ÐÅÏ¢Çå¾²Öܱ¨-2020ÄêµÚ13ÖÜ

Ðû²¼Ê±¼ä 2020-03-31

> ±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


2020Äê03ÔÂ23ÈÕÖÁ29ÈÕ¹²ÊÕ¼Çå¾²Îó²î62¸ö£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇMicrosoft Windows Adobe Type Manager Library×ÖÌå´¦Öóͷ£´úÂëÖ´ÐÐÎó²î; Apple Safari Webkit CVE-2020-3901ÄÚ´æ¹ýʧÒýÓôúÂëÖ´ÐÐÎó²î£»£»£»£»Apache Shiro Spring dynamic controllersÑéÖ¤ÈÆ¹ýÎó²î£»£»£»£»rConfig lib/crud/search.crud.phpÏÂÁî×¢ÈëÎó²î£»£»£»£»3S-Smart Software Solutions CODESYS V3 web server»º³åÇøÒç³öÎó²î¡£¡£¡£¡£¡£ ¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇKeepnet Labs ESʵÀýй¶Áè¼Ý50ÒÚÌõ¼Í¼£¬£¬£¬£¬£¬¾ùΪÒÔǰй¶£»£»£»£»Î¢ÈíÖÒÑÔAdobe Type Manager¿âÖеÄÁ½¸öRCE 0day£»£»£»£»»ÝÆÕÔÙ´ÎÖÒÑÔ²¿·ÖSSD½«ÔÚÔËÐÐ4ÍòСʱºó·ºÆð¹ÊÕÏ£»£»£»£»¿ªÔ´Â·ÓÉÆ÷¿¯ÐаæOPENWRT/LEDE RCEÎó²î£¨CVE-2020-7982£©£»£»£»£»GithubºÍ¾©¶«µÈÍøÕ¾Ôâµ½ÖÐÐÄÈ˹¥»÷£¬£¬£¬£¬£¬¶à¸öÊ¡ÊÐÇøÊÜÓ°Ïì¡£¡£¡£¡£¡£ ¡£


ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£¡£ ¡£


>Ö÷ÒªÇå¾²Îó²îÁбí


1. Microsoft Windows Adobe Type Manager Library×ÖÌå´¦Öóͷ£´úÂëÖ´ÐÐÎó²î


Microsoft Windows Adobe Type Manager Library´¦Öóͷ£Adobe Type 1 PostScriptÃûÌÃ×ÖÌå±£´æÄÚ´æÆÆËðÎó²î£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²î¹¹½¨¶ñÒâÎļþ£¬£¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»£»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£ ¡£

https://portal.msrc.microsoft.com/zh-cn/security-guidance/advisory/ADV200006


2. Apple Safari Webkit CVE-2020-3901ÄÚ´æ¹ýʧÒýÓôúÂëÖ´ÐÐÎó²î


Apple Safari Webkit±£´æÄÚ´æÆÆËðÎó²î£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄWEBÇëÇ󣬣¬£¬£¬£¬ÓÕʹÓû§»á¼û£¬£¬£¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»£»ò¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£ ¡£

https://support.apple.com/en-us/HT211104


3. Apache Shiro Spring dynamic controllersÑéÖ¤ÈÆ¹ýÎó²î


Apache Shiro Spring dynamic controllers±£´æÑéÖ¤ÈÆ¹ýÎó²î£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬¿ÉÈÆ¹ýÑé֤δÊÚȨ»á¼ûÓ¦Óᣡ£¡£¡£¡£ ¡£

https://lists.apache.org/thread.html/r17f371fc89d34df2d0c8131473fbc68154290e1be238895648f5a1e6%40%3Cdev.shiro.apache.org%3E


4. rConfig lib/crud/search.crud.phpÏÂÁî×¢ÈëÎó²î


rConfig lib/crud/search.crud.php´¦Öóͷ£nodeId±£´æÊäÈëÑéÖ¤Îó²î£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬¿É×¢Èëí§ÒâÏÂÁî²¢Ö´ÐС£¡£¡£¡£¡£ ¡£

https://github.com/rconfig/rconfig/commit/3385f906427d228c48b914625136bf620f4ca0a9


