ÐÅÏ¢Çå¾²Öܱ¨-2020ÄêµÚ03ÖÜ

Ðû²¼Ê±¼ä 2020-01-20


±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


2020Äê01ÔÂ13ÈÕÖÁ19ÈÕ¹²ÊÕ¼Çå¾²Îó²î53¸ö£¬£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇMicrosoft Windows CryptoAPIÑéÖ¤ÈÆ¹ýÎó²î; Apache XML-RPC XMLRPC client´úÂëÖ´ÐÐÎó²î£»£»£»£»Oracle E-Business Suite Human Resources CVE-2020-2587δÃ÷´úÂëÖ´ÐÐÎó²î£»£»£»£»Adobe Illustrator CC CVE-2020-3710ÄÚ´æ¹ýʧÒýÓôúÂëÖ´ÐÐÎó²î£»£»£»£»Microsoft .NET Core CVE-2020-0602Ô¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£ ¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇÒÔÉ«ÁÐÆô¶¯Ãñº½ÍøÂçÇå¾²ÍýÏ룬£¬£¬£¬£¬£¬£¬½«¸ÄÉÆº½¿ÕÍøÂç·ÀÓùÄÜÁ¦£»£»£»£»Î¢ÈíÕýʽÖÕÖ¹¶ÔWindows 7¡¢Server 2008ºÍ2008 R2Ìṩ֧³Ö£»£»£»£»ÃÀ¹úLimeLeads¹«Ë¾4900ÍòÌõÓû§¼Í¼ÔÚ°µÍøÂÛ̳³öÊÛ£»£»£»£»ÊÔÓÃAppÐ¶ÔØºóÖ±½Ó¿Û·Ñ£¬£¬£¬£¬£¬£¬£¬È«Çò½ü6ÒÚAndroidÓû§ÖÐÕУ»£»£»£»Êý°Ù¸öҽѧ³ÉÏñϵͳÔÚÍøÉÏ̻¶ÁËÊý°ÙÍò»¼ÕßµÄÊý¾Ý¡£¡£¡£¡£¡£¡£ ¡£


ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£¡£¡£ ¡£



Ö÷ÒªÇå¾²Îó²îÁбí


1. Microsoft Windows CryptoAPIÑéÖ¤ÈÆ¹ýÎó²î


Microsoft Windows CryptoAPI´¦Öóͷ£ECCÍÖÔ²ÇúÏß¼ÓÃܱ£´æÇå¾²Îó²î£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬¿ÉÒÔʹÓÃαÔìµÄÖ¤Êé¶Ô¶ñÒâµÄ¿ÉÖ´ÐÐÎļþ¾ÙÐÐÊðÃû£¬£¬£¬£¬£¬£¬£¬Ê¹Îļþ¿´ÆðÀ´À´×Ô¿ÉÐŵÄȪԴ£¬£¬£¬£¬£¬£¬£¬»òÕß¾ÙÐÐÖÐÐÄÈ˹¥»÷²¢½âÃÜÓû§ÅþÁ¬µ½ÊÜÓ°ÏìÈí¼þµÄÉñÃØÐÅÏ¢¡£¡£¡£¡£¡£¡£ ¡£

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0601


2. Apache XML-RPC XMLRPC client´úÂëÖ´ÐÐÎó²î


Apache XML-RPC XMLRPC clientʵÏÖXMLRPC¹ýʧÐÂÎÅfaultCauseÊôÐÔ´¦Öóͷ£±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²î¹¹½¨¶ñÒâXMLRPCЧÀÍÇëÇ󣬣¬£¬£¬£¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»£»òÕßÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£ ¡£

https://access.redhat.com/security/cve/cve-2019-17570


3. Oracle E-Business Suite Human Resources CVE-2020-2587δÃ÷´úÂëÖ´ÐÐÎó²î


Oracle E-Business Suite Human Resources±£´æÎ´Ã÷Çå¾²Îó²î£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»£»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£ ¡£

https://www.oracle.com/security-alerts/cpujan2020.html


4. Adobe Illustrator CC CVE-2020-3710ÄÚ´æ¹ýʧÒýÓôúÂëÖ´ÐÐÎó²î


Adobe Illustrator CC´¦Öóͷ£Îļþ±£´æÄÚ´æÆÆËðÎó²î£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬£¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£ ¡£

https://helpx.adobe.com/security/products/illustrator/apsb20-03.html


5. Microsoft .NET Core CVE-2020-0602Ô¶³Ì´úÂëÖ´ÐÐÎó²î


Microsoft .NET CoreʵÏÖ±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£ ¡£

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0602


Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢ÒÔÉ«ÁÐÆô¶¯Ãñº½ÍøÂçÇå¾²ÍýÏ룬£¬£¬£¬£¬£¬£¬½«¸ÄÉÆº½¿ÕÍøÂç·ÀÓùÄÜÁ¦


