ÐÅÏ¢Çå¾²Öܱ¨-2020ÄêµÚ13ÖÜ

Ðû²¼Ê±¼ä 2020-03-31

> ±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


2020Äê03ÔÂ23ÈÕÖÁ29ÈÕ¹²ÊÕ¼Çå¾²Îó²î62¸ö £¬£¬£¬£¬ £¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇMicrosoft Windows Adobe Type Manager Library×ÖÌå´¦Öóͷ£´úÂëÖ´ÐÐÎó²î; Apple Safari Webkit CVE-2020-3901ÄÚ´æ¹ýʧÒýÓôúÂëÖ´ÐÐÎó²î£»£» £»£»£»Apache Shiro Spring dynamic controllersÑéÖ¤ÈÆ¹ýÎó²î£»£» £»£»£»rConfig lib/crud/search.crud.phpÏÂÁî×¢ÈëÎó²î£»£» £»£»£»3S-Smart Software Solutions CODESYS V3 web server»º³åÇøÒç³öÎó²î¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇKeepnet Labs ESʵÀýй¶Áè¼Ý50ÒÚÌõ¼Í¼ £¬£¬£¬£¬ £¬£¬£¬¾ùΪÒÔǰй¶£»£» £»£»£»Î¢ÈíÖÒÑÔAdobe Type Manager¿âÖеÄÁ½¸öRCE 0day£»£» £»£»£»»ÝÆÕÔÙ´ÎÖÒÑÔ²¿·ÖSSD½«ÔÚÔËÐÐ4ÍòСʱºó·ºÆð¹ÊÕÏ£»£» £»£»£»¿ªÔ´Â·ÓÉÆ÷¿¯ÐаæOPENWRT/LEDE RCEÎó²î£¨CVE-2020-7982£©£»£» £»£»£»GithubºÍ¾©¶«µÈÍøÕ¾Ôâµ½ÖÐÐÄÈ˹¥»÷ £¬£¬£¬£¬ £¬£¬£¬¶à¸öÊ¡ÊÐÇøÊÜÓ°Ïì¡£¡£¡£


ƾ֤ÒÔÉÏ×ÛÊö £¬£¬£¬£¬ £¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£


>Ö÷ÒªÇå¾²Îó²îÁбí


1. Microsoft Windows Adobe Type Manager Library×ÖÌå´¦Öóͷ£´úÂëÖ´ÐÐÎó²î


Microsoft Windows Adobe Type Manager Library´¦Öóͷ£Adobe Type 1 PostScriptÃûÌÃ×ÖÌå±£´æÄÚ´æÆÆËðÎó²î £¬£¬£¬£¬ £¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²î¹¹½¨¶ñÒâÎļþ £¬£¬£¬£¬ £¬£¬£¬ÓÕʹÓû§ÆÊÎö £¬£¬£¬£¬ £¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£» £»£»£»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£

https://portal.msrc.microsoft.com/zh-cn/security-guidance/advisory/ADV200006


2. Apple Safari Webkit CVE-2020-3901ÄÚ´æ¹ýʧÒýÓôúÂëÖ´ÐÐÎó²î


Apple Safari Webkit±£´æÄÚ´æÆÆËðÎó²î £¬£¬£¬£¬ £¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄWEBÇëÇó £¬£¬£¬£¬ £¬£¬£¬ÓÕʹÓû§»á¼û £¬£¬£¬£¬ £¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£» £»£»£»ò¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£

https://support.apple.com/en-us/HT211104


3. Apache Shiro Spring dynamic controllersÑéÖ¤ÈÆ¹ýÎó²î


Apache Shiro Spring dynamic controllers±£´æÑéÖ¤ÈÆ¹ýÎó²î £¬£¬£¬£¬ £¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó £¬£¬£¬£¬ £¬£¬£¬¿ÉÈÆ¹ýÑé֤δÊÚȨ»á¼ûÓ¦Óᣡ£¡£

https://lists.apache.org/thread.html/r17f371fc89d34df2d0c8131473fbc68154290e1be238895648f5a1e6%40%3Cdev.shiro.apache.org%3E


4. rConfig lib/crud/search.crud.phpÏÂÁî×¢ÈëÎó²î


rConfig lib/crud/search.crud.php´¦Öóͷ£nodeId±£´æÊäÈëÑéÖ¤Îó²î £¬£¬£¬£¬ £¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó £¬£¬£¬£¬ £¬£¬£¬¿É×¢Èëí§ÒâÏÂÁî²¢Ö´ÐС£¡£¡£

https://github.com/rconfig/rconfig/commit/3385f906427d228c48b914625136bf620f4ca0a9


