ÐÅÏ¢Äþ¾²Öܱ¨-2020ÄêµÚ36ÖÜ
Ðû²¼Ê±¼ä 2020-09-08> ±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö
2020Äê08ÔÂ31ÈÕÖÁ09ÔÂ06ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´56¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇGigadevice GD32F103´úÂëÖ´ÐЩ¶´£»Gigadevice GD32F103¹Ì¼þÌáȡ©¶´£»NETGEAR R8300ÃüÁî×¢È멶´£»Education openSIS SQL×¢È멶´£»Education openSIS EmailCheck.php SQL×¢È멶´¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊǹ¤ÐŲ¿Í¨±¨101¿îAPPÇÖ·¸Óû§È¨Ò棬ÇáËɳïµÈƽ̨ÉÏ°ñ£»Å²ÍþÒé»áÓʼþϵͳÔâ¹¥»÷£¬¹¤µ³ºÍÖÐÐĵ³¾ùÊÜÓ°Ï죻Cisco¾¯¸æÆäIOS XR´æÔÚ0day²¢Òѱ»ÔÚÒ°ÀûÓã»Cisco Jabber´æÔÚÔ¶³ÌÖ´ÐдúÂ멶´£¬ÏÖÒѱ»ÐÞ¸´£»Ó¢ÌضûÐû²¼Î¢´úÂëÄþ¾²¸üУ¬Ö÷ÒªÊÊÓÃÓÚWin10ϵÁС£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£
> ÖØÒªÄþ¾²Â©¶´Áбí
1.Gigadevice GD32F103´úÂëÖ´ÐЩ¶´
Gigadevice GD32F103Äþ¾²±£»¤´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÎïÀíÄÜ·ÃÎʹ¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó£¬Öض¨Ïò¿ØÖÆÁ÷Ö´ÐÐÈÎÒâ´úÂë¡£
https://www.usenix.org/system/files/woot20-paper-obermaier.pdf
2. Gigadevice GD32F103¹Ì¼þÌáȡ©¶´
Gigadevice GD32F103ÉÁ´æ¶Á³ö±£»¤´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÎïÀíÄÜ·ÃÎʹ¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ɴӵ÷ÊÔ½Ó¿Ú»ñÈ¡¹Ì¼þ¡£
https://www.usenix.org/system/files/woot20-paper-obermaier.pdf
3.NETGEAR R8300ÃüÁî×¢È멶´
NETGEAR R8300´æÔÚÊäÈëÑé֤©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£
https://kb.netgear.com/000062158/Security-Advisory-for-Pre-Authentication-Command-Injection-on-R8300-PSV-2020-0211
4. Education openSIS SQL×¢È멶´
Open Solutions for Education openSIS´æÔÚSQL×¢È멶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄSQLÇëÇ󣬲Ù×÷Êý¾Ý¿â£¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢»òÖ´ÐÐÈÎÒâ´úÂë¡£
https://talosintelligence.com/vulnerability_reports/TALOS-2020-1081
5. Education openSIS EmailCheck.php SQL×¢È멶´
Open Solutions for Education EmailCheck.php´æÔÚSQL×¢È멶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄSQLÇëÇ󣬲Ù×÷Êý¾Ý¿â£¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢»òÖ´ÐÐÈÎÒâ´úÂë¡£¡£
https://talosintelligence.com/vulnerability_reports/TALOS-2020-1073
> ÖØÒªÄþ¾²Ê¼þ×ÛÊö
1¡¢¹¤ÐŲ¿Í¨±¨101¿îAPPÇÖ·¸Óû§È¨Ò棬ÇáËɳïµÈƽ̨ÉÏ°ñ
