ÐÅÏ¢Äþ¾²Öܱ¨-2019ÄêµÚ44ÖÜ

Ðû²¼Ê±¼ä 2019-11-12

>±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


2019Äê11ÔÂ04ÈÕÖÁ10ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´46¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇFuji Electric V-Server CVE-2019-18240»º³åÇøÒç³ö©¶´; Cisco Small Business RV016, RV042, RV042G, RV082 CVE-2019-15271ÈÎÒâÃüÁîÖ´ÐЩ¶´£»TYPO3ÅäÖñäÁ¿fileDenyPatternÈÎÒâ´úÂëÖ´ÐЩ¶´£»Atlassian Jira Service Desk ServerĿ¼±éÀú©¶´£»Aruba Networks ClearPass Policy ManagerÊý¾Ý¿âƾ֤鶩¶´¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊǶíÂÞ˹¡°Ö÷Ȩ»¥ÁªÍø¡±Ö´·¨ÉúЧ£¬¿ÉÓëÈ«Çò»¥ÁªÍø¶Ï¿ª£»ºÚ¿Í¿ÉÀûÓü¤¹âÈëÇÖGoogleÖÇÄÜÓïÒôÖúÊÖ£»Libarchive´úÂëÖ´ÐЩ¶´Ó°ÏìLinux¼°BSD¿¯Ðа棻Ç÷ÊƿƼ¼ÄÚ²¿Ô±¹¤ÇÔÈ¡Áè¼Ý12ÍòÓû§ÐÅÏ¢²¢³öÊÛ£»2019ÄêÇï¼¾µöÓã¹¥»÷»î¶¯Ôö³¤ÖÁÈýÄêÀ´×î¸ß¼Ç¼¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£



>ÖØÒªÄþ¾²Â©¶´Áбí


1. Fuji Electric V-Server CVE-2019-18240»º³åÇøÒç³ö©¶´


Fuji Electric V-Server´æÔÚ»º³åÇøÒç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐÈÎÒâ´úÂë¡£

https://www.us-cert.gov/ics/advisories/icsa-19-311-02


2. Cisco Small Business RV016, RV042, RV042G, RV082 CVE-2019-15271ÈÎÒâÃüÁîÖ´ÐЩ¶´


Cisco RV016 Multi-WAN VPN RouterûÓжÔHTTP payload½øÐÐÊäÈëÑéÖ¤´¦Öã¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÖ´ÐÐÈÎÒâOSÃüÁî¡£

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20191106-sbrv-cmd-x


3. TYPO3ÅäÖñäÁ¿fileDenyPatternÈÎÒâ´úÂëÖ´ÐЩ¶´


TYPO3ÅäÖñäÁ¿fileDenyPatternÖµ´¦ÖôæÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó£¬Ö´ÐÐÈÎÒâ´úÂë¡£

https://typo3.org/security/advisory/typo3-sa-2010-012


4. Atlassian Jira Service Desk ServerĿ¼±éÀú©¶´


Atlassian Jira Service Desk Server´æÔÚĿ¼±éÀú©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎĶÁȡϵͳÎļþÄÚÈÝ¡£

https://jira.atlassian.com/browse/JSDSERVER-6589


5. Aruba Networks ClearPass Policy ManagerÊý¾Ý¿âƾ֤鶩¶´


Aruba Networks ClearPass Policy Manager´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬻ñÈ¡Êý¾Ý¿âƾ֤¡£

https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2016-010.txt



>ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢¶íÂÞ˹¡°Ö÷Ȩ»¥ÁªÍø¡±Ö´·¨ÉúЧ£¬¿ÉÓëÈ«Çò»¥ÁªÍø¶Ï¿ª


