ÐÅÏ¢°²È«Öܱ¨-2019ÄêµÚ5ÖÜ

°ä²¼¹¦·ò 2019-03-04

±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2019Äê1ÔÂ28ÈÕÖÁ2ÔÂ03ÈÕ¹²ÊÕ¼°²È«·ì϶42¸ö£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇApache Hadoop CVE-2018-1296°²È«Èƹý·ì϶ £»£»£»£»£»£»D-Link DIR-823G HNAP1ÒªÇóºÅÁî×¢Èë·ì϶ £»£»£»£»£»£»ACD Systems Canvas Draw CVE-2018-3976»º³åÇøÒç¶Âí½Å £»£»£»£»£»£»ARM Trusted Firmware-AÐÅϢй¶·ì϶ £»£»£»£»£»£»Google Chrome PDFium CVE-2019-5772¿ªÊͺóÀûÓôúÂëÖ´Ðзì϶¡£¡£ ¡£¡£¡£¡£¡£¡£

±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇÊý¾ÝÖÎÀí¹«Ë¾RubrikÒâ±íй¶´óÁ¿¿Í»§Êý¾Ý £»£»£»£»£»£»FaceTimeÆØ³Á´óÇÔÌý·ì϶£¬£¬£¬£¬£¬£¬Apple°µÊ¾½«ÔÚ±¾Öܽ¨¸´ £»£»£»£»£»£»Å·ÖÞÍøÂçÐÅÏ¢°²È«¾ÖENISA°ä²¼2018ÄêÍøÂçÍþв¾°¹Û»ã±¨ £»£»£»£»£»£»Ó¡¶È¹ú¶ÈÒøÐÐSBIÒâ±íй¶Êý°ÙÍò¿Í»§ÐÅÏ¢ £»£»£»£»£»£»ºÉÀ¼DPA°ä²¼2018ÄêÊý¾Ýй¶ͳ¼Æ»ã±¨¡£¡£ ¡£¡£¡£¡£¡£¡£

ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖС£¡£ ¡£¡£¡£¡£¡£¡£

³ÁÒª°²È«·ì϶Áбí


1. Apache Hadoop CVE-2018-1296°²È«Èƹý·ì϶
Apache Hadoop´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬Èƹý°²È«ÏÞ¶È£¬£¬£¬£¬£¬£¬Ö´ÐÐδÊÚȨµÄ²Ù×÷¡£¡£ ¡£¡£¡£¡£¡£¡£
https://hadoop.apache.org/cve_list.html#cve-2018-8009-http-cve-mitre-org-cgi-bin-cvename-cgi-name-cve-2018-8009-zip-slip-impact-on-apache-hadoop

2. D-Link DIR-823G HNAP1ÒªÇóºÅÁî×¢Èë·ì϶
D-Link DIR-823G´æÔÚ´úÂë×¢Èë·ì϶£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄHNAP1ÒªÇ󣬣¬£¬£¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐOSºÅÁî¡£¡£ ¡£¡£¡£¡£¡£¡£
https://github.com/leonW7/D-Link/blob/master/Vul_1.md

3. ACD Systems Canvas Draw CVE-2018-3976»º³åÇøÒç¶Âí½Å
ACD Systems Canvas Draw CALS RasterÎļþ½âÎöÖ°ÄÜ´æÔÚÔ½½çдÈë·ì϶£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇ󣬣¬£¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ £»£»£»£»£»£»òÖ´ÐÐËÁÒâ´úÂë¡£¡£ ¡£¡£¡£¡£¡£¡£
https://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0642

4. ARM Trusted Firmware-AÐÅϢй¶·ì϶
ARM Trusted Firmware-A´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬ÔÊÐí±¾µØ¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢¡£¡£ ¡£¡£¡£¡£¡£¡£
https://github.com/ARM-software/arm-trusted-firmware/wiki/Trusted-Firmware-A-Security-Advisory-TFV-8

5. Google Chrome PDFium CVE-2019-5772¿ªÊͺóÀûÓôúÂëÖ´Ðзì϶
Google Chrome PDFium´æÔÚ¿ªÊͺóʹÓ÷ì϶£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄWEBÒ³ÒªÇ󣬣¬£¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬£¬£¬£¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢¡£¡£ ¡£¡£¡£¡£¡£¡£
https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html

