ÐÅÏ¢°²È«Öܱ¨-2019ÄêµÚ24ÖÜ
°ä²¼¹¦·ò 2019-06-24±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
2019Äê6ÔÂ17ÈÕÖÁ23ÈÕ¹²ÊÕ¼°²È«·ì϶43¸ö£¬£¬£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇISC BIND¾ºÕùǰÌá»Ø¾ø·þÎñ·ì϶£»£»£»£»£»£»£»Oracle Fusion Middleware WebLogic Server×é¼þÔ¶³Ì´úÂëÖ´Ðзì϶£»£»£»£»£»£»£» Apache AXIS freemaker´úÂëÖ´Ðзì϶£»£»£»£»£»£»£»Webmin update.cgiËÁÒâºÅÁîÖ´Ðзì϶£»£»£»£»£»£»£»TP-Link TL-WR1043NDδÊÚȨ½Ó¼û·ì϶¡£¡£¡£¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇÃÀ¹ÙÔ±ÈÏ¿ÉÏò¶íÂÞ˹µçÍøÖ²È벡¶¾£¬£¬£¬£¬£¬£¬£¬£¬ÌØÀÊÆÕÅí¡ÃÀýÅѹú£»£»£»£»£»£»£»AMCAÊý¾Ýй¶²¨¼°ÈËÊý³¬¹ý2000Íò£¬£¬£¬£¬£¬£¬£¬£¬5¼Ò¹«Ë¾ÊÜÓ°Ï죻£»£»£»£»£»£»EquifaxÊý¾Ýй¶ӰÏìÃÀ¹ú¶à¸öµ±¾Ö»ú¹¹µÄÉí·ÝÑéÖ¤Á÷³Ì£»£»£»£»£»£»£»Firefox´¹Î£½¨¸´RCE 0day£¨CVE-2019-11707£©£»£»£»£»£»£»£»¼ÓÄôó½ðÈÚ»ú¹¹Desjardinsй¶Լ290Íò»áÔ±µÄÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£
³ÁÒª°²È«·ì϶Áбí
ISC BIND´¦ÖýøÐб¨ÎÄʱ´æÔÚ¾ºÕùǰÌᰲȫ·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬¿É½øÐлؾø·þÎñ¹¥»÷¡£¡£¡£¡£¡£
https://kb.isc.org/docs/cve-2019-6471
2. Oracle Fusion Middleware WebLogic Server×é¼þÔ¶³Ì´úÂëÖ´Ðзì϶
Oracle Fusion Middleware WebLogic Server×é¼þXMLDecoder´æÔÚ·´ÐòÁл¯·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£
https://www.oracle.com/technetwork/security-advisory/alert-cve-2019-2729-5570780.html
3. Apache AXIS freemaker´úÂëÖ´Ðзì϶
Apache AXIS freemaker×é¼þÖÐŲÓÃtemplate.utility.ExecuteÀà´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄHTTP POSTÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬¿ÉÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£
http://axis.apache.org/
4. Webmin update.cgiËÁÒâºÅÁîÖ´Ðзì϶
Webmin update.cgi´¦Öá®data¡¯²ÎÊý´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬Äܹ»rootȨÏÞÖ´ÐÐËÁÒâºÅÁî¡£¡£¡£¡£¡£
https://pentest.com.tr/exploits/Webmin-1910-Package-Updates-Remote-Command-Execution.html
5. TP-Link TL-WR1043NDδÊÚȨ½Ó¼û·ì϶
