ÐÅÏ¢Çå¾²Öܱ¨-2020ÄêµÚ03ÖÜ
Ðû²¼Ê±¼ä 2020-01-20
±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö
2020Äê01ÔÂ13ÈÕÖÁ19ÈÕ¹²ÊÕ¼Çå¾²Îó²î53¸ö£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇMicrosoft Windows CryptoAPIÑéÖ¤ÈÆ¹ýÎó²î; Apache XML-RPC XMLRPC client´úÂëÖ´ÐÐÎó²î£»£»£»Oracle E-Business Suite Human Resources CVE-2020-2587δÃ÷´úÂëÖ´ÐÐÎó²î£»£»£»Adobe Illustrator CC CVE-2020-3710ÄÚ´æ¹ýʧÒýÓôúÂëÖ´ÐÐÎó²î£»£»£»Microsoft .NET Core CVE-2020-0602Ô¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇÒÔÉ«ÁÐÆô¶¯Ãñº½ÍøÂçÇå¾²ÍýÏ룬£¬£¬£¬½«¸ÄÉÆº½¿ÕÍøÂç·ÀÓùÄÜÁ¦£»£»£»Î¢ÈíÕýʽÖÕÖ¹¶ÔWindows 7¡¢Server 2008ºÍ2008 R2Ìṩ֧³Ö£»£»£»ÃÀ¹úLimeLeads¹«Ë¾4900ÍòÌõÓû§¼Í¼ÔÚ°µÍøÂÛ̳³öÊÛ£»£»£»ÊÔÓÃAppÐ¶ÔØºóÖ±½Ó¿Û·Ñ£¬£¬£¬£¬È«Çò½ü6ÒÚAndroidÓû§ÖÐÕУ»£»£»Êý°Ù¸öҽѧ³ÉÏñϵͳÔÚÍøÉÏ̻¶ÁËÊý°ÙÍò»¼ÕßµÄÊý¾Ý¡£¡£¡£
ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£
Ö÷ÒªÇå¾²Îó²îÁбí
1. Microsoft Windows CryptoAPIÑéÖ¤ÈÆ¹ýÎó²î
Microsoft Windows CryptoAPI´¦Öóͷ£ECCÍÖÔ²ÇúÏß¼ÓÃܱ£´æÇå¾²Îó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬¿ÉÒÔʹÓÃαÔìµÄÖ¤Êé¶Ô¶ñÒâµÄ¿ÉÖ´ÐÐÎļþ¾ÙÐÐÊðÃû£¬£¬£¬£¬Ê¹Îļþ¿´ÆðÀ´À´×Ô¿ÉÐŵÄȪԴ£¬£¬£¬£¬»òÕß¾ÙÐÐÖÐÐÄÈ˹¥»÷²¢½âÃÜÓû§ÅþÁ¬µ½ÊÜÓ°ÏìÈí¼þµÄÉñÃØÐÅÏ¢¡£¡£¡£
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0601
2. Apache XML-RPC XMLRPC client´úÂëÖ´ÐÐÎó²î
Apache XML-RPC XMLRPC clientʵÏÖXMLRPC¹ýʧÐÂÎÅfaultCauseÊôÐÔ´¦Öóͷ£±£´æÇå¾²Îó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²î¹¹½¨¶ñÒâXMLRPCЧÀÍÇëÇ󣬣¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»òÕßÖ´ÐÐí§Òâ´úÂë¡£¡£¡£
