ÐÅÏ¢°²È«Öܱ¨-2021ÄêµÚ5ÖÜ

°ä²¼¹¦·ò 2021-02-01

> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2021Äê01ÔÂ25ÈÕÖÁ01ÔÂ31ÈÕ¹²ÊÕ¼°²È«·ì϶59¸ö£¬£¬£¬ £¬£¬ÖµµÃ¹Ø×¢µÄÊÇGoogle AndroidÔËÐÐʱCVE-2020-0267´úÂëÖ´Ðзì϶£»£» £»£»£»Bosch FSM-2500 serverÃÜÂëй¶·ì϶£»£» £»£»£»Rust SmallVec::insert_many¶ÑÒç¶Âí½Å£»£» £»£»£»SonicWall SSL-VPN User-AgentÔ¶³ÌºÅÁîÖ´Ðзì϶£»£» £»£»£»Mozilla Firefox CVE-2021-23964ÄÚ´æ·ÛËé´úÂëÖ´Ðзì϶¡£¡£¡£¡£¡£ ¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇSonicWallÖÒ¸æÀûÓÃÆäVPN²úÆ·ÖÐ0dayµÄ¹¥»÷»î¶¯£»£» £»£»£»ºÚ¿Í¹«¿ª¼ÓÃÜÇ®±ÒÂòÂôËùBuyucoinÓû§µÄÊý¾Ý£»£» £»£»£»Apple°²È«¸üУ¬£¬£¬ £¬£¬½¨¸´iOSÖÐ3¸öÒѱ»ÔÚÒ°ÀûÓõÄ0day£»£» £»£»£»Sudo·ì϶BaronSameditÎÞÐèÃÜÂë¿ÉÌáȨÖÁrootȨÏÞ£»£» £»£»£»È«Çò·¨Âɲ¿ÃŽáºÏÆÆ»ñEmotet½©Ê¬ÍøÂçµÄ»ù´¡ÉèÊ©¡£¡£¡£¡£¡£ ¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬ £¬£¬±¾Öܰ²È«ÍþвΪÖС£¡£¡£¡£¡£ ¡£


> ³ÁÒª°²È«·ì϶Áбí


1.Google AndroidÔËÐÐʱCVE-2020-0267´úÂëÖ´Ðзì϶


Google AndroidÔËÐÐʱ´æÔÚ°²È«·ì϶£¬£¬£¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬ £¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£» £»£»£»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£ ¡£

https://source.android.com/security/bulletin/android-11


2.Bosch FSM-2500 serverÃÜÂëй¶·ì϶


Bosch FSM-2500 serverʹÓõÄÃÜÂë¹þÏ£²»¹»×³Êµ£¬£¬£¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬ £¬£¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£ ¡£

https://psirt.bosch.com/security-advisories/BOSCH-SA-332072-BT.html


3.Rust SmallVec::insert_many¶ÑÒç¶Âí½Å


Rust SmallVec::insert_many´æÔÚ¶ÑÒç¶Âí½Å£¬£¬£¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬ £¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£» £»£»£»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£ ¡£

https://github.com/servo/rust-smallvec/issues/252


4.SonicWall SSL-VPN User-AgentÔ¶³ÌºÅÁîÖ´Ðзì϶


Sonicwall ssl-vpn CGI·¨Ê½´¦ÖôæÔÚÂß¼­·ì϶£¬£¬£¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄUser-AgentÒªÇ󣬣¬£¬ £¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£ ¡£

https://darrenmartyn.ie/2021/01/24/visualdoor-sonicwall-ssl-vpn-exploit/


5.Mozilla Firefox CVE-2021-23964ÄÚ´æ·ÛËé´úÂëÖ´Ðзì϶


Mozilla Firefox´¦ÖÃWEBÒ³´æÔÚÄÚ´æ·ÛËé·ì϶£¬£¬£¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶¹¹½¨¶ñÒâWEBÒ³£¬£¬£¬ £¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬ £¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£» £»£»£»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£ ¡£

https://www.auscert.org.au/bulletins/ESB-2021.0291/


> ³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢SonicWallÖÒ¸æÀûÓÃÆäVPN²úÆ·ÖÐ0dayµÄ¹¥»÷»î¶¯


