ÐÅÏ¢°²È«Öܱ¨-2019ÄêµÚ19ÖÜ

°ä²¼¹¦·ò 2019-05-13

±¾Öܰ²È«Ì¬ÊÆ×ÛÊö



2019Äê5ÔÂ6ÈÕÖÁ12ÈÕ¹²ÊÕ¼°²È«·ì϶44¸ö£¬£¬£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇAlpine Linux Docker CVE-2019-5021Ó²±àÂëÆ¾Ö¤ÑéÖ¤ÈÆ¹ý·ì϶£»£»£»£»£» £»£»NGINX njs¶Ñ»º³åÇøÒç¶Âí½Å; Hisilicon HI3516 hisilicon streaming server CVE-2019-11560»º³åÇøÒç¶Âí½Å£»£»£»£»£» £»£»Android libpacÀàÐÍ»ìºÏ´úÂëÖ´Ðзì϶£»£»£»£»£» £»£»CyberArk Software Enterprise Password Vault XXE×¢Èë·ì϶ ¡£¡£¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇÃÀ¹úÄÜÔ´²¿°ä²¼2019ÄêQ1µçÁ¦ÍøÂ紹ΣÇé¿öºÍ×ÌÈŻ㱨£»£»£»£»£» £»£»Watertown Daily TimesÔâµ½ÀÕË÷Èí¼þRyuk¹¥»÷£»£»£»£»£» £»£»AIHS¹«Ë¾²¿ÃÅ»¼Õß¼°¹©¸øÉ̵ÄÃô¸ÐÐÅϢй¶£»£»£»£»£» £»£»Verizon°ä²¼2019ÄêÊý¾Ýй¶µ÷²é»ã±¨£»£»£»£»£» £»£»Freedom MobileÒâ±íй¶½ü500ÍòÌõÓû§¼Í¼ ¡£¡£¡£¡£¡£¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖÐ ¡£¡£¡£¡£¡£¡£


³ÁÒª°²È«·ì϶Áбí



1. Alpine Linux Docker CVE-2019-5021Ó²±àÂëÆ¾Ö¤ÑéÖ¤ÈÆ¹ý·ì϶
Alpine Linux Docker´æÔÚµÄrootÃÜÂëΪNULL£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬Î´ÊÚȨÌáȨ½Ó¼û ¡£¡£¡£¡£¡£¡£
https://www.alpinelinux.org/posts/Docker-image-vulnerability-CVE-2019-5021.html

2. NGINX njs¶Ñ»º³åÇøÒç¶Âí½Å
NGINX njs Array.prototype.push´æÔÚ¶ÑÒç¶Âí½Å£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£» £»£»òÖ´ÐÐËÁÒâ´úÂë ¡£¡£¡£¡£¡£¡£
https://github.com/nginx/njs/commit/b0f23dbc4d4713f65470272768ef79b7cb47db78

3. Hisilicon HI3516 hisilicon streaming server CVE-2019-11560»º³åÇøÒç¶Âí½Å
Hisilicon HI3516 hisilicon streaming server´æÔÚ»º³åÇøÒç¶Âí½Å£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£» £»£»òÖ´ÐÐËÁÒâ´úÂë ¡£¡£¡£¡£¡£¡£
https://gist.github.com/vulnfan1337/e95c2dba75ad93a1a325c6ace950eba9

4. Android libpacÀàÐÍ»ìºÏ´úÂëÖ´Ðзì϶
Android libpac´æÔÚÀàÐÍ»ìºÏ·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄPACÎļþÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬¿Éʹϵͳ±ÀÀ£»£»£»£»£» £»£»òÖ´ÐÐËÁÒâ´úÂë ¡£¡£¡£¡£¡£¡£
https://source.android.com/security/bulletin/2019-05-01

5. CyberArk Software Enterprise Password Vault XXE×¢Èë·ì϶
CyberArk Software Enterprise Password Vault Password Vault Web Access (PVWA) ´æÔÚXML±í²¿ÊµÌå×¢Èë·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬»òÈÆ¹ýÑéÖ¤ ¡£¡£¡£¡£¡£¡£
https://www.octority.com/2019/05/07/cyberark-enterprise-password-vault-xml-external-entity-xxe-injection/


