PCI SSC°ä²¼·Ç½Ó´¥Ê½Ö§¸¶µÄÐÂÊý¾Ý°²È«³ß¶È£»£»£»£»£»£»£»Linux·ì϶£¨CVE-2019-14899£©¿Éµ¼Ö¹¥»÷Õß½Ù³ÖVPN

°ä²¼¹¦·ò 2019-12-06


1.OpenBSDÍŶӽ¨¸´4¸öÉí·ÝÑéÖ¤ÈÆ¹ý/ÌáȨ·ì϶


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


OpenBSDÍŶӽ¨¸´ÁË4¸ö¿Éµ¼ÖÂÌØÈ¨Éý¼¶ºÍÉí·ÝÑéÖ¤ÈÆ¹ýµÄ°²È«·ì϶£¬£¬£¬ £¬£¬£¬£¬£¬Qualys Research LabsÔÚ±¾ÖÜÔçЩʱ³½·¢ÏÖ²¢»ã±¨ÁËÕâЩ·ì϶£¬£¬£¬ £¬£¬£¬£¬£¬OpenBSD¿ª·¢ÍŶÓÔÚ40¸öÓ×ʱ֮ÄÚ°ä²¼ÁËÕë¶ÔOpenBSD 6.5ºÍOpenBSD 6.6µÄ½¨¸´²¹¶¡¡£¡£ ¡£¡£¡£¡£¡£¡£·ì϶ÁìÓòÔ̺¬Éí·ÝÑéÖ¤ÈÆ¹ý£¨CVE-2019-19521£©ºÍÌØÈ¨Éý¼¶£¨CVE-2019-19519¡¢CVE-2019-19520ºÍCVE-2019-19520£©¡£¡£ ¡£¡£¡£¡£¡£¡£Qualys×êÑÐÈËÔ±»¹ÔÚÿ¸ö·ì϶µÄÕ÷ѯ²¼¸æÖа䲼ÁËÓйØPoCÀûÓᣡ£ ¡£¡£¡£¡£¡£¡£


  Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/openbsd-patches-severe-authentication-bypass-privilege-escalation-vulnerabilities/


2.Ubuntu°ä²¼Intel΢Âë¸üУ¬£¬£¬ £¬£¬£¬£¬£¬½¨¸´CPU¹ÒÆðÎÊÌâ


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


CanonicalΪUbuntu°ä²¼ÁËеÄLinux Intel΢´úÂë¸üУ¬£¬£¬ £¬£¬£¬£¬£¬¸Ã¸üн¨¸´Á˵¼ÖÂIntel Skylake CPUÔÚÈȳÁÆôºó¹ÒÆðµÄÎÊÌâ¡£¡£ ¡£¡£¡£¡£¡£¡£Ö®Ç°11ÔÂ12ÈÕµÄIntel΢´úÂë¸üÐÂÖлº½âÁËÊÂÎñͬ²½À©´ó£¨TSX£©Ö°ÄÜÖеķì϶ºÍÖÁÇ¿´¦ÖÃÆ÷ÖеÄDoS·ì϶£¬£¬£¬ £¬£¬£¬£¬£¬µ«¸Ã¸üе¼ÖÂÁËÒ»¸ö»Ø¹é·ì϶£ºIntel Skylake´¦ÖÃÆ÷ÔÚÈȳÁÆôºó¹ÒÆð¡£¡£ ¡£¡£¡£¡£¡£¡£Îª½â¾ö´ËÎÊÌ⣬£¬£¬ £¬£¬£¬£¬£¬UbuntuÍŶӰ䲼ÁËеÄintel-microcode-3.20191115.1ubuntu0¸üУ¬£¬£¬ £¬£¬£¬£¬£¬¸Ã¸üпɻ¹Ô­Skylake´¦ÖÃÆ÷µÄ΢´úÂ룬£¬£¬ £¬£¬£¬£¬£¬Ê¹Æä²»ÔÙ¹ÒÆð¡£¡£ ¡£¡£¡£¡£¡£¡£UbuntuÓû§Äܹ»ÔËÐÐSoftware Updater·¨Ê½À´²é³­²¢×°ÖÃ×îиüС£¡£ ¡£¡£¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/linux/ubuntu-linux-gets-intel-microcode-update-to-fix-cpu-hangs/


