ÐÅÏ¢Äþ¾²Öܱ¨-2020ÄêµÚ36ÖÜ

Ðû²¼Ê±¼ä 2020-09-08

> ±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


2020Äê08ÔÂ31ÈÕÖÁ09ÔÂ06ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´56¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇGigadevice GD32F103´úÂëÖ´ÐЩ¶´£»Gigadevice GD32F103¹Ì¼þÌáȡ©¶´£»NETGEAR R8300ÃüÁî×¢È멶´£»Education openSIS SQL×¢È멶´£»Education openSIS EmailCheck.php SQL×¢È멶´ ¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊǹ¤ÐŲ¿Í¨±¨101¿îAPPÇÖ·¸Óû§È¨Ò棬ÇáËɳïµÈƽ̨ÉÏ°ñ£»Å²ÍþÒé»áÓʼþϵͳÔâ¹¥»÷£¬¹¤µ³ºÍÖÐÐĵ³¾ùÊÜÓ°Ï죻Cisco¾¯¸æÆäIOS XR´æÔÚ0day²¢Òѱ»ÔÚÒ°ÀûÓã»Cisco Jabber´æÔÚÔ¶³ÌÖ´ÐдúÂ멶´£¬ÏÖÒѱ»ÐÞ¸´£»Ó¢ÌضûÐû²¼Î¢´úÂëÄþ¾²¸üУ¬Ö÷ÒªÊÊÓÃÓÚWin10ϵÁÐ ¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖÐ ¡£


ÖØÒªÄþ¾²Â©¶´Áбí


1.Gigadevice GD32F103´úÂëÖ´ÐЩ¶´


Gigadevice GD32F103Äþ¾²±£»¤´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÎïÀíÄÜ·ÃÎʹ¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó£¬Öض¨Ïò¿ØÖÆÁ÷Ö´ÐÐÈÎÒâ´úÂë ¡£

https://www.usenix.org/system/files/woot20-paper-obermaier.pdf


2. Gigadevice GD32F103¹Ì¼þÌáȡ©¶´


Gigadevice GD32F103ÉÁ´æ¶Á³ö±£»¤´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÎïÀíÄÜ·ÃÎʹ¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ɴӵ÷ÊÔ½Ó¿Ú»ñÈ¡¹Ì¼þ ¡£

https://www.usenix.org/system/files/woot20-paper-obermaier.pdf


3.NETGEAR R8300ÃüÁî×¢È멶´


NETGEAR R8300´æÔÚÊäÈëÑé֤©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë ¡£


https://kb.netgear.com/000062158/Security-Advisory-for-Pre-Authentication-Command-Injection-on-R8300-PSV-2020-0211


4. Education openSIS SQL×¢È멶´


Open Solutions for Education openSIS´æÔÚSQL×¢È멶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄSQLÇëÇ󣬲Ù×÷Êý¾Ý¿â£¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢»òÖ´ÐÐÈÎÒâ´úÂë ¡£

https://talosintelligence.com/vulnerability_reports/TALOS-2020-1081


5. Education openSIS EmailCheck.php SQL×¢È멶´


Open Solutions for Education EmailCheck.php´æÔÚSQL×¢È멶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄSQLÇëÇ󣬲Ù×÷Êý¾Ý¿â£¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢»òÖ´ÐÐÈÎÒâ´úÂë ¡£ ¡£

https://talosintelligence.com/vulnerability_reports/TALOS-2020-1073


> ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢¹¤ÐŲ¿Í¨±¨101¿îAPPÇÖ·¸Óû§È¨Ò棬ÇáËɳïµÈƽ̨ÉÏ°ñ


1.jpg


¹¤ÒµºÍÐÅÏ¢»¯²¿¹ÙÍøÐû²¼¹ØÓÚÇÖº¦Óû§È¨ÒæÐÐΪµÄAPPͨ±¨ ¡£µ°¿Ç¹«Ô¢¡¢ÇáËɳ±¦±¦Ê÷ÔÐÓý¡¢ZAKERÐÂÎÅ¡¢ÍøÒ×¹ûÈ»¿Î¡¢¼Ý¿¼±¦µä¡¢ÃÀÀö˵¡¢ÂìÒ϶Ì×â¡¢¿ì¼ô¼­¡¢360ÇåÀí´óʦ¡¢µÃÎï¡¢ËѺüÊÓƵ¡¢Ó³¿ÍÖ±²¥µÈ101¿îAPP´æÔÚÇÖº¦Óû§È¨ÒæÐÐΪ ¡£ÕâЩӦÓÃÈí¼þÖ÷ÒªÉæ¼°ÎÊÌâÊÇÎ¥¹æÊÕ¼¯¸öÈËÐÅÏ¢£¬ÁíÍ⻹Éæ¼°APPÇ¿ÖÆ¡¢Æµ·±¡¢¹ý¶ÈË÷ȡȨÏÞ£¬Ç¿ÖÆÓû§Ê¹Óö¨ÏòÍÆË͹¦Ð§£¬³¬·¶Î§ÊÕ¼¯¸öÈËÐÅÏ¢µÈÎÊÌâ ¡£


