ÐÅÏ¢Çå¾²Öܱ¨-2020ÄêµÚ11ÖÜ

Ðû²¼Ê±¼ä 2020-03-16

> ±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


2020Äê03ÔÂ09ÈÕÖÁ15ÈÕ¹²ÊÕ¼Çå¾²Îó²î67¸ö£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇMicrosoft Server Message BlockѹËõËã·¨´úÂëÖ´ÐÐÎó²î; Apache ShardingSphere unmarshalÊý¾Ý´¦Öóͷ£´úÂëÖ´ÐÐÎó²î£»£»£» £»£»SAP Solution ManagerÑéÖ¤ÈÆ¹ýÎó²î£»£»£» £»£»Johnson Controls Kantech EntraPass SmartService APIЧÀÍÑ¡Ïî´úÂëÖ´ÐÐÎó²î£»£»£» £»£»Barracuda Load Balancer ADC LDAPЧÀÍÉèÖÃÎó²î¡£¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇ΢ÈíÐû²¼Õë¶ÔSMBv3Îó²îµÄKB4551762Çå¾²¸üУ»£»£» £»£»WhisperÊý¾Ý¿â¿É¹ûÕæ»á¼û£¬£¬£¬£¬£¬Ð¹Â¶Ô¼9ÒÚÌõ¼Í¼£»£»£» £»£»Å·ÖÞµçÁ¦ÔËÓªÉÌͬÃËENTSO-E°ì¹«ÍøÂçÔâºÚ¿ÍÈëÇÖ£»£»£» £»£»ÎÒ¹ú8ÏîÍøÂçÇå¾²¹ú¼Ò±ê×¼»ñÅúÐû²¼£»£»£» £»£»Á½ÖÖеÄAMD²àÐŵÀ¹¥»÷£¬£¬£¬£¬£¬Ó°ÏìZen¼Ü¹¹¡£¡£¡£¡£¡£


ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£¡£


>Ö÷ÒªÇå¾²Îó²îÁбí


1. Microsoft Server Message BlockѹËõËã·¨´úÂëÖ´ÐÐÎó²î


Microsoft Server Message Block SMBv3ЭÒéÔÚ´¦Öóͷ£¶ñÒâѹËõÊý¾Ý°ü±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬¿ÉÒÔϵͳÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£

https://portal.msrc.microsoft.com/zh-cn/security-guidance/advisory/CVE-2020-0796


2. Apache ShardingSphere unmarshalÊý¾Ý´¦Öóͷ£´úÂëÖ´ÐÐÎó²î


Apache ShardingSphere WEB¿ØÖÆÌ¨SnakeYAMLÆÊÎöÊý¾Ý±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£

https://lists.apache.org/thread.html/r4a61a24c119bd820da6fb02100d286f8aae55c8f9b94a346b9bb27d8%40%3Cdev.shardingsphere.apache.org%3E


3. SAP Solution ManagerÑéÖ¤ÈÆ¹ýÎó²î


SAP Solution ManagerÑéÖ¤¼ì²é±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬Í¨¹ýSMDAgentsδÊÚȨ»á¼û¡£¡£¡£¡£¡£

https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=540935305


4. Johnson Controls Kantech EntraPass SmartService APIЧÀÍÑ¡Ïî´úÂëÖ´ÐÐÎó²î


Johnson Controls Kantech EntraPass SmartService APIЧÀÍÑ¡Ïî±£´æ´úÂëÉÏ´«Îó²î£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÉÏ´«ÇëÇ󣬣¬£¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£

https://www.us-cert.gov/ics/advisories/icsa-20-070-04


5. Barracuda Load Balancer ADC LDAPЧÀÍÉèÖÃÎó²î


Barracuda Load Balancer ADC LDAPЧÀÍÉèÖñ£´æÇå¾²Îó²î£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬¿ÉδÊÚȨ»á¼ûLDAPЧÀÍ¡£¡£¡£¡£¡£

https://blog.rapid7.com/2020/03/05/r7-2019-39-cve-2019-5648-ldap-credential-exposure-in-barracuda-load-balancer-adc-fixed/


> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢Î¢ÈíÐû²¼Õë¶ÔSMBv3Îó²îµÄKB4551762Çå¾²¸üÐÂ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


΢Èí½ñÌìÔçЩʱ¼äÐû²¼ÁËÕë¶ÔSMBv3 RCEÎó²î£¨CVE-2020-0796£©µÄ²¹¶¡¸üУ¨KB4551762£©£¬£¬£¬£¬£¬Óû§¿ÉÒÔͨ¹ýWindows Update¼ì²é¸üлò´Ó΢Èí²¹¶¡Ä¿Â¼£¨https://www.catalog.update.microsoft.com/Search.aspx?q=KB4551762£©ÉÏÊÖ¶¯ÏÂÔØÊʺÏ×Ô¼ºWindows°æ±¾µÄKB4551762¡£¡£¡£¡£¡£Î¢ÈíÌåÏÖËäȻûÓз¢Ã÷ʹÓôËÎó²îµÄ¹¥»÷£¬£¬£¬£¬£¬µ«½¨ÒéÓû§ÓÅÏÈ×°Öô˸üС£¡£¡£¡£¡£´ËÎó²îÒ²±»³ÆÎªSMBGhost»òEternalDarkness£¬£¬£¬£¬£¬½öÓ°ÏìÔËÐÐWindows 10°æ±¾1903ºÍ1909ÒÔ¼°Windows Server Server Core×°Öð汾1903ºÍ1909µÄ×°±¸¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/microsoft-releases-kb4551762-security-update-for-smbv3-vulnerability/


