ÐÅÏ¢Äþ¾²Öܱ¨-2019ÄêµÚ27ÖÜ

Ðû²¼Ê±¼ä 2019-07-15

±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö



2019Äê7ÔÂ08ÈÕÖÁ14ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´54¸ö £¬ÖµµÃ¹Ø×¢µÄÊÇFastjsonÈÎÒâ´úÂëÖ´ÐЩ¶´£»Apache Solr·´ÐòÁл¯Ô¶³Ì´úÂëÖ´ÐЩ¶´£»Cesanta Mongoose ¡®mq_parse_http¡¯ º¯Êý»º³åÇøÒç³ö©¶´£»Microsoft Azure DevOps Server CVE-2019-1072´úÂëÖ´ÐЩ¶´£»Microsoft SQL Server CVE-2019-1068ÄÚ´æÆÆ»µ´úÂëÖ´ÐЩ¶´ ¡£



±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊǹã¸æÈí¼þAgent SmithѬȾԼ2500Íǫ̀AndroidÉ豸£»Ï£À°¶¥¼¶ÓòÃû×¢²áÉÌICS-ForthÔâºÚ¿Í¹¥»÷ £¬DNS¼Ç¼±»¸Ä¶¯£»ÍòºÀÒòÊý¾Ýй¶ÃæÁÙÓ¢¹ú¼à¹Ü»ú¹¹1.23ÒÚÃÀÔª· £¿î£»ÊÓƵ»áÒéÈí¼þZoom RCE©¶´ £¬¿É½Ù³ÖMacÉãÏñÍ·£»Ó¢¹úº½¿Õ¹«Ë¾ÒòÊý¾Ýй¶ÃæÁÙ1.83ÒÚÓ¢°÷· £¿î ¡£


ƾ¾ÝÒÔÉÏ×ÛÊö £¬±¾ÖÜÄþ¾²ÍþвΪÖÐ ¡£



ÖØÒªÄþ¾²Â©¶´Áбí



1. FastjsonÈÎÒâ´úÂëÖ´ÐЩ¶´


Fastjson autotype´æÔÚ·´ÐòÁл¯Â©¶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬¿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë ¡£
https://github.com/alibaba/fastjson/wiki/update_faq_20190722

2. Apache Solr·´ÐòÁл¯Ô¶³Ì´úÂëÖ´ÐЩ¶´


Apache Solr Config API´¦ÖÃPOSTÇëÇóÅäÖÃJMX·þÎñÆ÷´æÔÚ·´ÐòÁл¯Â©¶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬¿ÉÖ´ÐÐÈÎÒâ´úÂë ¡£
https://seclists.org/oss-sec/2019/q1/169

3. Cesanta Mongoose ¡®mq_parse_http¡¯ º¯Êý»º³åÇøÒç³ö©¶´


Cesanta Mongoose mongoose.cÎļþµÄ¡®mq_parse_http¡¯ º¯Êý´æÔÚ»º³åÇøÒç³ö©¶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐÈÎÒâ´úÂë ¡£
https://github.com/cesanta/mongoose/pull/1035

4. Microsoft Azure DevOps Server CVE-2019-1072´úÂëÖ´ÐЩ¶´


Microsoft Azure DevOps Server´¦ÖÃÌØÊâÎļþ´æÔÚÄþ¾²Â©¶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬¿ÉÒÔTFS ·þÎñÕÊ»§µÄÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë ¡£
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-1072

5. Microsoft SQL Server CVE-2019-1068ÄÚ´æÆÆ»µ´úÂëÖ´ÐЩ¶´


Microsoft SQL ServerÄÚ²¿º¯Êý´¦ÖôæÔÚÄþ¾²Â©¶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬¿ÉÒÔ SQL ServerÊý¾Ý¿âÒýÇæ·þÎñÕË»§ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë ¡£
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-1068