5. 3S-Smart Software Solutions CODESYS V3 web server»º³åÇøÒç³öÎó²î


3S-Smart Software Solutions CODESYS V3 web server CmpWebServerHandlerV3.dll±£´æ¶ÑÒç³öÎó²î £¬£¬£¬£¬ £¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó £¬£¬£¬£¬ £¬£¬£¬¿ÉʹЧÀͳÌÐò±ÀÀ£»£» £»£»£»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£

https://zh-cn.tenable.com/security/research/tra-2020-16?tns_redirect=true


> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢Keepnet Labs ESʵÀýй¶Áè¼Ý50ÒÚÌõ¼Í¼ £¬£¬£¬£¬ £¬£¬£¬¾ùΪÒÔǰй¶


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


Ó¢¹úÇå¾²³§ÉÌKeepnet LabsµÄÒ»¸öElasticsearchʵÀýй¶ÁËÁè¼Ý50ÒÚÌõÊý¾Ý¼Í¼ £¬£¬£¬£¬ £¬£¬£¬ÕâЩ¼Í¼ÊÇ2012ÄêÖÁ2019ÄêÖ®¼ä±¬·¢µÄй¶ÊÂÎñÖеļͼ¡£¡£¡£¸ÃÊý¾Ý¿âÓÉÁ½¸öÜöÝÍ×é³É £¬£¬£¬£¬ £¬£¬£¬Ò»¸ö°üÀ¨50.88ÒÚÌõ¼Í¼ £¬£¬£¬£¬ £¬£¬£¬¶øÁíÒ»¸öʵʱ¸üеÄÜöÝÍÔò°üÀ¨Áè¼Ý1500ÍòÌõ¼Í¼¡£¡£¡£Ð¹Â¶µÄ¼Í¼°üÀ¨¹þÏ£ÀàÐÍ¡¢Ð¹Â¶Äê·Ý¡¢ÃÜÂ루¹þÏ£¡¢¼ÓÃÜ»òÃ÷ÎÄÃûÌã©¡¢µç×ÓÓʼþ¡¢µç×ÓÓʼþÓòÃûÒÔ¼°Ð¹Â¶Ô´£¨°üÀ¨Adobe¡¢Last.fm¡¢Twitter¡¢LinkedIn¡¢TumblrºÍVKµÈ£©¡£¡£¡£Keepnet LabsÌåÏÖÊý¾Ý¿âÊÇÔÚÆä¹©Ó¦É̽«Ë÷ÒýǨáãÖÁÁíһ̨ESЧÀÍÆ÷ʱ̻¶µÄ £¬£¬£¬£¬ £¬£¬£¬ÔÚǨáãÀú³ÌÖзÀ»ðǽÔÝʱ½ûÓÃÁËÔ¼10·ÖÖÓ £¬£¬£¬£¬ £¬£¬£¬Ê¹µÃËÑË÷ÒýÇæ¿ÉÒÔΪÊý¾Ý¿â½¨ÉèË÷Òý¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/100198/data-breach/keepnet-labs-data-leak.html