 ³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢Êý¾ÝÖÎÀí¹«Ë¾RubrikÒâ±íй¶´óÁ¿¿Í»§Êý¾Ý

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

°²È«×êÑÐÔ±Oliver Hough·¢ÏÖÊôÓÚÊý¾ÝÖÎÀí¹«Ë¾RubrikµÄÒ»¸öElasticsearch·þÎñÆ÷δÊÜÃÜÂë± £»£»£»£»£»£»¤£¬£¬£¬£¬£¬£¬¸ÃÊý¾Ý¿â´æ´¢ÁËÊýÊ®GBµÄÊý¾Ý£¬£¬£¬£¬£¬£¬Ô̺¬ÆóÒµ¿Í»§µÄÃû³Æ¡¢ÁªÏµÐÅÏ¢ºÍ¹¤×÷°¸Àý¡£¡£ ¡£¡£¡£¡£¡£¡£Æ¾¾Ý¹¦·ò´Á£¬£¬£¬£¬£¬£¬ÕâЩÊý¾Ý¿É×·ÒäÖÁ2018Äê10Ô¡£¡£ ¡£¡£¡£¡£¡£¡£¾­¹ýµ÷²é£¬£¬£¬£¬£¬£¬Rubrik³ÆÕâÒ»ÊÂÎñÊÇÓɱ¨´ðÃýÎóµ¼ÖµÄ¡£¡£ ¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://techcrunch.com/2019/01/29/rubrik-data-leak/

2¡¢FaceTimeÆØ³Á´óÇÔÌý·ì϶£¬£¬£¬£¬£¬£¬Apple°µÊ¾½«ÔÚ±¾Öܽ¨¸´

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


¾Ý±íý±¨Â·£¬£¬£¬£¬£¬£¬Apple FaceTime´æÔÚ³Á´ó°²È«·ì϶£¬£¬£¬£¬£¬£¬¿ÉÔÊÐí¹¥»÷ÕßÔÚÖ¸±ê½ÓÌý»ò»Ø¾øFaceTimeͨ»°Ö®Ç°¼àÌý¶Ô·½µÄÉùÒô¡£¡£ ¡£¡£¡£¡£¡£¡£ÈôÊǶԷ½°´ÏÂÒôÁ¿½µµÍ°´Å¥»òµçÔ´°´Å¥À´¾²Òô»òÈ¡µÞͨ»°£¬£¬£¬£¬£¬£¬ÔòÆäǰÖÃÉãÏñÍ·Ò²»á´ò¿ª£¬£¬£¬£¬£¬£¬²¢½«ÊÓÆµÐźŷ¢Ë͸ø¹¥»÷Õß¡£¡£ ¡£¡£¡£¡£¡£¡£¾ÝϤ£¬£¬£¬£¬£¬£¬¸Ã·ì϶»á³Ê´Ë¿ÌiOS 12.1»ò¸ü¸ß°æ±¾µÄiOSÉ豸ÖС£¡£ ¡£¡£¡£¡£¡£¡£AppleÒѾ­Ò»Ê±½ûÓÃÁËFaceTimeÖеÄȺ×éͨ»°Ö°ÄÜ£¬£¬£¬£¬£¬£¬²¢°µÊ¾½«ÔÚ±¾ÖÜÍíЩʱ³½°ä²¼½¨¸´²¹¶¡¡£¡£ ¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://thehackernews.com/2019/01/apple-facetime-privacy-hack.html