1.jpg


°²È«³§ÉÌSonicWall°ä²¼´¹Î£Í¨Öª£¬£¬£¬ £¬£¬ÖÒ¸æÀûÓÃÆäVPN²úÆ·ÖÐ0dayµÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£ ¡£¸Ã·ì϶λÓÚSecure Mobile Access£¨SMA£©VPNÉ豸¼°NetExtender VPN¿Í»§¶ËÖУ¬£¬£¬ £¬£¬¿É±»ÓÃÀ´¶Ô¹«Ë¾µÄÄÚ²¿ÏµÍ³½øÐÐЭͬ¹¥»÷¡£¡£¡£¡£¡£ ¡£SonicWallÉÐδ°ä²¼Óйظ÷ì϶µÄ¾ßÌåÐÅÏ¢£¬£¬£¬ £¬£¬µ«Æ¾¾Ý»º½â´ëÊ©Åжϣ¬£¬£¬ £¬£¬Æä¿ÉÄÜÊÇÊÇÉí·ÝÑéÖ¤·ì϶£¬£¬£¬ £¬£¬¿É±»ÓÃÀ´Ôڿɹ«¿ª½Ó¼ûµÄÉ豸ÉÏÔ¶³ÌÀûÓᣡ£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/sonicwall-firewall-maker-hacked-using-zero-day-in-its-vpn-device/


2¡¢ºÚ¿Í¹«¿ª¼ÓÃÜÇ®±ÒÂòÂôËùBuyucoinÓû§µÄÊý¾Ý


2.png


ShinyHuntersÔÚ°µÍøÉϹ«¿ªÓ¡¶È¼ÓÃÜÇ®±ÒÂòÂôËùBuyucoinÓû§µÄÊý¾Ý¡£¡£¡£¡£¡£ ¡£Õâ´Î×ܹ²Ð¹Â¶ÁËÈý¸öMongoDBÊý¾Ý¿â£¬£¬£¬ £¬£¬ÕâЩÊý¾Ý¿â¾ùÒÔ¹¦·ò¶¨Ãû£¬£¬£¬ £¬£¬±ðÀëΪ2020Äê6ÔÂ1ÈÕ¡¢2020Äê7ÔÂ14ÈÕºÍ2020Äê9ÔÂ5ÈÕ¡£¡£¡£¡£¡£ ¡£Ð¹Â¶Êý¾ÝÔ̺¬Óû§¼Í¼¡¢¼ÓÃÜÇ®±ÒÒµÎñÂòÂô¡¢Óû§Á´½ÓµÄÒøÐÐÕÊ»§ÐÅÏ¢ÒÔ¼°ÂòÂôËùÄÚ²¿Ê¹ÓÃµÄÆäËû±í£¬£¬£¬ £¬£¬ÆäÖÐÓû§¼Í¼±í´æ´¢ÁË161487¸ö³ÉÔ±µÄÐÅÏ¢£¬£¬£¬ £¬£¬Ô̺¬µç×ÓÓʼþµØÖ·¡¢¹ú¶È/µØÓò¡¢¹þÏ£ÃÜÂë¡¢ÊÖ»úºÅÂëºÍGoogleµÇ¼ÁîÅÆµÈ¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/data-breach-at-buyucoin-crypto-exchange-leaks-user-info-trades/


3¡¢Apple°²È«¸üУ¬£¬£¬ £¬£¬½¨¸´iOSÖÐ3¸öÒѱ»ÔÚÒ°ÀûÓõÄ0day


3.png


Apple°ä²¼ÁËÕë¶ÔiOSµÄ°²È«¸üУ¬£¬£¬ £¬£¬½¨¸´ÁË3¸öÒѱ»ÔÚÒ°ÀûÓõÄ0day¡£¡£¡£¡£¡£ ¡£µÚÒ»¸öΪӰÏìiOS²Ù×÷ϵͳÄں˵ľºÕùǰÌá·ì϶£¨CVE-2021-1782£©£¬£¬£¬ £¬£¬ËüÄܹ»Ê¹¹¥»÷ÕßÌáÉýÆä¹¥»÷´úÂëµÄȨÏÞ¡£¡£¡£¡£¡£ ¡£Áí±íÁ½¸öΪӰÏìWebKitä¯ÀÀÆ÷ÒýÇæµÄÂß¼­·ì϶£¨CVE-2021-1870ºÍCVE-2021-1871£©£¬£¬£¬ £¬£¬¿ÉÔÊÐíÔ¶³Ì¹¥»÷ÕßÔÚÓû§µÄSafariä¯ÀÀÆ÷ÖÐÖ´ÐжñÒâ´úÂë¡£¡£¡£¡£¡£ ¡£ÔÚ·ì϶ÀûÓÃÁ´ÖУ¬£¬£¬ £¬£¬Óû§±»ÒýÓÕµ½Ò»¸ö¶ñÒâÍøÕ¾£¬£¬£¬ £¬£¬¸ÃÍøÕ¾ÀûÓÃWebKit·ì϶ÔËÐдúÂ룬£¬£¬ £¬£¬ËæºóÉý¼¶ÆäÔËÐÐϵͳ¼¶´úÂëµÄȨÏÞ£¬£¬£¬ £¬£¬Î£¼°²Ù×÷ϵͳ¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/apple-fixes-another-three-ios-zero-days-exploited-in-the-wild/


