ÐÅÏ¢°²È«Öܱ¨-2019ÄêµÚ45ÖÜ

°ä²¼¹¦·ò 2019-11-18

>±¾Öܰ²È«Ì¬ÊÆ×ÛÊö



2019Äê11ÔÂ11ÈÕÖÁ17ÈÕ¹²ÊÕ¼°²È«·ì϶48¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇMicrosoft Windows OpenType×ÖÌå½âÎöCVE-2019-1456Ô¶³ÌÖ´ÐдúÂë·ì϶; eQ-3 Homematic CCU3 testtcl.cgi´úÂëÖ´Ðзì϶£»SAP Diagnostics AgentËÁÒâOSºÅÁî×¢Èë·ì϶£»Istio»Ø¾ø·þÎñ·ì϶£»Adobe Illustrator CVE-2019-8248ÄÚ´æ·ÛËéËÁÒâ´úÂëÖ´Ðзì϶¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇÍйܷþÎñÉÌSmarterASP.NETÔâÀÕË÷Èí¼þ¹¥»÷£»¶íÂÞ˹з¨°¸Ç¿ÔìÊÖ»úºÍPCԤװÖñ¾¹úÈí¼þ£»5Gзì϶¿É¸ú×ٵ绰µØÎ»¼°¹ã²¥Ðéα¾¯±¨£»McAfeeɱ¶¾Èí¼þ´úÂëÖ´Ðзì϶(CVE-2019-3648)£»¸ßͨоƬ×éQSEE·ì϶¿ÉÖÂAndroidÉ豸Êý¾Ýй¶¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖС£


>³ÁÒª°²È«·ì϶Áбí


1. Microsoft Windows OpenType×ÖÌå½âÎöCVE-2019-1456Ô¶³ÌÖ´ÐдúÂë·ì϶
Microsoft Windows OpenType×ÖÌå½âÎö´¦ÖÃOpentype×ÖÌå´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇ󣬿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐËÁÒâ´úÂë¡£
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1456

2. eQ-3 Homematic CCU3 testtcl.cgi´úÂëÖ´Ðзì϶
eQ-3 Homematic CCU3 save.cgi¾ç±¾¿ÉÓÃÀ´ÉÏ´«¾ç±¾²¢±»testtcl.cgi¾ç±¾Ö´ÐУ¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉÖ´ÐÐËÁÒâ´úÂë¡£
https://psytester.github.io/CVE-2019-18938/

3. SAP Diagnostics AgentËÁÒâOSºÅÁî×¢Èë·ì϶
SAP Diagnostic Agent´æÔÚδÃ÷°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉÖ´ÐÐËÁÒâOSºÅÁî¡£
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=528880390

4. Istio»Ø¾ø·þÎñ·ì϶
Istio´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉʹÀûÓ÷¨Ê½±ÀÀ£¡£
https://github.com/istio/istio/issues/18229

5. Adobe Illustrator CVE-2019-8248ÄÚ´æ·ÛËéËÁÒâ´úÂëÖ´Ðзì϶
Adobe Illustrator´¦ÖÃÎļþ´æÔÚÄÚ´æ·ÛËé·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇ󣬿ÉÖ´ÐÐËÁÒâ´úÂë»òÕß½øÐлؾø·þÎñ¹¥»÷¡£
https://helpx.adobe.com/security/products/illustrator/apsb19-36.html


>³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢ÍйܷþÎñÉÌSmarterASP.NETÔâÀÕË÷Èí¼þ¹¥»÷


