ÐÅÏ¢Çå¾²Öܱ¨-2020ÄêµÚ51ÖÜ
Ðû²¼Ê±¼ä 2020-12-21> ±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö
2020Äê12ÔÂ14ÈÕÖÁ12ÔÂ20ÈÕ¹²ÊÕ¼Çå¾²Îó²î58¸ö£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇFoxit Reader CVE-2020-13548ÄÚ´æ¹ýʧÒýÓôúÂëÖ´ÐÐÎó²î£»£»£»£»Dex Idp Dex samlÑéÖ¤ÈÆ¹ýÎó²î£»£»£»£»IBM Financial Transaction Manager for SWIFT Services CVE-2020-4904¿çÕ¾ÇëÇóαÔìÎó²î£»£»£»£»DELL Dell EMC iDRAC9 CVE-2020-26198¿çÕ¾¾ç±¾Îó²î£»£»£»£»EPSON EPS TSE Server CVE-2020-28930¿çÕ¾¾ç±¾Îó²î¡£¡£¡£¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇIntelµÄHabana LabsѬȾPay2Key£¬£¬£¬ÉÌÒµÎĵµºÍÔ´´úÂë±»µÁ£»£»£»£»ÃÀ¹ú²ÆÎñ²¿µÈ²¿·ÖÔâµ½ÓëFireEyeÏàͬµÄ¹©Ó¦Á´¹¥»÷£»£»£»£»AppleÇå¾²¸üУ¬£¬£¬ÐÞ¸´Ó°ÏìiOSºÍiPadOSµÄ11¸öÎó²î£»£»£»£»ÐµÄAIR-FIÊÖÒÕ¿ÉʹÓÃRAMÀ´ÇÔÈ¡ÆøÏ¶ÏµÍ³ÖÐÊý¾Ý£»£»£»£»Avast½üÆÚ·¢Ã÷28¿î¶ñÒâµÄä¯ÀÀÆ÷²å¼þ£¬£¬£¬Ó°Ïì300ÍòÓû§¡£¡£¡£¡£¡£
ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£¡£
> Ö÷ÒªÇå¾²Îó²îÁбí
1.Foxit Reader CVE-2020-13548ÄÚ´æ¹ýʧÒýÓôúÂëÖ´ÐÐÎó²î
Foxit Reader±£´æÊͷźóʹÓÃÎó²î£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþÇëÇ󣬣¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»£»òÕßÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£
https://www.foxitsoftware.com/support/security-bulletins.html
2.Dex Idp Dex samlÑéÖ¤ÈÆ¹ýÎó²î
Dex Idp Dex saml±£´æÑéÖ¤ÈÆ¹ýÎó²î£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬¿ÉδÊÚȨ»á¼û¡£¡£¡£¡£¡£
https://access.redhat.com/security/cve/cve-2020-27847
3.IBM Financial Transaction Manager for SWIFT Services CVE-2020-4904¿çÕ¾ÇëÇóαÔìÎó²î
IBM Financial Transaction Manager for SWIFT Services±£´æ¿çÕ¾ÇëÇóαÔìÎó²î£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²î¹¹½¨¶ñÒâURI£¬£¬£¬ÓÕʹÇëÇ󣬣¬£¬¿ÉÒÔÄ¿µÄÓû§ÉÏÏÂÎÄÖ´ÐжñÒâ²Ù×÷¡£¡£¡£¡£¡£
https://www.ibm.com/support/pages/node/6371260
4.DELL Dell EMC iDRAC9 CVE-2020-26198¿çÕ¾¾ç±¾Îó²î
DELL Dell EMC iDRAC9 webÓ¦Óñ£´æ¿çÕ¾¾ç±¾Îó²î£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²î×¢Èë¶ñÒâ¾ç±¾»òHTML´úÂ룬£¬£¬µ±¶ñÒâÊý¾Ý±»Éó²éʱ£¬£¬£¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢»òÐ®ÖÆÓû§»á»°¡£¡£¡£¡£¡£
https://www.dell.com/support/kbdoc/en-us/000181088/dsa-2020-268-dell-emc-idrac9-reflected-xss-vulnerability
5.EPSON EPS TSE Server CVE-2020-28930¿çÕ¾¾ç±¾Îó²î
EPSON EPS TSE Server±£´æ¿çÕ¾¾ç±¾Îó²î£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²î×¢Èë¶ñÒâ¾ç±¾»òHTML´úÂ룬£¬£¬µ±¶ñÒâÊý¾Ý±»Éó²éʱ£¬£¬£¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢»òÐ®ÖÆÓû§»á»°¡£¡£¡£¡£¡£
https://www.seh-technology.com/services/downloads/download-fiscal-solutions/eps-tse-server-8.html
> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö
1¡¢IntelµÄHabana LabsѬȾPay2Key£¬£¬£¬ÉÌÒµÎĵµºÍÔ´´úÂë±»µÁ

