ÐÅÏ¢Äþ¾²Öܱ¨-2019ÄêµÚ24ÖÜ

Ðû²¼Ê±¼ä 2019-06-24

±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö



2019Äê6ÔÂ17ÈÕÖÁ23ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´43¸ö  £¬ÖµµÃ¹Ø×¢µÄÊÇISC BIND¾ºÕùÌõ¼þ¾Ü¾ø·þÎñ©¶´£»Oracle Fusion Middleware WebLogic Server×é¼þÔ¶³Ì´úÂëÖ´ÐЩ¶´£» Apache AXIS freemaker´úÂëÖ´ÐЩ¶´£»Webmin update.cgiÈÎÒâÃüÁîÖ´ÐЩ¶´£»TP-Link TL-WR1043NDδÊÚȨ·ÃÎÊ©¶´¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇÃÀ¹ÙÔ±ÈÏ¿ÉÏò¶íÂÞ˹µçÍøÖ²È벡¶¾  £¬ÌØÀÊÆÕÅ­í¡ÃÀýÅѹú£»AMCAÊý¾Ýй¶²¨¼°ÈËÊýÁè¼Ý2000Íò  £¬5¼Ò¹«Ë¾ÊÜÓ°Ï죻EquifaxÊý¾Ýй¶ӰÏìÃÀ¹ú¶à¸öÕþ¸®»ú¹¹µÄÉí·ÝÑéÖ¤Á÷³Ì£»Firefox½ô¼±ÐÞ¸´RCE 0day£¨CVE-2019-11707£©£»¼ÓÄôó½ðÈÚ»ú¹¹Desjardinsй¶Լ290Íò»áÔ±µÄÃô¸ÐÐÅÏ¢¡£


ƾ¾ÝÒÔÉÏ×ÛÊö  £¬±¾ÖÜÄþ¾²ÍþвΪÖС£


ÖØÒªÄþ¾²Â©¶´Áбí



1. ISC BIND¾ºÕùÌõ¼þ¾Ü¾ø·þÎñ©¶´
ISC BIND´¦ÖýøÐб¨ÎÄʱ´æÔÚ¾ºÕùÌõ¼þÄþ¾²Â©¶´  £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó  £¬¿É½øÐоܾø·þÎñ¹¥»÷¡£
https://kb.isc.org/docs/cve-2019-6471

2. Oracle Fusion Middleware WebLogic Server×é¼þÔ¶³Ì´úÂëÖ´ÐЩ¶´
Oracle Fusion Middleware WebLogic Server×é¼þXMLDecoder´æÔÚ·´ÐòÁл¯Â©¶´  £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó  £¬¿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£
https://www.oracle.com/technetwork/security-advisory/alert-cve-2019-2729-5570780.html

3. Apache AXIS freemaker´úÂëÖ´ÐЩ¶´
Apache AXIS freemaker×é¼þÖе÷ÓÃtemplate.utility.ExecuteÀà´æÔÚÄþ¾²Â©¶´  £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄHTTP POSTÇëÇó  £¬¿ÉÖ´ÐÐÈÎÒâ´úÂë¡£
http://axis.apache.org/

4. Webmin update.cgiÈÎÒâÃüÁîÖ´ÐЩ¶´
Webmin update.cgi´¦Öá®data¡¯²ÎÊý´æÔÚÄþ¾²Â©¶´  £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó  £¬¿ÉÒÔrootȨÏÞÖ´ÐÐÈÎÒâÃüÁî¡£
https://pentest.com.tr/exploits/Webmin-1910-Package-Updates-Remote-Command-Execution.html

5. TP-Link TL-WR1043NDδÊÚȨ·ÃÎÊ©¶´
TP-Link TL-WR1043ND´¦Öà ¡°Authorization¡±´æÔÚÄþ¾²Â©¶´  £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó  £¬¿ÉδÊÚȨ¿ØÖÆÉ豸¡£
https://github.com/MalFuzzer/Vulnerability-Research/blob/master/TL-WR1043ND%20V2%20-%20TP-LINK/TL-WR1043ND_PoC.pdf


