ÐÅÏ¢°²È«Öܱ¨-2019ÄêµÚ21ÖÜ
°ä²¼¹¦·ò 2019-06-03±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
2019Äê5ÔÂ27ÈÕÖÁ6ÔÂ02ÈÕ¹²ÊÕ¼°²È«·ì϶53¸ö£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇApache HadoopÔ¶³ÌȨÏÞÌáÉý·ì϶£»£»£»£»£»£»£»ISC BIND EDNS¿Í»§¶Ë×ÓÍøÖ°ÄÜÔ¶³Ì»Ø¾ø·þÎñ·ì϶£»£»£»£»£»£»£» Adobe Flash Player¿ªÊͺóʹÓôúÂëÖ´Ðзì϶£»£»£»£»£»£»£»HPE Intelligent Management Center ByteMessageResource transformEntity·´ÐòÁл¯´úÂëÖ´Ðзì϶£»£»£»£»£»£»£»Serv-U FTP ServerȨÏÞÌáÉý·ì϶¡£¡£¡£¡£¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖС£¡£¡£¡£¡£
³ÁÒª°²È«·ì϶Áбí
Apache Hadoop´æÔÚÒ»¸ö°²È«·ì϶£¬£¬£¬£¬£¬£¬ÔÊÐíÕ¼ÓÐYAMȨÏÞµÄÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬Äܹ»rootÓû§Éí·ÝÔËÐÐËÁÒâºÅÁî¡£¡£¡£¡£¡£
https://seclists.org/oss-sec/2019/q2/132
2. ISC BIND EDNS¿Í»§¶Ë×ÓÍøÖ°ÄÜÔ¶³Ì»Ø¾ø·þÎñ·ì϶
ISC BINDµÝ¹é½âÎöÆ÷µÄEDNS¿Í»§¶Ë×ÓÍø´æÔÚÒ»¸ö°²È«·ì϶£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬´¦ÖÃÔ̺¬RRSIGµÄÏìÓ¦µÄ±¨ÎÄʱ¿Ìʹ·þÎñÆ÷±ÀÀ£¡£¡£¡£¡£¡£
https://kb.isc.org/docs/cve-2019-6469
3. Adobe Flash Player¿ªÊͺóʹÓôúÂëÖ´Ðзì϶
Adobe Flash Player´æÔÚ¿ªÊͺóÀûÓ÷ì϶£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇ󣬣¬£¬£¬£¬£¬ÓÕʹÓû§ÒªÇ󣬣¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»£»£»òÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£
https://helpx.adobe.com/security/products/flash-player/apsb19-26.html
4. HPE Intelligent Management Center ByteMessageResource transformEntity·´ÐòÁл¯´úÂëÖ´Ðзì϶
HPE Intelligent Management Center ByteMessageResource transformEntity²½Öè´æÔÚ·´ÐòÁл¯·ì϶£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬¿ÉÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£
https://www.zerodayinitiative.com/advisories/ZDI-19-528/
5. Serv-U FTP ServerȨÏÞÌáÉý·ì϶
WindowsϵÄServ-U FTP ServerÑéÖ¤´¦ÖôæÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬ÔÊÐí±¾µØ¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬¿ÉÌáÉýȨÏÞ¡£¡£¡£¡£¡£
https://packetstormsecurity.com/files/153128/Serv-U-FTP-Server-15.1.6.25-Local-Privilege-Escalation.html
³ÁÒª°²È«ÊÂÎñ×ÛÊö
