ÐÅÏ¢Äþ¾²Öܱ¨-2019ÄêµÚ22ÖÜ

Ðû²¼Ê±¼ä 2019-06-10

±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö



2019Äê6ÔÂ03ÈÕÖÁ09ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´51¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇVimºÍNeovim OSÃüÁî×¢È멶´ £»Exim deliver_message() ´úÂëÖ´ÐЩ¶´ £» Citrix Workspace app and Receiver for WindowsÔ¶³Ì´úÂëÖ´ÐЩ¶´ £»PHP php_jpg_get16¶ÑÒç³ö©¶´ £»NETGEAR Insight post-authenticationÃüÁî×¢È멶´¡£±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇGandCrabÍ£Ö¹ÔËÓª£¬¹¥»÷ÕßÐû²¼¹Ø±ÕRaaS·þÎñ £»AMCAÔâºÚ¿ÍÈëÇÖ£¬µ¼ÖÂ1190ÍòQuest Diagnostics»¼ÕßÐÅϢй¶ £»WestpacÒøÐÐÔâºÚ¿Í¹¥»÷£¬Ô¼10ÍòÃû¿Í»§ÐÅϢй¶ £»Windows RDPÐÂ0day£¬¿É½Ù³ÖÔ¶³Ì×ÀÃæ»á»° £»AMCAÊý¾Ý鶻¹²¨¼°Ô¼770ÍòLabCorp¿Í»§¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£


ÖØÒªÄþ¾²Â©¶´Áбí



1. VimºÍNeovim OSÃüÁî×¢È멶´
VimºÍNeovim getchar.cÎļþ´æÔÚÊäÈëÑé֤©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÎļþÇëÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâOSÃüÁî¡£
https://github.com/vim/vim/commit/53575521406739cf20bbe4e384d88e7dca11f040

2. Exim deliver_message() ´úÂëÖ´ÐЩ¶´
Exim deliver_message()²»ÕýÈ·ÑéÖ¤½ÓÊÕÈëµØַ©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó£¬ÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£
https://exim.org/static/doc/security/CVE-2019-10149.txt

3. Citrix Workspace app and Receiver for WindowsÔ¶³Ì´úÂëÖ´ÐЩ¶´
Citrix Workspace app and Receiver for Windows´æÔÚÄþ¾²Â©¶´£¬ÓÉÓÚδǿÖÆÖ´Ðе±µØÇý¶¯Æ÷·ÃÎÊÊ×Ñ¡Ï¹¥»÷Õß¿ÉÒÔ¶Ô¿Í»§¶Ëµ±µØÇý¶¯Æ÷½øÐжÁ/д·ÃÎÊ£¬½ø¶øÔÚ¿Í»§¶ËÉè±¹ØÁ¬Ä´úÂëÖ´ÐС£
https://support.citrix.com/article/CTX251986

4. PHP php_jpg_get16¶ÑÒç³ö©¶´
PHP php_jpg_get16´æÔÚ¶ÑÒç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴¿ÉÌá½»ÌØÊâµÄÇëÇ󣬿ÉʹӦÓ÷¨Ê½±ÀÀ £»òÖ´ÐÐÈÎÒâ´úÂë¡£
https://bugs.php.net/bug.php?id=77988

5. NETGEAR Insight post-authenticationÃüÁî×¢È멶´
NETGEAR Insight Cloud post-authentication´æÔÚÊäÈëÑé֤©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÖ´ÐÐÈÎÒâÃüÁî¡£
https://kb.netgear.com/000060977/Security-Advisory-for-Post-Authentication-Command-Injection-on-Insight-Cloud-PSV-2018-0366


 ÖØÒªÄþ¾²Ê¼þ×ÛÊö



1¡¢GandCrabÍ£Ö¹ÔËÓª£¬¹¥»÷ÕßÐû²¼¹Ø±ÕRaaS·þÎñ

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ÀÕË÷Èí¼þGandCrabµÄ¿ª·¢ÕßÔÚºÚ¿ÍÂÛ̳ÉÏÐû²¼½«ÔÚÒ»¸öÔÂÄڹرÕÆäRaaS£¨ÀÕË÷Èí¼þ¼´·þÎñ£©ÒµÎñ£¬×Ô2018Äê1ÔÂÕýʽÍƳöÒÔÀ´£¬GandCrab RaaSÒ»Ö±ÔÚ¸ÃÂÛ̳ÉÏÐû´«×Ô¼ºµÄ·þÎñ¡£¹¥»÷ÕßÌåÏÖËûÃÇÒѾ­¿¿¸ÃÀÕË÷Èí¼þ׬ȡÁËÁè¼Ý20ÒÚÃÀÔªµÄÊê½ð£¬Òò´Ë¾ö¶¨¡°ÍËÐÝ¡±£¬µ«ÕâÒ»Êý×ÖµÄÕæʵÐÔ´æÒÉ¡£¹¥»÷Õß»¹ÌåÏÖ½«É¾³ýËùÓеĽâÃÜÃÜÔ¿£¬Ê¹µÃÊܺ¦ÕßÎÞ·¨»Ö¸´Îļþ¡£

Ô­ÎÄÁ´½Ó£º
https://www.zdnet.com/article/gandcrab-ransomware-operation-says-its-shutting-down/

