ÐÅÏ¢°²È«Öܱ¨-2020ÄêµÚ13ÖÜ
°ä²¼¹¦·ò 2020-03-31> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
2020Äê03ÔÂ23ÈÕÖÁ29ÈÕ¹²ÊÕ¼°²È«·ì϶62¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇMicrosoft Windows Adobe Type Manager Library×ÖÌå´¦ÖôúÂëÖ´Ðзì϶; Apple Safari Webkit CVE-2020-3901ÄÚ´æÃýÎóÒýÓôúÂëÖ´Ðзì϶£»Apache Shiro Spring dynamic controllersÑéÖ¤ÈÆ¹ý·ì϶£»rConfig lib/crud/search.crud.phpºÅÁî×¢Èë·ì϶£»3S-Smart Software Solutions CODESYS V3 web server»º³åÇøÒç¶Âí½Å¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇKeepnet Labs ESÊ·ýй¶³¬¹ý50Òڱʼͼ£¬¾ùΪÒÔǰй¶£»Î¢ÈíÖÒ¸æAdobe Type Manager¿âÖеÄÁ½¸öRCE 0day£»»ÝÆÕÔÙ´ÎÖҸ沿ÃÅSSD½«ÔÚÔËÐÐ4ÍòÓ×ʱºó³öÏÖ¹ÊÕÏ£»¿ªÔ´Â·ÓÉÆ÷¿¯ÐаæOPENWRT/LEDE RCE·ì϶£¨CVE-2020-7982£©£»GithubºÍ¾©¶«µÈÍøÕ¾Ôâµ½ÖÐÑëÈ˹¥»÷£¬¶à¸öÊ¡ÊÐÇøÊÜÓ°Ïì¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖС£
>³ÁÒª°²È«·ì϶Áбí
1. Microsoft Windows Adobe Type Manager Library×ÖÌå´¦ÖôúÂëÖ´Ðзì϶
Microsoft Windows Adobe Type Manager Library´¦ÖÃAdobe Type 1 PostScriptÌåʽ×ÖÌå´æÔÚÄÚ´æ·ÛËé·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶¹¹½¨¶ñÒâÎļþ£¬ÓÕʹÓû§½âÎö£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐËÁÒâ´úÂë¡£
https://portal.msrc.microsoft.com/zh-cn/security-guidance/advisory/ADV200006
2. Apple Safari Webkit CVE-2020-3901ÄÚ´æÃýÎóÒýÓôúÂëÖ´Ðзì϶
Apple Safari Webkit´æÔÚÄÚ´æ·ÛËé·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄWEBÒªÇó£¬ÓÕʹÓû§½Ó¼û£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÄܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£
https://support.apple.com/en-us/HT211104
3. Apache Shiro Spring dynamic controllersÑéÖ¤ÈÆ¹ý·ì϶
Apache Shiro Spring dynamic controllers´æÔÚÑéÖ¤ÈÆ¹ý·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉÈÆ¹ýÑé֤δÊÚȨ½Ó¼ûÀûÓá£
https://lists.apache.org/thread.html/r17f371fc89d34df2d0c8131473fbc68154290e1be238895648f5a1e6%40%3Cdev.shiro.apache.org%3E
