Oracle°ä²¼1Ô³ÁÒª²¹¶¡¸üУ¬½¨¸´334¸ö·ì϶£»Intel½¨¸´»úÄÜ·ÖÎö¹¤¾ßVTune ProfilerÖеÄÌáȨ·ì϶
°ä²¼¹¦·ò 2020-01-16
1.Oracle°ä²¼1Ô³ÁÒª²¹¶¡¸üУ¬½¨¸´334¸ö·ì϶
OracleÔÚ2020Äê1Ôµļ¾¶È³ÁÒª²¹¶¡¸üУ¨CPU£©Öн¨¸´ÁËÆäËùÓвúƷϵÁеÄ334¸ö·ì϶£¬ÆäÖÐÓÐ43¸ö·ì϶±»±êΪÑϳÁ¼¶±ð£¬ÆäCVSSÆÀ·ÖΪ9.1»ò¸ü¸ß¡£±¾´ÎCPUÖн¨¸´µÄ·ì϶ÊýÁ¿Óë2019Äê7Ôµĺ¹Çà×î¸ß¼Í¼ά³ÖÒ»Ö£¬³¬¹ýÁË2017Äê7ÔµÄ308¸ö·ì϶µÄ¼Í¼¡£ÕâЩ¸üк¸ÇÁËOracle²¿Êð×î¿í·ºµÄ²úÆ·½¨¸´²¹¶¡£¬Ô̺¬OracleÊý¾Ý¿â·þÎñÆ÷£¨¹²12¸ö²¹¶¡£¬ÆäÖÐ3¸öÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓã©£»OracleͨѶÀûÓ÷¨Ê½£¨25¸ö²¹¶¡£¬ÆäÖÐ23¸öÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓã¬6¸öΪÑϳÁ¼¶±ð£©£»OracleÆóÒµÖÎÀíÆ÷£¨50¸ö²¹¶¡£¬ÆäÖÐ10¸öÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓã¬4¸öΪÑϳÁ¼¶±ð£©£»OracleÈÚºÏÖÐÑë¼þ£¨38¸ö²¹¶¡£¬ÆäÖÐ30¸öÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓã¬3¸öÑϳÁ¼¶±ð£©£»ºÏÓÃÓÚOracle MySQLµÄ19¸öа²È«²¹¶¡£¨6¸öÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓã©£»ÒÔ¼°Oracle E-Business Suite£¨23¸ö²¹¶¡£¬ÆäÖÐ21¸öÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓã¬2¸öΪÑϳÁ¼¶±ð£©µÈ¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/oracle-cpu-all-time-patch-high-january/151861/
2.InfiniteWPºÍWP Time Capsule²å¼þ·ì϶£¬32Íò¸öÍøÕ¾ÊÜÓ°Ïì
WordPress²å¼þInfiniteWPºÍWP Time CapsuleÖеÄÑϳÁ·ì϶ʹµÃ32Íò¸öÍøÕ¾Ò×Êܹ¥»÷¡£ÕâÁ½¸ö²å¼þÓÃÓÚÔ®ÊÖÓû§ÖÎÀíһ̨·þÎñÆ÷ÉϵĶà¸öWordPressÍøÕ¾£¬²¢ÔÚ°ä²¼¸üÐÂʱΪÎļþºÍÊý¾Ý¿âÌõ¿î´´½¨±¸·Ý¡£WebArx°²È«×êÑÐÈËÔ±·¢ÏÖËüÃǵĴúÂëÖдæÔÚÂß¼ÃýÎó£¬Ê¹µÃ¹¥»÷ÕßÄܹ»ÈƹýÃÜÂëÀ´µÇ¼ÖÎÀíÔ¹ØË»§¡£Æ¾¾ÝWordPress²å¼þ¿â£¬InfiniteWP±»×°ÖÃÔÚ30¶àÍò¸öÍøÕ¾ÉÏ£»¶øWP