ADLab2019ÄêÇå¾²Ñо¿»ØÊ×
Ðû²¼Ê±¼ä 2019-12-312019Ä꣬ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøADLabÑо¿Æ«ÏòÖصã°üÀ¨Ö÷Á÷²Ù×÷ϵͳ¼°Ó¦ÓÃÇå¾²Ñо¿¡¢WebÇå¾²Ñо¿¡¢Òƶ¯»¥ÁªÍøÇå¾²Ñо¿¡¢ÎïÁªÍøÇå¾²Ñо¿¡¢¹¤¿Ø»¥ÁªÍøÇå¾²Ñо¿ºÍÇø¿éÁ´Çå¾²Ñо¿£¬ÆäÖв¿·ÖÑо¿ÎÄÕÂÒÑͨ¹ýADLab¹«ÖÚƽ̨Ðû²¼£¬ÎªÀû±ã¸÷È˲éÔÄÎÒÃǶÔÕûÄêÐû²¼µÄÖ÷ÒªÑо¿ÎÄÕ¾ÙÐÐÁËÕûÀí¡£
ÈÈÃÅÊÂÎñͨ¸æ
¡¾Ô´´Îó²î¡¿Adobe ColdFusion ·´ÐòÁл¯RCEÎó²îÆÊÎö
ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøADLab·¢Ã÷Adobe ColdFusionÖÐFlashGateway·þÎñ±£´æCritical£¨Î£¼±£©·´ÐòÁл¯Îó²î£¨CVE-2019-7091£©£¬Ê¹ÓøÃÎó²î¹¥»÷Õß¿ÉÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£
¡¾Îó²îͨ¸æ¡¿LinuxÄں˱£´æÍâµØÌáȨÎó²î£¨CVE-2019-8912£©
¡¾Ô´´Îó²î¡¿LinuxÄÚºËMarvell WI-FIоƬÇý¶¯Îó²î£¨CVE-2019-3846/CVE-2019-10126£©
¡¾Ô´´Îó²î¡¿LinuxÄÚºËMarvell WI-FIоƬÇý¶¯¶à¸öÔ¶³ÌÎó²î
Linux git±£´æÍâµØÌáȨÎó²î£¬¿ÉÒÔµ¼ÖÂÍâµØ´úÂëÖ´ÐоÙÐÐȨÏÞÌáÉý¡£LinuxÄÚºËMarvell WI-FIоƬÇý¶¯±£´æ¶à¸öÔ¶³ÌÒç³öÎó²îºÍÍâµØÒç³öÎó²î£¬¿Éµ¼Ö¾ܾø·þÎñ£¨ÏµÍ³Í߽⣩»òí§Òâ´úÂëÖ´ÐС£Îó²îÓ°Ïì¹æÄ£½Ï¹ã¡£
¡¾Ô´´Îó²î¡¿WebLogicí§ÒâÎļþ¶ÁÈ¡Îó²î£¨CVE-2019-2615£©
¡¾Ô´´Îó²î¡¿WebLogic Blind XXEÎó²î£¨CVE-2019-2647£©
¡¾Ô´´Îó²î¡¿WebLogic Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î£¨CVE-2019-2725²¹¶¡Èƹý£©
¡¾Ô´´Îó²î¡¿WebLogic ·´ÐòÁл¯Îó²î£¨CVE-2019-2890£©
¡¾Ô´´Îó²î¡¿WebLogic Blind XXEÎó²î£¨CVE-2019-2887£©
ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøADLab·¢Ã÷WebLogic±£´æÉÏÊöÎó²î£¬¹¥»÷Õß¿ÉÔÚÒÑÖªÓû§ÃûÃÜÂëµÄÇéÐÎ϶ÁÈ¡WebLogic·þÎñÆ÷ÖеÄí§ÒâÎļþ£»¿ÉÔÚδÊÚȨµÄÇéÐÎÏÂʵÏÖ¶Ô±£´æÎó²îµÄWebLogic×é¼þ¾ÙÐÐÔ¶³ÌBlind XXE¹¥»÷£»¿ÉÔڵͰ汾JDKµÄÇéÐÎÖÐÈƹý²¹¶¡È±Ïݵ¼ÖÂí§ÒâÔ¶³ÌÏÂÁîÖ´ÐУ»¿Éͨ¹ýT3ÐÒé¶Ô±£´æÎó²îµÄWebLogic×é¼þʵÑéÔ¶³Ìí§Òâ´úÂë¹¥»÷¡£
¡¾Îó²îͨ¸æ¡¿²©Í¨Wi-FiÇý¶¯±£´æ¶à¸öÇå¾²Îó²î
²©Í¨wlÇý¶¯Öб£´æÁ½¸ö¶ÑÒç³öÎó²î£¨CVE-2019-9501¡¢CVE-2019-9502£©£¬¿ªÔ´µÄbrcmfmacÇý¶¯Öб£´æÊý¾ÝÖ¡ÑéÖ¤ÈƹýÎó²î£¨CVE-2019-9503£©ºÍ¶ÑÒç³öÎó²î(CVE-2019-9500£©¡£Î´¾ÊÚȨµÄ¹¥»÷Õßͨ¹ýÔ¶³Ì·¢ËͶñÒâµÄwifi°ü£¬ÔÚ×îÑÏÖصÄÇéÐÎÏ£¬¿ÉÒÔÔÚÊÜÓ°ÏìϵͳÖÐÖ´ÐÐí§Òâ´úÂë¡£
¡¾Ô´´Îó²î¡¿WebSphereÎó²î£¨CVE-2019-4505£©
ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøADLab·¢Ã÷Websphere±£´æí§ÒâÎļþ¶ÁÈ¡Îó²îCVE-2019-4505¡£Í¨¹ý¸ÃÎó²î£¬¹¥»÷Õß¿ÉÒÔ»ñÈ¡Ãô¸ÐÐÅÏ¢¶øµ¼Ö½øÒ»²½Ê¹Óá£Îó²îΣº¦Ë®Æ½½Ï´ó¡£
ÎïÁªÍøרÌâÆÊÎö
¹¤¿ØÊ®´óÍøÂç¹¥»÷ÎäÆ÷ÆÊÎö±¨¸æ
ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøADLab¶Ô2000ÄêÖ®ºóµÄ¹¤¿ØÍøÂç¹¥»÷ÊÂÎñ¾ÙÐÐÊáÀí£¬²¢É¸Ñ¡³öÊ®´ó¹¤¿ØÍøÂç¹¥»÷ÎäÆ÷£ºStuxnet¡¢Duqu¡¢Flame¡¢Havex¡¢Dragonfly2.0¡¢ BlackEnergy¡¢Industroyer¡¢GreyEnergy¡¢VPNFilterºÍTriton
£¬Éî¶ÈÆÊÎöÆä¹¥»÷Åä¾°¡¢Ä¿µÄ¡¢ÊÖ·¨ÒÔ¼°ÊÖÒÕÌØÕ÷£¬ÒÔ±ã¸÷È˶Թ¤Òµ¿ØÖÆϵͳËùÃæÁÙµÄÇå¾²ÍþвÓÐÒ»¸ö¸üΪÖÜÈ«µÄÊìϤ¡£
ºÚȸ¹¥»÷£ºÉî¶ÈÆÊÎö²¢ËÝÔ´Dofloo½©Ê¬ÎïÁªÍø±³ºóµÄ¡°ºÚȸ¡±
ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøADLab·¢Ã÷ConfluenceÔ¶³Ì´úÂëÖ´ÐÐÎó²îCVE-2019-3396±»Dofloo½©Ê¬ÍøÂç¼Ò×åÓÃÓÚ¹¥Õ¼×°±¸×ÊÔ´£¬Dofloo½©Ê¬¼Ò×å²»µ«×îÏÈʹÓøßΣÎó²î¾ÙÐй¥»÷£¬ÇÒÆä±³ºóµÄºÚ¿Í»¹Ê¹ÓÃÒ»ÖÖ¸ü¾ßÓ°ÏìÁ¦µÄ¡°ºÚȸ¹¥»÷¡±À´ÈëÇÖ¹¤ÒµÁ´¡£±¾ÎÄÏêϸÐðÊöÁ˺Úȸ¹¥»÷µÄ×îз¢Ã÷Àú³Ì£¬²¢ÉîÈëÆÊÎöÁËDofloo½©Ê¬ÍøÂç¼Ò×åÖÐËù±£´æµÄ¡°ºÚȸÕ÷Ïó¡±£»Í¬Ê±¶ÔÒþ²ØÔÚÆä±³ºóµÄºÚȸ¾ÙÐÐÉî¶ÈÍÚ¾òºÍ¶¨Î»£¬ÆÊÎö¸Ã½©Ê¬ÓëMrBlack¡¢DnsAmp¡¢Flood.AÖ®¼äµÄͬԴÌØÕ÷¡£
ÖÇÄÜÒôÏäÍøÂçÇå¾²ÓëÒþ˽Ñо¿±¨¸æ
±¾±¨¸æÖصãÆÊÎöÁËÖÇÄÜÒôÏäÃæÁÙµÄÇ徲Σº¦ºÍÒþ˽Σº¦¡£Í¨¹ý¶ÔÖÇÄÜÒôÏäµÄÑо¿£¬ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøADLab·¢Ã÷Á˲úÆ·Öб£´æÓÐÓ²¼þµ÷ÊÔ½Ó¿ÚÎó²î¡¢DLNA·þÎñԽȨÎó²î¡¢·þÎñ¶Ë¿ÚԽȨÎó²îµÈÊ®Óà¸öÇå¾²Îó²î£¬ÕâЩÎó²î¿ÉÔì³ÉδÊÚȨװ±¸¿ØÖÆ¡¢ÓïÒôÇÔÌý¡¢Ãô¸ÐÐÅϢй¶µÈ¡£ADLabÒѵÚһʱ¼äÏòCNVDºÍCNNVD¾ÙÐÐÁËÎó²îת´ï£¬²¢ÓëICSCERTÍŽáÐû²¼ÁË¡¶ÖÇÄÜÒôÏäÒþ˽ÓëÍøÂçÇå¾²ÆÊÎö±¨¸æ¡·¡£
VxWorks¶à¸öÔ¶³ÌÎó²îÆÊÎö
ÔÚ¹¤Òµ¡¢µçÁ¦¡¢ÄÜÔ´£¬º½¿Õº½ÌìµÈÐÐÒµÒªº¦»ù´¡ÉèÊ©ÖÐÆÕ±éʹÓõÄVxWorks±»·¢Ã÷±£´æ11¸ö0dayÎó²î±»³ÆΪURGENT/11£¬ÆäÖÐ6¸öÎó²îΪÑÏÖØÎó²î²¢¿ÉÒÔÔ¶³ÌÖ´ÐдúÂ루RCE£©£¬ÆäÓà5¸öÎó²î°üÀ¨¾Ü¾ø·þÎñ¡¢ÐÅϢй¶ºÍÂ߼ȱÏÝÎó²î¡£ÕâЩÎó²îÄܹ»Ê¹¹¥»÷ÕßÔ¶³Ì½ÓÊÜ×°±¸£¬¶øÎÞÐè½»»¥£¬ÉõÖÁ¿ÉÒÔÈƹý·À»ðǽµÈÖܱßÇå¾²×°±¸£¬ÕâÒâζ×ÅËüÃÇ¿ÉÓÃÓÚ½«¶ñÒâÈí¼þÈö²¥µ½ÍøÂçÄÚ²¿£¬ÕâÖÖ¹¥»÷¾ßÓкܴóµÄDZÁ¦£¬ÀàËÆÓÚWannaCry¶ñÒâÈí¼þµÄÈö²¥·½·¨¡£
ºÚ¿Í¹¥»÷ÓëÍþвÆÊÎö
