ÐÅÏ¢Çå¾²Öܱ¨-2019ÄêµÚ5ÖÜ

Ðû²¼Ê±¼ä 2019-03-04

±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


2019Äê1ÔÂ28ÈÕÖÁ2ÔÂ03ÈÕ¹²ÊÕ¼Çå¾²Îó²î42¸ö£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇApache Hadoop CVE-2018-1296Çå¾²ÈÆ¹ýÎó²î£»£»£»£»D-Link DIR-823G HNAP1ÇëÇóÏÂÁî×¢ÈëÎó²î£»£»£»£»ACD Systems Canvas Draw CVE-2018-3976»º³åÇøÒç³öÎó²î£»£»£»£»ARM Trusted Firmware-AÐÅϢй¶Îó²î£»£»£»£»Google Chrome PDFium CVE-2019-5772ÊͷźóʹÓôúÂëÖ´ÐÐÎó²î¡£¡£¡£ ¡£

±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇÊý¾ÝÖÎÀí¹«Ë¾RubrikÒâÍâй¶´ó×Ú¿Í»§Êý¾Ý£»£»£»£»FaceTimeÆØÖØ´óÇÔÌýÎó²î£¬£¬£¬£¬£¬AppleÌåÏÖ½«ÔÚ±¾ÖÜÐÞ¸´£»£»£»£»Å·ÖÞÍøÂçÐÅÏ¢Çå¾²¾ÖENISAÐû²¼2018ÄêÍøÂçÍþв¾°¹Û±¨¸æ£»£»£»£»Ó¡¶È¹ú¼ÒÒøÐÐSBIÒâÍâй¶Êý°ÙÍò¿Í»§ÐÅÏ¢£»£»£»£»ºÉÀ¼DPAÐû²¼2018ÄêÊý¾Ýй¶ͳ¼Æ±¨¸æ¡£¡£¡£ ¡£

ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£ ¡£

Ö÷ÒªÇå¾²Îó²îÁбí


1. Apache Hadoop CVE-2018-1296Çå¾²ÈÆ¹ýÎó²î
Apache Hadoop±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬ÈƹýÇå¾²ÏÞÖÆ£¬£¬£¬£¬£¬Ö´ÐÐδÊÚȨµÄ²Ù×÷¡£¡£¡£ ¡£
https://hadoop.apache.org/cve_list.html#cve-2018-8009-http-cve-mitre-org-cgi-bin-cvename-cgi-name-cve-2018-8009-zip-slip-impact-on-apache-hadoop

2. D-Link DIR-823G HNAP1ÇëÇóÏÂÁî×¢ÈëÎó²î
D-Link DIR-823G±£´æ´úÂë×¢ÈëÎó²î£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄHNAP1ÇëÇ󣬣¬£¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐOSÏÂÁî¡£¡£¡£ ¡£
https://github.com/leonW7/D-Link/blob/master/Vul_1.md

3. ACD Systems Canvas Draw CVE-2018-3976»º³åÇøÒç³öÎó²î
ACD Systems Canvas Draw CALS RasterÎļþÆÊÎö¹¦Ð§±£´æÔ½½çдÈëÎó²î£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþÇëÇ󣬣¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬£¬¿ÉʹӦÓóÌÐòÍ߽⻣»£»£»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£ ¡£
https://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0642

4. ARM Trusted Firmware-AÐÅϢй¶Îó²î
ARM Trusted Firmware-A±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬ÔÊÐíÍâµØ¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢¡£¡£¡£ ¡£
https://github.com/ARM-software/arm-trusted-firmware/wiki/Trusted-Firmware-A-Security-Advisory-TFV-8

5. Google Chrome PDFium CVE-2019-5772ÊͷźóʹÓôúÂëÖ´ÐÐÎó²î
Google Chrome PDFium±£´æÊͷźóʹÓÃÎó²î£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄWEBÒ³ÇëÇ󣬣¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬£¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢¡£¡£¡£ ¡£
https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html

 Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢Êý¾ÝÖÎÀí¹«Ë¾RubrikÒâÍâй¶´ó×Ú¿Í»§Êý¾Ý

Z6¡¤×ðÁú¿­Ê±¡¸ÖйúÇø¡¹¹Ù·½ÍøÕ¾

Çå¾²Ñо¿Ô±Oliver Hough·¢Ã÷ÊôÓÚÊý¾ÝÖÎÀí¹«Ë¾RubrikµÄÒ»¸öElasticsearchЧÀÍÆ÷δÊÜÃÜÂë±£»£»£»£»¤£¬£¬£¬£¬£¬¸ÃÊý¾Ý¿â´æ´¢ÁËÊýÊ®GBµÄÊý¾Ý£¬£¬£¬£¬£¬°üÀ¨ÆóÒµ¿Í»§µÄÃû³Æ¡¢ÁªÏµÐÅÏ¢ºÍÊÂÇé°¸Àý¡£¡£¡£ ¡£Æ¾Ö¤Ê±¼ä´Á£¬£¬£¬£¬£¬ÕâЩÊý¾Ý¿É×·ËÝÖÁ2018Äê10Ô¡£¡£¡£ ¡£¾­ÓÉÊӲ죬£¬£¬£¬£¬Rubrik³ÆÕâÒ»ÊÂÎñÊÇÓÉÈËΪ¹ýʧµ¼ÖµÄ¡£¡£¡£ ¡£

Ô­ÎÄÁ´½Ó£º
https://techcrunch.com/2019/01/29/rubrik-data-leak/

2¡¢FaceTimeÆØÖØ´óÇÔÌýÎó²î£¬£¬£¬£¬£¬AppleÌåÏÖ½«ÔÚ±¾ÖÜÐÞ¸´

Z6¡¤×ðÁú¿­Ê±¡¸ÖйúÇø¡¹¹Ù·½ÍøÕ¾


¾ÝÍâý±¨µÀ£¬£¬£¬£¬£¬Apple FaceTime±£´æÖØ´óÇå¾²Îó²î£¬£¬£¬£¬£¬¿ÉÔÊÐí¹¥»÷ÕßÔÚÄ¿µÄ½ÓÌý»ò¾Ü¾øFaceTimeͨ»°Ö®Ç°¼àÌý¶Ô·½µÄÉùÒô¡£¡£¡£ ¡£ÈôÊǶԷ½°´ÏÂÒôÁ¿½µµÍ°´Å¥»òµçÔ´°´Å¥À´¾²Òô»ò×÷·Ïͨ»°£¬£¬£¬£¬£¬ÔòÆäǰÖÃÉãÏñÍ·Ò²»á·­¿ª£¬£¬£¬£¬£¬²¢½«ÊÓÆµÐźŷ¢Ë͸ø¹¥»÷Õß¡£¡£¡£ ¡£¾ÝϤ£¬£¬£¬£¬£¬¸ÃÎó²î»á·ºÆðÔÚiOS 12.1»ò¸ü¸ß°æ±¾µÄiOS×°±¸ÖС£¡£¡£ ¡£AppleÒѾ­ÔÝʱ½ûÓÃÁËFaceTimeÖеÄȺ×éͨ»°¹¦Ð§£¬£¬£¬£¬£¬²¢ÌåÏÖ½«ÔÚ±¾ÖÜÍíЩʱ¼äÐû²¼ÐÞ¸´²¹¶¡¡£¡£¡£ ¡£

Ô­ÎÄÁ´½Ó£º
https://thehackernews.com/2019/01/apple-facetime-privacy-hack.html

3¡¢Å·ÖÞÍøÂçÐÅÏ¢Çå¾²¾ÖENISAÐû²¼2018ÄêÍøÂçÍþв¾°¹Û±¨¸æ

Z6¡¤×ðÁú¿­Ê±¡¸ÖйúÇø¡¹¹Ù·½ÍøÕ¾


Å·ÖÞÍøÂçÐÅÏ¢Çå¾²¾Ö£¨ENISA£©Ðû²¼2018ÄêÍþв¾°¹Û±¨¸æ£¬£¬£¬£¬£¬¸Ã±¨¸æÖصãÏÈÈÝÁË2018ÄêµÄÍøÂçÍþвÇ÷ÊÆ×ª±ä£¬£¬£¬£¬£¬°üÀ¨µç×ÓÓʼþºÍ´¹ÂÚ¶ÌÐÅÒѾ­³ÉΪÖ÷ÒªµÄ¶ñÒâÈí¼þѬȾǰÑÔ£»£»£»£»¶ñÒâ¿ó¹¤³ÉΪ·¸·¨·Ö×ÓµÄÖ÷Ҫ׬ǮÊֶΣ»£»£»£»¹ú¼Ò×ÊÖúµÄ·¸·¨ÍÅ»ïÔ½À´Ô½¶àµØÃé×¼ÒøÐУ»£»£»£»ÓÉÓÚȱ°±ÉͶËÎïÁªÍø×°±¸ºÍЧÀ͵ı£»£»£»£»¤»úÖÆ£¬£¬£¬£¬£¬¶ÔͨÓÃÎïÁªÍø±£»£»£»£»¤¼Ü¹¹/ÓÅÒìʵ¼ùµÄÐèÇóÈÔÈ»ÊÇÒ»¸ö½ôÆÈµÄÎÊÌ⣻£»£»£»ÍþвÇ鱨ÐèҪʹÓÃеÄ×Ô¶¯»¯¹¤¾ßºÍÒªÁìÀ´Ó¦¶Ô×Ô¶¯»¯µÄ¹¥»÷£»£»£»£»Çå¾²ÁìÓòÓ¦¸ÃÖØµã¹Ø×¢È˲źÍÊÖÒÕµÄÅàѵ¡£¡£¡£ ¡£¸Ã±¨¸æ»¹´ÓÕþ²ß¡¢ÆóÒµÒÔ¼°ÊÖÒÕ¡¢Ñо¿ºÍ½ÌÓý·½ÃæÌá³öÁ˽¨Òé¡£¡£¡£ ¡£

Ô­ÎÄÁ´½Ó£º
https://www.enisa.europa.eu/publications/enisa-threat-landscape-report-2018/

4¡¢Ó¡¶È¹ú¼ÒÒøÐÐSBIÒâÍâй¶Êý°ÙÍò¿Í»§ÐÅÏ¢

Z6¡¤×ðÁú¿­Ê±¡¸ÖйúÇø¡¹¹Ù·½ÍøÕ¾


ÄäÃûÇå¾²Ñо¿Ö°Ô±·¢Ã÷һ̨ÓÃÓÚÒøÐмÓËÙЧÀ͵ÄЧÀÍÆ÷£¬£¬£¬£¬£¬ÕâÊÇÒ»ÖÖ»ùÓÚÒÆ¶¯µÄÐÅϢЧÀÍ¡£¡£¡£ ¡£¸ÃÊý¾Ý¿âÔÚûÓб£»£»£»£»¤µÄÇéÐÎϱ»¹ûÕæ£¬£¬£¬£¬£¬¸ÃÊý¾Ý¿â°üÀ¨Êý°ÙÍòÌõ¶ÌÐÅ£¬£¬£¬£¬£¬¿É×·Ëݵ½12Ô·Ý£¬£¬£¬£¬£¬°üÀ¨¿Í»§µÄµç»°ºÅÂ룬£¬£¬£¬£¬²¿·ÖÒøÐÐÕ˺Å£¬£¬£¬£¬£¬ÒøÐÐÓà¶îºÍÉúÒâ¼Í¼¡£¡£¡£ ¡£ºÃÐÂÎÅÊÇ£¬£¬£¬£¬£¬Ó¡¶È¹ú¼ÒÒøÐÐÔÚµÃÖªÎÊÌâºóÊýСʱÄÚѸËÙ½â¾öÁËÕâ¸öÎÊÌ⣬£¬£¬£¬£¬Òź¶µÄÊÇ£¬£¬£¬£¬£¬²»ÖªµÀÊý¾ÝÔÚÍøÉÏ̻¶Á˶೤ʱ¼ä¡£¡£¡£ ¡£ÕâЩÐÅÏ¢µÄ¿ÉÓÃÐÔ¸øÒøÐпͻ§´øÀ´ÁËÑÏÖØµÄΣº¦£¬£¬£¬£¬£¬ÍþвÐÐΪÕß¿ÉÒÔʹÓÃËüÀ´Ãé×¼ÒøÐпͻ§¡£¡£¡£ ¡£

