ADLab2019Ä갲ȫ×êÑлØÊ×

°ä²¼¹¦·ò 2019-12-31

2019Ä꣬GA»Æ½ð¼×ADLab×êÑз½Ïò³ÁµãÔ̺¬Ö÷Á÷²Ù×÷ϵͳ¼°ÀûÓð²È«×êÑÓ×¢Web°²È«×êÑÓ×¢ÒÆ¶¯»¥ÁªÍø°²È«×êÑÓ×¢ÎïÁªÍø°²È«×êÑÓ×¢¹¤¿Ø»¥ÁªÍø°²È«×êÑкÍÇø¿éÁ´°²È«×êÑУ¬ÆäÖв¿ÃÅ×êÑÐÎÄÕÂÒÑͨ¹ýADLab¹«¼Òƽ̨°ä²¼£¬Îª·½±ã¸÷È˲éÔÄÎÒÃǶÔÕûÄê°ä²¼µÄÖØÒª×êÑÐÎÄÕ½øÐÐÁËÕû¶Ù¡£


ÈȵãÊÂÎñ¹«¸æ


¡¾Ô­´´·ì϶¡¿Adobe ColdFusion ·´ÐòÁл¯RCE·ì϶·ÖÎö


GA»Æ½ð¼×ADLab·¢ÏÖAdobe ColdFusionÖÐFlashGateway·þÎñ´æÔÚCritical£¨Î£»ú£©·´ÐòÁл¯·ì϶£¨CVE-2019-7091£©£¬ÀûÓø÷ì϶¹¥»÷Õß¿ÉÔ¶³ÌÖ´ÐÐËÁÒâ´úÂë¡£


¡¾·ì϶¹«¸æ¡¿LinuxÄں˴æÔÚ±¾µØÌáȨ·ì϶£¨CVE-2019-8912£©


¡¾Ô­´´·ì϶¡¿LinuxÄÚºËMarvell WI-FIоƬÇý¶¯·ì϶£¨CVE-2019-3846/CVE-2019-10126£©


¡¾Ô­´´·ì϶¡¿LinuxÄÚºËMarvell WI-FIоƬÇý¶¯¶à¸öÔ¶³Ì·ì϶


Linux git´æÔÚ±¾µØÌáȨ·ì϶£¬Äܹ»µ¼Ö±¾µØ´úÂëִǰ½øÐÐȨÏÞÌáÉý¡£LinuxÄÚºËMarvell WI-FIоƬÇý¶¯´æÔÚ¶à¸öÔ¶³ÌÒç¶Âí½ÅºÍ±¾µØÒç¶Âí½Å£¬¿Éµ¼Ö»ؾø·þÎñ£¨ÏµÍ³±ÀÀ££©»òËÁÒâ´úÂëÖ´ÐС£·ì϶ӰÏìÁìÓò½Ï¹ã¡£


¡¾Ô­´´·ì϶¡¿WebLogicËÁÒâÎļþ¶ÁÈ¡·ì϶£¨CVE-2019-2615£©


¡¾Ô­´´·ì϶¡¿WebLogic Blind XXE·ì϶£¨CVE-2019-2647£©


¡¾Ô­´´·ì϶¡¿WebLogic Ô¶³ÌºÅÁîÖ´Ðзì϶£¨CVE-2019-2725²¹¶¡Èƹý£©


¡¾Ô­´´·ì϶¡¿WebLogic ·´ÐòÁл¯·ì϶£¨CVE-2019-2890£©


¡¾Ô­´´·ì϶¡¿WebLogic Blind XXE·ì϶£¨CVE-2019-2887£©


GA»Æ½ð¼×ADLab·¢ÏÖWebLogic´æÔÚÉÏÊö·ì϶£¬¹¥»÷Õß¿ÉÔÚÒÑÖªÓû§ÃûÃÜÂëµÄÇé¿ö϶ÁÈ¡WebLogic·þÎñÆ÷ÖеÄËÁÒâÎļþ£»¿ÉÔÚδÊÚȨµÄÇé¿öÏÂʵÏÖ¶Ô´æÔÚ·ì϶µÄWebLogic×é¼þ½øÐÐÔ¶³ÌBlind XXE¹¥»÷£»¿ÉÔڵͰ汾JDKµÄ»·¾³ÖÐÈÆ¹ý²¹¶¡È±µãµ¼ÖÂËÁÒâÔ¶³ÌºÅÁîÖ´ÐУ»¿Éͨ¹ýT3ºÍ̸¶Ô´æÔÚ·ì϶µÄWebLogic×é¼þÖ´ÐÐÔ¶³ÌËÁÒâ´úÂë¹¥»÷¡£


