Aspose API¶à¸öRCE 0day·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-08-23

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-5032 £¬£¬£¬£¬£¬ £¬£¬£¬Î£ÏÕ¼¶±ð£ºÑϳÁ £¬£¬£¬£¬£¬ £¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8 £¬£¬£¬£¬£¬ £¬£¬£¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-5033 £¬£¬£¬£¬£¬ £¬£¬£¬Î£ÏÕ¼¶±ð£ºÑϳÁ £¬£¬£¬£¬£¬ £¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8 £¬£¬£¬£¬£¬ £¬£¬£¬¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-5041 £¬£¬£¬£¬£¬ £¬£¬£¬Î£ÏÕ¼¶±ð£ºÑϳÁ £¬£¬£¬£¬£¬ £¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8 £¬£¬£¬£¬£¬ £¬£¬£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


Aspose Aspose.Cells 19.1.0

Aspose Aspose.Words 18.11.0.0


·ì϶¸ÅÊö


°²È«×êÑÐÔ±ÔÚ¶à¸öAspose APIÖз¢ÏÖ¶à¸ö·ì϶ £¬£¬£¬£¬£¬ £¬£¬£¬¿Éµ¼ÖÂÔ¶³Ì¹¥»÷ÕßÔÚÊÜÓ°Ïì»úеÉÏÖ´ÐдúÂë¡£¡£ ¡£¡£¡£¡£¡£¡£


AsposeÌṩµÄAPIÖ¼ÔÚÔ®Êְѳֲ¢×ª»»´óÁ¿ÎĵµÌåʽ¡£¡£ ¡£¡£¡£¡£¡£¡£ÕâЩ°²È«È±µãÓ°ÏìÔ®ÊÖ´¦ÖÃPDF¡¢Î¢ÈíWordµÈ¶àÖÖÎļþÀàÐ͵ÄAPI¡£¡£ ¡£¡£¡£¡£¡£¡£


ÒªÀûÓÃÕâЩ·ì϶ £¬£¬£¬£¬£¬ £¬£¬£¬¹¥»÷Õß±ØÒªÏòÖ¸±êÓû§·¢ËÍÌØÊâ»ú¹ØµÄÎļþ £¬£¬£¬£¬£¬ £¬£¬£¬Ö®ºóÓÕÆ­ËûÃÇÔÚʹÓÃÏàÓ¦API֮ʱ´ò¿ª¸ÃÎļþ¡£¡£ ¡£¡£¡£¡£¡£¡£·ì϶¸ÅÊöÈçÏ£º


CVE-2019-5032

ËüÊÇ¿ÉÀûÓõĴø±í¶ÁÈ¡·ì϶ £¬£¬£¬£¬£¬ £¬£¬£¬´æÔÚÓÚAspose.Cells 19.1.0 °æ±¾µÄ LabelSst ¼Í¼½âÎöÆ÷ÖÓ×£¡£ ¡£¡£¡£¡£¡£¡£Apose. Cells ¿âÓÃÓÚ´óÁ¿ÆóÒµ¡¢ÒøÐк͵±¾Ö×éÖ¯»ú¹¹ÖÐ £¬£¬£¬£¬£¬ £¬£¬£¬ÓÃ×÷Êý¾Ý´¦ÖúÍת»»µÄÈí¼þ²úÆ·¡£¡£ ¡£¡£¡£¡£¡£¡£¸Ã·ì϶´æÔÚÓÚÕÆ¹Ü´¦Öà LabelSst ¼Í¼µÄº¯ÊýÖÐ £¬£¬£¬£¬£¬ £¬£¬£¬¿Éµ¼Ö¹¥»÷ÕßʹÓÃÌØÊâ»ú¹ØµÄ XLS ÎļþÓ¡·¢´ø±í¶ÁÈ¡ £¬£¬£¬£¬£¬ £¬£¬£¬´Ó¶øµ¼Ö¹¥»÷ÕßÔ¶³ÌÖ´ÐдúÂë¡£¡£ ¡£¡£¡£¡£¡£¡£


CVE-2019-5033

ËüÊÇ´æÔÚÓÚAspose.Cells 19.1.0 ¿âÖÐ Number ¼Í¼½âÎöÆ÷ÖеÄÒ»¸ö´ø±í¶ÁÈ¡ÎÊÌâ¡£¡£ ¡£¡£¡£¡£¡£¡£ºÍCVE-2019-5032 ÀàËÆ £¬£¬£¬£¬£¬ £¬£¬£¬ÈôÊÇÔ¶³Ì¹¥»÷ÕßÏòÊܺ¦Õß·¢ËÍ»ûÐÎ XLS Îļþ £¬£¬£¬£¬£¬ £¬£¬£¬Ôò¿Éµ¼Ö´úÂëÖ´Ðкó¹û¡£¡£ ¡£¡£¡£¡£¡£¡£


CVE-2019-5041

ËüÊÇ´æÔÚÓÚAspose.Words ¿â°æ±¾18.11.0.0 ÖÐ FnumMetaInfo º¯ÊýÖеÄÒ»¸ö»ùÓÚÕ»µÄ»º³åÇøÒç¶Âí½Å¡£¡£ ¡£¡£¡£¡£¡£¡£Aspose.Words ¿âÓÃÓÚºÍ DOC(X) ÎļþÓйصĶàÖÖ²Ù×÷ÖÓ×£¡£ ¡£¡£¡£¡£¡£¡£ËüºÍ Aspose.Cells Ò»Ñù £¬£¬£¬£¬£¬ £¬£¬£¬ÀûÓÃÓںö๫˾¡¢ÒøÐк͵±¾Ö×éÖ¯»ú¹¹ÖÐ £¬£¬£¬£¬£¬ £¬£¬£¬×÷ΪÊý¾Ý´¦ÖÃ/ת»»Èí¼þ²úÆ·µÄÒ»²¿ÃÅ¡£¡£ ¡£¡£¡£¡£¡£¡£¸Ã·ì϶´æÔÚÓÚÕÆ¹Ü´¦ÖÃÎĵµÔªÊý¾ÝµÄº¯ÊýÖÓ×£¡£ ¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓÃÌØÊâ»ú¹ØµÄ DOC Îļþ´¥·¢¸Ã·ì϶²¢ÊµÏÖÔ¶³Ì´úÂëÖ´ÐÓ×£¡£ ¡£¡£¡£¡£¡£¡£


·ì϶ÑéÖ¤


ÔÝÎÞPOC/EXP¡£¡£ ¡£¡£¡£¡£¡£¡£


½¨¸´½¨Òé


Ŀǰ³§ÉÌÔÝδ°ä²¼½¨¸´´ëÊ©½â¾ö´Ë°²È«ÎÊÌâ £¬£¬£¬£¬£¬ £¬£¬£¬½¨ÒéʹÓôËÈí¼þµÄÓû§ËæÊ±¹Ø×¢³§ÉÌÖ÷Ò³»ò²Î¿¼ÍøÖ·ÒÔ»ñÈ¡½â¾ö·¨×Ó£ºhttps://www.aspose.com¡£¡£ ¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0805