3¡¢Å·ÖÞÍøÂçÐÅÏ¢°²È«¾ÖENISA°ä²¼2018ÄêÍøÂçÍþв¾°¹Û»ã±¨

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Å·ÖÞÍøÂçÐÅÏ¢°²È«¾Ö£¨ENISA£©°ä²¼2018ÄêÍþв¾°¹Û»ã±¨£¬£¬£¬£¬£¬£¬¸Ã»ã±¨³Áµã½éÉÜÁË2018ÄêµÄÍøÂçÍþвÇ÷Ïò±ä¶¯£¬£¬£¬£¬£¬£¬Ô̺¬µç×ÓÓʼþºÍ´¹µö¶ÌÐÅÒѾ­³ÉÎªÖØÒªµÄ¶ñÒâÈí¼þϰȾý½é £»£»£»£»£»£»¶ñÒâ¿ó¹¤³ÉΪ·¸×ï·Ö×ӵijÁÒª»ñÀû¼¿Á© £»£»£»£»£»£»¹ú¶ÈÔÞÖúµÄ·¸×ïÍÅ»ïÔ½À´Ô½¶àµØ¶Ô×¼ÒøÐÐ £»£»£»£»£»£»ÓÉÓÚ¶ÌȱµÍ¶ËÎïÁªÍøÉ豸ºÍ·þÎñµÄ± £»£»£»£»£»£»¤»úÔ죬£¬£¬£¬£¬£¬¶ÔͨÓÃÎïÁªÍø± £»£»£»£»£»£»¤¼Ü¹¹/ÓÅÁ¼Êµ¼ÊµÄÐèÒªÒÀÈ»ÊÇÒ»¸ö½ôÆÈµÄÎÊÌâ £»£»£»£»£»£»Íþвµý±¨±ØÒªÊ¹ÓÃеÄ×Ô¶¯»¯¹¤¾ßºÍ²½ÖèÀ´Ó¦¶Ô×Ô¶¯»¯µÄ¹¥»÷ £»£»£»£»£»£»°²È«ÁìÓòÓ¦¸Ã³Áµã¹Ø×¢È˲źͼ¼ÊõµÄÅàѵ¡£¡£ ¡£¡£¡£¡£¡£¡£¸Ã»ã±¨»¹´ÓÕþ²ß¡¢ÆóÒµÒÔ¼°¼¼Êõ¡¢×êÑкͽÌÓý·½ÃæÌá³öÁ˽¨Òé¡£¡£ ¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.enisa.europa.eu/publications/enisa-threat-landscape-report-2018/

4¡¢Ó¡¶È¹ú¶ÈÒøÐÐSBIÒâ±íй¶Êý°ÙÍò¿Í»§ÐÅÏ¢

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ÄäÃû°²È«×êÑÐÈËÔ±·¢ÏÖһ̨ÓÃÓÚÒøÐмӿì·þÎñµÄ·þÎñÆ÷£¬£¬£¬£¬£¬£¬ÕâÊÇÒ»ÖÖ»ùÓÚÒÆ¶¯µÄÐÅÏ¢·þÎñ¡£¡£ ¡£¡£¡£¡£¡£¡£¸ÃÊý¾Ý¿âÔÚûÓб £»£»£»£»£»£»¤µÄÇé¿öϱ»¹«¿ª£¬£¬£¬£¬£¬£¬¸ÃÊý¾Ý¿âÔ̺¬Êý°ÙÍòÌõ¶ÌÐÅ£¬£¬£¬£¬£¬£¬¿É×·Òäµ½12Ô·Ý£¬£¬£¬£¬£¬£¬Ô̺¬¿Í»§µÄµç»°ºÅÂ룬£¬£¬£¬£¬£¬²¿ÃÅÒøÐÐÕ˺Å£¬£¬£¬£¬£¬£¬ÒøÐÐÓà¶îºÍÂòÂô¼Í¼¡£¡£ ¡£¡£¡£¡£¡£¡£ºÃÐÂÎÅÊÇ£¬£¬£¬£¬£¬£¬Ó¡¶È¹ú¶ÈÒøÐÐÔÚµÃÖªÎÊÌâºóÊýÓ×ʱÄÚѸËÙ½â¾öÁËÕâ¸öÎÊÌ⣬£¬£¬£¬£¬£¬Òź¶µÄÊÇ£¬£¬£¬£¬£¬£¬²»ÖªÂ·Êý¾ÝÔÚÍøÉ϶³öÁ˶೤¹¦·ò¡£¡£ ¡£¡£¡£¡£¡£¡£ÕâЩÐÅÏ¢µÄ¿ÉÓÃÐÔ¸øÒøÐпͻ§´øÀ´ÁËÑϳÁµÄ·çÏÕ£¬£¬£¬£¬£¬£¬ÍþвÐÐΪÕßÄܹ»Ê¹ÓÃËüÀ´¶Ô×¼ÒøÐпͻ§¡£¡£ ¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/80555/data-breach/state-bank-of-india-leak.html