https://access.redhat.com/security/cve/cve-2019-17570
3. Oracle E-Business Suite Human Resources CVE-2020-2587δÃ÷´úÂëÖ´ÐÐÎó²î
Oracle E-Business Suite Human Resources±£´æÎ´Ã÷Çå¾²Îó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£
https://www.oracle.com/security-alerts/cpujan2020.html
4. Adobe Illustrator CC CVE-2020-3710ÄÚ´æ¹ýʧÒýÓôúÂëÖ´ÐÐÎó²î
Adobe Illustrator CC´¦Öóͷ£Îļþ±£´æÄÚ´æÆÆËðÎó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£
https://helpx.adobe.com/security/products/illustrator/apsb20-03.html
5. Microsoft .NET Core CVE-2020-0602Ô¶³Ì´úÂëÖ´ÐÐÎó²î
Microsoft .NET CoreʵÏÖ±£´æÇå¾²Îó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0602
Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö
1¡¢ÒÔÉ«ÁÐÆô¶¯Ãñº½ÍøÂçÇå¾²ÍýÏ룬£¬£¬£¬½«¸ÄÉÆº½¿ÕÍøÂç·ÀÓùÄÜÁ¦
¾ÝÉÏÖÜÈÕÒÔÉ«Áйú¼ÒÍøÂçÖÎÀí¾Ö£¨INCD£©±¨µÀ£¬£¬£¬£¬ÒÔÉ«ÁÐÕþ¸®Åú×¼ÁËÒ»ÏîÃñº½ÍøÂçÇå¾²ÍýÏë¡£¡£¡£×÷Ϊ¸ÃÍýÏëµÄÒ»²¿·Ö£¬£¬£¬£¬ÒÔÉ«Áн«½¨ÉèÒ»¸ö¹ú¼ÒÖ¸µ¼Î¯Ô±»áÀ´¸ÄÉÆ¸Ã¹ú¼ÒµÄº½¿ÕÍøÂç·ÀÓùÄÜÁ¦¡£¡£¡£¸ÃίԱ»áÓÉINCDÏòµ¼£¬£¬£¬£¬²¢ÇÒÓÉÒÔÉ«Áн»Í¨²¿¡¢Ãñº½¾Ö¡¢»ú³¡ÖÎÀí¾Ö¡¢Çå¾²¾Ö¡¢¹ú·À²¿¡¢¹ú¼ÒÇ徲ίԱ»áºÍÒÔÉ«Áйú·À¾üµÄ´ú±í×é³É¡£¡£¡£¸ÃÍýÏëµÄÄÚÈݰüÀ¨£ºÍþвӳÉäÏ¢Õù¾ö¼Æ»®ÏîÄ¿¡¢Ôڸ߿Ƽ¼ºÍÍøÂçÐÐÒµÒÔ¼°Ñ§Êõ½çÍÆ¶¯Ç°ÑØÊÖÒÕÑо¿ºÍ¹ú·À½â¾ö¼Æ»®µÄÑз¢¡¢Ó벨Òô¾ÙÐÐÏàÖú¡¢½¨ÉèÔËÊä¿ØÖÆÖÐÐÄ¡¢¿ª·¢º½ÐÐÔ±Åàѵ¿Î³ÌµÈ¡£¡£¡£
ÔÎÄÁ´½Ó£º
http://www.xinhuanet.com/english/2020-01/13/c_138699304.htm
2¡¢Î¢ÈíÕýʽÖÕÖ¹¶ÔWindows 7¡¢Server 2008ºÍ2008 R2Ìṩ֧³Ö
