ÐÅÏ¢Äþ¾²Öܱ¨-2019ÄêµÚ45ÖÜ

Ðû²¼Ê±¼ä 2019-11-18

>±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö



2019Äê11ÔÂ11ÈÕÖÁ17ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´48¸ö £¬ÖµµÃ¹Ø×¢µÄÊÇMicrosoft Windows OpenType×ÖÌå½âÎöCVE-2019-1456Ô¶³ÌÖ´ÐдúÂ멶´; eQ-3 Homematic CCU3 testtcl.cgi´úÂëÖ´ÐЩ¶´£»SAP Diagnostics AgentÈÎÒâOSÃüÁî×¢È멶´£»Istio¾Ü¾ø·þÎñ©¶´£»Adobe Illustrator CVE-2019-8248ÄÚ´æÆÆ»µÈÎÒâ´úÂëÖ´ÐЩ¶´ ¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇÍйܷþÎñÉÌSmarterASP.NETÔâÀÕË÷Èí¼þ¹¥»÷£»¶íÂÞ˹з¨°¸Ç¿ÖÆÊÖ»úºÍPCÔ¤°²×°±¾¹úÈí¼þ£»5GЩ¶´¿É¸ú×ٵ绰λÖü°¹ã²¥Ðé¼Ù¾¯±¨£»McAfeeɱ¶¾Èí¼þ´úÂëÖ´ÐЩ¶´(CVE-2019-3648)£»¸ßͨоƬ×éQSEE©¶´¿ÉÖÂAndroidÉ豸Êý¾Ýй¶ ¡£


ƾ¾ÝÒÔÉÏ×ÛÊö £¬±¾ÖÜÄþ¾²ÍþвΪÖÐ ¡£


>ÖØÒªÄþ¾²Â©¶´Áбí


1. Microsoft Windows OpenType×ÖÌå½âÎöCVE-2019-1456Ô¶³ÌÖ´ÐдúÂ멶´
Microsoft Windows OpenType×ÖÌå½âÎö´¦ÖÃOpentype×ÖÌå´æÔÚÄþ¾²Â©¶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÎļþÇëÇó £¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐÈÎÒâ´úÂë ¡£
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1456

2. eQ-3 Homematic CCU3 testtcl.cgi´úÂëÖ´ÐЩ¶´
eQ-3 Homematic CCU3 save.cgi½Å±¾¿ÉÓÃÀ´ÉÏ´«½Å±¾²¢±»testtcl.cgi½Å±¾Ö´ÐÐ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬¿ÉÖ´ÐÐÈÎÒâ´úÂë ¡£
https://psytester.github.io/CVE-2019-18938/

3. SAP Diagnostics AgentÈÎÒâOSÃüÁî×¢È멶´
SAP Diagnostic Agent´æÔÚδÃ÷Äþ¾²Â©¶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬¿ÉÖ´ÐÐÈÎÒâOSÃüÁî ¡£
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=528880390

4. Istio¾Ü¾ø·þÎñ©¶´
Istio´æÔÚÄþ¾²Â©¶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬¿ÉʹӦÓ÷¨Ê½Í߽⠡£
https://github.com/istio/istio/issues/18229

5. Adobe Illustrator CVE-2019-8248ÄÚ´æÆÆ»µÈÎÒâ´úÂëÖ´ÐЩ¶´
Adobe Illustrator´¦ÖÃÎļþ´æÔÚÄÚ´æÆÆ»µÂ©¶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÎļþÇëÇó £¬¿ÉÖ´ÐÐÈÎÒâ´úÂë»òÕß½øÐоܾø·þÎñ¹¥»÷ ¡£
https://helpx.adobe.com/security/products/illustrator/apsb19-36.html


>ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢ÍйܷþÎñÉÌSmarterASP.NETÔâÀÕË÷Èí¼þ¹¥»÷


