ÐÅÏ¢Äþ¾²Öܱ¨-2019ÄêµÚ19ÖÜ

Ðû²¼Ê±¼ä 2019-05-13

±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö



2019Äê5ÔÂ6ÈÕÖÁ12ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´44¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇAlpine Linux Docker CVE-2019-5021Ó²±àÂëƾ֤ÑéÖ¤Èƹý©¶´£»NGINX njs¶Ñ»º³åÇøÒç³ö©¶´; Hisilicon HI3516 hisilicon streaming server CVE-2019-11560»º³åÇøÒç³ö©¶´£»Android libpacÀàÐÍ»ìÏý´úÂëÖ´ÐЩ¶´£»CyberArk Software Enterprise Password Vault XXE×¢È멶´¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇÃÀ¹úÄÜÔ´²¿Ðû²¼2019ÄêQ1µçÁ¦ÍøÂç½ô¼±Çé¿öºÍ×ÌÈųÂËߣ»Watertown Daily TimesÔâµ½ÀÕË÷Èí¼þRyuk¹¥»÷£»AIHS¹«Ë¾²¿ÃÅ»¼Õß¼°¹©Ó¦É̵ÄÃô¸ÐÐÅϢй¶£»VerizonÐû²¼2019ÄêÊý¾Ýй¶ÊÓ²ì³ÂËߣ»Freedom MobileÒâÍâй¶½ü500ÍòÌõÓû§¼Ç¼¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£


ÖØÒªÄþ¾²Â©¶´Áбí



1. Alpine Linux Docker CVE-2019-5021Ó²±àÂëƾ֤ÑéÖ¤Èƹý©¶´
Alpine Linux Docker´æÔÚµÄrootÃÜÂëΪNULL£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó£¬Î´ÊÚȨÌáȨ·ÃÎÊ¡£
https://www.alpinelinux.org/posts/Docker-image-vulnerability-CVE-2019-5021.html

2. NGINX njs¶Ñ»º³åÇøÒç³ö©¶´
NGINX njs Array.prototype.push´æÔÚ¶ÑÒç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐÈÎÒâ´úÂë¡£
https://github.com/nginx/njs/commit/b0f23dbc4d4713f65470272768ef79b7cb47db78

3. Hisilicon HI3516 hisilicon streaming server CVE-2019-11560»º³åÇøÒç³ö©¶´
Hisilicon HI3516 hisilicon streaming server´æÔÚ»º³åÇøÒç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐÈÎÒâ´úÂë¡£
https://gist.github.com/vulnfan1337/e95c2dba75ad93a1a325c6ace950eba9

4. Android libpacÀàÐÍ»ìÏý´úÂëÖ´ÐЩ¶´
Android libpac´æÔÚÀàÐÍ»ìÏý©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄPACÎļþÇëÇ󣬿Éʹϵͳ±ÀÀ£»òÖ´ÐÐÈÎÒâ´úÂë¡£
https://source.android.com/security/bulletin/2019-05-01

5. CyberArk Software Enterprise Password Vault XXE×¢È멶´
CyberArk Software Enterprise Password Vault Password Vault Web Access (PVWA) ´æÔÚXMLÍⲿʵÌå×¢È멶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ɻñÈ¡Ãô¸ÐÐÅÏ¢£¬»òÈƹýÑéÖ¤¡£
https://www.octority.com/2019/05/07/cyberark-enterprise-password-vault-xml-external-entity-xxe-injection/


