ÐÅÏ¢°²È«Öܱ¨-2019ÄêµÚ8ÖÜ

°ä²¼¹¦·ò 2019-02-25

±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2019Äê2ÔÂ18ÈÕÖÁ24ÈÕ¹²ÊÕ¼°²È«·ì϶48¸ö  £¬ÖµµÃ¹Ø×¢µÄÊÇDrupal CVE-2019-6340Ô¶³Ì´úÂëÖ´Ðзì϶£»WinRAR ACEÎļþËÁÒâ´úÂëÖ´Ðзì϶; Intel Data Center Manager SDK CVE-2019-0107ȨÏÞÌáÉý·ì϶£»Adobe Acrobat/Reader CVE-2019-7018ËÁÒâ´úÂëÖ´Ðзì϶£»Huawei Mate20 CVE-2019-5296»º³åÇøÒç¶Âí½Å¡£

±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊǺڿͰµÍøÏúÊÛµÚÈýÅúÓû§Êý¾Ý  £¬Éæ¼°8¸öÍøÕ¾Ô¼9300ÍòÓû§£»Wendy'sÔÞ³ÉΪÊý¾Ýй¶ÊÂÎñÖ§¸¶5000ÍòÃÀÔªºÍ½â½ð£»IxigoÔâºÚ¿ÍÈëÇÖ  £¬Ô¼1800ÍòÓû§Êý¾Ýй¶£»WinRAR´úÂëÖ´Ðзì϶  £¬³¬¹ý5ÒÚÓû§Êܵ½Ó°Ï죻ӡ¶ÈIndane¹«Ë¾Ð¹Â¶Ô¼679ÍòAadhaar¿Í»§µÄÓ×ÎÒÐÅÏ¢¡£

ƾ¾ÝÒÔÉÏ×ÛÊö  £¬±¾Öܰ²È«ÍþвΪÖС£

³ÁÒª°²È«·ì϶Áбí


1. Drupal CVE-2019-6340Ô¶³Ì´úÂëÖ´Ðзì϶
DrupalÔÚͨ¹ý·Ç±í¸ñ£¨non-form resources£©ÀàÐÍÊäÈëʱδÄÜÕýÈ·¹ýÂËijЩ×Ö¶Î  £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó  £¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£
https://www.drupal.org/sa-core-2019-003

2. WinRAR ACEÎļþËÁÒâ´úÂëÖ´Ðзì϶
WinRAR UNACEV2.dll¿â´¦ÖÃ.aceÎļþ´æÔÚĿ¼´©Ô½ÎÊÌâ  £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇó  £¬ÓÕʹÓû§½âÎö  £¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£
http://win-rar.com/

3. Intel Data Center Manager SDK CVE-2019-0107ȨÏÞÌáÉý·ì϶
Intel Data Center Manager SDK×°Ö÷¨Ê½Óû§ÌáÐÑʵÏÖ´æÔÚ°²È«·ì϶  £¬ÔÊÐí±¾µØ¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó  £¬¿ÉÌáÉýȨÏÞ¡£
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00215.html

4. Adobe Acrobat/Reader CVE-2019-7018ËÁÒâ´úÂëÖ´Ðзì϶
Adobe Acrobat/Reader´æÔÚ¿ªÊͺóʹÓ÷ì϶  £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇó  £¬ÓÕʹÓû§½âÎö  £¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐËÁÒâ´úÂë¡£
https://helpx.adobe.com/security/products/acrobat/apsb19-07.html

5. Huawei Mate20 CVE-2019-5296»º³åÇøÒç¶Âí½Å
Huawei Mate20´æÔÚÔ½½ç¶Á·ì϶  £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó  £¬¿ÉʹÉ豸Òì³£¡£
https://www.huawei.com/cn/psirt/security-advisories/huawei-sa-20190220-01-phone-cn