΢ÈíÓÚ1ÔÂ14ÈÕÕýʽÖÕÖ¹¶ÔWindows 7¡¢Server 2008ºÍServer 2008 R2Ìṩ֧³Ö¡£¡£¡£ÔÚ´ËÖ®ºóÕâЩ²Ù×÷ϵͳÈԿɼÌÐøÊÂÇ飬£¬£¬£¬µ«½«²»ÔÙÊÕµ½Çå¾²¸üС£¡£¡£¶ÔWindows Server 2008µÄÖÕÖ¹Ö§³ÖÒâζ×ÅÆäÌØÁíÍâÃâ·ÑÇå¾²¸üС¢·ÇÇå¾²¸üС¢Ãâ·ÑµÄÖ§³ÖЧÀÍÒÔ¼°ÔÚÏßÊÖÒÕÄÚÈݸüж¼ÒÑ¿¢Ê¡£¡£¡£Î¢Èí±Þ²ßÓû§½«Æä²úÆ·ºÍЧÀÍǨáãµ½Azure»òÊÇÉý¼¶µ½×îа汾Server 2016¡£¡£¡£ÎÞ·¨ÔÚÖ§³ÖÖÕÖ¹ÏÞÆÚ֮ǰÍê³ÉÉý¼¶µÄÈË¿ÉÒÔ¹ºÖÃÀ©Õ¹Çå¾²¸üУ¬£¬£¬£¬ÒÔ±£»£»£»¤Ð§ÀÍÆ÷ÊÂÇé¸ºÔØÖ±ÖÁÉý¼¶ÎªÖ¹¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.darkreading.com/risk/microsoft-to-officially-end-support-for-windows-7-server-2008/d/d-id/1336791
3¡¢ÃÀ¹úLimeLeads¹«Ë¾4900ÍòÌõÓû§¼Í¼ÔÚ°µÍøÂÛ̳³öÊÛ
¾ÝZDNet±¨µÀ£¬£¬£¬£¬ºÚ¿ÍOmnichorusÕýÔÚ°µÍøÂÛ̳ÉϳöÊÛÃÀ¹úÊý¾Ý¾¼ÍÉÌLimeLeadsµÄ4900ÍòÌõÓû§¼Í¼¡£¡£¡£Çå¾²Ñо¿Ô±Bob DiachenkoÈ·ÈÏÕâЩÊý¾ÝÊÇÓɸù«Ë¾µÄÄÚ²¿ElasticsearchЧÀÍÆ÷̻¶ÔÚInternetÉÏй¶µÄ¡£¡£¡£Æ¾Ö¤DiachenkoµÄ˵·¨£¬£¬£¬£¬ÖÁÉÙ´Ó2019Äê7ÔÂ27ÈÕÆðLimeLeadsµÄһ̨ЧÀÍÆ÷¾Í¿É¹ûÕæ»á¼û£¬£¬£¬£¬ËûÓÚÈ¥Äê9ÔÂ16ÈÕ֪ͨÁ˸ù«Ë¾£¬£¬£¬£¬¸Ã¹«Ë¾ÔÚµÚ¶þÌìѸËÙ¶ÔЧÀÍÆ÷¾ÙÐÐÁ˱£»£»£»¤£¬£¬£¬£¬µ«ÏÔÈ»OmnichorusÒѾÇÔÈ¡ÁËÕâЩÊý¾Ý£¬£¬£¬£¬²¢ÇÒ´ÓÈ¥Äê10ÔÂÒÔÀ´Ò»Ö±ÔÚÍøÉϳöÊÛ¡£¡£¡£Æ¾Ö¤OmnichorusÐû²¼µÄÊý¾ÝÑù±¾£¬£¬£¬£¬ÕâЩÊý¾Ý°üÀ¨Óû§µÄÐÕÃû¡¢Ö°Îñ¡¢µç×ÓÓʼþ¡¢¹ÍÖ÷/¹«Ë¾Ãû³Æ¡¢¹«Ë¾µØµã¡¢¶¼»á¡¢ÖÝ¡¢ÓÊÕþ±àÂë¡¢µç»°ºÅÂë¡¢ÍøÕ¾URL¡¢¹«Ë¾×ÜÊÕÈëÒÔ¼°¹«Ë¾µÄÔ¤¼ÆÔ±¹¤ÈËÊýµÈÐÅÏ¢¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/49-million-user-records-from-us-data-broker-limeleads-put-up-for-sale-online/
4¡¢ÊÔÓÃAppÐ¶ÔØºóÖ±½Ó¿Û·Ñ£¬£¬£¬£¬È«Çò½ü6ÒÚAndroidÓû§ÖÐÕÐ
