ÐÅÏ¢°²È«Öܱ¨-2019ÄêµÚ28ÖÜ

°ä²¼¹¦·ò 2019-07-22

±¾Öܰ²È«Ì¬ÊÆ×ÛÊö



2019Äê7ÔÂ15ÈÕÖÁ21ÈÕ¹²ÊÕ¼°²È«·ì϶50¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇNGINX njs nxt_vsprintf»º³åÇøÒç¶Âí½Å£»SolarWinds Orion Network Performance MonitorÔ¶³Ì´úÂëÖ´Ðзì϶£»CentOS Web PanelδÊÚȨ½Ó¼û·ì϶£»Palo Alto Networks PAN-OS CVE-2019-1576ºÅÁî×¢Èë·ì϶£»Linaro OP-TEE optee_os»º³åÇøÒç¶Âí½Å¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊǹ㲥µç̨KHSUÒòÀÕË÷Èí¼þ¹¥»÷µ¼Ö½ÚÄ¿ÖжÏ£»Evite½ü1.01ÒÚÕË»§ÐÅϢй¶£¬Òѱ»HIBPÊÕ¼£»±£¼ÓÀûÑǹú¶È˰Îñ¾ÖÔâºÚ¿ÍÈëÇÖ£¬500¶àÍò¹«ÃñÐÅÏ¢±»µÁ£»¾ÆµêÖÎÀí¹«Ë¾AavGoÒâ±íй¶800Íò¿Í»§ÐÅÏ¢£»¹þÈø¿Ë˹̹µ±¾ÖÀ¹½Ø¾³ÄÚËùÓеÄHTTPSÁ÷Á¿¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖС£



³ÁÒª°²È«·ì϶Áбí



1. NGINX njs nxt_vsprintf»º³åÇøÒç¶Âí½Å


NGINX njs nxt/nxt_sprintf.cÎļþµÄnxt_vsprintf´æÔÚ»º³åÇøÒç¶Âí½Å£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐËÁÒâ´úÂë¡£
https://github.com/torvalds/linux/commit/6994eefb0053799d2e07cd140df6c2ea106c41ee

2. SolarWinds Orion Network Performance MonitorÔ¶³Ì´úÂëÖ´Ðзì϶


SolarWinds Orion Network Performance Monitor OrionModuleEngine·þÎñ´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Äܹ»SYSTEMÓû§Ö´ÐÐËÁÒâ´úÂë¡£
http://www.securityfocus.com/bid/107061

3. CentOS Web PanelδÊÚȨ½Ó¼û·ì϶


CentOS Web Panel´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬ÒÔÆäËûÓû§ÃûÈÆ¹ýÑé֤δÊÚȨ½Ó¼û¡£
https://github.com/i3umi3iei3ii/CentOS-Control-Web-Panel-CVE/blob/master/CVE-2019-13360.md

4. Palo Alto Networks PAN-OS CVE-2019-1576ºÅÁî×¢Èë·ì϶


Palo Alto Networks PAN-OS´æÔÚÊäÈëÑéÖ¤·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉÖ´ÐÐËÁÒâOSºÅÁî¡£
https://securityadvisories.paloaltonetworks.com/Home/Detail/156

5. Linaro OP-TEE optee_os»º³åÇøÒç¶Âí½Å


Linaro OP-TEE optee_os´æÔÚ»º³åÇøÒç¶Âí½Å£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐËÁÒâ´úÂë¡£
https://github.com/OP-TEE/optee_os/commit/70697bf3c5dc3d201341b01a1a8e5bc6d2fb48f8



