ÐÅÏ¢Äþ¾²Öܱ¨-2019ÄêµÚ45ÖÜ

Ðû²¼Ê±¼ä 2019-11-18

>±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö



2019Äê11ÔÂ11ÈÕÖÁ17ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´48¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇMicrosoft Windows OpenType×ÖÌå½âÎöCVE-2019-1456Ô¶³ÌÖ´ÐдúÂ멶´; eQ-3 Homematic CCU3 testtcl.cgi´úÂëÖ´ÐЩ¶´£»SAP Diagnostics AgentÈÎÒâOSÃüÁî×¢È멶´£»Istio¾Ü¾ø·þÎñ©¶´£»Adobe Illustrator CVE-2019-8248ÄÚ´æÆÆ»µÈÎÒâ´úÂëÖ´ÐЩ¶´¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇÍйܷþÎñÉÌSmarterASP.NETÔâÀÕË÷Èí¼þ¹¥»÷£»¶íÂÞ˹з¨°¸Ç¿ÖÆÊÖ»úºÍPCÔ¤°²×°±¾¹úÈí¼þ£»5GЩ¶´¿É¸ú×ٵ绰λÖü°¹ã²¥Ðé¼Ù¾¯±¨£»McAfeeɱ¶¾Èí¼þ´úÂëÖ´ÐЩ¶´(CVE-2019-3648)£»¸ßͨоƬ×éQSEE©¶´¿ÉÖÂAndroidÉ豸Êý¾Ýй¶¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£


>ÖØÒªÄþ¾²Â©¶´Áбí


1. Microsoft Windows OpenType×ÖÌå½âÎöCVE-2019-1456Ô¶³ÌÖ´ÐдúÂ멶´
Microsoft Windows OpenType×ÖÌå½âÎö´¦ÖÃOpentype×ÖÌå´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÎļþÇëÇ󣬿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐÈÎÒâ´úÂë¡£
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1456

2. eQ-3 Homematic CCU3 testtcl.cgi´úÂëÖ´ÐЩ¶´
eQ-3 Homematic CCU3 save.cgi½Å±¾¿ÉÓÃÀ´ÉÏ´«½Å±¾²¢±»testtcl.cgi½Å±¾Ö´ÐУ¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÖ´ÐÐÈÎÒâ´úÂë¡£
https://psytester.github.io/CVE-2019-18938/

3. SAP Diagnostics AgentÈÎÒâOSÃüÁî×¢È멶´
SAP Diagnostic Agent´æÔÚδÃ÷Äþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÖ´ÐÐÈÎÒâOSÃüÁî¡£
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=528880390

4. Istio¾Ü¾ø·þÎñ©¶´
Istio´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉʹӦÓ÷¨Ê½Í߽⡣
https://github.com/istio/istio/issues/18229

5. Adobe Illustrator CVE-2019-8248ÄÚ´æÆÆ»µÈÎÒâ´úÂëÖ´ÐЩ¶´
Adobe Illustrator´¦ÖÃÎļþ´æÔÚÄÚ´æÆÆ»µÂ©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÎļþÇëÇ󣬿ÉÖ´ÐÐÈÎÒâ´úÂë»òÕß½øÐоܾø·þÎñ¹¥»÷¡£
https://helpx.adobe.com/security/products/illustrator/apsb19-36.html


>ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢ÍйܷþÎñÉÌSmarterASP.NETÔâÀÕË÷Èí¼þ¹¥»÷


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


SmarterASP.NETÊÇÒ»¼ÒÓµÓÐÁè¼Ý44Íò¸ö¿Í»§µÄASP.NETÍйܷþÎñÉÌ£¬¸Ã¹«Ë¾ÔÚÖÜÄ©Ôâµ½ÀÕË÷Èí¼þ¹¥»÷¡£µ±Ç°SmarterASP.NETÌåÏÖÕýÔÚŬÁ¦»Ö¸´¿Í»§µÄ·þÎñÆ÷£¬µ«²»Çå³þ¸Ã¹«Ë¾ÊÇÖ§¸¶ÁËÊê½ð»¹ÊÇÔÚ´Ó±¸·ÝÖлָ´¡£´Ë´Î¹¥»÷Öв»½ö¿Í»§Êý¾ÝÊܵ½Ó°Ï죬¶øÇÒSmarterASP.NET×Ô¼ºÒàÊÜÓ°Ïì¡£¸Ã¹«Ë¾µÄÍøÕ¾ÔÚÐÇÆÚÁùÈ«Ì춼ÏÂÏߣ¬Ö±µ½ÐÇÆÚÌìÔçÉϲÅÖØÐÂÉÏÏß¡£·þÎñÆ÷»Ö¸´ÊÂÇé½øÕ¹»ºÂý£¬Ðí¶à¿Í»§ÈÔÈ»ÎÞ·¨·ÃÎÊÆäÕË»§ºÍÊý¾Ý£¬°üÂÞÍøÕ¾ÎļþºÍºó¶ËÊý¾Ý¿â¡£Æ¾¾ÝÔÚTwitterÉÏÐû²¼µÄ½Øͼ£¬±»¼ÓÃܵĿͻ§Îļþºó¸½¼ÓÁË¡°.kjhbx¡±À©Õ¹Ãû£¬Ä¿Ç°Ñо¿ÈËÔ±ÈÔÔÚÊÔͼȷÈÏÀÕË÷Èí¼þµÄÖÖÀà¡£

