ÐÅÏ¢Äþ¾²Öܱ¨-2021ÄêµÚ45ÖÜ

Ðû²¼Ê±¼ä 2021-11-08

>±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


±¾Öܹ²ÊÕ¼Äþ¾²Â©¶´60¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇCisco Policy Suite¾²Ì¬SSHÃÜԿ©¶´ £»Mozilla Firefox ESR  HTTP2 session objectÄÚ´æ´íÎóÒýÓôúÂëÖ´ÐЩ¶´ £»Apache Traffic Server stats-over-http²å¼þÄÚ´æÁýÕÖ©¶´ £»D-Link DIR-823G HNAP1ÃüÁî×¢È멶´ £»Beckhoff Automation TwinCAT OPC UA ServerĿ¼±éÀú©¶´¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊDz¿ÃÅMacÉ豸Éý¼¶ÖÁmacOS MontereyºóÎÞ·¨Õý³£Æô¶¯ £»Ñо¿ÍŶӷ¢ÏÖ¼¸ºõÍþвËùÓдúÂëµÄ©¶´Trojan Source £»Ñо¿ÍŶӳƽ©Ê¬ÍøÂçPinkÒÑѬȾÁè¼Ý160Íǫ̀ÖйúµÄÉ豸 £»GoogleÐû²¼Android 11Ô¸üУ¬×ܼÆÐÞ¸´39¸ö©¶´ £»BlackMatterÍÅ»ïÐû²¼ÆÈÓÚÖ´·¨²¿ÃŵÄѹÁ¦½«Í£Ö¹ÔËÓª¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£


>ÖØÒªÄþ¾²Â©¶´Áбí


1. Cisco Policy Suite¾²Ì¬SSHÃÜԿ©¶´


Cisco Policy Suite´æÔÚ¾²Ì¬SSHÃÜԿ©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó£¬Î´ÊÚȨ·ÃÎÊϵͳ¡£


https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cps-static-key-JmS92hNv



2. Mozilla Firefox ESR  HTTP2 session objectÄÚ´æ´íÎóÒýÓôúÂëÖ´ÐЩ¶´


Mozilla Firefox ESR  HTTP2 session object´æÔÚÊͷźóʹÓ鶴£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄWEBÇëÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹӦÓ÷¨Ê½±ÀÀ £»òÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£


https://www.mozilla.org/en-US/security/advisories/mfsa2021-49/



3. Apache Traffic Server stats-over-http²å¼þÄÚ´æÁýÕÖ©¶´


Apache Traffic Server stats-over-http²å¼þ´æÔÚÄÚ´æÁýÕÖ©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£


https://lists.apache.org/thread/k01797hyncx53659wr3o72s5cvkc3164



4. D-Link DIR-823G HNAP1ÃüÁî×¢È멶´


D-Link DIR-823G HNAP1´æÔÚÊäÈëÑé֤©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâSHELLÃüÁî¡£


https://www.dlink.com/en/security-bulletin/



5. Beckhoff Automation TwinCAT OPC UA ServerĿ¼±éÀú©¶´


Beckhoff Automation TwinCAT OPC UA Server´æÔÚĿ¼±éÀú©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄ´´½¨»òɾ³ýϵͳÉϵÄÈκÎÎļþ¡£


https://download.beckhoff.com/download/document/product-security/Advisories/advisory-2021-003.pdf



>ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢²¿ÃÅMacÉ豸Éý¼¶ÖÁmacOS MontereyºóÎÞ·¨Õý³£Æô¶¯


½üÆÚ£¬Ô½À´Ô½¶àµÄMacºÍMacbookÓû§³ÂËߣ¬µ±Æä¸üе½ÉÏÖÜÐû²¼µÄ×îаæmacOS Montereyºó£¬É豸ÎÞ·¨Õý³£Æô¶¯¡£´ËÎÊÌâËƺõ½öÓ°ÏìÁË2019Äê֮ǰµÄMacÉ豸£¬²»»áÓ°ÏìʹÓÃM1оƬµÄпîMac¡£´ËÍ⣬ËäÈ»²¿ÃÅÓû§³ÆËûÃǵÄϵͳÒѾ­±äש£¬µ«´ó¶àÊýÓû§¿ÉÒÔͨ¹ýApple Configurator¹¤¾ß»Ö¸´É豸¡£ÆäËûÓû§ÔòÕÒµ½ÁËÁíÒ»ÖÖÒªÁ죬¾ÍÊÇͨ¹ýÆô¶¯DFUÀ´»Ö¸´É豸¡£    


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/apple/macos-monterey-update-causes-some-macs-to-become-unbootable/


