CVE编号
CVE-2019-1009利用情况
暂无补丁情况
N/A披露时间
2019-06-11漏洞描述
当Windows GDI组件不正确地公开其内存内容(即“Windows GDI信息泄露漏洞”)时,存在信息泄露漏洞。该CVE ID独特于CVE-2019-0968,CVE-2019-0977,CVE-2019-1010,CVE-2019-1011,CVE-2019-1012,CVE-2019-1013,CVE-2019-1015,CVE- 2019-1016,CVE-2019-1046,CVE-2019-1047,CVE-2019-1048,CVE-2019-1049,CVE-2019-1050。解决建议
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:https://portal.msrc.microsoft.com/en-us/security-guidance
参考链接 |
|
---|---|
https://lists.apache.org/thread.html/39723d8227b248781898c200aa24b15468367328... | |
https://lists.apache.org/thread.html/da9ee189d1756f8508d0f2386d8e25aca5a6df54... | |
https://lists.apache.org/thread.html/fb6c84fd387de997e5e366d50b0ca331a328c466... | |
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2019-1009 | |
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1009 |
受影响软件情况
# | 类型 | 厂商 | 产品 | 版本 | 影响面 | ||||
1 | |||||||||
---|---|---|---|---|---|---|---|---|---|
运行在以下环境 | |||||||||
系统 | alibaba_cloud_linux_2.1903 | tika | * |
Up to (excluding) 2.4.6-95.2.al7 |
|||||
运行在以下环境 | |||||||||
系统 | alpine_3.10 | tika | * |
Up to (excluding) 2.4.41-r0 |
|||||
运行在以下环境 | |||||||||
系统 | alpine_3.11 | tika | * |
Up to (excluding) 2.4.41-r0 |
|||||
运行在以下环境 | |||||||||
系统 | alpine_3.12 | tika | * |
Up to (excluding) 2.4.41-r0 |
|||||
运行在以下环境 | |||||||||
系统 | alpine_3.13 | tika | * |
Up to (excluding) 2.4.41-r0 |
|||||
运行在以下环境 | |||||||||
系统 | alpine_3.7 | tika | * |
Up to (excluding) 2.4.41-r0 |
|||||
运行在以下环境 | |||||||||
系统 | alpine_3.8 | tika | * |
Up to (excluding) 2.4.41-r0 |
|||||
运行在以下环境 | |||||||||
系统 | alpine_3.9 | tika | * |
Up to (excluding) 2.4.41-r0 |
|||||
运行在以下环境 | |||||||||
系统 | alpine_edge | tika | * |
Up to (excluding) 2.4.41-r0 |
|||||
运行在以下环境 | |||||||||
系统 | amazon linux_2 | tika | * |
Up to (excluding) 2.4.41-1.amzn2.0.1 |
|||||
运行在以下环境 | |||||||||
系统 | amazon linux_AMI | tika | * |
Up to (excluding) 2.4.41-1.88.amzn1 |
|||||
运行在以下环境 | |||||||||
系统 | amazon_2 | httpd | * |
Up to (excluding) 2.4.41-1.amzn2.0.1 |
|||||
运行在以下环境 | |||||||||
系统 | amazon_AMI | httpd | * |
Up to (excluding) 2.4.41-1.88.amzn1 |
|||||
运行在以下环境 | |||||||||
系统 | centos_8 | httpd | * |
Up to (excluding) 2.4.37-30.module+el8.3.0+7001+0766b9e7 |
|||||
运行在以下环境 | |||||||||
系统 | debian_10 | tika | * |
Up to (excluding) 2.4.38-3+deb10u1 |
|||||
运行在以下环境 | |||||||||
系统 | debian_8 | tika | * |
Up to (excluding) 2.4.10-10+deb8u1 |
|||||
运行在以下环境 | |||||||||
系统 | debian_9 | tika | * |
Up to (excluding) 2.4.25-3+deb9u9 |
|||||
运行在以下环境 | |||||||||
系统 | fedora_29 | tika | * |
Up to (excluding) 2.4.41-1.fc29 |
|||||
运行在以下环境 | |||||||||
系统 | fedora_30 | tika | * |
Up to (excluding) 2.4.41-1.fc30 |
|||||
运行在以下环境 | |||||||||
系统 | microsoft | windows_7 | - | - | |||||
运行在以下环境 | |||||||||
系统 | microsoft | windows_server_2008 | - | - | |||||
运行在以下环境 | |||||||||
系统 | microsoft | windows_server_2008 | r2 | - | |||||
运行在以下环境 | |||||||||
系统 | opensuse_Leap_15.0 | tika | * |
Up to (excluding) 2.4.33-lp151.8.6.1 |
|||||
运行在以下环境 | |||||||||
系统 | opensuse_Leap_15.1 | tika | * |
Up to (excluding) 2.4.33-lp151.8.6.1 |
|||||
运行在以下环境 | |||||||||
系统 | oracle linux_7 | tika | * |
Up to (excluding) 2.4.6-95.0.1.el7 |
|||||
运行在以下环境 | |||||||||
系统 | oracle linux_8 | tika | * |
Up to (excluding) 2.4.37-30.0.1.module+el8.3.0+7816+49791cfd |
|||||
运行在以下环境 | |||||||||
系统 | oracle_7 | httpd | * |
Up to (excluding) 2.4.6-95.0.1.el7 |
|||||
运行在以下环境 | |||||||||
系统 | oracle_8 | httpd | * |
Up to (excluding) 2.4.37-30.0.1.module+el8.3.0+7816+49791cfd |
|||||
运行在以下环境 | |||||||||
系统 | redhat_7 | httpd | * |
Up to (excluding) 0:2.4.6-95.el7 |
|||||
运行在以下环境 | |||||||||
系统 | redhat_8 | httpd | * |
Up to (excluding) 2.4.37-30.module+el8.3.0+7001+0766b9e7 |
|||||
运行在以下环境 | |||||||||
系统 | sles_12 | apache2 | * |
Up to (excluding) 2.4.23-29.43 |
|||||
运行在以下环境 | |||||||||
系统 | sles_12_SP4 | tika | * |
Up to (excluding) 2.4.23-29.43.1 |
|||||
运行在以下环境 | |||||||||
系统 | sles_12_SP5 | tika | * |
Up to (excluding) 2.4.23-29.69.1 |
|||||
运行在以下环境 | |||||||||
系统 | suse_12_SP4 | httpd | * |
Up to (excluding) 2.4.23-29.43.1 |
|||||
运行在以下环境 | |||||||||
系统 | ubuntu_16.04_lts | apache2 | * |
Up to (excluding) 2.4.18-2ubuntu3.12 |
|||||
运行在以下环境 | |||||||||
系统 | ubuntu_18.04_lts | apache2 | * |
Up to (excluding) 2.4.29-1ubuntu4.10 |
|||||
- 攻击路径 网络
- 攻击复杂度 低
- 权限要求 无
- 影响范围 未更改
- 用户交互 需要
- 可用性 无
- 保密性 高
- 完整性 无
还没有评论,来说两句吧...