ÐÅÏ¢Çå¾²Öܱ¨-2019ÄêµÚ44ÖÜ

Ðû²¼Ê±¼ä 2019-11-12

>±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


2019Äê11ÔÂ04ÈÕÖÁ10ÈÕ¹²ÊÕ¼Çå¾²Îó²î46¸ö£¬£¬£¬£¬ £¬ £¬£¬ÖµµÃ¹Ø×¢µÄÊÇFuji Electric V-Server CVE-2019-18240»º³åÇøÒç³öÎó²î; Cisco Small Business RV016, RV042, RV042G, RV082 CVE-2019-15271í§ÒâÏÂÁîÖ´ÐÐÎó²î£»£»£»£»TYPO3ÉèÖñäÁ¿fileDenyPatterní§Òâ´úÂëÖ´ÐÐÎó²î£»£»£»£»Atlassian Jira Service Desk ServerĿ¼±éÀúÎó²î£»£»£»£»Aruba Networks ClearPass Policy ManagerÊý¾Ý¿âƾ֤й¶Îó²î¡£¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊǶíÂÞ˹¡°Ö÷Ȩ»¥ÁªÍø¡±Ö´·¨ÉúЧ£¬£¬£¬£¬ £¬ £¬£¬¿ÉÓëÈ«Çò»¥ÁªÍø¶Ï¿ª£»£»£»£»ºÚ¿Í¿ÉʹÓü¤¹âÈëÇÖGoogleÖÇÄÜÓïÒôÖúÊÖ£»£»£»£»Libarchive´úÂëÖ´ÐÐÎó²îÓ°ÏìLinux¼°BSD¿¯Ðаæ£»£»£»£»Ç÷ÊÆ¿Æ¼¼ÄÚ²¿Ô±¹¤ÇÔÈ¡Áè¼Ý12ÍòÓû§ÐÅÏ¢²¢³öÊÛ£»£»£»£»2019ÄêÇï¼¾´¹ÂÚ¹¥»÷»î¶¯ÔöÌíÖÁÈýÄêÀ´×î¸ß¼Í¼¡£¡£¡£¡£¡£


ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬ £¬ £¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£¡£



>Ö÷ÒªÇå¾²Îó²îÁбí


1. Fuji Electric V-Server CVE-2019-18240»º³åÇøÒç³öÎó²î


Fuji Electric V-Server±£´æ»º³åÇøÒç³öÎó²î£¬£¬£¬£¬ £¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬ £¬ £¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»£»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£

https://www.us-cert.gov/ics/advisories/icsa-19-311-02


2. Cisco Small Business RV016, RV042, RV042G, RV082 CVE-2019-15271í§ÒâÏÂÁîÖ´ÐÐÎó²î


Cisco RV016 Multi-WAN VPN RouterûÓжÔHTTP payload¾ÙÐÐÊäÈëÑéÖ¤´¦Öóͷ££¬£¬£¬£¬ £¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬ £¬ £¬£¬¿ÉÖ´ÐÐí§ÒâOSÏÂÁî¡£¡£¡£¡£¡£

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20191106-sbrv-cmd-x


3. TYPO3ÉèÖñäÁ¿fileDenyPatterní§Òâ´úÂëÖ´ÐÐÎó²î


TYPO3ÉèÖñäÁ¿fileDenyPatternÖµ´¦Öóͷ£±£´æÇå¾²Îó²î£¬£¬£¬£¬ £¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬ £¬ £¬£¬Ö´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£

https://typo3.org/security/advisory/typo3-sa-2010-012


4. Atlassian Jira Service Desk ServerĿ¼±éÀúÎó²î


Atlassian Jira Service Desk Server±£´æÄ¿Â¼±éÀúÎó²î£¬£¬£¬£¬ £¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬ £¬ £¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎĶÁȡϵͳÎļþÄÚÈÝ¡£¡£¡£¡£¡£

https://jira.atlassian.com/browse/JSDSERVER-6589


5. Aruba Networks ClearPass Policy ManagerÊý¾Ý¿âƾ֤й¶Îó²î


Aruba Networks ClearPass Policy Manager±£´æÇå¾²Îó²î£¬£¬£¬£¬ £¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬ £¬ £¬£¬»ñÈ¡Êý¾Ý¿âƾ֤¡£¡£¡£¡£¡£

https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2016-010.txt



>Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢¶íÂÞ˹¡°Ö÷Ȩ»¥ÁªÍø¡±Ö´·¨ÉúЧ£¬£¬£¬£¬ £¬ £¬£¬¿ÉÓëÈ«Çò»¥ÁªÍø¶Ï¿ª


