ÐÅÏ¢Çå¾²Öܱ¨-2019ÄêµÚ36ÖÜ

Ðû²¼Ê±¼ä 2019-09-16

> ±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö



2019Äê9ÔÂ09ÈÕÖÁ13ÈÕ¹²ÊÕ¼Çå¾²Îó²î48¸ö£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇDabman & Imperial Web Radio Devices telnetºóÃÅÎó²î £»£»£»Exim³õʼTLSÎÕÊÖí§Òâ´úÂëÖ´ÐÐÎó²î £»£»£»Apache OFBiz template×¢Èë´úÂëÖ´ÐÐÎó²î £»£»£»Adobe Flash Player PSDKÄÚ´æ¹ýʧÒýÓÃÎó²î £»£»£»Microsoft OfficeÄÚ´æÆÆËð´úÂëÖ´ÐÐÎó²î¡£ ¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇDealer LeadsÒâÍâй¶1.98ÒÚÆû³µÂò¼Ò¼Í¼ £»£»£»ÐÂNetCAT¹¥»÷¿É´ÓÓ¢ÌØ¶ûCPUÖÐÇÔÈ¡Êý¾Ý £»£»£»ÃÀ¹ú¹ú¼Ò±ê×¼ÓëÊÖÒÕÑо¿ÔºÐû²¼Òþ˽¿ò¼Ü³õ¸å £»£»£»ºÚ¿ÍʹÓÃDoSÎó²îµ¼ÖÂÃÀ¹úµçÍø·À»ðÇ½ÖØ¸´ÖØÆô £»£»£»Telestar±»ÆØTelnetºóÃÅÎó²îÓ°Ïì100¶àÍòIoT×°±¸¡£ ¡£¡£¡£¡£


ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£ ¡£¡£¡£¡£


> Ö÷ÒªÇå¾²Îó²îÁбí



1. Dabman & Imperial Web Radio Devices telnetºóÃÅÎó²î


Dabman & Imperial Web Radio Devices±£´æÎ´Îĵµ»¯µÄtelnetºóÃÅÎó²î£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬¿ÉδÊÚȨ»á¼ûÓ¦Óᣠ¡£¡£¡£¡£
https://packetstormsecurity.com/files/154416/Dabman-And-Imperial-Web-Radio-Devices-Undocumented-Telnet-Backdoor.html

2. Exim³õʼTLSÎÕÊÖí§Òâ´úÂëÖ´ÐÐÎó²î


Exim´¦Öóͷ£TLSÁ´½ÓµÄ³õʼTLSÎÕÊÖ±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬·¢ËÍÒ»¸öÒÔ¡°\0¡±×îºóµÄSNIÀ´´¥·¢Îó²î£¬£¬£¬£¬£¬Ö´ÐÐí§Òâ´úÂë¡£ ¡£¡£¡£¡£
https://www.kb.cert.org/vuls/id/672565/

3. Apache OFBiz template×¢Èë´úÂëÖ´ÐÐÎó²î


Apache OFBiz±£´ætemplate×¢ÈëÎó²î£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬¿ÉÖ´ÐÐí§Òâ´úÂë¡£ ¡£¡£¡£¡£
https://www.auscert.org.au/bulletins/ESB-2019.3469/

4. Adobe Flash Player PSDKÄÚ´æ¹ýʧÒýÓÃÎó²î


Adobe Flash Player PSDK namespace´¦Öóͷ£¹¤¾ß±£´æÄÚ´æÆÆËðÎó²î£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþÇëÇ󣬣¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ £»£»£»òÖ´ÐÐí§Òâ´úÂë¡£ ¡£¡£¡£¡£
https://www.zerodayinitiative.com/advisories/ZDI-19-818/

5. Microsoft OfficeÄÚ´æÆÆËð´úÂëÖ´ÐÐÎó²î


Microsoft Office´¦Öóͷ£Îĵµ±£´æÄÚ´æÆÆËðÎó²î£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþÇëÇ󣬣¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ £»£»£»òÖ´ÐÐí§Òâ´úÂë¡£ ¡£¡£¡£¡£
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-1264


 > Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö



1¡¢Dealer LeadsÒâÍâй¶1.98ÒÚÆû³µÂò¼Ò¼Í¼


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


Dealer LeadsµÄElasticsearchÊý¾Ý¿âδÊÜÃÜÂë± £»£»£»¤£¬£¬£¬£¬£¬µ¼ÖÂ1.98ÒÚÆû³µÂò¼Ò¼Í¼ÔÚÍøÉÏ̻¶¡£ ¡£¡£¡£¡£Dealer Leadsͨ¹ýSEOÓÅ»¯µÄÄ¿µÄÍøÕ¾ÍøÂçÍøÂçÓйØÇ±ÔÚÂò¼ÒµÄÐÅÏ¢£¬£¬£¬£¬£¬Çå¾²Ñо¿Ô±Jeremiah FowlerÌåÏÖÕâÐ©ÍøÕ¾Îª·Ã¿ÍÌṩ¹º³µÑо¿ÐÅÏ¢ºÍ·ÖÀà¹ã¸æ£¬£¬£¬£¬£¬ÍøÂçµÄÐÅÏ¢±»·¢Ë͸øÆû³µ¾­ÏúÉÌ×÷ΪÏúÊÛÊý¾Ý¡£ ¡£¡£¡£¡£¸Ã̻¶µÄÊý¾Ý¿â×ܹ²°üÀ¨413GBÐÅÏ¢£¬£¬£¬£¬£¬°üÀ¨Ç±ÔÚ¹º³µÕßµÄÐÕÃû¡¢µç×ÓÓʼþµØµã¡¢µç»°ºÅÂë¡¢ÎïÀíµØµã¡¢IPµØµãÒÔ¼°´û¿îºÍ²ÆÎñÊý¾Ý¡¢³µÁ¾ÐÅÏ¢µÈ¡£ ¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://threatpost.com/198m-car-buyer-records-exposed-online/148231/

2¡¢ÐÂNetCAT¹¥»÷¿É´ÓÓ¢ÌØ¶ûCPUÖÐÇÔÈ¡Êý¾Ý


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


Ñо¿Ö°Ô±·¢Ã÷Ò»ÖÖеIJàÐŵÀ¹¥»÷£¬£¬£¬£¬£¬ËüÓ°ÏìÁË×Ô2012ÄêÒÔÀ´ÖÆÔìµÄËùÓÐÏÖ´úÓ¢ÌØ¶ûЧÀÍÆ÷´¦Öóͷ£Æ÷¡£ ¡£¡£¡£¡£¸Ã¹¥»÷±»³ÆÎªNetCAT£¨ÍøÂ绺´æ¹¥»÷£©£¬£¬£¬£¬£¬ÓëÓ¢ÌØ¶ûµÄÊý¾ÝÖ±½ÓI/OÊÖÒÕ£¨DDIO£©ÓйØ£¬£¬£¬£¬£¬DDIOÔÚ×îеÄÓ¢ÌØ¶ûЧÀÍÆ÷¼¶´¦Öóͷ£Æ÷ÖÐĬÈÏ·­¿ª£¬£¬£¬£¬£¬°üÀ¨Intel Xeon E5¡¢E7ºÍSP´¦Öóͷ£Æ÷ϵÁС£ ¡£¡£¡£¡£¸ÃÎó²î£¨CVE-2019-11184£©µÄʹÓÃÄѶȽϸߣ¬£¬£¬£¬£¬¹¥»÷ÕßÐèÒª¾ÙÐÐÉí·ÝÑéÖ¤£¬£¬£¬£¬£¬²¢ÇÒÐèÒªÓëÄ¿µÄϵͳ½¨ÉèÖ±½ÓÍøÂçÅþÁ¬¡£ ¡£¡£¡£¡£Ó¢Ìضû½«¸ÃÎó²îµÄCVSSÆÀ·ÖÈ·¶¨Îª2.6·Ö£¬£¬£¬£¬£¬²¢½¨ÒéÔÚÊÜÓ°ÏìµÄCPUÉϽûÓÃDDIOºÍRDMA¹¦Ð§£¬£¬£¬£¬£¬»òÏÞÖÆ´ÓÍⲿ²»ÊÜÐÅÈεÄÍøÂçÖ±½Ó»á¼ûÒ×Êܹ¥»÷µÄϵͳ¡£ ¡£¡£¡£¡£ÌØÁíÍ⻺½â²½·¥°üÀ¨Ê¹ÓÃÄܹ»¶Ô¿¹×¼Ê±¹¥»÷µÄÈí¼þÄ£¿£¿£¿£¿£¿£¿£¿é»òʹÓúã׼ʱ¼äÑùʽµÄ´úÂë¡£ ¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://thehackernews.com/2019/09/netcat-intel-side-channel.html

