ÐÅÏ¢Çå¾²Öܱ¨-2020ÄêµÚ10ÖÜ

Ðû²¼Ê±¼ä 2020-03-10

> ±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


2020Äê03ÔÂ02ÈÕÖÁ08ÈÕ¹²ÊÕ¼Çå¾²Îó²î52¸ö £¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇFasterXML jackson-databind CVE-2020-9548´úÂëÖ´ÐÐÎó²î; Rubetek SmartHome²¨¶ÎÉè¼ÆÎó²î£»£»£»Envoy²»×¼È·»á¼û¿ØÖÆÎó²î£»£»£»Qualcomm MDM9206 WLAN»º³åÇøÒç³öÎó²î£»£»£»Google Chrome mediaÇå¾²ÈÆ¹ýÎó²î¡£¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇTeslaºÍSpaceXµÄÁã¼þÖÆÔìÉÌVisserÈ·ÈÏÔâºÚ¿Í¹¥»÷ÇÒÊý¾Ýй¶£»£»£»Let's Encrypt³·»ØÁè¼Ý300Íò¸öTLSÖ¤Ê飻£»£»CrowdStrikeÐû²¼¡¶2020ÄêÈ«ÇòÍþв±¨¸æ¡·£»£»£»Ó¢¹úÊý¾Ýî¿Ïµ»ú¹¹¶Ô¹úÌ©º½¿Õ´¦ÒÔ50ÍòÓ¢°÷·£¿£¿î£»£»£»°Ä´óÀûÑÇACSCÐû²¼CMSϵͳÇå¾²Ö¸ÄÏ¡£¡£¡£¡£¡£


ƾ֤ÒÔÉÏ×ÛÊö £¬£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£¡£


>Ö÷ÒªÇå¾²Îó²îÁбí


1. FasterXML jackson-databind CVE-2020-9548´úÂëÖ´ÐÐÎó²î


FasterXML jackson-databind ibatis-sqlmapÒÔ¼°anteros-core×é¼þ±£´æºÚÃûµ¥ÈƹýÎó²î £¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó £¬£¬£¬£¬£¬¿ÉÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£

https://github.com/FasterXML/jackson-databind/issues/2631


2. Rubetek SmartHome²¨¶ÎÉè¼ÆÎó²î


Rubetek SmartHomeʹÓÃÁËδ¼ÓÃܵÄ433 MHz²¨¶Î¾ÙÐÐͨѶ £¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó £¬£¬£¬£¬£¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢»ò¾ÙÐоܾøÐ§À͹¥»÷¡£¡£¡£¡£¡£

https://pastebin.com/CckKKJcM


3. Envoy²»×¼È·»á¼û¿ØÖÆÎó²î


EnvoyʹÓÃSDS±£´æ²»×¼È·»á¼û¿ØÖÆÎó²î £¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó £¬£¬£¬£¬£¬¿ÉδÊÚȨ»á¼ûÊÜÏÞ×ÊÔ´¡£¡£¡£¡£¡£

https://github.com/envoyproxy/envoy/security/advisories/GHSA-3x9m-pgmg-xpx8


4. Qualcomm MDM9206 WLAN»º³åÇøÒç³öÎó²î


Qualcomm MDM9206 WLAN±£´æ»º³åÇøÒç³öÎó²î £¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó £¬£¬£¬£¬£¬¿É¾ÙÐоܾøÐ§À͹¥»÷»ò¿ÉÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£

https://www.qualcomm.com/company/product-security/bulletins/march-2020-bulletin


5. Google Chrome mediaÇå¾²ÈÆ¹ýÎó²î


Google Chrome media´¦Öóͷ£Çå¾²Õ½ÂÔ±£´æÇå¾²Îó²î £¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄWEBÇëÇó £¬£¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö £¬£¬£¬£¬£¬¿ÉÈÆ¹ýÇå¾²ÏÞÖÆ £¬£¬£¬£¬£¬Î´ÊÚȨ»á¼û¡£¡£¡£¡£¡£

https://chromereleases.googleblog.com/2020/03/stable-channel-update-for-desktop.html


> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢TeslaºÍSpaceXµÄÁã¼þÖÆÔìÉÌVisserÈ·ÈÏÔâºÚ¿Í¹¥»÷ÇÒÊý¾Ýй¶