2¡¢WhisperÊý¾Ý¿â¿É¹ûÕæ»á¼û£¬£¬£¬£¬£¬Ð¹Â¶Ô¼9ÒÚÌõ¼Í¼


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


¾Ý¡¶»ªÊ¢¶ÙÓʱ¨¡·±¨µÀ£¬£¬£¬£¬£¬ÄäÃûÉñÃØ¹²ÏíÓ¦ÓÃWhisperÓÉÓÚÊý¾Ý¿â¿É¹ûÕæ»á¼û£¬£¬£¬£¬£¬µ¼ÖÂÔ¼9ÒÚÌõ¼Í¼й¶¡£¡£¡£¡£¡£Ñо¿Ö°Ô±Matthew PorterºÍDan Ehrlich·¢Ã÷Á˸ÃÊý¾Ý¿â£¬£¬£¬£¬£¬Êý¾Ý¿âÖд洢µÄÊý¾ÝÊÇ´Ó2012Äê¸ÃAPPÐû²¼Ò»Ö±µ½ÏÖÔÚµÄËùÓÐÊý¾Ý¡£¡£¡£¡£¡£Ö»¹Ü¼Í¼Öв»°üÀ¨Óû§Ãû£¬£¬£¬£¬£¬µ«ÆäÖаüÀ¨êdzơ¢ÄêËê¡¢ÖÖ×å¡¢ÐԱ𡢼ÒÏç¡¢ÕûÌå³ÉÔ±¹ØÏµÒÔ¼°Óë·¢ÌûÏà¹ØµÄλÖÃÊý¾Ý¡£¡£¡£¡£¡£ÕâЩλÖÃÐÅÏ¢°üÀ¨À´×ÔÓû§×î½ü·¢ÌûµÄ×ø±ê£¬£¬£¬£¬£¬ÀýÈçÌØ¶¨µÄѧУ¡¢ÊÂÇ鳡ºÏºÍסÃñÇø¡£¡£¡£¡£¡£WhisperÔÚ½Óµ½Í¨Öªºó×÷·ÏÁ˸ÃÊý¾Ý¿âµÄ»á¼ûȨÏÞ£¬£¬£¬£¬£¬²¢Í¨ÖªÁËÁª°îÖ´·¨»ú¹¹¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/whisper-an-anonymous-secret-sharing-app-failed-to-keep-messages-profiles-private/


3¡¢Å·ÖÞµçÁ¦ÔËÓªÉÌͬÃËENTSO-E°ì¹«ÍøÂçÔâºÚ¿ÍÈëÇÖ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Å·ÖÞµçÁ¦ÔËÓªÉÌͬÃË£¨ENTSO-E£©ÔÚÒ»·Ý¼ò¶ÌµÄÉùÃ÷ÖÐÌåÏÖ£¬£¬£¬£¬£¬½üÆÚÆä°ì¹«ÍøÂçÔâµ½ºÚ¿ÍÈëÇÖ¡£¡£¡£¡£¡£ÓÉÓÚ¸Ã°ì¹«ÍøÂ粢δÅþÁ¬µ½ÈκÎÔËÓªÖеĵçÁ¦´«Êäϵͳ£¬£¬£¬£¬£¬ÕâÒâζ׏¥»÷½öÏÞÓÚITϵͳ£¬£¬£¬£¬£¬Ã»ÓÐÓ°ÏìÒªº¦¿ØÖÆÏµÍ³¡£¡£¡£¡£¡£ENTSO-E×ܲ¿Î»ÓÚ²¼Â³Èû¶û£¬£¬£¬£¬£¬ÓÉ35¸öÅ·ÖÞ¹ú¼ÒµÄ42¼ÒµçÍøÔËÓªÉÌ×é³É¡£¡£¡£¡£¡£ENTSO-EÌåÏÖÒѾ­¾ÙÐÐÁËΣº¦ÆÀ¹ÀºÍÖÆ¶©ÁËÓ¦¼±ÍýÏ룬£¬£¬£¬£¬ÒÔïÔÌ­½øÒ»²½¹¥»÷µÄΣº¦ºÍÓ°Ï죬£¬£¬£¬£¬µ«Ã»ÓÐ͸¶ÓëÈëÇÖºÎʱ×îÏÈÒÔ¼°Ë­¿ÉÄܶԹ¥»÷ÈÏÕæÓйصÄÏêϸÐÅÏ¢¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.cyberscoop.com/european-entso-breach-fingrid/


