ÐÅÏ¢Çå¾²Öܱ¨-2019ÄêµÚ41ÖÜ
Ðû²¼Ê±¼ä 2019-10-21>±¾ÖÜÇ徲̬ÊÆ×ÛÊö
2019Äê10ÔÂ14ÈÕÖÁ20ÈÕ¹²ÊÕ¼Çå¾²Îó²î53¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇISC BIND QNAME×îС»¯´úÂë¾Ü¾ø·þÎñÎó²î;Samsung Galaxy S10δÊÚȨ»á¼ûÎó²î£»Kubernetes API Server JSON/YAMLÆÊÎö¾Ü¾ø·þÎñÎó²î£»Adobe Experience Manager CVE-2019-8088ÏÂÁî×¢ÈëÎó²î£»Adobe AcrobatºÍReaderÄÚ´æ¹ýʧÒýÓÃí§Òâ´úÂëÖ´ÐÐÎó²î¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊǺ½Ô˾ÞÍ·Pitney BowesÔâÀÕË÷Èí¼þ¹¥»÷£¬¶à¸öϵͳ崻ú£»ÈüÃÅÌú¿ËÖÕ¶ËÇå¾²²úÆ·µÄ¸üе¼ÖÂÓû§×°±¸À¶ÆÁ£»Android 0day(CVE-2019-2215)µÄPoC´úÂëÒÑÐû²¼£»Êý°ÙÍòÑÇÂíÑ·EchoºÍKindle×°±¸Ò×ÊÜWiFi KRACK¹¥»÷£»Linux sudoȨÏÞÈƹýÎó²î£¬¿ÉÒÔrootȨÏÞÖ´ÐÐÏÂÁî¡£
>Ö÷ÒªÇå¾²Îó²îÁбí
ISC BIND QNAME×îС»¯´úÂë´¦Öóͷ£±£´æÇå¾²Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉʹnamedÍ˳ö£¬Ôì³É¾Ü¾ø·þÎñ¹¥»÷¡£
https://kb.isc.org/docs/cve-2019-6476
2. Samsung Galaxy S10δÊÚȨ»á¼ûÎó²î
Samsung Galaxy S10Ö¸ÎÆÑéÖ¤±£´æÇå¾²Îó²î£¬ÔÊÐí¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌύδ¼ÈëÖ¸ÎÆ£¬¿É»á¼ûÊÖ»ú¡£
https://www.forbes.com/sites/gordonkelly/2019/10/15/samsung-galaxy-s10-note10-plus-fingerprint-reader-warning-upgrade-galaxy-s11
3. Kubernetes API Server JSON/YAMLÆÊÎö¾Ü¾ø·þÎñÎó²î
Kubernetes API Server JSON/YAMLÆÊÎö±£´æÇå¾²Îó²î£¬ÔÊÐíͨ¹ýÊÚȨµÄÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄ¶ñÒâÇëÇ󣬿ɾÙÐоܾø·þÎñ¹¥»÷¡£
https://github.com/kubernetes/kubernetes/issues/83253
4. Adobe Experience Manager CVE-2019-8088ÏÂÁî×¢ÈëÎó²î
Adobe Experience ManagerÏÂÁî×¢ÈëÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§ÒâÏÂÁî¡£
https://helpx.adobe.com/security/products/experience-manager/apsb19-48.html
5. Adobe AcrobatºÍReaderÄÚ´æ¹ýʧÒýÓÃí§Òâ´úÂëÖ´ÐÐÎó²î
Adobe AcrobatºÍReader±£´æÊͷźóʹÓÃÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄPDFÎļþ£¬ÓÕʹÓû§ÆÊÎö£¬¿ÉʹӦÓóÌÐò±ÀÀ£»òÖ´ÐÐí§Òâ´úÂë¡£
https://helpx.adobe.com/security/products/acrobat/apsb19-49.html
>Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö
È«Çòº½Ô˾ÞÍ·Pitney BowesÐû²¼ÔâÓöÀÕË÷Èí¼þ¹¥»÷£¬µ¼Ö²¿·ÖϵͳÖÐÖ¹£¬´Ó¶øÓ°ÏìÁË¿Í»§¶ÔÆäijЩ·þÎñµÄ»á¼û¡£Pitney BowesΪȫÇòÁè¼Ý150Íò¿Í»§Ìṩ·þÎñ£¬°üÀ¨90%µÄ²Æ²ú500Ç¿¹«Ë¾¡£ÏÖÔÚÓжà¸öPitney Bowes·þÎñÊܵ½Ó°Ï죬°üÀ¨Pitney BowesµÄÓʼþϵͳ²úÆ·¡£¿Í»§ÎÞ·¨ÔÚÆäÓʼþϵͳÉÏÔö²¹ÓÊ×Ê»òÉÏ´«ÉúÒ⣬ҲÎÞ·¨»á¼ûÓ¢¹úºÍ¼ÓÄôóµÄSendPro Online²úÆ·¼°Your AccountºÍPitney Bowes SuppliesÍøÉÏÊÐËÁ£¬Õâ·´¹ýÀ´ÓÖÓ°ÏìÁ˶©ÔÄAutoInkºÍSupplies AppµÄ¿Í»§¡£¸Ã¹«Ë¾ÔÚÉùÃ÷ÖÐÌåÏÖ£¬ÏÖÔÚûÓÐÖ¤¾ÝÅú×¢¿Í»§»òÔ±¹¤µÄÊý¾Ý±»²»µ±»á¼û£¬¸Ã¹«Ë¾ÕýÔÚÓëµÚÈý·½ÏàÖú¾ÙÐÐÊÓ²ìÓë½â¾öÎÊÌâ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/global-shipping-firm-pitney-bowes-affected-by-ransomware-attack/
2¡¢ÈüÃÅÌú¿ËÖÕ¶ËÇå¾²²úÆ·µÄ¸üе¼ÖÂÓû§×°±¸À¶ÆÁ
ÈüÃÅÌú¿ËΪÆäEndpoint Protection²úÆ·ÍƳöµÄÈëÇÖ¼ì²âÊðÃû¸üе¼ÖÂÓû§×°±¸·ºÆðÍ߽ⲢÏÔʾÀ¶ÆÁ£¨BSOD£©¡£¸ÃÎÊÌâÓ°ÏìÁËWin 7¡¢Win8¼°Win 10£¬Æ¾Ö¤ÈüÃÅÌú¿ËµÄ±íÊö£¬ÔÚÔËÐÐLiveUpdateʱEndpoint Protection Client»áÏÔʾéæÃüÀ¶ÆÁ£¬²¢ÏÔʾIDSvix86.sys/IDSvia64.sys·ºÆðÎÊÌ⣬µ¼ÖÂBAD_POOL_CALLER (c2)»òKERNEL_MODE_HEAP_CORRUPTION (13A)Òì³£¡£¸Ã¹«Ë¾»¹Ôö²¹³ÆÊÜÓ°ÏìµÄÈëÇÖ¼ì²âµÄÊðÃû°æ±¾Îª2019/10/14 r61£¬¸ÃÎÊÌâÒÑÔÚа汾2019/10/14 r62Öнâ¾ö¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/symantec-fixes-bad-ips-definitions-that-cause-a-windows-bsod/
3¡¢Android 0day(CVE-2019-2215)µÄPoC´úÂëÒÑÐû²¼
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/security-researcher-publishes-proof-of-concept-code-for-recent-android-zero-day/4¡¢Êý°ÙÍòÑÇÂíÑ·EchoºÍKindle×°±¸Ò×ÊÜWiFi KRACK¹¥»÷
ƾ֤ESETµÄÒ»·Ý±¨¸æ£¬Ñо¿Ö°Ô±·¢Ã÷Amazon Echo 1stºÍAmazon Kindle 8th×°±¸ÈÔÈ»Êܵ½WiFi KRACKÎó²îµÄÓ°Ï죬Õâ¿ÉÄÜÓ°ÏìÊý°ÙÍò×°±¸¡£KRACKÎó²îÊÇWPA2ÐÒé4´ÎÎÕÊÖÖеÄÎó²î£¨CVE-2017-13077ºÍCVE-2017-13078£©£¬¸ÃÎó²îÓÚ2017Äê10Ô±»¹ûÕ档ƾ֤ESETµÄ±íÊö£¬ÕâЩÎó²î¿ÉÄÜÔÊÐí¹¥»÷ÕßÖ´ÐÐDoS¹¥»÷¡¢ÆÆËðÍøÂçͨѶ»òÖز¥¹¥»÷£¬×赲ϢÕùÃÜÓû§´«ÊäµÄÃÜÂë»ò»á»°µÈÃô¸ÐÐÅÏ¢£¬Î±ÔìÊý¾Ý°üÉõÖÁ×¢ÈëÐÂÊý¾Ý°üµÈ¡£ESETÓÚ2018Äê10ÔÂ23ÈÕ֪ͨÁËÑÇÂíÑ·£¬ÑÇÂíÑ·ÔÚ2019Äê1ÔÂÒÑÏòÊÜÓ°ÏìµÄ×°±¸ÍÆËÍÁËÏà¹ØÐÞ¸´²¹¶¡¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/millions-of-amazon-echo-and-kindle-devices-affected-by-wifi-bug/5¡¢Linux sudoȨÏÞÈƹýÎó²î£¬¿ÉÒÔrootȨÏÞÖ´ÐÐÏÂÁî
Linux sudoÆسöÌáȨÎó²î£¬¿ÉÈƹýRunasÓû§ÏÞÖÆÒÔrootȨÏÞÖ´ÐÐÏÂÁî¡£¸ÃÎó²î£¨CVE-2019-14287£©ÓÉÆ»¹ûÐÅÏ¢Çå¾²²¿·ÖµÄJoe Vennix·¢Ã÷£¬ÈôÊǽ«sudoÉèÖÃΪÔÊÐíÓû§ÒÔí§ÒâÓû§Éí·ÝÔËÐÐÏÂÁÔò¿ÉÒÔͨ¹ýÖ¸¶¨Óû§IDΪ-1»ò4294967295µÄ·½·¨ÒÔrootÉí·ÝÔËÐÐÏÂÁî¡£ÕâÊÇÓÉÓÚ½«Óû§IDת»»ÎªÓû§ÃûµÄº¯Êý£¬»á½«-1£¨»òµÈЧµÄ4294967295£©ÎóÒÔΪ0£¬¶øÕâÕýºÃÊÇrootÓû§µÄUser ID¡£±ðµÄ£¬ÓÉÓÚͨ¹ý-uÑ¡ÏîÖ¸¶¨µÄUser IDÔÚÃÜÂëÊý¾Ý¿âÖв»±£´æ£¬Òò´Ë²»»áÔËÐÐÈκÎPAM»á»°Ä£¿é¡£¸ÃÎó²îÓ°Ïì°æ±¾1.8.28֮ǰµÄËùÓÐSudo°æ±¾¡£
ÔÎÄÁ´½Ó£º
https://www.sudo.ws/alerts/minus_1_uid.html