¡°BankThief¡±- Õë¶Ô²¨À¼ºÍ½Ý¿ËµÄÐÂÐÍÒøÐд¹ÂÚ¹¥»÷
ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøADLab·¢Ã÷ÁËÒ»¿îȫеÄAndroidÒøÐд¹ÂÚľÂí¡±BankThief¡°£¬¸ÃľÂí½«×ÔÉíαװ³É¡°Google Play¡±Ó¦Ó㬿ÉÇÔÈ¡Êܺ¦Óû§µÄÒøÐеǼƾ֤¡£¹¥»÷Õß½«¿ØÖÆÖ¸ÁîÒþ²ØÔÚÇå¾²µÄFirebaseͨѶËíµÀÖУ¬Ê¹Æä¹¥»÷ÐÐΪԽ·¢Òþ²Ø¡£´Ë´Î¹¥»÷µÄÄ¿µÄÒøÐÐĬÈÏ°üÀ¨°üÀ¨»¨ÆìÒøÐÐÔÚÄÚµÄÈýÊ®¶à¼ÒÒøÐС£
СÐÄ£ººÚ¿ÍʹÓá°Á÷ÀëµØÇòƱ·¿ºì°ü¡±ÔÚ΢ÐÅÖÐÈö²¥¶ñÒâթƹã¸æ
ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøADLabÊÕµ½¿Í»§·´À¡£ºÔÚʹÓÃ΢ÐŵÄÀú³ÌÖÐÒÉËÆ·ºÆð¡°Öж¾¡±Õ÷Ïó£¬Óû§ÔÚȺÁÄÖÐÊÕµ½¡°Î¢ÐÅÓïÒô¡±£¬µã¿ªºóÈ´ÌáÐÑÁìÈ¡¡°Á÷ÀëµØÇòӰϷƱ·¿ºì°ü¡±¡£²»Ã÷ÕæÏàµÄÓû§·×·×ÖÐÕУ¬Ôì³ÉÖî¶àȺÁÄÖзºÆðÁË¡°ÈºÔ¼Ç롱 ¡¢¡°ÓïÒô¡±ºÍ¡°¹ã¸æ¡±µÈÓÕÆÐÔ·ÖÏíÁ´½Ó£¬²¢³É²¡¶¾Ê½¿ìËÙÈö²¥¡£Á´½ÓÖ¸Ïò¡°ÀÏÖÐÒ½¡±¡¢¡°Í¶×ÊÖ¸µ¼¡±ºÍ¡°µÍË×С˵¡±µÈ¶ñÒâ¹ã¸æ£¬ÓÕµ¼Óû§Ìí¼Ó΢ÐÅ»ò¹Ø×¢¹«Öںţ¬Ö®ºóÒ»²½²½Í¨¹ýÆÈ¡¶¨½ð»ò²ÊƱˢµ¥µÈÊÖ¶ÎÕ©ÆÓû§¹¤Òµ£¬ÉÔÓÐʧÉ÷¾Í»áÂäÈëȦÌס£
¡¾Ð¡ÐÄ¡¿¡°ÏÀµÁ¡±ÀÕË÷²¡¶¾V5.3бäÖÖÖÜÈ«ÆÊÎö
2019Äê4Ô£¬ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøADLab²¶»ñµ½ÁË¡°ÏÀµÁ¡±²¡¶¾×îбäÖÖ£¬¸Ã²¡¶¾µÄ°æ±¾ºÅΪV5.3£¬±àÒëʱ¼äΪ4ÔÂ14ÈÕ£¬¾àÀëÆäÉÏÒ»¸ö°æ±¾V5.2ÔÚÖйúËÁÅ°½ö½öÒ»¸ö¶àÔ¡£×ÔÆäÓÚ2018Äê1Ô½µÉúÖÁ½ñÒѾ¸üеü´úÁË5¸ö´óµÄ°æ±¾¡¢20¼¸¸öС°æ±¾¡£¡°ÏÀµÁ¡±×îÏÈËÁÅ°ÖйúµÄʱ¼äΪ2019Äê3ÔÂ11ÈÕ£¬²¢ÒÑѬȾÁËÎÒ¹úÉÏǧ̨Õþ¸®¡¢ÆóÒµºÍÏà¹Ø¿ÆÑлú¹¹µÄÅÌËã»ú¡£
ºÚʨÐж¯£ºÕë¶ÔÎ÷°àÑÀÓïµØÇøµÄ¹¥»÷Ô˶¯ÆÊÎö
ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøADLab¼à²âµ½Ò»ÅúÕë¶ÔÎ÷°àÑÀÓïµØÇøµÄÕþ¸®»ú¹¹¼°ÄÜÔ´ÆóÒµµÈ²¿·ÖµÄ¶¨Ïò¹¥»÷Ô˶¯£¬Í¨¹ý¶Ô¹¥»÷ÕßµÄÐÐΪºÍËùÓ÷þÎñÆ÷Ïà¹ØÐÅÏ¢µÄÆÊÎöºÍ×·×Ù£¬È·¶¨¸Ã´Î¹¥»÷ȪԴÓÚÒ»ÅúÒþÃضàÄêµÄÍÁ¶úÆäºÚ¿Í×éÖ¯-KingSqlZºÚ¿Í×éÖ¯¡£ÆäÔø¹¥ÏÝ3ǧ¶à¸öÍøÕ¾·þÎñÆ÷£¬²¢¸ßµ÷µÄÔÚ±»¹¥»÷ÍøÕ¾ÉÏÁôÏÂ×éÖ¯µÄÃû³Æ£¬ËæºóÏûÊÅÁ˶àÄê¡£ÎÒÃÇͨ¹ý¶Ô¡±ºÚʨÐж¯¡±µÄ×·×ÙÔÙ´ÎÍÚ³ö¸ÃºÚ¿Í×éÖ¯³ÉÔ±¼°Ô˶¯¼£Ï󣬲¢¶Ô¹¥»÷Ä¿µÄÒÔ¼°ÆäËùʹÓõĹ¥»÷ÎäÆ÷¾ÙÐÐÖÜÈ«ÁËÆÊÎö¡£
ÓÉÒ»¶ÎÉñÃØÎÄ×ÖËùÒý·¢µÄÊÓ²ìÓëÆÊÎö
ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøADLab¶Ô±ãÇ©ÍøÕ¾Pastebinƽ̨£¨¸Ãƽ̨¾³£±»ºÚ¿ÍÓÃÓÚ´æ´¢¹¥»÷Ч¹û£©ÄÚÈݾÙÐÐɸѡºÍÆÊÎö£¬·¢Ã÷ÁËÒ»¶ÎÉñÃضøÀëÆæµÄÖÐÎÄ×Ö·û¡£¸Ã¶ÎÎÄ×Ö±»´æ´¢ÔÚÒ»¸öÃûΪ¡°Unitled¡±µÄÓû§ÎļþÖУ¬´Ó×ÖÃæÉÏ¿´£¬ÕâÊÇÒ»¶ÎûÓÐÍêÕûÓïÒåµÄÎÄ×Ö£¬¿´ÆðÀ´¾ÍÏñ˽ÓïÒ»Ñù£¬ËƺõÆäÖÐÒþ²Ø×ÅһЩ²»ÎªÈËÖªµÄÐÅÏ¢¡£ÄÇôÕâ»áÊÇij¸öºÚ¿Í×éÖ¯»òÕßÇ鱨ְԱ֮¼äµÄÉñÃØÆìºÅÄØ£¬ÕÕ¾É˵½ö½öÖ»ÊÇËæ»úÊäÈëµÄºÁÎÞÒâÒåµÄÎÄ×Ö£¿±¾ÎĶÔÕâÆäÖÐÒþ²ØµÄÉñÃؾÙÐÐÁËÆÊÎö×·²é¡£
Õë¶ÔÖÆÒ©ÐÐÒµ¼°ÕþÆóµÄºÚ¿Í×éÖ¯×îй¥»÷Ô˶¯Éî¶ÈÆÊÎö
ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøADLab·¢Ã÷´ó×ÚʹÓøßΣÎó²îCVE-2017-11882¾ÙÐÐÍøÂç¹¥»÷µÄÊÂÎñ£¬Í¨Ì«¹ýÎöÎÒÃÇ·¢Ã÷ºÚ¿ÍµÄÎѵ㲢ÕÒµ½ÁËÊܺ¦ÈËÏà¹ØÐÅÏ¢£¬´ËÅúºÚ¿ÍÀÖ³ÉÉø͸½øÁ˵¹úºÍÓ¡¶ÈÄáÎ÷ÑǵĶà¼ÒÖÆÒ©ÆóÒµ£¬ÒÔ¼°Î÷°àÑÀµÄÕþ¸®¡¢ÆóÊÂÒµµ¥Î»µÈ»ú¹¹£¬²¢ÇÒ͵ȡÁË´ó×ÚµÄÃôÇéÐ÷±¨¡£Í¨¹ýËÝÔ´ÆÊÎöÈ·¶¨´Ë´Î¹¥»÷À´×ÔÓÚÄáÈÕÀûÑÇ£¬²¢ÓÉÄ¿½ñ¹¥»÷¹ØÁª³öÁ˸ü¶àºÚ¶ñÒâÓòÃûºÍÑù±¾¡£±¾ÎĶԺڿÍ×éÖ¯ËùʵÑéµÄ¹¥»÷Àú³Ì¾ÙÐÐÏêϸµØÆÊÎöºÍËÝÔ´£¬²¢¶ÔÆäËùʹÓõÄÌع¤Èí¼þºÍ»ù´¡ÉèÊ©¾ÙÐÐ͸³¹µØÆÊÎö¡£
