ÐÅÏ¢Çå¾²Öܱ¨-2019ÄêµÚ24ÖÜ

Ðû²¼Ê±¼ä 2019-06-24

±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö



2019Äê6ÔÂ17ÈÕÖÁ23ÈÕ¹²ÊÕ¼Çå¾²Îó²î43¸ö£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇISC BIND¾ºÕùÌõ¼þ¾Ü¾øÐ§ÀÍÎó²î£»£»£»Oracle Fusion Middleware WebLogic Server×é¼þÔ¶³Ì´úÂëÖ´ÐÐÎó²î£»£»£» Apache AXIS freemaker´úÂëÖ´ÐÐÎó²î£»£»£»Webmin update.cgií§ÒâÏÂÁîÖ´ÐÐÎó²î£»£»£»TP-Link TL-WR1043NDδÊÚȨ»á¼ûÎó²î¡£¡£¡£¡£ ¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇÃÀ¹ÙÔ±ÈÏ¿ÉÏò¶íÂÞ˹µçÍøÖ²È벡¶¾£¬£¬£¬£¬£¬£¬ÌØÀÊÆÕÅ­í¡ÃÀýÅѹú£»£»£»AMCAÊý¾Ýй¶²¨¼°ÈËÊýÁè¼Ý2000Íò£¬£¬£¬£¬£¬£¬5¼Ò¹«Ë¾ÊÜÓ°Ï죻£»£»EquifaxÊý¾Ýй¶ӰÏìÃÀ¹ú¶à¸öÕþ¸®»ú¹¹µÄÉí·ÝÑéÖ¤Á÷³Ì£»£»£»Firefox½ôÆÈÐÞ¸´RCE 0day£¨CVE-2019-11707£©£»£»£»¼ÓÄôó½ðÈÚ»ú¹¹Desjardinsй¶Լ290Íò»áÔ±µÄÃô¸ÐÐÅÏ¢¡£¡£¡£¡£ ¡£


ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£ ¡£


Ö÷ÒªÇå¾²Îó²îÁбí



1. ISC BIND¾ºÕùÌõ¼þ¾Ü¾øÐ§ÀÍÎó²î
ISC BIND´¦Öóͷ£¾ÙÐб¨ÎÄʱ±£´æ¾ºÕùÌõ¼þÇå¾²Îó²î£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬¿É¾ÙÐоܾøÐ§À͹¥»÷¡£¡£¡£¡£ ¡£
https://kb.isc.org/docs/cve-2019-6471

2. Oracle Fusion Middleware WebLogic Server×é¼þÔ¶³Ì´úÂëÖ´ÐÐÎó²î
Oracle Fusion Middleware WebLogic Server×é¼þXMLDecoder±£´æ·´ÐòÁл¯Îó²î£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£ ¡£
https://www.oracle.com/technetwork/security-advisory/alert-cve-2019-2729-5570780.html

3. Apache AXIS freemaker´úÂëÖ´ÐÐÎó²î
Apache AXIS freemaker×é¼þÖÐŲÓÃtemplate.utility.ExecuteÀà±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄHTTP POSTÇëÇ󣬣¬£¬£¬£¬£¬¿ÉÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£ ¡£
http://axis.apache.org/

4. Webmin update.cgií§ÒâÏÂÁîÖ´ÐÐÎó²î
Webmin update.cgi´¦Öóͷ£¡®data¡¯²ÎÊý±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬¿ÉÒÔrootȨÏÞÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£ ¡£
https://pentest.com.tr/exploits/Webmin-1910-Package-Updates-Remote-Command-Execution.html

5. TP-Link TL-WR1043NDδÊÚȨ»á¼ûÎó²î
TP-Link TL-WR1043ND´¦Öóͷ£ ¡°Authorization¡±±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬¿ÉδÊÚȨ¿ØÖÆ×°±¸¡£¡£¡£¡£ ¡£
https://github.com/MalFuzzer/Vulnerability-Research/blob/master/TL-WR1043ND%20V2%20-%20TP-LINK/TL-WR1043ND_PoC.pdf


Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö



1¡¢ÃÀ¹ÙÔ±ÈÏ¿ÉÏò¶íÂÞ˹µçÍøÖ²È벡¶¾£¬£¬£¬£¬£¬£¬ÌØÀÊÆÕÅ­í¡ÃÀýÅѹú


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú

ÍâµØÊ±¼ä6ÔÂ15ÈÕ£¬£¬£¬£¬£¬£¬¡¶Å¦Ô¼Ê±±¨¡·Ô®ÒýÃÀ¹úÏÖÈκÍǰÈÎÕþ¸®¹ÙÔ±µÄ»°³Æ£¬£¬£¬£¬£¬£¬ÃÀ¹úÕýÔÚ¼Ó´ó¶Ô¶íÂÞ˹µçÍøµÄÍøÂç¹¥»÷£¬£¬£¬£¬£¬£¬¡°ÖÁÉÙ´Ó2012Äê×îÏÈ£¬£¬£¬£¬£¬£¬ÃÀ¹úÒѽ«Õì²é̽²âÆ÷ÖÃÈë¶íÂÞ˹µçÍøµÄ¿ØÖÆÏµÍ³¡£¡£¡£¡£ ¡£¡±ÉÏÊö¹ÙÔ±ÌåÏÖ£¬£¬£¬£¬£¬£¬ÏÖÔÚÃÀ¹úµÄÕ½ÂÔÒѾ­¸ü¶àµØ×ªÏò½ø¹¥£¬£¬£¬£¬£¬£¬²¢ÒÔ¡°Ø¨¹ÅδÓС±µÄÉî¶È½«Ç±ÔڵĶñÒâÈí¼þ°²¶ÙÓÚ¶íÂÞ˹ϵͳÄÚ¡£¡£¡£¡£ ¡£ÃÀ¹úÕþÒª²¢Î´¾Í±¨µÀ×÷³ö»ØÓ¦£¬£¬£¬£¬£¬£¬µ«¿´Í걨µÀµÄÌØÀÊÆÕÈ´Ê®·ÖÄÕÅ­£¬£¬£¬£¬£¬£¬ËûËæ¼´ÔÚÍÆÌØÉÏ·¢ÍÆÎÄ»Øí¡£¬£¬£¬£¬£¬£¬³Æ¡¶Å¦Ô¼Ê±±¨¡·µÄ±¨µÀÊǼٵÄ£¬£¬£¬£¬£¬£¬²¢³ÆÆä×ö·¨¡°¼òÖ±ÊÇÅѹúÐо¶£¬£¬£¬£¬£¬£¬ÊÇÈËÃñµÄ³ðÈË£¡¡±¡£¡£¡£¡£ ¡£

Ô­ÎÄÁ´½Ó£º
https://www.nytimes.com/2019/06/15/us/politics/trump-cyber-russia-grid.html

2¡¢AMCAÊý¾Ýй¶²¨¼°ÈËÊýÁè¼Ý2000Íò£¬£¬£¬£¬£¬£¬5¼Ò¹«Ë¾ÊÜÓ°Ïì


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


ÃÀ¹úÒ½ÁÆÆóÒµÕ˵¥Ð§ÀÍÉÌAMCAµÄÊý¾Ýй¶ÊÂÎñÏÖÒѲ¨¼°Áè¼Ý2000Íò»¼Õß¡£¡£¡£¡£ ¡£Ð¹Â¶µÄÊý¾ÝÊôÓÚÃÀ¹ú¸÷¸öÁÙ´²ºÍѪҺ¼ì²âʵÑéÊҵϼÕߣ¬£¬£¬£¬£¬£¬°üÀ¨ËûÃǵÄÐÕÃû¡¢¼Òͥסַ¡¢µç»°ºÅÂë¡¢³öÉúÈÕÆÚ¡¢Éç»áÇå¾²ºÅÂë¡¢Ö§¸¶¿¨ÏêϸÐÅÏ¢ºÍÒøÐÐÕË»§ÐÅÏ¢µÈ¡£¡£¡£¡£ ¡£ÊÜÓ°ÏìµÄʵÑéÊÒ°üÀ¨Quest Diagnostics£¨²¨¼°1190Íò»¼Õߣ©¡¢LabCorp£¨770Íò»¼Õߣ©¡¢BioReferenceʵÑéÊÒ£¨Opko Health×Ó¹«Ë¾£¬£¬£¬£¬£¬£¬422600Ãû»¼Õߣ©¡¢Carecentrix£¨50ÍòÃû»¼Õߣ©ºÍSunrise Laboratories£¨Î´¹ûÕæ»¼ÕßÊý£©¡£¡£¡£¡£ ¡£

Ô­ÎÄÁ´½Ó£º
https://www.zdnet.com/article/amca-data-breach-has-now-gone-over-the-20-million-mark/