 ÖØÒªÄþ¾²Ê¼þ×ÛÊö



1¡¢ÃÀ¹úÄÜÔ´²¿Ðû²¼2019ÄêQ1µçÁ¦ÍøÂç½ô¼±Çé¿öºÍ×ÌÈųÂËß

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ƾ¾ÝÃÀ¹úÄÜÔ´²¿Ðû²¼µÄ2019ÄêµÚÒ»¼¾¶ÈµçÁ¦ÍøÂç½ô¼±Çé¿öºÍ×ÌÈųÂËߣ¬3ÔÂ5ÈÕÉÏÎç9:12µ½ÏÂÎç6:57Æڼ䱱ÃÀµçÍøÔâÓöµ½Ò»¸ö¡°µ¼ÖµçÁ¦ÏµÍ³ÔËÓªÖжϵÄÍøÂçʼþ¡±£¬ÊÜÓ°ÏìµÄµØÓò°üÂÞ¼ÓÖݵĿ˶÷ÏغÍÂåɼí¶ÏØ¡¢ÓÌËûÖݵÄÑκþÏغͻ³¶íÃ÷ÖݵĿµ¸¥Ë¹ÏØ¡£Æ¾¾ÝÃÀ¹úÄÜÔ´²¿µÄ½ç˵£¬¡°ÍøÂçʼþ¡±ÊÇÖ¸¡°Î´ÊÚȨ·ÃÎÊ¡±µ¼ÖµÄÍøÂçÖжÏ£¬µ«Ã»Óиü¶àÐÅÏ¢±íÃ÷¸ÃʼþÊÇÔ¶³ÌºÚ¿Í¹¥»÷»¹ÊÇÆóÒµÄÚ²¿µÄ¹¥»÷¡£´ÓÀúÊ·ÉÏ¿´£¬±±ÃÀµçÍø´ÓδÔâµ½ÍøÂç¹¥»÷µ¼ÖµÄÆÆ»µ»òÖжÏ£¬Èç¹ûÊÂÇéÊôʵ£¬Õâһʼþ¿ÉÄܳÉΪÀúÊ·ÐÔµÄʼþ¡£

Ô­ÎÄÁ´½Ó£º
https://blog.avast.com/western-us-power-grid-hit-by-cyber-event

2¡¢Watertown Daily TimesÔâµ½ÀÕË÷Èí¼þRyuk¹¥»÷

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ô¼º²Ñ·±¨Òµ¹«Ë¾Ôâµ½ÀÕË÷Èí¼þRyuk¹¥»÷£¬ÆäÄÚ²¿ÓÃÓÚÔÚWatertown¡¢HudsonºÍMassenaÉú²ú±¨Ö½µÄÄÚÈݹ²Ïí·þÎñÆ÷Êܵ½Ñ¬È¾£¬°üÂÞµç×ÓÓʼþ·þÎñÆ÷ºÍÁªÍøµç»°¡£Watertown Daily TimesÔÚ4ÔÂ27ÈÕÔâµ½µÚÒ»´Î¹¥»÷£¬²¢ÔÚ5ÔÂ2ÈÕÔٴμì²âµ½Ñ¬È¾¡£Ä¿Ç°»¹²»Çå³þÕâÊÇÁ½´Î¹¥»÷»¹ÊǵÚÒ»´Î¹¥»÷µÄÑÓÐø¡£¸Ã¹«Ë¾ÕýÔÚÓëÍøÂçÄþ¾²×¨¼ÒºÏ×÷ÒÔÈ·¶¨Ñ¬È¾µÄ»ù´¡Ô­Òò²¢É¾³ýÀÕË÷Èí¼þ¡£

Ô­ÎÄÁ´½Ó£º
https://cyware.com/news/watertown-daily-times-again-gets-hit-with-ryuk-ransomware-attack-36f62397

3¡¢AIHS¹«Ë¾²¿ÃÅ»¼Õß¼°¹©Ó¦É̵ÄÃô¸ÐÐÅϢй¶

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÃÀ¹úÓ¡¶È½¡¿µÓë·þÎñ¹«Ë¾£¨AIHS£©·¢ÉúÊý¾Ýй¶Ê¼þ£¬Æ¾¾Ý¸Ã¹«Ë¾Ðû²¼µÄ֪ͨ£¬Ò»ÃûÇ°¹ÍÔ±ÔÚÈÎÖ°Æڼ佫²¿ÃÅAIHSµç×ÓÓʼþת·¢µ½Æä¸öÈËÓÊÏ䣬µ¼Ö²¿ÃÅ»¼Õß¡¢Ô±¹¤¼°¹©Ó¦É̵ÄÃô¸ÐÐÅϢй¶¡£ÊÜËðµÄ»¼ÕßÐÅÏ¢°üÂÞÐÕÃû¡¢Õ˵¥Ã÷ϸ¡¢Ò½ÁƱ£ÏÕÊý¾Ý¡¢½ÓÊÜAIHS·þÎñµÄÈÕÆÚ¼°Ö§¸¶½ð¶îµÈ£¬Ä¿Ç°Éв»Çå³þÊÇ·ñÓл¼ÕßÊý¾Ý±»ÀÄÓá£Õâһʼþ·¢ÉúÔÚ2ÔÂ26ÈÕÖÁ3ÔÂ6ÈÕÆڼ䡣AIHS½«ÎªÊÜÓ°ÏìµÄ»¼ÕßÌṩ12¸öÔµÄÉí·Ý͵ÇÔ±£»¤·þÎñ¡£

