ÐÅÏ¢Çå¾²Öܱ¨-2021ÄêµÚ48ÖÜ

Ðû²¼Ê±¼ä 2021-11-29

>±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


±¾Öܹ²ÊÕ¼Çå¾²Îó²î50¸ö £¬ £¬£¬£¬£¬£¬ £¬ÖµµÃ¹Ø×¢µÄÊÇDell Networking X-Series firmwareÑéÖ¤ÈÆ¹ýÎó²î£»£»£»D-Link DWR-932C E1 debug_fcgi OSÏÂÁî×¢ÈëÎó²î£»£»£»Commvault CommCell AppStudioUploadHandlerí§ÒâÎļþÉÏ´«Îó²î£»£»£»HejHome GKW-IC052 IP CameraÓ²±àÂëÎó²î£»£»£»QNAP QVR²»×¼È·ÑéÖ¤Îó²î¡£¡£ ¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇRedCurlÍÅ»ï»Ø¹é £¬ £¬£¬£¬£¬£¬ £¬ÐµĹ¥»÷Ä¿µÄÉæ¼°¸÷Ðи÷Òµ£»£»£»LinuxºóÃÅlinux_avp¿ÉÈÆ¹ýµçÉÌÆ½Ì¨µÄÇå¾²¼ì²â£»£»£»CloudLinuxÐÞ¸´Imunify360ÖеÄPHP·´ÐòÁл¯Îó²î£»£»£»AppGalleryÖжà¿îÓÎÏ·Ó¦Óñ£´æÄ¾Âí £¬ £¬£¬£¬£¬£¬ £¬ÒÑѬȾ900¶àÍò×°±¸£»£»£»KasperskyÐû²¼2021ÄêºÚÎåʱ´úÕ©Æ­»î¶¯µÄÆÊÎö±¨¸æ¡£¡£ ¡£¡£¡£


ƾ֤ÒÔÉÏ×ÛÊö £¬ £¬£¬£¬£¬£¬ £¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£ ¡£¡£¡£


>Ö÷ÒªÇå¾²Îó²îÁбí


1. Dell Networking X-Series firmwareÑéÖ¤ÈÆ¹ýÎó²î


Dell Networking X-Series firmware±£´æÑéÖ¤ÈÆ¹ýÎó²î £¬ £¬£¬£¬£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó £¬ £¬£¬£¬£¬£¬ £¬¿ÉÐ®ÖÆ»á»° £¬ £¬£¬£¬£¬£¬ £¬Í¨¹ýαÔì»á»°id»á¼ûwebЧÀÍÆ÷¡£¡£ ¡£¡£¡£


https://www.dell.com/support/kbdoc/en-us/000193230/dsa-2021-191-dell-networking-x-series-security-update-for-multiple-security-vulnerabilities


2. D-Link DWR-932C E1 debug_fcgi OSÏÂÁî×¢ÈëÎó²î


D-Link DWR-932C E1 debug_fcgi±£´æÊäÈëÑéÖ¤Îó²î £¬ £¬£¬£¬£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó £¬ £¬£¬£¬£¬£¬ £¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£ ¡£¡£¡£


https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10246


3. Commvault CommCell AppStudioUploadHandlerí§ÒâÎļþÉÏ´«Îó²î


Commvault CommCell AppStudioUploadHandlerÀà±£´æÇå¾²Îó²î £¬ £¬£¬£¬£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó £¬ £¬£¬£¬£¬£¬ £¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÉÏ´«Îļþ²¢Ö´ÐС£¡£ ¡£¡£¡£


https://www.zerodayinitiative.com/advisories/ZDI-21-1332/


4. HejHome GKW-IC052 IP CameraÓ²±àÂëÎó²î


HejHome GKW-IC052 IP Camera±£´æÓ²±àÂëÎó²î £¬ £¬£¬£¬£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó £¬ £¬£¬£¬£¬£¬ £¬¿É¿ØÖÆÏµÍ³Î´ÊÚȨ¾ÙÐвÙ×÷¡£¡£ ¡£¡£¡£


https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=36359


5. QNAP QVR²»×¼È·ÑéÖ¤Îó²î


NAP QVR±£´æ²»×¼È·ÑéÖ¤Îó²î £¬ £¬£¬£¬£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó £¬ £¬£¬£¬£¬£¬ £¬¿ÉδÊÚȨ»á¼ûϵͳ¡£¡£ ¡£¡£¡£


https://www.qnap.com.cn/en/security-advisory/qsa-21-52


>Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢RedCurlÍÅ»ï»Ø¹é £¬ £¬£¬£¬£¬£¬ £¬ÐµĹ¥»÷Ä¿µÄÉæ¼°¸÷Ðи÷Òµ