¡¾·ì϶¹«¸æ¡¿²©Í¨Wi-FiÇý¶¯´æÔÚ¶à¸ö°²È«·ì϶


²©Í¨wlÇý¶¯ÖдæÔÚÁ½¸ö¶ÑÒç¶Âí½Å£¨CVE-2019-9501¡¢CVE-2019-9502£©£¬¿ªÔ´µÄbrcmfmacÇý¶¯ÖдæÔÚÊý¾ÝÖ¡ÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2019-9503£©ºÍ¶ÑÒç¶Âí½Å(CVE-2019-9500£©¡£Î´¾­ÊÚȨµÄ¹¥»÷Õßͨ¹ýÔ¶³Ì·¢ËͶñÒâµÄwifi°ü£¬ÔÚ×îÑϳÁµÄÇé¿öÏ£¬Äܹ»ÔÚÊÜÓ°ÏìϵͳÖÐÖ´ÐÐËÁÒâ´úÂë¡£


¡¾Ô­´´·ì϶¡¿WebSphere·ì϶£¨CVE-2019-4505£©


GA»Æ½ð¼×ADLab·¢ÏÖWebsphere´æÔÚËÁÒâÎļþ¶ÁÈ¡·ì϶CVE-2019-4505¡£Í¨¹ý¸Ã·ì϶£¬¹¥»÷ÕßÄܹ»»ñÈ¡Ãô¸ÐÐÅÏ¢¶øµ¼Ö½øÒ»²½ÀûÓ᣷ì϶·çÏÕˮƽ½Ï´ó¡£


ÎïÁªÍø×¨Ìâ·ÖÎö


¹¤¿ØÊ®´óÍøÂç¹¥»÷±øÆ÷·ÖÎö»ã±¨


GA»Æ½ð¼×ADLab¶Ô2000ÄêÖ®ºóµÄ¹¤¿ØÍøÂç¹¥»÷ÊÂÎñ½øÐÐÊáÀí£¬²¢É¸Ñ¡³öÊ®´ó¹¤¿ØÍøÂç¹¥»÷±øÆ÷£ºStuxnet¡¢Duqu¡¢Flame¡¢Havex¡¢Dragonfly2.0¡¢ BlackEnergy¡¢Industroyer¡¢GreyEnergy¡¢VPNFilterºÍTriton

£¬Éî¶È·ÖÎöÆä¹¥»÷²¼¾°¡¢Ö¸±ê¡¢ÊÖ·¨ÒÔ¼°¼¼Êõ¸öÐÔ£¬ÒÔ±ã¸÷È˶Թ¤Òµ½ÚÔìϵͳËùÃæ¶ÔµÄ°²È«ÍþвÓÐÒ»¸ö¸üÎªÈ«ÃæµÄÒâʶ¡£


ºÚȸ¹¥»÷£ºÉî¶È·ÖÎö²¢ËÝÔ´Dofloo½©Ê¬ÎïÁªÍø±³ºóµÄ¡°ºÚȸ¡±


GA»Æ½ð¼×ADLab·¢ÏÖConfluenceÔ¶³Ì´úÂëÖ´Ðзì϶CVE-2019-3396±»Dofloo½©Ê¬ÍøÂç¼Ò×åÓÃÓÚ¹¥Õ¼É豸×ÊÔ´£¬Dofloo½©Ê¬¼Ò×å²»½öÆðÍ·ÀûÓøßΣ·ì϶½øÐй¥»÷£¬ÇÒÆä±³ºóµÄºÚ¿Í»¹ÀûÓÃÒ»ÖÖ¸ü¾ßÓ°ÏìÁ¦µÄ¡°ºÚȸ¹¥»÷¡±À´ÈëÇÖ²úÒµÁ´¡£±¾ÎľßÌåÂÛÊöÁ˺Úȸ¹¥»÷µÄ×îз¢ÏÖ¹ý³Ì£¬²¢Éî¿Ì·ÖÎöÁËDofloo½©Ê¬ÍøÂç¼Ò×åÖÐËù´æÔڵġ°ºÚȸ¾°Ïó¡±£»Í¬Ê±¶Ô°µ²ØÔÚÆä±³ºóµÄºÚȸ½øÐÐÉî¶ÈÍÚ¾òºÍ¶¨Î»£¬·ÖÎö¸Ã½©Ê¬ÓëMrBlack¡¢DnsAmp¡¢Flood.AÖ®¼äµÄͬԴ¸öÐÔ¡£


