ÐÅÏ¢Çå¾²Öܱ¨-2019ÄêµÚ37ÖÜ

Ðû²¼Ê±¼ä 2019-09-23

> ±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


2019Äê9ÔÂ16ÈÕÖÁ22ÈÕ¹²ÊÕ¼Çå¾²Îó²î43¸ö£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇFastjson<=1.2.60Ô¶³Ì´úÂëÖ´ÐÐÎó²î£»£»£»£»£»£»£»e-cologyÔ¶³Ì´úÂëÖ´ÐÐÎó²î£»£»£»£»£»£»£»CODESYS V3 Web ServerÕ»Òç³öÎó²î£»£»£»£»£»£»£»VMware ESXi 'busybox'ÏÂÁî×¢ÈëÎó²î£»£»£»£»£»£»£»Schneider Electric BMXNOR0200H Ethernet/Serial RTU module¾Ü¾øÐ§ÀÍÎó²î¡£¡£¡£¡£¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊǶò¹Ï¶à¶û´ó²¿·Ö¹«ÃñÒþ˽й¶£¬£¬£¬°üÀ¨670Íò¶ùͯÐÅÏ¢£»£»£»£»£»£»£»Ê¨×Óº½¿Õ¹«Ë¾ÊýÍòÍòÓû§¼Í¼ÔÚ°µÍøÐ¹Â¶£»£»£»£»£»£»£»MITREÐû²¼2019ÄêCWE×îΣÏÕÈí¼þ¹ýʧÁбíTop25£»£»£»£»£»£»£»AMD RadeonÇý¶¯³ÌÐò±»ÆØ±£´æÐéÄâ»úÌÓÒÝÎó²î£»£»£»£»£»£»£»ÈýÐǺÍLGÖÇÄÜ×°±¸½«Óû§Ãô¸ÐÊý¾Ý·¢Ë͵½ÏàÖú¹«Ë¾¡£¡£¡£¡£¡£¡£¡£¡£


ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£¡£¡£¡£¡£



> Ö÷ÒªÇå¾²Îó²îÁбí


1. Fastjson<=1.2.60Ô¶³Ì´úÂëÖ´ÐÐÎó²î


Fastjson±£´æ·´ÐòÁл¯Îó²î£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»£»£»£»£»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£

https://github.com/alibaba/fastjson/commit/05a7aa7f748115018747f7676fd2aefdc545d17a


2. e-cologyÔ¶³Ì´úÂëÖ´ÐÐÎó²î


e-cology BeanShell×é¼þ±£´æÇå¾²Îó²î£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬¿ÉÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£¡£¡£¡£

https://help.aliyun.com/noticelist/articleid/1060057523.html?spm=5176.2020520154.sas.20.36a91e43Zt9Vx7


3. CODESYS V3 Web ServerÕ»Òç³öÎó²î


CODESYS V3 Web Servers±£´æÕ»Òç³öÎó²î£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬¿ÉÖ´ÐÐí§Òâ´úÂë»òʹӦÓóÌÐòÍ߽⡣¡£¡£¡£¡£¡£¡£¡£

https://www.codesys.com/fileadmin/data/customers/security/2019/Advisory2019-06_CDS-64543.pdf


4. VMware ESXi 'busybox'ÏÂÁî×¢ÈëÎó²î


VMware ESXi 'busybox'´¦Öóͷ£ÎļþÃû±£´æÇå¾²Îó²î£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬¿ÉÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£¡£¡£¡£

https://www.vmware.com/security/advisories/VMSA-2019-0013.html


5. Schneider Electric BMXNOR0200H Ethernet/Serial RTU module¾Ü¾øÐ§ÀÍÎó²î


Schneider Electric BMXNOR0200H Ethernet/Serial RTU module´¦Öóͷ£´ó×ÚIEC 60870-5-104±¨Îı£´æÇå¾²Îó²î£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬¿ÉʹӦÓóÌÐòÍ߽⡣¡£¡£¡£¡£¡£¡£¡£

https://www.schneider-electric.com/en/download/document/SEVD-2019-225-03/



 > Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢¶ò¹Ï¶à¶û´ó²¿·Ö¹«ÃñÒþ˽й¶£¬£¬£¬°üÀ¨670Íò¶ùͯÐÅÏ¢


