ÐÅÏ¢Äþ¾²Öܱ¨-2019ÄêµÚ8ÖÜ

Ðû²¼Ê±¼ä 2019-02-25

±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


2019Äê2ÔÂ18ÈÕÖÁ24ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´48¸ö £¬ÖµµÃ¹Ø×¢µÄÊÇDrupal CVE-2019-6340Ô¶³Ì´úÂëÖ´ÐЩ¶´ £»WinRAR ACEÎļþÈÎÒâ´úÂëÖ´ÐЩ¶´; Intel Data Center Manager SDK CVE-2019-0107ȨÏÞÌáÉý©¶´ £»Adobe Acrobat/Reader CVE-2019-7018ÈÎÒâ´úÂëÖ´ÐЩ¶´ £»Huawei Mate20 CVE-2019-5296»º³åÇøÒç³ö©¶´ ¡£

±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊǺڿͰµÍø³öÊÛµÚÈýÅúÓû§Êý¾Ý £¬Éæ¼°8¸öÍøÕ¾Ô¼9300ÍòÓû§ £»Wendy'sͬÒâΪÊý¾Ýй¶Ê¼þÖ§¸¶5000ÍòÃÀÔªºÍ½â½ð £»IxigoÔâºÚ¿ÍÈëÇÖ £¬Ô¼1800ÍòÓû§Êý¾Ýй¶ £»WinRAR´úÂëÖ´ÐЩ¶´ £¬Áè¼Ý5ÒÚÓû§Êܵ½Ó°Ïì £»Ó¡¶ÈIndane¹«Ë¾Ð¹Â¶Ô¼679ÍòAadhaar¿Í»§µÄ¸öÈËÐÅÏ¢ ¡£

ƾ¾ÝÒÔÉÏ×ÛÊö £¬±¾ÖÜÄþ¾²ÍþвΪÖÐ ¡£

ÖØÒªÄþ¾²Â©¶´Áбí


1. Drupal CVE-2019-6340Ô¶³Ì´úÂëÖ´ÐЩ¶´
DrupalÔÚͨ¹ý·Ç±í¸ñ£¨non-form resources£©ÀàÐÍÊäÈëʱδÄÜÕýÈ·¹ýÂËijЩ×ֶΠ£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬¿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë ¡£
https://www.drupal.org/sa-core-2019-003

2. WinRAR ACEÎļþÈÎÒâ´úÂëÖ´ÐЩ¶´
WinRAR UNACEV2.dll¿â´¦ÖÃ.aceÎļþ´æÔÚĿ¼´©Ô½ÎÊÌâ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÎļþÇëÇó £¬ÓÕʹÓû§½âÎö £¬¿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë ¡£
http://win-rar.com/

3. Intel Data Center Manager SDK CVE-2019-0107ȨÏÞÌáÉý©¶´
Intel Data Center Manager SDK°²×°·¨Ê½Óû§ÌáʾʵÏÖ´æÔÚÄþ¾²Â©¶´ £¬ÔÊÐíµ±µØ¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬¿ÉÌáÉýȨÏÞ ¡£
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00215.html

4. Adobe Acrobat/Reader CVE-2019-7018ÈÎÒâ´úÂëÖ´ÐЩ¶´
Adobe Acrobat/Reader´æÔÚÊͷźóʹÓ鶴 £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÎļþÇëÇó £¬ÓÕʹÓû§½âÎö £¬¿ÉʹӦÓ÷¨Ê½±ÀÀ £»òÖ´ÐÐÈÎÒâ´úÂë ¡£
https://helpx.adobe.com/security/products/acrobat/apsb19-07.html

5. Huawei Mate20 CVE-2019-5296»º³åÇøÒç³ö©¶´
Huawei Mate20´æÔÚÔ½½ç¶Á©¶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬¿ÉʹÉ豸Òì³£ ¡£
https://www.huawei.com/cn/psirt/security-advisories/huawei-sa-20190220-01-phone-cn

 ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢ºÚ¿Í°µÍø³öÊÛµÚÈýÅúÓû§Êý¾Ý £¬Éæ¼°8¸öÍøÕ¾Ô¼9300ÍòÓû§

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

GnosticplayersÔÚ°µÍøÊг¡ÉÏÐû²¼Á˵ÚÈýÅú´ýÊÛµÄÓû§ÕË»§Êý¾Ý £¬Éæ¼°µ½8¸öÍøÕ¾µÄ9276ÍòÓû§ ¡£Õâ8¸öÍøÕ¾°üÂÞ£ºLegendas.tv£¨386Íò£©¡¢Jobandtalent£¨1100Íò£©¡¢Onebip£¨260Íò£©¡¢StoryBird£¨400Íò£©¡¢StreetEasy£¨100Íò£©¡¢GfyCat£¨800Íò£©¡¢ClassPass£¨150Íò£©ºÍPizap£¨6080Íò£© ¡£ÕâÅúÓû§Êý¾ÝµÄ×ܼ۸ñΪ2.6249¸ö±ÈÌØ±Ò £¬¹²Ô¼9400ÃÀÔª ¡£

Ô­ÎÄÁ´½Ó£º
https://www.zdnet.com/article/hacker-puts-up-for-sale-third-round-of-hacked-databases-on-the-dark-web/

2¡¢Wendy'sͬÒâΪÊý¾Ýй¶Ê¼þÖ§¸¶5000ÍòÃÀÔªºÍ½â½ð

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾Ý×îб¨µÀ £¬²ÍÒû¹«Ë¾Wendy'sÒÑͬÒâΪ2015ÄêµÄÊý¾Ýй¶Ê¼þÖ§¸¶5000ÍòÃÀÔªµÄºÍ½â½ð ¡£ÔÚ¸ÃÊý¾Ýй¶Ê¼þÖÐ £¬Ô¼1800ÍòÕÅÐÅÓÿ¨¼°½è¼Ç¿¨ÐÅÏ¢Ô⵽й¶ £¬Îª´Ë½ðÈÚ»ú¹¹ÔÚ2016ÄêÌáÆðÁËËßËÏ ¡£Æ¾¾ÝÌá½»¸øÆ¥×ȱ¤Áª°î·¨ÔºµÄÒ»·ÝÎļþ £¬ÕâЩºÍ½â½ð½«Ö§¸¶¸øÔ¼7500¼ÒÒøÐкÍÐÅÓÃÉç ¡£¸Ã½»Ò×ÈÔÐèµÃµ½·¨ÔºµÄÅú×¼ ¡£

Ô­ÎÄÁ´½Ó£º
https://www.databreaches.net/update-wendys-settles-financial-firms-lawsuit-over-data-breach-for-50-mln/

3¡¢IxigoÔâºÚ¿ÍÈëÇÖ £¬Ô¼1800ÍòÓû§Êý¾Ýй¶

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÔÚÏßÂÃÓÎƽ̨IxigoµÄÔ¼1800ÍòÓû§Êý¾Ý±»µÁ £¬ÕâЩÊý¾ÝÖ÷Òª°üÂÞÓû§µÄµç×ÓÓʼþIDºÍ¹þÏ£ÃÜÂëµÈ ¡£¸Ã¹«Ë¾CEO Aloke BajpaiÌåÏָù«Ë¾²¢Î´´æ´¢Óû§µÄÖ§¸¶ÐÅÏ¢ £¬Òò´ËûÓÐÏà¹ØÐÅÏ¢±»µÁ £¬ÇҸù«Ë¾ÕýÔÚ֪ͨ²¢ÒªÇóÓû§ÖØÖÃÆäÃÜÂëºÍÄþ¾²ÁîÅÆ ¡£¸Ã¹«Ë¾·¢ÑÔÈËÌåÏÖ £¬ÆäÓû§×ÜÊýΪԼ1ÒÚ ¡£


