ÐÅÏ¢Äþ¾²Öܱ¨-2020ÄêµÚ16ÖÜ

Ðû²¼Ê±¼ä 2020-04-20

> ±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


2020Äê04ÔÂ13ÈÕÖÁ19ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´72¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇGoogle Chrome speech recognizer´úÂëÖ´ÐЩ¶´; VeeamOne Agent PerformHandshake´úÂëÖ´ÐЩ¶´ £»Apache Heron·´ÐòÁл¯´úÂëÖ´ÐЩ¶´ £»Cisco UCS Director ApplianceStorageUtil unzipĿ¼±éÀú´úÂëÖ´ÐЩ¶´ £»Triangle MicroWorks SCADA Data Gateway DNP3 GET_FILE_INFOÕ»Òç³ö©¶´¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇ°Í»ù˹̹1.15ÒÚÒƶ¯Óû§Êý¾ÝÔÚ°µÍø³öÊÛ £»µ¤ÂóË®±ÃÖÆÔìÉÌDESMIÔâÍøÂç¹¥»÷£¬ÏµÍ³ÈÔδ»Ö¸´ £»OracleÐû²¼4ÔÂÖØÒª²¹¶¡¸üУ¬ÐÞ¸´397¸ö©¶´ £»Ó¢ÌضûÐû²¼4ÔÂÄþ¾²¸üУ¬ÐÞ¸´¶à¿î²úÎïÖеÄ9¸ö©¶´ £»EA SportsÔâ´ó¹æÄ£DDoS¹¥»÷£¬È«Çò·þÎñÖжÏ¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£


>ÖØÒªÄþ¾²Â©¶´Áбí


1. Google Chrome speech recognizer´úÂëÖ´ÐЩ¶´


Google Chrome speech recognizer´æÔÚÊͷźóʹÓ鶴£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄWEBÇëÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹӦÓ÷¨Ê½±ÀÀ £»òÖ´ÐÐÈÎÒâ´úÂë¡£

https://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop_15.html


2. Veeam One Agent PerformHandshake´úÂëÖ´ÐЩ¶´


Veeam One Agent PerformHandshakeÒªÁì´æÔÚ·´ÐòÁл¯Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉʹӦÓ÷¨Ê½±ÀÀ £»òÖ´ÐÐÈÎÒâ´úÂë¡£

https://www.zerodayinitiative.com/advisories/ZDI-20-545/


3. Apache Heron·´ÐòÁл¯´úÂëÖ´ÐЩ¶´


Apache Heron´æÔÚ·´ÐòÁл¯Â©¶´£¬ÔÊÐíͨ¹ýÑéÖ¤µÄ¹ÜÀíÔ±Óû§ÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£

https://lists.apache.org/thread.html/r16dd39f4180e4443ef4ca774a3a5a3d7ac69f91812c183ed2a99e959%40%3Cdev.heron.apache.org%3E


4. Cisco UCS Director ApplianceStorageUtil unzipĿ¼±éÀú´úÂëÖ´ÐЩ¶´


Cisco UCS Director ApplianceStorageUtil unzip´¦ÖÃÎļþ²Ù×÷´æÔÚĿ¼±éÀú©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔrootÕË»§ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£

https://www.zerodayinitiative.com/advisories/ZDI-20-539/


5. Triangle MicroWorks SCADA Data Gateway DNP3 GET_FILE_INFOÕ»Òç³ö©¶´


Triangle MicroWorks SCADA Data Gateway´¦ÖÃDNP3 GET_FILE_INFO´æÔÚÕ»Òç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉʹӦÓ÷¨Ê½±ÀÀ £»òÖ´ÐÐÈÎÒâ´úÂë¡£

https://www.zerodayinitiative.com/advisories/ZDI-20-547


> ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢°Í»ù˹̹1.15ÒÚÒƶ¯Óû§Êý¾ÝÔÚ°µÍø³öÊÛ