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


¾ÝÉÏÖÜÈÕÒÔÉ«Áйú¼ÒÍøÂçÖÎÀí¾Ö£¨INCD£©±¨µÀ£¬£¬£¬£¬£¬£¬£¬ÒÔÉ«ÁÐÕþ¸®Åú×¼ÁËÒ»ÏîÃñº½ÍøÂçÇå¾²ÍýÏë¡£¡£¡£¡£¡£¡£ ¡£×÷Ϊ¸ÃÍýÏëµÄÒ»²¿·Ö£¬£¬£¬£¬£¬£¬£¬ÒÔÉ«Áн«½¨ÉèÒ»¸ö¹ú¼ÒÖ¸µ¼Î¯Ô±»áÀ´¸ÄÉÆ¸Ã¹ú¼ÒµÄº½¿ÕÍøÂç·ÀÓùÄÜÁ¦¡£¡£¡£¡£¡£¡£ ¡£¸ÃίԱ»áÓÉINCDÏòµ¼£¬£¬£¬£¬£¬£¬£¬²¢ÇÒÓÉÒÔÉ«Áн»Í¨²¿¡¢Ãñº½¾Ö¡¢»ú³¡ÖÎÀí¾Ö¡¢Çå¾²¾Ö¡¢¹ú·À²¿¡¢¹ú¼ÒÇ徲ίԱ»áºÍÒÔÉ«Áйú·À¾üµÄ´ú±í×é³É¡£¡£¡£¡£¡£¡£ ¡£¸ÃÍýÏëµÄÄÚÈݰüÀ¨£ºÍþвӳÉäÏ¢Õù¾ö¼Æ»®ÏîÄ¿¡¢Ôڸ߿Ƽ¼ºÍÍøÂçÐÐÒµÒÔ¼°Ñ§Êõ½çÍÆ¶¯Ç°ÑØÊÖÒÕÑо¿ºÍ¹ú·À½â¾ö¼Æ»®µÄÑз¢¡¢Ó벨Òô¾ÙÐÐÏàÖú¡¢½¨ÉèÔËÊä¿ØÖÆÖÐÐÄ¡¢¿ª·¢º½ÐÐÔ±Åàѵ¿Î³ÌµÈ¡£¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

http://www.xinhuanet.com/english/2020-01/13/c_138699304.htm


2¡¢Î¢ÈíÕýʽÖÕÖ¹¶ÔWindows 7¡¢Server 2008ºÍ2008 R2Ìṩ֧³Ö


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


΢ÈíÓÚ1ÔÂ14ÈÕÕýʽÖÕÖ¹¶ÔWindows 7¡¢Server 2008ºÍServer 2008 R2Ìṩ֧³Ö¡£¡£¡£¡£¡£¡£ ¡£ÔÚ´ËÖ®ºóÕâЩ²Ù×÷ϵͳÈԿɼÌÐøÊÂÇ飬£¬£¬£¬£¬£¬£¬µ«½«²»ÔÙÊÕµ½Çå¾²¸üС£¡£¡£¡£¡£¡£ ¡£¶ÔWindows Server 2008µÄÖÕÖ¹Ö§³ÖÒâζ×ÅÆäÌØÁíÍâÃâ·ÑÇå¾²¸üС¢·ÇÇå¾²¸üС¢Ãâ·ÑµÄÖ§³ÖЧÀÍÒÔ¼°ÔÚÏßÊÖÒÕÄÚÈݸüж¼ÒÑ¿¢Ê¡£¡£¡£¡£¡£¡£ ¡£Î¢Èí±Þ²ßÓû§½«Æä²úÆ·ºÍЧÀÍǨáãµ½Azure»òÊÇÉý¼¶µ½×îа汾Server 2016¡£¡£¡£¡£¡£¡£ ¡£ÎÞ·¨ÔÚÖ§³ÖÖÕÖ¹ÏÞÆÚ֮ǰÍê³ÉÉý¼¶µÄÈË¿ÉÒÔ¹ºÖÃÀ©Õ¹Çå¾²¸üУ¬£¬£¬£¬£¬£¬£¬ÒÔ±£»£»£»£»¤Ð§ÀÍÆ÷ÊÂÇé¸ºÔØÖ±ÖÁÉý¼¶ÎªÖ¹¡£¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.darkreading.com/risk/microsoft-to-officially-end-support-for-windows-7-server-2008/d/d-id/1336791