Ô­ÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/80555/data-breach/state-bank-of-india-leak.html

5¡¢ºÉÀ¼DPAÐû²¼2018ÄêÊý¾Ýй¶ͳ¼Æ±¨¸æ

Z6¡¤×ðÁú¿­Ê±¡¸ÖйúÇø¡¹¹Ù·½ÍøÕ¾


2019Äê1ÔÂ29ÈÕ£¬£¬£¬£¬£¬ºÉÀ¼Êý¾Ý±£»£»£»£»¤¾Ö£¨Autoriteit Persoonsgegevens£¬£¬£¬£¬£¬¡°ºÉÀ¼DPA¡±£©½ÒÏþÁËÒ»·Ý±¨¸æ¹ØÓÚ2018ÄêÊÕµ½µÄСÎÒ˽¼ÒÊý¾Ýй¶֪ͨ£¨¡°±¨¸æ¡±£©¡£¡£¡£ ¡£Å·ÃËͨÓÃÊý¾Ý±£»£»£»£»¤¹æÔò£¨¡°GDPR¡±£©ÒªÇóÊý¾ÝÖÎÀíÔ±ÔÚ֪ϤºóµÄ72СʱÄÚ½«Êý¾Ýй¶֪ͨÖ÷¹ÜÊý¾Ý±£»£»£»£»¤¾Ö£¨¡°DPA¡±£©¡£¡£¡£ ¡£ÔÚºÉÀ¼£¬£¬£¬£¬£¬×Ô2016Äê1ÔÂ1ÈÕÆð£¬£¬£¬£¬£¬¸ÃÎ¥¹æÍ¨ÖªÒªÇóÒѾ­ÊµÑé¡£¡£¡£ ¡£¿ÉÊÇ£¬£¬£¬£¬£¬GDPR»®¶¨ÁËÌØÁíÍâÒªÇ󣬣¬£¬£¬£¬°üÀ¨£ºÔÚÎ¥¹æÍ¨ÖªÖÐÌṩijЩÐÅÏ¢; ÈôÊÇÎ¥¹æÐÐΪ¿ÉÄܶÔÕâЩÈ˵ÄȨÁ¦ºÍ×ÔÓÉÔì³É¸ßΣº¦£¬£¬£¬£¬£¬Êý¾ÝÖÎÀíÔ±ÓÐÒåÎñ֪ͨÊÜÓ°ÏìµÄСÎÒ˽¼Ò; ¹«Ë¾ÓÐÒåÎñ¼Í¼ÈκÎСÎÒ˽¼ÒÊý¾Ýй¶ÊÂÎñ¡£¡£¡£ ¡£2018Ä꣬£¬£¬£¬£¬ºÉÀ¼DPAÊÕµ½µÄÊý¾Ýй¶֪ͨÊýÄ¿ÔöÌíÁËÒ»±¶£¬£¬£¬£¬£¬¹²¼Æ20,881´ÎÎ¥¹æÍ¨Öª¡£¡£¡£ ¡£ÊÜÓ°Ïì×î´óµÄ²¿·ÖÊÇ¿µ½¡ºÍ¸£Àû²¿·Ö£¨×ª´ïµÄÎ¥¹æÐÐΪµÄ29£¥£©£¬£¬£¬£¬£¬½ðÈÚ²¿·Ö£¨Í¨ÖªµÄÎ¥¹æÐÐΪµÄ26£¥£©ºÍ¹«¹²²¿·Ö£¨17£¥µÄÎ¥¹æÍ¨Öª£©¡£¡£¡£ ¡£

Ô­ÎÄÁ´½Ó£º
https://www.databreaches.net/dutch-dpa-publishes-2018-report-on-data-breach-statistics/

ÉùÃ÷£º±¾×ÊѶÓÉZ6×ðÁú¿­Ê±Î¬ËûÃüÇ徲С×é·­ÒëºÍÕûÀí