当前位置:首页 > 建站教程 > 不明觉厉
作者:开伯帝
来源:文化大观园
发布时间:2026-08-27

不明觉厉

请立即更新至26.02版本:7-Zip被曝高危漏洞,可远程执行任意代码_我的网站

happy together

A |     (ECNS) -- China's zero-tariff policy for all 53 African countries with diplomatic ties has yielded over 730 million yuan (about $106.6 million) in import savings at Guangzhou Customs in the first three months since its implementation, according to customs data released on Wednesday.        From May 1 to July 31, enterprises in the Guangzhou Customs district imported eligible goods worth over 730 million yuan, with tariff reductions exceeding 80 million yuan. Imports from 20 African countries not classified as least developed accounted for 470 million yuan, with tariff savings surpassing 50 million yuan.    Zhang Yazhou, head of the Rules of Origin Management Section of Guangzhou Customs, said the electronic data from certificates issued under this system can be transmitted in real time to China's customs clearance system, allowing enterprises to import without submitting paper certificates.    Guangzhou Customs has streamlined clearance procedures and implemented 24-hour smart clearance to facilitate trade. In the first half of this year, Guangzhou Customs handled 76.39 billion yuan in imports and exports with African countries, up 25.3% year on year.    (By Tang Yuxian)                    。    IT之家 7 月 21 日消息,安全研究机构 Zero Day Initiative 上周(7 月 15 日)提交漏洞报告称,压缩软件 7-Zip 存在一项基于堆(Heap)的缓冲区溢出漏洞,黑客可利用其远程执行任意代码。         据介绍,该漏洞编号为 CVE-2026-14266,CVSS 3.0 评分为 7.0 分(IT之家注:高危,满分 10 分)。

B |          据悉,7-Zip 在处理 XZ 格式压缩文件时的分块(Chunk)数据存在部分缺陷,可能导致缓冲区溢出。攻击者只需要诱导用户打开精心构造的 XZ 压缩文件,就能成功触发漏洞,远程执行任意代码。

C |          此外,该漏洞已于 6 月 5 日提交给 7-Zip 开发者,并在 6 月 25 日发布的 7-Zip 26.02 中完成修复。随后 ZDI 根据协调披露流程,于 7 月 15 日发出报告。仍在使用 26.02 以下版本的 7-Zip 用户应立即更新,以规避潜在的安全风险。

Current article:http://vb8kf.jiubengtaibingpengou.pics/news/20260826_899354.html

Published on:00:00:00


  • 本文标签:
  • 那年花开月正圆