ÖÇÄÜÒôÏäÍøÂ簲ȫÓëÒþÖÔ×êÑл㱨


±¾»ã±¨³Áµã·ÖÎöÁËÖÇÄÜÒôÏäÃæ¶ÔµÄ°²È«·çÏÕºÍÒþÖÔ·çÏÕ¡£Í¨¹ý¶ÔÖÇÄÜÒôÏäµÄ×êÑУ¬GA»Æ½ð¼×ADLab·¢ÏÖÁ˲úÆ·ÖдæÔÚÓÐÓ²¼þµ÷ÊÔ½Ó¿Ú·ì϶¡¢DLNA·þÎñԽȨ·ì϶¡¢·þÎñ¶Ë¿ÚԽȨ·ì϶µÈÊ®Óà¸ö°²È«·ì϶£¬ÕâЩ·ì϶¿ÉÔì³ÉδÊÚȨÉ豸½ÚÔì¡¢ÓïÒôÇÔÌý¡¢Ãô¸ÐÐÅϢй¶µÈ¡£ADLabÒѵÚÒ»¹¦·òÏòCNVDºÍCNNVD½øÐÐÁË·ì϶´«µÝ£¬²¢ÓëICSCERT½áºÏ°ä²¼ÁË¡¶ÖÇÄÜÒôÏäÒþÖÔÓëÍøÂ簲ȫ·ÖÎö»ã±¨¡·¡£


VxWorks¶à¸öÔ¶³Ì·ì϶·ÖÎö


ÔÚ¹¤Òµ¡¢µçÁ¦¡¢ÄÜÔ´£¬º½¿Õº½ÌìµÈÐÐÒµ¹Ø¼ü»ù´¡ÉèÊ©ÖÐ¿í·ºÊ¹ÓõÄVxWorks±»·¢ÏÖ´æÔÚ11¸ö0day·ì϶±»³ÆÎªURGENT/11£¬ÆäÖÐ6¸ö·ì϶ΪÑϳÁ·ì϶²¢Äܹ»Ô¶³ÌÖ´ÐдúÂ루RCE£©£¬ÆäÓà5¸ö·ì϶Ô̺¬»Ø¾ø·þÎñ¡¢ÐÅϢй¶ºÍÂß¼­È±µã·ì϶¡£ÕâЩ·ì϶¿ÉÄÜʹ¹¥»÷ÕßÔ¶³ÌÊÕÊÜÉ豸£¬¶øÎÞÐè½»»¥£¬ÉõÖÁÄܹ»Èƹý·À»ðǽµÈÖܱ߰²È«É豸£¬ÕâÒâζ×ÅËüÃÇ¿ÉÓÃÓÚ½«¶ñÒâÈí¼þ´«²¼µ½ÍøÂçÄÚ²¿£¬ÕâÖÖ¹¥»÷ÓµÓкܴóµÄDZÁ¦£¬ÀàËÆÓÚWannaCry¶ñÒâÈí¼þµÄ´«²¼·½Ê½¡£



ºÚ¿Í¹¥»÷ÓëÍþв·ÖÎö



¡°BankThief¡±- Õë¶Ô²¨À¼ºÍ½Ý¿ËµÄÐÂÐÍÒøÐд¹µö¹¥»÷


GA»Æ½ð¼×ADLab·¢ÏÖÁËÒ»¿îȫеÄAndroidÒøÐд¹µöľÂí¡±BankThief¡°£¬¸ÃľÂí½«×ÔÉí¼Ù×°³É¡°Google Play¡±ÀûÓ㬿ÉÇÔÈ¡Êܺ¦Óû§µÄÒøÐеǼƾ֤¡£¹¥»÷Õß½«½ÚÔìÖ¸Áî°µ²ØÔÚ°²È«µÄFirebaseͨѶËí·ÖУ¬Ê¹Æä¹¥»÷ÐÐΪԽ·¢Òñ±Î¡£Õâ´Î¹¥»÷µÄÖ¸±êÒøÐÐĬÈÏÔ̺¬Ô̺¬»¨ÆìÒøÐÐÔÚÄÚµÄÈýÊ®¶à¼ÒÒøÐС£


