ºÀÔ˹ú¼ÊÔƹٷ½É̳Ç
ÌìÔªÊý¾ÝÍø
ÔÆERP¹Ù·½É̳Ç
×÷ΪÖйú×î¾ßÓ°ÏìÁ¦µÄITÆ·ÅÆÖ®Ò»£¬ºÀÔ˹ú¼Ê½èÅÌËãÖ®Á¦£¬´òÔ컥Áª»¥Í¨µÄÊý¾ÝÉú̬£¬ÒÔÊý¾ÝÖ®Ãû£¬¿ªÆôÈ«ÐÂÕ³̵ÄÌìÏÂÎÄÃ÷¡£
Éó²é¸ü¶àÊÓƵ >ºÀÔ˹ú¼ÊÃñÕþÔÆƽ̨ƾ֤ÌìÏÂÃñÕþϽµµÍìÏÈ¡¢Õþ¸®²¿·ÖÒ»Á÷µÄ±ê×¼ÍýÏëÉè¼Æ£¬Æ½Ì¨ÈÚºÏÃñÕþÓªÒµ¹ÜÀí¡¢¹«¹²·þÎñ¡¢´óÊý¾Ý×ÊÔ´·þÎñ¡£
ÏàʶÏêÇé >Çå¾²Ñо¿¹«Ë¾ EclypsiumÆعâÁËLinux Grub2Ö¸µ¼¼ÓÔسÌÐòÖÐÒ»¸öÃûΪ¡°BootHole¡±£¨CVE-2020-10713£©µÄÎó²î¡£´ËÎó²îÔÊÐí¹¥»÷ÕßЮÖÆÖ¸µ¼Àú³Ì²¢ÔÚϵͳÆô¶¯Ê±´úÖ´ÐжñÒâ´úÂ룬×ÝȻʹÓÃUEFI Secure BootµÄϵͳҲ¿ÉÒÔʹÓôËÎó²îÈƹý¡£
Grub2 boot loaderͨ¹ýgrub.cfgÎļþÉèÖ㬸ÃÎļþÖаüÀ¨¶à¸ötokens×Ö·û´®¡£ÔÚ³õʼָµ¼¼ÓÔسÌÐò£¨³ÆΪshim£©¼ÓÔØÖ®ºó£¬×îÏȼÓÔØÏ¢ÕùÎögrub.cfgÉèÖÃÎļþ¡£ÔÚÆÊÎö½×¶Î£¬ÉèÖÃÎļþµÄÄÚÈݱ»¸´ÖƵ½ÄÚ´æµÄÄÚ²¿»º³åÇøÖд洢¡£µ±tokens³¤¶È´óÓÚÄÚ²¿»º³åÇø¾Þϸʱ»áµ¼Ö»º³åÇøÒç³öÎÊÌâ¡£¹¥»÷Õß¿ÉÒÔʹÓôËÎó²îÖ´ÐÐí§Òâ´úÂ룬½øÒ»²½Ð®ÖÆÅÌËã»úµÄÖ¸µ¼Àú³Ì²¢ÈƹýSecure Boot±£»¤¡£
²úÆ·Ãû³Æ | ÊÜÓ°Ïì²úÆ·°æ±¾ | ÐÞ¸´²¹¶¡°ü/Éý¼¶°ü°æ±¾ |
¡¡¡¡AS13000 | AS13000 > 3.5.0.1 | grub2-2.02-0.65-AS13000-update.tar.gz |
ICS | ICS<=5.8.1 | V5.8.1°æ±¾Í¨¹ý²¹¶¡¾ÙÐÐÐÞ¸´£¬²¹¶¡°üÃû³Æ£º IncloudSphere-V5R08B017-b1-M001.hotfix.zip IncloudSphere-V5R08B017-b1-S001.hotfix.zip£» СÓÚV5.8.1°æ±¾²úÆ·£¬ÐèÒªÏÈÉý¼¶µ½v5.8.1°æ±¾£¬ÔÙͨ¹ý²¹¶¡¾ÙÐÐÐÞ¸´¡£ |
ICOS | ICOS>=5.2,ICOS<=5.8 | ICOS-CVE-2020-10713.rar |
ISIB | ISIB-V2.1.1-20200605_1610-CN֮ǰµÄ°æ±¾ | ISIB-v2.1.1-sp1-x86_64-20200831.rpm |
ISPIM | 1. ISPIM-V2.1.1-20200827_2041_CN֮ǰµÄ°æ±¾ 2. ISPIM-V2.1.1-20200827_2112_EN֮ǰµÄ°æ±¾ |