Group-IBÔÚ11ÔÂ18ÈÕÅû¶Á˺ڿÍÍÅ»ïRedCurlµÄл¡£¡£ ¡£¡£¡£ÍøÂçÌØ¹¤ºÚ¿Í×éÖ¯RedCurlÔÚ2018ÄêÖÁ2020Äêʱ´ú £¬ £¬£¬£¬£¬£¬ £¬ÌᳫÁËÖÁÉÙ26´Î¹¥»÷ £¬ £¬£¬£¬£¬£¬ £¬Éæ¼°Ó¢¹ú¡¢µÂ¹ú¡¢¼ÓÄôó¡¢Å²Íþ¡¢¶íÂÞ˹ºÍÎÚ¿ËÀ¼µÈµØÇøµÄÐÞ½¨¡¢½ðÈÚ¡¢×Éѯ¡¢ÁãÊÛ¡¢°ü¹ÜºÍÖ´·¨ÐÐÒµµÄ¹«Ë¾¡£¡£ ¡£¡£¡£¸ÃÍÅ»ïÔÚÖÐÖ¹7¸öÔºó¾íÍÁÖØÀ´ £¬ £¬£¬£¬£¬£¬ £¬×Ô2021ÄêÍ·ÒÔÀ´Õë¶Ô4¼Ò¹«Ë¾ÌᳫÁËÐµĹ¥»÷ £¬ £¬£¬£¬£¬£¬ £¬ÆäÖаüÀ¨¶íÂÞ˹×î´óµÄÅú·¢ÊÐËÁ¡£¡£ ¡£¡£¡£Group-IB³Æ £¬ £¬£¬£¬£¬£¬ £¬RedCurlÔÚÿ´Î¹¥»÷Öж¼»áʹÓÃÆä×Ô½ç˵¶ñÒâÈí¼þÈÆ¹ý¼ì²â¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.group-ib.com/media/red-curl-threat-report/


2¡¢LinuxºóÃÅlinux_avp¿ÉÈÆ¹ýµçÉÌÆ½Ì¨µÄÇå¾²¼ì²â


SansecÍþвÑо¿ÍŶÓÔÚ11ÔÂ18µÄ×îÐÂÑо¿·¢Ã÷ÁËLinuxºóÃÅlinux_avp¡£¡£ ¡£¡£¡£Ñо¿Ö°Ô±³Æ £¬ £¬£¬£¬£¬£¬ £¬¹¥»÷ÕßÔÚµçÉÌÍøÕ¾×¢ÈëÐÅÓÿ¨ÇÔÈ¡Æ÷ºó £¬ £¬£¬£¬£¬£¬ £¬»¹»áÔÚ±»ÈëÇÖµÄЧÀÍÆ÷ÉÏ×°ÖÃLinuxºóÃÅ¡£¡£ ¡£¡£¡£linux_avpÒ»µ©Æô¶¯ £¬ £¬£¬£¬£¬£¬ £¬¾ÍÁ¬Ã¦½«×Ô¼º´Ó´ÅÅÌÖÐɾ³ý £¬ £¬£¬£¬£¬£¬ £¬Î±×°³Éps -efÀú³Ì £¬ £¬£¬£¬£¬£¬ £¬ÓÃÓÚ»ñȡĿ½ñÕýÔÚÔËÐеÄÀú³ÌÁÐ±í²¢ÈÆ¹ý¼ì²â¡£¡£ ¡£¡£¡£¸ÃÑù±¾ÓÚ10ÔÂ8ÈÕÊ×´ÎÉÏ´« £¬ £¬£¬£¬£¬£¬ £¬ÏÖÔÚVirusTotalµÄ·´¶ñÒâÈí¼þÒýÇæÈÔδ¼ì²âµ½Ëü¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/hackers-deploy-linux-malware-web-skimmer-on-e-commerce-servers/


3¡¢CloudLinuxÐÞ¸´Imunify360ÖеÄPHP·´ÐòÁл¯Îó²î


Cisco TaloÔÚ11ÔÂ22ÈÕÅû¶ÁËCloudLinuxµÄ²úÆ·Imunify360ÖеÄPHP·´ÐòÁл¯Îó²î¡£¡£ ¡£¡£¡£¸Ã²úÆ·ÊÇ»ùÓÚLinuxµÄWebЧÀÍÆ÷µÄÇ徲ƽ̨ £¬ £¬£¬£¬£¬£¬ £¬Óû§¿ÉʹÓÃÆäͨ¹ýÖÖÖÖÉèÖÃÀ´ÊµÊ±±£»£»£»¤ÍøÕ¾ºÍWebЧÀÍÆ÷µÄÇå¾²¡£¡£ ¡£¡£¡£¸ÃÎó²î(CVE-2021-21956)CVSSÆÀ·ÖΪ8.2 £¬ £¬£¬£¬£¬£¬ £¬±£´æÓÚAi-Bolit¹¦Ð§ÖÐ £¬ £¬£¬£¬£¬£¬ £¬¹¥»÷Õß¿ÉÒÔͨ¹ý¸ÃÎó²îÔÚÄ¿µÄϵͳÖÐÖ´ÐÐí§Òâ´úÂë £¬ £¬£¬£¬£¬£¬ £¬»òÍêÈ«¿ØÖÆÐ§ÀÍÆ÷¡£¡£ ¡£¡£¡£ÏÖÔÚ £¬ £¬£¬£¬£¬£¬ £¬CloudLinuxÒÑÐÞ¸´¸ÃÎó²î¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://blog.talosintelligence.com/2021/11/vulnerability-spotlight-php-deserialize.html


