ÐÅÏ¢Çå¾²Öܱ¨-2019ÄêµÚ3ÖÜ
Ðû²¼Ê±¼ä 2019-01-21±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇ»úƱԤ¶©ÏµÍ³AmadeusÑÏÖØÎó²î£¬£¬£¬£¬£¬£¬£¬Ó°ÏìÈ«Çò141¼Òº½¿Õ¹«Ë¾;ÃÀOklahomaÖÝÕþ¸®Ð§ÀÍÆ÷ÒâÍâ̻¶3TBÃô¸ÐÊý¾Ý;Ó¢¹úBSIAÐû²¼»¥ÁªÇ徲ϵͳ×î¼Ñʵ¼ùÖ¸ÄÏ;VoIPЧÀÍÉÌVOIPOÒâÍâй¶ÒÑÍùËÄÄêµÄ¿Í»§Êý¾Ý;ESÎļþä¯ÀÀÆ÷Á½¸öÎó²îʹµÃÁè¼Ý1ÒÚAndroidÓû§ÃæÁÙΣº¦¡£¡£¡£¡£¡£¡£
ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£¡£¡£
Ö÷ÒªÇå¾²Îó²îÁбí
Brocade Network Advisor±£´æÓ²±àÂëÎó²î£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬¿ÉµÇ¼µ½JBoss Administration½çÃæ²¢×°ÖÃÆäËûJEEÓ¦ÓóÌÐò¡£¡£¡£¡£¡£¡£
https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2018-743
2. systemd-journaldÕ»»º³åÇøÒç³öÎó²î
systemd-journaldʵÏÖ±£´æ»º³åÇøÒç³öÎó²î£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬Ê¹systemd-journald±ÀÀ£»£»£»£»£»£»£»òÒÔjournaldȨÏÞÖ´ÐдúÂë¡£¡£¡£¡£¡£¡£
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16864
3. SAS Web Infrastructure Platform·´ÐòÁл¯´úÂëÖ´ÐÐÎó²î
SAS Web Infrastructure PlatformµÄ·´ÐòÁл¯Îó²î£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬¿ÉÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£
https://support.sas.com/kb/63/391.html
4. IDenticard PremisysÊý¾Ý¿âĬÈÏÆ¾Ö¤Îó²î
IDenticard Premisys IdenticardЧÀÍÔÚ×°ÖÃʱʹÓÃĬÈϵÄÊý¾Ý¿âÓû§ÃûºÍÃÜÂ룬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬Î´ÊÚȨ»á¼ûÊý¾Ý¿âȨÏÞ¡£¡£¡£¡£¡£¡£
http://www.securityfocus.com/bid/106552
5. LCDS LAquis SCADAδÊÚȨ»á¼ûÎó²î
LCDS LAquis SCADAʵÏÖ±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬ÈƹýÉí·ÝÑéÖ¤£¬£¬£¬£¬£¬£¬£¬»ñÈ¡Ãô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£
https://ics-cert.us-cert.gov/advisories/ICSA-19-015-01
Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö

ÒÔÉ«ÁÐÇå¾²Ñо¿Ô±Noam Rotem·¢Ã÷»úƱԤ¶©ÏµÍ³Amadeus±£´æÒ»¸öÑÏÖØµÄÇå¾²Îó²î£¬£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂÓû§ÐÅϢй¶ºÍÕË»§¸ü¸Ä¡£¡£¡£¡£¡£¡£RotemÔÚÒÔÉ«Áк½¿Õ¹«Ë¾ELALÔ¤¶©»úƱʱ·¢Ã÷ÁËÕâÒ»ÎÊÌ⣬£¬£¬£¬£¬£¬£¬ÔÚÔ¤¶©º½°àºó£¬£¬£¬£¬£¬£¬£¬ÓοͻáÊÕµ½PNRºÅÂëºÍÓÃÓÚÉó²éÔ¤¶©ÐÅÏ¢µÄÁ´½Ó¡£¡£¡£¡£¡£¡£Rotem·¢Ã÷ͨ¹ý½«¸ÃÁ´½ÓÉϵÄRULE_SOURCE_1_ID²ÎÊýÐÞ¸ÄΪÆäËüÈ˵ÄPNRºÅÂë¼´¿ÉÉó²éËûÈ˵ÄÔ¤¶©ÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß»¹¿ÉʹÓÃÕâЩÐÅÏ¢»á¼ûELALÃÅ»§ÍøÕ¾²¢¸ü¸ÄÊܺ¦ÕßµÄÕË»§ÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬°üÀ¨¶Ò»»Àï³Ì¡¢¸ü¸ÄÓʼþµØµãºÍµç»°ºÅÂëµÈ¡£¡£¡£¡£¡£¡£ÓÉÓÚAmadeus¿ª·¢µÄ»úƱԤ¶©ÏµÍ³±»È«ÇòÖÁÉÙ141¼Òº½¿Õ¹«Ë¾Ê¹Ó㨰üÀ¨ÃÀ¹úÁªºÏº½¿Õ¹«Ë¾¡¢µÂ¹úººÉ¯º½¿Õ¹«Ë¾ºÍ¼ÓÄô󺽿չ«Ë¾µÈ£©£¬£¬£¬£¬£¬£¬£¬Òò´Ë¸ÃÎó²î¿ÉÄÜÓ°ÏìÁËÊýÒÚÓο͡£¡£¡£¡£¡£¡£ÏÖÔÚAmadeusÒѾÐÞ¸´Á˸ÃÎÊÌâ¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/01/airlines-flight-hacking.html
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/01/oklahoma-fbi-data-leak.html
3¡¢Ó¢¹úBSIAÐû²¼»¥ÁªÇ徲ϵͳ×î¼Ñʵ¼ùÖ¸ÄÏ
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/bsia-guidelines-digital-sabotage/
4¡¢VoIPЧÀÍÉÌVOIPOÒâÍâй¶ÒÑÍùËÄÄêµÄ¿Í»§Êý¾Ý
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/01/voip-service-database-hacking.html
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/es-file-explorer-flaws-put-100-million-users-data-at-risk-fix-promised/
ÉùÃ÷£º±¾×ÊѶÓɼøºÚµ£±£ÍøÎ¬ËûÃüÇ徲С×é·ÒëºÍÕûÀí