ÐÅÏ¢Çå¾²Öܱ¨-2020ÄêµÚ10ÖÜ

Ðû²¼Ê±¼ä 2020-03-10

> ±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


2020Äê03ÔÂ02ÈÕÖÁ08ÈÕ¹²ÊÕ¼Çå¾²Îó²î52¸ö£¬£¬ £¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇFasterXML jackson-databind CVE-2020-9548´úÂëÖ´ÐÐÎó²î; Rubetek SmartHome²¨¶ÎÉè¼ÆÎó²î£»£»£»Envoy²»×¼È·»á¼û¿ØÖÆÎó²î£»£»£»Qualcomm MDM9206 WLAN»º³åÇøÒç³öÎó²î£»£»£»Google Chrome mediaÇå¾²ÈÆ¹ýÎó²î¡£¡£¡£¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇTeslaºÍSpaceXµÄÁã¼þÖÆÔìÉÌVisserÈ·ÈÏÔâºÚ¿Í¹¥»÷ÇÒÊý¾Ýй¶£»£»£»Let's Encrypt³·»ØÁè¼Ý300Íò¸öTLSÖ¤Ê飻£»£»CrowdStrikeÐû²¼¡¶2020ÄêÈ«ÇòÍþв±¨¸æ¡·£»£»£»Ó¢¹úÊý¾Ýî¿Ïµ»ú¹¹¶Ô¹úÌ©º½¿Õ´¦ÒÔ50ÍòÓ¢°÷·£¿£¿£¿£¿î£»£»£»°Ä´óÀûÑÇACSCÐû²¼CMSϵͳÇå¾²Ö¸ÄÏ¡£¡£¡£¡£¡£¡£¡£


ƾ֤ÒÔÉÏ×ÛÊö£¬£¬ £¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£¡£¡£¡£


>Ö÷ÒªÇå¾²Îó²îÁбí


1. FasterXML jackson-databind CVE-2020-9548´úÂëÖ´ÐÐÎó²î


FasterXML jackson-databind ibatis-sqlmapÒÔ¼°anteros-core×é¼þ±£´æºÚÃûµ¥ÈƹýÎó²î£¬£¬ £¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬ £¬£¬£¬¿ÉÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£

https://github.com/FasterXML/jackson-databind/issues/2631


2. Rubetek SmartHome²¨¶ÎÉè¼ÆÎó²î


Rubetek SmartHomeʹÓÃÁËδ¼ÓÃܵÄ433 MHz²¨¶Î¾ÙÐÐͨѶ£¬£¬ £¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬ £¬£¬£¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢»ò¾ÙÐоܾøÐ§À͹¥»÷¡£¡£¡£¡£¡£¡£¡£

https://pastebin.com/CckKKJcM


3. Envoy²»×¼È·»á¼û¿ØÖÆÎó²î


EnvoyʹÓÃSDS±£´æ²»×¼È·»á¼û¿ØÖÆÎó²î£¬£¬ £¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬ £¬£¬£¬¿ÉδÊÚȨ»á¼ûÊÜÏÞ×ÊÔ´¡£¡£¡£¡£¡£¡£¡£

https://github.com/envoyproxy/envoy/security/advisories/GHSA-3x9m-pgmg-xpx8


4. Qualcomm MDM9206 WLAN»º³åÇøÒç³öÎó²î


Qualcomm MDM9206 WLAN±£´æ»º³åÇøÒç³öÎó²î£¬£¬ £¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬ £¬£¬£¬¿É¾ÙÐоܾøÐ§À͹¥»÷»ò¿ÉÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£

https://www.qualcomm.com/company/product-security/bulletins/march-2020-bulletin


5. Google Chrome mediaÇå¾²ÈÆ¹ýÎó²î


Google Chrome media´¦Öóͷ£Çå¾²Õ½ÂÔ±£´æÇå¾²Îó²î£¬£¬ £¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄWEBÇëÇ󣬣¬ £¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬ £¬£¬£¬¿ÉÈÆ¹ýÇå¾²ÏÞÖÆ£¬£¬ £¬£¬£¬Î´ÊÚȨ»á¼û¡£¡£¡£¡£¡£¡£¡£

https://chromereleases.googleblog.com/2020/03/stable-channel-update-for-desktop.html


> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢TeslaºÍSpaceXµÄÁã¼þÖÆÔìÉÌVisserÈ·ÈÏÔâºÚ¿Í¹¥»÷ÇÒÊý¾Ýй¶


welcome-°ÙÀÖ²©


TeslaºÍSpaceXµÄÁã¼þÖÆÔìÉÌVisserÈ·ÈÏÔâÓöÊý¾Ýй¶ÊÂÎñ£¬£¬ £¬£¬£¬¸Ã¹«Ë¾ÊÇÒ»¼ÒרÃÅΪ̫¿ÕºÍ¹ú·À³Ð°üÉÌÉè¼ÆÏ¸ÃÜÁã¼þµÄÖÆÔìÉÌ¡£¡£¡£¡£¡£¡£¡£ÔÚÒ»·Ý¼ò¶ÌµÄÉùÃ÷ÖУ¬£¬ £¬£¬£¬¸Ã¹«Ë¾È·ÈÏÆä½üÆÚ³ÉΪ¡°ÍøÂçÇå¾²·¸·¨ÊÂÎñ£¨°üÀ¨»á¼ûºÍ͵ÇÔÊý¾Ý£©µÄÄ¿µÄ¡±¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾½²»°ÈËÌåÏÖ½«¡°¼ÌÐø¶Ô¸Ã¹¥»÷¾ÙÐÐÖÜÈ«ÊӲ죬£¬ £¬£¬£¬²¢ÇÒÓªÒµÔËÐÐÕý³£¡±¡£¡£¡£¡£¡£¡£¡£TechCrunchÑо¿Ö°Ô±³ÆÕâ´Î¹¥»÷ºÜÓпÉÄÜÊÇÓÉDoppelPaymerÀÕË÷Èí¼þÒýÆðµÄ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://techcrunch.com/2020/03/01/visser-breach/


2¡¢4Let's Encrypt³·»ØÁè¼Ý300Íò¸öTLSÖ¤Êé


welcome-°ÙÀÖ²©


ÓÉÓÚÔÚºó¶Ë´úÂëÖз¢Ã÷ÁËÒ»¸öbug£¬£¬ £¬£¬£¬Let's EncryptÏîÄ¿ÍýÏë´ÓÌìϱê׼ʱ¼ä2020Äê3ÔÂ4ÈÕ00:00×îÏÈ×÷·ÏÁè¼Ý300Íò¸öTLSÖ¤Êé¡£¡£¡£¡£¡£¡£¡£ÏêϸÀ´Ëµ£¬£¬ £¬£¬£¬¸ÃbugÓ°ÏìÁËBoulder£¬£¬ £¬£¬£¬Let's EncryptÏîĿʹÓøÃЧÀÍÆ÷Èí¼þÔÚ¿¯ÐÐTLSÖ¤Êé֮ǰÑéÖ¤Óû§¼°ÆäÓò¡£¡£¡£¡£¡£¡£¡£¸ÃbugÓ°ÏìÁËBoulderÄÚ²¿CAA£¨Ö¤Êé½ÒÏþ»ú¹¹ÊÚȨ£©¹æ·¶µÄʵÑ飬£¬ £¬£¬£¬¡°µ±Ò»¸öÖ¤ÊéÇëÇó°üÀ¨N¸öÐèÒª¾ÙÐÐCAAÖØÐ¼ì²éµÄÓòÃûʱ£¬£¬ £¬£¬£¬Boulder½«Ñ¡ÔñÒ»¸öÓòÃû²¢¼ì²éN´Î¡£¡£¡£¡£¡£¡£¡£ÕâÏÖʵÉÏÒâζ×ÅÈôÊÇÒ»¸öÓû§ÔÚʱ¼äXÑéÖ¤ÁËÒ»¸öÓòÃû£¬£¬ £¬£¬£¬²¢ÇÒ¸ÃÓòÃûÔÚʱ¼äXµÄCAA¼Í¼ÔÊÐíLet's Encrypt¿¯ÐУ¬£¬ £¬£¬£¬Ôò¸ÃÓû§¿ÉÒÔÔÚX+30ÌìµÄʱ¼äÀ￯ÐаüÀ¨¸ÃÓòÃûµÄÖ¤Ê飬£¬ £¬£¬£¬×ÝȻ֮ºóÓÐÈËÔÚ¸ÃÓòÃûÉÏ×°ÖÃÁËեȡLet's Encrypt¿¯ÐеÄCAA¼Í¼¡±¡£¡£¡£¡£¡£¡£¡£ÔÚÕâ300Íò¸ö×÷·ÏµÄÖ¤ÊéÖУ¬£¬ £¬£¬£¬ÓÐ100Íò¸öÊÇͳһÓò/×ÓÓòµÄÖØ¸´Ï£¬ £¬£¬£¬Òò´ËÊÜÓ°ÏìÖ¤ÊéµÄÏÖʵÊýĿԼΪ200Íò¸ö¡£¡£¡£¡£¡£¡£¡£ÔÚ3ÔÂ4ÈÕ00:00Ö®ºóËùÓÐÊÜÓ°ÏìµÄÖ¤Êé¶¼½«´¥·¢ä¯ÀÀÆ÷ºÍÆäËûÓ¦ÓóÌÐòÖеĹýʧ£¬£¬ £¬£¬£¬ÓòÃûËùÓÐÕß½«±ØÐèÇëÇóеÄTLSÖ¤Êé²¢Ìæ»»¾ÉµÄTLSÖ¤Êé¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/lets-encrypt-to-revoke-3-million-certificates-on-march-4-due-to-bug/