×ðÁú¶¶È¦ - Ϊdu¶øÉú


¶íÂÞ˹¡°Ö÷Ȩ»¥ÁªÍø¡±Ö´·¨ÔÚÉÏÖÜÎåÉúЧ£¬Õ⽫ʹ¶íÂÞ˹Õþ¸®Äܹ»½«¸Ã¹úÓëÈ«Çò»¥ÁªÍø¶Ï¿ªÁ¬½Ó¡£ÕâÏîÖ´·¨ÓÉÆÕ¾©×ÜͳÔÚ5Ô·ÝÇ©Êð£¬ÒªÇóISP°²×°Õþ¸®ÌṩµÄ¼¼ÊõÉ豸ÒÔ½øÐÐÁ÷Á¿¼ì²é£¬Õâ¿ÉÄÜΪ´ó¹æÄ£¼àÊÓ´ò¿ªÁË´óÃÅ¡£Æ¾¾Ý¶íÂÞ˹Õþ¸®µÄ˵·¨£¬¸ÃÖ´·¨Ö¼ÔÚÈ·±£¼´Ê¹¶Ï¿ªÓëÈ«Çò»¥ÁªÍøµÄÁ¬½ÓÒ²¿ÉÒÔ·ÃÎʶíÂÞ˹վµã£¬ÒÔÓ¦¶ÔÓÉÍøÂç¹¥»÷»òÄþ¾²Ê¼þµ¼ÖµÄÖжÏ¡£¸ÃÖ´·¨½«Ê¹¶íÂÞ˹Õþ¸®Äܹ»Éó²éÔÚÏßÄÚÈݲ¢¼àÊÓÍøÃñ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/93315/laws-and-regulations/russia-controversial-law-russia.html


2¡¢ºÚ¿Í¿ÉÀûÓü¤¹âÈëÇÖGoogleÖÇÄÜÓïÒôÖúÊÖ


×ðÁú¶¶È¦ - Ϊdu¶øÉú


½üÆÚ£¬ÈÕ±¾µç×ÓͨÐÅ´óѧºÍÃÜЪ¸ù´óѧµÄÑо¿ÈËÔ±·¢ÏÖ¿Éͨ¹ý¼¤¹âÈëÇֹȸ衢ƻ¹ûºÍÑÇÂíÑ·µÄÖÇÄÜÓïÒôÉ豸¡£ÕâÖÖ±»³ÆΪ¡°¹âÃüÁµÄ¹¥»÷¿Éͨ¹ýÏòʹÓÃ΢»úµçϵͳ£¨MEMS£©µÄÂó¿Ë·çÉÏ·¢É伤¹âÊøʵÏÖ£¬Í¨¹ýµ÷ÖƹâÊøµÄÇ¿¶È£¬¿ÉÒÔÓÕÆ­MEMS·¢ÉúÓëÒôƵÃüÁîÏàͬµÄµçÐźÅ£¬×îÔ¶ÉõÖÁ¿ÉÒÔ´Ó110Ã×Íâ¹¥»÷¡£ÊÜÓ°ÏìµÄÉ豸°üÂ޹ȸèHome¡¢Nest Cam¡¢ÑÇÂíÑ·Echo¡¢Fire Cube TV¡¢iPhone¡¢ÈýÐÇGalaxy S9¡¢¹È¸èPixelºÍiPad¡£Ñо¿ÈËÔ±Ö¤Ã÷¸Ã¹¥»÷ÉõÖÁ¿ÉÒÔ´ò¿ª³µ¿âÃÅ»ò½âËøºâÓîÃÅ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/using-light-beams-to-control-google-apple-amazon-assistants/


3¡¢Libarchive´úÂëÖ´ÐЩ¶´Ó°ÏìLinux¼°BSD¿¯Ðаæ


×ðÁú¶¶È¦ - Ϊdu¶øÉú


¹È¸èÄþ¾²Ñо¿ÈËÔ±ÔÚLibarchiveÖз¢ÏÖÒ»¸ö´úÂëÖ´ÐЩ¶´£¨CVE-2019-18408£©£¬¹¥»÷Õß¿ÉÓÕʹÓû§´ò¿ª¶ñÒâ´æµµÎļþÔÚÆäϵͳÉÏÖ´ÐдúÂë¡£Debian¡¢Ubuntu¡¢Gentoo¡¢Arch LinuxÒÔ¼°FreeBSDºÍNetBSD¿¯Ðаæ¾ùÊÜÓ°Ï죬µ«WindowsºÍmacOS²»ÊÜÓ°Ïì¡£LibarchiveÍŶÓÔÚа汾3.4.0ÖÐÐÞ¸´Á˸鶴£¬Ä¿Ç°ÉÐδÔÚÒ°Íâ·¢Ïָ鶴µÄPoC»òÀûÓôúÂë¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/libarchive-vulnerability-can-lead-to-code-execution-on-linux-freebsd-netbsd/