4¡¢ÎÒ¹ú8ÏîÍøÂçÇå¾²¹ú¼Ò±ê×¼»ñÅúÐû²¼


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ƾ֤2020Äê3ÔÂ6ÈÕ¹ú¼ÒÊг¡¼àÊÓÖÎÀí×ܾ֡¢¹ú¼Ò±ê×¼»¯ÖÎÀíίԱ»áÐû²¼µÄÖлªÈËÃñ¹²ºÍ¹ú¹ú¼Ò±ê׼ͨ¸æ£¨2020ÄêµÚ1ºÅ£©£¬£¬£¬£¬£¬ÌìÏÂÐÅÏ¢Çå¾²±ê×¼»¯ÊÖÒÕίԱ»á¹é¿ÚµÄGB/T 35273-2020¡¶ÐÅÏ¢Çå¾²ÊÖÒÕ Ð¡ÎÒ˽¼ÒÐÅÏ¢Çå¾²¹æ·¶¡·µÈ8Ïî¹ú¼Ò±ê×¼ÕýʽÐû²¼¡£¡£¡£¡£¡£ÏêϸÇåµ¥°üÀ¨GB/T 17901.1-2020¡¶ÐÅÏ¢ÊÖÒÕ Çå¾²ÊÖÒÕ ÃØÔ¿ÖÎÀí µÚ1²¿·Ö£º¿ò¼Ü¡·¡¢GB/T 38540-2020¡¶ÐÅÏ¢Çå¾²ÊÖÒÕ Çå¾²µç×ÓÇ©ÕÂÃÜÂëÊÖÒչ淶¡·¡¢GB/T 38541-2020¡¶ÐÅÏ¢Çå¾²ÊÖÒÕ µç×ÓÎļþÃÜÂëÓ¦ÓÃÖ¸ÄÏ¡·¡¢GB/T 38543-2020¡¶ÐÅÏ¢Çå¾²ÊÖÒÕ »ùÓÚÉúÎïÌØÕ÷ʶ±ðµÄÒÆ¶¯ÖÇÄÜÖÕ¶ËÉí·ÝÅбðÊÖÒÕ¿ò¼Ü¡·¡¢GB/T 38556-2020¡¶ÐÅÏ¢Çå¾²ÊÖÒÕ ¶¯Ì¬¿ÚÁîÃÜÂëÓ¦ÓÃÊÖÒչ淶¡·¡¢GB/T 338558-2020¡¶ÐÅÏ¢Çå¾²ÊÖÒÕ °ì¹«×°±¸Çå¾²²âÊÔÒªÁì¡·ÒÔ¼°GB/T 38561-2020¡¶ÐÅÏ¢Çå¾²ÊÖÒÕ ÍøÂçÇå¾²ÖÎÀíÖ§³ÖϵͳÊÖÒÕÒªÇó¡·¡£¡£¡£¡£¡£ËùÓÐ8Ïî±ê×¼µÄʵÑéÈÕÆÚ¶¼ÊÇ2020-10-01¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.tc260.org.cn/front/postDetail.html?id=20200307152229


5¡¢Á½ÖÖеÄAMD²àÐŵÀ¹¥»÷£¬£¬£¬£¬£¬Ó°ÏìZen¼Ü¹¹


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


¸ñÀ­´ÄÊÖÒÕ´óѧÐû²¼µÄһƪÐÂÂÛÎÄÏêϸÏÈÈÝÁËÁ½ÖÖеÄAMD CPU²àÐŵÀ¹¥»÷£¬£¬£¬£¬£¬¼´Collide+ProbeºÍLoad+Reload¹¥»÷£¬£¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ýʹÓÃL1D»º´æÕ¹Íû±äÁ¿À´×ß©AMD´¦Öóͷ£Æ÷µÄÉñÃØÊý¾Ý¡£¡£¡£¡£¡£Ñо¿Ö°Ô±³Æ¸ÃÎó²îÓ°ÏìÁË´Ó2011Äêµ½2019ÄêµÄËùÓÐAMD´¦Öóͷ£Æ÷£¬£¬£¬£¬£¬ÕâÒâζ×ÅZen¼Ü¹¹Ò»¨Üµ½Ó°Ïì¡£¡£¡£¡£¡£¸Ã´óѧÌåÏÖËüÒÑÓÚ2019Äê8ÔÂ23ÈÕÏòAMDÅû¶ÁËÕâЩÎó²î£¬£¬£¬£¬£¬µ«AMDÉÐδÐû²¼Î¢´úÂë¸üУ¬£¬£¬£¬£¬²¢³ÆÕâЩ¹¥»÷²¢²»ÊÇеĻùÓÚÍÆ²âµÄ¹¥»÷¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/amd-processors-from-2011-to-2019-vulnerable-to-two-new-attacks/