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


Ñо¿Ö°Ô±·¢Ã÷Ò»¼ÒÍâµØ¹«Ë¾NovaestratµÄElasticsearchЧÀÍÆ÷̻¶Á˶ò¹Ï¶à¶û´ó´ó¶¼¹«ÃñµÄÒþ˽ÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£¶ò¹Ï¶à¶ûµÄÉú³Ý»ùÊýΪ1660Íò£¬£¬£¬¶ø¸ÃÊý¾Ý¿â°üÀ¨½ü2080ÍòÌõÓû§¼Í¼£¬£¬£¬Áè¼ÝÁ˸ùúµÄÉú³ÝÊý¾Ý£¬£¬£¬ÆäÔµ¹ÊÔ­ÓÉÊÇÊý¾Ý¿âÖаüÀ¨Ò»Ð©Öظ´¼Í¼ºÍéæÃü¹«ÃñµÄ¼Í¼¡£¡£¡£¡£¡£¡£¡£¡£Ð¹Â¶µÄÊý¾Ý°üÀ¨ÐÕÃû¡¢¼ÒÍ¥³ÉÔ±/¼Ò×åÊ÷¡¢¹«Ãñ×¢²áÊý¾Ý¡¢²ÆÎñ¼°ÊÂÇéÐÅÏ¢¡¢³µÁ¾ÐÅÏ¢µÈ¡£¡£¡£¡£¡£¡£¡£¡£Êý¾Ý¿âÖл¹°üÀ¨Õþ¸®Ô±¹¤ÐÅÏ¢ºÍ677Íò¶ùͯÐÅÏ¢£¬£¬£¬ÒÔ¼°700ÍòÌõ²ÆÎñ¼Í¼ºÍ250ÍòÌõ³µÁ¾¼Í¼¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/database-leaks-data-on-most-of-ecuadors-citizens-including-6-7-million-children/


2¡¢Ê¨×Óº½¿Õ¹«Ë¾ÊýÍòÍòÓû§¼Í¼ÔÚ°µÍøÐ¹Â¶


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


ʨ×Óº½¿ÕÆìÏÂÁ½¼Òº½¿Õ¹«Ë¾µÄÊýÍòÍòÌõÓοͼͼÔÚ°µÍøÂÛ̳ÉÏй¶¡£¡£¡£¡£¡£¡£¡£¡£ÕâЩÊý¾Ý´æ´¢ÔڿɹûÕæ»á¼ûµÄAmazon´æ´¢Í°ÖУ¬£¬£¬¹²ÓÐÁ½¸öÊý¾Ý¿â£¬£¬£¬Ò»¸ö°üÀ¨2100ÍòÌõ¼Í¼£¬£¬£¬ÁíÒ»¸ö°üÀ¨1400ÍòÌõ¼Í¼£¬£¬£¬¸ÃĿ¼Ï»¹°üÀ¨2019Äê5Ô·ݽ¨ÉèµÄ±¸·ÝÎļþ£¬£¬£¬Ö÷ÒªÊôÓÚMalindo AirºÍThai Lion Air¡£¡£¡£¡£¡£¡£¡£¡£ÁíÒ»¸ö±¸·ÝÎļþµÄÃû³ÆÊÇBatik Air£¬£¬£¬¸Ã¹«Ë¾µÄĸ¹«Ë¾Ò²ÊÇʨ×Óº½¿Õ¡£¡£¡£¡£¡£¡£¡£¡£Ð¹Â¶µÄÐÅÏ¢°üÀ¨Óο͵ÄÔ¤¶©ID¡¢ÆÜÉíµØµã¡¢µç»°ºÅÂë¡¢ÓÊÏ䵨µã¡¢ÐÕÃû¡¢³öÉúÈÕÆÚ¡¢»¤ÕÕºÅÂëºÍµ½ÆÚÈÕÆÚµÈ¡£¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚ»¹²»ÇåÎúÕâЩÊý¾ÝÊ×´Îй¶µÄʱ¼ä£¬£¬£¬µ«¾Ý³ÆÖÁÉÙ´Ó8ÔÂ10ÈÕÆð¸ÃÊý¾Ý¿âÒÑÔÚÂÛ̳ÉÏÁ÷ͨ¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/millions-of-lion-air-passenger-records-exposed-and-exchanged-on-forums/


3¡¢MITREÐû²¼2019ÄêCWE×îΣÏÕÈí¼þ¹ýʧÁбíTop25


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


·ÇÓªÀû×éÖ¯MITERÐû²¼2019Äê×îΣÏÕµÄÈí¼þÎó²îºÍ¹ýʧÁбíTop25¡£¡£¡£¡£¡£¡£¡£¡£Æ¾Ö¤MITRE£¬£¬£¬×îΣÏÕµÄÈí¼þ¹ýʧÊÇCWE-119£¬£¬£¬Ëü±»ÐÎòΪ¡°¶ÔÄڴ滺³åÇø½çÏßÄÚ²Ù×÷µÄ²»×¼È·ÏÞÖÆ¡±£¬£¬£¬¼´»º³åÇøÒç³öµ¼ÖµÄÔ½½ç¶Á»òд¡£¡£¡£¡£¡£¡£¡£¡£ÅÅÔÚµÚ¶þλµÄÊÇCWE-79£¬£¬£¬±»ÐÎòΪ¡°ÍøÒ³ÌìÉúʱ´úÊäÈëÔì³ÉµÄ²»×¼È··´Ó¦¡±£¬£¬£¬¼´XSS¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£µÚÈýÃûÔòÊÇCWE-20£¬£¬£¬¼´¡°²»×¼È·µÄÊäÈëÑéÖ¤¡±¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÁбíÊÇ»ùÓÚMITERÊý¾Ý¿âÖеÄCVEÊý¾Ý¼°NVDÊý¾Ý¿âºÍCVSS»ñµÃµÄÐÅÏ¢£¬£¬£¬×ܹ²ÓÐԼĪ2.5Íò¸öCVEÌṩÁËÔ´Êý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£ÍêÕûÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/these-software-vulnerabilities-top-mitres-most-dangerous-list-in-2019/