4¡¢Sudo·ì϶BaronSameditÎÞÐèÃÜÂë¿ÉÌáȨÖÁrootȨÏÞ


4.png


°²È«É󼯹«Ë¾Qualys·¢ÏÖSudo·ì϶BaronSameditÎÞÐèÃÜÂë¿ÉÌáȨÖÁrootȨÏÞ£¬£¬£¬ £¬£¬ÒÑÓнüÊ®ÄêµÄº¹Çà¡£¡£¡£¡£¡£ ¡£¸Ã·ì϶ÊÇÓÉÓÚsudoÃýÎóµØÔÚ²ÎÊýÖÐתÒåÁË·´Ð±¸Üµ¼Ö»ùÓڶѵĻº³åÇøÒç¶Âí½Å£¬£¬£¬ £¬£¬±»×·×ÙΪCVE-2021-3156£¬£¬£¬ £¬£¬ÔÊÐíÈκα¾µØÓû§£¨ÎÞÂÛÊÇ·ñÔÚsudoersÎļþÖУ©ÎÞÐè½øÐÐÉí·ÝÑéÖ¤»ñµÃrootȨÏÞ¡£¡£¡£¡£¡£ ¡£ÔÚ´ÓǰÁ½ÄêÖз¢ÏÖÁËÁí±íÁ½¸öSudo·ì϶£¨CVE-2019-14287ºÍCVE-2019-18634£©£¬£¬£¬ £¬£¬µ«ÊÇÕâ´ÎÅû¶µÄ·ì϶ÊÇÈý¸öÖÐ×îΣÏÕµÄÒ»¸ö¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/10-years-old-sudo-bug-lets-linux-users-gain-root-level-access/


5¡¢È«Çò·¨Âɲ¿ÃŽáºÏÆÆ»ñEmotet½©Ê¬ÍøÂçµÄ»ù´¡ÉèÊ©


5.png


ÓÉÅ·ÖÞÐ̾¯×éÖ¯£¨Europol£©¸¨µ¼µÄÈ«Çò·¨ÂÉÐж¯ÆÆ»ñÁ˳ÛÃû½©Ê¬ÍøÂçEmotetµÄ»ù´¡ÉèÊ©¡£¡£¡£¡£¡£ ¡£EmotetÖÁÉÙ´Ó2014ÄêÆðÍ·»îÔ¾£¬£¬£¬ £¬£¬ÓëºÚ¿Í×éÖ¯TA542ÓйØ¡£¡£¡£¡£¡£ ¡£Europol³Æ£¬£¬£¬ £¬£¬Õâ´ÎÐж¯±»³ÆÎªOperation Ladybird£¬£¬£¬ £¬£¬ÓɺÉÀ¼¡¢µÂ¹ú¡¢ÃÀ¹ú¡¢Ó¢¹ú¡¢·¨¹ú¡¢Á¢ÌÕÍð¡¢¼ÓÄôóºÍÎÚ¿ËÀ¼µ±¾Ö¹²Í¬ºÏ×÷£¬£¬£¬ £¬£¬·ÛËé²¢ÊÕÊÜÁËλÓÚ90¶à¸ö¹ú¶ÈµÄEmotetµÄC&C£¬£¬£¬ £¬£¬²¢¿ÛÁôÁ˶àÁ½ÃûÍøÂç·¸×ï·Ö×Ó¡£¡£¡£¡£¡£ ¡£¾ÝºÉÀ¼¾¯·½³Æ£¬£¬£¬ £¬£¬Emotet×ܼÆÔì³ÉÁËÊýÒÚÃÀÔªµÄËðʧ£¬£¬£¬ £¬£¬¶øÎÚ¿ËÀ¼·¨Âɲ¿ÃÅËðʧ¶î¹À¼ÆÎª25ÒÚÃÀÔª¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/113933/cyber-crime/emotet-global-takedown.html