ÖØÒªÄþ¾²Ê¼þ×ÛÊö



1¡¢ÃÀ¹ÙÔ±ÈÏ¿ÉÏò¶íÂÞ˹µçÍøÖ²È벡¶¾  £¬ÌØÀÊÆÕÅ­í¡ÃÀýÅѹú


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

µ±µØʱ¼ä6ÔÂ15ÈÕ  £¬¡¶Å¦Ô¼Ê±±¨¡·Ô®ÒýÃÀ¹úÏÖÈκÍÇ°ÈÎÕþ¸®¹ÙÔ±µÄ»°³Æ  £¬ÃÀ¹úÕýÔÚ¼Ó´ó¶Ô¶íÂÞ˹µçÍøµÄÍøÂç¹¥»÷  £¬¡°ÖÁÉÙ´Ó2012Ä꿪ʼ  £¬ÃÀ¹úÒѽ«Õì²é̽²âÆ÷ÖÃÈë¶íÂÞ˹µçÍøµÄ¿ØÖÆϵͳ¡£¡±ÉÏÊö¹ÙÔ±ÌåÏÖ  £¬Èç½ñÃÀ¹úµÄÕ½ÂÔÒѾ­¸ü¶àµØתÏò½ø¹¥  £¬²¢ÒÔ¡°Ç°ËùδÓС±µÄÉî¶È½«Ç±ÔڵĶñÒâÈí¼þ°²ÖÃÓÚ¶íÂÞ˹ϵͳÄÚ¡£ÃÀ¹úÕþÒª²¢Î´¾Í±¨µÀ×÷³ö»ØÓ¦  £¬µ«¿´Í걨µÀµÄÌØÀÊÆÕÈ´Ê®·ÖÄÕÅ­  £¬ËûËæ¼´ÔÚÍÆÌØÉÏ·¢ÍÆÎÄ»Øí¡  £¬³Æ¡¶Å¦Ô¼Ê±±¨¡·µÄ±¨µÀÊÇ¼ÙµÄ  £¬²¢³ÆÆä×ö·¨¡°¼òÖ±ÊÇÅѹúÐо¶  £¬ÊÇÈËÃñµÄµÐÈË£¡¡±¡£

Ô­ÎÄÁ´½Ó£º
https://www.nytimes.com/2019/06/15/us/politics/trump-cyber-russia-grid.html

2¡¢AMCAÊý¾Ýй¶²¨¼°ÈËÊýÁè¼Ý2000Íò  £¬5¼Ò¹«Ë¾ÊÜÓ°Ïì


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÃÀ¹úÒ½ÁÆÆóÒµÕ˵¥·þÎñÉÌAMCAµÄÊý¾Ýй¶Ê¼þÏÖÒѲ¨¼°Áè¼Ý2000Íò»¼Õß¡£Ð¹Â¶µÄÊý¾ÝÊôÓÚÃÀ¹ú¸÷¸öÁÙ´²ºÍѪҺ¼ì²âʵÑéÊҵĻ¼Õß  £¬°üÂÞËûÃǵÄÐÕÃû¡¢¼Òͥסַ¡¢µç»°ºÅÂë¡¢³öÉúÈÕÆÚ¡¢Éç»áÄþ¾²ºÅÂë¡¢Ö§¸¶¿¨ÏêϸÐÅÏ¢ºÍÒøÐÐÕË»§ÐÅÏ¢µÈ¡£ÊÜÓ°ÏìµÄʵÑéÊÒ°üÂÞQuest Diagnostics£¨²¨¼°1190Íò»¼Õߣ©¡¢LabCorp£¨770Íò»¼Õߣ©¡¢BioReferenceʵÑéÊÒ£¨Opko Health×Ó¹«Ë¾  £¬422600Ãû»¼Õߣ©¡¢Carecentrix£¨50ÍòÃû»¼Õߣ©ºÍSunrise Laboratories£¨Î´¹ûÈ»»¼ÕßÊý£©¡£

Ô­ÎÄÁ´½Ó£º
https://www.zdnet.com/article/amca-data-breach-has-now-gone-over-the-20-million-mark/