Ô­ÎÄÁ´½Ó£º
https://cyware.com/news/aihs-reports-data-breach-involving-information-related-to-employees-patients-and-vendors-f823c1cd

4¡¢VerizonÐû²¼2019ÄêÊý¾Ýй¶ÊÓ²ì³ÂËß


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


VerizonÐû²¼2019ÄêÊý¾Ýй¶ÊÓ²ì³ÂËߣ¨DBIR£©£¬¸Ã³ÂËß·ÖÎöÁË86¸ö¹ú¼Ò·¢ÉúµÄ41000¶àÆðÍøÂçÄþ¾²Ê¼þºÍ2000¶àÆðÊý¾Ýй¶Ê¼þ¡£¸Ã³ÂËßÖ¸³ö£¬´Ó2018Ä꿪ʼÔÆ´æ´¢ÅäÖôíÎó¡¢BECºÍ֪ʶ²úȨ͵ÇÔ¶¼´¦ÓÚÉÏÉýÇ÷ÊÆ¡£ÒÔÉÌÒµ¼äµý»î¶¯Îª¶¯»úµÄÍøÂç¹¥»÷ÓÐËùÔö³¤£¬ÔÚ¹ýÈ¥µÄ12¸öÔÂÀÓÐ1/4µÄÍøÂçÈëÇÖÓëÕì²ìºÍÊý¾ÝÉø©ÓйØ¡£×ÜÌå¶øÑÔ´ó¶àÊýÍøÂç¹¥»÷¶¼ÊÇÒÔ¾­¼ÃÀûÒæ×÷ΪÇý¶¯¡£²»ÐÒµÄÊÇ£¬ÓÐÒ»°ëµÄÆóÒµÐèÒª»¨·ÑÊýÔÂÉõÖÁ¸ü³¤µÄʱ¼äÀ´·¢ÏÖÈëÇÖÐÐΪ¡£

Ô­ÎÄÁ´½Ó£º
https://enterprise.verizon.com/resources/reports/2019-data-breach-investigations-report.pdf

5¡¢Freedom MobileÒâÍâй¶½ü500ÍòÌõÓû§¼Ç¼


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¼ÓÄôóµçÐŹ«Ë¾Freedom MobileµÄÒ»¸ö°üÂÞ¿Í»§Êý¾ÝµÄElasticSearchÊý¾Ý¿âÒòÅäÖôíÎóÔÚÍøÉÏ̻¶£¬µ¼Ö½ü500ÍòÌõ¿Í»§¼Ç¼й¶¡£Æ¾¾ÝÄþ¾²Ñо¿Ô±Noam RotemºÍRan LocarµÄ·¢ÏÖ£¬¸ÃÊý¾Ý¿âÊôÓÚFreedom MobileµÄµÚÈý·½·þÎñÌṩÉÌApptium¡£¸Ã¹«Ë¾·¢ÑÔÈËÌåÏÖ£¬Ð¹Â¶Ê¼þÓ°ÏìÁË3ÔÂ25ÈÕÖÁ4ÔÂ15ÈÕÆÚ¼äÔÚ17¸öFreedom MobileÓªÒµÌü¿ªÉè»ò¸ü¸ÄÕË»§µÄÓû§£¬Ô¼ÓÐ1.5ÍòÓû§Êܵ½Ó°Ï졣鶵ÄÐÅÏ¢²»½ö°üÂÞÓû§µÄÐÕÃû¡¢ÓÊÏäµÈ¸öÈËÐÅÏ¢£¬»¹°üÂÞÐÅÓÿ¨ºÅµÈÖ§¸¶ÐÅÏ¢¡£

Ô­ÎÄÁ´½Ó£º
https://cyware.com/news/freedom-mobile-exposed-almost-5-million-customer-records-due-to-a-misconfigured-database-fddd4855