 ³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢ºÚ¿Í°µÍøÏúÊÛµÚÈýÅúÓû§Êý¾Ý  £¬Éæ¼°8¸öÍøÕ¾Ô¼9300ÍòÓû§

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

GnosticplayersÔÚ°µÍøÊг¡Éϰ䲼Á˵ÚÈýÅú´ýÊÛµÄÓû§ÕË»§Êý¾Ý  £¬Éæ¼°µ½8¸öÍøÕ¾µÄ9276ÍòÓû§¡£Õâ8¸öÍøÕ¾Ô̺¬£ºLegendas.tv£¨386Íò£©¡¢Jobandtalent£¨1100Íò£©¡¢Onebip£¨260Íò£©¡¢StoryBird£¨400Íò£©¡¢StreetEasy£¨100Íò£©¡¢GfyCat£¨800Íò£©¡¢ClassPass£¨150Íò£©ºÍPizap£¨6080Íò£©¡£ÕâÅúÓû§Êý¾ÝµÄ×ܼÛֵΪ2.6249¸ö±ÈÌØ±Ò  £¬¹²Ô¼9400ÃÀÔª¡£

Ô­ÎÄÁ´½Ó£º
https://www.zdnet.com/article/hacker-puts-up-for-sale-third-round-of-hacked-databases-on-the-dark-web/

2¡¢Wendy'sÔÞ³ÉΪÊý¾Ýй¶ÊÂÎñÖ§¸¶5000ÍòÃÀÔªºÍ½â½ð

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾Ý×îб¨Â·  £¬²ÍÒû¹«Ë¾Wendy'sÒÑÔÞ³ÉΪ2015ÄêµÄÊý¾Ýй¶ÊÂÎñÖ§¸¶5000ÍòÃÀÔªµÄºÍ½â½ð¡£ÔÚ¸ÃÊý¾Ýй¶ÊÂÎñÖÐ  £¬Ô¼1800ÍòÕÅÐÅÓþ¿¨¼°½è¼Ç¿¨ÐÅÏ¢Ô⵽й¶  £¬Îª´Ë½ðÈÚ»ú¹¹ÔÚ2016ÄêÌáÆðÁËËßËÏ¡£Æ¾¾ÝÌá½»¸øÆ¥×ȱ¤ÁªÍõ·¨ÔºµÄÒ»·ÝÎļþ  £¬ÕâЩºÍ½â½ð½«Ö§¸¶¸øÔ¼7500¼ÒÒøÐкÍÐÅÓþÉç¡£¸ÃÂòÂôÈÔÐèµÃµ½·¨ÔºµÄºË×¼¡£

Ô­ÎÄÁ´½Ó£º
https://www.databreaches.net/update-wendys-settles-financial-firms-lawsuit-over-data-breach-for-50-mln/

3¡¢IxigoÔâºÚ¿ÍÈëÇÖ  £¬Ô¼1800ÍòÓû§Êý¾Ýй¶

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÔÚÏßÓÎÀÀƽ̨IxigoµÄÔ¼1800ÍòÓû§Êý¾Ý±»µÁ  £¬ÕâЩÊý¾ÝÖØÒªÔ̺¬Óû§µÄµç×ÓÓʼþIDºÍ¹þÏ£ÃÜÂëµÈ¡£¸Ã¹«Ë¾CEO Aloke Bajpai°µÊ¾¸Ã¹«Ë¾²¢Î´´æ´¢Óû§µÄÖ§¸¶ÐÅÏ¢  £¬Òò¶øÃ»ÓÐÓйØÐÅÏ¢±»µÁ  £¬ÇҸù«Ë¾ÔÚ֪ͨ²¢ÒªÇóÓû§³ÁÖÃÆäÃÜÂëºÍ°²È«ÁîÅÆ¡£¸Ã¹«Ë¾½²»°È˰µÊ¾  £¬ÆäÓû§×ÜÊýΪԼ1ÒÚ¡£