SophosÇå¾²Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»×éеÄfleeceware APP£¬£¬£¬£¬ÕâЩAPPÒѾ±»Áè¼Ý6ÒÚAndroidÓû§ÏÂÔØ×°Öᣡ£¡£fleecewareÊÇÖ¸¹È¸èPlayÊÐËÁÖб£´æµÄÒ»ÖÖÐÂÐͽðÈÚÚ²ÆÐÐΪ£¬£¬£¬£¬ÕâЩAPPÀÄÓÃAndroidÓ¦ÓõÄÊÔÓÃÆÚ¹¦Ð§ÏòÓû§ÊÕ·Ñ¡£¡£¡£Ä¬ÈÏÇéÐÎÏÂAndroidÓû§ÔÚ×¢²áʹÓþßÓÐÊÔÓÃÆÚµÄAPPʱ±ØÐèÊÖ¾Ù´ë·ÏÊÔÓ㬣¬£¬£¬È»¶ø´ó´ó¶¼Óû§Ö»ÊÇÔÚ²»Ï²»¶µÄʱ¼äÐ¶ÔØAPP£¬£¬£¬£¬¾ø´ó´ó¶¼¿ª·¢Õß½«ÕâÖÖÐ¶ÔØÐÐΪÊÓΪ×÷·ÏÊÔÓ㬣¬£¬£¬µ«Ò»Ð©¿ª·¢ÕßÔÚÓû§Ð¶ÔغóûÓÐ×÷·ÏÊÔÓò¢ÇÒ¼ÌÐøÊÕ·Ñ¡£¡£¡£Sophos×î³õ·¢Ã÷µÄ24¸öAPP°üÀ¨¶þάÂëɨÃèÆ÷¡¢ÅÌËãÆ÷µÈ£¬£¬£¬£¬ËüÃÇÒÔÕâÖÖ·½·¨ÏòÓû§ÊÕȡÿÄê100ÃÀÔªµ½240ÃÀÔªµÄ¶©ÔÄÓöȡ£¡£¡£ÔÚ¿ËÈÕÐû²¼µÄÒ»·Ý±¨¸æÖУ¬£¬£¬£¬Sophos·¢Ã÷ÁËÁíÍâ25¸ö´ËÀàAPP£¬£¬£¬£¬Æä×Ü×°ÖÃÁ¿Áè¼Ý6ÒÚ£¬£¬£¬£¬ÍêÕûµÄAPPÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/more-than-600-million-users-installed-android-fleeceware-apps-from-the-play-store/
5¡¢Êý°Ù¸öҽѧ³ÉÏñϵͳÔÚÍøÉÏ̻¶ÁËÊý°ÙÍò»¼ÕßµÄÊý¾Ý
µÂ¹úÇå¾²³§ÉÌGreenbone³ÆÊý°Ù¸ö¿É¹ûÕæ»á¼ûµÄҽѧ³ÉÏñϵͳÔÚ»¥ÁªÍøÉÏ̻¶ÁËÈ«ÇòÊý°ÙÍò»¼ÕßµÄÊý¾Ý¡£¡£¡£¸ÃÏîÑо¿ÖصãÆÊÎöÔÚÍøÉÏ̻¶µÄҽѧͼƬ´æµµºÍͨѶϵͳ£¨PACS£©£¬£¬£¬£¬ÔÚËùÓÐÊÜÆÊÎöµÄPACSЧÀÍÆ÷ÖУ¬£¬£¬£¬ÓпìÒª1/4µÄϵͳ½«Êý¾Ý̻¶ÔÚ»¥ÁªÍøÉÏ¡£¡£¡£ÏêϸÀ´Ëµ£¬£¬£¬£¬ÔÚ2019Äê7ÔÂÖÁ2019Äê9ÔÂÖ®¼äÆÊÎöµÄ2300¸öϵͳÖУ¬£¬£¬£¬ÓÐ590¸ö¿É´ÓInternet»á¼û²¢ÇÒδÉèÃÜÂ룬£¬£¬£¬¹²ÓÐÁè¼Ý2450ÍòÌõ»¼ÕßÊý¾Ý̻¶£¬£¬£¬£¬ÔÚ11Ô·ݵÄÑо¿ÖУ¬£¬£¬£¬¸Ã¹«Ë¾Í¸Â¶ÓÐ3500ÍòÌõ»¼Õ߼ͼ¿É¹ûÕæ»á¼û¡£¡£¡£ÔÚ9ÔÂÖÁ11ÔÂÖ®¼ä£¬£¬£¬£¬°üÀ¨Ò½ÁÆÍ¼ÏñµÄ̻¶»¼Õ߼ͼÊýÄ¿ÒÑ´Ó440ÍòÔöÌíÁËÒ»±¶£¬£¬£¬£¬µÖ´ï900Íò¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/unprotected-medical-systems-expose-data-millions-patients


¾©¹«Íø°²±¸11010802024551ºÅ