3.ÃÀ¹úÊý¾ÝÖÐÐÄ·þÎñÉÌCyrusOneÊÜÀÕË÷Èí¼þ¹¥»÷


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ÃÀ¹úÊý¾ÝÖÐÐÄ·þÎñÉÌCyrusOneÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬ £¬£¬£¬£¬£¬¸Ã¹«Ë¾½²»°ÈËÔÚÒ»·âµç×ÓÓʼþÖÐ֤ʵÁËÕâÒ»ÊÂÎñ£¬£¬£¬ £¬£¬£¬£¬£¬²¢°µÊ¾ËûÃÇĿǰÔÚÓë·¨ÂÉ»ú¹¹ºÍ·¨Ö¤¹«Ë¾ºÏ×÷½øÐе÷²éÒÔ¼°Ô®ÊÖ¿Í»§¸´Ô­ÊÜÓ°ÏìµÄϵͳ¡£¡£ ¡£¡£¡£¡£¡£¡£CyrusOne°µÊ¾ÓÉÓÚÀÕË÷Èí¼þ¶ÔÍøÂçÖеÄijЩÉ豸½øÐмÓÃÜ£¬£¬£¬ £¬£¬£¬£¬£¬µ¼ÖÂλÓÚŦԼÊý¾ÝÖÐÐĵÄÁù¸öÍйܷþÎñ¿Í»§Óöµ½ÁË¿ÉÓÃÐÔÎÊÌ⣬£¬£¬ £¬£¬£¬£¬£¬ÆäÖÐÔ̺¬½ðÈں;­¼Í¹«Ë¾FIA Tech¡£¡£ ¡£¡£¡£¡£¡£¡£Æ¾¾ÝZDNetÊÕµ½µÄÐÂÎÅ£¬£¬£¬ £¬£¬£¬£¬£¬¸ÃÊÂÎñ²úÉúÔÚ12ÔÂ4ºÅ£¬£¬£¬ £¬£¬£¬£¬£¬²¢ÇÒÊÇÓÉÀÕË÷Èí¼þREvil£¨Sodinokibi£©ÒýÆðµÄ¡£¡£ ¡£¡£¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/ransomware-attack-hits-major-us-data-center-provider/


4.ÒÁÀÊAPT×éÖ¯ÀûÓÃÊý¾Ý²Á³ýÆ÷ZeroCleare¶Ô×¼Öж«


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


IBM×êÑÐÈËÔ±·¢ÏÖÒ»¸öеķÛËéÐÔÊý¾Ý²Á³ý¶ñÒâÈí¼þZeroCleare£¬£¬£¬ £¬£¬£¬£¬£¬¸ÃÈí¼þ±»¹ú¶ÈÔÞÖúµÄºÚ¿Í×éÖ¯ÔÚÒ°±íÓÃÓÚÕë¶ÔÖж«µÄÄÜÔ´ºÍ¹¤Òµ×éÖ¯¡£¡£ ¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±³ÆZeroCleareÓëÁ½¸öÒÁÀÊAPT×éÖ¯Óйأ¬£¬£¬ £¬£¬£¬£¬£¬Ò»¸öÊÇAPT34£¨Ò²±»³ÆÎªITG13ºÍOilrig£©£¬£¬£¬ £¬£¬£¬£¬£¬ÁíÒ»¸öÊÇHive0081£¨Ò²±»³ÆÎªxHunt£©¡£¡£ ¡£¡£¡£¡£¡£¡£ZeroCleareÊǶà½×¶Î¹¥»÷ÖеÄ×îÖÕpayload£¬£¬£¬ £¬£¬£¬£¬£¬ËüÓÐÁ½¸ö±äÌ壬£¬£¬ £¬£¬£¬£¬£¬±ðÀëÕë¶Ô32λºÍ64λµÄWindowsϵͳ¡£¡£ ¡£¡£¡£¡£¡£¡£µ«×êÑÐÈËÔ±°µÊ¾Ö»ÓÐ32λµÄ°æ±¾¿ÉÓ㬣¬£¬ £¬£¬£¬£¬£¬ÓÉÓÚ64λ°æ±¾ÔÚÏÖʵÆðÍ·²Á³ýÊý¾Ý֮ǰ»á±ÀÀ£¡£¡£ ¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±»¹³ÆZeroCleare¹¥»÷ÊÇÕë¶ÔÌØ¶¨²¿ÃźÍ×éÖ¯µÄÕë¶ÔÐÔÐж¯¡£¡£ ¡£¡£¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-iranian-zerocleare-data-wiper-malware-used-in-targeted-attacks/