IntelµÄAI´¦Öóͷ£Æ÷¿ª·¢ÉÌHabana LabsÔâµ½ÁËPay2KeyÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬ÉÌÒµÎĵµºÍÔ´´úÂë±»µÁ¡£¡£¡£¡£¡£Habana LabsÊÇÒÔÉ«ÁÐAI´¦Öóͷ£Æ÷µÄ¿ª·¢ÉÌ£¬£¬£¬ÓÚ2019Äê12ÔÂÒÔ20ÒÚÃÀÔªµÄ¼ÛÇ®±»IntelÊÕ¹º¡£¡£¡£¡£¡£Pay2KeyÔÚTwitterÉÏÐû²¼Á˴˴ι¥»÷£¬£¬£¬²¢Éù³ÆÒÑÇÔÈ¡ÁËÓйØÈ˹¤ÖÇÄÜоƬ´úÂëGaudiµÄÐÅÏ¢Êý¾Ý¡£¡£¡£¡£¡£¸ÃÍÅ»ïÔÚÆäÊý¾ÝÐ¹Â¶ÍøÕ¾ÉϹûÕæÁ˸ù«Ë¾µÄÔ´´úÂëºÍÄÚ²¿Àú³ÌµÄͼƬ£¬£¬£¬ÒÔ¼°WindowsÓò¿ØÖÆÆ÷Êý¾ÝºÍGerrit¿ª·¢´úÂë¼ì²éϵͳµÄÎļþÁÐ±í¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/112258/data-breach/pay2key-hacked-habana-labs.html
2¡¢ÃÀ¹ú²ÆÎñ²¿µÈ²¿·ÖÔâµ½ÓëFireEyeÏàͬµÄ¹©Ó¦Á´¹¥»÷

ÃÀ¹ú²ÆÎñ²¿ºÍÉÌÎñ²¿¹ú¼ÒµçÐÅÓëÐÅÏ¢ÖÎÀí¾Ö£¨NTIA£©Ôâµ½ÓëFireEyeÏàͬµÄ¹©Ó¦Á´¹¥»÷¡£¡£¡£¡£¡£Çå¾²¹«Ë¾FireEye½ñÌìÌåÏÖ£¬£¬£¬Õþ¸®Ö§³ÖµÄºÚ¿Í¹¥»÷ÁËÈí¼þÌṩÉÌSolarWinds£¬£¬£¬È»ºóΪÆäOrionÈí¼þ°²ÅÅÁ˶ñÒâ¸üгÌÐò£¬£¬£¬ÒÔѬȾ¶à¸öÃÀ¹ú¹«Ë¾ºÍÕþ¸®ÍøÂ磬£¬£¬FireEye֮ǰҲÔâµ½ÁËÐÎͬµÄ¹¥»÷¡£¡£¡£¡£¡£SolarWindsÈ·ÈÏÆäÔÚ2020Äê3ÔÂÖÁ6ÔÂÖ®¼äÐû²¼µÄOrion¸üа汾2019.4ÖÁ2020.2.1Òѱ»¶ñÒâÈí¼þѬȾ¡£¡£¡£¡£¡£¾ÝÐÅ£¬£¬£¬´Ë´Î¹¥»÷»î¶¯Óë¶íÂÞ˹Íâ¹úÇ鱨¾Ö£¨SVR£©Ïà¹ØµÄºÚ¿Í×éÖ¯APT29Óйء£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/microsoft-fireeye-confirm-solarwinds-supply-chain-attack/
3¡¢AppleÇå¾²¸üУ¬£¬£¬ÐÞ¸´Ó°ÏìiOSºÍiPadOSµÄ11¸öÎó²î

