ÐÅÏ¢°²È«Öܱ¨-2019ÄêµÚ37ÖÜ
°ä²¼¹¦·ò 2019-09-23> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
2019Äê9ÔÂ16ÈÕÖÁ22ÈÕ¹²ÊÕ¼°²È«·ì϶43¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇFastjson<=1.2.60Ô¶³Ì´úÂëÖ´Ðзì϶£»e-cologyÔ¶³Ì´úÂëÖ´Ðзì϶£»CODESYS V3 Web ServerÕ»Òç¶Âí½Å£»VMware ESXi 'busybox'ºÅÁî×¢Èë·ì϶£»Schneider Electric BMXNOR0200H Ethernet/Serial RTU module»Ø¾ø·þÎñ·ì϶¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊǶò¹Ï¶à¶û´ó²¿ÃŹ«ÃñÒþÖÔй¶£¬Ô̺¬670Íò¶ùͯÐÅÏ¢£»Ê¨×Óº½¿Õ¹«Ë¾ÊýǧÍòÓû§¼Í¼ÔÚ°µÍøÐ¹Â¶£»MITRE°ä²¼2019ÄêCWE×îΣÏÕÈí¼þÃýÎóÁбíTop25£»AMD RadeonÇý¶¯·¨Ê½±»ÆØ´æÔÚÐé¹¹»úÌÓÒÝ·ì϶£»ÈýÐǺÍLGÖÇÄÜÉ豸½«Óû§Ãô¸ÐÊý¾Ý·¢Ë͵½ºÏ×÷¹«Ë¾¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖС£
> ³ÁÒª°²È«·ì϶Áбí
1. Fastjson<=1.2.60Ô¶³Ì´úÂëÖ´Ðзì϶
Fastjson´æÔÚ·´ÐòÁл¯·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐËÁÒâ´úÂë¡£
https://github.com/alibaba/fastjson/commit/05a7aa7f748115018747f7676fd2aefdc545d17a
2. e-cologyÔ¶³Ì´úÂëÖ´Ðзì϶
e-cology BeanShell×é¼þ´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉÖ´ÐÐËÁÒâºÅÁî¡£
https://help.aliyun.com/noticelist/articleid/1060057523.html?spm=5176.2020520154.sas.20.36a91e43Zt9Vx7
3. CODESYS V3 Web ServerÕ»Òç¶Âí½Å
CODESYS V3 Web Servers´æÔÚÕ»Òç¶Âí½Å£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉÖ´ÐÐËÁÒâ´úÂë»òʹÀûÓ÷¨Ê½±ÀÀ£¡£
https://www.codesys.com/fileadmin/data/customers/security/2019/Advisory2019-06_CDS-64543.pdf
4. VMware ESXi 'busybox'ºÅÁî×¢Èë·ì϶
VMware ESXi 'busybox'´¦ÖÃÎļþÃû´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉÖ´ÐÐËÁÒâºÅÁî¡£
https://www.vmware.com/security/advisories/VMSA-2019-0013.html
5. Schneider Electric BMXNOR0200H Ethernet/Serial RTU module»Ø¾ø·þÎñ·ì϶