×ðÁú¶¶È¦ - Ϊdu¶øÉú


°Í»ù˹̹Äþ¾²³§ÉÌRewterz·¢ÏÖ£¬Ä¿Ç°ÓÐ1.15ÒÚ°Í»ù˹̹Òƶ¯Óû§µÄÊý¾ÝÔÚ°µÍøÂÛ̳³öÊÛ£¬¼Û¸ñΪ300 BTC£¨Ô¼ºÏ210ÍòÃÀÔª£©¡£ÕâЩÊý¾Ý°üÂÞÓû§µÄÏêϸ¸öÈËÐÅÏ¢£¬ÀýÈçÐÕÃû¡¢ÍêÕûµØÖ·¡¢ÊÖ»úºÅÂëÒÔ¼°NICºÅºÍË°ÎñºÅÂë¡£RewterzÍþвÇ鱨ר¼ÒÈÏΪÕâЩÊý¾Ý¿ÉÄÜÊÇÒ»´Î»ò¶à´Îй¶µÄ½á¹û£¬Ä¿Ç°»¹²»Çå³þÊÇ·ñÓÐÈκÎÌض¨µÄµçÐÅÔËÓªÉÌ»òÊÇËùÓеçÐÅÔËÓªÉ̳ÉΪ´Ë´Î¹¥»÷µÄÊܺ¦Õß¡£¸Ãй¶Êý¾ÝµÄ¹æÄ£Òý·¢Á˶ԵçÐŹ«Ë¾Êý¾ÝÄþ¾²ÐÔºÍÒþ˽ÐԵĵ£ÓÇ¡£


Ô­ÎÄÁ´½Ó£º

http://www.rewterz.com/articles/115-million-pakistani-mobile-users-data-go-on-sale-on-dark-web


2¡¢µ¤ÂóË®±ÃÖÆÔìÉÌDESMIÔâÍøÂç¹¥»÷£¬ÏµÍ³ÈÔδ»Ö¸´


×ðÁú¶¶È¦ - Ϊdu¶øÉú


µ¤ÂóË®±ÃÖÆÔìÉÌDESMIÔâµ½ÍøÂç¹¥»÷£¬¸Ã¹¥»÷ʼþ·¢ÉúÔÚÉÏÖÜËĵÄÍíÉÏ£¬Ôâµ½¹¥»÷ºó¹«Ë¾µÄËùÓÐϵͳ¾ù±»¹Ø±Õ¡£Æ¾¾Ý¸Ã¹«Ë¾ÔÚ¹ÙÍøÉÏÐû²¼µÄ¾¯¸æ£¬¹«Ë¾µÄËùÓÐϵͳ¾ù±»¹Ø±Õ£¬¶øÇÒÕýÔÚ»¹Ô­¹ý³ÌÖУ¬Ê×Åú²¿ÃÅϵͳ½«ÔÚ¼¸ÌìÄÚÆô¶¯²¢ÔËÐУ¬ÆäÓàµÄϵͳ½«ÔÚ¼¸ÖÜÖ®ÄÚÔËÐС£Ä¿Ç°ÊÓ²ìÈÔÔÚ½øÐÐÖ®ÖУ¬Éв»Çå³þ¹¥»÷µÄˮƽ£¬DESMIÒѽ«Ê¼þ³ÂË߸øµ¤ÂóÕþ¸®ºÍ¾¯²ì¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/101495/hacking/desmi-discloses-cyber-attack.html


3¡¢OracleÐû²¼4ÔÂÖØÒª²¹¶¡¸üУ¬ÐÞ¸´397¸ö©¶´


×ðÁú¶¶È¦ - Ϊdu¶øÉú


OracleÔÚÆä4ÔÂÖØÒª²¹¶¡¸üÐÂÖÐÐÞ¸´ÁË397¸ö©¶´£¬ÆäÖÐOracle Database Server²úÎïÖÐÐÞ¸´ÁË8¸ö©¶´ £»µç×ÓÉÌÎñÌ×¼þÖÐÐÞ¸´ÁË74¸ö©¶´£¬°üÂÞ70¸öÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓõÄ©¶´ £»OracleÈÚºÏÖмä¼þÖÐÐÞ¸´ÁË51¸ö©¶´£¬ÆäÖÐ44¸öÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓà £»Java SEÖÐÐÞ¸´ÁË15¸ö©¶´£¬ËùÓЩ¶´¾ù¿ÉÒÔÔÚ²»½øÐÐÉí·ÝÑéÖ¤µÄÇé¿öϽøÐÐÔ¶³ÌÀûÓà £»MySQLÖÐÐÞ¸´ÁË45¸ö©¶´£¬ÆäÖÐ9¸ö©¶´ÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓá£ÍêÕû©¶´ÁбíÇë²Î¿¼ÒÔϹٷ½Á´½Ó£¬½¨ÒéÓû§¾¡¿ìÓ¦ÓøüС£


