ÐÅÏ¢Äþ¾²Öܱ¨-2019ÄêµÚ28ÖÜ

Ðû²¼Ê±¼ä 2019-07-22

±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö



2019Äê7ÔÂ15ÈÕÖÁ21ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´50¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇNGINX njs nxt_vsprintf»º³åÇøÒç³ö©¶´ £»SolarWinds Orion Network Performance MonitorÔ¶³Ì´úÂëÖ´ÐЩ¶´ £»CentOS Web PanelδÊÚȨ·ÃÎÊ©¶´ £»Palo Alto Networks PAN-OS CVE-2019-1576ÃüÁî×¢È멶´ £»Linaro OP-TEE optee_os»º³åÇøÒç³ö©¶´¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊǹ㲥µç̨KHSUÒòÀÕË÷Èí¼þ¹¥»÷µ¼Ö½ÚÄ¿ÖÐ¶Ï £»Evite½ü1.01ÒÚÕË»§ÐÅϢй¶£¬Òѱ»HIBPÊÕ¼ £»±£¼ÓÀûÑǹú¼ÒË°Îñ¾ÖÔâºÚ¿ÍÈëÇÖ£¬500¶àÍò¹«ÃñÐÅÏ¢±»µÁ £»¾Æµê¹ÜÀí¹«Ë¾AavGoÒâÍâй¶800Íò¿Í»§ÐÅÏ¢ £»¹þÈø¿Ë˹̹Õþ¸®À¹½Ø¾³ÄÚËùÓеÄHTTPSÁ÷Á¿¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£



ÖØÒªÄþ¾²Â©¶´Áбí



1. NGINX njs nxt_vsprintf»º³åÇøÒç³ö©¶´


NGINX njs nxt/nxt_sprintf.cÎļþµÄnxt_vsprintf´æÔÚ»º³åÇøÒç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉʹӦÓ÷¨Ê½±ÀÀ £»òÖ´ÐÐÈÎÒâ´úÂë¡£
https://github.com/torvalds/linux/commit/6994eefb0053799d2e07cd140df6c2ea106c41ee

2. SolarWinds Orion Network Performance MonitorÔ¶³Ì´úÂëÖ´ÐЩ¶´


SolarWinds Orion Network Performance Monitor OrionModuleEngine·þÎñ´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔSYSTEMÓû§Ö´ÐÐÈÎÒâ´úÂë¡£
http://www.securityfocus.com/bid/107061

3. CentOS Web PanelδÊÚȨ·ÃÎÊ©¶´


CentOS Web Panel´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó£¬ÒÔÆäËûÓû§ÃûÈƹýÑé֤δÊÚȨ·ÃÎÊ¡£
https://github.com/i3umi3iei3ii/CentOS-Control-Web-Panel-CVE/blob/master/CVE-2019-13360.md

4. Palo Alto Networks PAN-OS CVE-2019-1576ÃüÁî×¢È멶´


Palo Alto Networks PAN-OS´æÔÚÊäÈëÑé֤©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÖ´ÐÐÈÎÒâOSÃüÁî¡£
https://securityadvisories.paloaltonetworks.com/Home/Detail/156

5. Linaro OP-TEE optee_os»º³åÇøÒç³ö©¶´


Linaro OP-TEE optee_os´æÔÚ»º³åÇøÒç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉʹӦÓ÷¨Ê½±ÀÀ £»òÖ´ÐÐÈÎÒâ´úÂë¡£
https://github.com/OP-TEE/optee_os/commit/70697bf3c5dc3d201341b01a1a8e5bc6d2fb48f8