2¡¢Î¢ÈíÖÒÑÔAdobe Type Manager¿âÖеÄÁ½¸öRCE 0day


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


΢ÈíÐû²¼Ç徲ͨ¸æ £¬£¬£¬£¬ £¬£¬£¬ÖÒÑÔWindows Adobe Type Manager¿âÖеÄÁ½¸öRCE 0day £¬£¬£¬£¬ £¬£¬£¬ÕâÁ½¸öÎó²îÓ°ÏìÁËÄ¿½ñËùÓÐÊÜÖ§³ÖµÄWindowsºÍWindows Server°æ±¾¡£¡£¡£Îó²î±£´æÓÚAdobe Type Manager¿â´¦Öóͷ£Adobe Type 1 PostScript×ÖÌåÃûÌõķ½·¨ÖÐ £¬£¬£¬£¬ £¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ý¶àÖÖ·½·¨Ê¹ÓôËÎó²î £¬£¬£¬£¬ £¬£¬£¬ÀýÈç˵·þÓû§·­¿ª¶ñÒâÎĵµ»òÔÚWindowsÔ¤ÀÀ´°¸ñÖÐÉó²éËü¡£¡£¡£Î¢ÈíÒѾ­·¢Ã÷ʹÓôËÎó²îµÄÓÐÏÞÕë¶ÔÐÔ¹¥»÷¡£¡£¡£½¨ÒéÔÚWindows×ÊÔ´ÖÎÀíÆ÷ÖнûÓá°Ô¤ÀÀ´°¸ñ¡±ºÍ¡°ÏêϸÐÅÏ¢´°¸ñ¡± £¬£¬£¬£¬ £¬£¬£¬ÒÔ¼õÇáʹÓÃΣº¦ £¬£¬£¬£¬ £¬£¬£¬ÁíÍâÁ½¸ö»º½â²½·¥ÊǽûÓÃWebClientЧÀͺÍÖØÃüÃû¡°ATMFD.DLL¡±¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV200006


3¡¢»ÝÆÕÔÙ´ÎÖÒÑÔ²¿·ÖSSD½«ÔÚÔËÐÐ4ÍòСʱºó·ºÆð¹ÊÕÏ


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


»ÝÆÕÔÙ´ÎÖÒÑÔÆä¿Í»§ £¬£¬£¬£¬ £¬£¬£¬Ä³Ð©´®ÐÐÅþÁ¬µÄSCSI¹Ì̬ӲÅÌ»áÔÚÔËÐÐ4ÍòСʱ£¨Ï൱ÓÚ4Äê206Ìì16¸öСʱ£©ºó·ºÆð¹ÊÕÏ £¬£¬£¬£¬ £¬£¬£¬Êý¾ÝºÍÓ²Å̾ùÎÞ·¨»Ö¸´¡£¡£¡£¸Ã¹«Ë¾ÓÚ2019Äê11ÔÂÐû²¼ÁËÀàËÆµÄͨ¸æ £¬£¬£¬£¬ £¬£¬£¬Æäʱ²¿·ÖSSDÔÚÔËÐÐ32768Сʱºó±¬·¢¹ÊÕÏ¡£¡£¡£ÕâÒ»´ÎÊÜÓ°ÏìµÄSSDÐͺŰüÀ¨EK0800JVYPN¡¢EO1600JVYPP¡¢MK0800JVYPQºÍMO1600JVYPR £¬£¬£¬£¬ £¬£¬£¬ÊÜÓ°ÏìµÄ²úÆ·°üÀ¨¶àÖÖHPЧÀÍÆ÷ºÍ´æ´¢²úÆ· £¬£¬£¬£¬ £¬£¬£¬ÈçHP ProLiant¡¢Synergy¡¢Apollo 4200µÈ¡£¡£¡£HPEÔ¤¼Æ £¬£¬£¬£¬ £¬£¬£¬Î´´ò²¹¶¡µÄSSD×îÔ罫ÔÚ2020Äê10ÔÂ×îÏÈ·ºÆð¹ÊÕÏ £¬£¬£¬£¬ £¬£¬£¬½¨ÒéÓû§¾¡¿ìÓ¦Óù̼þ¸üС£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/hpe-warns-of-new-bug-that-kills-ssd-drives-after-40-000-hours/