2¡¢AMCAÔâºÚ¿ÍÈëÇÖ£¬µ¼ÖÂ1190ÍòQuest Diagnostics»¼ÕßÐÅϢй¶


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÃÀ¹úÕ˵¥·þÎñ¹«Ë¾AMCAÔâºÚ¿ÍÈëÇÖ£¬¸Ãʼþµ¼ÖÂѪҺ¼ì²â¹«Ë¾Quest DiagnosticsµÄ1190Íò»¼ÕßÐÅϢй¶¡£Æ¾¾ÝAMCAµÄͨ¸æ£¬¸Ãʼþ·¢ÉúÔÚ2018Äê8ÔÂ1ÈÕÖÁ2019Äê3ÔÂ30ÈÕÆڼ䣬δ¾­ÊÚȨµÄ¹¥»÷Õß·ÃÎÊÁËAMCAµÄϵͳ£¬¸Ãϵͳ°üÂÞQuest DiagnosticsµÄ»¼ÕßÐÅÏ¢¡£Ð¹Â¶µÄÐÅÏ¢°üÂÞÒøÐÐÕË»§Êý¾ÝºÍÐÅÓÿ¨ºÅµÈ²ÆÕþÐÅÏ¢ÒÔ¼°Ò½ÁÆÐÅÏ¢ºÍÉç»áÄþ¾²ºÅÂëµÈ¸öÈËÐÅÏ¢¡£QuestºÍAMCAÕýÔÚ¶Ô´Ëʼþ½øÐÐÊӲ졣

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/billing-details-for-119m-quest-diagnostics-clients-exposed/

3¡¢WestpacÒøÐÐÔâºÚ¿Í¹¥»÷£¬Ô¼10ÍòÃû¿Í»§ÐÅϢй¶

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾ÝϤÄáÏÈÇý³¿±¨µÄ±¨µÀ£¬WestpacÒøÐÐÔâµ½ºÚ¿Í¹¥»÷£¬µ¼Ö½ü10Íò°Ä´óÀûÑÇÓû§µÄ¸öÈËÐÅϢй¶¡£¹¥»÷ÕßÀ´×ÔÓÚº£Í⣬¶Ô¸ÃÒøÐеÄPayIDƽ̨½øÐÐÁË¡°Ã¶¾Ù¹¥»÷¡±¡£¾Ý³Æ¹¥»÷Õß½øÐÐÁËԼĪ60Íò´Î²éѯ£¬ÀֳɻñÈ¡ÁËÔ¼9.8Íò¿Í»§µÄÐÕÃû¡£WestpacÌåÏÖ¿Í»§µÄ²ÆÕþÐÅϢûÓÐÊܵ½Ë𺦣¬¸ÃÒøÐеÄPayIDƽֻ̨´æ´¢ÁË¿Í»§µÄÐÕÃûºÍÊÖ»úºÅÂë¡£

Ô­ÎÄÁ´½Ó£º
https://au.finance.yahoo.com/news/100-000-australians-reportedly-risk-232227017.html

4¡¢Windows RDPÐÂ0day£¬¿É½Ù³ÖÔ¶³Ì×ÀÃæ»á»°


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¿¨ÄÚ»ù÷¡CERT/CCÅû¶Windows RDP·þÎñÖеÄÒ»¸öδÐÞ¸´µÄ0day£¨CVE-2019-9510£©£¬¸Ã©¶´¿ÉÔÊÐí¹¥»÷ÕßÈƹýÔ¶³Ì×ÀÃæ»á»°ÖеÄÆÁÄ»Ëø¶¨²¢½Ù³Ö»á»°¡£¸Ã©¶´ÓëRDPµÄÍøÂçÉí·ÝÑéÖ¤NLAÓйØ£¬CERTÃèÊöµÄ¹¥»÷³¡¾°Îª£ºÓû§Ê¹ÓÃRDPÁ¬½Óµ½Windows 10 1803»òServer 2019»ò¸üеÄϵͳ£¬È»ºóËø¶¨Ô¶³Ì×ÀÃæ»á»°²¢À뿪¿Í»§¶Ë£¬´Ëʱ¹¥»÷Õß¿ÉÖжÏRDPÍøÂçÁ¬½Ó£¬Õ⽫µ¼ÖÂËü×Ô¶¯ÖØÁ¬²¢ÈƹýWindowsÆÁÄ»Ëø¶¨£¬´Ó¶ø½øÐзǷ¨·ÃÎÊ¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/remote-desktop-zero-day-bug-allows-attackers-to-hijack-sessions/

5¡¢AMCAÊý¾Ý鶻¹²¨¼°Ô¼770ÍòLabCorp¿Í»§


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


LabCorpÒ²Êܵ½µÚÈý·½¹©Ó¦ÉÌAMCAÊý¾Ýй¶Ê¼þµÄÓ°Ï죬Լ770Íò¿Í»§ÐÅϢй¶¡£Ð¹Â¶µÄÐÅÏ¢°üÂÞÐÕÃû¡¢³öÉúÈÕÆÚ¡¢µØÖ·¡¢µç»°ºÅÂë¡¢·þÎñÈÕÆÚÒÔ¼°ÐÅÓÿ¨ºÍÒøÐÐÐÅÏ¢µÈ¡£¸Ãʼþ·¢ÉúÔÚ2018Äê8ÔÂ1ÈÕÖÁ2019Äê3ÔÂ30ÈÕÖ®¼ä£¬´ËÇ°Íâý±¨µÀQuest DiagnosticsµÄ¿Í»§ÐÅÏ¢ÔÚ¸ÃʼþÖÐй¶¡£LabCorpÌåÏÖ¿Í»§µÄÉç»áÄþ¾²ºÅÂ벢δй¶£¬´ËÍâ¿Í»§µÄ¼ì²â½á¹û¡¢Ò½ÁÆÕï¶ÏÐÅϢҲδй¶¡£

Ô­ÎÄÁ´½Ó£º
https://cyware.com/news/around-77-million-labcorp-customers-impacted-from-amca-data-breach-c3edd754