Ô­ÎÄÁ´½Ó£º

http://tech.cnr.cn/techgd/20200831/t20200831_525234083.shtml


2¡¢Å²ÍþÒé»áÓʼþϵͳÔâ¹¥»÷£¬¹¤µ³ºÍÖÐÐĵ³¾ùÊÜÓ°Ïì


2.jpg


ŲÍþÒé»á£¨Storting£©Ðû²¼ÉùÃ÷£¬ÌåÏÖÓкڿ͹¥»÷Æä³ÉÔ±µÄµç×ÓÓʼþÕÊ»§²¢ÇÔÈ¡Êý¾Ý ¡£¸ÃʼþÕýÔÚÊÓ²ìÖУ¬Ä¿Ç°Éв»Çå³þ±»µÁÊý¾ÝµÄÊýÁ¿¡¢ÖÖÀàÒÔ¼°¹¥»÷µÄÆÆ»µË®Æ½ ¡£Å²Íþ¹¤µ³µÄJarle RoheimH?konsen֤ʵ£¬¹¤µ³³ÉÔ±ºÍÕþ¿ÍÔÚÕâ´Î¹¥»÷ÖоùÊܵ½Ó°Ï죬ͬʱÖÐÐĵ³Ò²È·ÈÏÆä´ú±íºÍÔ±¹¤Êܵ½ÁËÓ°Ïì ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/hackers-breached-norwegian-parliament-emails-to-steal-data/


3¡¢Cisco¾¯¸æÆäIOS XR´æÔÚ0day²¢Òѱ»ÔÚÒ°ÀûÓÃ


3.jpg


˼¿ÆÉÏÖÜÁù¾¯¸æ˵£¬ÆäIOS XR´æÔÚÒ»¸öеÄ0day£¬Ä¿Ç°Òѱ»ºÚ¿ÍÔÚÒ°ÀûÓà ¡£¸Ã©¶´±»¸ú×ÙCVE-2020-3566£¬Ó°ÏìÁ˲Ù×÷ϵͳIOS XR°æ±¾¸½´øµÄ¾àÀëʸÁ¿×鲥·ÓÉЭÒé(DVMRP)¹¦Ð§£¬¸Ã°æ±¾µÄ²Ù×÷ϵͳͨ³£°²×°ÔÚµçÐż¶ºÍÊý¾ÝÖÐÐÄ·ÓÉÆ÷ÉÏ ¡£Ë¼¿ÆÌåÏÖ£¬¸Ã©¶´ÊÇÓÉÓÚInternet×é¹ÜÀíЭÒ飨IGMP£©Êý¾Ý°üµÄÐÐÁйÜÀí²»×ãËùÖ£¬¹¥»÷Õß¿ÉÒÔͨ¹ý·¢ËÍÌØÖƵÄIGMPÁ÷Á¿À´ÀûÓôË©¶´ ¡£ÀÖ³ÉÀûÓø鶴¿Éµ¼ÖÂÄÚ´æºÄ¾¡£¬´Ó¶øµ¼ÖÂÆäËû½ø³Ì£¨ÈçÄÚ²¿ºÍÍⲿ·ÓÉЭÒ飩²»Îȶ¨ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/cisco-warns-of-actively-exploited-ios-xr-zero-day/


4¡¢Cisco Jabber´æÔÚÔ¶³ÌÖ´ÐдúÂ멶´£¬ÏÖÒѱ»ÐÞ¸´


4.jpg


WatchcomµÄOlav Sortland Thoresen·¢ÏÖWindows°æCisco JabberÖдæÔÚÑÏÖصĴúÂëÖ´ÐЩ¶´£¬ÏÖÒѱ»ÐÞ¸´ ¡£¸Ã©¶´±»¸ú×ÙΪCVE-2020-3495£¬ CVSSΪ9.9·Ö£¬ÊÇÓÉÓÚ´«ÈëÏûÏ¢ÄÚÈݵÄÊäÈëÑéÖ¤²»ÕýÈ·ÒýÆðµÄ ¡£¾­¹ýÉí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓöñÒâµÄ¿ÉÀ©Õ¹ÏûÏ¢ºÍ״̬ЭÒ飨XMPP£©ÏûÏ¢ÀûÓø鶴£¬ÀÖ³ÉÀûÓú󹥻÷Õß¿ÉÔÚÄ¿±êϵͳÉÏÖ´ÐÐÈÎÒⷨʽ ¡£Ë¼¿Æ²úÎïÄþ¾²Ê¼þÏìӦС×飨PSIRT£©ÌåÏÖ£¬¸Ã©¶´Ä¿Ç°ÉÐδ±»¹ã·ºÀûÓà ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/cisco-fixes-critical-code-execution-bug-in-jabber-for-windows/


5¡¢Ó¢ÌضûÐû²¼Î¢´úÂëÄþ¾²¸üУ¬Ö÷ÒªÊÊÓÃÓÚWin10ϵÁÐ


5.jpg


MicrosoftÐû²¼ÁËIntel΢´úÂë¸üУ¬ÒÔÐÞ¸´Intel CPUÖеÄÓ²¼þ©¶´ ¡£´Ë´Î¸üÐÂÐû²¼Á˰˸ö¿ÉÑ¡¸üУ¬Ö÷ÒªÕë¶ÔWindows 10 2004¡¢1909¡¢1903¡¢1809¡¢1803¡¢1709¡¢1703ºÍ1607µÈ°æ±¾£¬ÐÞ¸´ÁËAmber Lake¡¢Avoton¡¢BroadwellºÍCascade LakeµÈ56¿îCPUÖЩ¶´ ¡£´ËÍ⣬ӢÌضû΢Âë¸üв¢²»ÄÜͨ¹ýWindows Update°²×°£¬±ØÐëÊÖ¶¯°²×° ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/new-intel-microcode-updates-for-windows-10-fix-cpu-hardware-bugs/