¹¤ÒµºÍÐÅÏ¢»¯²¿¹ÙÍøÐû²¼¹ØÓÚÇÖº¦Óû§È¨ÒæÐÐΪµÄAPPͨ±¨¡£µ°¿Ç¹«Ô¢¡¢ÇáËɳ±¦±¦Ê÷ÔÐÓý¡¢ZAKERÐÂÎÅ¡¢ÍøÒ×¹ûÈ»¿Î¡¢¼Ý¿¼±¦µä¡¢ÃÀÀö˵¡¢ÂìÒ϶Ì×â¡¢¿ì¼ô¼¡¢360ÇåÀí´óʦ¡¢µÃÎï¡¢ËѺüÊÓƵ¡¢Ó³¿ÍÖ±²¥µÈ101¿îAPP´æÔÚÇÖº¦Óû§È¨ÒæÐÐΪ¡£ÕâЩӦÓÃÈí¼þÖ÷ÒªÉæ¼°ÎÊÌâÊÇÎ¥¹æÊÕ¼¯¸öÈËÐÅÏ¢£¬ÁíÍ⻹Éæ¼°APPÇ¿ÖÆ¡¢Æµ·±¡¢¹ý¶ÈË÷ȡȨÏÞ£¬Ç¿ÖÆÓû§Ê¹Óö¨ÏòÍÆË͹¦Ð§£¬³¬·¶Î§ÊÕ¼¯¸öÈËÐÅÏ¢µÈÎÊÌâ¡£
ÔÎÄÁ´½Ó£º
http://tech.cnr.cn/techgd/20200831/t20200831_525234083.shtml
2¡¢Å²ÍþÒé»áÓʼþϵͳÔâ¹¥»÷£¬¹¤µ³ºÍÖÐÐĵ³¾ùÊÜÓ°Ïì
ŲÍþÒé»á£¨Storting£©Ðû²¼ÉùÃ÷£¬ÌåÏÖÓкڿ͹¥»÷Æä³ÉÔ±µÄµç×ÓÓʼþÕÊ»§²¢ÇÔÈ¡Êý¾Ý¡£¸ÃʼþÕýÔÚÊÓ²ìÖУ¬Ä¿Ç°Éв»Çå³þ±»µÁÊý¾ÝµÄÊýÁ¿¡¢ÖÖÀàÒÔ¼°¹¥»÷µÄÆÆ»µË®Æ½¡£Å²Íþ¹¤µ³µÄJarle RoheimH?konsen֤ʵ£¬¹¤µ³³ÉÔ±ºÍÕþ¿ÍÔÚÕâ´Î¹¥»÷ÖоùÊܵ½Ó°Ï죬ͬʱÖÐÐĵ³Ò²È·ÈÏÆä´ú±íºÍÔ±¹¤Êܵ½ÁËÓ°Ïì¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/hackers-breached-norwegian-parliament-emails-to-steal-data/
3¡¢Cisco¾¯¸æÆäIOS XR´æÔÚ0day²¢Òѱ»ÔÚÒ°ÀûÓÃ
˼¿ÆÉÏÖÜÁù¾¯¸æ˵£¬ÆäIOS XR´æÔÚÒ»¸öеÄ0day£¬Ä¿Ç°Òѱ»ºÚ¿ÍÔÚÒ°ÀûÓ᣸鶴±»¸ú×ÙCVE-2020-3566£¬Ó°ÏìÁ˲Ù×÷ϵͳIOS XR°æ±¾¸½´øµÄ¾àÀëʸÁ¿×鲥·ÓÉÐÒé(DVMRP)¹¦Ð§£¬¸Ã°æ±¾µÄ²Ù×÷ϵͳͨ³£°²×°ÔÚµçÐż¶ºÍÊý¾ÝÖÐÐÄ·ÓÉÆ÷ÉÏ¡£Ë¼¿ÆÌåÏÖ£¬¸Ã©¶´ÊÇÓÉÓÚInternet×é¹ÜÀíÐÒ飨IGMP£©Êý¾Ý°üµÄÐÐÁйÜÀí²»×ãËùÖ£¬¹¥»÷Õß¿ÉÒÔͨ¹ý·¢ËÍÌØÖƵÄIGMPÁ÷Á¿À´ÀûÓôË©¶´¡£ÀÖ³ÉÀûÓø鶴¿Éµ¼ÖÂÄÚ´æºÄ¾¡£¬´Ó¶øµ¼ÖÂÆäËû½ø³Ì£¨ÈçÄÚ²¿ºÍÍⲿ·ÓÉÐÒ飩²»Îȶ¨¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/cisco-warns-of-actively-exploited-ios-xr-zero-day/
4¡¢Cisco Jabber´æÔÚÔ¶³ÌÖ´ÐдúÂ멶´£¬ÏÖÒѱ»ÐÞ¸´
WatchcomµÄOlav Sortland Thoresen·¢ÏÖWindows°æCisco JabberÖдæÔÚÑÏÖصĴúÂëÖ´ÐЩ¶´£¬ÏÖÒѱ»ÐÞ¸´¡£¸Ã©¶´±»¸ú×ÙΪCVE-2020-3495£¬ CVSSΪ9.9·Ö£¬ÊÇÓÉÓÚ´«ÈëÏûÏ¢ÄÚÈݵÄÊäÈëÑéÖ¤²»ÕýÈ·ÒýÆðµÄ¡£¾¹ýÉí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓöñÒâµÄ¿ÉÀ©Õ¹ÏûÏ¢ºÍ״̬ÐÒ飨XMPP£©ÏûÏ¢ÀûÓø鶴£¬ÀÖ³ÉÀûÓú󹥻÷Õß¿ÉÔÚÄ¿±êϵͳÉÏÖ´ÐÐÈÎÒⷨʽ¡£Ë¼¿Æ²úÎïÄþ¾²Ê¼þÏìӦС×飨PSIRT£©ÌåÏÖ£¬¸Ã©¶´Ä¿Ç°ÉÐδ±»¹ã·ºÀûÓá£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/cisco-fixes-critical-code-execution-bug-in-jabber-for-windows/
5¡¢Ó¢ÌضûÐû²¼Î¢´úÂëÄþ¾²¸üУ¬Ö÷ÒªÊÊÓÃÓÚWin10ϵÁÐ
MicrosoftÐû²¼ÁËIntel΢´úÂë¸üУ¬ÒÔÐÞ¸´Intel CPUÖеÄÓ²¼þ©¶´¡£´Ë´Î¸üÐÂÐû²¼Á˰˸ö¿ÉÑ¡¸üУ¬Ö÷ÒªÕë¶ÔWindows 10 2004¡¢1909¡¢1903¡¢1809¡¢1803¡¢1709¡¢1703ºÍ1607µÈ°æ±¾£¬ÐÞ¸´ÁËAmber Lake¡¢Avoton¡¢BroadwellºÍCascade LakeµÈ56¿îCPUÖЩ¶´¡£´ËÍ⣬ӢÌضû΢Âë¸üв¢²»ÄÜͨ¹ýWindows Update°²×°£¬±ØÐëÊÖ¶¯°²×°¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/microsoft/new-intel-microcode-updates-for-windows-10-fix-cpu-hardware-bugs/