¾¯Ì裺ºÚ¿ÍÀûÓá°Á÷ÀëµØÇòƱ·¿ºì°ü¡±ÔÚ΢ÐÅÖд«²¼¶ñÒâÚ¿Æ­¸æ°×


GA»Æ½ð¼×ADLabÊÕµ½¿Í»§·´À¡£ºÔÚʹÓÃ΢ÐŵĹý³ÌÖÐÒÉËÆ³öÏÖ¡°Öж¾¡±¾°Ïó£¬Óû§ÔÚȺÁÄÖÐÊÕµ½¡°Î¢ÐÅÓïÒô¡±£¬µã¿ªºóÈ´ÌáÐÑÁìÈ¡¡°Á÷ÀëµØÇòµçӰƱ·¿ºì°ü¡±¡£²»Ã÷ÕæÏàµÄÓû§·×·×ÖÐÕУ¬Ôì³ÉÖî¶àȺÁÄÖгöÏÖÁË¡°ÈºÔ¼Ç롱 ¡¢¡°ÓïÒô¡±ºÍ¡°¸æ°×¡±µÈºýŪÐÔ·ÖÏíÁ´½Ó£¬²¢³É²¡¶¾Ê½¼±¾ç´«²¼¡£Á´½ÓÖ¸Ïò¡°ÀÏÖÐÒ½¡±¡¢¡°Í¶×ÊÁìµ¼¡±ºÍ¡°µÍË×Ó×˵¡±µÈ¶ñÒâ¸æ°×£¬ÓÕµ¼Óû§Ôö³¤Î¢ÐÅ»ò¹Ø×¢¹«¼ÒºÅ£¬Ö®ºóÒ»²½²½Í¨¹ýÆ­È¡¶¨½ð»ò²ÊƱˢµ¥µÈ¼¿Á©Ú¿Æ­Óû§²Æ¸»£¬ÉÔÓÐʧÉ÷¾Í»áÂäÈëȦÌס£


¡¾¾¯Ìè¡¿¡°ÏÀµÁ¡±ÀÕË÷²¡¶¾V5.3бäÖÖÈ«Ãæ·Ö½â


2019Äê4Ô£¬GA»Æ½ð¼×ADLab²¶»ñµ½ÁË¡°ÏÀµÁ¡±²¡¶¾×îбäÖÖ£¬¸Ã²¡¶¾µÄ°æ±¾ºÅΪV5.3£¬±àÒ빦·òΪ4ÔÂ14ÈÕ£¬¾àÀëÆäÉÏÒ»¸ö°æ±¾V5.2ÔÚÖйúËÁŰ½ö½öÒ»¸ö¶àÔ¡£×ÔÆäÓÚ2018Äê1Ôµ®ÉúÖÁ½ñÒѾ­¸üеü´úÁË5¸ö´óµÄ°æ±¾¡¢20¼¸¸öÓ×°æ±¾¡£¡°ÏÀµÁ¡±ÆðÍ·ËÁŰÖйúµÄ¹¦·òΪ2019Äê3ÔÂ11ÈÕ£¬²¢ÒÑϰȾÁËÎÒ¹úÉÏǧ̨µ±¾Ö¡¢ÆóÒµºÍÓйؿÆÑлú¹¹µÄÍÆËã»ú¡£


