Intel嚴重漏洞 OS更新將會降低效能 - 3C
By Tracy
at 2018-01-05T09:45
at 2018-01-05T09:45
Table of Contents
昨晚開始微軟陸續對WIN7、WIN8、WIN10等各版本的作業系統
推送Meltdown修補程式,
如果你的Windows更新遲遲沒有收到更新通知,
有可能是因為修補程式和系統上的防毒軟體不相容,
為了避免引發系統當機藍屏所以被延遲了推送,
Kevin Beaumont製作了一個表格列出目前已知
相容和不相容Meltdown修補程式的防毒軟體
https://docs.google.com/spreadsheets/d/184wcDt9I9TUNFFbsAVLpzAtckQxYiuirADzf3cL42FQ/htmlview?sle=true#gid=0
https://goo.gl/tdzLwa
相容
Kaspersky, ESET, Avast, Symantec/Norton, F-Secure, Windows Defender
不相容
Sophos, Trend Micro, McAfee, Bitdefender, Webroot
需等待防毒軟體推出相容性修正後才能更新
其他軟硬體和服務商目前的對策:
AMD: 官方表示目前揭露的三種攻擊
1. Bounds Check Bypass (CVE-2017-5753)
可由軟體/OS更新來解決,對效能影響極小
2. Branch Target Injection (CVE-2017-5715 也就是Spectre)
由於架構的不同,AMD"相信"受到這個攻擊而洩漏資料的風險趨近0
3. Rogue Data Cache Load (CVE-2017-5754 也就是Meltdown)
AMD表示完全免疫Meltdown
https://www.amd.com/en/corporate/speculative-execution
Intel: 不是只有我,大家都有問題
Recent reports that these exploits are caused by a “bug” or a “flaw”
and are unique to Intel products are incorrect.
Based on the analysis to date, many types of computing devices
— with many different vendors’ processors and operating systems
— are susceptible to these exploits.
https://newsroom.intel.com/news/intel-responds-to-security-research-findings/
ARM: 受影響的處理器列表
https://developer.arm.com/support/security-update
Android: Google的裝置已在1月2號推送安全性更新,
其他廠商需等待廠商推送更新
macOS: 蘋果目前還沒有官方說明,不過根據Alex Ionescu表示,
Sierra 10.13.2已在12月3號的時候修補了這個問題
https://twitter.com/aionescu/status/948609809540046849
iOS: 目前還沒有官方說明
Linux: 開發人員已經為此工作了好幾個月,
許多發行版已經修補了這個問題
Chrome OS: 已在12月15號的v63修補
Google Chrome 瀏覽器: 將會在1月23號發行的v64修補這個問題,
在這之前,Google建議使用者打開v63的Strict Site Isolation功能,
不過開啟這個功能會增加Chrome使用的記憶體
Mozilla Firefox: 已推送57.0.4版本更新緩解
Apple Safari: 目前沒有說明
Amazon AWS:
https://aws.amazon.com/tw/security/security-bulletins/AWS-2018-013/
Microsoft Azure:
https://support.microsoft.com/en-us/help/4072699/important-information-regarding-the-windows-security-updates-released
VMware: 官方列出受到影響的版本以及更新修補程式
https://www.vmware.com/us/security/advisories/VMSA-2018-0002.html
Nvidia: 官方的聲明指出,"相信"自家的GPU免疫上述的漏洞,
同時會更新驅動幫助緩解CPU的安全性問題。
來源
https://www.bleepingcomputer.com/news/security/list-of-meltdown-and-spectre-vulnerability-advisories-patches-and-updates/
https://goo.gl/ScfMbQ
https://www.tomsguide.com/us/meltdown-spectre-fixes,news-26326.html
https://goo.gl/6fydnw
--
推送Meltdown修補程式,
如果你的Windows更新遲遲沒有收到更新通知,
有可能是因為修補程式和系統上的防毒軟體不相容,
為了避免引發系統當機藍屏所以被延遲了推送,
Kevin Beaumont製作了一個表格列出目前已知
相容和不相容Meltdown修補程式的防毒軟體
https://docs.google.com/spreadsheets/d/184wcDt9I9TUNFFbsAVLpzAtckQxYiuirADzf3cL42FQ/htmlview?sle=true#gid=0
https://goo.gl/tdzLwa
相容
Kaspersky, ESET, Avast, Symantec/Norton, F-Secure, Windows Defender
不相容
Sophos, Trend Micro, McAfee, Bitdefender, Webroot
需等待防毒軟體推出相容性修正後才能更新
其他軟硬體和服務商目前的對策:
AMD: 官方表示目前揭露的三種攻擊
1. Bounds Check Bypass (CVE-2017-5753)
可由軟體/OS更新來解決,對效能影響極小
2. Branch Target Injection (CVE-2017-5715 也就是Spectre)
由於架構的不同,AMD"相信"受到這個攻擊而洩漏資料的風險趨近0
3. Rogue Data Cache Load (CVE-2017-5754 也就是Meltdown)
AMD表示完全免疫Meltdown
https://www.amd.com/en/corporate/speculative-execution
Intel: 不是只有我,大家都有問題
Recent reports that these exploits are caused by a “bug” or a “flaw”
and are unique to Intel products are incorrect.
