ÐÅÏ¢Çå¾²Öܱ¨-2020ÄêµÚ36ÖÜ

Ðû²¼Ê±¼ä 2020-09-08

> ±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


2020Äê08ÔÂ31ÈÕÖÁ09ÔÂ06ÈÕ¹²ÊÕ¼Çå¾²Îó²î56¸ö£¬£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇGigadevice GD32F103´úÂëÖ´ÐÐÎó²î£»£»£» £»£»£»Gigadevice GD32F103¹Ì¼þÌáÈ¡Îó²î£»£»£» £»£»£»NETGEAR R8300ÏÂÁî×¢ÈëÎó²î£»£»£» £»£»£»Education openSIS SQL×¢ÈëÎó²î£»£»£» £»£»£»Education openSIS EmailCheck.php SQL×¢ÈëÎó²î¡£ ¡£¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊǹ¤ÐŲ¿×ª´ï101¿îAPPÇÖÕ¼Óû§È¨Ò棬£¬£¬£¬£¬£¬£¬ÇáËɳïµÈƽ̨Éϰñ£»£»£» £»£»£»Å²ÍþÒé»áÓʼþϵͳÔâ¹¥»÷£¬£¬£¬£¬£¬£¬£¬¹¤µ³ºÍÖÐÐĵ³¾ùÊÜÓ°Ï죻£»£» £»£»£»CiscoÖÒÑÔÆäIOS XR±£´æ0day²¢Òѱ»ÔÚҰʹÓ㻣»£» £»£»£»Cisco Jabber±£´æÔ¶³ÌÖ´ÐдúÂëÎó²î£¬£¬£¬£¬£¬£¬£¬ÏÖÒѱ»ÐÞ¸´£»£»£» £»£»£»Ó¢ÌضûÐû²¼Î¢´úÂëÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬Ö÷ÒªÊÊÓÃÓÚWin10ϵÁС£ ¡£¡£¡£¡£¡£


ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£ ¡£¡£¡£¡£¡£


Ö÷ÒªÇå¾²Îó²îÁбí


1.Gigadevice GD32F103´úÂëÖ´ÐÐÎó²î


Gigadevice GD32F103Çå¾²±£»£»£» £»£»£»¤±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÎïÀíÄÜ»á¼û¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬Öض¨Ïò¿ØÖÆÁ÷Ö´ÐÐí§Òâ´úÂë¡£ ¡£¡£¡£¡£¡£

https://www.usenix.org/system/files/woot20-paper-obermaier.pdf


2. Gigadevice GD32F103¹Ì¼þÌáÈ¡Îó²î


Gigadevice GD32F103ÉÁ´æ¶Á³ö±£»£»£» £»£»£»¤±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÎïÀíÄÜ»á¼û¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬¿É´Óµ÷ÊÔ½Ó¿Ú»ñÈ¡¹Ì¼þ¡£ ¡£¡£¡£¡£¡£

https://www.usenix.org/system/files/woot20-paper-obermaier.pdf


3.NETGEAR R8300ÏÂÁî×¢ÈëÎó²î


NETGEAR R8300±£´æÊäÈëÑéÖ¤Îó²î£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£ ¡£¡£¡£¡£¡£


https://kb.netgear.com/000062158/Security-Advisory-for-Pre-Authentication-Command-Injection-on-R8300-PSV-2020-0211


4. Education openSIS SQL×¢ÈëÎó²î


Open Solutions for Education openSIS±£´æSQL×¢ÈëÎó²î£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄSQLÇëÇ󣬣¬£¬£¬£¬£¬£¬²Ù×÷Êý¾Ý¿â£¬£¬£¬£¬£¬£¬£¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢»òÖ´ÐÐí§Òâ´úÂë¡£ ¡£¡£¡£¡£¡£

https://talosintelligence.com/vulnerability_reports/TALOS-2020-1081


5. Education openSIS EmailCheck.php SQL×¢ÈëÎó²î


Open Solutions for Education EmailCheck.php±£´æSQL×¢ÈëÎó²î£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄSQLÇëÇ󣬣¬£¬£¬£¬£¬£¬²Ù×÷Êý¾Ý¿â£¬£¬£¬£¬£¬£¬£¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢»òÖ´ÐÐí§Òâ´úÂë¡£ ¡£¡£¡£¡£¡£¡£ ¡£¡£¡£¡£¡£

https://talosintelligence.com/vulnerability_reports/TALOS-2020-1073


> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢¹¤ÐŲ¿×ª´ï101¿îAPPÇÖÕ¼Óû§È¨Ò棬£¬£¬£¬£¬£¬£¬ÇáËɳïµÈƽ̨Éϰñ