ºÚʨÐж¯£ºÕë¶ÔÎ÷°àÑÀÓïµØÓòµÄ¹¥»÷»î¶¯·ÖÎö


GA»Æ½ð¼×ADLab¼à²âµ½Ò»ÅúÕë¶ÔÎ÷°àÑÀÓïµØÓòÈ·µ±¾Ö»ú¹¹¼°ÄÜÔ´ÆóÒµµÈ²¿Ãŵ͍Ïò¹¥»÷»î¶¯£¬Í¨¹ý¶Ô¹¥»÷ÕßµÄÐÐΪºÍËùÓ÷þÎñÆ÷ÓйØÐÅÏ¢µÄ·ÖÎöºÍ×·×Ù£¬È·¶¨¸Ã´Î¹¥»÷ÆðÔ´ÓÚÒ»ÅúÒþÃØ¶àÄêµÄÍÁ¶úÆäºÚ¿Í×éÖ¯-KingSqlZºÚ¿Í×éÖ¯¡£ÆäÔø¹¥ÏÂ3ǧ¶à¸öÍøÕ¾·þÎñÆ÷£¬²¢¸ßµ÷µÄÔÚ±»¹¥»÷ÍøÕ¾ÉÏÁôÏÂ×éÖ¯µÄÃû³Æ£¬ËæºóÒþûÁ˶àÄê¡£ÎÒÃÇͨ¹ý¶Ô¡±ºÚʨÐж¯¡±µÄ×·×ÙÔÙ´ÎÍÚ³ö¸ÃºÚ¿Í×éÖ¯³ÉÔ±¼°»î¶¯¼£Ï󣬲¢¶Ô¹¥»÷Ö¸±êÒÔ¼°ÆäËùʹÓõĹ¥»÷±øÆ÷½øÐÐÈ«ÃæÁË·ÖÎö¡£


ÓÉÒ»¶ÎÉñÃØÎÄ×ÖËùÒý·¢µÄµ÷²éÓë·ÖÎö


GA»Æ½ð¼×ADLab¶Ô±ãÇ©ÍøÕ¾Pastebinƽ̨£¨¸Ãƽ̨ʱʱ±»ºÚ¿ÍÓÃÓÚ´æ´¢¹¥»÷³É¾Í£©ÄÚÈݽøÐÐɸѡºÍ·ÖÎö£¬·¢ÏÖÁËÒ»¶ÎÉñÃØ¶ø¹Å¹ÖµÄÖÐÎÄ×Ö·û¡£¸Ã¶ÎÎÄ×Ö±»´æ´¢ÔÚÒ»¸öÃûΪ¡°Unitled¡±µÄÓû§ÎļþÖУ¬´Ó×ÖÃæÉÏ¿´£¬ÕâÊÇÒ»¶ÎûÓÐÆëÈ«ÓïÒåµÄÎÄ×Ö£¬¿´ÆðÀ´¾ÍÏñÃÜÓïÒ»Ñù£¬ËƺõÆäÖаµ²Ø×ÅһЩ²»ÎªÈËÖªµÄÐÅÏ¢¡£ÄÇôÕâ»áÊÇij¸öºÚ¿Í×éÖ¯»òÕßµý±¨ÈËÔ±Ö®¼äµÄ°ÂÃØ¼ÇºÅÄØ£¬»¹ÊÇ˵½ö½öÖ»ÊÇËæ»úÊäÈëµÄºÁÎÞÒâ˼µÄÎÄ×Ö £¿±¾ÎĶÔÕâÆäÖаµ²ØµÄ°ÂÃØ½øÐÐÁË·ÖÎö²é¾¿¡£


Õë¶ÔÔìÒ©ÐÐÒµ¼°ÕþÆóµÄºÚ¿Í×éÖ¯×îй¥»÷»î¶¯Éî¶È·ÖÎö


GA»Æ½ð¼×ADLab·¢ÏÖ´óÁ¿Ê¹ÓøßΣ·ì϶CVE-2017-11882½øÐÐÍøÂç¹¥»÷µÄÊÂÎñ£¬Í¨¹ý¶ÈÎöÎÒÃÇ·¢Ïֺڿ͵ÄÎѵ㲢ÕÒµ½ÁËÊܺ¦ÈËÓйØÐÅÏ¢£¬´ËÅúºÚ¿Í³É¹¦ÉøÈë½øÁ˵¹úºÍÓ¡¶ÈÄáÎ÷ÑǵĶà¼ÒÔìÒ©ÆóÒµ£¬ÒÔ¼°Î÷°àÑÀÈ·µ±¾Ö¡¢ÆóÊÂÒµµ¥ÔªµÈ»ú¹¹£¬²¢ÇÒµÁÈ¡ÁË´óÁ¿µÄÃô¸Ðµý±¨¡£Í¨¹ýËÝÔ´·ÖÎöÈ·¶¨Õâ´Î¹¥»÷À´×ÔÓÚÄáÈÕÀûÑÇ£¬²¢Óɵ±Ç°¹¥»÷¹ØÁª³öÁ˸ü¶àºÚ¶ñÒâÓòÃûºÍÑù±¾¡£±¾ÎĶԺڿÍ×éÖ¯ËùÖ´ÐеĹ¥»÷¹ý³Ì½øÐоßÌ嵨·ÖÎöºÍËÝÔ´£¬²¢¶ÔÆäËùʹÓõļäµýÈí¼þºÍ»ù´¡ÉèÊ©½øÐÐ͸±ÙµØ·ÖÎö¡£


