÖлá°üÀ¨ÓÐÄ¿½ñTomcatµÄ°æ±¾ºÅ£¬Óû§¿Éͨ¹ýÉó²é½âѹºóµÄÎļþ¼ÐÃû³ÆÀ´È·¶¨
¸ü¶à -
Îó²î¸ÅÊö¿ËÈÕ£¬Çå¾²Ñо¿Ö°Ô±Åû¶ÁËPostgreSQLÌáȨ´úÂëÖ´ÐÐÎó²î£¨CVE-2019-9193£©µÄÎó²îϸ½Ú£¬¾ßÓÐÊý¾Ý¿â·þÎñ¶ËÎļþ¶ÁȨÏ޵Ĺ¥»÷ÕßʹÓôËÎó²î£¬¿ÉÖ´ÐÐí§ÒâϵͳÏÂÁî¡£PostgreSQLÊÇÒ»¿î¹¦Ð§Ç¿Ê¢µÄÊý¾Ý¿âÈí¼þ£¬¿ÉÔËÐÐÔÚËùÓÐÖ÷Á÷²Ù×÷ϵͳÉÏ£¬°üÀ¨Linux¡¢Windows¡¢Mac OS XµÈ¡£´Ë´ÎÅû¶µÄÎó²î±£´æÓÚµ¼Èëµ¼³öÊý¾ÝµÄÏÂÁî“COPY TO FROM PROGRAM””ÖУ¬“pg_read_server_files”×éÄÚÓû§Ö´ÐÐÉÏÊöÏÂÁîºó£¬¿É»ñÈ¡Êý¾Ý¿â³¬µÈÓû§È¨ÏÞ
¸ü¶à