4. rConfig lib/crud/search.crud.phpºÅÁî×¢Èë·ì϶
rConfig lib/crud/search.crud.php´¦ÖÃnodeId´æÔÚÊäÈëÑéÖ¤·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿É×¢ÈëËÁÒâºÅÁî²¢Ö´ÐС£
https://github.com/rconfig/rconfig/commit/3385f906427d228c48b914625136bf620f4ca0a9
5. 3S-Smart Software Solutions CODESYS V3 web server»º³åÇøÒç¶Âí½Å
3S-Smart Software Solutions CODESYS V3 web server CmpWebServerHandlerV3.dll´æÔÚ¶ÑÒç¶Âí½Å£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿Éʹ·þÎñ·¨Ê½±ÀÀ£»òÖ´ÐÐËÁÒâ´úÂë¡£
https://zh-cn.tenable.com/security/research/tra-2020-16?tns_redirect=true
> ³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢Keepnet Labs ESÊ·ýй¶³¬¹ý50Òڱʼͼ£¬¾ùΪÒÔǰй¶
Ó¢¹ú°²È«³§ÉÌKeepnet LabsµÄÒ»¸öElasticsearchÊ·ýй¶Á˳¬¹ý50ÒÚÌõÊý¾Ý¼Í¼£¬ÕâЩ¼Í¼ÊÇ2012ÄêÖÁ2019ÄêÖ®¼ä²úÉúµÄй¶ÊÂÎñÖеļͼ¡£¸ÃÊý¾Ý¿âÓÉÁ½¸ö¼¯ÖÐ×é³É£¬Ò»¸öÔ̺¬50.88Òڱʼͼ£¬¶øÁíÒ»¸öʵʱ¸üеļ¯ÖÐÔòÔ̺¬³¬¹ý1500Íò±Ê¼Í¼¡£Ð¹Â¶µÄ¼Í¼Ô̺¬¹þÏ£ÀàÐÍ¡¢Ð¹Â¶Äê·Ý¡¢ÃÜÂ루¹þÏ£¡¢¼ÓÃÜ»òÃ÷ÎÄÌåʽ£©¡¢µç×ÓÓʼþ¡¢µç×ÓÓʼþÓòÃûÒÔ¼°Ð¹Â¶Ô´£¨Ô̺¬Adobe¡¢Last.fm¡¢Twitter¡¢LinkedIn¡¢TumblrºÍVKµÈ£©¡£Keepnet Labs°µÊ¾Êý¾Ý¿âÊÇÔÚÆä¹©¸øÉ̽«Ë÷ÒýǨáãÖÁÁíһ̨ES·þÎñÆ÷ʱ¶³öµÄ£¬ÔÚǨáã¹ý³ÌÖзÀ»ðǽһʱ½ûÓÃÁËÔ¼10·ÖÖÓ£¬Ê¹µÃËÑË÷ÒýÇæ¿ÉÒÔΪÊý¾Ý¿â³ÉÁ¢Ë÷Òý¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/100198/data-breach/keepnet-labs-data-leak.html
2¡¢Î¢ÈíÖÒ¸æAdobe Type Manager¿âÖеÄÁ½¸öRCE 0day
΢Èí°ä²¼°²È«²¼¸æ£¬ÖÒ¸æWindows Adobe Type Manager¿âÖеÄÁ½¸öRCE 0day£¬ÕâÁ½¸ö·ì϶ӰÏìÁ˵±Ç°ËùÓÐÊÜÖ§³ÖµÄWindowsºÍWindows Server°æ±¾¡£·ì϶´æÔÚÓÚAdobe Type Manager¿â´¦ÖÃAdobe Type 1 PostScript×ÖÌåÌåʽµÄ·½Ê½ÖУ¬¹¥»÷ÕßÄܹ»Í¨¹ý¶àÖÖ·½Ê½ÀûÓô˷ì϶£¬ÀýÈç˵·þÓû§´ò¿ª¶ñÒâÎĵµ»òÔÚWindowsÔ¤ÀÀ´°¸ñÖв鿴Ëü¡£Î¢ÈíÒѾ·¢ÏÖÀûÓô˷ì϶µÄÓÐÏÞÕë¶ÔÐÔ¹¥»÷¡£½¨ÒéÔÚWindows×ÊÔ´ÖÎÀíÆ÷ÖнûÓá°Ô¤ÀÀ´°¸ñ¡±ºÍ¡°¾ßÌåÐÅÏ¢´°¸ñ¡±£¬ÒÔ¼õÇáÀûÓ÷çÏÕ£¬Áí±íÁ½¸ö»º½â´ëÊ©ÊǽûÓÃWebClient·þÎñºÍ³Á¶¨Ãû¡°ATMFD.DLL¡±¡£
ÔÎÄÁ´½Ó£º
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV200006
3¡¢»ÝÆÕÔÙ´ÎÖҸ沿ÃÅSSD½«ÔÚÔËÐÐ4ÍòÓ×ʱºó³öÏÖ¹ÊÕÏ
»ÝÆÕÔÙ´ÎÖÒ¸æÆä¿Í»§£¬Ä³Ð©´®ÐÐÏνӵÄSCSI¹Ì̬ӲÅÌ»áÔÚÔËÐÐ4ÍòÓ×ʱ£¨Ï൱ÓÚ4Äê206Ìì16¸öÓ×ʱ£©ºó³öÏÖ¹ÊÕÏ£¬Êý¾ÝºÍÓ²Å̾ùÎÞ·¨¸´Ô¡£¸Ã¹«Ë¾ÓÚ2019Äê11Ô°䲼ÁËÀàËÆµÄ²¼¸æ£¬Æäʱ²¿ÃÅSSDÔÚÔËÐÐ32768Ó×ʱºó²úÉú¹ÊÕÏ¡£ÕâÒ»´ÎÊÜÓ°ÏìµÄSSDÐͺÅÔ̺¬EK0800JVYPN¡¢EO1600JVYPP¡¢MK0800JVYPQºÍMO1600JVYPR£¬ÊÜÓ°ÏìµÄ²úÆ·Ô̺¬¶àÖÖHP·þÎñÆ÷ºÍ´æ´¢²úÆ·£¬ÈçHP ProLiant¡¢Synergy¡¢Apollo 4200µÈ¡£HPE¹À¼Æ£¬Î´´ò²¹¶¡µÄSSD×îÔ罫ÔÚ2020Äê10ÔÂÆðÍ·³öÏÖ¹ÊÕÏ£¬½¨ÒéÓû§¾¡¿ìÀûÓù̼þ¸üС£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/hpe-warns-of-new-bug-that-kills-ssd-drives-after-40-000-hours/
4¡¢¿ªÔ´Â·ÓÉÆ÷¿¯ÐаæOPENWRT/LEDE RCE·ì϶£¨CVE-2020-7982£©
×êÑÐÈËÔ±Åû¶¿ªÔ´Â·ÓÉÆ÷¿¯ÐаæOPENWRT/LEDEÖеĹؼüRCE·ì϶£¨CVE-2020-7982£©µÄ¼¼Êõϸ½ÚºÍPoC¡£¸Ã·ì϶´æÔÚÓÚOpenWrtµÄOPKGÈí¼þ°üÖÎÀíÆ÷ÖУ¬OPKG¶ÔÏÂÔØµÄÈí¼þ°üÖ´ÐÐÆëÈ«ÐÔ²é³Ê±£¬ÈôÊÇSHA-256УÑéºÍÔ̺¬ÈκÎǰµ¼¿Õ¸ñ£¬OPKG»áÌø¹ýÆëÈ«ÐԲ鳳ÖÐøÖ´ÐÐ×°Öù¤×÷¡£¸Ã·ì϶¿ÉÄÜʹԶ³ÌMitM¹¥»÷Õß¿ÉÄÜÓÕÆÏµÍ³×°ÖÃδ¾ÑéÖ¤µÄ¶ñÒâÈí¼þ°ü»òÈí¼þ¸üУ¬´Ó¶øÀ¹½ØÖ¸±êÉ豸µÄͨѶºÍÖ´ÐÐËÁÒâ´úÂë¡£OpenWrt°æ±¾18.06.0ÖÁ18.06.6ºÍ19.07.0ÒÔ¼°LEDE 17.01.0ÖÁ17.01.7¾ùÊܵ½Ó°Ïì¡£½¨ÒéÊÜÓ°ÏìµÄÓû§½«ÆäÉ豸¹Ì¼þÉý¼¶µ½×îÐÂOpenWrt°æ±¾18.06.7ºÍ19.07.1¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2020/03/openwrt-rce-vulnerability.html
5¡¢GithubºÍ¾©¶«µÈÍøÕ¾Ôâµ½ÖÐÑëÈ˹¥»÷£¬¶à¸öÊ¡ÊÐÇøÊÜÓ°Ïì
3ÔÂ26ÈÕÓй¥»÷ÕßÕë¶ÔGithubºÍ¾©¶«µÈÍøÕ¾ÌáÒé´ó¹æÄ£ÖÐÑëÈ˹¥»÷£¬Ä¿Ç°ÊÜÓ°ÏìµÄÖØÒªÊDz¿ÃŵØÓòÓû§£¬µ«Éæ¼°ËùÓÐÔËÓªÉÌ£¬ÀýÈçÖйúÒÆ¶¯¡¢ÖйúÁªÍ¨¡¢ÖйúµçÐÅÒÔ¼°½ÌÓýÍø¾ù¿É¸´ÏÖ½Ù³ÖÎÊÌ⣬¶ø¹ú±íÍøÂç½Ó¼ûÕâЩվµã²¢Î´³öÏÖÒì³£Çé¿ö¡£´ÓÄ¿Ç°ÍøÉϲéÎʵÄÐÅÏ¢Äܹ»¿´µ½Õâ´Î¹¥»÷Éæ¼°×î¹ãµÄÊÇGitHub.io£¬Æä´ÎÓû§½Ó¼û¾©¶«µÈ¹úÄÚ³ÛÃûÍøÕ¾Òà»á±¨´í¡£²é¿´Ö¤ÊÖÔýÏ¢Äܹ»·¢ÏÖÕâÐ©ÍøÕ¾µÄÖ¤Êé±»¹¥»÷ÕßʹÓõÄ×ÔÊðÃûÖ¤Êé°ü°ì£¬µ¼ÖÂä¯ÀÀÆ÷ÎÞ·¨ÐÅÀµ´Ó¶ø×èÖ¹Óû§½Ó¼û¡£Ä¿Ç°È«Íø¾ø´óÎÞÊýÍøÕ¾¶¼ÒѾ¿ªÆô¼ÓÃܼ¼ÊõÆ¥µÐ½Ù³Ö£¬Òò¶øÓû§½Ó¼û»á±»×èÖ¹¶ø²»»á±»Êèµ¼µ½´¹µöÍøÕ¾ÉÏÈ¥¡£Õâ´Î¹¥»÷ËÆºõÊÇͨ¹ý¹Ç¸ÉÍøÂç½Ù³Ö443¶Ë¿Ú£¬Ä¿Ç°¾²âÊÔDNSϵͳ½âÎöÊÇÆëÈ«Õý³£µÄ¡£
ÔÎÄÁ´½Ó£º
https://www.landiannews.com/archives/71707.html


¾©¹«Íø°²±¸11010802024551ºÅ