ÐÅÏ¢Äþ¾²Öܱ¨-2020ÄêµÚ23ÖÜ

Ðû²¼Ê±¼ä 2020-06-09

> ±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


2020Äê06ÔÂ01ÈÕÖÁ06ÔÂ07ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´79¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇZoom Client´¦Öö¯»­GIFÏûϢ·¾¶±éÀú©¶´£»Cisco 829 Industrial Integrated Services Routers»º³åÇøÒç³ö©¶´£»NEC ESMPRO Manager RMI·´ÐòÁл¯´úÂëÖ´ÐЩ¶´£»IBM WebSphere Application Server Network DeploymentÔ¶³Ì´úÂëÖ´ÐЩ¶´£»Docker EngineÖмäÈ˹¥»÷©¶´¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊǶíÂÞ˹ºÚ¿Í¹¥»÷²¨À¼Õþ¸®»ú¹¹£¬Ðû²¼Óйر±Ô¼ÑÝÏ°Ðé¼ÙÐÅÏ¢£»ÊÓƵ¼ô¼­Ó¦ÓÃVivaVideo»òΪ¼äµýÈí¼þ£¬Ó°ÏìÁè¼Ý1.57ÒÚÓû§£»Ó¡¶ÈÖ§¸¶Ó¦ÓÃBHIMÒòÅäÖôíÎó£¬Ð¹Â¶Êý°ÙÍòÓû§ÐÅÏ¢£»DopplePaymerÌåÏÖÒÑÀÖ³ÉÈëÇÖDMI²¢ÇÔÈ¡NASAµÄÏà¹ØÎļþ£»MozillaÐû²¼FirefoxÄþ¾²¸üУ¬ÐÞ¸´¶à¸öÈÎÒâ´úÂëÖ´ÐЩ¶´¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£



>ÖØÒªÄþ¾²Â©¶´Áбí


1.Zoom Client´¦Öö¯»­GIFÏûϢ·¾¶±éÀú©¶´


Zoom Client´¦ÖðüÂÞ¶¯»­GIFµÄÏûÏ¢´æÔÚĿ¼±éÀú©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÏûÏ¢ÇëÇ󣬿ÉÒÔÄ¿±êÓû§ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂ룬»òÕû¸ö×éÓû§ÊÜÓ°Ïì¡£

https://talosintelligence.com/vulnerability_reports/TALOS-2020-1055


2. Cisco 829 Industrial Integrated Services Routers»º³åÇøÒç³ö©¶´


Cisco 829 Industrial Integrated Services Routers¹ÜÀíinter-VMÐźŴæÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÕß¿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ios-iot-rce-xYRSeMNH


3. NEC ESMPRO Manager RMI·´ÐòÁл¯´úÂëÖ´ÐЩ¶´


NEC ESMPRO Manager RMI·þÎñ´æÔÚÊäÈëÑé֤©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£

https://www.zerodayinitiative.com/advisories/ZDI-20-684/


4. IBM WebSphere Application Server Network DeploymentÔ¶³Ì´úÂëÖ´ÐЩ¶´


IBM WebSphere Application Server Network Deployment´æÔÚδÃ÷Äþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£

https://www.ibm.com/blogs/psirt/security-bulletin-remote-code-execution-vulnerability-in-websphere-application-server-nd-cve-2020-4448/


5. Docker EngineÖмäÈ˹¥»÷©¶´


Docker EngineËù´´½¨µÄÍøÂçÁ¬½Ó»áĬÈϽÓÊÕIPv6·ÓÉÆ÷ͨ¸æ£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ɽøÐÐÖмäÈ˹¥»÷£¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢¡£

https://github.com/docker/docker-ce/releases/v19.03.11



> ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢¶íÂÞ˹ºÚ¿Í¹¥»÷²¨À¼Õþ¸®»ú¹¹£¬Ðû²¼Óйر±Ô¼ÑÝÏ°Ðé¼ÙÐÅÏ¢


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ô­ÎÄÁ´½Ó£º

https://www.ehackingnews.com/2020/05/russian-hackers-attacked-poland-due-to.html


2¡¢ÊÓƵ¼ô¼­Ó¦ÓÃVivaVideo»òΪ¼äµýÈí¼þ£¬Ó°ÏìÁè¼Ý1.57ÒÚÓû§


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ô­ÎÄÁ´½Ó£º

https://latesthackingnews.com/2020/05/31/vivavideo-and-other-apps-with-over-157-million-installs-spy-on-users/


3¡¢Ó¡¶ÈÖ§¸¶Ó¦ÓÃBHIMÒòÅäÖôíÎó£¬Ð¹Â¶Êý°ÙÍòÓû§ÐÅÏ¢


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/indian-payment-app-bhim-data-breach/


4¡¢DopplePaymerÌåÏÖÒÑÀÖ³ÉÈëÇÖDMI²¢ÇÔÈ¡NASAµÄÏà¹ØÎļþ


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/ransomware-gang-says-it-breached-one-of-nasas-it-contractors/


5¡¢MozillaÐû²¼FirefoxÄþ¾²¸üУ¬ÐÞ¸´¶à¸öÈÎÒâ´úÂëÖ´ÐЩ¶´


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ô­ÎÄÁ´½Ó£º

https://www.theregister.com/2020/06/04/firefox_77_security_fixes/