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


SmarterASP.NETÊÇÒ»¼ÒÕ¼Óг¬¹ý44Íò¸ö¿Í»§µÄASP.NETÍйܷþÎñÉÌ£¬¸Ã¹«Ë¾ÔÚÖÜÄ©Ôâµ½ÀÕË÷Èí¼þ¹¥»÷¡£µ±Ç°SmarterASP.NET°µÊ¾ÔÚÖÂÁ¦¸´Ô­¿Í»§µÄ·þÎñÆ÷£¬µ«²»Ã÷ÏԸù«Ë¾ÊÇÖ§¸¶ÁËÊê½ð»¹ÊÇÔÚ´Ó±¸·ÝÖи´Ô­¡£Õâ´Î¹¥»÷Öв»½ö¿Í»§Êý¾ÝÊܵ½Ó°Ï죬²¢ÇÒSmarterASP.NET×ÔÉíÒàÊÜÓ°Ïì¡£¸Ã¹«Ë¾µÄÍøÕ¾ÔÚÐÇÆÚÁùÈ«Ìì¶¼ÏÂÏߣ¬Ö±µ½ÐÇÆÚÌìÔçÉϲųÁÐÂÉÏÏß¡£·þÎñÆ÷¸´Ô­¹¤×÷½øÕ¹»ºÂý£¬ºÜ¶à¿Í»§ÒÀÈ»ÎÞ·¨½Ó¼ûÆäÕË»§ºÍÊý¾Ý£¬Ô̺¬ÍøÕ¾ÎļþºÍºó¶ËÊý¾Ý¿â¡£Æ¾¾ÝÔÚTwitterÉϰ䲼µÄ½ØÍ¼£¬±»¼ÓÃܵĿͻ§Îļþºó¸½¼ÓÁË¡°.kjhbx¡±À©´óÃû£¬Ä¿Ç°×êÑÐÈËÔ±ÈÔÔÚÊÔͼȷÈÏÀÕË÷Èí¼þµÄÖÖÀà¡£

Ô­ÎÄÁ´½Ó£º
https://www.zdnet.com/article/major-asp-net-hosting-provider-infected-by-ransomware/

2¡¢¶íÂÞ˹з¨°¸Ç¿ÔìÊÖ»úºÍPCԤװÖñ¾¹úÈí¼þ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¶íÂÞ˹Òé»áÔÚÍÆ¶¯Ò»ÏîÁ¢·¨£¬¸Ã·¨°¸½«Ç¿ÔìÒªÇóËùÓÐÔÚ¶íÂÞ˹ÏúÊ۵ĵç×ÓÉ豸£¨Ô̺¬ÖÇÄÜÊÖ»ú¡¢PCºÍÖÇÄܵçÊӵȣ©Ô¤×°Öñ¾¹ú¿Æ¼¼¹«Ë¾µÄÀûÓá£Õâ¿ÉÄÜ»á´øÀ´°²È«Òþ»¼¡£Á¢·¨Õß°µÊ¾¸Ã·¨°¸ÊÇΪÁ˱£»¤±¾µØµÄ¼¼ÊõÊг¡ÃâÊܱí¹ú£¨¿ÉÄÜÊÇÖ¸ÃÀ¹ú£©µÄ¾ºÕù¡£µ±¾Ö½«Õë¶ÔÿÖÖÉ豸ÀàÐͰ䲼һ·ÝÈí¼þÁбí£¬É豸¹©¸øÉ̱ØÒªÔÚ¶íÂÞ˹ÏúÊÛµÄÉ豸ÉÏԤװÖÃÕâЩÈí¼þ¡£ÈôÊǹ©¸øÉ̲»×ñÊØ»®¶¨£¬½«±»´¦ÒÔ×î¸ß20Íò¬²¼£¨Ô¼ºÏ3100ÃÀÔª£©µÄ·£¿î¡£¸Ã·¨°¸µÃµ½ÁËËùÓÐÖØÒªÕþµ³µÄÖ§³Ö£¬ÕâÒâζ×ÅËüºÜÓпÉÄܽ«ÔÚ2020Äê7ÔÂ1ÈÕÉúЧ¡£

Ô­ÎÄÁ´½Ó£º
https://www.zdnet.com/article/phones-and-pcs-sold-in-russia-will-have-to-come-pre-installed-with-russian-apps/

3¡¢5Gзì϶¿É¸ú×ٵ绰µØÎ»¼°¹ã²¥Ðéα¾¯±¨


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÆÕ¶É´óѧ£¨Purdue University£©ºÍ°®ºÉ»ª´óѧ£¨University of Iowa£©µÄ°²È«×êÑÐÈËÔ±·¢ÏÖ½«½ü12¸ö5G°²È«·ì϶£¬×êÑÐÈËÔ±°µÊ¾ÕâЩ·ì϶¿ÉÔÊÐí¹¥»÷Õß»ñȡָ±êÓû§µç»°µÄÐÂ/¾ÉÒ»Ê±ÍøÂç±êʶ·û£¬´Ó¶ø¸ú×ٵ绰µÄµØÎ»£¬ÉõÖÁ½Ù³ÖѰºôÐÅ·½øÐÐÐéαµÄ´¹Î£¾¯±¨¹ã²¥¡£ÔÚijЩÇé¿öÏ£¬ÕâЩ·ì϶¿ÉÄܱ»ÓÃÀ´½«·äÎÑÏνӽµ¼¶Îª²»Ì«°²È«µÄ³ß¶È¡£Ò»Ð©ÐµĹ¥»÷Ò²¿ÉÄÜÔÚÏÖÓеÄ4GÍøÂçÉϱ»ÀûÓ᣼øÓÚ·ì϶µÄÐÔÖÊ£¬×êÑÐÈËÔ±°µÊ¾ËûÃDz»³ïË㹫¿ªÆäPoC´úÂ룬µ«ËûÃǽ«ÕâЩ·¢ÏÖ֪ͨÁËÈ«Çò·äÎÑÍøÂçGSMЭ»á£¨GSMA£©¡£GSMAûÓÐй©ÊÇ·ñÄܹ»½¨¸´·ì϶£¬Ò²Ã»ÓÐй©½¨¸´¹¦·ò¡£