4¡¢¿ªÔ´Â·ÓÉÆ÷¿¯ÐаæOPENWRT/LEDE RCEÎó²î£¨CVE-2020-7982£©


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


Ñо¿Ö°Ô±Åû¶¿ªÔ´Â·ÓÉÆ÷¿¯ÐаæOPENWRT/LEDEÖеÄÒªº¦RCEÎó²î£¨CVE-2020-7982£©µÄÊÖÒÕϸ½ÚºÍPoC¡£¡£¡£¸ÃÎó²î±£´æÓÚOpenWrtµÄOPKGÈí¼þ°ü¹ÜÀíÆ÷ÖÐ £¬£¬£¬£¬ £¬£¬£¬OPKG¶ÔÏÂÔØµÄÈí¼þ°üÖ´ÐÐÍêÕûÐÔ¼ì²éʱ £¬£¬£¬£¬ £¬£¬£¬ÈôÊÇSHA-256УÑéºÍ°üÀ¨ÈκÎǰµ¼¿Õ¸ñ £¬£¬£¬£¬ £¬£¬£¬OPKG»áÌø¹ýÍêÕûÐÔ¼ì²é¼ÌÐøÖ´ÐÐ×°ÖÃʹÃü¡£¡£¡£¸ÃÎó²î¿ÉÄÜʹԶ³ÌMitM¹¥»÷ÕßÄܹ»ÓÕÆ­ÏµÍ³×°ÖÃδÂÄÀúÖ¤µÄ¶ñÒâÈí¼þ°ü»òÈí¼þ¸üР£¬£¬£¬£¬ £¬£¬£¬´Ó¶ø×赲ĿµÄ×°±¸µÄͨѶºÍÖ´ÐÐí§Òâ´úÂë¡£¡£¡£OpenWrt°æ±¾18.06.0ÖÁ18.06.6ºÍ19.07.0ÒÔ¼°LEDE 17.01.0ÖÁ17.01.7¾ùÊܵ½Ó°Ïì¡£¡£¡£½¨ÒéÊÜÓ°ÏìµÄÓû§½«Æä×°±¸¹Ì¼þÉý¼¶µ½×îÐÂOpenWrt°æ±¾18.06.7ºÍ19.07.1¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2020/03/openwrt-rce-vulnerability.html


5¡¢GithubºÍ¾©¶«µÈÍøÕ¾Ôâµ½ÖÐÐÄÈ˹¥»÷ £¬£¬£¬£¬ £¬£¬£¬¶à¸öÊ¡ÊÐÇøÊÜÓ°Ïì


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


3ÔÂ26ÈÕÓй¥»÷ÕßÕë¶ÔGithubºÍ¾©¶«µÈÍøÕ¾Ìᳫ´ó¹æÄ£ÖÐÐÄÈ˹¥»÷ £¬£¬£¬£¬ £¬£¬£¬ÏÖÔÚÊÜÓ°ÏìµÄÖ÷ÒªÊDz¿·ÖµØÇøÓû§ £¬£¬£¬£¬ £¬£¬£¬µ«Éæ¼°ËùÓÐÔËÓªÉÌ £¬£¬£¬£¬ £¬£¬£¬ÀýÈçÖйúÒÆ¶¯¡¢ÖйúÁªÍ¨¡¢ÖйúµçÐÅÒÔ¼°½ÌÓýÍø¾ù¿É¸´ÏÖÐ®ÖÆÎÊÌâ £¬£¬£¬£¬ £¬£¬£¬¶øÍâÑóÍøÂç»á¼ûÕâЩվµã²¢Î´·ºÆðÒì³£ÇéÐΡ£¡£¡£´ÓÏÖÔÚÍøÉÏÅÌÎʵÄÐÅÏ¢¿ÉÒÔ¿´µ½´Ë´Î¹¥»÷Éæ¼°×î¹ãµÄÊÇGitHub.io £¬£¬£¬£¬ £¬£¬£¬Æä´ÎÓû§»á¼û¾©¶«µÈº£ÄÚ×ÅÃûÍøÕ¾Òà»á±¨´í¡£¡£¡£Éó²éÖ¤ÊéÐÅÏ¢¿ÉÒÔ·¢Ã÷ÕâÐ©ÍøÕ¾µÄÖ¤Êé±»¹¥»÷ÕßʹÓõÄ×ÔÊðÃûÖ¤ÊéÈ¡´ú £¬£¬£¬£¬ £¬£¬£¬µ¼ÖÂä¯ÀÀÆ÷ÎÞ·¨ÐÅÈδӶø×èÖ¹Óû§»á¼û¡£¡£¡£ÏÖÔÚÈ«Íø¾ø´ó´ó¶¼ÍøÕ¾¶¼ÒѾ­¿ªÆô¼ÓÃÜÊÖÒÕ¶Ô¿¹Ð®ÖÆ £¬£¬£¬£¬ £¬£¬£¬Òò´ËÓû§»á¼û»á±»×èÖ¹¶ø²»»á±»Ö¸µ¼µ½´¹ÂÚÍøÕ¾ÉÏÈ¥¡£¡£¡£´Ë´Î¹¥»÷ËÆºõÊÇͨ¹ýÖ÷¸ÉÍøÂçÐ®ÖÆ443¶Ë¿Ú £¬£¬£¬£¬ £¬£¬£¬ÏÖÔÚ¾­²âÊÔDNSϵͳÆÊÎöÊÇÍêÈ«Õý³£µÄ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.landiannews.com/archives/71707.html