¹ØÓÚÃÅÂÞ±Ò¹©Ó¦Á´¹¥»÷ÊÂÎñÆÊÎö
2019Äê11ÔÂ19ÈÕ£¬ÃÅÂÞ±Ò¹Ù·½githubÉÏ·ºÆð¶ÔÃÅÂÞ±Òrelease°æÓë¹ÙÍøÉÏ·ºÆð·×ÆçÖÂÎÊÌâµÄissues£¬ÆäÖÐÌá¼°·ºÆðÎÊÌâµÄÃÅÂޱҰ汾Ϊ×îаæ0.15.0.0¡£ÃÅÂÞ±Ò¹Ù·½ÈÏ¿ÉÆä¹ÙÍøÊܵ½ºÚ¿ÍÈëÇÖ£¬ÕâÊÇÊ״α»·¢Ã÷Õë¶Ô¼ÓÃÜÇ®±Ò¿Í»§¶ËµÄ¹©Ó¦Á´¹¥»÷¡£±¾ÎÄÏêϸÆÊÎöÁ˱»¸Ä¶¯µÄmonero-wallet-cli¶ñÒâÎļþ£¬²¢¶ÔºÚ¿ÍµÄ»ù´¡ÉèÊ©¾ÙÐÐ×·×ÙÆÊÎö£¬·¢Ã÷Á˺ڿÍËùʹÓùýµÄÆäËû»ù´¡ÉèÊ©¡£
Çå¾²Îó²îÆÊÎö
LinuxÄÚºËCVE-2017-11176Îó²îÆÊÎöÓ븴ÏÖ
LinuxÄÚºËÖеÄPOSIX ÐÂÎÅÐÐÁÐʵÏÖÖб£´æÒ»¸öUAFÎó²îCVE-2017-11176¡£¹¥»÷Õß¿ÉÒÔʹÓøÃÎó²îµ¼Ö¾ܾø·þÎñ»òÖ´ÐÐí§Òâ´úÂë¡£±¾ÎĽ«´ÓÎó²î³ÉÒò¡¢²¹¶¡ÆÊÎöÒÔ¼°Îó²î¸´Ïֵȶà¸ö½Ç¶È¶Ô¸ÃÎó²î¾ÙÐÐÏêϸÆÊÎö¡£
ThinkPHP5½¹µãÀàRequestÔ¶³Ì´úÂëÎó²îÆÊÎö
ThinkPHPÍŶÓÐû²¼²¹¶¡¸üУ¬ÐÞ¸´ÁËÒ»´¦ÓÉÓÚ²»Çå¾²µÄ¶¯Ì¬º¯ÊýŲÓõ¼ÖµÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬¸ÃÎó²îΣº¦Ë®Æ½ºÜÊǸߡ£ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøADLab¶ÔThinkPHP¶à¸ö°æ±¾¾ÙÐÐÁËÔ´ÂëÆÊÎöºÍÑéÖ¤£¬ÊÜÓ°Ïì°æ±¾ÎªThinkPHP5.0-5.0.23ÍêÕû°æ¡£
Windows DHCP ServerÔ¶³Ì´úÂëÖ´ÐÐÎó²îÆÊÎö£¨CVE-2019-0626£©
Windows DHCP Server±£´æÔ¶³Ì´úÂëÖ´ÐиßΣÎó²îCVE-2019-0626£¬µ±¹¥»÷ÕßÏòDHCP·þÎñÆ÷·¢ËÍÈ«ÐÄÉè¼ÆµÄÊý¾Ý°ü²¢ÀÖ³ÉʹÓú󣬾ͿÉÒÔÔÚDHCP·þÎñÖÐÖ´ÐÐí§Òâ´úÂ룬Îó²îÓ°Ïì¹æÄ£½Ï´ó¡£