TP-Link TL-WR1043ND´¦Öà ¡°Authorization¡±´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬¿ÉδÊÚȨ½ÚÔìÉ豸¡£¡£¡£¡£¡£
https://github.com/MalFuzzer/Vulnerability-Research/blob/master/TL-WR1043ND%20V2%20-%20TP-LINK/TL-WR1043ND_PoC.pdf
³ÁÒª°²È«ÊÂÎñ×ÛÊö
±¾µØ¹¦·ò6ÔÂ15ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬¡¶Å¦Ô¼Ê±±¨¡·Ô®ÒýÃÀ¹úÏÖÈκÍǰÈε±¾Ö¹ÙÔ±µÄ»°³Æ£¬£¬£¬£¬£¬£¬£¬£¬ÃÀ¹úÔÚ¼Ó´ó¶Ô¶íÂÞ˹µçÍøµÄÍøÂç¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬¡°ÖÁÉÙ´Ó2012ÄêÆðÍ·£¬£¬£¬£¬£¬£¬£¬£¬ÃÀ¹úÒѽ«¿úËÅ̽²âÆ÷ÖÃÈë¶íÂÞ˹µçÍøµÄ½ÚÔìϵͳ¡£¡£¡£¡£¡£¡±ÉÏÊö¹ÙÔ±°µÊ¾£¬£¬£¬£¬£¬£¬£¬£¬Èç½ñÃÀ¹úµÄÕ½ÊõÒѾ¸ü¶àµØ×ªÏò½ø¹¥£¬£¬£¬£¬£¬£¬£¬£¬²¢ÒÔ¡°Ç°ËùδÓÓ×±µÄÉî¶È½«Ç±ÔڵĶñÒâÈí¼þ°²ÉèÓÚ¶íÂÞ˹ϵͳÄÚ¡£¡£¡£¡£¡£ÃÀ¹úÕþÒª²¢Î´¾Í±¨Â·×÷³ö»ØÓ¦£¬£¬£¬£¬£¬£¬£¬£¬µ«¿´Í걨·µÄÌØÀÊÆÕÈ´¼«¶ÈÄÕÅ£¬£¬£¬£¬£¬£¬£¬£¬ËûËæ¼´ÔÚÍÆÌØÉÏ·¢ÍÆÎÄ»Øí¡£¡£¡£¡£¡£¬£¬£¬£¬£¬£¬£¬£¬³Æ¡¶Å¦Ô¼Ê±±¨¡·µÄ±¨Â·ÊǼٵ쬣¬£¬£¬£¬£¬£¬£¬²¢³ÆÆä×ö·¨¡°ÏÕЩÊÇÅѹúÐо¶£¬£¬£¬£¬£¬£¬£¬£¬ÊÇÈËÃñµÄµÐÈË£¡¡±¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.nytimes.com/2019/06/15/us/politics/trump-cyber-russia-grid.html
2¡¢AMCAÊý¾Ýй¶²¨¼°ÈËÊý³¬¹ý2000Íò£¬£¬£¬£¬£¬£¬£¬£¬5¼Ò¹«Ë¾ÊÜÓ°Ïì
ÃÀ¹úÒ½ÁÆÆóÒµÕ˵¥·þÎñÉÌAMCAµÄÊý¾Ýй¶ÊÂÎñÏÖÒѲ¨¼°³¬¹ý2000Íò»¼Õß¡£¡£¡£¡£¡£Ð¹Â¶µÄÊý¾ÝÊôÓÚÃÀ¹ú¸÷¸öÁÙ´²ºÍѪҺ¼ì²â³¢ÊÔÊҵϼÕߣ¬£¬£¬£¬£¬£¬£¬£¬Ô̺¬ËûÃǵÄÐÕÃû¡¢¼Òͥסַ¡¢µç»°ºÅÂë¡¢µ®ÉúÈÕÆÚ¡¢Éç»á°²È«ºÅÂë¡¢Ö§¸¶¿¨¾ßÌåÐÅÏ¢ºÍÒøÐÐÕË»§ÐÅÏ¢µÈ¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄ³¢ÊÔÊÒÔ̺¬Quest Diagnostics£¨²¨¼°1190Íò»¼Õߣ©¡¢LabCorp£¨770Íò»¼Õߣ©¡¢BioReference³¢ÊÔÊÒ£¨Opko Health×Ó¹«Ë¾£¬£¬£¬£¬£¬£¬£¬£¬422600Ãû»¼Õߣ©¡¢Carecentrix£¨50ÍòÃû»¼Õߣ©ºÍSunrise Laboratories£¨Î´¹«¿ª»¼ÕßÊý£©¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/amca-data-breach-has-now-gone-over-the-20-million-mark/
3¡¢EquifaxÊý¾Ýй¶ӰÏìÃÀ¹ú¶à¸öµ±¾Ö»ú¹¹µÄÉí·ÝÑéÖ¤Á÷³Ì
