ÐÅÏ¢°²È«Öܱ¨-2021ÄêµÚ48ÖÜ
°ä²¼¹¦·ò 2021-11-29>±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
±¾Öܹ²ÊÕ¼°²È«·ì϶50¸ö£¬£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇDell Networking X-Series firmwareÑéÖ¤ÈÆ¹ý·ì϶£»£»£»£»£»D-Link DWR-932C E1 debug_fcgi OSºÅÁî×¢Èë·ì϶£»£»£»£»£»Commvault CommCell AppStudioUploadHandlerËÁÒâÎļþÉÏ´«·ì϶£»£»£»£»£»HejHome GKW-IC052 IP CameraÓ²±àÂë·ì϶£»£»£»£»£»QNAP QVR²»ÕýÈ·ÑéÖ¤·ì϶¡£¡£¡£¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇRedCurlÍÅ»ï»Ø¹é£¬£¬£¬£¬£¬£¬£¬ÐµĹ¥»÷Ö¸±êÉæ¼°¸÷Ðи÷Òµ£»£»£»£»£»LinuxºóÃÅlinux_avp¿ÉÈÆ¹ýµçÉÌÆ½Ì¨µÄ°²È«¼ì²â£»£»£»£»£»CloudLinux½¨¸´Imunify360ÖеÄPHP·´ÐòÁл¯·ì϶£»£»£»£»£»AppGalleryÖжà¿îÓÎÏ·ÀûÓôæÔÚľÂí£¬£¬£¬£¬£¬£¬£¬ÒÑϰȾ900¶àÍòÉ豸£»£»£»£»£»Kaspersky°ä²¼2021ÄêºÚÎåÆÚ¼äڿƻµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖС£¡£¡£¡£¡£
>³ÁÒª°²È«·ì϶Áбí
1. Dell Networking X-Series firmwareÑéÖ¤ÈÆ¹ý·ì϶
Dell Networking X-Series firmware´æÔÚÑéÖ¤ÈÆ¹ý·ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬¿É½Ù³Ö»á»°£¬£¬£¬£¬£¬£¬£¬Í¨¹ýαÔì»á»°id½Ó¼ûweb·þÎñÆ÷¡£¡£¡£¡£¡£
https://www.dell.com/support/kbdoc/en-us/000193230/dsa-2021-191-dell-networking-x-series-security-update-for-multiple-security-vulnerabilities
2. D-Link DWR-932C E1 debug_fcgi OSºÅÁî×¢Èë·ì϶
D-Link DWR-932C E1 debug_fcgi´æÔÚÊäÈëÑéÖ¤·ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£
https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10246
3. Commvault CommCell AppStudioUploadHandlerËÁÒâÎļþÉÏ´«·ì϶
Commvault CommCell AppStudioUploadHandlerÀà´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÉÏ´«Îļþ²¢Ö´ÐС£¡£¡£¡£¡£
https://www.zerodayinitiative.com/advisories/ZDI-21-1332/
4. HejHome GKW-IC052 IP CameraÓ²±àÂë·ì϶
HejHome GKW-IC052 IP Camera´æÔÚÓ²±àÂë·ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬¿É½ÚÔìϵͳδÊÚȨ½øÐвÙ×÷¡£¡£¡£¡£¡£
