ÐÅÏ¢°²È«Öܱ¨-2020ÄêµÚ13ÖÜ

°ä²¼¹¦·ò 2020-03-31

> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2020Äê03ÔÂ23ÈÕÖÁ29ÈÕ¹²ÊÕ¼°²È«·ì϶62¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇMicrosoft Windows Adobe Type Manager Library×ÖÌå´¦ÖôúÂëÖ´Ðзì϶; Apple Safari Webkit CVE-2020-3901ÄÚ´æÃýÎóÒýÓôúÂëÖ´Ðзì϶£»Apache Shiro Spring dynamic controllersÑéÖ¤ÈÆ¹ý·ì϶£»rConfig lib/crud/search.crud.phpºÅÁî×¢Èë·ì϶£»3S-Smart Software Solutions CODESYS V3 web server»º³åÇøÒç¶Âí½Å¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇKeepnet Labs ESÊ·ýй¶³¬¹ý50Òڱʼͼ£¬¾ùΪÒÔǰй¶£»Î¢ÈíÖÒ¸æAdobe Type Manager¿âÖеÄÁ½¸öRCE 0day£»»ÝÆÕÔÙ´ÎÖҸ沿ÃÅSSD½«ÔÚÔËÐÐ4ÍòÓ×ʱºó³öÏÖ¹ÊÕÏ£»¿ªÔ´Â·ÓÉÆ÷¿¯ÐаæOPENWRT/LEDE RCE·ì϶£¨CVE-2020-7982£©£»GithubºÍ¾©¶«µÈÍøÕ¾Ôâµ½ÖÐÑëÈ˹¥»÷£¬¶à¸öÊ¡ÊÐÇøÊÜÓ°Ïì¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖС£


>³ÁÒª°²È«·ì϶Áбí


1. Microsoft Windows Adobe Type Manager Library×ÖÌå´¦ÖôúÂëÖ´Ðзì϶


Microsoft Windows Adobe Type Manager Library´¦ÖÃAdobe Type 1 PostScriptÌåʽ×ÖÌå´æÔÚÄÚ´æ·ÛËé·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶¹¹½¨¶ñÒâÎļþ£¬ÓÕʹÓû§½âÎö£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐËÁÒâ´úÂë¡£

https://portal.msrc.microsoft.com/zh-cn/security-guidance/advisory/ADV200006


2. Apple Safari Webkit CVE-2020-3901ÄÚ´æÃýÎóÒýÓôúÂëÖ´Ðзì϶


Apple Safari Webkit´æÔÚÄÚ´æ·ÛËé·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄWEBÒªÇó£¬ÓÕʹÓû§½Ó¼û£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÄܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£

https://support.apple.com/en-us/HT211104


3. Apache Shiro Spring dynamic controllersÑéÖ¤ÈÆ¹ý·ì϶


Apache Shiro Spring dynamic controllers´æÔÚÑéÖ¤ÈÆ¹ý·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉÈÆ¹ýÑé֤δÊÚȨ½Ó¼ûÀûÓá£

https://lists.apache.org/thread.html/r17f371fc89d34df2d0c8131473fbc68154290e1be238895648f5a1e6%40%3Cdev.shiro.apache.org%3E


4. rConfig lib/crud/search.crud.phpºÅÁî×¢Èë·ì϶


rConfig lib/crud/search.crud.php´¦ÖÃnodeId´æÔÚÊäÈëÑéÖ¤·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿É×¢ÈëËÁÒâºÅÁî²¢Ö´ÐС£

https://github.com/rconfig/rconfig/commit/3385f906427d228c48b914625136bf620f4ca0a9


5. 3S-Smart Software Solutions CODESYS V3 web server»º³åÇøÒç¶Âí½Å


3S-Smart Software Solutions CODESYS V3 web server CmpWebServerHandlerV3.dll´æÔÚ¶ÑÒç¶Âí½Å£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿Éʹ·þÎñ·¨Ê½±ÀÀ£»òÖ´ÐÐËÁÒâ´úÂë¡£