¿­Ðý¹ú¼ÊÓÎÏ·(Öйú)¹Ù·½ÍøÕ¾


TeslaºÍSpaceXµÄÁã¼þÖÆÔìÉÌVisserÈ·ÈÏÔâÓöÊý¾Ýй¶ÊÂÎñ £¬£¬£¬£¬£¬¸Ã¹«Ë¾ÊÇÒ»¼ÒרÃÅΪ̫¿ÕºÍ¹ú·À³Ð°üÉÌÉè¼ÆÏ¸ÃÜÁã¼þµÄÖÆÔìÉÌ¡£¡£¡£¡£¡£ÔÚÒ»·Ý¼ò¶ÌµÄÉùÃ÷ÖÐ £¬£¬£¬£¬£¬¸Ã¹«Ë¾È·ÈÏÆä½üÆÚ³ÉΪ¡°ÍøÂçÇå¾²·¸·¨ÊÂÎñ£¨°üÀ¨»á¼ûºÍ͵ÇÔÊý¾Ý£©µÄÄ¿µÄ¡±¡£¡£¡£¡£¡£¸Ã¹«Ë¾½²»°ÈËÌåÏÖ½«¡°¼ÌÐø¶Ô¸Ã¹¥»÷¾ÙÐÐÖÜÈ«ÊÓ²ì £¬£¬£¬£¬£¬²¢ÇÒÓªÒµÔËÐÐÕý³£¡±¡£¡£¡£¡£¡£TechCrunchÑо¿Ö°Ô±³ÆÕâ´Î¹¥»÷ºÜÓпÉÄÜÊÇÓÉDoppelPaymerÀÕË÷Èí¼þÒýÆðµÄ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://techcrunch.com/2020/03/01/visser-breach/


2¡¢4Let's Encrypt³·»ØÁè¼Ý300Íò¸öTLSÖ¤Êé


¿­Ðý¹ú¼ÊÓÎÏ·(Öйú)¹Ù·½ÍøÕ¾


ÓÉÓÚÔÚºó¶Ë´úÂëÖз¢Ã÷ÁËÒ»¸öbug £¬£¬£¬£¬£¬Let's EncryptÏîÄ¿ÍýÏë´ÓÌìϱê׼ʱ¼ä2020Äê3ÔÂ4ÈÕ00:00×îÏÈ×÷·ÏÁè¼Ý300Íò¸öTLSÖ¤Êé¡£¡£¡£¡£¡£ÏêϸÀ´Ëµ £¬£¬£¬£¬£¬¸ÃbugÓ°ÏìÁËBoulder £¬£¬£¬£¬£¬Let's EncryptÏîĿʹÓøÃЧÀÍÆ÷Èí¼þÔÚ¿¯ÐÐTLSÖ¤Êé֮ǰÑéÖ¤Óû§¼°ÆäÓò¡£¡£¡£¡£¡£¸ÃbugÓ°ÏìÁËBoulderÄÚ²¿CAA£¨Ö¤Êé½ÒÏþ»ú¹¹ÊÚȨ£©¹æ·¶µÄʵÑé £¬£¬£¬£¬£¬¡°µ±Ò»¸öÖ¤ÊéÇëÇó°üÀ¨N¸öÐèÒª¾ÙÐÐCAAÖØÐ¼ì²éµÄÓòÃûʱ £¬£¬£¬£¬£¬Boulder½«Ñ¡ÔñÒ»¸öÓòÃû²¢¼ì²éN´Î¡£¡£¡£¡£¡£ÕâÏÖʵÉÏÒâζ×ÅÈôÊÇÒ»¸öÓû§ÔÚʱ¼äXÑéÖ¤ÁËÒ»¸öÓòÃû £¬£¬£¬£¬£¬²¢ÇÒ¸ÃÓòÃûÔÚʱ¼äXµÄCAA¼Í¼ÔÊÐíLet's Encrypt¿¯ÐÐ £¬£¬£¬£¬£¬Ôò¸ÃÓû§¿ÉÒÔÔÚX+30ÌìµÄʱ¼äÀ￯ÐаüÀ¨¸ÃÓòÃûµÄÖ¤Êé £¬£¬£¬£¬£¬×ÝȻ֮ºóÓÐÈËÔÚ¸ÃÓòÃûÉÏ×°ÖÃÁËեȡLet's Encrypt¿¯ÐеÄCAA¼Í¼¡±¡£¡£¡£¡£¡£ÔÚÕâ300Íò¸ö×÷·ÏµÄÖ¤ÊéÖÐ £¬£¬£¬£¬£¬ÓÐ100Íò¸öÊÇͳһÓò/×ÓÓòµÄÖØ¸´Ïî £¬£¬£¬£¬£¬Òò´ËÊÜÓ°ÏìÖ¤ÊéµÄÏÖʵÊýĿԼΪ200Íò¸ö¡£¡£¡£¡£¡£ÔÚ3ÔÂ4ÈÕ00:00Ö®ºóËùÓÐÊÜÓ°ÏìµÄÖ¤Êé¶¼½«´¥·¢ä¯ÀÀÆ÷ºÍÆäËûÓ¦ÓóÌÐòÖеĹýʧ £¬£¬£¬£¬£¬ÓòÃûËùÓÐÕß½«±ØÐèÇëÇóеÄTLSÖ¤Êé²¢Ìæ»»¾ÉµÄTLSÖ¤Êé¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/lets-encrypt-to-revoke-3-million-certificates-on-march-4-due-to-bug/