Based on the analysis to date, many types of computing devices
— with many different vendors’ processors and operating systems
— are susceptible to these exploits.
https://newsroom.intel.com/news/intel-responds-to-security-research-findings/
ARM: 受影響的處理器列表
https://developer.arm.com/support/security-update
Android: Google的裝置已在1月2號推送安全性更新,
其他廠商需等待廠商推送更新
macOS: 蘋果目前還沒有官方說明,不過根據Alex Ionescu表示,
Sierra 10.13.2已在12月3號的時候修補了這個問題
https://twitter.com/aionescu/status/948609809540046849
iOS: 目前還沒有官方說明
Linux: 開發人員已經為此工作了好幾個月,
許多發行版已經修補了這個問題
Chrome OS: 已在12月15號的v63修補
Google Chrome 瀏覽器: 將會在1月23號發行的v64修補這個問題,
在這之前,Google建議使用者打開v63的Strict Site Isolation功能,
不過開啟這個功能會增加Chrome使用的記憶體
Mozilla Firefox: 已推送57.0.4版本更新緩解
Apple Safari: 目前沒有說明
Amazon AWS:
https://aws.amazon.com/tw/security/security-bulletins/AWS-2018-013/
Microsoft Azure:
https://support.microsoft.com/en-us/help/4072699/important-information-regarding-the-windows-security-updates-released
VMware: 官方列出受到影響的版本以及更新修補程式
https://www.vmware.com/us/security/advisories/VMSA-2018-0002.html
Nvidia: 官方的聲明指出,"相信"自家的GPU免疫上述的漏洞,
同時會更新驅動幫助緩解CPU的安全性問題。
來源
https://www.bleepingcomputer.com/news/security/list-of-meltdown-and-spectre-vulnerability-advisories-patches-and-updates/
https://goo.gl/ScfMbQ
https://www.tomsguide.com/us/meltdown-spectre-fixes,news-26326.html
https://goo.gl/6fydnw
--
Tags:
3C
All Comments
By Sarah
at 2018-01-05T16:46
at 2018-01-05T16:46
By Carol
at 2018-01-06T09:28
at 2018-01-06T09:28
By Wallis
at 2018-01-10T12:15
at 2018-01-10T12:15
By Elma
at 2018-01-10T13:26
at 2018-01-10T13:26
By Leila
at 2018-01-14T19:45
at 2018-01-14T19:45
By Victoria
at 2018-01-15T10:30
at 2018-01-15T10:30
By Sandy
at 2018-01-17T18:29
at 2018-01-17T18:29
By Regina
at 2018-01-21T16:05
at 2018-01-21T16:05
By Damian
at 2018-01-22T05:36
at 2018-01-22T05:36
By Hazel
at 2018-01-25T04:35
at 2018-01-25T04:35
By Doris
at 2018-01-27T23:47
at 2018-01-27T23:47
By Lauren
at 2018-01-30T21:45
at 2018-01-30T21:45
By Jessica
at 2018-02-04T13:01
at 2018-02-04T13:01
By Zenobia
at 2018-02-07T11:22
at 2018-02-07T11:22
By Edith
at 2018-02-09T10:40
at 2018-02-09T10:40
By Agatha
at 2018-02-10T04:17
at 2018-02-10T04:17
By George
at 2018-02-12T19:20
at 2018-02-12T19:20
By Frederic
at 2018-02-14T12:42
at 2018-02-14T12:42
By Faithe
at 2018-02-18T15:46
at 2018-02-18T15:46
By Daniel
at 2018-02-18T16:52
at 2018-02-18T16:52
By Agatha
at 2018-02-18T20:56
at 2018-02-18T20:56