https://zh-cn.tenable.com/security/research/tra-2020-16?tns_redirect=true


> ³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢Keepnet Labs ESÊ·ýй¶³¬¹ý50Òڱʼͼ£¬¾ùΪÒÔǰй¶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ó¢¹ú°²È«³§ÉÌKeepnet LabsµÄÒ»¸öElasticsearchÊ·ýй¶Á˳¬¹ý50ÒÚÌõÊý¾Ý¼Í¼£¬ÕâЩ¼Í¼ÊÇ2012ÄêÖÁ2019ÄêÖ®¼ä²úÉúµÄй¶ÊÂÎñÖеļͼ¡£¸ÃÊý¾Ý¿âÓÉÁ½¸ö¼¯ÖÐ×é³É£¬Ò»¸öÔ̺¬50.88Òڱʼͼ£¬¶øÁíÒ»¸öʵʱ¸üеļ¯ÖÐÔòÔ̺¬³¬¹ý1500Íò±Ê¼Í¼¡£Ð¹Â¶µÄ¼Í¼Ô̺¬¹þÏ£ÀàÐÍ¡¢Ð¹Â¶Äê·Ý¡¢ÃÜÂ루¹þÏ£¡¢¼ÓÃÜ»òÃ÷ÎÄÌåʽ£©¡¢µç×ÓÓʼþ¡¢µç×ÓÓʼþÓòÃûÒÔ¼°Ð¹Â¶Ô´£¨Ô̺¬Adobe¡¢Last.fm¡¢Twitter¡¢LinkedIn¡¢TumblrºÍVKµÈ£©¡£Keepnet Labs°µÊ¾Êý¾Ý¿âÊÇÔÚÆä¹©¸øÉ̽«Ë÷ÒýǨáãÖÁÁíһ̨ES·þÎñÆ÷ʱ¶³öµÄ£¬ÔÚǨáã¹ý³ÌÖзÀ»ðǽһʱ½ûÓÃÁËÔ¼10·ÖÖÓ£¬Ê¹µÃËÑË÷ÒýÇæ¿ÉÒÔΪÊý¾Ý¿â³ÉÁ¢Ë÷Òý¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/100198/data-breach/keepnet-labs-data-leak.html


2¡¢Î¢ÈíÖÒ¸æAdobe Type Manager¿âÖеÄÁ½¸öRCE 0day


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


΢Èí°ä²¼°²È«²¼¸æ£¬ÖÒ¸æWindows Adobe Type Manager¿âÖеÄÁ½¸öRCE 0day£¬ÕâÁ½¸ö·ì϶ӰÏìÁ˵±Ç°ËùÓÐÊÜÖ§³ÖµÄWindowsºÍWindows Server°æ±¾¡£·ì϶´æÔÚÓÚAdobe Type Manager¿â´¦ÖÃAdobe Type 1 PostScript×ÖÌåÌåʽµÄ·½Ê½ÖУ¬¹¥»÷ÕßÄܹ»Í¨¹ý¶àÖÖ·½Ê½ÀûÓô˷ì϶£¬ÀýÈç˵·þÓû§´ò¿ª¶ñÒâÎĵµ»òÔÚWindowsÔ¤ÀÀ´°¸ñÖв鿴Ëü¡£Î¢ÈíÒѾ­·¢ÏÖÀûÓô˷ì϶µÄÓÐÏÞÕë¶ÔÐÔ¹¥»÷¡£½¨ÒéÔÚWindows×ÊÔ´ÖÎÀíÆ÷ÖнûÓá°Ô¤ÀÀ´°¸ñ¡±ºÍ¡°¾ßÌåÐÅÏ¢´°¸ñ¡±£¬ÒÔ¼õÇáÀûÓ÷çÏÕ£¬Áí±íÁ½¸ö»º½â´ëÊ©ÊǽûÓÃWebClient·þÎñºÍ³Á¶¨Ãû¡°ATMFD.DLL¡±¡£


Ô­ÎÄÁ´½Ó£º

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV200006


3¡¢»ÝÆÕÔÙ´ÎÖҸ沿ÃÅSSD½«ÔÚÔËÐÐ4ÍòÓ×ʱºó³öÏÖ¹ÊÕÏ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


»ÝÆÕÔÙ´ÎÖÒ¸æÆä¿Í»§£¬Ä³Ð©´®ÐÐÏνӵÄSCSI¹Ì̬ӲÅÌ»áÔÚÔËÐÐ4ÍòÓ×ʱ£¨Ï൱ÓÚ4Äê206Ìì16¸öÓ×ʱ£©ºó³öÏÖ¹ÊÕÏ£¬Êý¾ÝºÍÓ²Å̾ùÎÞ·¨¸´Ô­¡£¸Ã¹«Ë¾ÓÚ2019Äê11Ô°䲼ÁËÀàËÆµÄ²¼¸æ£¬Æäʱ²¿ÃÅSSDÔÚÔËÐÐ32768Ó×ʱºó²úÉú¹ÊÕÏ¡£ÕâÒ»´ÎÊÜÓ°ÏìµÄSSDÐͺÅÔ̺¬EK0800JVYPN¡¢EO1600JVYPP¡¢MK0800JVYPQºÍMO1600JVYPR£¬ÊÜÓ°ÏìµÄ²úÆ·Ô̺¬¶àÖÖHP·þÎñÆ÷ºÍ´æ´¢²úÆ·£¬ÈçHP ProLiant¡¢Synergy¡¢Apollo 4200µÈ¡£HPE¹À¼Æ£¬Î´´ò²¹¶¡µÄSSD×îÔ罫ÔÚ2020Äê10ÔÂÆðÍ·³öÏÖ¹ÊÕÏ£¬½¨ÒéÓû§¾¡¿ìÀûÓù̼þ¸üС£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/hpe-warns-of-new-bug-that-kills-ssd-drives-after-40-000-hours/