Time CapsuleµÄ×°ÖÃÁ¿ÖÁÉÙΪ2Íò¡£×êÑÐÈËÔ±·¢´Ë¿ÌµÍÓÚ°æ±¾1.9.4.5µÄInfiniteWPÖУ¬¹¥»÷ÕßÄܹ»Ê¹ÓôøÓÐJSONºÍBase64±àÂëµÄpayloadµÄPOSTÒªÇóÀ´ÈƹýÃÜÂ룬ͨ¹ý½ö֪·ÖÎÀíÔ±Óû§ÃûÀ´µÇ¼¡£¶øÔÚµÍÓÚ1.21.16µÄWP Time Capsule°æ±¾ÖУ¬¹¥»÷Õß¿Éͨ¹ýÔÚÔʼPOSTÒªÇóÖÐÔö³¤¶ñÒâ×Ö·û´®À´Å²Óú¯Êý²¶»ñ¿ÉÓõÄÖÎÀíÔ¹ØË»§ÁÐ±í²¢ÒÔµÚÒ»¸öÖÎÀíÔ±Éí·ÝµÇ¼¡£Ä¿Ç°ÕâÁ½¸ö²å¼þ¶¼ÒѰ䲼¸üн¨¸´Á˸ÃÎÊÌâ¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/critical-bugs-in-wordpress-plugins-infinitewp-wp-time-capsule-expose-300000-websites-to-attack/
3.Adobe°ä²¼1Ô°²È«¸üУ¬½¨¸´¶à¿î²úÆ·ÖеÄ9¸ö·ì϶
Adobe°ä²¼1Ô°²È«¸üУ¬½¨¸´Adobe Experience ManagerºÍAdobe Illustrator CCÖеÄ9¸ö°²È«·ì϶¡£ÕâÊÇAdobeÔÚ2020Äê°ä²¼µÄÊ׸ö°²È«¸üУ¬ÁîÈËÒâ±íµÄÊDZ¾´Î¸üв¢Î´Ô̺¬ÈκÎÕë¶ÔFlash ManagerµÄ²¹¶¡¡£Õâ´Î¸üн¨¸´ÁËAdobe Experience ManagerÖеÄ4¸öÐÅϢй¶·ì϶£¬µ«Ö»ÓÐ3¸ö±»¹éÀàΪ¡°³ÁÒª¡±£¬ÁíÒ»¸ö±»¹éÀàΪ¡°Öеȡ±¡£Õâ´Î¸üл¹½¨¸´ÁËAdobe IllustratorÖеÄ5¸ö¡°ÑϳÁ¡±µÄÔ¶³ÌÖ´ÐдúÂë·ì϶£¨CVE-2020-3710~CVE-2020-3714£©¡£½¨ÒéËùÓÐЧ»§¾¡¿ì×°ÖúÏÓõĸüС£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/adobe-releases-their-january-2020-security-updates/
4.Intel½¨¸´»úÄÜ·ÖÎö¹¤¾ßVTune ProfilerÖеÄÌáȨ·ì϶
Intel½¨¸´ÁËÆä»úÄÜ·ÖÎö¹¤¾ßVTune ProfilerÖеÄÌáȨ·ì϶£¨CVE-2019-14613£©£¬¸Ã·ì϶±»¹éÀàΪÑϳÁ¼¶±ð£¬¿ÉÔÊÐí¾¹ýÉí·ÝÑéÖ¤µÄ±¾µØ¹¥»÷ÕßDZÔÚµØÌáÉýÌØÈ¨¡£Ö»¹ÜVTune ProfilerÖ§³ÖWindows¡¢LinuxºÍAndroidƽ̨£¬µ«Intel°µÊ¾Ö»ÓÐWindows°æ±¾Êܵ½Ó°Ï죬²¢ÇҸ÷ì϶ԴÓÚVTune AmplifierÇý¶¯·¨Ê½ÖеIJ»µ±½Ó¼û½ÚÔì¡£³ý´ËÖ®±í£¬Intel»¹ÔÚ1Ô²¹¶¡¸üÐÂÖн¨¸´ÁË5¸ö·ì϶£¬µ«ÕâЩ·ì϶µÄÑϳÁÐÔ¾ùΪ¡°ÖÓ×±»ò¡°µÍ¡±¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/intel-fixes-high-severity-flaw-in-performance-analysis-tool/151837/
