ÐÅÏ¢Çå¾²Öܱ¨-2019ÄêµÚ28ÖÜ

Ðû²¼Ê±¼ä 2019-07-22

±¾ÖÜÇ徲̬ÊÆ×ÛÊö



2019Äê7ÔÂ15ÈÕÖÁ21ÈÕ¹²ÊÕ¼Çå¾²Îó²î50¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇNGINX njs nxt_vsprintf»º³åÇøÒç³öÎó²î£»SolarWinds Orion Network Performance MonitorÔ¶³Ì´úÂëÖ´ÐÐÎó²î£»CentOS Web PanelδÊÚȨ»á¼ûÎó²î£»Palo Alto Networks PAN-OS CVE-2019-1576ÏÂÁî×¢ÈëÎó²î£»Linaro OP-TEE optee_os»º³åÇøÒç³öÎó²î ¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊǹ㲥µç̨KHSUÒòÀÕË÷Èí¼þ¹¥»÷µ¼Ö½ÚÄ¿ÖÐÖ¹£»Evite½ü1.01ÒÚÕË»§ÐÅϢй¶£¬Òѱ»HIBPÊÕ¼£»±£¼ÓÀûÑǹú¼ÒË°Îñ¾ÖÔâºÚ¿ÍÈëÇÖ£¬500¶àÍò¹«ÃñÐÅÏ¢±»µÁ£»ÂùÝÖÎÀí¹«Ë¾AavGoÒâÍâй¶800Íò¿Í»§ÐÅÏ¢£»¹þÈø¿Ë˹̹Õþ¸®×èµ²¾³ÄÚËùÓеÄHTTPSÁ÷Á¿ ¡£


ƾ֤ÒÔÉÏ×ÛÊö£¬±¾ÖÜÇå¾²ÍþвΪÖÐ ¡£



Ö÷ÒªÇå¾²Îó²îÁбí



1. NGINX njs nxt_vsprintf»º³åÇøÒç³öÎó²î


NGINX njs nxt/nxt_sprintf.cÎļþµÄnxt_vsprintf±£´æ»º³åÇøÒç³öÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉʹӦÓóÌÐò±ÀÀ£»òÖ´ÐÐí§Òâ´úÂë ¡£
https://github.com/torvalds/linux/commit/6994eefb0053799d2e07cd140df6c2ea106c41ee

2. SolarWinds Orion Network Performance MonitorÔ¶³Ì´úÂëÖ´ÐÐÎó²î


SolarWinds Orion Network Performance Monitor OrionModuleEngine·þÎñ±£´æÇå¾²Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔSYSTEMÓû§Ö´ÐÐí§Òâ´úÂë ¡£
http://www.securityfocus.com/bid/107061

3. CentOS Web PanelδÊÚȨ»á¼ûÎó²î


CentOS Web Panel±£´æÇå¾²Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó£¬ÒÔÆäËûÓû§ÃûÈƹýÑé֤δÊÚȨ»á¼û ¡£
https://github.com/i3umi3iei3ii/CentOS-Control-Web-Panel-CVE/blob/master/CVE-2019-13360.md

4. Palo Alto Networks PAN-OS CVE-2019-1576ÏÂÁî×¢ÈëÎó²î


Palo Alto Networks PAN-OS±£´æÊäÈëÑéÖ¤Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉÖ´ÐÐí§ÒâOSÏÂÁî ¡£
https://securityadvisories.paloaltonetworks.com/Home/Detail/156

5. Linaro OP-TEE optee_os»º³åÇøÒç³öÎó²î


Linaro OP-TEE optee_os±£´æ»º³åÇøÒç³öÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉʹӦÓóÌÐò±ÀÀ£»òÖ´ÐÐí§Òâ´úÂë ¡£
https://github.com/OP-TEE/optee_os/commit/70697bf3c5dc3d201341b01a1a8e5bc6d2fb48f8



Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö



1¡¢¹ã²¥µç̨KHSUÒòÀÕË÷Èí¼þ¹¥»÷µ¼Ö½ÚÄ¿ÖÐÖ¹


ÓÅ·¢¹ú¼Ê¡¤ËæÓŶø¶¯Ò»´¥¼´·¢


ÃÀ¹ú¼ÓÖݺ鱤ÖÝÁ¢´óѧӵÓеÄKHSU¹ã²¥µç̨Ôâµ½ÀÕË÷Èí¼þ¹¥»÷£¬µ¼Ö¸õç̨µÄËùÓÐϵͳºÍ´æ´¢·þÎñÆ÷̱»¾£¬½ÚÄ¿±»ÆÈÖÐÖ¹ ¡£µ«KHSUÈ·ÈϳÆÊÜѬȾµÄ·þÎñÆ÷²¢Î´°üÀ¨ÈκÎÃô¸ÐÐÅÏ¢ ¡£KHSUÔÚ7ÔÂ1ÈÕ·¢Ã÷´Ë´Î¹¥»÷£¬¹¥»÷ÕßʹÓÃÁËKHSUϵͳÖеÄÇå¾²Îó²î ¡£KHSUÌåÏÖûÓÐÊÕµ½Êê½ðÒªÇó£¬Ò²²»ÖªµÀ¹¥»÷µÄȪԴ ¡£ÔÚ·¢Ã÷ÊÂÎñºó£¬KHSUÏòÁª°îÖ´·¨²¿·ÖºÍÁª°îͨѶίԱ»á±¨¸æÁËÕâÒ»ÊÂÎñ ¡£

Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/khsu-radio-stations-regular-programming-interrupted-due-to-ransomware-attack-e39dbd3d

2¡¢Evite½ü1.01ÒÚÕË»§ÐÅϢй¶£¬Òѱ»HIBPÊÕ¼


ÓÅ·¢¹ú¼Ê¡¤ËæÓŶø¶¯Ò»´¥¼´·¢


2019Äê5ÔÂEviteÐû²¼Êý¾Ýй¶֪ͨ£¬ÌåÏÖÆä·þÎñÆ÷´Ó2ÔÂ22ÈÕ·¢Ã÷δÊÚȨ»á¼û£¬Ô¼1000ÍòÓû§ÐÅϢй¶ ¡£µ«Æ¾Ö¤Have I Been PwnedÍøÕ¾ÊÕ¼µÄÊý¾Ý¿â£¬ÕâÒ»Êý×ÖÒª´óµÃ¶à£¬¹²Óнü1.01ÒÚÓû§ÐÅÏ¢±»µÁ ¡£ÕâЩÊý¾Ý×îÔç¿É×·ËÝÖÁ2013Ä꣬鶵ÄÐÅÏ¢°üÀ¨ÐÕÃû¡¢µç»°ºÅÂë¡¢ÏÖʵµØµã¡¢³öÉúÈÕÆÚ¡¢ÐÔ±ð¡¢Ã÷ÎÄÃÜÂëºÍµç×ÓÓʼþµØµã ¡£×î³õ±»Ð¹Â¶µÄÊý¾Ý¿âÔÚDream MarketÉϳöÊÛ£¬µ«¸ÃÍøÕ¾Òѱ»¾¯·½¹Ø±Õ£¬Òò´ËÏÖÔÚÉв»ÇåÎúÕâ¸ö¸ü´óµÄÊý¾Ý¿âÊÇ·ñÒ²ÔÚ³öÊÛ ¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/evite-invites-over-100-million-people-to-their-data-breach/

3¡¢±£¼ÓÀûÑǹú¼ÒË°Îñ¾ÖÔâºÚ¿ÍÈëÇÖ£¬500¶àÍò¹«ÃñÐÅÏ¢±»µÁ


ÓÅ·¢¹ú¼Ê¡¤ËæÓŶø¶¯Ò»´¥¼´·¢


¾Ýzdnet±¨µÀ£¬Ò»ºÚ¿Í×éÖ¯´Ó±£¼ÓÀûÑǹú¼ÒË°Îñ¾Ö£¨NRA£©ÖÐÇÔÈ¡ÁËÔ¼110¸öÊý¾Ý¿â£¬ÆäÖаüÀ¨½ü21GBµÄСÎÒ˽¼ÒÊý¾Ý£¬ÊÜÓ°ÏìÈËÊýÁè¼Ý500Íò ¡£ºÚ¿Í½«²¿·Ö±»µÁÊý¾Ýͨ¹ýµç×ÓÓʼþ·¢Ë͸øÍâµØýÌ壬µ¼ÖÂÊÂÎñÆعâ ¡£¸Ã¹úÓйز¿·ÖÒѾ­ÈÏ¿ÉÕâÒ»ÊÂÎñ£¬²¢ÕýÓë±£¼ÓÀûÑǹú¼ÒÇå¾²¾ÖÏàÖúÊÓ²ì ¡£Ð¹Â¶µÄÐÅÏ¢°üÀ¨±£¼ÓÀûÑǹ«ÃñµÄСÎÒ˽¼Òʶ±ðÂ루PIN£©¡¢ÐÕÃû¡¢¼ÒͥסַºÍ²ÆÎñÊÕÈ룬ÕâЩÊý¾Ý×îÔç¿É×·Ëݵ½2007Äê ¡£

Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/bulgarias-national-revenue-agency-hacked-to-steal-over-five-million-peoples-data-8e64c8d9

4¡¢ÂùÝÖÎÀí¹«Ë¾AavGoÒâÍâй¶800Íò¿Í»§ÐÅÏ¢


ÓÅ·¢¹ú¼Ê¡¤ËæÓŶø¶¯Ò»´¥¼´·¢


WizcaseÇå¾²Ñо¿Ô±Daniel Brown·¢Ã÷ÂùÝÖÎÀíÉÌAavGoµÄÒ»¸öElasticsearchÊý¾Ý¿â¿É¹ûÕæ»á¼û£¬¸ÃÊý¾Ý¿â°üÀ¨800ÍòÌõ¿Í»§ÐÅÏ¢£¬°üÀ¨Ô¤¶©ÐÅÏ¢¡¢¿Í»§Í¶Ëß¡¢·¢Æ±¡¢¹¤µ¥¡¢Ô±¹¤±¸Íü¼ºÍÐÂÎÅ¡¢Âùݷ¿¼äͼƬ¡¢ÎïÆ·Ëð»µÍ¼Æ¬ÒÔ¼°¿Í»§µÄСÎÒ˽¼ÒÐÅÏ¢£¨ÐÕÃû¡¢³öÉúÈÕÆÚ¡¢µç»°ºÅÂë¡¢ÓÊÏäµØµã¡¢×¡Ö·¡¢»éÒö״̬¡¢µÇ¼ÐÅÏ¢ºÍ¸¶¿î·½·¨£© ¡£Ð¹Â¶µÄÊý¾Ý»¹°üÀ¨ÂùÝÖÎÀíÔ±µÄÏêϸµÇ¼ÐÅÏ¢£¬ÀýÈçÖÎÀíÃæ°å¡¢Ô¤¶©ÏµÍ³ºÍÄÚ²¿Êý¾Ý¿âµÄÓû§ÃûºÍÃÜÂë ¡£ÊÜÓ°ÏìµÄÂùݰüÀ¨The Row Hotel¡¢Stay Cal HotelsµÈÊ®¶à¼ÒÂÃ¹Ý ¡£¸Ã¹«Ë¾ÒÑÔÚ7ÔÂ16ÈÕ¶ÔÊý¾Ý¿â½ÓÄÉÁ˱£»¤²½·¥ ¡£

Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/unprotected-elasticsearch-database-belonging-to-aavgo-exposed-8-million-records-of-guest-details-f5fb1eac

5¡¢¹þÈø¿Ë˹̹Õþ¸®×èµ²¾³ÄÚËùÓеÄHTTPSÁ÷Á¿


ÓÅ·¢¹ú¼Ê¡¤ËæÓŶø¶¯Ò»´¥¼´·¢


¹þÈø¿Ë˹̹Õþ¸®ÒÑ´Ó7ÔÂ17ÈÕ×îÏÈ×èµ²Æä¾³ÄÚµÄËùÓÐHTTPSÁ÷Á¿ ¡£ÔÚÍâµØÕþ¸®µÄָʾÏ£¬ÍâµØISPÇ¿ÖÆÓû§ÔÚÿ¸ö×°±¸ºÍä¯ÀÀÆ÷ÖÐ×°ÖÃÕþ¸®½ÒÏþµÄÖ¤Êé ¡£¸ÃÖ¤Ê齫ÔÊÐíÕþ¸®»ú¹¹½âÃÜÓû§µÄHTTPSÁ÷Á¿²¢Éó²éÆäÄÚÈÝ ¡£ÔÚÓû§×°ÖøÃÖ¤Êé֮ǰ£¬ËûÃǽ«ÎÞ·¨»á¼û»¥ÁªÍø ¡£Õþ¸®¹ÙÔ±ÌåÏִ˾ÙÖ¼ÔÚÔöÇ¿¶Ô¹«Ãñ¡¢Õþ¸®»ú¹¹ºÍ˽ӪÆóÒµµÄ±£»¤£¬Ê¹ÆäÃâÔâºÚ¿Í¹¥»÷¡¢»¥ÁªÍøڲƭµÈÍøÂçÍþв ¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/kazakhstan-government-is-now-intercepting-all-https-traffic/