Windows RDP·þÎñ¸ßΣÎó²îÆÊÎö£¨CVE-2019-0708£©
Windows RDP·þÎñµÄÔ¶³Ì´úÂëÖ´ÐиßΣÎó²îÓ°ÏìÁËijЩ¾É°æ±¾µÄWindowsϵͳ£¬ÓÉÓÚ¸ÃÎó²îÎÞÐèÉí·ÝÑéÖ¤ÇÒÎÞÐèÓû§½»»¥£¬ÒÔÊÇ¿ÉÒÔͨ¹ýÍøÂçÈä³æµÄ·½·¨±»Ê¹Óã¬Ê¹ÓôËÎó²îµÄ¶ñÒâÈí¼þ¿ÉÒÔ´Ó±»Ñ¬È¾µÄÅÌËã»úÈö²¥µ½ÍøÂçÖÐÆäËûÒ×Êܹ¥»÷µÄÅÌËã»ú£¬Èö²¥·½·¨Óë2017ÄêWannaCry¶ñÒâÈí¼þµÄÈö²¥·½·¨ÀàËÆ¡£
LinuxÄÚºËSCTPÐÒéÎó²îÆÊÎöÓ븴ÏÖ
LinuxÄÚºËSCTPÐÒéʵÏÖÖб£´æÒ»¸öÇå¾²Îó²îCVE-2019-8956£¬¿ÉÒÔµ¼Ö¾ܾø·þÎñ¡£¸ÃÎó²î±£´æÓÚnet/sctp/socket.cÖеÄsctp_sendmsg()º¯Êý£¬¸Ãº¯ÊýÔÚ´¦Öóͷ£SENDALL±ê¼Ç²Ù×÷Àú³Ìʱ±£´æuse-after-freeÎó²î¡£
LinuxÄÚºËTCPÐÒé¶à¸öSACK¹¦Ð§¾Ü¾ø·þÎñÎó²îÆÊÎö
LinuxÄÚºËTCP/IPÐÒéÕ»±£´æ3¸öÇå¾²Îó²î£¨CVE-2019-11477¡¢CVE-2019-11478¡¢CVE-2019-11479£©£¬ÕâЩÎó²îÓë×î´ó·Ö¶Î´óС£¨MSS£©ºÍTCPÑ¡ÔñÐÔÈ·ÈÏ£¨SACK£©¹¦Ð§Ïà¹Ø£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¾ÙÐоܾø·þÎñ¹¥»÷¡£
Advantech WebAccess¶à¸öÎó²îÆÊÎö
ZDIÐû²¼¶à¸öWebAccessÎó²î£¬ÆäÖаüÀ¨¶à¸öÄÚ´æÆÆËðÎó²îºÍÕ»Òç³öÎó²î¡£²¿·ÖÄÚ´æÆÆËðÎó²î¿ÉÒÔÔÚÊÜÓ°ÏìµÄϵͳÖÐÖ´ÐÐí§Òâ´úÂ룬¿ÉÊǴ󲿷ÖÄÚ´æÆÆËðÎó²îʹÓÃÌõ¼þ½ÏΪ¿Á¿Ì¡£Í¬Ê±£¬ÓÉÓÚAdvantech WebAccessÐí¶àÄ£¿é²¢Ã»ÓпªÆôASLR¡¢DEPµÈϵͳÏà¹ØÇå¾²»úÖÆ£¬Ê¹µÃÕ»Òç³öµÈÎó²îÔÚÊÜÓ°ÏìµÄϵͳÖÐÈÝÒ×Ôì³É´úÂëÖ´ÐС£
¿ªÔ´Ñ¹Ëõ¿âlibarchive´úÂëÖ´ÐÐÎó²î£¨CVE-2019-18408£©ÆÊÎö
¹È¸èÇå¾²Ñо¿Ô±·¢Ã÷libarchive¿âÖб£´æÎó²îCVE-2019-18408¡£¹¥»÷Õß¿ÉʹÓÃÈ«ÐĽṹµÄѹËõÎļþ£¬¶ÔÊÜÓ°ÏìÓû§Ôì³ÉѹËõ³ÌÐò¾Ü¾ø·þÎñ»òÖ´ÐжñÒâ´úÂë¡£Õâ´Î±»ÆسöµÄÇå¾²Îó²î¼ä½ÓÓ°Ïìµ½ÁË´ó×ÚÏîÄ¿ºÍ²úÆ·¡£
