ÐÅÏ¢Äþ¾²Öܱ¨-2020ÄêµÚ10ÖÜ

Ðû²¼Ê±¼ä 2020-03-10

> ±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


2020Äê03ÔÂ02ÈÕÖÁ08ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´52¸ö £¬ÖµµÃ¹Ø×¢µÄÊÇFasterXML jackson-databind CVE-2020-9548´úÂëÖ´ÐЩ¶´; Rubetek SmartHome²¨¶ÎÉè¼Æ©¶´ £»Envoy²»ÕýÈ··ÃÎÊ¿ØÖÆ©¶´ £»Qualcomm MDM9206 WLAN»º³åÇøÒç³ö©¶´ £»Google Chrome mediaÄþ¾²Èƹý©¶´¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇTeslaºÍSpaceXµÄÁã¼þÖÆÔìÉÌVisserÈ·ÈÏÔâºÚ¿Í¹¥»÷ÇÒÊý¾Ýй¶ £»Let's Encrypt³·»ØÁè¼Ý300Íò¸öTLSÖ¤Êé £»CrowdStrikeÐû²¼¡¶2020ÄêÈ«ÇòÍþв³ÂËß¡· £»Ó¢¹úÊý¾Ý¼à¹Ü»ú¹¹¶Ô¹úÌ©º½¿Õ´¦ÒÔ50ÍòÓ¢°÷·£¿î £»°Ä´óÀûÑÇACSCÐû²¼CMSϵͳÄþ¾²Ö¸ÄÏ¡£


ƾ¾ÝÒÔÉÏ×ÛÊö £¬±¾ÖÜÄþ¾²ÍþвΪÖС£


>ÖØÒªÄþ¾²Â©¶´Áбí


1. FasterXML jackson-databind CVE-2020-9548´úÂëÖ´ÐЩ¶´


FasterXML jackson-databind ibatis-sqlmapÒÔ¼°anteros-core×é¼þ´æÔÚºÚÃûµ¥Èƹý©¶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬¿ÉÖ´ÐÐÈÎÒâ´úÂë¡£

https://github.com/FasterXML/jackson-databind/issues/2631


2. Rubetek SmartHome²¨¶ÎÉè¼Æ©¶´


Rubetek SmartHomeʹÓÃÁËδ¼ÓÃܵÄ433 MHz²¨¶Î½øÐÐͨÐÅ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢»ò½øÐоܾø·þÎñ¹¥»÷¡£

https://pastebin.com/CckKKJcM


3. Envoy²»ÕýÈ··ÃÎÊ¿ØÖÆ©¶´


EnvoyʹÓÃSDS´æÔÚ²»ÕýÈ··ÃÎÊ¿ØÖÆ©¶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬¿ÉδÊÚȨ·ÃÎÊÊÜÏÞ×ÊÔ´¡£

https://github.com/envoyproxy/envoy/security/advisories/GHSA-3x9m-pgmg-xpx8


4. Qualcomm MDM9206 WLAN»º³åÇøÒç³ö©¶´


Qualcomm MDM9206 WLAN´æÔÚ»º³åÇøÒç³ö©¶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬¿É½øÐоܾø·þÎñ¹¥»÷»ò¿ÉÖ´ÐÐÈÎÒâ´úÂë¡£

https://www.qualcomm.com/company/product-security/bulletins/march-2020-bulletin


5. Google Chrome mediaÄþ¾²Èƹý©¶´


Google Chrome media´¦ÖÃÄþ¾²¼Æı´æÔÚÄþ¾²Â©¶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄWEBÇëÇó £¬ÓÕʹÓû§½âÎö £¬¿ÉÈƹýÄþ¾²ÏÞÖÆ £¬Î´ÊÚȨ·ÃÎÊ¡£

https://chromereleases.googleblog.com/2020/03/stable-channel-update-for-desktop.html


> ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢TeslaºÍSpaceXµÄÁã¼þÖÆÔìÉÌVisserÈ·ÈÏÔâºÚ¿Í¹¥»÷ÇÒÊý¾Ýй¶