¹ØÓÚÃÅÂÞ±Ò¹©¸øÁ´¹¥»÷ÊÂÎñ·ÖÎö


2019Äê11ÔÂ19ÈÕ£¬ÃÅÂÞ±Ò¹Ù·½githubÉϳöÏÖ¶ÔÃÅÂÞ±Òrelease°æÓë¹ÙÍøÉϳöÏÖ²»Ò»ÖÂÎÊÌâµÄissues£¬ÆäÖÐÌá¼°³öÏÖÎÊÌâµÄÃÅÂޱҰ汾Ϊ×îаæ0.15.0.0¡£ÃÅÂÞ±Ò¹Ù·½ÈÏ¿ÉÆä¹ÙÍøÊܵ½ºÚ¿ÍÈëÇÖ£¬ÕâÊdzõ´Î±»·¢ÏÖÕë¶Ô¼ÓÃÜÇ®±Ò¿Í»§¶ËµÄ¹©¸øÁ´¹¥»÷¡£±¾ÎľßÌå·ÖÎöÁ˱»´Û¸ÄµÄmonero-wallet-cli¶ñÒâÎļþ£¬²¢¶ÔºÚ¿ÍµÄ»ù´¡ÉèÊ©½øÐÐ×·×Ù·ÖÎö£¬·¢ÏÖÁ˺ڿÍËùʹÓùýµÄÆäËû»ù´¡ÉèÊ©¡£


°²È«·ì϶·ÖÎö


LinuxÄÚºËCVE-2017-11176·ì϶·ÖÎöÓ븴ÏÖ


LinuxÄÚºËÖеÄPOSIX ÐÂÎŶÓÁÐʵÏÖÖдæÔÚÒ»¸öUAF·ì϶CVE-2017-11176¡£¹¥»÷ÕßÄܹ»ÀûÓø÷ì϶µ¼Ö»ؾø·þÎñ»òÖ´ÐÐËÁÒâ´úÂë¡£±¾ÎĽ«´Ó·ì϶³ÉÒò¡¢²¹¶¡·ÖÎöÒÔ¼°·ì϶¸´Ïֵȶà¸ö½Ç¶È¶Ô¸Ã·ì϶½øÐоßÌå·ÖÎö¡£


ThinkPHP5Ö÷ÌâÀàRequestÔ¶³Ì´úÂë·ì϶·ÖÎö


ThinkPHPÍŶӰ䲼²¹¶¡¸üУ¬½¨¸´ÁËÒ»´¦ÓÉÓÚ²»°²È«µÄ¶¯Ì¬º¯ÊýŲÓõ¼ÖµÄÔ¶³Ì´úÂëÖ´Ðзì϶£¬¸Ã·ì϶·çÏÕˮƽ¼«¶È¸ß¡£GA»Æ½ð¼×ADLab¶ÔThinkPHP¶à¸ö°æ±¾½øÐÐÁËÔ´Âë·ÖÎöºÍÑéÖ¤£¬ÊÜÓ°Ïì°æ±¾ÎªThinkPHP5.0-5.0.23ÆëÈ«°æ¡£


Windows DHCP ServerÔ¶³Ì´úÂëÖ´Ðзì϶·ÖÎö£¨CVE-2019-0626£©


Windows DHCP Server´æÔÚÔ¶³Ì´úÂëÖ´ÐиßΣ·ì϶CVE-2019-0626£¬µ±¹¥»÷ÕßÏòDHCP·þÎñÆ÷·¢Ë;«ÐÄÉè¼ÆµÄÊý¾Ý°ü²¢³É¹¦ÀûÓú󣬾ÍÄܹ»ÔÚDHCP·þÎñÖÐÖ´ÐÐËÁÒâ´úÂ룬·ì϶ӰÏìÁìÓò½Ï´ó¡£