4¡¢¿ªÔ´Â·ÓÉÆ÷¿¯ÐаæOPENWRT/LEDE RCE·ì϶£¨CVE-2020-7982£©


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


×êÑÐÈËÔ±Åû¶¿ªÔ´Â·ÓÉÆ÷¿¯ÐаæOPENWRT/LEDEÖеĹؼüRCE·ì϶£¨CVE-2020-7982£©µÄ¼¼Êõϸ½ÚºÍPoC¡£¸Ã·ì϶´æÔÚÓÚOpenWrtµÄOPKGÈí¼þ°üÖÎÀíÆ÷ÖУ¬OPKG¶ÔÏÂÔØµÄÈí¼þ°üÖ´ÐÐÆëÈ«ÐԲ鳭ʱ£¬ÈôÊÇSHA-256УÑéºÍÔ̺¬ÈκÎǰµ¼¿Õ¸ñ£¬OPKG»áÌø¹ýÆëÈ«ÐԲ鳭³ÖÐøÖ´ÐÐ×°Öù¤×÷¡£¸Ã·ì϶¿ÉÄÜʹԶ³ÌMitM¹¥»÷Õß¿ÉÄÜÓÕÆ­ÏµÍ³×°ÖÃδ¾­ÑéÖ¤µÄ¶ñÒâÈí¼þ°ü»òÈí¼þ¸üУ¬´Ó¶øÀ¹½ØÖ¸±êÉ豸µÄͨѶºÍÖ´ÐÐËÁÒâ´úÂë¡£OpenWrt°æ±¾18.06.0ÖÁ18.06.6ºÍ19.07.0ÒÔ¼°LEDE 17.01.0ÖÁ17.01.7¾ùÊܵ½Ó°Ïì¡£½¨ÒéÊÜÓ°ÏìµÄÓû§½«ÆäÉ豸¹Ì¼þÉý¼¶µ½×îÐÂOpenWrt°æ±¾18.06.7ºÍ19.07.1¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2020/03/openwrt-rce-vulnerability.html


5¡¢GithubºÍ¾©¶«µÈÍøÕ¾Ôâµ½ÖÐÑëÈ˹¥»÷£¬¶à¸öÊ¡ÊÐÇøÊÜÓ°Ïì


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


3ÔÂ26ÈÕÓй¥»÷ÕßÕë¶ÔGithubºÍ¾©¶«µÈÍøÕ¾ÌáÒé´ó¹æÄ£ÖÐÑëÈ˹¥»÷£¬Ä¿Ç°ÊÜÓ°ÏìµÄÖØÒªÊDz¿ÃŵØÓòÓû§£¬µ«Éæ¼°ËùÓÐÔËÓªÉÌ£¬ÀýÈçÖйúÒÆ¶¯¡¢ÖйúÁªÍ¨¡¢ÖйúµçÐÅÒÔ¼°½ÌÓýÍø¾ù¿É¸´ÏÖ½Ù³ÖÎÊÌ⣬¶ø¹ú±íÍøÂç½Ó¼ûÕâЩվµã²¢Î´³öÏÖÒì³£Çé¿ö¡£´ÓÄ¿Ç°ÍøÉϲéÎʵÄÐÅÏ¢Äܹ»¿´µ½Õâ´Î¹¥»÷Éæ¼°×î¹ãµÄÊÇGitHub.io£¬Æä´ÎÓû§½Ó¼û¾©¶«µÈ¹úÄÚ³ÛÃûÍøÕ¾Òà»á±¨´í¡£²é¿´Ö¤ÊÖÔýÏ¢Äܹ»·¢ÏÖÕâÐ©ÍøÕ¾µÄÖ¤Êé±»¹¥»÷ÕßʹÓõÄ×ÔÊðÃûÖ¤Êé°ü°ì£¬µ¼ÖÂä¯ÀÀÆ÷ÎÞ·¨ÐÅÀµ´Ó¶ø×èÖ¹Óû§½Ó¼û¡£Ä¿Ç°È«Íø¾ø´óÎÞÊýÍøÕ¾¶¼ÒѾ­¿ªÆô¼ÓÃܼ¼ÊõÆ¥µÐ½Ù³Ö£¬Òò¶øÓû§½Ó¼û»á±»×èÖ¹¶ø²»»á±»Êèµ¼µ½´¹µöÍøÕ¾ÉÏÈ¥¡£Õâ´Î¹¥»÷ËÆºõÊÇͨ¹ý¹Ç¸ÉÍøÂç½Ù³Ö443¶Ë¿Ú£¬Ä¿Ç°¾­²âÊÔDNSϵͳ½âÎöÊÇÆëÈ«Õý³£µÄ¡£


Ô­ÎÄÁ´½Ó£º

https://www.landiannews.com/archives/71707.html