Ô­ÎÄÁ´½Ó£º

https://www.oracle.com/security-alerts/cpuapr2020.html


4¡¢Ó¢ÌضûÐû²¼4ÔÂÄþ¾²¸üУ¬ÐÞ¸´¶à¿î²úÎïÖеÄ9¸ö©¶´


×ðÁú¶¶È¦ - Ϊdu¶øÉú


Ó¢ÌضûÔÚ4Ô²¹¶¡¸üÐÂÖÐÐÞ¸´ÁË9¸ö©¶´£¬ÕâЩ©¶´¾ùΪÖиßΣ©¶´£¬Ó°Ïì¶à¸öÈí¼þ¡¢¹Ì¼þ¼°Æ½Ì¨¡£Ó¢ÌضûÐÞ¸´ÁËPROSet/ÎÞÏßWiFi²úÎïÔÚWindows 10ÉϵÄÁ½¸ö©¶´-¾­¹ýÉí·ÝÑéÖ¤µÄ¹¥»÷ÕßÓÉÓÚ²»Äþ¾²µÄ¼Ì³ÐȨÏÞ¶ø¿ÉÄÜͨ¹ýµ±µØ·ÃÎʽøÐÐÌØȨÉý¼¶£¨CVE-2020-0557£© £»ÓÉÓÚÄÚºËÇý¶¯·¨Ê½ÖеĻº³åÇøÏÞÖƲ»Í×£¬ÎÞÌØȨµÄ¹¥»÷Õß¿ÉÄÜͨ¹ýÏàÁÚÍøÂç·ÃÎÊÀ´µ¼Ö¾ܾø·þÎñ£¨CVE-2020-0558£©¡£Ó¢Ìضû»¹ÐÞ¸´ÁËNUC mini PCµÄϵͳ¹Ì¼þÖкÍÄ£¿é»¯·þÎñÆ÷MFS2600KISPP¼ÆËãÄ£¿éÖеÄÁ½¸ö©¶´£¬°üÂÞ²»ÕýÈ·µÄ»º³åÇøÏÞÖƵ¼ÖµÄLPE©¶´£¨CVE-2020-0600£©ºÍÌõ¼þ¼ì²é²»Í×µ¼ÖµÄÌáȨ©¶´£¨CVE-2020-0578£©¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/intel-april-platform-update-fixes-high-severity-security-issues/


5¡¢EA SportsÔâ´ó¹æÄ£DDoS¹¥»÷£¬È«Çò·þÎñÖжÏ


×ðÁú¶¶È¦ - Ϊdu¶øÉú


ÓÎÏ·¹«Ë¾EA SportsÓÖÒ»´ÎÔâµ½´ó¹æÄ£µÄDDoS¹¥»÷£¬µ¼Ö¸ù«Ë¾µÄ·þÎñÆ÷ÔÚÈ«Çò·¶Î§ÄÚÍÑ»ú¡£´Ë´Î¹¥»÷·¢ÉúÔÚ4ÔÂ14ÈÕÏÂÎç4:19¡£Æ¾¾ÝDown DetectorµÄʵʱµØͼ£¬´Ë´Î¹¥»÷Ö÷ÒªÓ°ÏìÁËÅ·ÖÞµØÓòµÄ¿Í»§£¬µ«¼ÓÄô󡢰£¼°¡¢ÄϷǵȵصĿͻ§Ò²Êܵ½ÁË»ò¶à»òÉÙµÄÓ°Ïì¡£4ÔÂ15ÈÕÁ賿1µã25·Ö£¬EA SportsÈϿɸù«Ë¾¡°¾­ÀúÁËһϵÁÐDDoS¹¥»÷¡±¡£ÔÚÐû²¼±¾ÎÄʱ£¬EA SportsµÄ¿Í»§ÈÔÔÚËß¿à·þÎñå´»ú£¬Õâ±íÃ÷¸Ã¹«Ë¾ÈÔÔÚÔâÊܹ¥»÷¡£ÖµµÃ×¢ÒâµÄÊÇ£¬±©Ñ©Ò²ÔÚ4ÔÂ14ÈÕÁ賿4µã15·Ö×óÓÒÔ⵽һϵÁÐDDoS¹¥»÷£¬µ¼ÖÂÈ«Çò·þÎñÖжÏ¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/ea-sports-down-gaming-giant-hit-by-ddos-attacks/