Windows RDP·þÎñ¸ßΣ·ì϶·ÖÎö£¨CVE-2019-0708£©


Windows RDP·þÎñµÄÔ¶³Ì´úÂëÖ´ÐиßΣ·ì϶ӰÏìÁËijЩ¾É°æ±¾µÄWindowsϵͳ£¬ÓÉÓڸ÷ì϶ÎÞÐèÉí·ÝÑéÖ¤ÇÒÎÞÐèÓû§½»»¥£¬ËùÒÔÄܹ»Í¨¹ýÍøÂçÈ䳿µÄ·½Ê½±»ÀûÓã¬ÀûÓô˷ì϶µÄ¶ñÒâÈí¼þÄܹ»´Ó±»Ï°È¾µÄÍÆËã»ú´«²¼µ½ÍøÂçÖÐÆäËûÒ×Êܹ¥»÷µÄÍÆËã»ú£¬´«²¼·½Ê½Óë2017ÄêWannaCry¶ñÒâÈí¼þµÄ´«²¼·½Ê½ÀàËÆ¡£


LinuxÄÚºËSCTPºÍ̸·ì϶·ÖÎöÓ븴ÏÖ


LinuxÄÚºËSCTPºÍ̸ʵÏÖÖдæÔÚÒ»¸ö°²È«·ì϶CVE-2019-8956£¬Äܹ»µ¼Ö»ؾø·þÎñ¡£¸Ã·ì϶´æÔÚÓÚnet/sctp/socket.cÖеÄsctp_sendmsg()º¯Êý£¬¸Ãº¯ÊýÔÚ´¦ÖÃSENDALL±êÖ¾²Ù×÷¹ý³Ìʱ´æÔÚuse-after-free·ì϶¡£


LinuxÄÚºËTCPºÍ̸¶à¸öSACKÖ°Äܻؾø·þÎñ·ì϶·ÖÎö


LinuxÄÚºËTCP/IPºÍ̸ջ´æÔÚ3¸ö°²È«·ì϶£¨CVE-2019-11477¡¢CVE-2019-11478¡¢CVE-2019-11479£©£¬ÕâЩ·ì϶Óë×î´ó·Ö¶Î´óС£¨MSS£©ºÍTCPÑ¡ÔñÐÔÈ·ÈÏ£¨SACK£©Ö°ÄÜÓйØ£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß½øÐлؾø·þÎñ¹¥»÷¡£


Advantech WebAccess¶à¸ö·ì϶·ÖÎö


ZDI°ä²¼¶à¸öWebAccess·ì϶£¬ÆäÖÐÔ̺¬¶à¸öÄÚ´æ·ÛËé·ì϶ºÍÕ»Òç¶Âí½Å¡£²¿ÃÅÄÚ´æ·ÛËé·ì϶Äܹ»ÔÚÊÜÓ°ÏìµÄϵͳÖÐÖ´ÐÐËÁÒâ´úÂ룬µ«ÊÇ´ó²¿ÃÅÄÚ´æ·ÛËé·ì϶ÀûÓÃǰÌá½ÏΪ¿Ì±¡¡£Í¬Ê±£¬ÓÉÓÚAdvantech WebAccessºÜ¶àÄ £¿é²¢Ã»ÓпªÆôASLR¡¢DEPµÈϵͳÓйذ²È«»úÔ죬ʹµÃÕ»Òç³öµÈ·ì϶ÔÚÊÜÓ°ÏìµÄϵͳÖÐÈÝÒ×Ôì³É´úÂëÖ´ÐС£


¿ªÔ´Ñ¹Ëõ¿âlibarchive´úÂëÖ´Ðзì϶£¨CVE-2019-18408£©·ÖÎö


¹È¸è°²È«×êÑÐÔ±·¢ÏÖlibarchive¿âÖдæÔÚ·ì϶CVE-2019-18408¡£¹¥»÷Õß¿ÉÀûÓþ«ÐÄ»ú¹ØµÄѹËõÎļþ£¬¶ÔÊÜÓ°ÏìÓû§Ôì³ÉѹËõ·¨Ê½»Ø¾ø·þÎñ»òÖ´ÐжñÒâ´úÂë¡£Õâ´Î±»ÆØ³öµÄ°²È«·ì϶¼ä½ÓÓ°Ïìµ½ÁË´óÁ¿ÏîÄ¿ºÍ²úÆ·¡£