5.°Ä´óÀûÑÇP£¦NÒøÐÐÔâµ½ÍøÂç¹¥»÷£¬¿Í»§ÕË»§ÐÅϢй¶
°Ä´óÀûÑÇP£¦NÒøÐаµÊ¾ËüÃÇÔÚ·þÎñÆ÷Éý¼¶ÆÚ¼äÔâµ½ÍøÂç¹¥»÷£¬µ¼Ö¿ͻ§µÄPIIºÍÕË»§ÐÅϢй¶¡£P£¦NÒøÐÐÊÇPolice£¦Nurses LimitedµÄÒ»¸ö²¿ÃÅ£¬ÔÚÎ÷°Ä´óÀûÑÇÖÝÔËÓª£¬Æä°ä²¼µÄ֪ͨ³ÆÍ¨¹ýÆä¿Í»§¹ØÏµÖÎÀí£¨CRM£©Æ½Ì¨²úÉúÁËÐÅϢй¶ÊÂÎñ¡£¸ÃÒøÐаµÊ¾ÔÚÈ¥Äê12ÔÂ12ÈÕǰºó½øÐÐÁË·þÎñÆ÷Éý¼¶£¬µ«ÔÚ´ËÆÚ¼äÔâµ½ÍøÂç¹¥»÷£¬¾Ý³ÆÎª¸ÃÒøÐÐÌṩÍйܷþÎñµÄ¹«Ë¾Êǹ¥»÷Èë¿Úµã¡£¿ÉÄÜй¶µÄÐÅÏ¢Ô̺¬¿Í»§µÄÐÕÃû¡¢µØÖ·¡¢µç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂë¡¢¿Í»§±àºÅ¡¢´ºÇï¡¢ÕʺźÍÕÊ»§Óà¶îÒÔ¼°¿ÉÄÜÔ̺¬ÔÚ»¥¶¯¼Í¼ÖеÄÐÅÏ¢£¬µ«²»Ô̺¬ÃÜÂë¡¢Éç»á°²È«ºÅÂ롢˰ÎñÎļþ¡¢¼ÝÕÕ»òÐÅÓþ¿¨ÐÅÏ¢¡£Ä¿Ç°Éв»Ã÷ÏÔÓм¸¶à¿Í»§Êܵ½Ó°Ïì¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/p-n-bank-discloses-data-breach-customer-pii-account-information-stolen/
6.Ó¢¹úÕ÷ѯ¹«Ë¾CHS ConsultingÒâ±íй¶ÊýǧԱ¹¤ÐÅÏ¢
vpnMentor·¢ÏÖÒ»¸öÅäÖÃÃýÎóµÄAWS S3´æ´¢Í°Ð¹Â¶ÁËÊýǧӢ¹úÉÌÎñÈËÔ±µÄÓ×ÎÒ¾ßÌåÐÅÏ¢¡£¸Ã´æ´¢Í°ÊôÓÚÓ¢¹úÕ÷ѯ¹«Ë¾CHS Consulting£¬²¢ÇÒδ¾Éí·ÝÑéÖ¤¼´¿É¹«¿ª½Ó¼û¡£µ«ÓÉÓڸù«Ë¾Ã»ÓÐÍøÕ¾£¬×êÑÐÈËÔ±ÉÐδÄÜÓë¸Ã¹«Ë¾½øÐÐÈ·ÈÏ¡£Ð¹Â¶µÄÊý¾Ý¿âÖÐÔ̺¬¶à¼ÒÓ¢¹úÕ÷ѯ¹«Ë¾£¨Ô̺¬Eximius Consultants¡¢Dynamic PartnersºÍIQ Consulting£©µÄÈËÁ¦×ÊÔ´²¿ÃÅÎļþ£¬Ö»¹ÜÓÐЩ¼Í¼Äܹ»×·Òäµ½2011Ä꣬µ«´óÎÞÊýÊý¾ÝÀ´×Ô2014-15Äê¡£¼Í¼ÖÐÔ̺¬»¤ÕÕɨÃè¼þ¡¢Ë°ÎñÎļþ¡¢·¸×ïÐÅÏ¢¼Í¼ºÍ²¼¾°µ÷²é¡¢ÓëHMRCÓйصÄÎÄÊ鹤×÷¡¢µç×ÓÓʼþºÍ¸öÈËÐÂÎÅÒÔ¼°Ò»ÏµÁÐÓ×ÎÒ¼ø±ðÐÅÏ¢£¬Ô̺¬ÐÕÃû¡¢µç×ÓÓʼþºÍ¼Òͥסַ¡¢µ®ÉúÈÕÆÚºÍµç»°ºÅÂëµÈ¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/uk-consultancies-leak-data/


¾©¹«Íø°²±¸11010802024551ºÅ