ÐÅÏ¢°²È«Öܱ¨-2019ÄêµÚ36ÖÜ

°ä²¼¹¦·ò 2019-09-16

> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö



2019Äê9ÔÂ09ÈÕÖÁ13ÈÕ¹²ÊÕ¼°²È«·ì϶48¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇDabman & Imperial Web Radio Devices telnetºóÃÅ·ì϶  £»Exim³õʼTLSÎÕÊÖËÁÒâ´úÂëÖ´Ðзì϶  £»Apache OFBiz template×¢Èë´úÂëÖ´Ðзì϶  £»Adobe Flash Player PSDKÄÚ´æÃýÎóÒýÓ÷ì϶  £»Microsoft OfficeÄÚ´æ·ÛËé´úÂëÖ´Ðзì϶¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇDealer LeadsÒâ±íй¶1.98ÒÚÆû³µÂò¼Ò¼Í¼  £»ÐÂNetCAT¹¥»÷¿É´ÓÓ¢ÌØ¶ûCPUÖÐÇÔÈ¡Êý¾Ý  £»ÃÀ¹ú¹ú¶È³ß¶ÈÓë¼¼Êõ×êÑÐÔº°ä²¼ÒþÖÔ¿ò¼Ü³õ¸å  £»ºÚ¿ÍÀûÓÃDoS·ì϶µ¼ÖÂÃÀ¹úµçÍø·À»ðǽ·´¸´³ÁÆô  £»Telestar±»ÆØTelnetºóÃÅ·ì϶ӰÏì100¶àÍòIoTÉ豸¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖС£


> ³ÁÒª°²È«·ì϶Áбí



1. Dabman & Imperial Web Radio Devices telnetºóÃÅ·ì϶


Dabman & Imperial Web Radio Devices´æÔÚδÎĵµ»¯µÄtelnetºóÃÅ·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉδÊÚȨ½Ó¼ûÀûÓá£
https://packetstormsecurity.com/files/154416/Dabman-And-Imperial-Web-Radio-Devices-Undocumented-Telnet-Backdoor.html

2. Exim³õʼTLSÎÕÊÖËÁÒâ´úÂëÖ´Ðзì϶


Exim´¦ÖÃTLSÁ´½ÓµÄ³õʼTLSÎÕÊÖ´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬷¢ËÍÒ»¸öÒÔ¡°\0¡±½áβµÄSNIÀ´´¥·¢·ì϶£¬Ö´ÐÐËÁÒâ´úÂë¡£
https://www.kb.cert.org/vuls/id/672565/

3. Apache OFBiz template×¢Èë´úÂëÖ´Ðзì϶


Apache OFBiz´æÔÚtemplate×¢Èë·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉÖ´ÐÐËÁÒâ´úÂë¡£
https://www.auscert.org.au/bulletins/ESB-2019.3469/

4. Adobe Flash Player PSDKÄÚ´æÃýÎóÒýÓ÷ì϶


Adobe Flash Player PSDK namespace´¦ÖöÔÏó´æÔÚÄÚ´æ·ÛËé·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ  £»òÖ´ÐÐËÁÒâ´úÂë¡£
https://www.zerodayinitiative.com/advisories/ZDI-19-818/

5. Microsoft OfficeÄÚ´æ·ÛËé´úÂëÖ´Ðзì϶


Microsoft Office´¦ÖÃÎĵµ´æÔÚÄÚ´æ·ÛËé·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ  £»òÖ´ÐÐËÁÒâ´úÂë¡£
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-1264


 > ³ÁÒª°²È«ÊÂÎñ×ÛÊö



1¡¢Dealer LeadsÒâ±íй¶1.98ÒÚÆû³µÂò¼Ò¼Í¼


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Dealer LeadsµÄElasticsearchÊý¾Ý¿âδÊÜÃÜÂë±  £»¤£¬µ¼ÖÂ1.98ÒÚÆû³µÂò¼Ò¼Í¼ÔÚÍøÉ϶³ö¡£Dealer Leadsͨ¹ýSEOÓÅ»¯µÄÖ¸±êÍøÕ¾ÍøÂçÍøÂçÓйØÇ±ÔÚÂò¼ÒµÄÐÅÏ¢£¬°²È«×êÑÐÔ±Jeremiah Fowler°µÊ¾ÕâÐ©ÍøÕ¾Îª·Ã¿ÍÌṩ¹º³µ×êÑÐÐÅÏ¢ºÍ·ÖÀà¸æ°×£¬ÍøÂçµÄÐÅÏ¢±»·¢Ë͸øÆû³µ¾­ÏúÉÌ×÷ΪÏúÊÛÊý¾Ý¡£¸Ã¶³öµÄÊý¾Ý¿â×ܹ²Ô̺¬413GBÐÅÏ¢£¬Ô̺¬Ç±ÔÚ¹º³µÕßµÄÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂë¡¢ÎïÀíµØÖ·¡¢IPµØÖ·ÒÔ¼°´û¿îºÍ²ÆÕþÊý¾Ý¡¢³µÁ¾ÐÅÏ¢µÈ¡£