Ô­ÎÄÁ´½Ó£º
https://timesofindia.indiatimes.com/business/india-business/emails-hashed-passwords-of-18m-ixigo-users-stolen/articleshow/68016866.cms

4¡¢WinRAR´úÂëÖ´ÐЩ¶´ £¬Áè¼Ý5ÒÚÓû§Êܵ½Ó°Ïì

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Check PointÑо¿ÍŶÓÅû¶WinRARÖеĴúÂëÖ´ÐЩ¶´ £¬¸Ã©¶´ÒÑ´æÔÚÁËÁè¼Ý19ÄêµÄʱ¼ä £¬Ó°ÏìÁËÁè¼Ý5ÒÚÓû§ ¡£¸Ã©¶´£¨CVE-2018-20250¡¢CVE-2018-20251¡¢CVE-2018-20252ºÍCVE-2018-20253£©´æÔÚÓÚWinRARµÄUNACEV2.DLL¿âÖÐ £¬Õâ¸ö¿âÂôÁ¦½âѹËõACE¸ñʽµÄѹËõÎļþ ¡£Ñо¿ÈËÔ±·¢Ïָÿâ´æÔÚ±àÂëȱÏÝ £¬¹¥»÷Õß¿ÉÀûÓöñÒâACEÎļþÔÚ½âѹËõµÄÄ¿µÄ·¾¶Ö®ÍâÖ²Èë¶ñÒâÈí¼þ ¡£WinRARÍŶÓÌåÏÖÓÉÓÚUNACEV2.DLL´Ó2005ÄêÆð¾ÍÍ£Ö¹Á˸üР£¬¿ª·¢ÈËÔ±ÒѾ­Ê§È¥Á˸ÿâÔ´´úÂëµÄ·ÃÎÊȨÏÞ £¬Òò´ËËûÃÇÑ¡Ôñ·ÅÆú¶ÔACE¸ñʽµÄÖ§³Ö ¡£WinRAR¿ª·¢ÕßÔÚ1ÔÂ28ÈÕÐû²¼ÁËWinRAR 5.70 Beta 1ÒÔÐÞ¸´´Ë©¶´ ¡£

Ô­ÎÄÁ´½Ó£º
https://research.checkpoint.com/extracting-code-execution-from-winrar/

5¡¢Ó¡¶ÈIndane¹«Ë¾Ð¹Â¶Ô¼679ÍòAadhaar¿Í»§µÄ¸öÈËÐÅÏ¢

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


·¨¹úÄþ¾²Ñо¿Ô±Baptiste RobertÔÚһλÄäÃûÓ¡¶ÈÑо¿ÈËÔ±µÄ×ÊÖúÏ £¬·¢ÏÖÓ¡¶È¹úÓÐÒº»¯Ê¯ÓÍÆø¹«Ë¾IndaneµÄ¹ÙÍøй¶ÁËÊý°ÙÍòAadhaar¿Í»§µÄ¸öÈËÐÅÏ¢ ¡£RobertÌåÏÖ £¬Ëû¿ÉÒÔÀûÓÃIndaneÒƶ¯APPÖеÄ©¶´ÕÒµ½11062¸öÓÐЧµÄ¾­ÏúÉÌID £¬¶øÇÒÀûÓÃÕâЩIDÔÚ¾­ÏúÉÌÃÅ»§ÍøÕ¾ÉÏ»ñÈ¡AadhaarÓû§µÄ¸öÈËÐÅÏ¢ £¬°üÂÞAadhaarºÅÂë¡¢ÐÕÃûºÍסַ ¡£RobertÔ¤¼ÆÊÜÓ°ÏìµÄÓû§ÊýԼΪ679Íò ¡£

Ô­ÎÄÁ´½Ó£º
https://thehackernews.com/2019/02/indane-aadhaar-leak.html

ÉùÃ÷£º±¾×ÊѶÓɶ«É­Æ½Ì¨Î¬ËûÃüÄþ¾²Ð¡×é·­ÒëºÍÕûÀí