³ÁÒª°²È«ÊÂÎñ×ÛÊö



1¡¢¹ã²¥µç̨KHSUÒòÀÕË÷Èí¼þ¹¥»÷µ¼Ö½ÚÄ¿ÖжÏ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÃÀ¹ú¼ÓÖݺ鱤ÖÝÁ¢´óѧռÓеÄKHSU¹ã²¥µç̨Ôâµ½ÀÕË÷Èí¼þ¹¥»÷£¬µ¼Ö¸õç̨µÄËùÓÐϵͳºÍ´æ´¢·þÎñÆ÷̱»¾£¬½ÚÄ¿±»ÆÈÖжÏ¡£µ«KHSUÈ·ÈϳÆÊÜϰȾµÄ·þÎñÆ÷²¢Î´Ô̺¬ÈκÎÃô¸ÐÐÅÏ¢¡£KHSUÔÚ7ÔÂ1ÈÕ·¢ÏÖÕâ´Î¹¥»÷£¬¹¥»÷ÕßÀûÓÃÁËKHSUϵͳÖеݲȫ·ì϶¡£KHSU°µÊ¾Ã»ÓÐÊÕµ½Êê½ðÒªÇó£¬Ò²²»ÖªÂ·¹¥»÷µÄÆðÔ´¡£ÔÚ·¢ÏÖÊÂÎñºó£¬KHSUÏòÁª¹ú·¨Âɲ¿ÃźÍÁª¹úͨѶίԱ»á»ã±¨ÁËÕâÒ»ÊÂÎñ¡£

Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/khsu-radio-stations-regular-programming-interrupted-due-to-ransomware-attack-e39dbd3d

2¡¢Evite½ü1.01ÒÚÕË»§ÐÅϢй¶£¬Òѱ»HIBPÊÕ¼


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


2019Äê5ÔÂEvite°ä²¼Êý¾Ýй¶֪ͨ£¬°µÊ¾Æä·þÎñÆ÷´Ó2ÔÂ22ÈÕ·¢ÏÖδÊÚȨ½Ó¼û£¬Ô¼1000ÍòÓû§ÐÅϢй¶¡£µ«Æ¾¾ÝHave I Been PwnedÍøÕ¾ÊÕ¼µÄÊý¾Ý¿â£¬ÕâÒ»Êý×ÖÒª´óµÃ¶à£¬¹²Óнü1.01ÒÚÓû§ÐÅÏ¢±»µÁ¡£ÕâЩÊý¾Ý×îÔç¿É×·ÒäÖÁ2013Ä꣬й¶µÄÐÅÏ¢Ô̺¬ÐÕÃû¡¢µç»°ºÅÂë¡¢ÏÖʵµØÖ·¡¢µ®ÉúÈÕÆÚ¡¢ÐÔ±ð¡¢Ã÷ÎÄÃÜÂëºÍµç×ÓÓʼþµØÖ·¡£×î³õ±»Ð¹Â¶µÄÊý¾Ý¿âÔÚDream MarketÉÏÏúÊÛ£¬µ«¸ÃÍøÕ¾Òѱ»¾¯·½¹Ø¹Ø£¬Òò¶øÄ¿Ç°Éв»Ã÷ÏÔÕâ¸ö¸ü´óµÄÊý¾Ý¿âÊÇ·ñÒ²ÔÚÏúÊÛ¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/evite-invites-over-100-million-people-to-their-data-breach/

3¡¢±£¼ÓÀûÑǹú¶È˰Îñ¾ÖÔâºÚ¿ÍÈëÇÖ£¬500¶àÍò¹«ÃñÐÅÏ¢±»µÁ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¾Ýzdnet±¨Â·£¬Ò»ºÚ¿Í×éÖ¯´Ó±£¼ÓÀûÑǹú¶È˰Îñ¾Ö£¨NRA£©ÖÐÇÔÈ¡ÁËÔ¼110¸öÊý¾Ý¿â£¬ÆäÖÐÔ̺¬½ü21GBµÄÓ×ÎÒÊý¾Ý£¬ÊÜÓ°ÏìÈËÊý³¬¹ý500Íò¡£ºÚ¿Í½«²¿Ãű»µÁÊý¾Ýͨ¹ýµç×ÓÓʼþ·¢Ë͸ø±¾µØÃ½Ì壬µ¼ÖÂÊÂÎñÆØ¹â¡£¸Ã¹úÓйز¿ÃÅÒѾ­ÈÏ¿ÉÕâÒ»ÊÂÎñ£¬²¢ÕýÓë±£¼ÓÀûÑǹú¶È°²È«¾ÖºÏ×÷µ÷²é¡£Ð¹Â¶µÄÐÅÏ¢Ô̺¬±£¼ÓÀûÑǹ«ÃñµÄÓ×ÎÒ¼ø±ðÂ루PIN£©¡¢ÐÕÃû¡¢¼ÒͥסַºÍ²ÆÕþÊÕÈ룬ÕâЩÊý¾Ý×îÔç¿É×·Òäµ½2007Äê¡£

Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/bulgarias-national-revenue-agency-hacked-to-steal-over-five-million-peoples-data-8e64c8d9

4¡¢¾ÆµêÖÎÀí¹«Ë¾AavGoÒâ±íй¶800Íò¿Í»§ÐÅÏ¢


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Wizcase°²È«×êÑÐÔ±Daniel Brown·¢Ï־ƵêÖÎÀíÉÌAavGoµÄÒ»¸öElasticsearchÊý¾Ý¿â¿É¹«¿ª½Ó¼û£¬¸ÃÊý¾Ý¿âÔ̺¬800ÍòÌõ¿Í»§ÐÅÏ¢£¬Ô̺¬Ô¤Ô¼ÐÅÏ¢¡¢¿Í»§Í¶Ëß¡¢·¢Æ±¡¢¹¤µ¥¡¢Ô±¹¤±¸Íü¼ºÍÐÂÎÅ¡¢¾Æµê·¿¼äͼƬ¡¢ÎïÆ·°Ü»µÍ¼Æ¬ÒÔ¼°¿Í»§µÄÓ×ÎÒÐÅÏ¢£¨ÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢µç»°ºÅÂë¡¢ÓÊÏ䵨ַ¡¢×¡Ö·¡¢»éÒöÇé¿ö¡¢µÇ¼ÐÅÏ¢ºÍ¸¶¿î·½Ê½£©¡£Ð¹Â¶µÄÊý¾Ý»¹Ô̺¬¾ÆµêÖÎÀíÔ±µÄ¾ßÌåµÇ¼ÐÅÏ¢£¬ÀýÈçÖÎÀíÃæ°å¡¢Ô¤Ô¼ÏµÍ³ºÍÄÚ²¿Êý¾Ý¿âµÄÓû§ÃûºÍÃÜÂë¡£ÊÜÓ°ÏìµÄ¾ÆµêÔ̺¬The Row Hotel¡¢Stay Cal HotelsµÈÊ®¶à¼Ò¾Æµê¡£¸Ã¹«Ë¾ÒÑÔÚ7ÔÂ16ÈÕ¶ÔÊý¾Ý¿â²ÉÈ¡Á˱£»¤´ëÊ©¡£

Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/unprotected-elasticsearch-database-belonging-to-aavgo-exposed-8-million-records-of-guest-details-f5fb1eac

5¡¢¹þÈø¿Ë˹̹µ±¾ÖÀ¹½Ø¾³ÄÚËùÓеÄHTTPSÁ÷Á¿


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¹þÈø¿Ë˹̹µ±¾ÖÒÑ´Ó7ÔÂ17ÈÕÆðÍ·À¹½ØÆä¾³ÄÚµÄËùÓÐHTTPSÁ÷Á¿¡£ÔÚ±¾µØµ±¾ÖµÄÅúʾÏ£¬±¾µØISPÇ¿ÔìÓû§ÔÚÿ¸öÉ豸ºÍä¯ÀÀÆ÷ÖÐ×°Öõ±¾ÖÐû¸æµÄÖ¤Êé¡£¸ÃÖ¤Ê齫ÔÊÐíµ±¾Ö»ú¹¹½âÃÜÓû§µÄHTTPSÁ÷Á¿²¢²é¿´ÆäÄÚÈÝ¡£ÔÚÓû§×°ÖøÃÖ¤Êé֮ǰ£¬ËûÃǽ«ÎÞ·¨½Ó¼û»¥ÁªÍø¡£µ±¾Ö¹ÙÔ±°µÊ¾´Ë¾ÙÖ¼ÔÚ¼ÓÇ¿¶Ô¹«Ãñ¡¢µ±¾Ö»ú¹¹ºÍ˽ӪÆóÒµµÄ±£»¤£¬Ê¹ÆäÃâÔâºÚ¿Í¹¥»÷¡¢»¥ÁªÍøÚ²Æ­µÈÍøÂçÍþв¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/kazakhstan-government-is-now-intercepting-all-https-traffic/