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


¶íÂÞ˹¡°Ö÷Ȩ»¥ÁªÍø¡±Ö´·¨ÔÚÉÏÖÜÎåÉúЧ£¬£¬£¬£¬ £¬ £¬£¬Õ⽫ʹ¶íÂÞ˹Õþ¸®Äܹ»½«¸Ã¹úÓëÈ«Çò»¥ÁªÍø¶Ï¿ªÅþÁ¬¡£¡£¡£¡£¡£ÕâÏîÖ´·¨ÓÉÆÕ¾©×ÜͳÔÚ5Ô·ÝÇ©Ê𣬣¬£¬£¬ £¬ £¬£¬ÒªÇóISP×°ÖÃÕþ¸®ÌṩµÄÊÖÒÕ×°±¸ÒÔ¾ÙÐÐÁ÷Á¿¼ì²é£¬£¬£¬£¬ £¬ £¬£¬Õâ¿ÉÄÜΪ´ó¹æÄ£¼àÊÓ·­¿ªÁË´óÃÅ¡£¡£¡£¡£¡£Æ¾Ö¤¶íÂÞ˹Õþ¸®µÄ˵·¨£¬£¬£¬£¬ £¬ £¬£¬¸ÃÖ´·¨Ö¼ÔÚÈ·±£×ÝÈ»¶Ï¿ªÓëÈ«Çò»¥ÁªÍøµÄÅþÁ¬Ò²¿ÉÒÔ»á¼û¶íÂÞ˹վµã£¬£¬£¬£¬ £¬ £¬£¬ÒÔÓ¦¶ÔÓÉÍøÂç¹¥»÷»òÇå¾²ÊÂÎñµ¼ÖµÄÖÐÖ¹¡£¡£¡£¡£¡£¸ÃÖ´·¨½«Ê¹¶íÂÞ˹Õþ¸®Äܹ»Éó²éÔÚÏßÄÚÈݲ¢¼àÊÓÍøÃñ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/93315/laws-and-regulations/russia-controversial-law-russia.html


2¡¢ºÚ¿Í¿ÉʹÓü¤¹âÈëÇÖGoogleÖÇÄÜÓïÒôÖúÊÖ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


½üÆÚ£¬£¬£¬£¬ £¬ £¬£¬ÈÕ±¾µç×ÓͨѶ´óѧºÍÃÜЪ¸ù´óѧµÄÑо¿Ö°Ô±·¢Ã÷¿Éͨ¹ý¼¤¹âÈëÇֹȸ衢ƻ¹ûºÍÑÇÂíÑ·µÄÖÇÄÜÓïÒô×°±¸¡£¡£¡£¡£¡£ÕâÖÖ±»³ÆÎª¡°¹âÏÂÁµÄ¹¥»÷¿Éͨ¹ýÏòʹÓÃ΢»úµçϵͳ£¨MEMS£©µÄÂó¿Ë·çÉÏ·¢É伤¹âÊøÊµÏÖ£¬£¬£¬£¬ £¬ £¬£¬Í¨¹ýµ÷ÖÆ¹âÊøµÄÇ¿¶È£¬£¬£¬£¬ £¬ £¬£¬¿ÉÒÔÓÕÆ­MEMS±¬·¢ÓëÒôƵÏÂÁîÏàͬµÄµçÐźţ¬£¬£¬£¬ £¬ £¬£¬×îÔ¶ÉõÖÁ¿ÉÒÔ´Ó110Ã×Íâ¹¥»÷¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄ×°±¸°üÀ¨¹È¸èHome¡¢Nest Cam¡¢ÑÇÂíÑ·Echo¡¢Fire Cube TV¡¢iPhone¡¢ÈýÐÇGalaxy S9¡¢¹È¸èPixelºÍiPad¡£¡£¡£¡£¡£Ñо¿Ö°Ô±Ö¤Êµ¸Ã¹¥»÷ÉõÖÁ¿ÉÒÔ·­¿ª³µ¿âÃÅ»ò½âËøºâÓîÃÅ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/using-light-beams-to-control-google-apple-amazon-assistants/


3¡¢Libarchive´úÂëÖ´ÐÐÎó²îÓ°ÏìLinux¼°BSD¿¯Ðаæ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