×ðÁú¶¶È¦ - Ϊdu¶øÉú


SmarterASP.NETÊÇÒ»¼ÒÓµÓÐÁè¼Ý44Íò¸ö¿Í»§µÄASP.NETÍйܷþÎñÉÌ £¬¸Ã¹«Ë¾ÔÚÖÜÄ©Ôâµ½ÀÕË÷Èí¼þ¹¥»÷ ¡£µ±Ç°SmarterASP.NETÌåÏÖÕýÔÚŬÁ¦»Ö¸´¿Í»§µÄ·þÎñÆ÷ £¬µ«²»Çå³þ¸Ã¹«Ë¾ÊÇÖ§¸¶ÁËÊê½ð»¹ÊÇÔÚ´Ó±¸·ÝÖлָ´ ¡£´Ë´Î¹¥»÷Öв»½ö¿Í»§Êý¾ÝÊܵ½Ó°Ïì £¬¶øÇÒSmarterASP.NET×Ô¼ºÒàÊÜÓ°Ïì ¡£¸Ã¹«Ë¾µÄÍøÕ¾ÔÚÐÇÆÚÁùÈ«Ì춼ÏÂÏß £¬Ö±µ½ÐÇÆÚÌìÔçÉϲÅÖØÐÂÉÏÏß ¡£·þÎñÆ÷»Ö¸´ÊÂÇé½øÕ¹»ºÂý £¬Ðí¶à¿Í»§ÈÔÈ»ÎÞ·¨·ÃÎÊÆäÕË»§ºÍÊý¾Ý £¬°üÂÞÍøÕ¾ÎļþºÍºó¶ËÊý¾Ý¿â ¡£Æ¾¾ÝÔÚTwitterÉÏÐû²¼µÄ½Øͼ £¬±»¼ÓÃܵĿͻ§Îļþºó¸½¼ÓÁË¡°.kjhbx¡±À©Õ¹Ãû £¬Ä¿Ç°Ñо¿ÈËÔ±ÈÔÔÚÊÔͼȷÈÏÀÕË÷Èí¼þµÄÖÖÀà ¡£

Ô­ÎÄÁ´½Ó£º
https://www.zdnet.com/article/major-asp-net-hosting-provider-infected-by-ransomware/

2¡¢¶íÂÞ˹з¨°¸Ç¿ÖÆÊÖ»úºÍPCÔ¤°²×°±¾¹úÈí¼þ


×ðÁú¶¶È¦ - Ϊdu¶øÉú


¶íÂÞ˹Òé»áÕýÔÚÍƶ¯Ò»ÏîÁ¢·¨ £¬¸Ã·¨°¸½«Ç¿ÖÆÒªÇóËùÓÐÔÚ¶íÂÞ˹ÏúÊ۵ĵç×ÓÉ豸£¨°üÂÞÖÇÄÜÊÖ»ú¡¢PCºÍÖÇÄܵçÊӵȣ©Ô¤°²×°±¾¹ú¿Æ¼¼¹«Ë¾µÄÓ¦Óà ¡£Õâ¿ÉÄÜ»á´øÀ´Äþ¾²Òþ»¼ ¡£Á¢·¨ÕßÌåÏָ÷¨°¸ÊÇΪÁ˱£»¤µ±µØµÄ¼¼ÊõÊг¡ÃâÊÜÍâ¹ú£¨¿ÉÄÜÊÇÖ¸ÃÀ¹ú£©µÄ¾ºÕù ¡£Õþ¸®½«Õë¶ÔÿÖÖÉ豸ÀàÐÍÐû²¼Ò»·ÝÈí¼þÁбí £¬É豸¹©Ó¦ÉÌÐèÒªÔÚ¶íÂÞ˹ÏúÊÛµÄÉ豸ÉÏÔ¤°²×°ÕâЩÈí¼þ ¡£Èç¹û¹©Ó¦É̲»×ñÊع涨 £¬½«±»´¦ÒÔ×î¸ß20Íò¬²¼£¨Ô¼ºÏ3100ÃÀÔª£©µÄ·£¿î ¡£¸Ã·¨°¸µÃµ½ÁËËùÓÐÖ÷ÒªÕþµ³µÄÖ§³Ö £¬ÕâÒâζ×ÅËüºÜÓпÉÄܽ«ÔÚ2020Äê7ÔÂ1ÈÕÉúЧ ¡£

Ô­ÎÄÁ´½Ó£º
https://www.zdnet.com/article/phones-and-pcs-sold-in-russia-will-have-to-come-pre-installed-with-russian-apps/

3¡¢5GЩ¶´¿É¸ú×ٵ绰λÖü°¹ã²¥Ðé¼Ù¾¯±¨


×ðÁú¶¶È¦ - Ϊdu¶øÉú


Æնɴóѧ£¨Purdue University£©ºÍ°®ºÉ»ª´óѧ£¨University of Iowa£©µÄÄþ¾²Ñо¿ÈËÔ±·¢ÏÖ½«½ü12¸ö5GÄþ¾²Â©¶´ £¬Ñо¿ÈËÔ±ÌåÏÖÕâЩ©¶´¿ÉÔÊÐí¹¥»÷Õß»ñÈ¡Ä¿±êÓû§µç»°µÄÐÂ/¾ÉÁÙʱÍøÂç±êʶ·û £¬´Ó¶ø¸ú×ٵ绰µÄλÖà £¬ÉõÖÁ½Ù³ÖÑ°ºôÐŵÀ½øÐÐÐé¼ÙµÄ½ô¼±¾¯±¨¹ã²¥ ¡£ÔÚijЩÇé¿öÏ £¬ÕâЩ©¶´¿ÉÄܱ»ÓÃÀ´½«·äÎÑÁ¬½Ó½µ¼¶Îª²»Ì«Äþ¾²µÄ³ß¶È ¡£Ò»Ð©ÐµĹ¥»÷Ò²¿ÉÄÜÔÚÏÖÓеÄ4GÍøÂçÉϱ»ÀûÓà ¡£¼øÓÚ©¶´µÄÐÔÖÊ £¬Ñо¿ÈËÔ±ÌåÏÖËûÃDz»¼Æ»®¹ûÈ»ÆäPoC´úÂë £¬µ«ËûÃǽ«ÕâЩ·¢ÏÖ֪ͨÁËÈ«Çò·äÎÑÍøÂçGSMЭ»á£¨GSMA£© ¡£GSMAûÓÐ͸¶ÊÇ·ñ¿ÉÒÔÐÞ¸´Â©¶´ £¬Ò²Ã»ÓÐ͸¶ÐÞ¸´Ê±¼ä ¡£