ÃÀ¹úµ±¾ÖÎÊÔð°ì¹«ÊÒ£¨GAO£©µÄл㱨ָ³ö£¬£¬£¬£¬£¬£¬£¬£¬2017ÄêEquifaxµÄÊý¾Ýй¶ÊÂÎñÓ°ÏìÁ˶à¸öµ±¾Ö»ú¹¹µÄÔÚÏßÉí·ÝÑéÖ¤Á÷³Ì¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄ»ú¹¹Ô̺¬Ò½ÁƱ£ÏÕºÍÒ½ÁƲ¹Öú·þÎñÖÐÐÄ£¨CMS£©¡¢Éç»á±£ÏÕÖÎÀí¾Ö£¨SSA£©¡¢ÃÀ¹úÓÊÕþ·þÎñ£¨USPS£©ºÍÍËÒÛÎäÊ¿ÊÂÎñ²¿£¨VA£©¡£¡£¡£¡£¡£ÃÀ¹ú¹«ÃñÔÚÕâЩµ±¾Ö»ú¹¹¹ÙÍøÉêÇ븣Àûʱ£¬£¬£¬£¬£¬£¬£¬£¬ÒÀÀµÓÚEquifaxµÈÐÅÓþ»ã±¨»ú¹¹£¨CRA£©ÌṩµÄÊý¾Ý×÷ΪÉêÇëÈËÉí·ÝµÄÖ¤Ã÷£¬£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚºÚ¿ÍÒ²Õ¼ÓÐÕâЩÊý¾Ý£¬£¬£¬£¬£¬£¬£¬£¬Ê¹µÃÕâÒ»¹ý³Ì²»ÔÙ¿ÉÐÅ¡£¡£¡£¡£¡£2017ÄêÃÀ¹ú¹ú¶È³ß¶ÈÓë¼¼Êõ×êÑÐÔº£¨NIST£©½¨ÒéÓÃÆäËû½â¾ö¹æ»®´úÌæ»ùÓÚCRAµÄÔÚÏßÉí·ÝÖ¤Ã÷£¬£¬£¬£¬£¬£¬£¬£¬µ«GAO·¢ÏÖÉÏÊö»ú¹¹ÈÔÔÚʹÓþɵÄCRAÊý¾Ý¿â½øÐÐÔÚÏßÉí·Ý¼ø±ðÑéÖ¤¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/equifax-breach-impacted-the-online-id-verification-process-at-many-us-govt-agencies/
4¡¢Firefox´¹Î£½¨¸´RCE 0day£¨CVE-2019-11707£©
Mozilla°ä²¼Firefox 67.0.3ºÍFirefox ESR 60.7.1£¬£¬£¬£¬£¬£¬£¬£¬ÓÃÓÚ´¹Î£½¨¸´¿Éµ¼ÖÂRCEµÄ0day£¨CVE-2019-11707£©¡£¡£¡£¡£¡£¸Ã·ì϶ÓÉGoogle Project ZeroÍŶӷ¢ÏÖ²¢»ã±¨£¬£¬£¬£¬£¬£¬£¬£¬ÊÇÒ»¸öÀàÐÍ»ìºÏ·ì϶£¬£¬£¬£¬£¬£¬£¬£¬·ì϶±íÊöΪ£ºÓÉÓÚArray.popÖеÄÎÊÌ⣬£¬£¬£¬£¬£¬£¬£¬²Ù×÷JavaScript¶ÔÏóʱ¿ÉÄܻᴥ·¢·ì϶£¬£¬£¬£¬£¬£¬£¬£¬µ¼Ö¿ÉÀûÓõıÀÀ£¡£¡£¡£¡£¡£¸Ã·ì϶ÒÑÔÚÒ°±í±»ÀûÓ㬣¬£¬£¬£¬£¬£¬£¬½¨ÒéÓû§¾¡¿ì¸üС£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/mozilla-firefox-6703-patches-actively-exploited-zero-day/
5¡¢¼ÓÄôó½ðÈÚ»ú¹¹Desjardinsй¶Լ290Íò»áÔ±µÄÃô¸ÐÐÅÏ¢
DesjardinsÊDZ±ÃÀµØÓò×î´óµÄÐÅÓþÉ磬£¬£¬£¬£¬£¬£¬£¬Ò²ÊǼÓÄôó×î´óµÄºÏ×÷½ðÈÚ¼¯ÍÅ¡£¡£¡£¡£¡£Æ¾¾Ý¸Ã¹«Ë¾µÄÐÂΟ壬£¬£¬£¬£¬£¬£¬£¬Ô¼290Íò»áÔ±µÄÃô¸ÐÐÅÏ¢ÔÚÔ±¹¤Î´¾ÊÚȨÏò¹«Ë¾±í²¿ÈËÔ±Åû¶ºóй¶£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬270ÍòÃûÓ×ÎÒ»áÔ±ºÍ17.3ÍòÆóÒµ»áÔ±¡£¡£¡£¡£¡£DesjardinsÓÚ2019Äê6ÔÂ14ÈÕ·¢ÏÖй¶ÊÂÎñ£¬£¬£¬£¬£¬£¬£¬£¬Ð¹Â¶µÄÐÅÏ¢Ô̺¬Ó×ÎÒ»áÔ±µÄÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢Éç»á±£ÏÕºÅÂë¡¢µØÖ·¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØÖ·ÒÔ¼°ÒøÐкÍDesjardins²úÆ·µÄ¾ßÌåÐÅÏ¢£»£»£»£»£»£»£»ÆóÒµ»áÔ±µÄ¹«Ë¾Ãû³Æ¡¢µØÖ·¡¢µç»°ºÅÂë¡¢ËùÓÐÕßÐÕÃûºÍAcc¨¨sDAffairesÕÊ»§Ãû³ÆÒÔ¼°ÓëAcc¨¨sDAffairesÕÊ»§ÓйصÄһЩÓ×ÎÒÐÅÏ¢¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/desjardins-group-data-leak-exposes-info-of-29-million-members/


¾©¹«Íø°²±¸11010802024551ºÅ