3¡¢CrowdStrikeÐû²¼¡¶2020ÄêÈ«ÇòÍþв±¨¸æ¡·


welcome-°ÙÀÖ²©


CrowdStrikeµÄ¡¶2020ÄêÈ«ÇòÍþв±¨¸æ¡·¶ÔÒÑÍùÒ»ÄêÖж¥¼¶ÍøÂçÍþвÇ÷ÊÆ¾ÙÐÐÁËÉîÈëÆÊÎö£¬£¬ £¬£¬£¬¸Ã±¨¸æµÄÒªµã°üÀ¨£º´óÐ͹¥»÷»î¶¯£¨BGH£©Ò»Ö±Éý¼¶£¬£¬ £¬£¬£¬Êê½ðÒªÇóì­ÉýÖÁÊý°ÙÍò£¬£¬ £¬£¬£¬²¢ÇÒÔì³É¼«´óµÄÆÆË𣻣»£»ÍøÂç·¸·¨·Ö×ÓÕýÔÚʹÃô¸ÐÊý¾ÝÎäÆ÷»¯£¬£¬ £¬£¬£¬ÒÔÔöÌí¶ÔÀÕË÷Èí¼þÊܺ¦ÕßµÄѹÁ¦£»£»£»eCrimeÉú̬ϵͳһֱÉú³¤£¬£¬ £¬£¬£¬±äµÃ³ÉÊìºÍרҵ»¯Ë®Æ½Ò»Ö±Ìá¸ß£»£»£»ÔÚBGHÖ®Í⣬£¬ £¬£¬£¬Õë¶ÔÈ«Çò½ðÈÚ»ú¹¹µÄeCrime»î¶¯ÓÐËùÔöÌí£»£»£»³¯ÏòÎÞ¶ñÒâÈí¼þÕ½ÂÔµÄÇ÷ÊÆÕýÔÚ¼ÓËÙ£»£»£»¹ú¼Ò×ÊÖúµÄÓÐÕë¶ÔÐÔµÄÈëÇֻ¼ÌÐøÕë¶Ô֪ʶ²úȨ/¾ºÕùÇ鱨£¬£¬ £¬£¬£¬Ôö½øÉçÇøÄÚ²¿µÄÆÆË飬£¬ £¬£¬£¬²¢ÊӲ쵽ÁËÓëÏȽøeCrime¹¥»÷ÕßµÄÏàÖú¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.crowdstrike.com/resources/reports/2020-crowdstrike-global-threat-report/