4¡¢AMD RadeonÇý¶¯³ÌÐò±»ÆØ±£´æÐéÄâ»úÌÓÒÝÎó²î


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


˼¿ÆTalosÅû¶AMD ATI Radeon ATIDXX64.DLLÇý¶¯³ÌÐòÖеÄÐéÄâ»úÌÓÒÝÎó²î¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²î±£´æÓÚAMD Radeon RX 550¼°550ϵÁÐÏÔ¿¨ÖУ¬£¬£¬²¢ÇÒÖ»ÄÜÔÚÔËÐÐVMWare Workstation 15ʱ´¥·¢¡£¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±Ú¹Êͳƣ¬£¬£¬¿ÉÔÚVMwareÐéÄâ»úϵͳÖÐͨ¹ý¶ñÒâÏñËØ×ÅÉ«Æ÷ÔÚAMD ATIDXX64.DLLÇý¶¯³ÌÐòÖд¥·¢ÄÚ´æÔ½½çдÈ룬£¬£¬Õâ¿ÉÄܻᴥ·¢VMwareÀ´±öģʽµÄÎó²î£¬£¬£¬´Ó¶øÔÚËÞÖ÷»úÉÏÖ´ÐдúÂë¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îÓ°ÏìÁËATIDXX64.DLLÇý¶¯³ÌÐò°æ±¾25.20.15031.5004ºÍ25.20.15031.9002¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²î£¨CVE-2019-5049£©µÄCVSSÆÀ·ÖΪ9.0¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/amd-radeon-cards-vmware-workstations/148406/


5¡¢ÈýÐǺÍLGÖÇÄÜ×°±¸½«Óû§Ãô¸ÐÊý¾Ý·¢Ë͵½ÏàÖú¹«Ë¾


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


Ñо¿Ö°Ô±·¢Ã÷×ÝÈ»ÊÇÔÚ×°±¸ÏÐÖÃʱ£¬£¬£¬ÈýÐÇ¡¢LGºÍRokuµÈ¹«Ë¾µÄÖÇÄܵçÊÓÒ²»áÏòÏàÖúµÄ¿Æ¼¼¹«Ë¾·¢ËÍÃô¸ÐµÄÓû§Êý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£Æ¾Ö¤Á½¸öÍŶӵÄ×ÔÁ¦Ñо¿£¬£¬£¬ÖÇÄܵçÊÓµÄOTTƽ̨»á½«Óû§µÄÃô¸ÐÊý¾Ýй¶¸øFacebook¡¢ÑÇÂíÑ·¡¢¹È¸èºÍNetflixµÈ¹«Ë¾¡£¡£¡£¡£¡£¡£¡£¡£µÚÒ»·Ý±¨¸æÑо¿ÁË81̨װ±¸£¬£¬£¬·¢Ã÷ÓÐ72̨װ±¸½«Êý¾Ý·¢Ë͵½·ÇÖÆÔìÉÌµÄÆäËü¹«Ë¾¡£¡£¡£¡£¡£¡£¡£¡£µÚ¶þ·Ý±¨¸æ·¢Ã÷´ÓÖÇÄܵçÊÓ·¢Ë͵ÄÊý¾ÝÒ²Óë¹È¸èºÍFacebookÖÎÀíµÄ¸ú×ÙÆ÷Óйأ¬£¬£¬Ñо¿Ö°Ô±³Æ89%µÄAmazon Fire TVƵµÀºÍ69%µÄRokuƵµÀ¶¼°üÀ¨ÓÃÓÚ¸ú×ÙÓû§ÊÕ¿´Ï°¹ßºÍÆ«ºÃÐÅÏ¢µÄ¸ú×ÙÆ÷¡£¡£¡£¡£¡£¡£¡£¡£ÕâЩ¸ú×ÙÆ÷»¹¿ÉÒÔʶ±ð×°±¸ºÍʹÓÃλÖ㬣¬£¬°üÀ¨×°±¸ÐòÁкźÍID¡¢Wi-FiÃû³ÆºÍMACµØµãµÈ¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/smart-tvs-leak-data/148482/