5¡¢ºÉÀ¼DPA°ä²¼2018ÄêÊý¾Ýй¶ͳ¼Æ»ã±¨

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


2019Äê1ÔÂ29ÈÕ£¬£¬£¬£¬£¬£¬ºÉÀ¼Êý¾Ý± £»£»£»£»£»£»¤¾Ö£¨Autoriteit Persoonsgegevens£¬£¬£¬£¬£¬£¬¡°ºÉÀ¼DPA¡±£©°ä·¢ÁËÒ»·Ý»ã±¨¹ØÓÚ2018ÄêÊÕµ½µÄÓ×ÎÒÊý¾Ýй¶֪ͨ£¨¡°»ã±¨¡±£©¡£¡£ ¡£¡£¡£¡£¡£¡£Å·ÃËͨÓÃÊý¾Ý± £»£»£»£»£»£»¤ÂÉÀý£¨¡°GDPR¡±£©ÒªÇóÊý¾ÝÖÎÀíÔ±ÔÚ֪ϤºóµÄ72Ó×ʱÄÚ½«Êý¾Ýй¶֪ͨÖ÷¹ÜÊý¾Ý± £»£»£»£»£»£»¤¾Ö£¨¡°DPA¡±£©¡£¡£ ¡£¡£¡£¡£¡£¡£ÔÚºÉÀ¼£¬£¬£¬£¬£¬£¬×Ô2016Äê1ÔÂ1ÈÕÆð£¬£¬£¬£¬£¬£¬¸ÃÎ¥¹æÍ¨ÖªÒªÇóÒѾ­Ö´ÐС£¡£ ¡£¡£¡£¡£¡£¡£µ«ÊÇ£¬£¬£¬£¬£¬£¬GDPR»®¶¨Á˶î±íµÄÒªÇ󣬣¬£¬£¬£¬£¬Ô̺¬£ºÔÚÎ¥¹æÍ¨ÖªÖÐÌṩijЩÐÅÏ¢; ÈôÊÇÎ¥¹æÐÐΪ¿ÉÄܶÔÕâЩÈ˵ÄÈ¨ÊÆºÍ×ÔÓÉÔì³É¸ß·çÏÕ£¬£¬£¬£¬£¬£¬Êý¾ÝÖÎÀíÔ±ÓÐʹÃü֪ͨÊÜÓ°ÏìµÄÓ×ÎÒ; ¹«Ë¾ÓÐʹÃü¼Í¼ÈκÎÓ×ÎÒÊý¾Ýй¶ÊÂÎñ¡£¡£ ¡£¡£¡£¡£¡£¡£2018Ä꣬£¬£¬£¬£¬£¬ºÉÀ¼DPAÊÕµ½µÄÊý¾Ýй¶֪ͨÊýÁ¿Ôö³¤ÁËÒ»±¶£¬£¬£¬£¬£¬£¬¹²¼Æ20,881´ÎÎ¥¹æÍ¨Öª¡£¡£ ¡£¡£¡£¡£¡£¡£ÊÜÓ°Ïì×î´óµÄ²¿ÃÅÊǽ¡È«ºÍ¸£Àû²¿ÃÅ£¨´«µÝµÄÎ¥¹æÐÐΪµÄ29£¥£©£¬£¬£¬£¬£¬£¬½ðÈÚ²¿ÃÅ£¨Í¨ÖªµÄÎ¥¹æÐÐΪµÄ26£¥£©ºÍ¹«¹²²¿ÃÅ£¨17£¥µÄÎ¥¹æÍ¨Öª£©¡£¡£ ¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.databreaches.net/dutch-dpa-publishes-2018-report-on-data-breach-statistics/

ÉêÃ÷£º±¾×ÊѶÓÉ8827Ì«Ñô¼¯ÍÅάËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù