Intel嚴重漏洞 OS更新將會降低效能 - 3C

By Tracy
at 2018-01-05T09:45
at 2018-01-05T09:45
Table of Contents
昨晚開始微軟陸續對WIN7、WIN8、WIN10等各版本的作業系統
推送Meltdown修補程式,
如果你的Windows更新遲遲沒有收到更新通知,
有可能是因為修補程式和系統上的防毒軟體不相容,
為了避免引發系統當機藍屏所以被延遲了推送,
Kevin Beaumont製作了一個表格列出目前已知
相容和不相容Meltdown修補程式的防毒軟體
https://docs.google.com/spreadsheets/d/184wcDt9I9TUNFFbsAVLpzAtckQxYiuirADzf3cL42FQ/htmlview?sle=true#gid=0
https://goo.gl/tdzLwa
相容
Kaspersky, ESET, Avast, Symantec/Norton, F-Secure, Windows Defender
不相容
Sophos, Trend Micro, McAfee, Bitdefender, Webroot
需等待防毒軟體推出相容性修正後才能更新
其他軟硬體和服務商目前的對策:
AMD: 官方表示目前揭露的三種攻擊
1. Bounds Check Bypass (CVE-2017-5753)
可由軟體/OS更新來解決,對效能影響極小
2. Branch Target Injection (CVE-2017-5715 也就是Spectre)
由於架構的不同,AMD"相信"受到這個攻擊而洩漏資料的風險趨近0
3. Rogue Data Cache Load (CVE-2017-5754 也就是Meltdown)
AMD表示完全免疫Meltdown
https://www.amd.com/en/corporate/speculative-execution
Intel: 不是只有我,大家都有問題
Recent reports that these exploits are caused by a “bug” or a “flaw”
and are unique to Intel products are incorrect.
Based on the analysis to date, many types of computing devices
— with many different vendors’ processors and operating systems
— are susceptible to these exploits.
https://newsroom.intel.com/news/intel-responds-to-security-research-findings/
ARM: 受影響的處理器列表
https://developer.arm.com/support/security-update
Android: Google的裝置已在1月2號推送安全性更新,
其他廠商需等待廠商推送更新
macOS: 蘋果目前還沒有官方說明,不過根據Alex Ionescu表示,
Sierra 10.13.2已在12月3號的時候修補了這個問題
https://twitter.com/aionescu/status/948609809540046849
iOS: 目前還沒有官方說明
Linux: 開發人員已經為此工作了好幾個月,
許多發行版已經修補了這個問題
Chrome OS: 已在12月15號的v63修補
Google Chrome 瀏覽器: 將會在1月23號發行的v64修補這個問題,
在這之前,Google建議使用者打開v63的Strict Site Isolation功能,
不過開啟這個功能會增加Chrome使用的記憶體
Mozilla Firefox: 已推送57.0.4版本更新緩解
Apple Safari: 目前沒有說明
Amazon AWS:
https://aws.amazon.com/tw/security/security-bulletins/AWS-2018-013/
Microsoft Azure:
https://support.microsoft.com/en-us/help/4072699/important-information-regarding-the-windows-security-updates-released
VMware: 官方列出受到影響的版本以及更新修補程式
https://www.vmware.com/us/security/advisories/VMSA-2018-0002.html
Nvidia: 官方的聲明指出,"相信"自家的GPU免疫上述的漏洞,
同時會更新驅動幫助緩解CPU的安全性問題。
來源
https://www.bleepingcomputer.com/news/security/list-of-meltdown-and-spectre-vulnerability-advisories-patches-and-updates/
https://goo.gl/ScfMbQ
https://www.tomsguide.com/us/meltdown-spectre-fixes,news-26326.html
https://goo.gl/6fydnw
--
推送Meltdown修補程式,
如果你的Windows更新遲遲沒有收到更新通知,
有可能是因為修補程式和系統上的防毒軟體不相容,
為了避免引發系統當機藍屏所以被延遲了推送,
Kevin Beaumont製作了一個表格列出目前已知
相容和不相容Meltdown修補程式的防毒軟體
https://docs.google.com/spreadsheets/d/184wcDt9I9TUNFFbsAVLpzAtckQxYiuirADzf3cL42FQ/htmlview?sle=true#gid=0
https://goo.gl/tdzLwa
相容
Kaspersky, ESET, Avast, Symantec/Norton, F-Secure, Windows Defender
不相容
Sophos, Trend Micro, McAfee, Bitdefender, Webroot
需等待防毒軟體推出相容性修正後才能更新
其他軟硬體和服務商目前的對策:
AMD: 官方表示目前揭露的三種攻擊
1. Bounds Check Bypass (CVE-2017-5753)
可由軟體/OS更新來解決,對效能影響極小
2. Branch Target Injection (CVE-2017-5715 也就是Spectre)
由於架構的不同,AMD"相信"受到這個攻擊而洩漏資料的風險趨近0
3. Rogue Data Cache Load (CVE-2017-5754 也就是Meltdown)
AMD表示完全免疫Meltdown
https://www.amd.com/en/corporate/speculative-execution
Intel: 不是只有我,大家都有問題
Recent reports that these exploits are caused by a “bug” or a “flaw”
and are unique to Intel products are incorrect.
Based on the analysis to date, many types of computing devices
— with many different vendors’ processors and operating systems
— are susceptible to these exploits.
https://newsroom.intel.com/news/intel-responds-to-security-research-findings/
ARM: 受影響的處理器列表
https://developer.arm.com/support/security-update
Android: Google的裝置已在1月2號推送安全性更新,
其他廠商需等待廠商推送更新
macOS: 蘋果目前還沒有官方說明,不過根據Alex Ionescu表示,
Sierra 10.13.2已在12月3號的時候修補了這個問題
https://twitter.com/aionescu/status/948609809540046849
iOS: 目前還沒有官方說明
Linux: 開發人員已經為此工作了好幾個月,
許多發行版已經修補了這個問題
Chrome OS: 已在12月15號的v63修補
Google Chrome 瀏覽器: 將會在1月23號發行的v64修補這個問題,
在這之前,Google建議使用者打開v63的Strict Site Isolation功能,
不過開啟這個功能會增加Chrome使用的記憶體
Mozilla Firefox: 已推送57.0.4版本更新緩解
Apple Safari: 目前沒有說明
Amazon AWS:
https://aws.amazon.com/tw/security/security-bulletins/AWS-2018-013/
Microsoft Azure:
https://support.microsoft.com/en-us/help/4072699/important-information-regarding-the-windows-security-updates-released
VMware: 官方列出受到影響的版本以及更新修補程式
https://www.vmware.com/us/security/advisories/VMSA-2018-0002.html
Nvidia: 官方的聲明指出,"相信"自家的GPU免疫上述的漏洞,
同時會更新驅動幫助緩解CPU的安全性問題。
來源
https://www.bleepingcomputer.com/news/security/list-of-meltdown-and-spectre-vulnerability-advisories-patches-and-updates/
https://goo.gl/ScfMbQ
https://www.tomsguide.com/us/meltdown-spectre-fixes,news-26326.html
https://goo.gl/6fydnw
--
Tags:
3C
All Comments

By Sarah
at 2018-01-05T16:46
at 2018-01-05T16:46

By Carol
at 2018-01-06T09:28
at 2018-01-06T09:28

By Wallis
at 2018-01-10T12:15
at 2018-01-10T12:15

By Elma
at 2018-01-10T13:26
at 2018-01-10T13:26

By Leila
at 2018-01-14T19:45
at 2018-01-14T19:45

By Victoria
at 2018-01-15T10:30
at 2018-01-15T10:30

By Sandy
at 2018-01-17T18:29
at 2018-01-17T18:29

By Regina
at 2018-01-21T16:05
at 2018-01-21T16:05

By Damian
at 2018-01-22T05:36
at 2018-01-22T05:36

By Hazel
at 2018-01-25T04:35
at 2018-01-25T04:35

By Doris
at 2018-01-27T23:47
at 2018-01-27T23:47

By Lauren
at 2018-01-30T21:45
at 2018-01-30T21:45

By Jessica
at 2018-02-04T13:01
at 2018-02-04T13:01

By Zenobia
at 2018-02-07T11:22
at 2018-02-07T11:22

By Edith
at 2018-02-09T10:40
at 2018-02-09T10:40

By Agatha
at 2018-02-10T04:17
at 2018-02-10T04:17

By George
at 2018-02-12T19:20
at 2018-02-12T19:20

By Frederic
at 2018-02-14T12:42
at 2018-02-14T12:42

By Faithe
at 2018-02-18T15:46
at 2018-02-18T15:46

By Daniel
at 2018-02-18T16:52
at 2018-02-18T16:52

By Agatha
at 2018-02-18T20:56
at 2018-02-18T20:56

By Anonymous
at 2018-02-21T20:41
at 2018-02-21T20:41

By Margaret
at 2018-02-24T22:52
at 2018-02-24T22:52

By Michael
at 2018-02-28T11:02
at 2018-02-28T11:02

By Elma
at 2018-03-04T07:34
at 2018-03-04T07:34

By Mia
at 2018-03-06T07:21
at 2018-03-06T07:21

By Tom
at 2018-03-09T11:42
at 2018-03-09T11:42

By Hedda
at 2018-03-13T23:48
at 2018-03-13T23:48

By Odelette
at 2018-03-15T16:17
at 2018-03-15T16:17

By Gilbert
at 2018-03-15T19:14
at 2018-03-15T19:14

By Caitlin
at 2018-03-17T19:38
at 2018-03-17T19:38

By Elizabeth
at 2018-03-21T00:19
at 2018-03-21T00:19

By Catherine
at 2018-03-23T20:52
at 2018-03-23T20:52

By Sarah
at 2018-03-26T11:09
at 2018-03-26T11:09

By Brianna
at 2018-03-27T05:22
at 2018-03-27T05:22

By Genevieve
at 2018-03-28T23:21
at 2018-03-28T23:21

By Elizabeth
at 2018-04-02T23:10
at 2018-04-02T23:10

By Todd Johnson
at 2018-04-05T19:29
at 2018-04-05T19:29

By Agnes
at 2018-04-06T16:57
at 2018-04-06T16:57

By Madame
at 2018-04-10T16:28
at 2018-04-10T16:28

By Rae
at 2018-04-14T15:07
at 2018-04-14T15:07

By Leila
at 2018-04-14T22:05
at 2018-04-14T22:05

By Megan
at 2018-04-18T04:49
at 2018-04-18T04:49

By Zenobia
at 2018-04-22T11:28
at 2018-04-22T11:28

By Frederic
at 2018-04-25T07:50
at 2018-04-25T07:50

By Daph Bay
at 2018-04-29T16:53
at 2018-04-29T16:53

By Isabella
at 2018-04-30T14:35
at 2018-04-30T14:35

By Mason
at 2018-05-03T15:28
at 2018-05-03T15:28

By Frederica
at 2018-05-03T19:46
at 2018-05-03T19:46

By Liam
at 2018-05-04T10:10
at 2018-05-04T10:10

By Michael
at 2018-05-09T03:39
at 2018-05-09T03:39

By Ina
at 2018-05-09T22:55
at 2018-05-09T22:55

By Wallis
at 2018-05-12T14:01
at 2018-05-12T14:01

By Liam
at 2018-05-16T18:39
at 2018-05-16T18:39

By Caroline
at 2018-05-16T21:47
at 2018-05-16T21:47

By Hedda
at 2018-05-17T15:43
at 2018-05-17T15:43

By Belly
at 2018-05-21T01:01
at 2018-05-21T01:01

By Xanthe
at 2018-05-21T19:06
at 2018-05-21T19:06

By Adele
at 2018-05-26T15:33
at 2018-05-26T15:33

By Susan
at 2018-05-30T03:49
at 2018-05-30T03:49

By Puput
at 2018-06-03T02:48
at 2018-06-03T02:48

By Jacky
at 2018-06-03T10:27
at 2018-06-03T10:27
Related Posts
視博通 小尖兵 3.5吋硬碟架

By Adele
at 2018-01-05T09:43
at 2018-01-05T09:43
CPU升級選擇

By Oliver
at 2018-01-05T04:49
at 2018-01-05T04:49
這樣該升級主機板還是記憶體?

By Eartha
at 2018-01-05T03:11
at 2018-01-05T03:11
遇到這種需求的要怎應付?

By Edwina
at 2018-01-05T02:34
at 2018-01-05T02:34
華擎即將推出 M-ATX X399M Taichi

By Donna
at 2018-01-05T01:10
at 2018-01-05T01:10