3¡¢EquifaxÊý¾Ýй¶ӰÏìÃÀ¹ú¶à¸öÕþ¸®»ú¹¹µÄÉí·ÝÑéÖ¤Á÷³Ì


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÃÀ¹úÕþ¸®ÎÊÔð°ì¹«ÊÒ£¨GAO£©µÄгÂËßÖ¸³ö  £¬2017ÄêEquifaxµÄÊý¾Ýй¶Ê¼þÓ°ÏìÁ˶à¸öÕþ¸®»ú¹¹µÄÔÚÏßÉí·ÝÑéÖ¤Á÷³Ì¡£ÊÜÓ°ÏìµÄ»ú¹¹°üÂÞÒ½ÁƱ£ÏÕºÍÒ½ÁƲ¹Öú·þÎñÖÐÐÄ£¨CMS£©¡¢Éç»á±£ÕϹÜÀí¾Ö£¨SSA£©¡¢ÃÀ¹úÓÊÕþ·þÎñ£¨USPS£©ºÍÍËÎé¾üÈËÊÂÎñ²¿£¨VA£©¡£ÃÀ¹ú¹«ÃñÔÚÕâЩÕþ¸®»ú¹¹¹ÙÍøÉêÇ븣Àûʱ  £¬ÒÀÀµÓÚEquifaxµÈÐÅÓóÂËß»ú¹¹£¨CRA£©ÌṩµÄÊý¾Ý×÷ΪÉêÇëÈËÉí·ÝµÄÖ¤Ã÷  £¬ÓÉÓÚºÚ¿ÍÒ²ÓµÓÐÕâЩÊý¾Ý  £¬Ê¹µÃÕâÒ»¹ý³Ì²»ÔÙ¿ÉÐÅ¡£2017ÄêÃÀ¹ú¹ú¼Ò³ß¶ÈÓë¼¼ÊõÑо¿Ôº£¨NIST£©½¨ÒéÓÃÆäËû½â¾ö·½°¸Ìæ»»»ùÓÚCRAµÄÔÚÏßÉí·ÝÖ¤Ã÷  £¬µ«GAO·¢ÏÖÉÏÊö»ú¹¹ÈÔÔÚʹÓþɵÄCRAÊý¾Ý¿â½øÐÐÔÚÏßÉí·Ýʶ±ðÑéÖ¤¡£

Ô­ÎÄÁ´½Ó£º
https://www.zdnet.com/article/equifax-breach-impacted-the-online-id-verification-process-at-many-us-govt-agencies/

4¡¢Firefox½ô¼±ÐÞ¸´RCE 0day£¨CVE-2019-11707£©


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


MozillaÐû²¼Firefox 67.0.3ºÍFirefox ESR 60.7.1  £¬ÓÃÓÚ½ô¼±ÐÞ¸´¿Éµ¼ÖÂRCEµÄ0day£¨CVE-2019-11707£©¡£¸Ã©¶´ÓÉGoogle Project ZeroÍŶӷ¢ÏÖ²¢³ÂËß  £¬ÊÇÒ»¸öÀàÐÍ»ìÏý©¶´  £¬Â©¶´±íÊöΪ£ºÓÉÓÚArray.popÖеÄÎÊÌâ  £¬²Ù×÷JavaScript¹¤¾ßʱ¿ÉÄܻᴥ·¢Â©¶´  £¬µ¼Ö¿ÉÀûÓõÄÍ߽⡣¸Ã©¶´ÒÑÔÚÒ°Íâ±»ÀûÓà  £¬½¨ÒéÓû§¾¡¿ì¸üС£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/mozilla-firefox-6703-patches-actively-exploited-zero-day/

5¡¢¼ÓÄôó½ðÈÚ»ú¹¹Desjardinsй¶Լ290Íò»áÔ±µÄÃô¸ÐÐÅÏ¢


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


DesjardinsÊDZ±ÃÀµØÓò×î´óµÄÐÅÓÃÉç  £¬Ò²ÊǼÓÄôó×î´óµÄºÏ×÷½ðÈÚ¼¯ÍÅ¡£Æ¾¾Ý¸Ã¹«Ë¾µÄÐÂΟå  £¬Ô¼290Íò»áÔ±µÄÃô¸ÐÐÅÏ¢ÔÚÔ±¹¤Î´¾­ÊÚȨÏò¹«Ë¾ÍⲿÈËÔ±Åû¶ºóй¶  £¬ÆäÖаüÂÞ270ÍòÃû¸öÈË»áÔ±ºÍ17.3ÍòÆóÒµ»áÔ±¡£DesjardinsÓÚ2019Äê6ÔÂ14ÈÕ·¢ÏÖй¶Ê¼þ  £¬Ð¹Â¶µÄÐÅÏ¢°üÂÞ¸öÈË»áÔ±µÄÐÕÃû¡¢³öÉúÈÕÆÚ¡¢Éç»á±£ÏÕºÅÂë¡¢µØÖ·¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØÖ·ÒÔ¼°ÒøÐкÍDesjardins²úÎïµÄÏêϸÐÅÏ¢£»ÆóÒµ»áÔ±µÄ¹«Ë¾Ãû³Æ¡¢µØÖ·¡¢µç»°ºÅÂë¡¢ËùÓÐÕßÐÕÃûºÍAcc¨¨sDAffairesÕÊ»§Ãû³ÆÒÔ¼°ÓëAcc¨¨sDAffairesÕÊ»§Ïà¹ØµÄһЩ¸öÈËÐÅÏ¢¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/desjardins-group-data-leak-exposes-info-of-29-million-members/