 ÖØÒªÄþ¾²Ê¼þ×ÛÊö



1¡¢¹ã¸æÈí¼þAgent SmithѬȾԼ2500Íǫ̀AndroidÉ豸


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Check PointÑо¿ÈËÔ±·¢ÏÖԼĪÓÐ2500Íǫ̀AndroidÉ豸Òѱ»Ð¹ã¸æÈí¼þAgent SmithѬȾ ¡£¸Ã¶ñÒâÈí¼þÓÃÓÚÏòÓû§µÄÊÖ»úÍÆË͹ã¸æ £¬µ«¹¥»÷ÕßÒ²¿ÉÄܽ«ÆäÓÃÓÚ¸ü¶ñÒâµÄÄ¿µÄ £¬ÀýÈçÇÔÈ¡ÒøÐÐƾ¾Ý ¡£ÎªÁËÍê³É¸üа²×°¹ý³Ì £¬¸Ã¶ñÒâÈí¼þÀûÓÃÁËJanus©¶´ £¬ÒÔÈƹýÓ¦Ó÷¨Ê½µÄÇ©Ãû²¢ÏòÆäÌí¼ÓÈÎÒâ´úÂë ¡£ÊÜѬȾÉ豸ÊýÁ¿×î¶àµÄ¹ú¼ÒÊÇÓ¡¶È£¨Áè¼Ý1500Íǫ̀£© £¬Æä´ÎÊÇÃϼÓÀ­¹ú£¨Áè¼Ý250Íǫ̀£©ºÍ°Í»ù˹̹£¨½ü170Íǫ̀£© ¡£Æ¾¾ÝCheck PointµÄÊÓ²ì½á¹û £¬Agent Smith×îÔçÓÚ2016Äê³õ¿ªÊ¼»î¶¯ £¬Á½ÄêÀ´ËüÖ÷Ҫͨ¹ýµÚÈý·½Ó¦ÓÃÉ̵ê9apps.comÁ÷´« ¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/25-million-android-devices-infected-by-agent-smith-malware/

2¡¢Ï£À°¶¥¼¶ÓòÃû×¢²áÉÌICS-ForthÔâºÚ¿Í¹¥»÷ £¬DNS¼Ç¼±»¸Ä¶¯


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ï£À°¶¥¼¶ÓòÃû×¢²áÉÌICS-ForthÔâºÚ¿Í¹¥»÷ ¡£ICS-ForthÂôÁ¦¹ÜÀíÏ£À°µÄ¶¥¼¶ÓòÃû.grºÍ.el £¬¸Ã×é֯ȷÈÏÔâµ½ºÚ¿ÍÈëÇÖ ¡£¹¥»÷ÕßÓë˼¿ÆTalos4Ô·ݵijÂËßÖÐÃèÊöµÄ×éÖ¯Ïàͬ £¬¼´·¸×ïÍÅ»ïSea Turtle ¡£¸Ã×é֯ʹÓÃÒ»ÖÖÏà¶Ô½ÏеÄÒªÁì¹¥»÷Ä¿±ê £¬ËûÃDz»»áÖ±½ÓÕë¶ÔÄ¿±ê £¬¶øÊÇÈëÇÖÓòÃû×¢²áÉÌ»òDNSÍйܷþÎñÉ̵ÄÕË»§ £¬ÐÞ¸ÄÄ¿±ê¹«Ë¾µÄDNSÉèÖà £¬´Ó¶ø½«Ä¿±ê¹«Ë¾µÄÓ¦Ó÷¨Ê½»òµç×ÓÓʼþµÄÁ÷Á¿Öض¨ÏòÖÁ¹¥»÷ÕߵķþÎñÆ÷ £¬Ö´ÐÐÖмäÈ˹¥»÷²¢À¹½ØµÇ¼ƾ¾Ý ¡£ÕâÖÖ¹¥»÷Á¬Ðøʱ¼ä½Ï¶Ì £¬ÔÚÊýСʱÖÁÊýÌìÖ®¼ä £¬ÓÉÓÚ´ó¶àÊý¹«Ë¾Ã»ÓйØ×¢DNSÉèÖõĸü¸Ä £¬Òò´ËÕâÖÖ¹¥»÷ÄÑÒÔ±»²ì¾õ ¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/hackers-breached-greeces-top-level-domain-registrar/

3¡¢ÍòºÀÒòÊý¾Ýй¶ÃæÁÙÓ¢¹ú¼à¹Ü»ú¹¹1.23ÒÚÃÀÔª· £¿î


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ó¢¹úÊý¾Ý±£»¤»ú¹¹ÖܶþÌåÏÖ½«ÏòÍòºÀ´¦ÒÔ9900ÍòÓ¢°÷£¨ºÏ1.23ÒÚÃÀÔª£©µÄ· £¿î £¬Ô­ÒòÊÇ2018Äê11ÔÂÍòºÀÆìÏÂϲ´ïÎݾƵêµÄ»áÔ±Êý¾Ýй¶Ê¼þ ¡£¾ÝÐÅϢרԱ°ì¹«ÊÒ£¨ICO£©³Æ £¬Å·ÖÞ31¸ö¹ú¼ÒµÄ½ü3000Íò¾ÓÃñºÍ700ÍòÓ¢¹ú¾ÓÃñÊܵ½ÍòºÀÊý¾Ý鶵ÄÓ°Ïì ¡£ÕâÊǹýÈ¥Á½ÌìÄÚ·¢ÉúµÄµÚ¶þÆðÕë¶ÔÊý¾Ý鶵ÄÖØ´ó· £¿î֪ͨ ¡£ÍòºÀÌåÏÖ¶ÔÐÅϢרԱ°ì¹«Êҵľö¶¨¸ÐӦʧÍû £¬ÔÚ±»´¦ÒÔ· £¿î֮ǰ £¬Ëü¡°ÓÐȨ×ö³ö»ØÓ¦¡± £¬²¢¡°¼Æ»®×ö³ö»ØÓ¦ÇÒ»ý¼«º´ÎÀ¡±×Ô¼ºµÄÁ¢³¡ ¡£


Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2019/07/marriott-data-breach-gdpr.html

4¡¢ÊÓƵ»áÒéÈí¼þZoom RCE©¶´ £¬¿É½Ù³ÖMacÉãÏñÍ·


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Äþ¾²Ñо¿ÈËÔ±Jonathan LeitschuhÅû¶ÊÓƵ»áÒéÈí¼þZoomÖеÄÒ»¸öRCE©¶´ £¬¸Ã©¶´Ó°ÏìÁËMacƽ̨ÉϵÄZoom app°æ±¾4.4.4 £¬¿ÉÔÊÐí¹¥»÷ÕßÔÚÓû§·ÃÎÊÍøվʱ½Ó¹ÜÍøÂçÉãÏñÍ· ¡£Æ¾¾ÝLeitschuhµÄ˵·¨ £¬Áè¼Ý400ÍòÓû§ÃæÁÙ·çÏÕ ¡£¸Ã©¶´ÀûÓÃÁËZoomÈí¼þµÄµã»÷¼ÓÈ빦Ч £¬¼´Ö»Ðèµã»÷ÑûÇëÁ´½Ó¼´¿É×Ô¶¯¼¤»îϵͳÉÏ°²×°µÄÓ¦Ó÷¨Ê½²¢Í¨¹ýWebä¯ÀÀÆ÷¼ÓÈëÊÓƵ»áÒé ¡£¹¥»÷Õß¿Éͨ¹ýµöÓãÓʼþ·Ö·¢ÕâÖÖ¶ñÒâÁ´½Ó ¡£Leitschuh»¹ÌåÏÖZoomµÄÐÞ¸´Ö»ÊÇ×èÖ¹¹¥»÷Õß´ò¿ªÓû§µÄÉãÏñÍ· £¬¹¥»÷ÕßÈÔ¿ÉÒÔͨ¹ý¶ñÒâÁ´½ÓÓÕʹÓû§¼ÓÈë»áÒé ¡£


Ô­ÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/88147/hacking/zoom-mac-software-flaw.html

5¡¢Ó¢¹úº½¿Õ¹«Ë¾ÒòÊý¾Ýй¶ÃæÁÙ1.83ÒÚÓ¢°÷· £¿î


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


µ±µØʱ¼ä7ÔÂ8ÈÕ £¬Ó¢¹úÐÅϢרԱ°ì¹«ÊÒ£¨ICO£©Ðû²¼ £¬½«¶ÔÓ¢¹úº½¿Õ¹«Ë¾2018ÄêÊý¾Ýй¶Ê¼þ¿ª³ö1.83ÒÚÓ¢°÷¾Þ¶î·£µ¥ ¡£ÕâÊÇ×Ô¡¶Í¨ÓÃÊý¾Ý±£»¤ÌõÀý¡·£¨GDPR£©ÊµÊ©ÒÔÀ´×î´óµÄÒ»±Ê·£µ¥ £¬Ò²ÊǵÚÒ»¸öƾ¾ÝйæÔòÐû²¼µÄ·£µ¥ ¡£Ó¢¹úº½¿Õ¹«Ë¾¸ß²ã¶ÔÕâ¸ö¾ö¶¨¸ÐÓ¦Õ𾪠¡£1.83ÒÚÓ¢°÷ÊÇƾ¾Ý¸Ã¹«Ë¾2017²ÆÄêÈ«ÇòÓªÒµ¶îµÄ1.5%¼ÆËãµÃÀ´ £¬Æ¾¾ÝGDPR £¬ÕâÒ»´¦·£±ÈÀý×î¸ß¿É´ï4% ¡£ÔÚ´Ë֮ǰ £¬ICO×î¸ßµÄ· £¿î¶îÊÇ50ÍòÓ¢°÷ £¬2018ÄêFacebook½£ÇÅÊý¾Ý³óÎźÍ2017ÄêEquifax´ó¹æÄ£Êý¾Ýй¶¾ù±»´¦ÒÔ50ÍòÓ¢°÷µÄ· £¿î ¡£


Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2019/07/british-airways-breach-gdpr-fine.html