4¡¢Ó¢¹úÊý¾Ýî¿Ïµ»ú¹¹¶Ô¹úÌ©º½¿Õ´¦ÒÔ50ÍòÓ¢°÷·£¿£¿£¿£¿î


welcome-°ÙÀÖ²©


Ó¢¹úÐÅϢרԱ°ì¹«ÊÒÒò2018Äê940ÍòÂÿÍÊý¾Ýй¶ÊÂÎñ¶Ô¹úÌ©º½¿Õ¹«Ë¾´¦ÒÔ50ÍòÓ¢°÷µÄ·£¿£¿£¿£¿î¡£¡£¡£¡£¡£¡£¡£¸Ã¹¥»÷ÒÉËÆ±¬·¢ÔÚ2018Äê3Ô·Ý£¬£¬ £¬£¬£¬²¢ÓÚ5Ô·ݻñµÃÈ·ÈÏ£¬£¬ £¬£¬£¬Æäʱ¹úÌ©º½¿ÕµÄÊý¾Ý¿âÔâµ½Á˱©Á¦ÆÆ½â¹¥»÷¡£¡£¡£¡£¡£¡£¡£ICOÊÓ²ì³Æ¹úÌ©µÄϵͳÊܵ½ÁËÊý¾ÝÍøÂçÀà¶ñÒâÈí¼þµÄÓ°Ï죬£¬ £¬£¬£¬²¢·¢Ã÷¹úÌ©ÔÚÇå¾²ÐÔ·½ÃæµÄһЩȱ·¦£¬£¬ £¬£¬£¬°üÀ¨²»ÊÜÃÜÂë±£»£»£»¤µÄ±¸·ÝÎļþ¡¢Î´´ò²¹¶¡µÄWebЧÀÍÆ÷¡¢ÒѹýʱµÄ²Ù×÷ϵͳºÍȱ·¦·À²¡¶¾±£»£»£»¤µÈ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.theregister.co.uk/2020/03/04/ico_fines_cathay_pacific_500000/


5¡¢°Ä´óÀûÑÇACSCÐû²¼CMSϵͳÇå¾²Ö¸ÄÏ


welcome-°ÙÀÖ²©


°Ä´óÀûÑÇÍøÂçÇå¾²ÖÐÐÄ£¨ACSC£©Ðû²¼Ò»·ÝÓÃÓÚ±£»£»£»¤CMSϵͳµÄÍøÂçÇå¾²Ö¸ÄÏ£¬£¬ £¬£¬£¬¸ÃÖ¸ÄϸÅÊöÁËÔõÑùÔÚwebЧÀÍÆ÷ÉÏʶ±ðºÍ×îС»¯Ç±ÔÚΣº¦µÄÕ½ÂÔ£¬£¬ £¬£¬£¬ÆäÄ¿µÄÊÜÖÚÊÇÈÏÕæÊ¹ÓÃCMS¿ª·¢ºÍ±£»£»£»¤ÍøÕ¾»òWebÓ¦ÓóÌÐòµÄÈË¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔʹÓÃ×Ô¶¯»¯¹¤¾ßɨÃèInternetÉϵÄÇå¾²Îó²î¡£¡£¡£¡£¡£¡£¡£Ò»µ©CMS±»ÈëÇÖ£¬£¬ £¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓÃÆäȨÏÞÀ´£º»ñµÃWebÓ¦ÓóÌÐòµÄÑéÖ¤ÇøÓòºÍÌØÈ¨ÇøÓòµÄ»á¼ûȨÏÞ£»£»£»ÉÏ´«¶ñÒâÈí¼þÀ´»ñµÃÔ¶³Ì»á¼û£¬£¬ £¬£¬£¬ÀýÈçÉÏ´«Web Shell»òRAT£»£»£»ÔÚÕýµ±ÍøÒ³ÉÏ×¢Èë¶ñÒâÄÚÈÝ¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß»¹¿ÉÒÔ½«ÊÜѬȾµÄWebЧÀÍÆ÷ÓÃ×÷¡°Ë®¿Ó¡±¹¥»÷µÄÒ»²¿·Ö£¬£¬ £¬£¬£¬»òÓÃ×÷C&CµÄ»ù´¡ÉèÊ©¡£¡£¡£¡£¡£¡£¡£ACSC½¨Òé½ÓÄɵĻº½â²½·¥°üÀ¨£ºÊ¹ÓÃCMSÍйÜЧÀÍ£»£»£»ÓÅÒìµÄ²¹¶¡ÖÎÀí£»£»£»Îó²îÆÀ¹À£»£»£»ÕË»§ÖÎÀí£»£»£»ÔöÇ¿CMS×°ÖõÄÇå¾²ÐÔ¿ØÖƲ½·¥£»£»£»¼à¿ØCMS×°ÖÃÉ϶ÔÍйÜÄÚÈݵÄδÊÚȨ¸ü¸ÄµÈ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.cyber.gov.au/publications/securing-content-management-systems