Ô­ÎÄÁ´½Ó£º
https://threatpost.com/198m-car-buyer-records-exposed-online/148231/

2¡¢ÐÂNetCAT¹¥»÷¿É´ÓÓ¢ÌØ¶ûCPUÖÐÇÔÈ¡Êý¾Ý


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


×êÑÐÈËÔ±·¢ÏÖÒ»ÖÖеIJàÐÅ·¹¥»÷£¬ËüÓ°ÏìÁË×Ô2012ÄêÒÔÀ´Ôì×÷µÄËùÓÐÏÖ´úÓ¢ÌØ¶û·þÎñÆ÷´¦ÖÃÆ÷¡£¸Ã¹¥»÷±»³ÆÎªNetCAT£¨ÍøÂ绺´æ¹¥»÷£©£¬ÓëÓ¢ÌØ¶ûµÄÊý¾ÝÖ±½ÓI/O¼¼Êõ£¨DDIO£©ÓйØ£¬DDIOÔÚ×îеÄÓ¢ÌØ¶û·þÎñÆ÷¼¶´¦ÖÃÆ÷ÖÐĬÈÏ´ò¿ª£¬Ô̺¬Intel Xeon E5¡¢E7ºÍSP´¦ÖÃÆ÷ϵÁС£¸Ã·ì϶£¨CVE-2019-11184£©µÄÀûÓÃÄѶȽϸߣ¬¹¥»÷Õß±ØÒª½øÐÐÉí·ÝÑéÖ¤£¬²¢ÇÒ±ØÒªÓëÖ¸±êϵͳ³ÉÁ¢Ö±½ÓÍøÂçÏνÓ¡£Ó¢Ìضû½«¸Ã·ì϶µÄCVSSÆÀ·ÖÈ·¶¨Îª2.6·Ö£¬²¢½¨ÒéÔÚÊÜÓ°ÏìµÄCPUÉϽûÓÃDDIOºÍRDMAÖ°ÄÜ£¬»òÏÞ¶È´Ó±í²¿²»ÊÜÐÅÀµµÄÍøÂçÖ±½Ó½Ó¼ûÒ×Êܹ¥»÷µÄϵͳ¡£¶î±íµÄ»º½â´ëÊ©Ô̺¬Ê¹ÓÿÉÄֿܵ¹°´Ê±¹¥»÷µÄÈí¼þÄ £¿é»òʹÓú㰴¹¦·òÐÎ×´µÄ´úÂë¡£

Ô­ÎÄÁ´½Ó£º
https://thehackernews.com/2019/09/netcat-intel-side-channel.html

3¡¢ÃÀ¹ú¹ú¶È³ß¶ÈÓë¼¼Êõ×êÑÐÔº°ä²¼ÒþÖÔ¿ò¼Ü³õ¸å

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÃÀ¹ú¹ú¶È³ß¶ÈÓë¼¼Êõ×êÑÐÔº£¨NIST£©°ä²¼ÁËÒ»¸öÒþÖÔ¿ò¼Ü³õ¸å£¬Ö¼ÔÚͨ¹ýÆóÒµ·çÏÕÖÎÀíÔ®ÊÔìóÒµ¸ÄÉÆÓ×ÎÒÒþÖÔ¡£NIST°µÊ¾£¬ÒþÖÔ¿ò¼ÜÖ¼ÔÚͨ¹ýÈý¸öÊÂÏîÔ®ÊÔìóÒµ±  £»¤Ó×ÎÒÒþÖÔ£ºÍ¨¹ýÔÚ·þÎñºÍ²úÆ·ÖÐÖ§³Ö·µÂ¾ö²ßÀ´³ÉÁ¢¿Í»§ÐÅÀµ  £»ÍƹãºÏ¹æÊ¹Ãü;ÒÔ¼°ÍƽøÓë¿Í»§ºÍ¼à¹Ü»ú¹¹¾ÍÒþÖÔʵ¼Ê½øÐйµÍ¨¡£¸ÃÕþ²ß×ñÑ­ÍøÂ簲ȫ¿ò¼ÜµÄ½á¹¹£¬ÓÉÖ÷Ìâ¡¢¸Å¿öºÍÖ´Ðвã×é³É¡£Ö÷ÌⲿÃÅÖ¼ÔÚÍÆ½ø¹ØÓÚÒþÖÔ±  £»¤ÔËÓªºÍ½øÕ¹Á˾ֵĶԻ°£¬¶ø¸Å¿ö²¿ÃÅÔòÍÆ¶¯Âú×ã×é֯ʹÃüºÍÒþÖÔ¼ÛÖµµÄ»î¶¯ºÍÁ˾ֵÄÓÅÏÈÖÈÐò¡£Ö´ÐвãÔò¶Ô×éÖ¯´¦ÖÃÒþÖÔ·çÏÕÁ÷³ÌµÄ³ä·ÖÐÔ½øÐйµÍ¨ºÍ¾ö²ßÌṩ֧³Ö¡£