 ³ÁÒª°²È«ÊÂÎñ×ÛÊö



1¡¢ÃÀ¹úÄÜÔ´²¿°ä²¼2019ÄêQ1µçÁ¦ÍøÂ紹ΣÇé¿öºÍ×ÌÈŻ㱨

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

ƾ¾ÝÃÀ¹úÄÜÔ´²¿°ä²¼µÄ2019ÄêµÚÒ»¼¾¶ÈµçÁ¦ÍøÂ紹ΣÇé¿öºÍ×ÌÈŻ㱨£¬£¬£¬£¬£¬£¬£¬£¬3ÔÂ5ÈÕÉÏÎç9:12µ½ÏÂÎç6:57ÆÚ¼ä±±ÃÀµçÍøÔâ·êµ½Ò»¸ö¡°µ¼ÖµçÁ¦ÏµÍ³ÔËÓªÖжϵÄÍøÂçÊÂÎñ¡±£¬£¬£¬£¬£¬£¬£¬£¬ÊÜÓ°ÏìµÄµØÓòÔ̺¬¼ÓÖݵĿ˶÷ÏØºÍÂåɼí¶ÏØ¡¢ÓÌËûÖݵÄÑκþÏØºÍ»³¶íÃ÷ÖݵĿµ¸¥Ë¹ÏØ ¡£¡£¡£¡£¡£¡£Æ¾¾ÝÃÀ¹úÄÜÔ´²¿µÄ½ç˵£¬£¬£¬£¬£¬£¬£¬£¬¡°ÍøÂçÊÂÎñ¡±ÊÇÖ¸¡°Î´ÊÚȨ½Ó¼û¡±µ¼ÖµÄÍøÂçÖжÏ£¬£¬£¬£¬£¬£¬£¬£¬µ«Ã»Óиü¶àÐÅÏ¢Åú×¢¸ÃÊÂÎñÊÇÔ¶³ÌºÚ¿Í¹¥»÷»¹ÊÇÆóÒµÄÚ²¿µÄ¹¥»÷ ¡£¡£¡£¡£¡£¡£´Óº¹ÇàÉÏ¿´£¬£¬£¬£¬£¬£¬£¬£¬±±ÃÀµçÍø´ÓδÔâµ½ÍøÂç¹¥»÷µ¼ÖµķÛËé»òÖжÏ£¬£¬£¬£¬£¬£¬£¬£¬ÈôÊÇʼþÊôʵ£¬£¬£¬£¬£¬£¬£¬£¬ÕâÒ»ÊÂÎñ¿ÉÄܳÉΪº¹ÇàÐÔµÄÊÂÎñ ¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://blog.avast.com/western-us-power-grid-hit-by-cyber-event

2¡¢Watertown Daily TimesÔâµ½ÀÕË÷Èí¼þRyuk¹¥»÷

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Ô¼º²Ñ·±¨Òµ¹«Ë¾Ôâµ½ÀÕË÷Èí¼þRyuk¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬ÆäÄÚ²¿ÓÃÓÚÔÚWatertown¡¢HudsonºÍMassena³ö²ú±¨Ö½µÄÄÚÈݹ²Ïí·þÎñÆ÷Êܵ½Ï°È¾£¬£¬£¬£¬£¬£¬£¬£¬Ô̺¬µç×ÓÓʼþ·þÎñÆ÷ºÍÁªÍøµç»° ¡£¡£¡£¡£¡£¡£Watertown Daily TimesÔÚ4ÔÂ27ÈÕÔâµ½µÚÒ»´Î¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬²¢ÔÚ5ÔÂ2ÈÕÔٴμì²âµ½Ï°È¾ ¡£¡£¡£¡£¡£¡£Ä¿Ç°»¹²»Ã÷ÏÔÕâÊÇÁ½´Î¹¥»÷»¹ÊǵÚÒ»´Î¹¥»÷µÄÒ»Á¬ ¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÔÚÓëÍøÂ簲ȫר¼ÒºÏ×÷ÒÔÈ·¶¨Ï°È¾µÄµ××ÓÔ­Òò²¢É¾³ýÀÕË÷Èí¼þ ¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://cyware.com/news/watertown-daily-times-again-gets-hit-with-ryuk-ransomware-attack-36f62397

3¡¢AIHS¹«Ë¾²¿ÃÅ»¼Õß¼°¹©¸øÉ̵ÄÃô¸ÐÐÅϢй¶

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ÃÀ¹úÓ¡¶È½¡È«Óë·þÎñ¹«Ë¾£¨AIHS£©²úÉúÊý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬£¬£¬£¬£¬Æ¾¾Ý¸Ã¹«Ë¾°ä²¼µÄ֪ͨ£¬£¬£¬£¬£¬£¬£¬£¬Ò»Ãûǰ¹ÍÔ±ÔÚÖ°Ö°ÆÚ¼ä½«²¿ÃÅAIHSµç×ÓÓʼþת·¢µ½ÆäÓ×ÎÒÓÊÏ䣬£¬£¬£¬£¬£¬£¬£¬µ¼Ö²¿ÃÅ»¼Õß¡¢Ô±¹¤¼°¹©¸øÉ̵ÄÃô¸ÐÐÅϢй¶ ¡£¡£¡£¡£¡£¡£ÊÜËðµÄ»¼ÕßÐÅÏ¢Ô̺¬ÐÕÃû¡¢Õ˵¥Ã÷ϸ¡¢Ò½ÁƱ£ÏÕÊý¾Ý¡¢½ÓÊÜAIHS·þÎñµÄÈÕÆÚ¼°Ö§¸¶½ð¶îµÈ£¬£¬£¬£¬£¬£¬£¬£¬Ä¿Ç°Éв»Ã÷ÏÔÊÇ·ñÓл¼ÕßÊý¾Ý±»ÀÄÓà ¡£¡£¡£¡£¡£¡£ÕâÒ»ÊÂÎñ²úÉúÔÚ2ÔÂ26ÈÕÖÁ3ÔÂ6ÈÕÆÚ¼ä ¡£¡£¡£¡£¡£¡£AIHS½«ÎªÊÜÓ°ÏìµÄ»¼ÕßÌṩ12¸öÔµÄÉí·Ý͵ÇÔ±£»£»£»£»£» £»£»¤·þÎñ ¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://cyware.com/news/aihs-reports-data-breach-involving-information-related-to-employees-patients-and-vendors-f823c1cd