1.jpg


¹¤ÒµºÍÐÅÏ¢»¯²¿¹ÙÍøÐû²¼¹ØÓÚËðº¦Óû§È¨ÒæÐÐΪµÄAPPת´ï¡£ ¡£¡£¡£¡£¡£µ°¿Ç¹«Ô¢¡¢ÇáËɳ±¦±¦Ê÷ÔÐÓý¡¢ZAKERÐÂÎÅ¡¢ÍøÒ×¹ûÕæ¿Î¡¢¼Ý¿¼±¦µä¡¢Æ¯ÁÁ˵¡¢ÂìÒ϶Ì×â¡¢¿ì¼ô¼­¡¢360ÕûÀí¾Þ½³¡¢µÃÎï¡¢ËѺüÊÓÆµ¡¢Ó³¿ÍÖ±²¥µÈ101¿îAPP±£´æËðº¦Óû§È¨ÒæÐÐΪ¡£ ¡£¡£¡£¡£¡£ÕâЩӦÓÃÈí¼þÖ÷񻃾¼°ÎÊÌâÊÇÎ¥¹æÍøÂçСÎÒ˽¼ÒÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬ÁíÍâ»¹Éæ¼°APPÇ¿ÖÆ¡¢ÆµÈÔ¡¢Ì«¹ýË÷ȡȨÏÞ£¬£¬£¬£¬£¬£¬£¬Ç¿ÖÆÓû§Ê¹Óö¨ÏòÍÆË͹¦Ð§£¬£¬£¬£¬£¬£¬£¬³¬¹æÄ£ÍøÂçСÎÒ˽¼ÒÐÅÏ¢µÈÎÊÌâ¡£ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

http://tech.cnr.cn/techgd/20200831/t20200831_525234083.shtml


2¡¢Å²ÍþÒé»áÓʼþϵͳÔâ¹¥»÷£¬£¬£¬£¬£¬£¬£¬¹¤µ³ºÍÖÐÐĵ³¾ùÊÜÓ°Ïì


2.jpg


ŲÍþÒé»á£¨Storting£©Ðû²¼ÉùÃ÷£¬£¬£¬£¬£¬£¬£¬ÌåÏÖÓкڿ͹¥»÷Æä³ÉÔ±µÄµç×ÓÓʼþÕÊ»§²¢ÇÔÈ¡Êý¾Ý¡£ ¡£¡£¡£¡£¡£¸ÃÊÂÎñÕýÔÚÊÓ²ìÖУ¬£¬£¬£¬£¬£¬£¬ÏÖÔÚÉв»ÇåÎú±»µÁÊý¾ÝµÄÊýÄ¿¡¢ÖÖÀàÒÔ¼°¹¥»÷µÄÆÆËðˮƽ¡£ ¡£¡£¡£¡£¡£Å²Íþ¹¤µ³µÄJarle RoheimH?konsen֤ʵ£¬£¬£¬£¬£¬£¬£¬¹¤µ³³ÉÔ±ºÍÕþ¿ÍÔÚÕâ´Î¹¥»÷ÖоùÊܵ½Ó°Ï죬£¬£¬£¬£¬£¬£¬Í¬Ê±ÖÐÐĵ³Ò²È·ÈÏÆä´ú±íºÍÔ±¹¤Êܵ½ÁËÓ°Ïì¡£ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/hackers-breached-norwegian-parliament-emails-to-steal-data/