3¡¢CrowdStrikeÐû²¼¡¶2020ÄêÈ«ÇòÍþв±¨¸æ¡·


¿­Ðý¹ú¼ÊÓÎÏ·(Öйú)¹Ù·½ÍøÕ¾


CrowdStrikeµÄ¡¶2020ÄêÈ«ÇòÍþв±¨¸æ¡·¶ÔÒÑÍùÒ»ÄêÖж¥¼¶ÍøÂçÍþвÇ÷ÊÆ¾ÙÐÐÁËÉîÈëÆÊÎö £¬£¬£¬£¬£¬¸Ã±¨¸æµÄÒªµã°üÀ¨£º´óÐ͹¥»÷»î¶¯£¨BGH£©Ò»Ö±Éý¼¶ £¬£¬£¬£¬£¬Êê½ðÒªÇóì­ÉýÖÁÊý°ÙÍò £¬£¬£¬£¬£¬²¢ÇÒÔì³É¼«´óµÄÆÆË𣻣»£»ÍøÂç·¸·¨·Ö×ÓÕýÔÚʹÃô¸ÐÊý¾ÝÎäÆ÷»¯ £¬£¬£¬£¬£¬ÒÔÔöÌí¶ÔÀÕË÷Èí¼þÊܺ¦ÕßµÄѹÁ¦£»£»£»eCrimeÉú̬ϵͳһֱÉú³¤ £¬£¬£¬£¬£¬±äµÃ³ÉÊìºÍרҵ»¯Ë®Æ½Ò»Ö±Ìá¸ß£»£»£»ÔÚBGHÖ®Íâ £¬£¬£¬£¬£¬Õë¶ÔÈ«Çò½ðÈÚ»ú¹¹µÄeCrime»î¶¯ÓÐËùÔöÌí£»£»£»³¯ÏòÎÞ¶ñÒâÈí¼þÕ½ÂÔµÄÇ÷ÊÆÕýÔÚ¼ÓËÙ£»£»£»¹ú¼Ò×ÊÖúµÄÓÐÕë¶ÔÐÔµÄÈëÇֻ¼ÌÐøÕë¶Ô֪ʶ²úȨ/¾ºÕùÇ鱨 £¬£¬£¬£¬£¬Ôö½øÉçÇøÄÚ²¿µÄÆÆËé £¬£¬£¬£¬£¬²¢ÊӲ쵽ÁËÓëÏȽøeCrime¹¥»÷ÕßµÄÏàÖú¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.crowdstrike.com/resources/reports/2020-crowdstrike-global-threat-report/