Ô­ÎÄÁ´½Ó£º
https://www.zdnet.com/article/major-asp-net-hosting-provider-infected-by-ransomware/

2¡¢¶íÂÞ˹з¨°¸Ç¿ÖÆÊÖ»úºÍPCÔ¤°²×°±¾¹úÈí¼þ


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¶íÂÞ˹Òé»áÕýÔÚÍƶ¯Ò»ÏîÁ¢·¨£¬¸Ã·¨°¸½«Ç¿ÖÆÒªÇóËùÓÐÔÚ¶íÂÞ˹ÏúÊ۵ĵç×ÓÉ豸£¨°üÂÞÖÇÄÜÊÖ»ú¡¢PCºÍÖÇÄܵçÊӵȣ©Ô¤°²×°±¾¹ú¿Æ¼¼¹«Ë¾µÄÓ¦Óá£Õâ¿ÉÄÜ»á´øÀ´Äþ¾²Òþ»¼¡£Á¢·¨ÕßÌåÏָ÷¨°¸ÊÇΪÁ˱£»¤µ±µØµÄ¼¼ÊõÊг¡ÃâÊÜÍâ¹ú£¨¿ÉÄÜÊÇÖ¸ÃÀ¹ú£©µÄ¾ºÕù¡£Õþ¸®½«Õë¶ÔÿÖÖÉ豸ÀàÐÍÐû²¼Ò»·ÝÈí¼þÁбí£¬É豸¹©Ó¦ÉÌÐèÒªÔÚ¶íÂÞ˹ÏúÊÛµÄÉ豸ÉÏÔ¤°²×°ÕâЩÈí¼þ¡£Èç¹û¹©Ó¦É̲»×ñÊع涨£¬½«±»´¦ÒÔ×î¸ß20Íò¬²¼£¨Ô¼ºÏ3100ÃÀÔª£©µÄ· £¿î¡£¸Ã·¨°¸µÃµ½ÁËËùÓÐÖ÷ÒªÕþµ³µÄÖ§³Ö£¬ÕâÒâζ×ÅËüºÜÓпÉÄܽ«ÔÚ2020Äê7ÔÂ1ÈÕÉúЧ¡£

Ô­ÎÄÁ´½Ó£º
https://www.zdnet.com/article/phones-and-pcs-sold-in-russia-will-have-to-come-pre-installed-with-russian-apps/

3¡¢5GЩ¶´¿É¸ú×ٵ绰λÖü°¹ã²¥Ðé¼Ù¾¯±¨


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Æնɴóѧ£¨Purdue University£©ºÍ°®ºÉ»ª´óѧ£¨University of Iowa£©µÄÄþ¾²Ñо¿ÈËÔ±·¢ÏÖ½«½ü12¸ö5GÄþ¾²Â©¶´£¬Ñо¿ÈËÔ±ÌåÏÖÕâЩ©¶´¿ÉÔÊÐí¹¥»÷Õß»ñÈ¡Ä¿±êÓû§µç»°µÄÐÂ/¾ÉÁÙʱÍøÂç±êʶ·û£¬´Ó¶ø¸ú×ٵ绰µÄλÖã¬ÉõÖÁ½Ù³ÖÑ°ºôÐŵÀ½øÐÐÐé¼ÙµÄ½ô¼±¾¯±¨¹ã²¥¡£ÔÚijЩÇé¿öÏ£¬ÕâЩ©¶´¿ÉÄܱ»ÓÃÀ´½«·äÎÑÁ¬½Ó½µ¼¶Îª²»Ì«Äþ¾²µÄ³ß¶È¡£Ò»Ð©ÐµĹ¥»÷Ò²¿ÉÄÜÔÚÏÖÓеÄ4GÍøÂçÉϱ»ÀûÓ᣼øÓÚ©¶´µÄÐÔÖÊ£¬Ñо¿ÈËÔ±ÌåÏÖËûÃDz»¼Æ»®¹ûÈ»ÆäPoC´úÂ룬µ«ËûÃǽ«ÕâЩ·¢ÏÖ֪ͨÁËÈ«Çò·äÎÑÍøÂçGSMЭ»á£¨GSMA£©¡£GSMAûÓÐ͸¶ÊÇ·ñ¿ÉÒÔÐÞ¸´Â©¶´£¬Ò²Ã»ÓÐ͸¶ÐÞ¸´Ê±¼ä¡£