5. 3S-Smart Software Solutions CODESYS V3 web server»º³åÇøÒç³öÎó²î


3S-Smart Software Solutions CODESYS V3 web server CmpWebServerHandlerV3.dll±£´æ¶ÑÒç³öÎó²î£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬¿ÉʹЧÀͳÌÐò±ÀÀ£»£»£»£»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£ ¡£

https://zh-cn.tenable.com/security/research/tra-2020-16?tns_redirect=true


> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢Keepnet Labs ESʵÀýй¶Áè¼Ý50ÒÚÌõ¼Í¼£¬£¬£¬£¬£¬¾ùΪÒÔǰй¶


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


Ó¢¹úÇå¾²³§ÉÌKeepnet LabsµÄÒ»¸öElasticsearchʵÀýй¶ÁËÁè¼Ý50ÒÚÌõÊý¾Ý¼Í¼£¬£¬£¬£¬£¬ÕâЩ¼Í¼ÊÇ2012ÄêÖÁ2019ÄêÖ®¼ä±¬·¢µÄй¶ÊÂÎñÖеļͼ¡£¡£¡£¡£¡£ ¡£¸ÃÊý¾Ý¿âÓÉÁ½¸öÜöÝÍ×é³É£¬£¬£¬£¬£¬Ò»¸ö°üÀ¨50.88ÒÚÌõ¼Í¼£¬£¬£¬£¬£¬¶øÁíÒ»¸öʵʱ¸üеÄÜöÝÍÔò°üÀ¨Áè¼Ý1500ÍòÌõ¼Í¼¡£¡£¡£¡£¡£ ¡£Ð¹Â¶µÄ¼Í¼°üÀ¨¹þÏ£ÀàÐÍ¡¢Ð¹Â¶Äê·Ý¡¢ÃÜÂ루¹þÏ£¡¢¼ÓÃÜ»òÃ÷ÎÄÃûÌã©¡¢µç×ÓÓʼþ¡¢µç×ÓÓʼþÓòÃûÒÔ¼°Ð¹Â¶Ô´£¨°üÀ¨Adobe¡¢Last.fm¡¢Twitter¡¢LinkedIn¡¢TumblrºÍVKµÈ£©¡£¡£¡£¡£¡£ ¡£Keepnet LabsÌåÏÖÊý¾Ý¿âÊÇÔÚÆä¹©Ó¦É̽«Ë÷ÒýǨáãÖÁÁíһ̨ESЧÀÍÆ÷ʱ̻¶µÄ£¬£¬£¬£¬£¬ÔÚǨáãÀú³ÌÖзÀ»ðǽÔÝʱ½ûÓÃÁËÔ¼10·ÖÖÓ£¬£¬£¬£¬£¬Ê¹µÃËÑË÷ÒýÇæ¿ÉÒÔΪÊý¾Ý¿â½¨ÉèË÷Òý¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/100198/data-breach/keepnet-labs-data-leak.html


2¡¢Î¢ÈíÖÒÑÔAdobe Type Manager¿âÖеÄÁ½¸öRCE 0day


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


΢ÈíÐû²¼Ç徲ͨ¸æ£¬£¬£¬£¬£¬ÖÒÑÔWindows Adobe Type Manager¿âÖеÄÁ½¸öRCE 0day£¬£¬£¬£¬£¬ÕâÁ½¸öÎó²îÓ°ÏìÁËÄ¿½ñËùÓÐÊÜÖ§³ÖµÄWindowsºÍWindows Server°æ±¾¡£¡£¡£¡£¡£ ¡£Îó²î±£´æÓÚAdobe Type Manager¿â´¦Öóͷ£Adobe Type 1 PostScript×ÖÌåÃûÌõķ½·¨ÖУ¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ý¶àÖÖ·½·¨Ê¹ÓôËÎó²î£¬£¬£¬£¬£¬ÀýÈç˵·þÓû§·­¿ª¶ñÒâÎĵµ»òÔÚWindowsÔ¤ÀÀ´°¸ñÖÐÉó²éËü¡£¡£¡£¡£¡£ ¡£Î¢ÈíÒѾ­·¢Ã÷ʹÓôËÎó²îµÄÓÐÏÞÕë¶ÔÐÔ¹¥»÷¡£¡£¡£¡£¡£ ¡£½¨ÒéÔÚWindows×ÊÔ´ÖÎÀíÆ÷ÖнûÓá°Ô¤ÀÀ´°¸ñ¡±ºÍ¡°ÏêϸÐÅÏ¢´°¸ñ¡±£¬£¬£¬£¬£¬ÒÔ¼õÇáʹÓÃΣº¦£¬£¬£¬£¬£¬ÁíÍâÁ½¸ö»º½â²½·¥ÊǽûÓÃWebClientЧÀͺÍÖØÃüÃû¡°ATMFD.DLL¡±¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV200006