3¡¢EquifaxÊý¾Ýй¶ӰÏìÃÀ¹ú¶à¸öÕþ¸®»ú¹¹µÄÉí·ÝÑéÖ¤Á÷³Ì


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


ÃÀ¹úÕþ¸®ÎÊÔð°ì¹«ÊÒ£¨GAO£©µÄб¨¸æÖ¸³ö£¬£¬£¬£¬£¬£¬2017ÄêEquifaxµÄÊý¾Ýй¶ÊÂÎñÓ°ÏìÁ˶à¸öÕþ¸®»ú¹¹µÄÔÚÏßÉí·ÝÑéÖ¤Á÷³Ì¡£¡£¡£¡£ ¡£ÊÜÓ°ÏìµÄ»ú¹¹°üÀ¨Ò½Áưü¹ÜºÍÒ½ÁƽòÌùЧÀÍÖÐÐÄ£¨CMS£©¡¢Éç»á°ü¹ÜÖÎÀí¾Ö£¨SSA£©¡¢ÃÀ¹úÓÊÕþЧÀÍ£¨USPS£©ºÍÍËÎéÎäÊ¿ÊÂÎñ²¿£¨VA£©¡£¡£¡£¡£ ¡£ÃÀ¹ú¹«ÃñÔÚÕâЩÕþ¸®»ú¹¹¹ÙÍøÉêÇ븣Àûʱ£¬£¬£¬£¬£¬£¬ÒÀÀµÓÚEquifaxµÈÐÅÓñ¨¸æ»ú¹¹£¨CRA£©ÌṩµÄÊý¾Ý×÷ΪÉêÇëÈËÉí·ÝµÄ֤ʵ£¬£¬£¬£¬£¬£¬ÓÉÓÚºÚ¿ÍÒ²ÓµÓÐÕâЩÊý¾Ý£¬£¬£¬£¬£¬£¬Ê¹µÃÕâÒ»Àú³Ì²»ÔÙ¿ÉÐÅ¡£¡£¡£¡£ ¡£2017ÄêÃÀ¹ú¹ú¼Ò±ê×¼ÓëÊÖÒÕÑо¿Ôº£¨NIST£©½¨ÒéÓÃÆäËû½â¾ö¼Æ»®Ìæ»»»ùÓÚCRAµÄÔÚÏßÉí·Ý֤ʵ£¬£¬£¬£¬£¬£¬µ«GAO·¢Ã÷ÉÏÊö»ú¹¹ÈÔÔÚʹÓþɵÄCRAÊý¾Ý¿â¾ÙÐÐÔÚÏßÉí·Ýʶ±ðÑéÖ¤¡£¡£¡£¡£ ¡£

Ô­ÎÄÁ´½Ó£º
https://www.zdnet.com/article/equifax-breach-impacted-the-online-id-verification-process-at-many-us-govt-agencies/

4¡¢Firefox½ôÆÈÐÞ¸´RCE 0day£¨CVE-2019-11707£©


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


MozillaÐû²¼Firefox 67.0.3ºÍFirefox ESR 60.7.1£¬£¬£¬£¬£¬£¬ÓÃÓÚ½ôÆÈÐÞ¸´¿Éµ¼ÖÂRCEµÄ0day£¨CVE-2019-11707£©¡£¡£¡£¡£ ¡£¸ÃÎó²îÓÉGoogle Project ZeroÍŶӷ¢Ã÷²¢±¨¸æ£¬£¬£¬£¬£¬£¬ÊÇÒ»¸öÀàÐÍ»ìÏýÎó²î£¬£¬£¬£¬£¬£¬Îó²î±íÊöΪ£ºÓÉÓÚArray.popÖеÄÎÊÌ⣬£¬£¬£¬£¬£¬²Ù×÷JavaScript¹¤¾ßʱ¿ÉÄܻᴥ·¢Îó²î£¬£¬£¬£¬£¬£¬µ¼Ö¿ÉʹÓõÄÍ߽⡣¡£¡£¡£ ¡£¸ÃÎó²îÒÑÔÚÒ°ÍⱻʹÓ㬣¬£¬£¬£¬£¬½¨ÒéÓû§¾¡¿ì¸üС£¡£¡£¡£ ¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/mozilla-firefox-6703-patches-actively-exploited-zero-day/

5¡¢¼ÓÄôó½ðÈÚ»ú¹¹Desjardinsй¶Լ290Íò»áÔ±µÄÃô¸ÐÐÅÏ¢


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


DesjardinsÊDZ±ÃÀµØÇø×î´óµÄÐÅÓÃÉ磬£¬£¬£¬£¬£¬Ò²ÊǼÓÄôó×î´óµÄÏàÖú½ðÈÚ¼¯ÍÅ¡£¡£¡£¡£ ¡£Æ¾Ö¤¸Ã¹«Ë¾µÄÐÂΟ壬£¬£¬£¬£¬£¬Ô¼290Íò»áÔ±µÄÃô¸ÐÐÅÏ¢ÔÚÔ±¹¤Î´¾­ÊÚȨÏò¹«Ë¾ÍⲿְԱÅû¶ºóй¶£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨270ÍòÃûСÎÒ˽¼Ò»áÔ±ºÍ17.3ÍòÆóÒµ»áÔ±¡£¡£¡£¡£ ¡£DesjardinsÓÚ2019Äê6ÔÂ14ÈÕ·¢Ã÷й¶ÊÂÎñ£¬£¬£¬£¬£¬£¬Ð¹Â¶µÄÐÅÏ¢°üÀ¨Ð¡ÎÒ˽¼Ò»áÔ±µÄÐÕÃû¡¢³öÉúÈÕÆÚ¡¢Éç»á°ü¹ÜºÅÂë¡¢µØµã¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØµãÒÔ¼°ÒøÐкÍDesjardins²úÆ·µÄÏêϸÐÅÏ¢£»£»£»ÆóÒµ»áÔ±µÄ¹«Ë¾Ãû³Æ¡¢µØµã¡¢µç»°ºÅÂë¡¢ËùÓÐÕßÐÕÃûºÍAcc¨¨sDAffairesÕÊ»§Ãû³ÆÒÔ¼°ÓëAcc¨¨sDAffairesÕÊ»§Ïà¹ØµÄһЩСÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£¡£ ¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/desjardins-group-data-leak-exposes-info-of-29-million-members/