4¡¢Ó¢¹úÊý¾Ýî¿Ïµ»ú¹¹¶Ô¹úÌ©º½¿Õ´¦ÒÔ50ÍòÓ¢°÷·£¿£¿î


¿­Ðý¹ú¼ÊÓÎÏ·(Öйú)¹Ù·½ÍøÕ¾


Ó¢¹úÐÅϢרԱ°ì¹«ÊÒÒò2018Äê940ÍòÂÿÍÊý¾Ýй¶ÊÂÎñ¶Ô¹úÌ©º½¿Õ¹«Ë¾´¦ÒÔ50ÍòÓ¢°÷µÄ·£¿£¿î¡£¡£¡£¡£¡£¸Ã¹¥»÷ÒÉËÆ±¬·¢ÔÚ2018Äê3ÔÂ·Ý £¬£¬£¬£¬£¬²¢ÓÚ5Ô·ݻñµÃÈ·ÈÏ £¬£¬£¬£¬£¬Æäʱ¹úÌ©º½¿ÕµÄÊý¾Ý¿âÔâµ½Á˱©Á¦ÆÆ½â¹¥»÷¡£¡£¡£¡£¡£ICOÊÓ²ì³Æ¹úÌ©µÄϵͳÊܵ½ÁËÊý¾ÝÍøÂçÀà¶ñÒâÈí¼þµÄÓ°Ïì £¬£¬£¬£¬£¬²¢·¢Ã÷¹úÌ©ÔÚÇå¾²ÐÔ·½ÃæµÄһЩȱ·¦ £¬£¬£¬£¬£¬°üÀ¨²»ÊÜÃÜÂë±£»£»£»¤µÄ±¸·ÝÎļþ¡¢Î´´ò²¹¶¡µÄWebЧÀÍÆ÷¡¢ÒѹýʱµÄ²Ù×÷ϵͳºÍȱ·¦·À²¡¶¾±£»£»£»¤µÈ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.theregister.co.uk/2020/03/04/ico_fines_cathay_pacific_500000/


5¡¢°Ä´óÀûÑÇACSCÐû²¼CMSϵͳÇå¾²Ö¸ÄÏ


¿­Ðý¹ú¼ÊÓÎÏ·(Öйú)¹Ù·½ÍøÕ¾


°Ä´óÀûÑÇÍøÂçÇå¾²ÖÐÐÄ£¨ACSC£©Ðû²¼Ò»·ÝÓÃÓÚ±£»£»£»¤CMSϵͳµÄÍøÂçÇå¾²Ö¸ÄÏ £¬£¬£¬£¬£¬¸ÃÖ¸ÄϸÅÊöÁËÔõÑùÔÚwebЧÀÍÆ÷ÉÏʶ±ðºÍ×îС»¯Ç±ÔÚΣº¦µÄÕ½ÂÔ £¬£¬£¬£¬£¬ÆäÄ¿µÄÊÜÖÚÊÇÈÏÕæÊ¹ÓÃCMS¿ª·¢ºÍ±£»£»£»¤ÍøÕ¾»òWebÓ¦ÓóÌÐòµÄÈË¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔʹÓÃ×Ô¶¯»¯¹¤¾ßɨÃèInternetÉϵÄÇå¾²Îó²î¡£¡£¡£¡£¡£Ò»µ©CMS±»ÈëÇÖ £¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓÃÆäȨÏÞÀ´£º»ñµÃWebÓ¦ÓóÌÐòµÄÑéÖ¤ÇøÓòºÍÌØÈ¨ÇøÓòµÄ»á¼ûȨÏÞ£»£»£»ÉÏ´«¶ñÒâÈí¼þÀ´»ñµÃÔ¶³Ì»á¼û £¬£¬£¬£¬£¬ÀýÈçÉÏ´«Web Shell»òRAT£»£»£»ÔÚÕýµ±ÍøÒ³ÉÏ×¢Èë¶ñÒâÄÚÈÝ¡£¡£¡£¡£¡£¹¥»÷Õß»¹¿ÉÒÔ½«ÊÜѬȾµÄWebЧÀÍÆ÷ÓÃ×÷¡°Ë®¿Ó¡±¹¥»÷µÄÒ»²¿·Ö £¬£¬£¬£¬£¬»òÓÃ×÷C&CµÄ»ù´¡ÉèÊ©¡£¡£¡£¡£¡£ACSC½¨Òé½ÓÄɵĻº½â²½·¥°üÀ¨£ºÊ¹ÓÃCMSÍйÜЧÀÍ£»£»£»ÓÅÒìµÄ²¹¶¡ÖÎÀí£»£»£»Îó²îÆÀ¹À£»£»£»ÕË»§ÖÎÀí£»£»£»ÔöÇ¿CMS×°ÖõÄÇå¾²ÐÔ¿ØÖƲ½·¥£»£»£»¼à¿ØCMS×°ÖÃÉ϶ÔÍйÜÄÚÈݵÄδÊÚȨ¸ü¸ÄµÈ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.cyber.gov.au/publications/securing-content-management-systems