Ô­ÎÄÁ´½Ó£º

https://finance.yahoo.com/news/5g-flaws-track-phone-locations-163014364.html

4¡¢McAfeeɱ¶¾Èí¼þ´úÂëÖ´ÐЩ¶´(CVE-2019-3648)

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


SafeBreach Labs·¢ÏÖMcAfee·À²¡¶¾Èí¼þÊÜ´úÂëÖ´ÐЩ¶´£¨CVE-2019-3648£©µÄÓ°Ï죬¹¥»÷Õß¿ÉÈƹýMcAfeeµÄ×ÔÎÀ»úÖÆ£¬¿ÉÄܵ¼Ö¶ÔÊÜѬȾϵͳµÄ½øÒ»²½¹¥»÷¡£¸Ã©¶´ÊÇÓÉÓÚδÑéÖ¤¼ÓÔØDLLµÄÇ©Ãûµ¼ÖµÄ£¬¹¥»÷Õ߿ɽ«ÈÎÒâδǩÃûµÄDLL¼ÓÔص½ÒÔNT AUTHORITY\SYSTEMȨÏÞÔËÐеĶà¸ö·þÎñÖС£¸Ã¹¥»÷»¹¿ÉÒÔÈƹýÓ¦Ó÷¨Ê½°×Ãûµ¥±£»¤²¢ÖÆÖ¹±»Äþ¾²Èí¼þ¼ì²âµ½¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/mcafee-antivirus-software-impacted-by-code-execution-vulnerability/

5¡¢¸ßͨоƬ×éQSEE©¶´¿ÉÖÂAndroidÉ豸Êý¾Ýй¶


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾ÝÄþ¾²³§ÉÌCheckPointµÄÒ»·Ý³ÂËߣ¬¸ßͨоƬ×éÖеÄÄþ¾²Ö´Ðл·¾³£¨QSEE£©ÖдæÔÚ©¶´£¨CVE-2019-10574£©£¬¿Éµ¼ÖÂAndroidÉ豸ÖеĸöÈËÊý¾Ýй¶¡£QSEEÊÇ»ùÓÚARM TrustZone¼¼ÊõµÄÊÜÐÅÈÎÖ´Ðл·¾³£¨TEE£©µÄʵÏÖ£¬ÊÇÖ÷´¦ÖÃÆ÷ÉϵÄÒ»¸öÓ²¼þ¸ôÀëµÄÄþ¾²ÇøÓò£¬ÆäÖÐͨ³£°üÂÞרÓüÓÃÜÃÜÔ¿¡¢ÃÜÂë¡¢ÐÅÓÿ¨ºÍ½è¼Ç¿¨Æ¾¾ÝµÈÃô¸ÐÐÅÏ¢¡£Check PointÑо¿ÈËÔ±ÄæÏòÁ˸Ãϵͳ£¬²¢ÀûÓÃÄ£ºý²âÊÔ¶ÔÈýÐÇ¡¢LGºÍĦÍÐÂÞÀ­É豸½øÐÐÁ˲âÊÔ¡£×ÜÌå¶øÑÔ£¬Ñо¿ÈËÔ±·¢ÏÖÈýÐǵÄÊÜÐÅÈδúÂë°üÂÞËĸö©¶´£¬Ä¦ÍÐÂÞÀ­ºÍLG·Ö±ð°üÂÞÒ»¸ö©¶´£¬µ«ËùÓдúÂë¾ùÀ´×Ô¸ßͨ¹«Ë¾¡£ÈýÐÇ¡¢¸ßͨºÍLGÒÑÕë¶ÔÕâЩQSEE©¶´Ðû²¼Á˲¹¶¡¸üС£

Ô­ÎÄÁ´½Ó£º
https://thehackernews.com/2019/11/qualcomm-android-hacking.html