Ô­ÎÄÁ´½Ó£º

https://finance.yahoo.com/news/5g-flaws-track-phone-locations-163014364.html

4¡¢McAfeeɱ¶¾Èí¼þ´úÂëÖ´ÐЩ¶´(CVE-2019-3648)

×ðÁú¶¶È¦ - Ϊdu¶øÉú


SafeBreach Labs·¢ÏÖMcAfee·À²¡¶¾Èí¼þÊÜ´úÂëÖ´ÐЩ¶´£¨CVE-2019-3648£©µÄÓ°Ïì £¬¹¥»÷Õß¿ÉÈƹýMcAfeeµÄ×ÔÎÀ»úÖÆ £¬¿ÉÄܵ¼Ö¶ÔÊÜѬȾϵͳµÄ½øÒ»²½¹¥»÷ ¡£¸Ã©¶´ÊÇÓÉÓÚδÑéÖ¤¼ÓÔØDLLµÄÇ©Ãûµ¼Ö嵀 £¬¹¥»÷Õ߿ɽ«ÈÎÒâδǩÃûµÄDLL¼ÓÔص½ÒÔNT AUTHORITY\SYSTEMȨÏÞÔËÐеĶà¸ö·þÎñÖÐ ¡£¸Ã¹¥»÷»¹¿ÉÒÔÈƹýÓ¦Ó÷¨Ê½°×Ãûµ¥±£»¤²¢ÖÆÖ¹±»Äþ¾²Èí¼þ¼ì²âµ½ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/mcafee-antivirus-software-impacted-by-code-execution-vulnerability/

5¡¢¸ßͨоƬ×éQSEE©¶´¿ÉÖÂAndroidÉ豸Êý¾Ýй¶


×ðÁú¶¶È¦ - Ϊdu¶øÉú


ƾ¾ÝÄþ¾²³§ÉÌCheckPointµÄÒ»·Ý³ÂËß £¬¸ßͨоƬ×éÖеÄÄþ¾²Ö´Ðл·¾³£¨QSEE£©ÖдæÔÚ©¶´£¨CVE-2019-10574£© £¬¿Éµ¼ÖÂAndroidÉ豸ÖеĸöÈËÊý¾Ýй¶ ¡£QSEEÊÇ»ùÓÚARM TrustZone¼¼ÊõµÄÊÜÐÅÈÎÖ´Ðл·¾³£¨TEE£©µÄʵÏÖ £¬ÊÇÖ÷´¦ÖÃÆ÷ÉϵÄÒ»¸öÓ²¼þ¸ôÀëµÄÄþ¾²ÇøÓò £¬ÆäÖÐͨ³£°üÂÞרÓüÓÃÜÃÜÔ¿¡¢ÃÜÂë¡¢ÐÅÓÿ¨ºÍ½è¼Ç¿¨Æ¾¾ÝµÈÃô¸ÐÐÅÏ¢ ¡£Check PointÑо¿ÈËÔ±ÄæÏòÁ˸Ãϵͳ £¬²¢ÀûÓÃÄ£ºý²âÊÔ¶ÔÈýÐÇ¡¢LGºÍĦÍÐÂÞÀ­É豸½øÐÐÁ˲âÊÔ ¡£×ÜÌå¶øÑÔ £¬Ñо¿ÈËÔ±·¢ÏÖÈýÐǵÄÊÜÐÅÈδúÂë°üÂÞËĸö©¶´ £¬Ä¦ÍÐÂÞÀ­ºÍLG·Ö±ð°üÂÞÒ»¸ö©¶´ £¬µ«ËùÓдúÂë¾ùÀ´×Ô¸ßͨ¹«Ë¾ ¡£ÈýÐÇ¡¢¸ßͨºÍLGÒÑÕë¶ÔÕâЩQSEE©¶´Ðû²¼Á˲¹¶¡¸üР¡£

Ô­ÎÄÁ´½Ó£º
https://thehackernews.com/2019/11/qualcomm-android-hacking.html