Ô­ÎÄÁ´½Ó£º
https://timesofindia.indiatimes.com/business/india-business/emails-hashed-passwords-of-18m-ixigo-users-stolen/articleshow/68016866.cms

4¡¢WinRAR´úÂëÖ´Ðзì϶  £¬³¬¹ý5ÒÚÓû§Êܵ½Ó°Ïì

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Check Point×êÑÐÍŶÓÅû¶WinRARÖеĴúÂëÖ´Ðзì϶  £¬¸Ã·ì϶ÒÑ´æÔÚÁ˳¬¹ý19ÄêµÄ¹¦·ò  £¬Ó°ÏìÁ˳¬¹ý5ÒÚÓû§¡£¸Ã·ì϶£¨CVE-2018-20250¡¢CVE-2018-20251¡¢CVE-2018-20252ºÍCVE-2018-20253£©´æÔÚÓÚWinRARµÄUNACEV2.DLL¿âÖÐ  £¬Õâ¸ö¿âÕÆ¹Ü½âѹËõACEÌåʽµÄѹËõÎļþ¡£×êÑÐÈËÔ±·¢ÏÖ¸Ã¿â´æÔÚ±àÂëȱµã  £¬¹¥»÷Õß¿ÉÀûÓöñÒâACEÎļþÔÚ½âѹËõµÄÖ÷ÕÅõè¾¶Ö®±íÖ²Èë¶ñÒâÈí¼þ¡£WinRARÍŶӰµÊ¾ÓÉÓÚUNACEV2.DLL´Ó2005ÄêÆð¾ÍÖÕ³¡Á˸üР £¬¿ª·¢ÈËÔ±ÒѾ­Ê§È¥Á˸ÿâÔ´´úÂëµÄ½Ó¼ûȨÏÞ  £¬Òò¶øËûÃÇÑ¡ÔñÉÕ»Ù¶ÔACEÌåʽµÄÖ§³Ö¡£WinRAR¿ª·¢ÕßÔÚ1ÔÂ28ÈÕ°ä²¼ÁËWinRAR 5.70 Beta 1ÒÔ½¨¸´´Ë·ì϶¡£

Ô­ÎÄÁ´½Ó£º
https://research.checkpoint.com/extracting-code-execution-from-winrar/

5¡¢Ó¡¶ÈIndane¹«Ë¾Ð¹Â¶Ô¼679ÍòAadhaar¿Í»§µÄÓ×ÎÒÐÅÏ¢

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


·¨¹ú°²È«×êÑÐÔ±Baptiste RobertÔÚһλÄäÃûÓ¡¶È×êÑÐÈËÔ±µÄÔ®ÊÖÏ  £¬·¢ÏÖÓ¡¶È¹úÓÐÒº»¯Ê¯ÓÍÆø¹«Ë¾IndaneµÄ¹ÙÍøÐ¹Â¶ÁËÊý°ÙÍòAadhaar¿Í»§µÄÓ×ÎÒÐÅÏ¢¡£Robert°µÊ¾  £¬ËûÄܹ»ÀûÓÃIndaneÒÆ¶¯APPÖеķì϶ÕÒµ½11062¸öÓÐЧµÄ¾­ÏúÉÌID  £¬²¢ÇÒÀûÓÃÕâЩIDÔÚ¾­ÏúÉÌÃÅ»§ÍøÕ¾ÉÏ»ñÈ¡AadhaarÓû§µÄÓ×ÎÒÐÅÏ¢  £¬Ô̺¬AadhaarºÅÂë¡¢ÐÕÃûºÍסַ¡£Robert¹À¼ÆÊÜÓ°ÏìµÄÓû§ÊýԼΪ679Íò¡£

Ô­ÎÄÁ´½Ó£º
https://thehackernews.com/2019/02/indane-aadhaar-leak.html

ÉêÃ÷£º±¾×ÊѶÓÉGA»Æ½ð¼×άËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù