ÐÅÏ¢Äþ¾²Öܱ¨-2019ÄêµÚ25ÖÜ

Ðû²¼Ê±¼ä 2019-07-01

±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö



2019Äê6ÔÂ24ÈÕÖÁ30ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´47¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇActiontec WEB6000Q rootȨÏÞ·ÃÎÊ©¶´£»ÖÂÔ¶OAÎļþÉÏ´«´úÂëÖ´ÐЩ¶´£»Couchbase Sync GatewayÈÎÒâ´úÂëÖ´ÐЩ¶´£»Cesanta Mongoose ¡®parse_mqtt()¡¯º¯Êý»º³åÇøÒç³ö©¶´£»ABB PB610 IDAL HTTP serverÄþ¾²Èƹý´úÂëÖ´ÐЩ¶´¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇmacOSË«ÖØÊÍ·Å©¶´£¬¿Éµ¼ÖÂÌáȨ¼°´úÂëÖ´ÐУ»ÃÀý֤ʵÃÀ¶ÔÒÁÀʵ¼µ¯¿ØÖÆϵͳÌᳫÍøÂç¹¥»÷£»IBM WebSphereÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2019-4279£©£»BGP·ÓÉй©µ¼ÖÂCloudflareºÍAmazon AWSÍøÂçÖжÏ£»FireEyeÐû²¼Q1 µç×ÓÓʼþÍþв³ÂËߣ¬µöÓã¹¥»÷Ôö³¤17%¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£


ÖØÒªÄþ¾²Â©¶´Áбí



1. Actiontec WEB6000Q rootȨÏÞ·ÃÎÊ©¶´
Actiontec WEB6000Q Quantenna WiFi Controller´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄtelnetÇëÇ󣬿ÉÒÔROOTȨÏÞ·ÃÎÊ¡£
http://seclists.org/fulldisclosure/2019/Jun/2

2. ÖÂÔ¶OAÎļþÉÏ´«´úÂëÖ´ÐЩ¶´
ÖÂÔ¶OAÉÏ´«Îļþ¹¦Ð§´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÌá½»¶ñÒâÎļþ²¢Ö´ÐÐÈÎÒâ´úÂë¡£
http://www.seeyon.com/

3. Couchbase Sync GatewayÈÎÒâ´úÂëÖ´ÐЩ¶´
Couchbase Sync Gateway REST API´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿É×¢ÈëÆäËûN1QLÓï¾ä¡£
https://docs.couchbase.com/sync-gateway/2.5/release-notes.html

4. Cesanta Mongoose ¡®parse_mqtt()¡¯º¯Êý»º³åÇøÒç³ö©¶´
Cesanta Mongoose mg_mqtt.c ¡®parse_mqtt()¡¯º¯Êý´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐÈÎÒâ´úÂë¡£
https://github.com/cesanta/mongoose/releases/tag/6.15

5. ABB PB610 IDAL HTTP serverÄþ¾²Èƹý´úÂëÖ´ÐЩ¶´
ABB PB610 IDAL HTTP server´æÔÚÄÚ´æÆÆ»µÂ©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÈƹýÄþ¾²ÏÞÖÆÖ´ÐÐÈÎÒâ´úÂë¡£
https://library.e.abb.com/public/b0021d2ab9ba4e3ab14d7c2796f5908e/ABB-Advisory_3ADR010377_2.pdf


ÖØÒªÄþ¾²Ê¼þ×ÛÊö



1¡¢macOSË«ÖØÊÍ·Å©¶´£¬¿Éµ¼ÖÂÌáȨ¼°´úÂëÖ´ÐÐ

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

Ç÷ÊƿƼ¼Ñо¿ÈËÔ±ÔÚmacOSÖз¢ÏÖÒ»¸öË«ÖØÊÍ·Å©¶´£¨CVE-2019-8635£©¡£¸Ã©¶´ÊÇÓÉAMD×é¼þÖеÄÄÚ´æËð»µÎÊÌâÒýÆðµÄ£¬Èç¹ûÀÖ³ÉÀûÓ㬹¥»÷Õß¿ÉÌáȨÖÁrootȨÏÞ²¢ÔÚϵͳÉÏÖ´ÐжñÒâ´úÂë¡£¸ÃCVE IDº­¸ÇÁ½¸öË«ÖØÊÍ·Å©¶´£¬µÚÒ»¸ö´æÔÚÓÚAMDRadeonX4000_AMDSIGLContextÀàµÄdiscard_StretchTex2TexÒªÁìÖУ¬µÚ¶þ¸öÊǸÃÀàµÄprocess_StretchTex2TexÒªÁì¡£AppleÔÚmacOS Mojave 10.14.4¸üÐÂÖÐÐÞ¸´Á˸鶴¡£

Ô­ÎÄÁ´½Ó£º
https://blog.trendmicro.com/trendlabs-security-intelligence/cve-2019-8635-double-free-vulnerability-in-apple-macos-lets-attackers-escalate-system-privileges-and-execute-arbitrary-code/

