ÐÅÏ¢°²È«Öܱ¨-2019ÄêµÚ44ÖÜ

°ä²¼¹¦·ò 2019-11-12

>±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2019Äê11ÔÂ04ÈÕÖÁ10ÈÕ¹²ÊÕ¼°²È«·ì϶46¸ö£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇFuji Electric V-Server CVE-2019-18240»º³åÇøÒç¶Âí½Å; Cisco Small Business RV016, RV042, RV042G, RV082 CVE-2019-15271ËÁÒâºÅÁîÖ´Ðзì϶£»£» £»£»£»£»TYPO3ÅäÖñäÁ¿fileDenyPatternËÁÒâ´úÂëÖ´Ðзì϶£»£» £»£»£»£»Atlassian Jira Service Desk ServerĿ¼±éÀú·ì϶£»£» £»£»£»£»Aruba Networks ClearPass Policy ManagerÊý¾Ý¿âƾ֤й¶·ì϶ ¡£¡£¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊǶíÂÞ˹¡°Ö÷Ȩ»¥ÁªÍø¡±Ë¾·¨ÉúЧ£¬£¬£¬£¬£¬£¬¿ÉÓëÈ«Çò»¥ÁªÍø¶Ï¿ª£»£» £»£»£»£»ºÚ¿Í¿ÉÀûÓü¤¹âÈëÇÖGoogleÖÇÄÜÓïÒô¸±ÊÖ£»£» £»£»£»£»Libarchive´úÂëÖ´Ðзì϶ӰÏìLinux¼°BSD¿¯Ðаæ£»£» £»£»£»£»Ç÷Ïò¿Æ¼¼ÄÚ²¿Ô±¹¤ÇÔÈ¡³¬¹ý12ÍòÓû§ÐÅÏ¢²¢ÏúÊÛ£»£» £»£»£»£»2019ÄêÇï¼¾´¹µö¹¥»÷»î¶¯Ôö³¤ÖÁÈýÄêÀ´×î¸ß¼Í¼ ¡£¡£¡£¡£¡£¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖÐ ¡£¡£¡£¡£¡£¡£



>³ÁÒª°²È«·ì϶Áбí


1. Fuji Electric V-Server CVE-2019-18240»º³åÇøÒç¶Âí½Å


Fuji Electric V-Server´æÔÚ»º³åÇøÒç¶Âí½Å£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£» £»£»£»£»òÖ´ÐÐËÁÒâ´úÂë ¡£¡£¡£¡£¡£¡£

https://www.us-cert.gov/ics/advisories/icsa-19-311-02


2. Cisco Small Business RV016, RV042, RV042G, RV082 CVE-2019-15271ËÁÒâºÅÁîÖ´Ðзì϶


Cisco RV016 Multi-WAN VPN RouterûÓжÔHTTP payload½øÐÐÊäÈëÑéÖ¤´¦Ö㬣¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬¿ÉÖ´ÐÐËÁÒâOSºÅÁî ¡£¡£¡£¡£¡£¡£

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20191106-sbrv-cmd-x


3. TYPO3ÅäÖñäÁ¿fileDenyPatternËÁÒâ´úÂëÖ´Ðзì϶


TYPO3ÅäÖñäÁ¿fileDenyPatternÖµ´¦ÖôæÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬Ö´ÐÐËÁÒâ´úÂë ¡£¡£¡£¡£¡£¡£

https://typo3.org/security/advisory/typo3-sa-2010-012


4. Atlassian Jira Service Desk ServerĿ¼±éÀú·ì϶


Atlassian Jira Service Desk Server´æÔÚĿ¼±éÀú·ì϶£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎĶÁȡϵͳÎļþÄÚÈÝ ¡£¡£¡£¡£¡£¡£

https://jira.atlassian.com/browse/JSDSERVER-6589


5. Aruba Networks ClearPass Policy ManagerÊý¾Ý¿âƾ֤й¶·ì϶


Aruba Networks ClearPass Policy Manager´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬»ñÈ¡Êý¾Ý¿âƾ֤ ¡£¡£¡£¡£¡£¡£

https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2016-010.txt



>³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢¶íÂÞ˹¡°Ö÷Ȩ»¥ÁªÍø¡±Ë¾·¨ÉúЧ£¬£¬£¬£¬£¬£¬¿ÉÓëÈ«Çò»¥ÁªÍø¶Ï¿ª


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


¶íÂÞ˹¡°Ö÷Ȩ»¥ÁªÍø¡±Ë¾·¨ÔÚÉÏÖÜÎåÉúЧ£¬£¬£¬£¬£¬£¬Õ⽫ʹ¶íÂÞ˹µ±¾Ö¿ÉÄܽ«¸Ã¹úÓëÈ«Çò»¥ÁªÍø¶Ï¿ªÏÎ½Ó ¡£¡£¡£¡£¡£¡£ÕâÏî˾·¨ÓÉÆÕ¾©×ÜͳÔÚ5Ô·ÝÇ©Ê𣬣¬£¬£¬£¬£¬ÒªÇóISP×°Öõ±¾ÖÌṩµÄ¼¼ÊõÉ豸ÒÔ½øÐÐÁ÷Á¿²é³­£¬£¬£¬£¬£¬£¬Õâ¿ÉÄÜΪ´ó¹æÄ£¼à¶½´ò¿ªÁË´óÃÅ ¡£¡£¡£¡£¡£¡£Æ¾¾Ý¶íÂÞ˹µ±¾ÖµÄ˵·¨£¬£¬£¬£¬£¬£¬¸Ã˾·¨Ö¼ÔÚÈ·±£¼´±ã¶Ï¿ªÓëÈ«Çò»¥ÁªÍøµÄÏνÓÒ²Äܹ»½Ó¼û¶íÂÞ˹վµã£¬£¬£¬£¬£¬£¬ÒÔÓ¦¶ÔÓÉÍøÂç¹¥»÷»ò°²È«ÊÂÎñµ¼ÖµÄÖÐ¶Ï ¡£¡£¡£¡£¡£¡£¸Ã˾·¨½«Ê¹¶íÂÞ˹µ±¾Ö¿ÉÄÜÉó²éÔÚÏßÄÚÈݲ¢¼à¶½ÍøÃñ ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/93315/laws-and-regulations/russia-controversial-law-russia.html


2¡¢ºÚ¿Í¿ÉÀûÓü¤¹âÈëÇÖGoogleÖÇÄÜÓïÒô¸±ÊÖ


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


½üÆÚ£¬£¬£¬£¬£¬£¬ÈÕ±¾µç×ÓͨѶ´óѧºÍÃÜЪ¸ù´óѧµÄ×êÑÐÈËÔ±·¢ÏÖ¿Éͨ¹ý¼¤¹âÈëÇֹȸ衢ƻ¹ûºÍÑÇÂíÑ·µÄÖÇÄÜÓïÒôÉ豸 ¡£¡£¡£¡£¡£¡£ÕâÖÖ±»³ÆÎª¡°¹âºÅÁµÄ¹¥»÷¿Éͨ¹ýÏòʹÓÃ΢»úµçϵͳ£¨MEMS£©µÄÂó¿Ë·çÉÏ·¢É伤¹âÊøÊµÏÖ£¬£¬£¬£¬£¬£¬Í¨¹ýµ÷Ôì¹âÊøµÄÇ¿¶È£¬£¬£¬£¬£¬£¬Äܹ»ÓÕÆ­MEMS²úÉúÓëÒôƵºÅÁîÒ»ÑùµÄµçÐźţ¬£¬£¬£¬£¬£¬×îÔ¶ÉõÖÁÄܹ»´Ó110Ã×±í¹¥»÷ ¡£¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄÉ豸Ô̺¬¹È¸èHome¡¢Nest Cam¡¢ÑÇÂíÑ·Echo¡¢Fire Cube TV¡¢iPhone¡¢ÈýÐÇGalaxy S9¡¢¹È¸èPixelºÍiPad ¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±Ö¤Ã÷¸Ã¹¥»÷ÉõÖÁÄܹ»´ò¿ª³µ¿âÃÅ»ò½âËø·¿ÎÝÃÅ ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/using-light-beams-to-control-google-apple-amazon-assistants/


3¡¢Libarchive´úÂëÖ´Ðзì϶ӰÏìLinux¼°BSD¿¯Ðаæ


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


¹È¸è°²È«×êÑÐÈËÔ±ÔÚLibarchiveÖз¢ÏÖÒ»¸ö´úÂëÖ´Ðзì϶£¨CVE-2019-18408£©£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÓÕʹÓû§´ò¿ª¶ñÒâ´æµµÎļþÔÚÆäϵͳÉÏÖ´ÐдúÂë ¡£¡£¡£¡£¡£¡£Debian¡¢Ubuntu¡¢Gentoo¡¢Arch LinuxÒÔ¼°FreeBSDºÍNetBSD¿¯Ðаæ¾ùÊÜÓ°Ï죬£¬£¬£¬£¬£¬µ«WindowsºÍmacOS²»ÊÜÓ°Ïì ¡£¡£¡£¡£¡£¡£LibarchiveÍŶÓÔÚа汾3.4.0Öн¨¸´Á˸÷ì϶£¬£¬£¬£¬£¬£¬Ä¿Ç°ÉÐδÔÚÒ°±í·¢Ïָ÷ì϶µÄPoC»òÀûÓôúÂë ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/libarchive-vulnerability-can-lead-to-code-execution-on-linux-freebsd-netbsd/