3¡¢ÃÀ¹úLimeLeads¹«Ë¾4900ÍòÌõÓû§¼Í¼ÔÚ°µÍøÂÛ̳³öÊÛ


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


¾ÝZDNet±¨µÀ£¬£¬£¬£¬£¬£¬£¬ºÚ¿ÍOmnichorusÕýÔÚ°µÍøÂÛ̳ÉϳöÊÛÃÀ¹úÊý¾Ý¾­¼ÍÉÌLimeLeadsµÄ4900ÍòÌõÓû§¼Í¼¡£¡£¡£¡£¡£¡£ ¡£Çå¾²Ñо¿Ô±Bob DiachenkoÈ·ÈÏÕâЩÊý¾ÝÊÇÓɸù«Ë¾µÄÄÚ²¿ElasticsearchЧÀÍÆ÷̻¶ÔÚInternetÉÏй¶µÄ¡£¡£¡£¡£¡£¡£ ¡£Æ¾Ö¤DiachenkoµÄ˵·¨£¬£¬£¬£¬£¬£¬£¬ÖÁÉÙ´Ó2019Äê7ÔÂ27ÈÕÆðLimeLeadsµÄһ̨ЧÀÍÆ÷¾Í¿É¹ûÕæ»á¼û£¬£¬£¬£¬£¬£¬£¬ËûÓÚÈ¥Äê9ÔÂ16ÈÕ֪ͨÁ˸ù«Ë¾£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÔÚµÚ¶þÌìѸËÙ¶ÔЧÀÍÆ÷¾ÙÐÐÁ˱£»£»£»£»¤£¬£¬£¬£¬£¬£¬£¬µ«ÏÔÈ»OmnichorusÒѾ­ÇÔÈ¡ÁËÕâЩÊý¾Ý£¬£¬£¬£¬£¬£¬£¬²¢ÇÒ´ÓÈ¥Äê10ÔÂÒÔÀ´Ò»Ö±ÔÚÍøÉϳöÊÛ¡£¡£¡£¡£¡£¡£ ¡£Æ¾Ö¤OmnichorusÐû²¼µÄÊý¾ÝÑù±¾£¬£¬£¬£¬£¬£¬£¬ÕâЩÊý¾Ý°üÀ¨Óû§µÄÐÕÃû¡¢Ö°Îñ¡¢µç×ÓÓʼþ¡¢¹ÍÖ÷/¹«Ë¾Ãû³Æ¡¢¹«Ë¾µØµã¡¢¶¼»á¡¢ÖÝ¡¢ÓÊÕþ±àÂë¡¢µç»°ºÅÂë¡¢ÍøÕ¾URL¡¢¹«Ë¾×ÜÊÕÈëÒÔ¼°¹«Ë¾µÄÔ¤¼ÆÔ±¹¤ÈËÊýµÈÐÅÏ¢¡£¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/49-million-user-records-from-us-data-broker-limeleads-put-up-for-sale-online/