Ô­ÎÄÁ´½Ó£º

https://finance.yahoo.com/news/5g-flaws-track-phone-locations-163014364.html

4¡¢McAfeeɱ¶¾Èí¼þ´úÂëÖ´Ðзì϶(CVE-2019-3648)

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


SafeBreach Labs·¢ÏÖMcAfee·À²¡¶¾Èí¼þÊÜ´úÂëÖ´Ðзì϶£¨CVE-2019-3648£©µÄÓ°Ï죬¹¥»÷Õß¿ÉÈÆ¹ýMcAfeeµÄ×ÔÎÀ»úÔ죬¿ÉÄܵ¼Ö¶ÔÊÜϰȾϵͳµÄ½øÒ»²½¹¥»÷¡£¸Ã·ì϶ÊÇÓÉÓÚδÑéÖ¤¼ÓÔØDLLµÄÊðÃûµ¼ÖµÄ£¬¹¥»÷Õ߿ɽ«ËÁÒâδÊðÃûµÄDLL¼ÓÔØµ½ÒÔNT AUTHORITY\SYSTEMȨÏÞÔËÐеĶà¸ö·þÎñÖС£¸Ã¹¥»÷»¹Äܹ»ÈƹýÀûÓ÷¨Ê½°×Ãûµ¥±£»¤²¢Ô¤·À±»°²È«Èí¼þ¼ì²âµ½¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/mcafee-antivirus-software-impacted-by-code-execution-vulnerability/

5¡¢¸ßͨоƬ×éQSEE·ì϶¿ÉÖÂAndroidÉ豸Êý¾Ýй¶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾Ý°²È«³§ÉÌCheckPointµÄÒ»·Ý»ã±¨£¬¸ßͨоƬ×éÖеݲȫִÐл·¾³£¨QSEE£©ÖдæÔÚ·ì϶£¨CVE-2019-10574£©£¬¿Éµ¼ÖÂAndroidÉ豸ÖеÄÓ×ÎÒÊý¾Ýй¶¡£QSEEÊÇ»ùÓÚARM TrustZone¼¼ÊõµÄÊÜÐÅÀµÖ´Ðл·¾³£¨TEE£©µÄʵÏÖ£¬ÊÇÖ÷´¦ÖÃÆ÷ÉϵÄÒ»¸öÓ²¼þ¸ôÀëµÄ°²È«ÇøÓò£¬ÆäÖÐͨ³£Ô̺¬×¨ÓüÓÃÜÃÜÔ¿¡¢ÃÜÂë¡¢ÐÅÓþ¿¨ºÍ½è¼Ç¿¨Í´´¦µÈÃô¸ÐÐÅÏ¢¡£Check Point×êÑÐÈËÔ±ÄæÏòÁ˸Ãϵͳ£¬²¢ÀûÓÃÍÌͲâÊÔ¶ÔÈýÐÇ¡¢LGºÍĦÍÐÂÞÀ­É豸½øÐÐÁ˲âÊÔ¡£×ÜÌå¶øÑÔ£¬×êÑÐÈËÔ±·¢ÏÖÈýÐǵÄÊÜÐÅÀµ´úÂëÔ̺¬Ëĸö·ì϶£¬Ä¦ÍÐÂÞÀ­ºÍLG±ðÀëÔ̺¬Ò»¸ö·ì϶£¬µ«ËùÓдúÂë¾ùÀ´×Ô¸ßͨ¹«Ë¾¡£ÈýÐÇ¡¢¸ßͨºÍLGÒÑÕë¶ÔÕâЩQSEE·ì϶°ä²¼Á˲¹¶¡¸üС£

Ô­ÎÄÁ´½Ó£º
https://thehackernews.com/2019/11/qualcomm-android-hacking.html