Schneider Electric BMXNOR0200H Ethernet/Serial RTU module´¦ÖôóÁ¿IEC 60870-5-104±¨ÎÄ´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉʹÀûÓ÷¨Ê½±ÀÀ£¡£
https://www.schneider-electric.com/en/download/document/SEVD-2019-225-03/
> ³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢¶ò¹Ï¶à¶û´ó²¿ÃŹ«ÃñÒþÖÔй¶£¬Ô̺¬670Íò¶ùͯÐÅÏ¢
×êÑÐÈËÔ±·¢ÏÖÒ»¼Ò±¾µØ¹«Ë¾NovaestratµÄElasticsearch·þÎñÆ÷¶³öÁ˶ò¹Ï¶à¶û´óÎÞÊý¹«ÃñµÄÒþÖÔÐÅÏ¢¡£¶ò¹Ï¶à¶ûµÄÈ˶¡»ùÊýΪ1660Íò£¬¶ø¸ÃÊý¾Ý¿âÔ̺¬½ü2080ÍòÌõÓû§¼Í¼£¬³¬¹ýÁ˸ùúµÄÈ˶¡Êý¾Ý£¬ÆäÔÒòÊÇÊý¾Ý¿âÖÐÔ̺¬Ò»Ð©³Á¸´¼Í¼ºÍéæÃü¹«ÃñµÄ¼Í¼¡£Ð¹Â¶µÄÊý¾ÝÔ̺¬ÐÕÃû¡¢¼ÒÍ¥³ÉÔ±/¼Ò×åÊ÷¡¢¹«Ãñ×¢²áÊý¾Ý¡¢²ÆÕþ¼°¹¤×÷ÐÅÏ¢¡¢³µÁ¾ÐÅÏ¢µÈ¡£Êý¾Ý¿âÖл¹Ô̺¬µ±¾ÖÔ±¹¤ÐÅÏ¢ºÍ677Íò¶ùͯÐÅÏ¢£¬ÒÔ¼°700ÍòÌõ²ÆÕþ¼Í¼ºÍ250ÍòÌõ³µÁ¾¼Í¼¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/database-leaks-data-on-most-of-ecuadors-citizens-including-6-7-million-children/
2¡¢Ê¨×Óº½¿Õ¹«Ë¾ÊýǧÍòÓû§¼Í¼ÔÚ°µÍøÐ¹Â¶
ʨ×Óº½¿ÕÆìÏÂÁ½¼Òº½¿Õ¹«Ë¾µÄÊýǧÍòÌõ´î¿Í¼Í¼ÔÚ°µÍøÂÛ̳ÉÏй¶¡£ÕâЩÊý¾Ý´æ´¢Ôڿɹ«¿ª½Ó¼ûµÄAmazon´æ´¢Í°ÖУ¬¹²ÓÐÁ½¸öÊý¾Ý¿â£¬Ò»¸öÔ̺¬2100Íò±Ê¼Í¼£¬ÁíÒ»¸öÔ̺¬1400Íò±Ê¼Í¼£¬¸ÃĿ¼Ï»¹Ô̺¬2019Äê5Ô·ݴ´½¨µÄ±¸·ÝÎļþ£¬ÖØÒªÊôÓÚMalindo AirºÍThai Lion Air¡£ÁíÒ»¸ö±¸·ÝÎļþµÄÃû³ÆÊÇBatik Air£¬¸Ã¹«Ë¾µÄĸ¹«Ë¾Ò²ÊÇʨ×Óº½¿Õ¡£Ð¹Â¶µÄÐÅÏ¢Ô̺¬´î¿ÍµÄÔ¤Ô¼ID¡¢¾ÓסµØÖ·¡¢µç»°ºÅÂë¡¢ÓÊÏ䵨ַ¡¢ÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢»¤ÕÕºÅÂëºÍµ½ÆÚÈÕÆÚµÈ¡£Ä¿Ç°»¹²»Ã÷ÏÔÕâЩÊý¾Ý³õ´Îй¶µÄ¹¦·ò£¬µ«¾Ý³ÆÖÁÉÙ´Ó8ÔÂ10ÈÕÆð¸ÃÊý¾Ý¿âÒÑÔÚÂÛ̳ÉÏÁ÷ͨ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/millions-of-lion-air-passenger-records-exposed-and-exchanged-on-forums/
3¡¢MITRE°ä²¼2019ÄêCWE×îΣÏÕÈí¼þÃýÎóÁбíTop25