¾ÝŦԼʱ±¨±¨Â·£¬£¬£¬£¬£¬£¬ÃÀ¹ú½ðÈÚ¹«Ë¾First American Financial Corporation¹ÙÍøÉϵÄÒ»¸ö·ì϶й¶ÁË16ÄêÀ´ÓëµÖѺ´û¿îÓйصÄ8.85Òڱʼͼ¡£¡£¡£¡£¡£¸Ã·ì϶ÔÊÐíÈκÎÈ˽ӼûFirst American´æ´¢µÄÉç»á°²È«ºÅÂë¡¢ÒøÐÐÕË»§¾ßÌåÐÅÏ¢¡¢¼ÝÕÕÒÔ¼°µÖѺ´û¿îºÍ˰ÎñÐÅÏ¢¡£¡£¡£¡£¡£¸Ã¹«Ë¾°µÊ¾ÔÚÆÀ¹À´ËÊÂÎñ¶Ô¿Í»§ÐÅÏ¢°²È«ÐÔµÄÓ°Ï죬£¬£¬£¬£¬£¬ÔÚÄÚ²¿ÉóºËʵÏÖ֮ǰ£¬£¬£¬£¬£¬£¬½«²»»á°ä·¢ÈÎºÎÆÀÂÛ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.nytimes.com/2019/05/24/technology/data-leak-first-american.html
2¡¢ÒÔÉ«ÁÐÓÎÀÀ¹«Ë¾AmadeusÒâ±íй¶1500Íò³Ë¿ÍÐÅÏ¢
ÔÎÄÁ´½Ó£º
https://www.calcalistech.com/ctech/articles/0,7340,L-3762693,00.html
3¡¢Î÷ÃÅ×Ó¶à¿îÒ½ÁÆÉ豸Ò×ÊÜWindows BlueKeep·ì϶ӰÏì
ƾ¾ÝÎ÷ÃÅ×Ó°ä²¼µÄ°²È«²¼¸æ£¬£¬£¬£¬£¬£¬¶à¿îÎ÷ÃÅ×ÓÒ½ÁÆÉ豸Ò×ÊÜWindows RDP·þÎñBlueKeep·ì϶µÄÓ°Ï죬£¬£¬£¬£¬£¬Ô̺¬MagicLinkA¡¢MagicViewµÈÈí¼þ²úÆ·£¬£¬£¬£¬£¬£¬System ACOM¡¢SensisµÈ¸ß¼¶Ò½ÖβúÆ·£¬£¬£¬£¬£¬£¬Axiom¡¢MobilettµÈXÉäÏßÉ豸ÒÔ¼°Atellica¡¢AptioµÈ³¢ÊÔÊÒÕï¶Ï²úÆ·¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÒÑÒªÇó¿Í»§×°ÖÃ΢ÈíµÄ½¨¸´²¹¶¡£¡£¡£¡£¡£¬£¬£¬£¬£¬£¬µ«²»Äܱ£Õϲ¹¶¡µÄ¼æÈÝÐÔ£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾½¨ÒéÓû§²ÉÈ¡½ûÓÃRDP¡¢×èÖ¹TCP¶Ë¿Ú3389µÈ»º½â´ëÊ©¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/86222/security/siemens-healthineers-bluekeep.html
4¡¢Docker佨¸´µÄ¾ºÕùǰÌá·ì϶£¬£¬£¬£¬£¬£¬Ó°ÏìËùÓÐDocker°æ±¾
×êÑÐÈËÔ±Åû¶DockerÖÐ佨¸´µÄ¾ºÕùǰÌá·ì϶£¬£¬£¬£¬£¬£¬¸Ã·ì϶ӰÏìÁËËùÓеÄDocker°æ±¾¡£¡£¡£¡£¡£¸Ã·ì϶ÀàËÆÓÚCVE-2018-15664£¬£¬£¬£¬£¬£¬¿ÉÔÊÐí¹¥»÷ÕßÔÚÖ¸¶¨µÄ·¨Ê½¶Ô×ÊÔ´½øÐвÙ×÷֮ǰÅú¸Ä×ÊÔ´õè¾¶£¬£¬£¬£¬£¬£¬´Ó¶ø¿ÉÄÜ»ñµÃËÁÒâÎļþµÄ¶Áд½Ó¼ûȨÏÞ£¬£¬£¬£¬£¬£¬Õâ±»³ÆÎªTOCTOUÀàÐ͵Äbug¡£¡£¡£¡£¡£¸Ã·ì϶µÄÖ÷ÌâÔ´ÓÚFollowSymlinkInScopeÖ°ÄÜÒ×ÊÜTOCTOU¹¥»÷¡£¡£¡£¡£¡£×êÑÐÈËÔ±ÒѾ°ä²¼ÁËPoC´úÂë¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/unpatched-flaw-affects-all-docker-versions-exploits-ready/
5¡¢¹È¸è×êÑÐÈËÔ±ÔÚWindows¼Çʱ¾Öз¢ÏÖ´úÂëÖ´Ðзì϶
Google Project Zero×êÑÐÔ±Tavis OrmandyÔÚ΢ÈíµÄWindows¼Çʱ¾Öз¢ÏÖÒ»¸ö´úÂëÖ´Ðзì϶£¬£¬£¬£¬£¬£¬OrmandyÒÑÏò΢Èí»ã±¨Á˸ÃÎÊÌâ¡£¡£¡£¡£¡£·ì϶µÄϸ½ÚÉÐδÅû¶£¬£¬£¬£¬£¬£¬µ«OrmandyÔ¤¼Æ¸Ã·ì϶ÊÇÒ»¸öÄÚ´æ°Ü»µ·ì϶£¬£¬£¬£¬£¬£¬ËûÔÚTwitterÉÏ·ÖÏíµÄͼƬÑÝʾÁËÈôºÎÔÚ¼Çʱ¾Öе¯³öshell¡£¡£¡£¡£¡£Æ¾¾Ý¹È¸èµÄ·ì϶Åû¶Õþ²ß£¬£¬£¬£¬£¬£¬Ormandy½«ÔÚ90Ììºó»ò΢Èí°ä²¼½¨¸´²¹¶¡ºóÅû¶¸ü¶à·ì϶ϸ½Ú¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/86297/hacking/code-execution-flaw-notepad.html


¾©¹«Íø°²±¸11010802024551ºÅ