ÖØÒªÄþ¾²Ê¼þ×ÛÊö



1¡¢¹ã²¥µç̨KHSUÒòÀÕË÷Èí¼þ¹¥»÷µ¼Ö½ÚÄ¿ÖжÏ


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÃÀ¹ú¼ÓÖݺ鱤ÖÝÁ¢´óѧӵÓеÄKHSU¹ã²¥µç̨Ôâµ½ÀÕË÷Èí¼þ¹¥»÷£¬µ¼Ö¸õç̨µÄËùÓÐϵͳºÍ´æ´¢·þÎñÆ÷̱»¾£¬½ÚÄ¿±»ÆÈÖжÏ¡£µ«KHSUÈ·ÈϳÆÊÜѬȾµÄ·þÎñÆ÷²¢Î´°üÂÞÈκÎÃô¸ÐÐÅÏ¢¡£KHSUÔÚ7ÔÂ1ÈÕ·¢Ïִ˴ι¥»÷£¬¹¥»÷ÕßÀûÓÃÁËKHSUϵͳÖеÄÄþ¾²Â©¶´¡£KHSUÌåÏÖûÓÐÊÕµ½Êê½ðÒªÇó£¬Ò²²»ÖªµÀ¹¥»÷µÄÀ´Ô´¡£ÔÚ·¢ÏÖʼþºó£¬KHSUÏòÁª°îÖ´·¨²¿ÃźÍÁª°îͨÐÅίԱ»á³ÂËßÁËÕâһʼþ¡£

Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/khsu-radio-stations-regular-programming-interrupted-due-to-ransomware-attack-e39dbd3d

2¡¢Evite½ü1.01ÒÚÕË»§ÐÅϢй¶£¬Òѱ»HIBPÊÕ¼


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


2019Äê5ÔÂEviteÐû²¼Êý¾Ýй¶֪ͨ£¬ÌåÏÖÆä·þÎñÆ÷´Ó2ÔÂ22ÈÕ·¢ÏÖδÊÚȨ·ÃÎÊ£¬Ô¼1000ÍòÓû§ÐÅϢй¶¡£µ«Æ¾¾ÝHave I Been PwnedÍøÕ¾ÊÕ¼µÄÊý¾Ý¿â£¬ÕâÒ»Êý×ÖÒª´óµÃ¶à£¬¹²Óнü1.01ÒÚÓû§ÐÅÏ¢±»µÁ¡£ÕâЩÊý¾Ý×îÔç¿É×·ËÝÖÁ2013Ä꣬鶵ÄÐÅÏ¢°üÂÞÐÕÃû¡¢µç»°ºÅÂ롢ʵ¼ÊµØÖ·¡¢³öÉúÈÕÆÚ¡¢ÐÔ±ð¡¢Ã÷ÎÄÃÜÂëºÍµç×ÓÓʼþµØÖ·¡£×î³õ±»Ð¹Â¶µÄÊý¾Ý¿âÔÚDream MarketÉϳöÊÛ£¬µ«¸ÃÍøÕ¾Òѱ»¾¯·½¹Ø±Õ£¬Òò´ËÄ¿Ç°Éв»Çå³þÕâ¸ö¸ü´óµÄÊý¾Ý¿âÊÇ·ñÒ²ÔÚ³öÊÛ¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/evite-invites-over-100-million-people-to-their-data-breach/

3¡¢±£¼ÓÀûÑǹú¼ÒË°Îñ¾ÖÔâºÚ¿ÍÈëÇÖ£¬500¶àÍò¹«ÃñÐÅÏ¢±»µÁ


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¾Ýzdnet±¨µÀ£¬Ò»ºÚ¿Í×éÖ¯´Ó±£¼ÓÀûÑǹú¼ÒË°Îñ¾Ö£¨NRA£©ÖÐÇÔÈ¡ÁËÔ¼110¸öÊý¾Ý¿â£¬ÆäÖаüÂÞ½ü21GBµÄ¸öÈËÊý¾Ý£¬ÊÜÓ°ÏìÈËÊýÁè¼Ý500Íò¡£ºÚ¿Í½«²¿Ãű»µÁÊý¾Ýͨ¹ýµç×ÓÓʼþ·¢Ë͸øµ±µØýÌ壬µ¼ÖÂʼþÆعâ¡£¸Ã¹úÓйز¿ÃÅÒѾ­ÈÏ¿ÉÕâһʼþ£¬²¢ÕýÓë±£¼ÓÀûÑǹú¼ÒÄþ¾²¾ÖºÏ×÷ÊӲ졣鶵ÄÐÅÏ¢°üÂÞ±£¼ÓÀûÑǹ«ÃñµÄ¸öÈËʶ±ðÂ루PIN£©¡¢ÐÕÃû¡¢¼ÒͥסַºÍ²ÆÕþÊÕÈ룬ÕâЩÊý¾Ý×îÔç¿É×·Ëݵ½2007Äê¡£

Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/bulgarias-national-revenue-agency-hacked-to-steal-over-five-million-peoples-data-8e64c8d9

4¡¢¾Æµê¹ÜÀí¹«Ë¾AavGoÒâÍâй¶800Íò¿Í»§ÐÅÏ¢


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


WizcaseÄþ¾²Ñо¿Ô±Daniel Brown·¢Ï־Ƶê¹ÜÀíÉÌAavGoµÄÒ»¸öElasticsearchÊý¾Ý¿â¿É¹ûÈ»·ÃÎÊ£¬¸ÃÊý¾Ý¿â°üÂÞ800ÍòÌõ¿Í»§ÐÅÏ¢£¬°üÂÞÔ¤¶©ÐÅÏ¢¡¢¿Í»§Í¶Ëß¡¢·¢Æ±¡¢¹¤µ¥¡¢Ô±¹¤±¸Íü¼ºÍÏûÏ¢¡¢¾Æµê·¿¼äͼƬ¡¢ÎïÆ·Ëð»µÍ¼Æ¬ÒÔ¼°¿Í»§µÄ¸öÈËÐÅÏ¢£¨ÐÕÃû¡¢³öÉúÈÕÆÚ¡¢µç»°ºÅÂë¡¢ÓÊÏäµØÖ·¡¢×¡Ö·¡¢»éÒö×´¿ö¡¢µÇ¼ÐÅÏ¢ºÍ¸¶¿î·½Ê½£©¡£Ð¹Â¶µÄÊý¾Ý»¹°üÂ޾Ƶê¹ÜÀíÔ±µÄÏêϸµÇ¼ÐÅÏ¢£¬ÀýÈç¹ÜÀíÃæ°å¡¢Ô¤¶©ÏµÍ³ºÍÄÚ²¿Êý¾Ý¿âµÄÓû§ÃûºÍÃÜÂë¡£ÊÜÓ°ÏìµÄ¾Æµê°üÂÞThe Row Hotel¡¢Stay Cal HotelsµÈÊ®¶à¼Ò¾Æµê¡£¸Ã¹«Ë¾ÒÑÔÚ7ÔÂ16ÈÕ¶ÔÊý¾Ý¿â½ÓÄÉÁ˱ £»¤´ëÊ©¡£

Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/unprotected-elasticsearch-database-belonging-to-aavgo-exposed-8-million-records-of-guest-details-f5fb1eac

5¡¢¹þÈø¿Ë˹̹Õþ¸®À¹½Ø¾³ÄÚËùÓеÄHTTPSÁ÷Á¿


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¹þÈø¿Ë˹̹Õþ¸®ÒÑ´Ó7ÔÂ17ÈÕ¿ªÊ¼À¹½ØÆä¾³ÄÚµÄËùÓÐHTTPSÁ÷Á¿¡£ÔÚµ±µØÕþ¸®µÄָʾÏ£¬µ±µØISPÇ¿ÖÆÓû§ÔÚÿ¸öÉ豸ºÍä¯ÀÀÆ÷Öа²×°Õþ¸®·¢±íµÄÖ¤Êé¡£¸ÃÖ¤Ê齫ÔÊÐíÕþ¸®»ú¹¹½âÃÜÓû§µÄHTTPSÁ÷Á¿²¢¼ì²ìÆäÄÚÈÝ¡£ÔÚÓû§°²×°¸ÃÖ¤Êé֮ǰ£¬ËûÃǽ«ÎÞ·¨·ÃÎÊ»¥ÁªÍø¡£Õþ¸®¹ÙÔ±ÌåÏִ˾ÙÖ¼ÔÚ¼ÓÇ¿¶Ô¹«Ãñ¡¢Õþ¸®»ú¹¹ºÍ˽ӪÆóÒµµÄ± £»¤£¬Ê¹ÆäÃâÔâºÚ¿Í¹¥»÷¡¢»¥ÁªÍøÆÛÕ©µÈÍøÂçÍþв¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/kazakhstan-government-is-now-intercepting-all-https-traffic/