2¡¢Ñо¿ÍŶӷ¢ÏÖ¼¸ºõÍþвËùÓдúÂëµÄ©¶´Trojan Source


½£ÇÅ´óѧµÄÑо¿ÈËÔ±ÔÚ11ÔÂ1ÈÕ¹ûÈ»ÁËÒ»¸öÓ°Ïì´ó¶àÊý¼ÆËã»ú´úÂë±àÒëÆ÷ºÍÐí¶àÈí¼þ¿ª·¢»·¾³µÄ©¶´Trojan Source¡£¸Ã©¶´´æÔÚÓÚUnicodeÖУ¬ÓÐÁ½ÖÖÀûÓÃÒªÁ죺ÆäÒ»ÊÇʹÓÃUnicodeµÄBidiËã·¨£¨CVE-2021-42574£©£¬¶Ô×Ö·û½øÐÐÊÓ¾õÉϵÄÖØÐÂÅÅÐò£¬Ê¹Æä·ºÆðÓë±àÒëÆ÷ºÍ½âÊÍÆ÷Ëù²îÒìµÄÂß¼­Ë³Ðò £»ÁíÒ»ÖÖÊÇͬÐÎÎÄ×Ö¹¥»÷(CVE-2021-42694)£¬¼´ÀûÓÃÔÚÊÓ¾õÉÏ¿´ÆðÀ´ÏàËƵIJîÒì×Ö·û¡£¸Ã©¶´ÊÊÓÃÓÚC¡¢C++¡¢C#¡¢JavaScript¡¢JavaµÈ¹ã·ºÊ¹ÓõÄÓïÑÔ£¬¿ÉÓÃÓÚ¹©Ó¦Á´¹¥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://www.trojansource.codes/


3¡¢Ñо¿ÍŶӳƽ©Ê¬ÍøÂçPinkÒÑѬȾÁè¼Ý160Íǫ̀ÖйúµÄÉ豸


Ñо¿ÍŶÓÔÚ10ÔÂ29ÈÕÅû¶ÁËÔÚ¹ýÈ¥ÁùÄê·¢ÏÖµÄ×î´ó½©Ê¬ÍøÂçµÄϸ½Ú¡£ÒòΪÆä´óÁ¿µÄº¯ÊýÃû³ÆÒÔpinkΪÊ×£¬ËùÒÔÈ¡ÃûPinkbot¡£¸Ã½©Ê¬ÍøÂçÒÑѬȾÁËÁè¼Ý160Íǫ̀É豸£¬ÆäÖÐ96%λÓÚÖйú¡£ËüÖ÷ÒªÕë¶Ô»ùÓÚMIPSµÄ¹âÏË·ÓÉÆ÷£¬ÀûÓõÚÈý·½·þÎñµÄ×éºÏ£¬ÀýÈçGitHub¡¢P2PÍøÂçºÍC2·þÎñÆ÷£¬»¹¶Ô²¿ÃÅÓòÃûµÄ½âÎö²éѯ½ÓÄÉÁËDNS-Over-HTTPSµÄ·½Ê½¡£Ñо¿ÈËÔ±³Æ£¬Æù½ñΪֹ£¬PinkBotÌᳫÁ˽ü°Ù´ÎDDoS¹¥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/11/researchers-uncover-pink-botnet-malware.html


4¡¢GoogleÐû²¼Android 11Ô¸üУ¬×ܼÆÐÞ¸´39¸ö©¶´


GoogleÔÚ±¾ÖÜÒ»Ðû²¼ÁËAndroid 11Ô·ݵĸüУ¬×ܼÆÐÞ¸´39¸ö©¶´¡£´Ë´Î¸üÐÂÐÞ¸´ÁËÒ»¸öÒѱ»ÔÚÒ°ÀûÓõÄ0day£¬ÊÇÓÉÊͷźóʹÓõ¼Öµĵ±µØÌáȨ©¶´CVE-2021-1048¡£´ËÍ⣬»¹ÐÞ¸´Á˶à¸öÑÏÖصÄ©¶´£¬°üÂÞÔ¶³Ì´úÂëÖ´ÐЩ¶´CVE-2021-0918ºÍCVE-2021-0930£¬Ó°Ïì¸ßͨ×é¼þµÄCVE-2021-1924ºÍCVE-2021-1975£¬ÒÔ¼°Android TVÔ¶³Ì·þÎñÖеÄÔ¶³Ì´úÂëÖ´ÐЩ¶´CVE-2021-0889µÈ¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/android-patches-exploited-kernel-bug/175931/


5¡¢BlackMatterÍÅ»ïÐû²¼ÆÈÓÚÖ´·¨²¿ÃŵÄѹÁ¦½«Í£Ö¹ÔËÓª


11ÔÂ1ÈÕ£¬ÀÕË÷ÔËÓªÍÅ»ïBlackMatterÔÚÆäÊý¾Ýй¶ÍøÕ¾ÉÏÐû²¼ÏûÏ¢£¬³ÆÆÈÓÚÖ´·¨²¿ÃŵÄѹÁ¦ËûÃǽ«ÔÚ48СʱÄڹرÕÕû¸ö»ù´¡ÉèÊ©¡£Ñо¿ÍŶÓÌåÏÖ£¬Õâ¿ÉÄÜÓë×î½üµÄÒ»´Î¹ú¼ÊÖ´·¨Ðж¯ÓйØ£¬´Ë´ÎÐж¯¹²´þ²¶ÁË12¸öÉæ¼°1800ÆðÀÕË÷¹¥»÷»î¶¯µÄÏÓÒÉÈË¡£È»¶ø£¬¼´Ê¹BlackMatterÏÖÔÚÍ£Ö¹ÆäÔËÓª£¬ÔÚδÀ´Ò²½«»áÒÔеÄÃû³Æ»Ø¹é£¬ÕýÈçBlackMatter×Ô¼º¾ÍÊÇDarkSideÔÚ¹¥»÷Colonial PipelineºóÆÈÓÚѹÁ¦¸üÃû¶øÀ´µÄ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/124135/cyber-crime/blackmatter-ransomware-shutting-down-operations.html