ºìÁªLinuxÃÅ»§
Linux°ïÖú

Flash°²È«Â©¶´¿ÉÖÂPC¸ÐȾÀÕË÷Èí¼þ Adobe·¢²¼½ô¼±¸üÐÂ

·¢²¼Ê±¼ä:2016-04-08 15:00:16À´Ô´:ºìÁª×÷Õß:teisac
À´Ô´£º·ï»ËÍø¿Æ¼¼

¾Ý·͸É籨µÀ£¬AdobeÔÚÖÜËÄÃæÏò»¥ÁªÍøä¯ÀÀÆ÷¹ã·ºÊ¹ÓõÄFlashÈí¼þ·¢²¼½ô¼±¸üС£Ñо¿ÈËÔ±´Ëǰ·¢ÏÖÁËÒ»¸öFlash°²È«Â©¶´£¬¸Ã©¶´»á±»ÓÃÓÚÏò Windows PC´«²¥ÀÕË÷Èí¼þ¡£Ä¿Ç°£¬Óâ10ÒÚÓû§ÔÚWindows¡¢Mac¡¢Chrome OSÒÔ¼°LinuxµçÄÔÉÏʹÓÃFlash¡£Adobe¶½´ÙÕâЩÓû§¾¡¿ìÉý¼¶Flash¡£°²È«Ñо¿ÈËÔ±±íʾ£¬¸Ã©¶´Äܹ»±»¡°ÍøÕ¾¹ÒÂí¹¥»÷¡±(drive- by)ËùÀûÓᣵ±Óû§·ÃÎÊÊܸÐȾµÄÍøÕ¾Ê±£¬µçÄԾͻᱻ°²×°ÉÏÀÕË÷Èí¼þ¡£

ÀÕË÷Èí¼þ¶ÔÊý¾Ý¼ÓÃÜ£¬Ëø¶¨µçÄÔ£¬È»ºóÏòÓû§·¢³öÀÕË÷֪ͨ£¬ÒªÇ󸶿î²ÅÄܽâËøÃ¿Ò»Ì¨ÊܸÐȾµÄPC£¬Ë÷Òª·ÑÓÃÒ»°ãÔÚ200ÃÀÔªÖÁ600ÃÀÔªÖ®¼ä²»µÈ¡£

ÈÕ±¾°²È«Èí¼þ¿ª·¢ÉÌÇ÷ÊÆ¿Æ¼¼±íʾ£¬¹«Ë¾ÒÑÏòAdobe·¢³öÔ¤¾¯¡£Ç÷ÊÆ¿Æ¼¼·¢ÏÖ£¬×îÔç´Ó3ÔÂ31ÈÕ¿ªÊ¼£¬¹¥»÷ÕßÀûÓÃFlash©¶´Í¨¹ýÒ»ÖÖÃûΪ¡°Cerber¡±µÄÀÕË÷Èí¼þ¸ÐȾµçÄÔ¡£CerberÖÆ¶¨ÁËÒ»ÖÖ¡°ÉùÒô¡±²ßÂÔ£¬Í¨¹ý´óÉù¶Á³öÀÕË÷ÐÅÖÆÔìÒ»ÖÖ½ôÆÈ¸Ð£¬´ÙʹÓû§¸¶¿î¡£

Adobe×îв¹¶¡ÐÞ¸´ÁË´ËǰµÄÒ»¸öδ֪°²È«Â©¶´¡£ÕâЩ©¶´Ò²¾ÍÊÇËùνµÄ¡°ÁãÈÕ©¶´¡±£¬Ê®·ÖΣÏÕ£¬ÒòΪËüºÜÄÑ·ÀÓù£¬Èí¼þ¿ª·¢É̺Ͱ²È«¹«Ë¾¸ù±¾Ã»ÓÐʱ¼äÕÒ³ö·â¶ÂÕâһ©¶´µÄ·½·¨¡£ÕâÖÖ©¶´Í¨³£±»Õþ¸®Ê¹ÓôÓʼäµýºÍÆÆ»µ»î¶¯£¬¶øºÚ¿ÍÇãÏòÓÚʹÓÃÖÚËùÖÜÖªµÄ©¶´·¢¶¯¹¥»÷¡£

¹¥»÷Õß½èÖú¡°ÁãÈÕ©¶´¡±´«²¥ÀÕË÷Èí¼þ͹ÏÔ³öÀÕË÷Èí¼þÎÊÌâÈÕÒæÑÏÖØ£¬ËüÆÆ»µÁËÃÀ¹úºÍÅ·ÖÞÐí¶à»ú¹¹µÄÕý³£ÔËÓª£¬°üÀ¨Ò½Ôº¡¢¾¯²ì¾ÖÒÔ¼°Ñ§Ð£¡£

½ü¼¸¸öÔ£¬ÀÕË÷Èí¼þ¹¥»÷²»¶ÏÔö¶à£¬²¢ÇÒʹÓÃÁËÔ½À´Ô½ÏȽøµÄ¼¼ÊõºÍ¹¤¾ß¡£¡°ÁãÈÕ©¶´µÄʹÓÃ͹ÏÔ³öºÚ¿Í¹¥»÷¼¼ÊõµÄÉý¼¶Ç±Á¦£¬¡±ÍøÂ簲ȫ¹«Ë¾FireEye·¢ÑÔÈË¿ËÀ­¿Ë?˹Íжû(Kyrk Storer)±íʾ£¬¡°ÎÒÃÇ֮ǰ¼û¹ýʹÓÃÁãÈÕ©¶´µÄÀÕË÷Èí¼þºÍ·¸×ïÈí¼þ£¬µ«ÊǺÜÉÙ¡£¡±

FireEye³Æ£¬Flash©¶´±»ÖÃÓÚMagnitude©¶´¹¤¾ß°üÄÚ´«²¥ÀÕË÷Èí¼þ¡£Â©¶´¹¤¾ß°üÊÇÒ»ÖÖÔÚµØÏÂÂÛ̳ÖÐÏúÊÛµÄ×Ô¶¯»¯¹¤¾ß£¬Äܹ»ÈúڿÍͨ¹ýÊܸÐÈ¾ÍøÕ¾ÁîPC¸ÐȾ²¡¶¾¡£¡°ÍøÕ¾¹ÒÂí¹¥»÷¡±¾ÍÀûÓÃÁË©¶´¹¤¾ß°ü£¬×Ô¶¯¹¥»÷ÒÑä¯ÀÀÊܸÐÈ¾ÍøÕ¾µÄÓû§µçÄÔ¡£

Á˽â¸ü¶à£º

https://www.sophos.com/en-us/threat-center/threat-analyses/vulnerabilities/VET-000886.aspx
ÎÄÕÂÆÀÂÛ

¹²ÓÐ 0 ÌõÆÀÂÛ