4¡¢Ç÷Ïò¿Æ¼¼ÄÚ²¿Ô±¹¤ÇÔÈ¡³¬¹ý12ÍòÓû§ÐÅÏ¢²¢ÏúÊÛ


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Ç÷Ïò¿Æ¼¼ÄÚ²¿Ô±¹¤ÇÔÈ¡¹«Ë¾¿Í»§ÐÅÏ¢²¢½«ÆäÏúÊÛ¸øµÚÈý·½Ú¿Æ­ÍÅ»ï ¡£¡£¡£¡£¡£¡£ÔÚ¿Í»§Ôâµ½¼¼ÊõÖ§³¶à¿Æ­ºó£¬£¬£¬£¬£¬£¬Ç÷Ïò¿Æ¼¼·¢Õ¹µ÷²é²¢·¢ÏÖ¸ÃÔ±¹¤·¸·¨½Ó¼ûÁ˿ͻ§Ö§³ÖÊý¾Ý¿â ¡£¡£¡£¡£¡£¡£¿£¿ £¿£¿£¿£¿£¿£¿ÉÄܱ»ÇÔµÄÐÅÏ¢Ô̺¬¿Í»§µÄÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢¼¼ÊõÖ§³Öµ¥ºÅÒÔ¼°µç»°ºÅÂ룬£¬£¬£¬£¬£¬µ«¸Ã¹«Ë¾Ç¿µ÷ûÓм£ÏóÅú×¢²ÆÕþ»òÐÅÓþ¿¨ÐÅÏ¢±»ÇÔ£¬£¬£¬£¬£¬£¬²¢ÇÒûÓÐÉæ¼°µ½ÆóÒµ»òµ±¾Ö¿Í»§ ¡£¡£¡£¡£¡£¡£Æ¾¾ÝÆäÄÚ²¿µ÷²é£¬£¬£¬£¬£¬£¬ÊÜÓ°ÏìµÄ¿Í»§Ö»Õ¼Ç÷Ïò¿Æ¼¼1200Íò¿Í»§ÈºµÄ²»µ½1%£¬£¬£¬£¬£¬£¬¼´12Íò ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/trendmicro-employee-sold-customer-info-to-tech-support-scammers/


5¡¢2019ÄêÇï¼¾´¹µö¹¥»÷»î¶¯Ôö³¤ÖÁÈýÄêÀ´×î¸ß¼Í¼


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ƾ¾ÝAPWGµÄͳ¼ÆÊý¾Ý£¬£¬£¬£¬£¬£¬2019ÄêÇï¼¾ÍøÂç´¹µö¹¥»÷Ôö³¤ÖÁÈýÄêÀ´µÄ×î¸ß¼Í¼ ¡£¡£¡£¡£¡£¡£ÔÚ2019Äê7ÔÂÖÁ9ÔÂÆÚ¼ä¼ì²âµ½µÄ´¹µöÍøÕ¾×ÜÊýΪ266387£¬£¬£¬£¬£¬£¬±È2019ÄêµÚ¶þ¼¾¶ÈµÄ182465Ôö³¤ÁË46%£¬£¬£¬£¬£¬£¬ÏÕЩÊÇ2018ÄêµÚËÄʱ¶ÈµÄ138328µÄÁ½±¶ ¡£¡£¡£¡£¡£¡£³ýÁË´¹µöÍøÕ¾ÊýÁ¿µÄÔö³¤Ö®±í£¬£¬£¬£¬£¬£¬2019ÄêµÚÈý¼¾¶ÈÊÜ´¹µö¹¥»÷µÄÆ·ÅÆÊýÁ¿Ò²ÏÔÖøÔö³¤£¬£¬£¬£¬£¬£¬¾ùÔÈÿÔÂÓÐ400¶à¸öÆ·ÅÆÊܵ½¹¥»÷£¬£¬£¬£¬£¬£¬¶øµÚ¶þ¼¾¶ÈΪ313¸ö ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.helpnetsecurity.com/2019/11/07/phishing-attacks-levels-rise/