5.PCI SSC°ä²¼·Ç½Ó´¥Ê½Ö§¸¶µÄÐÂÊý¾Ý°²È«³ß¶È


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


PCI°²È«³ß¶ÈίԱ»á£¨PCI SSC£©°ä²¼ÁËÓÃÓڷǽӴ¥Ê½Ö§¸¶µÄÐÂÊý¾Ý°²È«³ß¶È¡£¡£ ¡£¡£¡£¡£¡£¡£¸Ã³ß¶ÈÔÊÐí´øÓÐNFCµÄCOTSÒÆ¶¯É豸½ÓÊܷǽӴ¥Ê½Ö§¸¶¡£¡£ ¡£¡£¡£¡£¡£¡£PCI CPoC³ß¶ÈÊǸÃίԱ»áΪ½â¾öÒÆ¶¯·Ç½Ó´¥Ê½Ö§¸¶°ä²¼µÄµÚ¶þ¸ö³ß¶È¡£¡£ ¡£¡£¡£¡£¡£¡£¾ßÌåÀ´Ëµ£¬£¬£¬ £¬£¬£¬£¬£¬PCI CPoC³ß¶È»®¶¨Á˹©¸øÉÌÔÚ±£»£»£»£»£»£»£»¤Êý¾Ý¡¢²âÊÔÒªÇóºÍÆÀ¹À½â¾ö¹æ»®·½ÃæµÄһЩ°²È«ÉϵÄÒªÇ󡣡£ ¡£¡£¡£¡£¡£¡£³ß¶ÈµÄCPoC½â¾ö¹æ»®Ô̺¬ÓµÓÐǶÈëʽNFC½Ó¿ÚµÄCOTSÉ豸¡¢¾­ÑéÖ¤µÄ¸¶¿îÈí¼þÒÔ¼°¶ÀÁ¢ÓÚCOTSÉ豸µÄºó¶Ëϵͳ¡£¡£ ¡£¡£¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/new-data-security-standards-published-for-contactless-payments-12566cb1


6.Linux·ì϶£¨CVE-2019-14899£©¿Éµ¼Ö¹¥»÷Õß½Ù³ÖVPN


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


°²È«×êÑÐÈËÔ±Åû¶ÁËÒ»¸öÓ°Ïì*NIXÉ豸µÄ°²È«·ì϶£¬£¬£¬ £¬£¬£¬£¬£¬¸Ã·ì϶¿ÉÔÊÐí¹¥»÷ÕßÐá̽¡¢½Ù³ÖºÍ´Û¸ÄVPNËí·Ïνӣ¬£¬£¬ £¬£¬£¬£¬£¬²¢½«ËÁÒâÓÐÐ§ÔØºÉ×¢ÈëIPv4ºÍIPv6µÄTCPÊý¾ÝÁ÷ÖС£¡£ ¡£¡£¡£¡£¡£¡£¸Ã·ì϶£¨CVE-2019-14899£©Î»ÓÚ»ùÓÚUnix²Ù×÷ϵͳµÄÍøÂç²Ö¿âÖУ¬£¬£¬ £¬£¬£¬£¬£¬¸ü¾ßÌåµØËµ£¬£¬£¬ £¬£¬£¬£¬£¬ÔÚ²Ù×÷ϵͳ¶ÔÒâ±íµÄÍøÂçÊý¾Ý°ü̽²â½øÐÐÏìÓ¦µÄ¹ý³ÌÖС£¡£ ¡£¡£¡£¡£¡£¡£ÒÑÖª¸Ã·ì϶»áÓ°Ïì´óÎÞÊýLinux¿¯ÐаæºÍÀàUnix²Ù×÷ϵͳ£¬£¬£¬ £¬£¬£¬£¬£¬Ô̺¬FreeBSD¡¢OpenBSD¡¢macOS¡¢iOSºÍAndroid¡£¡£ ¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±³Æ´Ë¹¥»÷¿ÉÕë¶ÔOpenVPN¡¢WireGuardºÍIKEv2/IPSecµÈVPN¼¼Êõ£¬£¬£¬ £¬£¬£¬£¬£¬µ«ÈÔÔÚ²âÊÔÆäÕë¶ÔTorµÄ¿ÉÐÐÐÔ¡£¡£ ¡£¡£¡£¡£¡£¡£·þÎñÆ÷ÖÎÀíÔ±Äܹ»Ñ¡È¡µÄ»º½â´ëÊ©Ô̺¬´ò¿ª·´Ïòõè¾¶¹ýÂË¡¢Ê¹ÓÃbogon¹ýÂËÐéαIPµØÖ·»òʹÓüÓÃܵÄÊý¾Ý°ü´óÓ׺Ͱ´Ê±µÈ¡£¡£ ¡£¡£¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-linux-vulnerability-lets-attackers-hijack-vpn-connections/