·ÇͶ»ú×éÖ¯MITER°ä²¼2019Äê×îΣÏÕµÄÈí¼þ·ì϶ºÍÃýÎóÁбíTop25¡£Æ¾¾ÝMITRE£¬×îΣÏÕµÄÈí¼þÃýÎóÊÇCWE-119£¬Ëü±»ÃèÊöΪ¡°¶ÔÄڴ滺³åÇøÌìǵÄÚ²Ù×÷µÄ²»ÕýÈ·ÏÞ¶È¡±£¬¼´»º³åÇøÒç³öµ¼ÖµÄÔ½½ç¶Á»òд¡£ÅÅÔÚµÚ¶þλµÄÊÇCWE-79£¬±»ÃèÊöΪ¡°ÍøÒ³ÌìÉúÆÚ¼äÊäÈëÔì³ÉµÄ²»ÕýÈ··´Ó³¡±£¬¼´XSS¹¥»÷¡£µÚÈýÃûÔòÊÇCWE-20£¬¼´¡°²»ÕýÈ·µÄÊäÈëÑéÖ¤¡±¡£¸ÃÁбíÊÇ»ùÓÚMITERÊý¾Ý¿âÖеÄCVEÊý¾Ý¼°NVDÊý¾Ý¿âºÍCVSS»ñµÃµÄÐÅÏ¢£¬×ܹ²ÓÐԼĪ2.5Íò¸öCVEÌṩÁËÔ´Êý¾Ý¡£ÆëÈ«ÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/these-software-vulnerabilities-top-mitres-most-dangerous-list-in-2019/
4¡¢AMD RadeonÇý¶¯·¨Ê½±»ÆØ´æÔÚÐé¹¹»úÌÓÒÝ·ì϶

˼¿ÆTalosÅû¶AMD ATI Radeon ATIDXX64.DLLÇý¶¯·¨Ê½ÖеÄÐé¹¹»úÌÓÒÝ·ì϶¡£¸Ã·ì϶´æÔÚÓÚAMD Radeon RX 550¼°550ϵÁÐÏÔ¿¨ÖУ¬²¢ÇÒÖ»ÄÜÔÚÔËÐÐVMWare Workstation 15ʱ´¥·¢¡£×êÑÐÈËÔ±Ú¹Êͳƣ¬¿ÉÔÚVMwareÐé¹¹»úϵͳÖÐͨ¹ý¶ñÒâÏñËØ×ÅÉ«Æ÷ÔÚAMD ATIDXX64.DLLÇý¶¯·¨Ê½Öд¥·¢ÄÚ´æÔ½½çдÈ룬Õâ¿ÉÄܻᴥ·¢VMwareÀ´±öģʽµÄ·ì϶£¬´Ó¶øÔÚËÞÖ÷»úÉÏÖ´ÐдúÂë¡£¸Ã·ì϶ӰÏìÁËATIDXX64.DLLÇý¶¯·¨Ê½°æ±¾25.20.15031.5004ºÍ25.20.15031.9002¡£¸Ã·ì϶£¨CVE-2019-5049£©µÄCVSSÆÀ·ÖΪ9.0¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/amd-radeon-cards-vmware-workstations/148406/
5¡¢ÈýÐǺÍLGÖÇÄÜÉ豸½«Óû§Ãô¸ÐÊý¾Ý·¢Ë͵½ºÏ×÷¹«Ë¾
×êÑÐÈËÔ±·¢ÏÖ¼´±ãÊÇÔÚÉ豸ÏÐÖÃʱ£¬ÈýÐÇ¡¢LGºÍRokuµÈ¹«Ë¾µÄÖÇÄܵçÊÓÒ²»áÏòºÏ×÷µÄ¿Æ¼¼¹«Ë¾·¢ËÍÃô¸ÐµÄÓû§Êý¾Ý¡£Æ¾¾ÝÁ½¸öÍŶӵĶÀÁ¢×êÑУ¬ÖÇÄܵçÊÓµÄOTTƽ̨»á½«Óû§µÄÃô¸ÐÊý¾Ýй¶¸øFacebook¡¢ÑÇÂíÑ·¡¢¹È¸èºÍNetflixµÈ¹«Ë¾¡£µÚÒ»·Ý»ã±¨×êÑÐÁË81̨É豸£¬·¢ÏÖÓÐ72̨É豸½«Êý¾Ý·¢Ë͵½·ÇÔì×÷ÉÌµÄÆäËü¹«Ë¾¡£µÚ¶þ·Ý»ã±¨·¢ÏÖ´ÓÖÇÄܵçÊÓ·¢Ë͵ÄÊý¾ÝÒ²Óë¹È¸èºÍFacebookÖÎÀíµÄ¸ú×ÙÆ÷Óйأ¬×êÑÐÈËÔ±³Æ89%µÄAmazon Fire TVƵ·ºÍ69%µÄRokuƵ·¶¼Ô̺¬ÓÃÓÚ¸ú×ÙÓû§ÊÕ¿´Ï°¹ßºÍÆ«ºÃÐÅÏ¢µÄ¸ú×ÙÆ÷¡£ÕâЩ¸ú×ÙÆ÷»¹Äܹ»¼ø±ðÉ豸ºÍʹÓõØÎ»£¬Ô̺¬É豸ÐòÁкźÍID¡¢Wi-FiÃû³ÆºÍMACµØÖ·µÈ¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/smart-tvs-leak-data/148482/


¾©¹«Íø°²±¸11010802024551ºÅ