¹È¸èÇå¾²Ñо¿Ö°Ô±ÔÚLibarchiveÖз¢Ã÷Ò»¸ö´úÂëÖ´ÐÐÎó²î£¨CVE-2019-18408£©£¬£¬£¬£¬ £¬ £¬£¬¹¥»÷Õß¿ÉÓÕʹÓû§·­¿ª¶ñÒâ´æµµÎļþÔÚÆäϵͳÉÏÖ´ÐдúÂë¡£¡£¡£¡£¡£Debian¡¢Ubuntu¡¢Gentoo¡¢Arch LinuxÒÔ¼°FreeBSDºÍNetBSD¿¯Ðаæ¾ùÊÜÓ°Ï죬£¬£¬£¬ £¬ £¬£¬µ«WindowsºÍmacOS²»ÊÜÓ°Ïì¡£¡£¡£¡£¡£LibarchiveÍŶÓÔÚа汾3.4.0ÖÐÐÞ¸´Á˸ÃÎó²î£¬£¬£¬£¬ £¬ £¬£¬ÏÖÔÚÉÐδÔÚÒ°Íâ·¢Ã÷¸ÃÎó²îµÄPoC»òʹÓôúÂë¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/libarchive-vulnerability-can-lead-to-code-execution-on-linux-freebsd-netbsd/


4¡¢Ç÷ÊÆ¿Æ¼¼ÄÚ²¿Ô±¹¤ÇÔÈ¡Áè¼Ý12ÍòÓû§ÐÅÏ¢²¢³öÊÛ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Ç÷ÊÆ¿Æ¼¼ÄÚ²¿Ô±¹¤ÇÔÈ¡¹«Ë¾¿Í»§ÐÅÏ¢²¢½«Æä³öÊÛ¸øµÚÈý·½Õ©Æ­ÍŻ¡£¡£¡£¡£ÔÚ¿Í»§Ôâµ½ÊÖÒÕÖ§³ÖÕ©Æ­ºó£¬£¬£¬£¬ £¬ £¬£¬Ç÷ÊÆ¿Æ¼¼Õö¿ªÊӲ첢·¢Ã÷¸ÃÔ±¹¤²»·¨»á¼ûÁ˿ͻ§Ö§³ÖÊý¾Ý¿â¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿£¿ÉÄܱ»ÇÔµÄÐÅÏ¢°üÀ¨¿Í»§µÄÐÕÃû¡¢µç×ÓÓʼþµØµã¡¢ÊÖÒÕÖ§³Öµ¥ºÅÒÔ¼°µç»°ºÅÂ룬£¬£¬£¬ £¬ £¬£¬µ«¸Ã¹«Ë¾Ç¿µ÷ûÓм£ÏóÅú×¢²ÆÎñ»òÐÅÓÿ¨ÐÅÏ¢±»ÇÔ£¬£¬£¬£¬ £¬ £¬£¬²¢ÇÒûÓÐÉæ¼°µ½ÆóÒµ»òÕþ¸®¿Í»§¡£¡£¡£¡£¡£Æ¾Ö¤ÆäÄÚ²¿ÊӲ죬£¬£¬£¬ £¬ £¬£¬ÊÜÓ°ÏìµÄ¿Í»§Ö»Õ¼Ç÷ÊÆ¿Æ¼¼1200Íò¿Í»§ÈºµÄ²»µ½1%£¬£¬£¬£¬ £¬ £¬£¬¼´12Íò¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/trendmicro-employee-sold-customer-info-to-tech-support-scammers/


5¡¢2019ÄêÇï¼¾´¹ÂÚ¹¥»÷»î¶¯ÔöÌíÖÁÈýÄêÀ´×î¸ß¼Í¼


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ƾ֤APWGµÄͳ¼ÆÊý¾Ý£¬£¬£¬£¬ £¬ £¬£¬2019ÄêÇï¼¾ÍøÂç´¹ÂÚ¹¥»÷ÔöÌíÖÁÈýÄêÀ´µÄ×î¸ß¼Í¼¡£¡£¡£¡£¡£ÔÚ2019Äê7ÔÂÖÁ9ÔÂʱ´ú¼ì²âµ½µÄ´¹ÂÚÍøÕ¾×ÜÊýΪ266387£¬£¬£¬£¬ £¬ £¬£¬±È2019ÄêµÚ¶þ¼¾¶ÈµÄ182465ÔöÌíÁË46%£¬£¬£¬£¬ £¬ £¬£¬ÏÕЩÊÇ2018ÄêµÚËÄÐò¶ÈµÄ138328µÄÁ½±¶¡£¡£¡£¡£¡£³ýÁË´¹ÂÚÍøÕ¾ÊýÄ¿µÄÔöÌíÖ®Í⣬£¬£¬£¬ £¬ £¬£¬2019ÄêµÚÈý¼¾¶ÈÊÜ´¹ÂÚ¹¥»÷µÄÆ·ÅÆÊýĿҲÏÔ×ÅÔöÌí£¬£¬£¬£¬ £¬ £¬£¬Æ½¾ùÿÔÂÓÐ400¶à¸öÆ·ÅÆÊܵ½¹¥»÷£¬£¬£¬£¬ £¬ £¬£¬¶øµÚ¶þ¼¾¶ÈΪ313¸ö¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.helpnetsecurity.com/2019/11/07/phishing-attacks-levels-rise/