2¡¢ÃÀý֤ʵÃÀ¶ÔÒÁÀʵ¼µ¯¿ØÖÆϵͳÌᳫÍøÂç¹¥»÷


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾ÝÖÜÈÕÃÀÁªÉçµÄ±¨µÀ£¬ÃÀ¹úÍøÂç˾ÁÔÚ×ÜͳÌØÀÊÆÕµÄÖ±½ÓÅú׼϶ÔÒÁÀʵľüÊÂITϵͳ·¢¶¯ÁËÍøÂç¹¥»÷¡£ÃÀÁªÉçÔ®ÒýÁËÁ½ÃûÄÚ²¿ÏûÏ¢À´Ô´²¢Í¨¹ýµÚÈýλÎå½Ç´óÂ¥¹ÙÔ±¶ÔÕâÒ»ÏûÏ¢½øÐÐÁËÈ·ÈÏ¡£ÃÀ¹úÍøÂç˾ÁÕë¶ÔµÄÊÇÒÁÀʾü·½ÓÃÀ´¿ØÖƵ¼µ¯·¢ÉäÆ÷µÄ¼ÆËã»úϵͳ¡£¡¶Å¦Ô¼Ê±±¨¡·µÄ±¨µÀÏÔʾ£¬ÕâЩ¹¥»÷ÔçÔÚ¼¸ÖÜÇ°¾ÍÓÐÁ˼ƻ®£¬ÒâÔÚ»ØÓ¦Õë¶ÔÓÍÂֵĹ¥»÷ÒÔ¼°×î½üÒ»¼ÜÃÀ¹úÎÞÈË»ú±»»÷ÂäµÄʼþ¡£

Ô­ÎÄÁ´½Ó£º
https://www.zdnet.com/article/us-launches-cyber-attack-aimed-at-iranian-rocket-and-missile-systems/

3¡¢IBM WebSphereÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2019-4279£©


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


IBMÐÞ¸´WebSphere Application ServerÖеÄÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2019-4279£©£¬¹¥»÷Õß¿Éͨ¹ý·¢Ë;«ÐĽṹµÄÐòÁл¯¹¤¾ß´¥·¢¸Ã©¶´£¬×îÖÕµ¼ÖÂÔÚ·þÎñÆ÷ÉÏÖ´ÐÐÈÎÒâ´úÂë¡£ÊÜÓ°ÏìµÄ²úÎï°üÂÞWebSphere Application Server ND°æ±¾9.0ºÍ°æ±¾8.5¡¢WebSphere Virtual Enterprise V7.0¡£ÓÉÓÚ½üÈո鶴µÄ¹¥»÷·½Ê½ÒÑÔÚÒ°ÍâÁ÷´«£¬½¨ÒéÓû§¼°Ê±½øÐзÀ»¤¡£

Ô­ÎÄÁ´½Ó£º
https://www-01.ibm.com/support/docview.wss?uid=ibm10883628

4¡¢BGP·ÓÉй©µ¼ÖÂCloudflareºÍAmazon AWSÍøÂçÖжÏ

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


6ÔÂ24ÈÕÓÉÓÚVerizon´íÎóµØת·¢ÁËBGP·Óɹ㲥£¬µ¼ÖÂÍøÂçÁ÷Á¿±»´íÎóµØµ¼ÏòVerizon£¬Ê¹µÃCloudflare¡¢Amazon AWSºÍFacebookµÈ¹«Ë¾µÄ·þÎñÎÞ·¨·ÃÎÊ¡£Ê¼þµÄÆðÒòÊDZöϦ·¨ÄáÑÇÖݵÄÒ»¼ÒСÐÍISP AS33154-DQE CommunicationsʹÓÃNoctionµÄBGPÓÅ»¯Æ÷ÓÅ»¯ÆäÄÚ²¿ÍøÂçµÄ·ÓÉ£¬µ«ÓÉÓÚ´íÎóÅäÖÃÕâЩ·ÓÉÐÅÏ¢±»´íÎóµØ·¢¸øÁËVerizon£¬×îÖÕµ¼Ö´ó·¶Î§µÄÍøÂçÖжÏ¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/technology/bgp-route-leak-causes-cloudflare-and-amazon-aws-problems/

5¡¢FireEyeÐû²¼Q1 µç×ÓÓʼþÍþв³ÂËߣ¬µöÓã¹¥»÷Ôö³¤17%

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾Ý±¾ÖܶþFireEyeÐû²¼µÄ2019ÄêµÚÒ»¼¾¶Èµç×ÓÓʼþÍþв³ÂËߣ¬Ê¹ÓÃHTTPSµÄ¶ñÒâURL±ÈÀýÔö³¤ÁË26%£¬¶ø´«Í³µÄ¸½¼þΪ¶ñÒâÈí¼þµÄµç×ÓÓʼþÔÚÎȲ½Ï½µ¡£»ùÓÚ¶Ô13ÒÚ·âµç×ÓÓʼþµÄ·ÖÎö£¬¸Ã³ÂËßÖ¸³ö2019ÄêµÚÒ»¼¾¶ÈµÄÍøÂçµöÓã¹¥»÷±ÈÉÏÒ»¼¾¶ÈÔö³¤ÁË17%£¬×ܹ²Óнü30%µÄ¹¥»÷ÊÇÄ£·ÂMicrosoft¡¢OneDrive¡¢Apple¡¢AmazonºÍPayPalµÈÖªÃûÆ·ÅÆ¡£´ËÍ⣬Îļþ¹²Ïí·þÎñÔÚÕë¶ÔÆóÒµµÄÍøÂç¹¥»÷Öб»¸üƵ·±µØʹÓ㬰üÂÞGoogle DriveºÍDropbox¡£

Ô­ÎÄÁ´½Ó£º
https://www.fireeye.com/offers/rpt-email-threat.html