3¡¢»ÝÆÕÔÙ´ÎÖÒÑÔ²¿·ÖSSD½«ÔÚÔËÐÐ4ÍòСʱºó·ºÆð¹ÊÕÏ


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


»ÝÆÕÔÙ´ÎÖÒÑÔÆä¿Í»§£¬£¬£¬£¬£¬Ä³Ð©´®ÐÐÅþÁ¬µÄSCSI¹Ì̬ӲÅÌ»áÔÚÔËÐÐ4ÍòСʱ£¨Ï൱ÓÚ4Äê206Ìì16¸öСʱ£©ºó·ºÆð¹ÊÕÏ£¬£¬£¬£¬£¬Êý¾ÝºÍÓ²Å̾ùÎÞ·¨»Ö¸´¡£¡£¡£¡£¡£ ¡£¸Ã¹«Ë¾ÓÚ2019Äê11ÔÂÐû²¼ÁËÀàËÆµÄͨ¸æ£¬£¬£¬£¬£¬Æäʱ²¿·ÖSSDÔÚÔËÐÐ32768Сʱºó±¬·¢¹ÊÕÏ¡£¡£¡£¡£¡£ ¡£ÕâÒ»´ÎÊÜÓ°ÏìµÄSSDÐͺŰüÀ¨EK0800JVYPN¡¢EO1600JVYPP¡¢MK0800JVYPQºÍMO1600JVYPR£¬£¬£¬£¬£¬ÊÜÓ°ÏìµÄ²úÆ·°üÀ¨¶àÖÖHPЧÀÍÆ÷ºÍ´æ´¢²úÆ·£¬£¬£¬£¬£¬ÈçHP ProLiant¡¢Synergy¡¢Apollo 4200µÈ¡£¡£¡£¡£¡£ ¡£HPEÔ¤¼Æ£¬£¬£¬£¬£¬Î´´ò²¹¶¡µÄSSD×îÔ罫ÔÚ2020Äê10ÔÂ×îÏÈ·ºÆð¹ÊÕÏ£¬£¬£¬£¬£¬½¨ÒéÓû§¾¡¿ìÓ¦Óù̼þ¸üС£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/hpe-warns-of-new-bug-that-kills-ssd-drives-after-40-000-hours/


4¡¢¿ªÔ´Â·ÓÉÆ÷¿¯ÐаæOPENWRT/LEDE RCEÎó²î£¨CVE-2020-7982£©


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


Ñо¿Ö°Ô±Åû¶¿ªÔ´Â·ÓÉÆ÷¿¯ÐаæOPENWRT/LEDEÖеÄÒªº¦RCEÎó²î£¨CVE-2020-7982£©µÄÊÖÒÕϸ½ÚºÍPoC¡£¡£¡£¡£¡£ ¡£¸ÃÎó²î±£´æÓÚOpenWrtµÄOPKGÈí¼þ°ü¹ÜÀíÆ÷ÖУ¬£¬£¬£¬£¬OPKG¶ÔÏÂÔØµÄÈí¼þ°üÖ´ÐÐÍêÕûÐÔ¼ì²éʱ£¬£¬£¬£¬£¬ÈôÊÇSHA-256УÑéºÍ°üÀ¨ÈκÎǰµ¼¿Õ¸ñ£¬£¬£¬£¬£¬OPKG»áÌø¹ýÍêÕûÐÔ¼ì²é¼ÌÐøÖ´ÐÐ×°ÖÃʹÃü¡£¡£¡£¡£¡£ ¡£¸ÃÎó²î¿ÉÄÜʹԶ³ÌMitM¹¥»÷ÕßÄܹ»ÓÕÆ­ÏµÍ³×°ÖÃδÂÄÀúÖ¤µÄ¶ñÒâÈí¼þ°ü»òÈí¼þ¸üУ¬£¬£¬£¬£¬´Ó¶ø×赲ĿµÄ×°±¸µÄͨѶºÍÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£ ¡£OpenWrt°æ±¾18.06.0ÖÁ18.06.6ºÍ19.07.0ÒÔ¼°LEDE 17.01.0ÖÁ17.01.7¾ùÊܵ½Ó°Ïì¡£¡£¡£¡£¡£ ¡£½¨ÒéÊÜÓ°ÏìµÄÓû§½«Æä×°±¸¹Ì¼þÉý¼¶µ½×îÐÂOpenWrt°æ±¾18.06.7ºÍ19.07.1¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2020/03/openwrt-rce-vulnerability.html