1. ISPIM-V2.1.1-20200827_2041_CN 2. ISPIM-V2.1.1-20200827_2112_EN 3. ²¹¶¡°ü£ºispimV2.1.1-sp1-x86_64-20200831.rpm |
¹¥»÷Õß¿ÉÒÔʹÓôËÎó²îÖ´ÐÐí§Òâ´úÂ룬½øÒ»²½Ð®ÖÆÅÌËã»úµÄÖ¸µ¼Àú³Ì²¢ÈƹýSecure Boot±£»¤, ¿ØÖÆÊÜÓ°ÏìµÄ×°±¸¡£
Îó²îµÃ·Ö£ºCVE | V3.1 Vector(Base) | Base Score | V3.1 Vector(Temporal Score) | Temporal Score |
CVE-2020-10713 | AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H | 8.2 | E:U/RL:O/RC:C | 7.1 |
Îó²îÔµ¹ÊÔÓÉ£ºGRUB2 ÔÚ´¦Öóͷ£Æä×ÔÉíµÄÉèÖÃÎļþ grub.cfg ʱ±£´æ»º³åÇøÒç³öÎó²î¡£¹¥»÷Õßͨ¹ý½¨ÉèÌØÖÆµÄ grub.cfg Îļþ£¬ÔÚÏÂÒ»´ÎÖØÆôºó¹¥»÷Õß¿ÉÒÔ²»ÊÜÏÞÖƵĿØÖÆÊÜÓ°ÏìµÄ×°±¸¡£
ʹÓÃÌõ¼þ£ºÔ¶³Ìroot»á¼û£¬¿ÉÐÞ¸Ägrub.cfgÎļþ¡£
AS13000Óû§Ö±½ÓÁªÏµ¿Í»§·þÎñÖ°Ô±»ò·¢ËÍÓʼþÖÁsun.meng@inspur.com£¬»ñÈ¡²¹¶¡£¬ÒÔ¼°Ïà¹ØµÄÊÖÒÕÐÖú¡£
ICOS¡¢ICSÓû§Ö±½ÓÁªÏµÖ§³ÖÖ°Ô±»ñÈ¡²¹¶¡ÒÔ¼°Ïà¹ØµÄÊÖÒÕÐÖú¡£
ISPIM:ÏÂÔØ
ISIB:ÏÂÔØ
ÔÝÎÞÕë¶Ô´ËÎó²îµÄ»º½â²½·¥
Îó²îȪԴ£ºÇå¾²Ñо¿¹«Ë¾ EclypsiumÅû¶
¸üмͼ£º20200812-V1.0-Initial Release
20200831-V1.1-Update ÔöÌíÊÜÓ°Ïì²úÆ·Çåµ¥
20200901-V1.2-Update ÔöÌíÊÜÓ°Ïì²úÆ·Çåµ¥
ÎÞ
ºÀÔ˹ú¼ÊÇå¾²Ó¦¼±ÏìÓ¦¶ÔÍâ·þÎñ£ººÀÔ˹ú¼ÊÒ»Ö±Ö÷Õž¡È«Á¦°ü¹Ü²úÆ·Óû§µÄ×îÖÕÀûÒ棬×ñÕÕÈÏÕæÈεÄÇå¾²ÊÂÎñÅû¶ÔÔò£¬²¢Í¨¹ý²úÆ·Çå¾²ÎÊÌâ´¦Öóͷ£»úÖÆ´¦Öóͷ£²úÆ·Çå¾²ÎÊÌâ¡£
·´ÏìºÀÔ˹ú¼ÊÏà¹ØµÄ²úÆ·Çå¾²ÎÊÌâ,Çë·´ÏìÖÁºÀÔ˹ú¼ÊPSIRTÓÊÏäsec@inspur.com£¬ÏêÇé²Î¿¼£º/lcjtww/2312126/2432763/index.html
·þÎñÆ÷¡¢´æ´¢¡¢ÍøÂç²úÆ·¹ºÖÃÈÈÏߣº
ERP¡¢¹ÜÀíÈí¼þ¹ºÖÃÈÈÏߣº
ÔÆ·þÎñ²úÆ·ÏúÊÛÈÈÏߣº
ºÀÔ˹ú¼ÊÍøÂçÊÛºóÈÈÏߣº