Çø¿éÁ´×¨ÌâÆÊÎö
Çø¿éÁ´ÖÇÄܺÏÔ¼¿ØÖÆÁ÷ʶ±ð´ó¹æģʵÑéÑо¿
ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøADLabÍŽáµç×ӿƼ¼´óѧÅÌËã»úѧԺ³ÂÌü½ÌÊÚ¶ÔÒÔÌ«·»Çø¿éÁ´ÖÇÄܺÏÔ¼¿ØÖÆÁ÷µÄʶ±ð¾ÙÐÐÁË´ó¹æÄ£Ñо¿£¬¸ÃÑо¿ÆÊÎöÁËÄ¿½ñ6¸öÖ÷Á÷µÄÖÇÄܺÏÔ¼¾²Ì¬ÆÊÎö¹¤¾ß£¬Í¨¹ý¶ÔÒÔÌ«·»Çø¿éÁ´ÉÏÒÑ°²ÅŵĺÏÔ¼£¨½ü500Íò£©ÊµÑéÖ´Ðиú×ÙÀ´ÆÀ¹ÀËûÃǵľ²Ì¬¿ØÖÆÁ÷ʶ±ðÄÜÁ¦¡£Ñо¿Ð§¹ûÒѽÒÏþÔÚCCFÍƼöµÄ2019ÄêBÀàѧÊõ¾Û»áÉÏ£¬²¢»ñµÃÁË×î¼ÑÂÛÎÄÌáÃû½±¡£
×èÖ¹¡°¶çÊÖ¡±ØÍÆ·£¿Çø¿éÁ´Á´ÉÏÁ´ÏÂÊý¾ÝÐͬÆÊÎö
ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøADLabÒÔΪ£¬Çø¿éÁ´µÄϵͳµÄ¿ÉÓÃÐÔÎÊÌâÊÇÉæ¼°¹¦Ð§ÊµÏÖÐÔµÄÎÊÌ⣬¶øʵÏÖÐÔÎÊÌâʵÖÊÊÇÖÊÆÓµÄÇå¾²ÐÔÎÊÌ⣬²¢Õë¶Ô¡°Á´ÉÏÁ´ÏÂÊý¾ÝÐͬÊÖÒÕ¡±¾ÙÐÐÁËÒ»Á¬Ñо¿¡£Ä¿½ñ£¬Á´ÉÏÁ´ÏÂÊý¾ÝÐͬÊÖÒÕ²¢²»ÍêÉÆ£¬µ¼ÖÂÇø¿éÁ´ÎÞ·¨Ðγɱջ·£¬ÊÇÏÞÖÆÇø¿éÁ´Ó¦Óó¡¾°µÄÖ÷Òª×è°¡£
ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøÆð¾¢·ÀÓùʵÑéÊÒ£¨ADLab£©
ADLab½¨ÉèÓÚ1999Ä꣬ÊÇÖйúÇå¾²ÐÐÒµ×îÔ罨ÉèµÄ¹¥·ÀÊÖÒÕÑо¿ÊµÑéÊÒÖ®Ò»£¬Î¢ÈíMAPPÍýÏë½¹µã³ÉÔ±£¬¡°ºÚȸ¹¥»÷¡±¿´·¨Ê×ÍÆÕß¡£×èÖ¹ÏÖÔÚ£¬ADLabÒÑͨ¹ýCVEÀÛ¼ÆÐû²¼Çå¾²Îó²î1000Óà¸ö£¬Í¨¹ý CNVD/CNNVDÀÛ¼ÆÐû²¼Çå¾²Îó²î600Óà¸ö£¬Ò»Á¬¼á³Ö¹ú¼ÊÍøÂçÇå¾²ÁìÓòÒ»Á÷Ë®×¼¡£ÊµÑéÊÒÑо¿Æ«Ïòº¸Ç²Ù×÷ϵͳÓëÓ¦ÓÃϵͳÇå¾²Ñо¿¡¢Òƶ¯ÖÇÄÜÖÕ¶ËÇå¾²Ñо¿¡¢ÎïÁªÍøÖÇÄÜ×°±¸Çå¾²Ñо¿¡¢WebÇå¾²Ñо¿¡¢¹¤¿ØϵͳÇå¾²Ñо¿¡¢ÔÆÇå¾²Ñо¿¡£Ñо¿Ð§¹ûÓ¦ÓÃÓÚ²úÆ·½¹µãÊÖÒÕÑо¿¡¢¹ú¼ÒÖصã¿Æ¼¼ÏîÄ¿¹¥¹Ø¡¢×¨ÒµÇå¾²·þÎñµÈ¡£