https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=36359
5. QNAP QVR²»ÕýÈ·ÑéÖ¤·ì϶
NAP QVR´æÔÚ²»ÕýÈ·ÑéÖ¤·ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬¿ÉδÊÚȨ½Ó¼ûϵͳ¡£¡£¡£¡£¡£
https://www.qnap.com.cn/en/security-advisory/qsa-21-52
>³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢RedCurlÍÅ»ï»Ø¹é£¬£¬£¬£¬£¬£¬£¬ÐµĹ¥»÷Ö¸±êÉæ¼°¸÷Ðи÷Òµ
Group-IBÔÚ11ÔÂ18ÈÕÅû¶Á˺ڿÍÍÅ»ïRedCurlµÄл¡£¡£¡£¡£¡£ÍøÂç¼äµýºÚ¿Í×éÖ¯RedCurlÔÚ2018ÄêÖÁ2020ÄêÆÚ¼ä£¬£¬£¬£¬£¬£¬£¬ÌáÒéÁËÖÁÉÙ26´Î¹¥»÷£¬£¬£¬£¬£¬£¬£¬Éæ¼°Ó¢¹ú¡¢µÂ¹ú¡¢¼ÓÄôó¡¢Å²Íþ¡¢¶íÂÞ˹ºÍÎÚ¿ËÀ¼µÈµØÓòµÄ¹¹Öþ¡¢½ðÈÚ¡¢Õ÷ѯ¡¢ÁãÊÛ¡¢±£ÏÕºÍ˾·¨ÐÐÒµµÄ¹«Ë¾¡£¡£¡£¡£¡£¸ÃÍÅ»ïÔÚÖжÏ7¸öÔºó¾íÍÁ³ÁÀ´£¬£¬£¬£¬£¬£¬£¬×Ô2021ËêÊ×ÒÔÀ´Õë¶Ô4¼Ò¹«Ë¾ÌáÒéÁËÐµĹ¥»÷£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬¶íÂÞ˹×î´óµÄÅú·¢É̵ꡣ¡£¡£¡£¡£Group-IB³Æ£¬£¬£¬£¬£¬£¬£¬RedCurlÔÚÿ´Î¹¥»÷ÖгÇÊÐʹÓÃÆä×Ô½ç˵¶ñÒâÈí¼þÈÆ¹ý¼ì²â¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.group-ib.com/media/red-curl-threat-report/
2¡¢LinuxºóÃÅlinux_avp¿ÉÈÆ¹ýµçÉÌÆ½Ì¨µÄ°²È«¼ì²â
SansecÍþв×êÑÐÍŶÓÔÚ11ÔÂ18µÄ×îÐÂ×êÑз¢ÏÖÁËLinuxºóÃÅlinux_avp¡£¡£¡£¡£¡£×êÑÐÈËÔ±³Æ£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÔÚµçÉÌÍøÕ¾×¢ÈëÐÅÓþ¿¨ÇÔÈ¡Æ÷ºó£¬£¬£¬£¬£¬£¬£¬»¹»áÔÚ±»ÈëÇֵķþÎñÆ÷ÉÏ×°ÖÃLinuxºóÃÅ¡£¡£¡£¡£¡£linux_avpÒ»µ©Æô¶¯£¬£¬£¬£¬£¬£¬£¬¾ÍÁ¢¼´½«×Ô¼º´Ó´ÅÅÌÖÐɾ³ý£¬£¬£¬£¬£¬£¬£¬¼Ù×°³Éps -ef¹ý³Ì£¬£¬£¬£¬£¬£¬£¬ÓÃÓÚ»ñÈ¡µ±Ç°ÔÚÔËÐеĹý³ÌÁÐ±í²¢ÈÆ¹ý¼ì²â¡£¡£¡£¡£¡£¸ÃÑù±¾ÓÚ10ÔÂ8ÈÕ³õ´ÎÉÏ´«£¬£¬£¬£¬£¬£¬£¬Ä¿Ç°VirusTotalµÄ·´¶ñÒâÈí¼þÒýÇæÈÔδ¼ì²âµ½Ëü¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/hackers-deploy-linux-malware-web-skimmer-on-e-commerce-servers/
3¡¢CloudLinux½¨¸´Imunify360ÖеÄPHP·´ÐòÁл¯·ì϶
