ÐÅÏ¢°²È«Öܱ¨-2019ÄêµÚ5ÖÜ
°ä²¼¹¦·ò 2019-03-04±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇÊý¾ÝÖÎÀí¹«Ë¾RubrikÒâ±íй¶´óÁ¿¿Í»§Êý¾Ý£»FaceTimeÆØ³Á´óÇÔÌý·ì϶£¬Apple°µÊ¾½«ÔÚ±¾Öܽ¨¸´£»Å·ÖÞÍøÂçÐÅÏ¢°²È«¾ÖENISA°ä²¼2018ÄêÍøÂçÍþв¾°¹Û»ã±¨£»Ó¡¶È¹ú¶ÈÒøÐÐSBIÒâ±íй¶Êý°ÙÍò¿Í»§ÐÅÏ¢£»ºÉÀ¼DPA°ä²¼2018ÄêÊý¾Ýй¶ͳ¼Æ»ã±¨¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖС£
³ÁÒª°²È«·ì϶Áбí
Apache Hadoop´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Èƹý°²È«ÏÞ¶È£¬Ö´ÐÐδÊÚȨµÄ²Ù×÷¡£
https://hadoop.apache.org/cve_list.html#cve-2018-8009-http-cve-mitre-org-cgi-bin-cvename-cgi-name-cve-2018-8009-zip-slip-impact-on-apache-hadoop
2. D-Link DIR-823G HNAP1ÒªÇóºÅÁî×¢Èë·ì϶
D-Link DIR-823G´æÔÚ´úÂë×¢Èë·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄHNAP1ÒªÇó£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐOSºÅÁî¡£
https://github.com/leonW7/D-Link/blob/master/Vul_1.md
3. ACD Systems Canvas Draw CVE-2018-3976»º³åÇøÒç¶Âí½Å
ACD Systems Canvas Draw CALS RasterÎļþ½âÎöÖ°ÄÜ´æÔÚÔ½½çдÈë·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐËÁÒâ´úÂë¡£
https://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0642
4. ARM Trusted Firmware-AÐÅϢй¶·ì϶
ARM Trusted Firmware-A´æÔÚ°²È«·ì϶£¬ÔÊÐí±¾µØ¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ɻñÈ¡Ãô¸ÐÐÅÏ¢¡£
https://github.com/ARM-software/arm-trusted-firmware/wiki/Trusted-Firmware-A-Security-Advisory-TFV-8
5. Google Chrome PDFium CVE-2019-5772¿ªÊͺóÀûÓôúÂëÖ´Ðзì϶
Google Chrome PDFium´æÔÚ¿ªÊͺóʹÓ÷ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄWEBÒ³ÒªÇó£¬ÓÕʹÓû§½âÎö£¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢¡£
https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html
³ÁÒª°²È«ÊÂÎñ×ÛÊö
°²È«×êÑÐÔ±Oliver Hough·¢ÏÖÊôÓÚÊý¾ÝÖÎÀí¹«Ë¾RubrikµÄÒ»¸öElasticsearch·þÎñÆ÷δÊÜÃÜÂë±£»¤£¬¸ÃÊý¾Ý¿â´æ´¢ÁËÊýÊ®GBµÄÊý¾Ý£¬Ô̺¬ÆóÒµ¿Í»§µÄÃû³Æ¡¢ÁªÏµÐÅÏ¢ºÍ¹¤×÷°¸Àý¡£Æ¾¾Ý¹¦·ò´Á£¬ÕâЩÊý¾Ý¿É×·ÒäÖÁ2018Äê10Ô¡£¾¹ýµ÷²é£¬Rubrik³ÆÕâÒ»ÊÂÎñÊÇÓɱ¨´ðÃýÎóµ¼Öµġ£
ÔÎÄÁ´½Ó£º
https://techcrunch.com/2019/01/29/rubrik-data-leak/
2¡¢FaceTimeÆØ³Á´óÇÔÌý·ì϶£¬Apple°µÊ¾½«ÔÚ±¾Öܽ¨¸´
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/01/apple-facetime-privacy-hack.html
3¡¢Å·ÖÞÍøÂçÐÅÏ¢°²È«¾ÖENISA°ä²¼2018ÄêÍøÂçÍþв¾°¹Û»ã±¨
ÔÎÄÁ´½Ó£º
https://www.enisa.europa.eu/publications/enisa-threat-landscape-report-2018/
4¡¢Ó¡¶È¹ú¶ÈÒøÐÐSBIÒâ±íй¶Êý°ÙÍò¿Í»§ÐÅÏ¢
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/80555/data-breach/state-bank-of-india-leak.html
5¡¢ºÉÀ¼DPA°ä²¼2018ÄêÊý¾Ýй¶ͳ¼Æ»ã±¨
ÔÎÄÁ´½Ó£º
https://www.databreaches.net/dutch-dpa-publishes-2018-report-on-data-breach-statistics/
ÉêÃ÷£º±¾×ÊѶÓÉGA»Æ½ð¼×άËûÃü°²È«Ó××é·ÒëºÍÕû¶Ù


¾©¹«Íø°²±¸11010802024551ºÅ