AppleÐû²¼ÁËiOSºÍiPadOSµÄÇå¾²¸üУ¬£¬£¬ÐÞ¸´°üÀ¨´úÂëÖ´ÐÐÎó²îÔÚÄÚµÄ11¸öÎó²î¡£¡£¡£¡£¡£´Ë´ÎÐÞ¸´µÄ×îΪÑÏÖØµÄÊÇ´úÂëÖ´ÐÐÎó²î£¨CVE-2020-27943ºÍCVE-2020-27944£©£¬£¬£¬¹¥»÷Õß¿ÉʹÓöñÒâ×ÖÌåÎļþÔÚApple iPhoneºÍiPadÉÏÖ´ÐжñÒâ´úÂë¡£¡£¡£¡£¡£Æä´ÎΪÈý¸öÓ°ÏìÁËImageIO±à³Ì½Ó¿Ú¿ò¼ÜµÄÎó²îCVE-2020-29617¡¢CVE-2020-29618ºÍCVE-2020-29619£¬£¬£¬¹¥»÷Õß¿ÉʹÓÃÕâЩÎó²îͨ¹ýÌØÖÆÍ¼ÏñÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/112304/security/ios-ipados-flaws.html
4¡¢ÐµÄAIR-FIÊÖÒÕ¿ÉʹÓÃRAMÀ´ÇÔÈ¡ÆøÏ¶ÏµÍ³ÖÐÊý¾Ý

ÒÔÉ«ÁÐѧÕß·¢Ã÷еÄAIR-FIÊÖÒÕ£¬£¬£¬¿É½«RAM¿¨×ª»»ÎªÎÞÏß·¢ÉäÆ÷£¬£¬£¬²¢ÔÚûÓÐWi-Fi¿¨µÄ·ÇÁªÍøÆøÏ¶ÏµÍ³ÖÐÇÔÈ¡Ãô¸ÐÊý¾Ý¡£¡£¡£¡£¡£AIR-FIÊÖÒյĽ¹µãÊÇ£¬£¬£¬µ±µçÁ÷ͨ¹ýʱ£¬£¬£¬Èκεç×ÓÔª¼þ¶¼»á±¬·¢µç´Å²¨¡£¡£¡£¡£¡£Wi-FiÐźÅÊÇÎÞÏߵ粨£¬£¬£¬¶øÎÞÏßµç»ù±¾ÉÏÊǵç´Å²¨£¬£¬£¬Òò´Ë¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÆøÏ¶ÏµÍ³ÖÐÖ²Èë¶ñÒâ´úÂ룬£¬£¬À´¿ÉÒÔʹÓÃRAM¿¨ÄÚ²¿µÄµçÁ÷±¬·¢ÇкÏÕý³£µÄwifiÐÅºÅÆµÆ×µÄµç´Å²¨¡£¡£¡£¡£¡£È»ºóʹÓÃÆøÏ¶ÏµÍ³´øÓÐWi-FiÌìÏßµÄ×°±¸À´»ñÈ¡¸ÃÐźţ¬£¬£¬ÒԸߴï100 b/sµÄËÙÂÊÇÔÈ¡Ãô¸ÐÊý¾Ý¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/academics-turn-ram-into-wifi-cards-to-steal-data-from-air-gapped-systems/
5¡¢Avast½üÆÚ·¢Ã÷28¿î¶ñÒâµÄä¯ÀÀÆ÷²å¼þ£¬£¬£¬Ó°Ïì300ÍòÓû§

Çå¾²¹«Ë¾Avast½üÆÚ·¢Ã÷28¿î¶ñÒâµÄä¯ÀÀÆ÷²å¼þ£¬£¬£¬°üÀ¨15¸öChromeÀ©Õ¹ºÍ13¸öEdgeÀ©Õ¹£¬£¬£¬ÒÑÓ°Ïì300ÍòÓû§¡£¡£¡£¡£¡£Õâ28¿î²å¼þ°üÀ¨´ó×ÚʵÏÖ¶ñÒâ²Ù×÷µÄ´úÂ룬£¬£¬ÀýÈ罫Óû§Á÷Á¿Öض¨Ïòµ½¹ã¸æ¡¢½«Óû§Á÷Á¿Öض¨Ïòµ½ÍøÂç´¹ÂÚÕ¾µã¡¢ÍøÂçСÎÒ˽¼ÒÊý¾Ý¡¢ÍøÂçä¯ÀÀ¼Í¼¡¢½«¸ü¶à¶ñÒâÈí¼þÏÂÔØµ½Óû§×°±¸ÉÏ¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬GoogleÒÑɾ³ýÁË15¸ö¶ñÒâÀ©Õ¹³ÌÐòÖеÄ3¸ö£¬£¬£¬¶øMicrosoftÒòÎÞ·¨È·ÈÏAvastµÄ±¨¸æ¶øÉÐδ¾ÙÐÐɾ³ý¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/three-million-users-installed-28-malicious-chrome-or-edge-extensions/


¾©¹«Íø°²±¸11010802024551ºÅ