5¡¢GithubºÍ¾©¶«µÈÍøÕ¾Ôâµ½ÖÐÐÄÈ˹¥»÷£¬£¬£¬£¬£¬¶à¸öÊ¡ÊÐÇøÊÜÓ°Ïì


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


3ÔÂ26ÈÕÓй¥»÷ÕßÕë¶ÔGithubºÍ¾©¶«µÈÍøÕ¾Ìᳫ´ó¹æÄ£ÖÐÐÄÈ˹¥»÷£¬£¬£¬£¬£¬ÏÖÔÚÊÜÓ°ÏìµÄÖ÷ÒªÊDz¿·ÖµØÇøÓû§£¬£¬£¬£¬£¬µ«Éæ¼°ËùÓÐÔËÓªÉÌ£¬£¬£¬£¬£¬ÀýÈçÖйúÒÆ¶¯¡¢ÖйúÁªÍ¨¡¢ÖйúµçÐÅÒÔ¼°½ÌÓýÍø¾ù¿É¸´ÏÖÐ®ÖÆÎÊÌ⣬£¬£¬£¬£¬¶øÍâÑóÍøÂç»á¼ûÕâЩվµã²¢Î´·ºÆðÒì³£ÇéÐΡ£¡£¡£¡£¡£ ¡£´ÓÏÖÔÚÍøÉÏÅÌÎʵÄÐÅÏ¢¿ÉÒÔ¿´µ½´Ë´Î¹¥»÷Éæ¼°×î¹ãµÄÊÇGitHub.io£¬£¬£¬£¬£¬Æä´ÎÓû§»á¼û¾©¶«µÈº£ÄÚ×ÅÃûÍøÕ¾Òà»á±¨´í¡£¡£¡£¡£¡£ ¡£Éó²éÖ¤ÊéÐÅÏ¢¿ÉÒÔ·¢Ã÷ÕâÐ©ÍøÕ¾µÄÖ¤Êé±»¹¥»÷ÕßʹÓõÄ×ÔÊðÃûÖ¤ÊéÈ¡´ú£¬£¬£¬£¬£¬µ¼ÖÂä¯ÀÀÆ÷ÎÞ·¨ÐÅÈδӶø×èÖ¹Óû§»á¼û¡£¡£¡£¡£¡£ ¡£ÏÖÔÚÈ«Íø¾ø´ó´ó¶¼ÍøÕ¾¶¼ÒѾ­¿ªÆô¼ÓÃÜÊÖÒÕ¶Ô¿¹Ð®ÖÆ£¬£¬£¬£¬£¬Òò´ËÓû§»á¼û»á±»×èÖ¹¶ø²»»á±»Ö¸µ¼µ½´¹ÂÚÍøÕ¾ÉÏÈ¥¡£¡£¡£¡£¡£ ¡£´Ë´Î¹¥»÷ËÆºõÊÇͨ¹ýÖ÷¸ÉÍøÂçÐ®ÖÆ443¶Ë¿Ú£¬£¬£¬£¬£¬ÏÖÔÚ¾­²âÊÔDNSϵͳÆÊÎöÊÇÍêÈ«Õý³£µÄ¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.landiannews.com/archives/71707.html