Çø¿éÁ´×¨Ìâ·ÖÎö


Çø¿éÁ´ÖÇÄܺÏÔ¼½ÚÔìÁ÷¼ø±ð´ó¹æÄ£³¢ÊÔ×êÑÐ


GA»Æ½ð¼×ADLab½áºÏµç×ӿƼ¼´óÑ§ÍÆËã»úѧԺ³ÂÌü½ÌÊÚ¶ÔÒÔÌ«·»Çø¿éÁ´ÖÇÄܺÏÔ¼½ÚÔìÁ÷µÄ¼ø±ð½øÐÐÁË´ó¹æÄ£×êÑУ¬¸Ã×êÑзÖÎöÁ˵±Ç°6¸öÖ÷Á÷µÄÖÇÄܺÏÔ¼¾²Ì¬·ÖÎö¹¤¾ß£¬Í¨¹ý¶ÔÒÔÌ«·»Çø¿éÁ´ÉÏÒѲ¿ÊðµÄºÏÔ¼£¨½ü500Íò£©Ö´ÐÐÖ´Ðиú×ÙÀ´ÆÀ¹ÀËûÃǵľ²Ì¬½ÚÔìÁ÷¼ø±ðÄÜÁ¦¡£×êÑгɾÍÒѰ䷢ÔÚCCFÍÆ¼öµÄ2019ÄêBÀàѧÊõ»áÒéÉÏ£¬²¢»ñµÃÁË×î¼ÑÂÛÎÄÌáÃû½±¡£


Ô¤·À¡°¶çÊÖ¡±ØÍÆ· £¿Çø¿éÁ´Á´ÉÏÁ´ÏÂÊý¾ÝЭͬ·ÖÎö


GA»Æ½ð¼×ADLabÒÔΪ£¬Çø¿éÁ´µÄϵͳµÄ¿ÉÓÃÐÔÎÊÌâÊÇÉæ¼°Ö°ÄÜʵÏÖÐÔµÄÎÊÌ⣬¶øÊµÏÖÐÔÎÊÌâÐÔÖÊÊÇÆÓËØµÄ°²È«ÐÔÎÊÌ⣬²¢Õë¶Ô¡°Á´ÉÏÁ´ÏÂÊý¾ÝЭͬ¼¼Êõ¡±½øÐÐÁ˳ÖÐø×êÑС£µ±Ç°£¬Á´ÉÏÁ´ÏÂÊý¾ÝЭͬ¼¼Êõ²¢²»ÃÀÂú£¬µ¼ÖÂÇø¿éÁ´ÎÞ·¨Ðγɹػ·£¬ÊÇÏÞ¶ÈÇø¿éÁ´ÀûÓó¡¾°µÄÖØÒª¹ÊÕÏ¡£


GA»Æ½ð¼×»ý¼«·ÀÓù³¢ÊÔÊÒ£¨ADLab£©


ADLab³ÉÁ¢ÓÚ1999Ä꣬ÊÇÖйú°²È«ÐÐÒµ×îÔç³ÉÁ¢µÄ¹¥·À¼¼Êõ×êÑг¢ÊÔÊÒÖ®Ò»£¬Î¢ÈíMAPP´òËãÖ÷Ìâ³ÉÔ±£¬¡°ºÚȸ¹¥»÷¡±¸ÅÏëÊ×ÍÆÕß¡£½ØÖ¹Ä¿Ç°£¬ADLabÒÑͨ¹ýCVEÀۼư䲼°²È«·ì϶1000Óà¸ö£¬Í¨¹ý CNVD/CNNVDÀۼư䲼°²È«·ì϶600Óà¸ö£¬³ÖÐøÎ¬³Ö¹ú¼ÊÍøÂ簲ȫÁìÓòÒ»Á÷Ë®×¼¡£³¢ÊÔÊÒ×êÑз½Ïòº­¸Ç²Ù×÷ϵͳÓëÀûÓÃϵͳ°²È«×êÑÓ×¢ÒÆ¶¯ÖÇÄÜÖն˰²È«×êÑÓ×¢ÎïÁªÍøÖÇÄÜÉ豸°²È«×êÑÓ×¢Web°²È«×êÑÓ×¢¹¤¿ØÏµÍ³°²È«×êÑÓ×¢ÔÆ°²È«×êÑС£×êÑгɾÍÀûÓÃÓÚ²úÆ·Ö÷Ìâ¼¼Êõ×êÑÓ×¢¹ú¶È³Áµã¿Æ¼¼ÏîÄ¿¹¥¹Ø¡¢×¨Òµ°²È«·þÎñµÈ¡£