Cisco TaloÔÚ11ÔÂ22ÈÕÅû¶ÁËCloudLinuxµÄ²úÆ·Imunify360ÖеÄPHP·´ÐòÁл¯·ì϶¡£¡£¡£¡£¡£¸Ã²úÆ·ÊÇ»ùÓÚLinuxµÄWeb·þÎñÆ÷µÄ°²È«Æ½Ì¨£¬£¬£¬£¬£¬£¬£¬Óû§¿ÉÀûÓÃÆäͨ¹ý¸÷ÀàÅäÖÃÀ´ÊµÊ±±£»£»£»£»£»¤ÍøÕ¾ºÍWeb·þÎñÆ÷µÄ°²È«¡£¡£¡£¡£¡£¸Ã·ì϶(CVE-2021-21956)CVSSÆÀ·ÖΪ8.2£¬£¬£¬£¬£¬£¬£¬´æÔÚÓÚAi-BolitÖ°ÄÜÖУ¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»Í¨¹ý¸Ã·ì϶ÔÚÖ¸±êϵͳÖÐÖ´ÐÐËÁÒâ´úÂ룬£¬£¬£¬£¬£¬£¬»òÆëÈ«½ÚÔì·þÎñÆ÷¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬£¬CloudLinuxÒѽ¨¸´¸Ã·ì϶¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://blog.talosintelligence.com/2021/11/vulnerability-spotlight-php-deserialize.html
4¡¢AppGalleryÖжà¿îÓÎÏ·ÀûÓôæÔÚľÂí£¬£¬£¬£¬£¬£¬£¬ÒÑϰȾ900¶àÍòÉ豸
11ÔÂ23ÈÕ£¬£¬£¬£¬£¬£¬£¬Dr. WebµÄ×êÑÐÈËÔ±Åû¶»ªÎªÀûÓÃÉ̵êAppGalleryÖеÄ190¿îÓÎÏ·ÖдæÔÚľÂíAndroid.Cynos.7.origin£¬£¬£¬£¬£¬£¬£¬ÒÑ×°ÖÃÔ¼9300000´Î¡£¡£¡£¡£¡£¸ÃľÂíÊǶñÒâÈí¼þCynosµÄ±äÌ壬£¬£¬£¬£¬£¬£¬Ö¼ÔÚÍøÂçÓû§µÄÐÅÏ¢¡£¡£¡£¡£¡£ÕâЩÓÎÏ·ÖØÒªÊ¹ÓöíÓï¡¢ÖÐÎĺÍÓ¢Ó£¬£¬£¬£¬£¬£¬ÆäÖÐÓÎÏ·¡°¿ìµã¶ãÆðÀ´¡±µÄÏÂÔØÁ¿¸ß´ï2000000´Î¡£¡£¡£¡£¡£×êÑÐÈËÔ±³Æ£¬£¬£¬£¬£¬£¬£¬¸ÃľÂí¿É·¢ËͺÍÀ¹½Ø¶ÌÐÅ¡¢ÏÂÔØºÍÆô¶¯ÆäËüÄ£¿£¿£¿£¿£¿é£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°ÏÂÔØºÍ×°ÖÃÆäËûÀûÓᣡ£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬£¬»ªÎª¹«Ë¾Òѽ«ÕâЩÓÎϷϼܡ£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/124927/malware/android-cynos-7-origin-trojan-infections.html
5¡¢Kaspersky°ä²¼2021ÄêºÚÎåÆÚ¼äڿƻµÄ·ÖÎö»ã±¨
11ÔÂ22ÈÕ£¬£¬£¬£¬£¬£¬£¬Kaspersky°ä²¼2021ÄêºÚÎåÆÚ¼äڿƻµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£»ã±¨ÖØÒª·ÖÎöÁËÓëÈ«Çò½Ó¼ûÁ¿×î´óµÄÎå¸öÁãÊÛÆ½Ì¨£ºÎÖ¶ûÂê¡¢eBay¡¢ÑÇÂíÑ·¡¢°¢Àï°Í°ÍºÍ Mercado Libre¡£¡£¡£¡£¡£×êÑз¢ÏÖ£¬£¬£¬£¬£¬£¬£¬2021Äêǰ10¸öÔ¼ì²âµ½40584415ÆðÕë¶ÔµçÉÌÆ½Ì¨ÒÔ¼°ÒøÐлú¹¹µÄ´¹µö¹¥»÷£»£»£»£»£»Õë¶Ôµç×ÓÖ§¸¶ÏµÍ³µÄ´¹µö»î¶¯Ôö³¤ÁË208%£»£»£»£»£»10ÔÂ27ÈÕÖÁ11ÔÂ19ÈÕ·¢ÏÖÁË221745·âÓëºÚÎåÓйصÄÓʼþ¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬£¬£¬£¬£¬£¬£¬ÐþÉ«ÐÇÆÚÎå²»½ö¶Ô¹ºÎïÕßÀ´ËµÊdzÁÒªµÄÒ»Ì죬£¬£¬£¬£¬£¬£¬¶Ô¹¥»÷ÕßÀ´ËµÒ²ÊÇÈç´Ë¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securelist.com/black-friday-2021/104915/


¾©¹«Íø°²±¸11010802024551ºÅ