3¡¢CiscoÖÒÑÔÆäIOS XR±£´æ0day²¢Òѱ»ÔÚҰʹÓÃ


3.jpg


˼¿ÆÉÏÖÜÁùÖÒÑÔ˵£¬£¬£¬£¬£¬£¬£¬ÆäIOS XR±£´æÒ»¸öеÄ0day£¬£¬£¬£¬£¬£¬£¬ÏÖÔÚÒѱ»ºÚ¿ÍÔÚҰʹÓᣠ¡£¡£¡£¡£¡£¸ÃÎó²î±»¸ú×ÙCVE-2020-3566£¬£¬£¬£¬£¬£¬£¬Ó°ÏìÁ˲Ù×÷ϵͳIOS XR°æ±¾¸½´øµÄ¾àÀëʸÁ¿×鲥·ÓÉЭÒé(DVMRP)¹¦Ð§£¬£¬£¬£¬£¬£¬£¬¸Ã°æ±¾µÄ²Ù×÷ϵͳͨ³£×°ÖÃÔÚµçÐż¶ºÍÊý¾ÝÖÐÐÄ·ÓÉÆ÷ÉÏ¡£ ¡£¡£¡£¡£¡£Ë¼¿ÆÌåÏÖ£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²îÊÇÓÉÓÚInternet×éÖÎÀíЭÒ飨IGMP£©Êý¾Ý°üµÄÐÐÁÐÖÎÀíȱ·¦ËùÖ£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ý·¢ËÍÌØÖÆµÄIGMPÁ÷Á¿À´Ê¹ÓôËÎó²î¡£ ¡£¡£¡£¡£¡£ÀÖ³ÉʹÓøÃÎó²î¿Éµ¼ÖÂÄÚ´æºÄ¾¡£¬£¬£¬£¬£¬£¬£¬´Ó¶øµ¼ÖÂÆäËûÀú³Ì£¨ÈçÄÚ²¿ºÍÍⲿ·ÓÉЭÒ飩²»Îȹ̡£ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/cisco-warns-of-actively-exploited-ios-xr-zero-day/


4¡¢Cisco Jabber±£´æÔ¶³ÌÖ´ÐдúÂëÎó²î£¬£¬£¬£¬£¬£¬£¬ÏÖÒѱ»ÐÞ¸´


4.jpg


WatchcomµÄOlav Sortland Thoresen·¢Ã÷Windows°æCisco JabberÖб£´æÑÏÖØµÄ´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬£¬£¬£¬ÏÖÒѱ»ÐÞ¸´¡£ ¡£¡£¡£¡£¡£¸ÃÎó²î±»¸ú×ÙΪCVE-2020-3495£¬£¬£¬£¬£¬£¬£¬ CVSSΪ9.9·Ö£¬£¬£¬£¬£¬£¬£¬ÊÇÓÉÓÚ´«ÈëÐÂÎÅÄÚÈݵÄÊäÈëÑéÖ¤²»×¼È·ÒýÆðµÄ¡£ ¡£¡£¡£¡£¡£¾­ÓÉÉí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓöñÒâµÄ¿ÉÀ©Õ¹ÐÂÎźÍ״̬ЭÒ飨XMPP£©ÐÂÎÅʹÓøÃÎó²î£¬£¬£¬£¬£¬£¬£¬ÀÖ³ÉʹÓú󹥻÷Õß¿ÉÔÚÄ¿µÄϵͳÉÏÖ´ÐÐí§Òâ³ÌÐò¡£ ¡£¡£¡£¡£¡£Ë¼¿Æ²úÆ·Çå¾²ÊÂÎñÏìӦС×飨PSIRT£©ÌåÏÖ£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²îÏÖÔÚÉÐδ±»ÆÕ±éʹÓᣠ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/cisco-fixes-critical-code-execution-bug-in-jabber-for-windows/


5¡¢Ó¢ÌضûÐû²¼Î¢´úÂëÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬Ö÷ÒªÊÊÓÃÓÚWin10ϵÁÐ


5.jpg


MicrosoftÐû²¼ÁËIntel΢´úÂë¸üУ¬£¬£¬£¬£¬£¬£¬ÒÔÐÞ¸´Intel CPUÖеÄÓ²¼þÎó²î¡£ ¡£¡£¡£¡£¡£´Ë´Î¸üÐÂÐû²¼Á˰˸ö¿ÉÑ¡¸üУ¬£¬£¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔWindows 10 2004¡¢1909¡¢1903¡¢1809¡¢1803¡¢1709¡¢1703ºÍ1607µÈ°æ±¾£¬£¬£¬£¬£¬£¬£¬ÐÞ¸´ÁËAmber Lake¡¢Avoton¡¢BroadwellºÍCascade LakeµÈ56¿îCPUÖÐÎó²î¡£ ¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬Ó¢Ìضû΢Âë¸üв¢²»¿Éͨ¹ýWindows Update×°Ö㬣¬£¬£¬£¬£¬£¬±ØÐèÊÖ¶¯×°Öᣠ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/new-intel-microcode-updates-for-windows-10-fix-cpu-hardware-bugs/