4¡¢ÊÔÓÃAppÐ¶ÔØºóÖ±½Ó¿Û·Ñ£¬£¬£¬£¬£¬£¬£¬È«Çò½ü6ÒÚAndroidÓû§ÖÐÕÐ


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


SophosÇå¾²Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»×éеÄfleeceware APP£¬£¬£¬£¬£¬£¬£¬ÕâЩAPPÒѾ­±»Áè¼Ý6ÒÚAndroidÓû§ÏÂÔØ×°Öᣡ£¡£¡£¡£¡£ ¡£fleecewareÊÇÖ¸¹È¸èPlayÊÐËÁÖб£´æµÄÒ»ÖÖÐÂÐͽðÈÚڲƭÐÐΪ£¬£¬£¬£¬£¬£¬£¬ÕâЩAPPÀÄÓÃAndroidÓ¦ÓõÄÊÔÓÃÆÚ¹¦Ð§ÏòÓû§ÊÕ·Ñ¡£¡£¡£¡£¡£¡£ ¡£Ä¬ÈÏÇéÐÎÏÂAndroidÓû§ÔÚ×¢²áʹÓþßÓÐÊÔÓÃÆÚµÄAPPʱ±ØÐèÊÖ¾Ù´ë·ÏÊÔÓ㬣¬£¬£¬£¬£¬£¬È»¶ø´ó´ó¶¼Óû§Ö»ÊÇÔÚ²»Ï²»¶µÄʱ¼äÐ¶ÔØAPP£¬£¬£¬£¬£¬£¬£¬¾ø´ó´ó¶¼¿ª·¢Õß½«ÕâÖÖÐ¶ÔØÐÐΪÊÓΪ×÷·ÏÊÔÓ㬣¬£¬£¬£¬£¬£¬µ«Ò»Ð©¿ª·¢ÕßÔÚÓû§Ð¶ÔغóûÓÐ×÷·ÏÊÔÓò¢ÇÒ¼ÌÐøÊÕ·Ñ¡£¡£¡£¡£¡£¡£ ¡£Sophos×î³õ·¢Ã÷µÄ24¸öAPP°üÀ¨¶þάÂëɨÃèÆ÷¡¢ÅÌËãÆ÷µÈ£¬£¬£¬£¬£¬£¬£¬ËüÃÇÒÔÕâÖÖ·½·¨ÏòÓû§ÊÕȡÿÄê100ÃÀÔªµ½240ÃÀÔªµÄ¶©ÔÄÓöȡ£¡£¡£¡£¡£¡£ ¡£ÔÚ¿ËÈÕÐû²¼µÄÒ»·Ý±¨¸æÖУ¬£¬£¬£¬£¬£¬£¬Sophos·¢Ã÷ÁËÁíÍâ25¸ö´ËÀàAPP£¬£¬£¬£¬£¬£¬£¬Æä×Ü×°ÖÃÁ¿Áè¼Ý6ÒÚ£¬£¬£¬£¬£¬£¬£¬ÍêÕûµÄAPPÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/more-than-600-million-users-installed-android-fleeceware-apps-from-the-play-store/


5¡¢Êý°Ù¸öҽѧ³ÉÏñϵͳÔÚÍøÉÏ̻¶ÁËÊý°ÙÍò»¼ÕßµÄÊý¾Ý


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


µÂ¹úÇå¾²³§ÉÌGreenbone³ÆÊý°Ù¸ö¿É¹ûÕæ»á¼ûµÄҽѧ³ÉÏñϵͳÔÚ»¥ÁªÍøÉÏ̻¶ÁËÈ«ÇòÊý°ÙÍò»¼ÕßµÄÊý¾Ý¡£¡£¡£¡£¡£¡£ ¡£¸ÃÏîÑо¿ÖصãÆÊÎöÔÚÍøÉÏ̻¶µÄҽѧͼƬ´æµµºÍͨѶϵͳ£¨PACS£©£¬£¬£¬£¬£¬£¬£¬ÔÚËùÓÐÊÜÆÊÎöµÄPACSЧÀÍÆ÷ÖУ¬£¬£¬£¬£¬£¬£¬ÓпìÒª1/4µÄϵͳ½«Êý¾Ý̻¶ÔÚ»¥ÁªÍøÉÏ¡£¡£¡£¡£¡£¡£ ¡£ÏêϸÀ´Ëµ£¬£¬£¬£¬£¬£¬£¬ÔÚ2019Äê7ÔÂÖÁ2019Äê9ÔÂÖ®¼äÆÊÎöµÄ2300¸öϵͳÖУ¬£¬£¬£¬£¬£¬£¬ÓÐ590¸ö¿É´ÓInternet»á¼û²¢ÇÒδÉèÃÜÂ룬£¬£¬£¬£¬£¬£¬¹²ÓÐÁè¼Ý2450ÍòÌõ»¼ÕßÊý¾Ý̻¶£¬£¬£¬£¬£¬£¬£¬ÔÚ11Ô·ݵÄÑо¿ÖУ¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾Í¸Â¶ÓÐ3500ÍòÌõ»¼Õ߼ͼ¿É¹ûÕæ»á¼û¡£¡£¡£¡£¡£¡£ ¡£ÔÚ9ÔÂÖÁ11ÔÂÖ®¼ä£¬£¬£¬£¬£¬£¬£¬°üÀ¨Ò½ÁÆÍ¼ÏñµÄ̻¶»¼Õ߼ͼÊýÄ¿ÒÑ´Ó440ÍòÔöÌíÁËÒ»±¶£¬£¬£¬£¬£¬£¬£¬µÖ´ï900Íò¡£¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/unprotected-medical-systems-expose-data-millions-patients