Ô­ÎÄÁ´½Ó£º

https://www.executivegov.com/2019/09/nist-issues-preliminary-draft-of-privacy-framework/

4¡¢ºÚ¿ÍÀûÓÃDoS·ì϶µ¼ÖÂÃÀ¹úµçÍø·À»ðǽ·´¸´³ÁÆô


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


±±ÃÀµçÁ¦¿¿µÃסÐÔ¹«Ë¾£¨NERC£©ÉÏÖܰµÊ¾½ñÄêÔçЩʱ³½Ó°ÏìÃÀ¹úµçÍøÊµÌåµÄÍøÂ簲ȫÊÂÎñ²¢Ã»ÓÐ×î³õÉèÏëµÄÄÇÑùΣÏÕ¡£NERCÔÚÒ»·Ý»ã±¨ÖÐÖ¸³ö£¬ºÚ¿ÍÔÚ2019Äê3ÔÂ5ÈÕÀûÓÃDoS·ì϶µ¼ÖµçÍø·À»ðǽÔÚ10Ó×ʱÄÚ·´¸´³ÁÆô£¬¸ÃÊÂÎñÖ»Ó°ÏìÁËһЩµÍÓ°Ïì¼¶·¢µçÕ¾µãµÄÍøÂç±íΧ·À»ðǽ£¬²¢Ã»ÓÐÔì³ÉµçÁ¦¹©¸øµÄÈκÎÖжÏ¡£ËæºóµÄ·ÖÎöÈ·¶¨³ÁÆôÊÇÓÉÀûÓÃÒÑÖª·À»ðǽ·ì϶µÄ±í²¿ÊµÌåÌáÒéµÄ£¬ÔËÓªÉÌ×îÖÕ·¢ÏÖËûÃÇδÄÜΪÊܵ½¹¥»÷µÄ·À»ðǽÀûÓù̼þ¸üУ¬ÔÚ²Ù×÷Ô±²¿ÊðÊʵ±µÄ²¹¶¡ºó£¬·À»ðǽ²»ÔÙ³ÁÆô¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/cyber-security-incident-at-us-power-grid-entity-linked-to-unpatched-firewalls/


5¡¢Telestar±»ÆØTelnetºóÃÅ·ì϶ӰÏì100¶àÍòIoTÉ豸

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


±¾ÖÜÒ»Vulnerability-Lab×êÑÐÔ±Benjamin KunzÅû¶Telestar Digital GmbHÎÞÏßµçIoTÉ豸ÖеÄÁ½¸öÑϳÁ·ì϶£¨CVE-2019-13473ºÍCVE-2019-13474£©£¬¿ÉÔÊÐí¹¥»÷ÕßÔ¶³Ì½Ù³Öϵͳ¡£ÊÜÓ°ÏìµÄÉ豸Ô̺¬¸Ã¹«Ë¾µÄImperial£¦DabmanϵÁвúÆ·£¬ÆäÖÐÔ̺¬±ãЯʽÊÕÒô»úºÍDABÁ¢ÌåÉùϵͳ¡£ÕâЩ²úÆ·ÖØÒªÔÚÅ·ÖÞÏúÊÛ£¬»ùÓÚBusyBox Linux Debian²¢ÀûÓÃÀ¶ÑÀºÍ»¥ÁªÍøÏνÓ¡£Kunz·¢ÏÖÕâЩÉ豸ÔÚ23¶Ë¿ÚÉÏÆôÓÃÁËTelnet·þÎñ£¬µ«Ã»ÓÐÎĵµ¼Í¼£¬ÓÉÓÚѡȡÁËÈõÃÜÂ룬×êÑÐÍŶÓÄܹ»ÔÚ10·ÖÖÓÄÚ»ñÈ¡root½Ó¼ûȨÏÞ¡£×êÑÐÈËÔ±³Æ¿ÉÄÜÓг¬¹ý100Íǫ̀Éè±¸Ãæ¶Ô·çÏÕ¡£


Ô­ÎÄÁ´½Ó£º
https://www.zdnet.com/article/critical-vulnerabilities-impact-over-a-million-iot-radio-devices/