3¡¢ÃÀ¹ú¹ú¼Ò±ê×¼ÓëÊÖÒÕÑо¿ÔºÐû²¼Òþ˽¿ò¼Ü³õ¸å

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


ÃÀ¹ú¹ú¼Ò±ê×¼ÓëÊÖÒÕÑо¿Ôº£¨NIST£©Ðû²¼ÁËÒ»¸öÒþ˽¿ò¼Ü³õ¸å£¬£¬£¬£¬£¬Ö¼ÔÚͨ¹ýÆóҵΣº¦ÖÎÀí×ÊÖúÆóÒµ¸ÄÉÆÐ¡ÎÒ˽¼ÒÒþ˽¡£ ¡£¡£¡£¡£NISTÌåÏÖ£¬£¬£¬£¬£¬Òþ˽¿ò¼ÜÖ¼ÔÚͨ¹ýÈý¸öÊÂÏî×ÊÖúÆóÒµ± £»£»£»¤Ð¡ÎÒ˽¼ÒÒþ˽£ºÍ¨¹ýÔÚЧÀͺͲúÆ·ÖÐÖ§³ÖÆ·µÂ¾öÒéÀ´½¨Éè¿Í»§ÐÅÈÎ £»£»£»ÍÆÐкϹæÒåÎñ;ÒÔ¼°Ôö½øÓë¿Í»§ºÍî¿Ïµ»ú¹¹¾ÍÒþ˽ʵ¼ù¾ÙÐÐÏàͬ¡£ ¡£¡£¡£¡£¸ÃÕþ²ß×ñÕÕÍøÂçÇå¾²¿ò¼ÜµÄ½á¹¹£¬£¬£¬£¬£¬Óɽ¹µã¡¢¸Å¿öºÍʵÑé²ã×é³É¡£ ¡£¡£¡£¡£½¹µã²¿·ÖÖ¼ÔÚÔö½ø¹ØÓÚÒþ˽± £»£»£»¤ÔËÓªºÍÆÚÍûЧ¹ûµÄ¶Ô»°£¬£¬£¬£¬£¬¶ø¸Å¿ö²¿·ÖÔòÍÆ½øÖª×ã×é֯ʹÃüºÍÒþ˽¼ÛÖµµÄ»î¶¯ºÍЧ¹ûµÄÓÅÏÈÐò´Î¡£ ¡£¡£¡£¡£ÊµÑé²ãÔò¶Ô×éÖ¯´¦Öóͷ£Òþ˽Σº¦Á÷³ÌµÄ³ä·ÖÐÔ¾ÙÐÐÏàͬºÍ¾öÒéÌṩ֧³Ö¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.executivegov.com/2019/09/nist-issues-preliminary-draft-of-privacy-framework/

4¡¢ºÚ¿ÍʹÓÃDoSÎó²îµ¼ÖÂÃÀ¹úµçÍø·À»ðÇ½ÖØ¸´ÖØÆô


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


±±ÃÀµçÁ¦¿É¿¿ÐÔ¹«Ë¾£¨NERC£©ÉÏÖÜÌåÏÖ½ñÄêÔçЩʱ¼äÓ°ÏìÃÀ¹úµçÍøÊµÌåµÄÍøÂçÇå¾²ÊÂÎñ²¢Ã»ÓÐ×î³õÉèÏëµÄÄÇÑùΣÏÕ¡£ ¡£¡£¡£¡£NERCÔÚÒ»·Ý±¨¸æÖÐÖ¸³ö£¬£¬£¬£¬£¬ºÚ¿ÍÔÚ2019Äê3ÔÂ5ÈÕʹÓÃDoSÎó²îµ¼ÖµçÍø·À»ðǽÔÚ10СʱÄÚÖØ¸´ÖØÆô£¬£¬£¬£¬£¬¸ÃÊÂÎñÖ»Ó°ÏìÁËһЩµÍÓ°Ïì¼¶·¢µçÕ¾µãµÄÍøÂçÍâΧ·À»ðǽ£¬£¬£¬£¬£¬²¢Ã»ÓÐÔì³ÉµçÁ¦¹©Ó¦µÄÈκÎÖÐÖ¹¡£ ¡£¡£¡£¡£ËæºóµÄÆÊÎöÈ·¶¨ÖØÆôÊÇÓÉʹÓÃÒÑÖª·À»ðǽÎó²îµÄÍⲿʵÌåÌᳫµÄ£¬£¬£¬£¬£¬ÔËÓªÉÌ×îÖÕ·¢Ã÷ËûÃÇδÄÜΪÊܵ½¹¥»÷µÄ·À»ðǽӦÓù̼þ¸üУ¬£¬£¬£¬£¬ÔÚ²Ù×÷Ô±°²ÅÅÊʵ±µÄ²¹¶¡ºó£¬£¬£¬£¬£¬·À»ðǽ²»ÔÙÖØÆô¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/cyber-security-incident-at-us-power-grid-entity-linked-to-unpatched-firewalls/


5¡¢Telestar±»ÆØTelnetºóÃÅÎó²îÓ°Ïì100¶àÍòIoT×°±¸

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


±¾ÖÜÒ»Vulnerability-LabÑо¿Ô±Benjamin KunzÅû¶Telestar Digital GmbHÎÞÏßµçIoT×°±¸ÖеÄÁ½¸öÑÏÖØÎó²î£¨CVE-2019-13473ºÍCVE-2019-13474£©£¬£¬£¬£¬£¬¿ÉÔÊÐí¹¥»÷ÕßÔ¶³ÌÐ®ÖÆÏµÍ³¡£ ¡£¡£¡£¡£ÊÜÓ°ÏìµÄ×°±¸°üÀ¨¸Ã¹«Ë¾µÄImperial£¦DabmanϵÁвúÆ·£¬£¬£¬£¬£¬ÆäÖаüÀ¨±ãЯʽÊÕÒô»úºÍDABÁ¢ÌåÉùϵͳ¡£ ¡£¡£¡£¡£ÕâЩ²úÆ·Ö÷ÒªÔÚÅ·ÖÞÏúÊÛ£¬£¬£¬£¬£¬»ùÓÚBusyBox Linux Debian²¢Ê¹ÓÃÀ¶ÑÀºÍ»¥ÁªÍøÅþÁ¬¡£ ¡£¡£¡£¡£Kunz·¢Ã÷ÕâЩװ±¸ÔÚ23¶Ë¿ÚÉÏÆôÓÃÁËTelnetЧÀÍ£¬£¬£¬£¬£¬µ«Ã»ÓÐÎĵµ¼Í¼£¬£¬£¬£¬£¬ÓÉÓÚ½ÓÄÉÁËÈõÃÜÂ룬£¬£¬£¬£¬Ñо¿ÍŶӿÉÒÔÔÚ10·ÖÖÓÄÚ»ñÈ¡root»á¼ûȨÏÞ¡£ ¡£¡£¡£¡£Ñо¿Ö°Ô±³Æ¿ÉÄÜÓÐÁè¼Ý100Íǫ̀װ±¸ÃæÁÙΣº¦¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º
https://www.zdnet.com/article/critical-vulnerabilities-impact-over-a-million-iot-radio-devices/