4¡¢AppGalleryÖжà¿îÓÎÏ·Ó¦Óñ£´æÄ¾Âí £¬ £¬£¬£¬£¬£¬ £¬ÒÑѬȾ900¶àÍò×°±¸


11ÔÂ23ÈÕ £¬ £¬£¬£¬£¬£¬ £¬Dr. WebµÄÑо¿Ö°Ô±Åû¶»ªÎªÓ¦ÓÃÊÐËÁAppGalleryÖеÄ190¿îÓÎÏ·Öб£´æÄ¾ÂíAndroid.Cynos.7.origin £¬ £¬£¬£¬£¬£¬ £¬ÒÑ×°ÖÃÔ¼9300000´Î¡£¡£ ¡£¡£¡£¸ÃľÂíÊǶñÒâÈí¼þCynosµÄ±äÌå £¬ £¬£¬£¬£¬£¬ £¬Ö¼ÔÚÍøÂçÓû§µÄÐÅÏ¢¡£¡£ ¡£¡£¡£ÕâЩÓÎÏ·Ö÷ҪʹÓöíÓï¡¢ÖÐÎĺÍÓ¢Óï £¬ £¬£¬£¬£¬£¬ £¬ÆäÖÐÓÎÏ·¡°¿ìµã¶ãÆðÀ´¡±µÄÏÂÔØÁ¿¸ß´ï2000000´Î¡£¡£ ¡£¡£¡£Ñо¿Ö°Ô±³Æ £¬ £¬£¬£¬£¬£¬ £¬¸ÃľÂí¿É·¢ËͺÍ×èµ²¶ÌÐÅ¡¢ÏÂÔØºÍÆô¶¯ÆäËüÄ£¿£¿£¿é £¬ £¬£¬£¬£¬£¬ £¬ÒÔ¼°ÏÂÔØºÍ×°ÖÃÆäËûÓ¦Óᣡ£ ¡£¡£¡£ÏÖÔÚ £¬ £¬£¬£¬£¬£¬ £¬»ªÎª¹«Ë¾Òѽ«ÕâЩÓÎϷϼÜ¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/124927/malware/android-cynos-7-origin-trojan-infections.html


5¡¢KasperskyÐû²¼2021ÄêºÚÎåʱ´úÕ©Æ­»î¶¯µÄÆÊÎö±¨¸æ


11ÔÂ22ÈÕ £¬ £¬£¬£¬£¬£¬ £¬KasperskyÐû²¼2021ÄêºÚÎåʱ´úÕ©Æ­»î¶¯µÄÆÊÎö±¨¸æ¡£¡£ ¡£¡£¡£±¨¸æÖ÷ÒªÆÊÎöÁËÓëÈ«Çò»á¼ûÁ¿×î´óµÄÎå¸öÁãÊÛÆ½Ì¨£ºÎÖ¶ûÂê¡¢eBay¡¢ÑÇÂíÑ·¡¢°¢Àï°Í°ÍºÍ Mercado Libre¡£¡£ ¡£¡£¡£Ñо¿·¢Ã÷ £¬ £¬£¬£¬£¬£¬ £¬2021Äêǰ10¸öÔ¼ì²âµ½40584415ÆðÕë¶ÔµçÉÌÆ½Ì¨ÒÔ¼°ÒøÐлú¹¹µÄ´¹ÂÚ¹¥»÷£»£»£»Õë¶Ôµç×ÓÖ§¸¶ÏµÍ³µÄ´¹ÂڻÔöÌíÁË208%£»£»£»10ÔÂ27ÈÕÖÁ11ÔÂ19ÈÕ·¢Ã÷ÁË221745·âÓëºÚÎåÓйصÄÓʼþ¡£¡£ ¡£¡£¡£±¨¸æÖ¸³ö £¬ £¬£¬£¬£¬£¬ £¬ÐþÉ«ÐÇÆÚÎå²»µ«¶Ô¹ºÎïÕßÀ´ËµÊÇÖ÷ÒªµÄÒ»Ìì £¬ £¬£¬£¬£¬£¬ £¬¶Ô¹¥»÷ÕßÀ´ËµÒ²ÊÇÔÆÔÆ¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securelist.com/black-friday-2021/104915/