By Anonymous
at 2018-02-21T20:41
at 2018-02-21T20:41
By Margaret
at 2018-02-24T22:52
at 2018-02-24T22:52
By Michael
at 2018-02-28T11:02
at 2018-02-28T11:02
By Elma
at 2018-03-04T07:34
at 2018-03-04T07:34
By Mia
at 2018-03-06T07:21
at 2018-03-06T07:21
By Tom
at 2018-03-09T11:42
at 2018-03-09T11:42
By Hedda
at 2018-03-13T23:48
at 2018-03-13T23:48
By Odelette
at 2018-03-15T16:17
at 2018-03-15T16:17
By Gilbert
at 2018-03-15T19:14
at 2018-03-15T19:14
By Caitlin
at 2018-03-17T19:38
at 2018-03-17T19:38
By Elizabeth
at 2018-03-21T00:19
at 2018-03-21T00:19
By Catherine
at 2018-03-23T20:52
at 2018-03-23T20:52
By Sarah
at 2018-03-26T11:09
at 2018-03-26T11:09
By Brianna
at 2018-03-27T05:22
at 2018-03-27T05:22
By Genevieve
at 2018-03-28T23:21
at 2018-03-28T23:21
By Elizabeth
at 2018-04-02T23:10
at 2018-04-02T23:10
By Todd Johnson
at 2018-04-05T19:29
at 2018-04-05T19:29
By Agnes
at 2018-04-06T16:57
at 2018-04-06T16:57
By Madame
at 2018-04-10T16:28
at 2018-04-10T16:28
By Rae
at 2018-04-14T15:07
at 2018-04-14T15:07
By Leila
at 2018-04-14T22:05
at 2018-04-14T22:05
By Megan
at 2018-04-18T04:49
at 2018-04-18T04:49
By Zenobia
at 2018-04-22T11:28
at 2018-04-22T11:28
By Frederic
at 2018-04-25T07:50
at 2018-04-25T07:50
By Daph Bay
at 2018-04-29T16:53
at 2018-04-29T16:53
By Isabella
at 2018-04-30T14:35
at 2018-04-30T14:35
By Mason
at 2018-05-03T15:28
at 2018-05-03T15:28
By Frederica
at 2018-05-03T19:46
at 2018-05-03T19:46
By Liam
at 2018-05-04T10:10
at 2018-05-04T10:10
By Michael
at 2018-05-09T03:39
at 2018-05-09T03:39
By Ina
at 2018-05-09T22:55
at 2018-05-09T22:55
By Wallis
at 2018-05-12T14:01
at 2018-05-12T14:01
By Liam
at 2018-05-16T18:39
at 2018-05-16T18:39
By Caroline
at 2018-05-16T21:47
at 2018-05-16T21:47
By Hedda
at 2018-05-17T15:43
at 2018-05-17T15:43
By Belly
at 2018-05-21T01:01
at 2018-05-21T01:01
By Xanthe
at 2018-05-21T19:06
at 2018-05-21T19:06
By Adele
at 2018-05-26T15:33
at 2018-05-26T15:33
By Susan
at 2018-05-30T03:49
at 2018-05-30T03:49
By Puput
at 2018-06-03T02:48
at 2018-06-03T02:48
By Jacky
at 2018-06-03T10:27
at 2018-06-03T10:27
Related Posts
視博通 小尖兵 3.5吋硬碟架
By Adele
at 2018-01-05T09:43
at 2018-01-05T09:43
CPU升級選擇
By Oliver
at 2018-01-05T04:49
at 2018-01-05T04:49
這樣該升級主機板還是記憶體?
By Eartha
at 2018-01-05T03:11
at 2018-01-05T03:11
遇到這種需求的要怎應付?
By Edwina
at 2018-01-05T02:34
at 2018-01-05T02:34
華擎即將推出 M-ATX X399M Taichi
By Donna
at 2018-01-05T01:10
at 2018-01-05T01:10