4¡¢Ç÷ÊƿƼ¼ÄÚ²¿Ô±¹¤ÇÔÈ¡Áè¼Ý12ÍòÓû§ÐÅÏ¢²¢³öÊÛ


×ðÁú¶¶È¦ - Ϊdu¶øÉú


Ç÷ÊƿƼ¼ÄÚ²¿Ô±¹¤ÇÔÈ¡¹«Ë¾¿Í»§ÐÅÏ¢²¢½«Æä³öÊÛ¸øµÚÈý·½Õ©Æ­ÍŻÔÚ¿Í»§Ôâµ½¼¼ÊõÖ§³ÖÕ©Æ­ºó£¬Ç÷ÊƿƼ¼Õ¹¿ªÊӲ첢·¢ÏÖ¸ÃÔ±¹¤·Ç·¨·ÃÎÊÁË¿Í»§Ö§³ÖÊý¾Ý¿â¡£¿ÉÄܱ»ÇÔµÄÐÅÏ¢°üÂÞ¿Í»§µÄÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢¼¼ÊõÖ§³Öµ¥ºÅÒÔ¼°µç»°ºÅÂ룬µ«¸Ã¹«Ë¾Ç¿µ÷ûÓм£Ïó±íÃ÷²ÆÕþ»òÐÅÓÿ¨ÐÅÏ¢±»ÇÔ£¬¶øÇÒûÓÐÉæ¼°µ½ÆóÒµ»òÕþ¸®¿Í»§¡£Æ¾¾ÝÆäÄÚ²¿ÊӲ죬ÊÜÓ°ÏìµÄ¿Í»§Ö»Õ¼Ç÷ÊƿƼ¼1200Íò¿Í»§ÈºµÄ²»µ½1%£¬¼´12Íò¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/trendmicro-employee-sold-customer-info-to-tech-support-scammers/


5¡¢2019ÄêÇï¼¾µöÓã¹¥»÷»î¶¯Ôö³¤ÖÁÈýÄêÀ´×î¸ß¼Ç¼


×ðÁú¶¶È¦ - Ϊdu¶øÉú


ƾ¾ÝAPWGµÄͳ¼ÆÊý¾Ý£¬2019ÄêÇï¼¾ÍøÂçµöÓã¹¥»÷Ôö³¤ÖÁÈýÄêÀ´µÄ×î¸ß¼Ç¼¡£ÔÚ2019Äê7ÔÂÖÁ9ÔÂÆÚ¼ä¼ì²âµ½µÄµöÓãÍøÕ¾×ÜÊýΪ266387£¬±È2019ÄêµÚ¶þ¼¾¶ÈµÄ182465Ôö³¤ÁË46%£¬¼¸ºõÊÇ2018ÄêµÚËļ¾¶ÈµÄ138328µÄÁ½±¶¡£³ýÁ˵öÓãÍøÕ¾ÊýÁ¿µÄÔö¼ÓÖ®Í⣬2019ÄêµÚÈý¼¾¶ÈÊܵöÓã¹¥»÷µÄÆ·ÅÆÊýÁ¿Ò²Ã÷ÏÔÔö³¤£¬Æ½¾ùÿÔÂÓÐ400¶à¸öÆ·ÅÆÊܵ½¹¥»÷£¬¶øµÚ¶þ¼¾¶ÈΪ313¸ö¡£


Ô­ÎÄÁ´½Ó£º

https://www.helpnetsecurity.com/2019/11/07/phishing-attacks-levels-rise/