4¡¢Verizon°ä²¼2019ÄêÊý¾Ýй¶µ÷²é»ã±¨


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Verizon°ä²¼2019ÄêÊý¾Ýй¶µ÷²é»ã±¨£¨DBIR£©£¬£¬£¬£¬£¬£¬£¬£¬¸Ã»ã±¨·ÖÎöÁË86¸ö¹ú¶È²úÉúµÄ41000¶àÆðÍøÂ簲ȫÊÂÎñºÍ2000¶àÆðÊý¾Ýй¶ÊÂÎñ ¡£¡£¡£¡£¡£¡£¸Ã»ã±¨Ö¸³ö£¬£¬£¬£¬£¬£¬£¬£¬´Ó2018ÄêÆðÍ·ÔÆ´æ´¢ÅäÖÃÃýÎó¡¢BECºÍ֪ʶ²úȨ͵ÇÔ¶¼´¦ÓÚÉÏÉýÇ÷Ïò ¡£¡£¡£¡£¡£¡£ÒÔóÒ×¼äµý»î¶¯Îª¶¯»úµÄÍøÂç¹¥»÷ÓÐËùÔö³¤£¬£¬£¬£¬£¬£¬£¬£¬ÔÚ´ÓǰµÄ12¸öÔÂÀ£¬£¬£¬£¬£¬£¬£¬ÓÐ1/4µÄÍøÂçÈëÇÖÓë¿úËźÍÊý¾ÝÉøÂ©ÓÐ¹Ø ¡£¡£¡£¡£¡£¡£×ÜÌå¶øÑÔ´óÎÞÊýÍøÂç¹¥»÷¶¼ÊÇÒÔ¾­¼ÃÀûÒæ×÷ΪÇý¶¯ ¡£¡£¡£¡£¡£¡£²»ÐÒµÄÊÇ£¬£¬£¬£¬£¬£¬£¬£¬ÓÐÒ»°ëµÄÆóÒµ±ØÒªÆÆ·ÑÊýÔÂÉõÖÁ¸ü³¤µÄ¹¦·òÀ´·¢ÏÖÈëÇÖÐÐΪ ¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://enterprise.verizon.com/resources/reports/2019-data-breach-investigations-report.pdf

5¡¢Freedom MobileÒâ±íй¶½ü500ÍòÌõÓû§¼Í¼


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


¼ÓÄôóµçÐŹ«Ë¾Freedom MobileµÄÒ»¸öÔ̺¬¿Í»§Êý¾ÝµÄElasticSearchÊý¾Ý¿âÒòÅäÖÃÃýÎóÔÚÍøÉ϶³ö£¬£¬£¬£¬£¬£¬£¬£¬µ¼Ö½ü500ÍòÌõ¿Í»§¼Í¼й¶ ¡£¡£¡£¡£¡£¡£Æ¾¾Ý°²È«×êÑÐÔ±Noam RotemºÍRan LocarµÄ·¢ÏÖ£¬£¬£¬£¬£¬£¬£¬£¬¸ÃÊý¾Ý¿âÊôÓÚFreedom MobileµÄµÚÈý·½·þÎñÌṩÉÌApptium ¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾½²»°È˰µÊ¾£¬£¬£¬£¬£¬£¬£¬£¬Ð¹Â¶ÊÂÎñÓ°ÏìÁË3ÔÂ25ÈÕÖÁ4ÔÂ15ÈÕÆÚ¼äÔÚ17¸öFreedom Mobile½»Ò×Ìü¿ªÉè»ò¸ü¸ÄÕË»§µÄÓû§£¬£¬£¬£¬£¬£¬£¬£¬Ô¼ÓÐ1.5ÍòÓû§Êܵ½Ó°Ïì ¡£¡£¡£¡£¡£¡£Ð¹Â¶µÄÐÅÏ¢²»½öÔ̺¬Óû§µÄÐÕÃû¡¢ÓÊÏäµÈÓ×ÎÒÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬»¹Ô̺¬ÐÅÓþ¿¨ºÅµÈÖ§¸¶ÐÅÏ¢ ¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://cyware.com/news/freedom-mobile-exposed-almost-5-million-customer-records-due-to-a-misconfigured-database-fddd4855