ÐÅÏ¢Çå¾²Öܱ¨-2019ÄêµÚ27ÖÜ

Ðû²¼Ê±¼ä 2019-07-15

±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö



2019Äê7ÔÂ08ÈÕÖÁ14ÈÕ¹²ÊÕ¼Çå¾²Îó²î54¸ö£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇFastjsoní§Òâ´úÂëÖ´ÐÐÎó²î£» £»£»£»£» £»Apache Solr·´ÐòÁл¯Ô¶³Ì´úÂëÖ´ÐÐÎó²î£» £»£»£»£» £»Cesanta Mongoose ¡®mq_parse_http¡¯ º¯Êý»º³åÇøÒç³öÎó²î£» £»£»£»£» £»Microsoft Azure DevOps Server CVE-2019-1072´úÂëÖ´ÐÐÎó²î£» £»£»£»£» £»Microsoft SQL Server CVE-2019-1068ÄÚ´æÆÆËð´úÂëÖ´ÐÐÎó²î¡£¡£ ¡£¡£



±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇ¹ã¸æÈí¼þAgent SmithѬȾԼ2500Íǫ̀Android×°±¸£» £»£»£»£» £»Ï£À°¶¥¼¶ÓòÃû×¢²áÉÌICS-ForthÔâºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬£¬DNS¼Í¼±»¸Ä¶¯£» £»£»£»£» £»ÍòºÀÒòÊý¾ÝÐ¹Â¶ÃæÁÙÓ¢¹úî¿Ïµ»ú¹¹1.23ÒÚÃÀÔª·£¿£¿£¿£¿£¿£¿î£» £»£»£»£» £»ÊÓÆµ¾Û»áÈí¼þZoom RCEÎó²î£¬£¬£¬£¬£¬£¬¿ÉÐ®ÖÆMacÉãÏñÍ·£» £»£»£»£» £»Ó¢¹úº½¿Õ¹«Ë¾ÒòÊý¾ÝÐ¹Â¶ÃæÁÙ1.83ÒÚÓ¢°÷·£¿£¿£¿£¿£¿£¿î¡£¡£ ¡£¡£


ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£ ¡£¡£



Ö÷ÒªÇå¾²Îó²îÁбí



1. Fastjsoní§Òâ´úÂëÖ´ÐÐÎó²î


Fastjson autotype±£´æ·´ÐòÁл¯Îó²î£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£ ¡£¡£
https://github.com/alibaba/fastjson/wiki/update_faq_20190722

2. Apache Solr·´ÐòÁл¯Ô¶³Ì´úÂëÖ´ÐÐÎó²î


Apache Solr Config API´¦Öóͷ£POSTÇëÇóÉèÖÃJMXЧÀÍÆ÷±£´æ·´ÐòÁл¯Îó²î£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬¿ÉÖ´ÐÐí§Òâ´úÂë¡£¡£ ¡£¡£
https://seclists.org/oss-sec/2019/q1/169

3. Cesanta Mongoose ¡®mq_parse_http¡¯ º¯Êý»º³åÇøÒç³öÎó²î


Cesanta Mongoose mongoose.cÎļþµÄ¡®mq_parse_http¡¯ º¯Êý±£´æ»º³åÇøÒç³öÎó²î£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬¿ÉʹӦÓóÌÐòÍ߽⻠£»£»£»£» £»òÖ´ÐÐí§Òâ´úÂë¡£¡£ ¡£¡£
https://github.com/cesanta/mongoose/pull/1035

4. Microsoft Azure DevOps Server CVE-2019-1072´úÂëÖ´ÐÐÎó²î


Microsoft Azure DevOps Server´¦Öóͷ£ÌØÊâÎļþ±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬¿ÉÒÔTFS ЧÀÍÕÊ»§µÄÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£ ¡£¡£
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-1072

5. Microsoft SQL Server CVE-2019-1068ÄÚ´æÆÆËð´úÂëÖ´ÐÐÎó²î


Microsoft SQL ServerÄÚ²¿º¯Êý´¦Öóͷ£±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬¿ÉÒÔ SQL ServerÊý¾Ý¿âÒýÇæÐ§ÀÍÕË»§ÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£ ¡£¡£
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-1068


 Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö



1¡¢¹ã¸æÈí¼þAgent SmithѬȾԼ2500Íǫ̀Android×°±¸


Z6¡¤×ðÁú¿­Ê±¡¸ÖйúÇø¡¹¹Ù·½ÍøÕ¾


Check PointÑо¿Ö°Ô±·¢Ã÷ԼĪÓÐ2500Íǫ̀Android×°±¸Òѱ»ÐÂ¹ã¸æÈí¼þAgent SmithѬȾ¡£¡£ ¡£¡£¸Ã¶ñÒâÈí¼þÓÃÓÚÏòÓû§µÄÊÖ»úÍÆËÍ¹ã¸æ£¬£¬£¬£¬£¬£¬µ«¹¥»÷ÕßÒ²¿ÉÄܽ«ÆäÓÃÓÚ¸ü¶ñÒâµÄÄ¿µÄ£¬£¬£¬£¬£¬£¬ÀýÈçÇÔÈ¡ÒøÐÐÆ¾Ö¤¡£¡£ ¡£¡£ÎªÁËÍê³É¸üÐÂ×°ÖÃÀú³Ì£¬£¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þʹÓÃÁËJanusÎó²î£¬£¬£¬£¬£¬£¬ÒÔÈÆ¹ýÓ¦ÓóÌÐòµÄÊðÃû²¢ÏòÆäÌí¼Óí§Òâ´úÂë¡£¡£ ¡£¡£ÊÜѬȾװ±¸ÊýÄ¿×î¶àµÄ¹ú¼ÒÊÇÓ¡¶È£¨Áè¼Ý1500Íǫ̀£©£¬£¬£¬£¬£¬£¬Æä´ÎÊÇÃϼÓÀ­¹ú£¨Áè¼Ý250Íǫ̀£©ºÍ°Í»ù˹̹£¨½ü170Íǫ̀£©¡£¡£ ¡£¡£Æ¾Ö¤Check PointµÄÊÓ²ìЧ¹û£¬£¬£¬£¬£¬£¬Agent Smith×îÔçÓÚ2016ÄêÍ·×îÏȻ£¬£¬£¬£¬£¬£¬Á½ÄêÀ´ËüÖ÷Ҫͨ¹ýµÚÈý·½Ó¦ÓÃÊÐËÁ9apps.comÈö²¥¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/25-million-android-devices-infected-by-agent-smith-malware/

2¡¢Ï£À°¶¥¼¶ÓòÃû×¢²áÉÌICS-ForthÔâºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬£¬DNS¼Í¼±»¸Ä¶¯


Z6¡¤×ðÁú¿­Ê±¡¸ÖйúÇø¡¹¹Ù·½ÍøÕ¾


Ï£À°¶¥¼¶ÓòÃû×¢²áÉÌICS-ForthÔâºÚ¿Í¹¥»÷¡£¡£ ¡£¡£ICS-ForthÈÏÕæÖÎÀíÏ£À°µÄ¶¥¼¶ÓòÃû.grºÍ.el£¬£¬£¬£¬£¬£¬¸Ã×é֯ȷÈÏÔâµ½ºÚ¿ÍÈëÇÖ¡£¡£ ¡£¡£¹¥»÷ÕßÓë˼¿ÆTalos4Ô·ݵı¨¸æÖÐÐÎòµÄ×éÖ¯Ïàͬ£¬£¬£¬£¬£¬£¬¼´·¸·¨ÍÅ»ïSea Turtle¡£¡£ ¡£¡£¸Ã×é֯ʹÓÃÒ»ÖÖÏà¶Ô½ÏеÄÒªÁì¹¥»÷Ä¿µÄ£¬£¬£¬£¬£¬£¬ËûÃDz»»áÖ±½ÓÕë¶ÔÄ¿µÄ£¬£¬£¬£¬£¬£¬¶øÊÇÈëÇÖÓòÃû×¢²áÉÌ»òDNSÍйÜЧÀÍÉ̵ÄÕË»§£¬£¬£¬£¬£¬£¬ÐÞ¸ÄÄ¿µÄ¹«Ë¾µÄDNSÉèÖ㬣¬£¬£¬£¬£¬´Ó¶ø½«Ä¿µÄ¹«Ë¾µÄÓ¦ÓóÌÐò»òµç×ÓÓʼþµÄÁ÷Á¿Öض¨ÏòÖÁ¹¥»÷ÕßµÄЧÀÍÆ÷£¬£¬£¬£¬£¬£¬Ö´ÐÐÖÐÐÄÈ˹¥»÷²¢×èµ²µÇ¼ƾ֤¡£¡£ ¡£¡£ÕâÖÖ¹¥»÷Ò»Á¬Ê±¼ä½Ï¶Ì£¬£¬£¬£¬£¬£¬ÔÚÊýСʱÖÁÊýÌìÖ®¼ä£¬£¬£¬£¬£¬£¬ÓÉÓÚ´ó´ó¶¼¹«Ë¾Ã»ÓйØ×¢DNSÉèÖõĸü¸Ä£¬£¬£¬£¬£¬£¬Òò´ËÕâÖÖ¹¥»÷ÄÑÒÔ±»²ì¾õ¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/hackers-breached-greeces-top-level-domain-registrar/

3¡¢ÍòºÀÒòÊý¾ÝÐ¹Â¶ÃæÁÙÓ¢¹úî¿Ïµ»ú¹¹1.23ÒÚÃÀÔª·£¿£¿£¿£¿£¿£¿î


Z6¡¤×ðÁú¿­Ê±¡¸ÖйúÇø¡¹¹Ù·½ÍøÕ¾


Ó¢¹úÊý¾Ý±£» £»£»£»£» £»¤»ú¹¹ÖܶþÌåÏÖ½«ÏòÍòºÀ´¦ÒÔ9900ÍòÓ¢°÷£¨ºÏ1.23ÒÚÃÀÔª£©µÄ·£¿£¿£¿£¿£¿£¿î£¬£¬£¬£¬£¬£¬Ôµ¹ÊÔ­ÓÉÊÇ2018Äê11ÔÂÍòºÀÆìÏÂϲ´ïÎÝÂùݵĻáÔ±Êý¾Ýй¶ÊÂÎñ¡£¡£ ¡£¡£¾ÝÐÅϢרԱ°ì¹«ÊÒ£¨ICO£©³Æ£¬£¬£¬£¬£¬£¬Å·ÖÞ31¸ö¹ú¼ÒµÄ½ü3000ÍòסÃñºÍ700ÍòÓ¢¹úסÃñÊܵ½ÍòºÀÊý¾Ýй¶µÄÓ°Ïì¡£¡£ ¡£¡£ÕâÊÇÒÑÍùÁ½ÌìÄÚ±¬·¢µÄµÚ¶þÆðÕë¶ÔÊý¾Ýй¶µÄÖØ´ó·£¿£¿£¿£¿£¿£¿î֪ͨ¡£¡£ ¡£¡£ÍòºÀÌåÏÖ¶ÔÐÅϢרԱ°ì¹«ÊҵľöÒé¸ÐӦʧÍû£¬£¬£¬£¬£¬£¬ÔÚ±»´¦ÒÔ·£¿£¿£¿£¿£¿£¿î֮ǰ£¬£¬£¬£¬£¬£¬Ëü¡°ÓÐȨ×ö³ö»ØÓ¦¡±£¬£¬£¬£¬£¬£¬²¢¡°ÍýÏë×ö³ö»ØÓ¦ÇÒÆð¾¢º´ÎÀ¡±×Ô¼ºµÄ̬¶È¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2019/07/marriott-data-breach-gdpr.html

4¡¢ÊÓÆµ¾Û»áÈí¼þZoom RCEÎó²î£¬£¬£¬£¬£¬£¬¿ÉÐ®ÖÆMacÉãÏñÍ·


Z6¡¤×ðÁú¿­Ê±¡¸ÖйúÇø¡¹¹Ù·½ÍøÕ¾


Çå¾²Ñо¿Ö°Ô±Jonathan LeitschuhÅû¶ÊÓÆµ¾Û»áÈí¼þZoomÖеÄÒ»¸öRCEÎó²î£¬£¬£¬£¬£¬£¬¸ÃÎó²îÓ°ÏìÁËMacƽ̨ÉϵÄZoom app°æ±¾4.4.4£¬£¬£¬£¬£¬£¬¿ÉÔÊÐí¹¥»÷ÕßÔÚÓû§»á¼ûÍøÕ¾Ê±½ÓÊÜÍøÂçÉãÏñÍ·¡£¡£ ¡£¡£Æ¾Ö¤LeitschuhµÄ˵·¨£¬£¬£¬£¬£¬£¬Áè¼Ý400ÍòÓû§ÃæÁÙΣº¦¡£¡£ ¡£¡£¸ÃÎó²îʹÓÃÁËZoomÈí¼þµÄµã»÷¼ÓÈ빦Ч£¬£¬£¬£¬£¬£¬¼´Ö»Ðèµã»÷Ô¼ÇëÁ´½Ó¼´¿É×Ô¶¯¼¤»îϵͳÉÏ×°ÖõÄÓ¦ÓóÌÐò²¢Í¨¹ýWebä¯ÀÀÆ÷¼ÓÈëÊÓÆµ¾Û»á¡£¡£ ¡£¡£¹¥»÷Õß¿Éͨ¹ý´¹ÂÚÓʼþ·Ö·¢ÕâÖÖ¶ñÒâÁ´½Ó¡£¡£ ¡£¡£Leitschuh»¹ÌåÏÖZoomµÄÐÞ¸´Ö»ÊÇ×èÖ¹¹¥»÷Õß·­¿ªÓû§µÄÉãÏñÍ·£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÈÔ¿ÉÒÔͨ¹ý¶ñÒâÁ´½ÓÓÕʹÓû§¼ÓÈë¾Û»á¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/88147/hacking/zoom-mac-software-flaw.html

5¡¢Ó¢¹úº½¿Õ¹«Ë¾ÒòÊý¾ÝÐ¹Â¶ÃæÁÙ1.83ÒÚÓ¢°÷·£¿£¿£¿£¿£¿£¿î


Z6¡¤×ðÁú¿­Ê±¡¸ÖйúÇø¡¹¹Ù·½ÍøÕ¾


ÍâµØÊ±¼ä7ÔÂ8ÈÕ£¬£¬£¬£¬£¬£¬Ó¢¹úÐÅϢרԱ°ì¹«ÊÒ£¨ICO£©Ðû²¼£¬£¬£¬£¬£¬£¬½«¶ÔÓ¢¹úº½¿Õ¹«Ë¾2018ÄêÊý¾Ýй¶ÊÂÎñ¿ª³ö1.83ÒÚÓ¢°÷¾Þ¶î·£µ¥¡£¡£ ¡£¡£ÕâÊÇ×Ô¡¶Í¨ÓÃÊý¾Ý±£» £»£»£»£» £»¤ÌõÀý¡·£¨GDPR£©ÊµÑéÒÔÀ´×î´óµÄÒ»±Ê·£µ¥£¬£¬£¬£¬£¬£¬Ò²ÊǵÚÒ»¸öƾ֤йæÔòÐû²¼µÄ·£µ¥¡£¡£ ¡£¡£Ó¢¹úº½¿Õ¹«Ë¾¸ß²ã¶ÔÕâ¸ö¾öÒé¸ÐÓ¦Õ𾪡£¡£ ¡£¡£1.83ÒÚÓ¢°÷ÊÇÆ¾Ö¤¸Ã¹«Ë¾2017²ÆÄêÈ«ÇòÓªÒµ¶îµÄ1.5%ÅÌËãµÃÀ´£¬£¬£¬£¬£¬£¬Æ¾Ö¤GDPR£¬£¬£¬£¬£¬£¬ÕâÒ»´¦·Ö±ÈÀý×î¸ß¿É´ï4%¡£¡£ ¡£¡£ÔÚ´Ë֮ǰ£¬£¬£¬£¬£¬£¬ICO×î¸ßµÄ·£¿£¿£¿£¿£¿£¿î¶îÊÇ50ÍòÓ¢°÷£¬£¬£¬£¬£¬£¬2018ÄêFacebook½£ÇÅÊý¾Ý³óÎźÍ2017ÄêEquifax´ó¹æÄ£Êý¾Ýй¶¾ù±»´¦ÒÔ50ÍòÓ¢°÷µÄ·£¿£¿£¿£¿£¿£¿î¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2019/07/british-airways-breach-gdpr-fine.html