×ðÁú¶¶È¦ - Ϊdu¶øÉú


TeslaºÍSpaceXµÄÁã¼þÖÆÔìÉÌVisserÈ·ÈÏÔâÓöÊý¾Ýй¶Ê¼þ £¬¸Ã¹«Ë¾ÊÇÒ»¼ÒרÃÅΪ̫¿ÕºÍ¹ú·À³Ð°üÉÌÉè¼Æ¾«ÃÜÁã¼þµÄÖÆÔìÉÌ¡£ÔÚÒ»·Ý¼ò¶ÌµÄÉùÃ÷ÖÐ £¬¸Ã¹«Ë¾È·ÈÏÆä½üÆÚ³ÉΪ¡°ÍøÂçÄþ¾²·¸×ïʼþ£¨°üÂÞ·ÃÎʺÍ͵ÇÔÊý¾Ý£©µÄÄ¿±ê¡±¡£¸Ã¹«Ë¾·¢ÑÔÈËÌåÏÖ½«¡°¼ÌÐø¶Ô¸Ã¹¥»÷½øÐÐÈ«ÃæÊÓ²ì £¬¶øÇÒÒµÎñÔËÐÐÕý³£¡±¡£TechCrunchÑо¿ÈËÔ±³ÆÕâ´Î¹¥»÷ºÜÓпÉÄÜÊÇÓÉDoppelPaymerÀÕË÷Èí¼þÒýÆðµÄ¡£


Ô­ÎÄÁ´½Ó£º

https://techcrunch.com/2020/03/01/visser-breach/


2¡¢4Let's Encrypt³·»ØÁè¼Ý300Íò¸öTLSÖ¤Êé


×ðÁú¶¶È¦ - Ϊdu¶øÉú


ÓÉÓÚÔÚºó¶Ë´úÂëÖз¢ÏÖÁËÒ»¸öbug £¬Let's EncryptÏîÄ¿¼Æ»®´ÓÊÀ½ç³ß¶Èʱ¼ä2020Äê3ÔÂ4ÈÕ00:00¿ªÊ¼È¡ÏûÁè¼Ý300Íò¸öTLSÖ¤Êé¡£¾ßÌåÀ´Ëµ £¬¸ÃbugÓ°ÏìÁËBoulder £¬Let's EncryptÏîĿʹÓø÷þÎñÆ÷Èí¼þÔÚ¿¯ÐÐTLSÖ¤Êé֮ǰÑéÖ¤Óû§¼°ÆäÓò¡£¸ÃbugÓ°ÏìÁËBoulderÄÚ²¿CAA£¨Ö¤Êé·¢±í»ú¹¹ÊÚȨ£©¹æ·¶µÄʵʩ £¬¡°µ±Ò»¸öÖ¤ÊéÇëÇó°üÂÞN¸öÐèÒª½øÐÐCAAÖØмì²éµÄÓòÃûʱ £¬Boulder½«Ñ¡ÔñÒ»¸öÓòÃû²¢¼ì²éN´Î¡£Õâʵ¼ÊÉÏÒâζ×ÅÈç¹ûÒ»¸öÓû§ÔÚʱ¼äXÑéÖ¤ÁËÒ»¸öÓòÃû £¬¶øÇÒ¸ÃÓòÃûÔÚʱ¼äXµÄCAA¼Ç¼ÔÊÐíLet's Encrypt¿¯ÐÐ £¬Ôò¸ÃÓû§¿ÉÒÔÔÚX+30ÌìµÄʱ¼äÀ￯ÐаüÂÞ¸ÃÓòÃûµÄÖ¤Êé £¬¼´Ê¹Ö®ºóÓÐÈËÔÚ¸ÃÓòÃûÉÏ°²×°Á˽ûÖ¹Let's Encrypt¿¯ÐеÄCAA¼Ç¼¡±¡£ÔÚÕâ300Íò¸öÈ¡ÏûµÄÖ¤ÊéÖÐ £¬ÓÐ100Íò¸öÊÇͬһÓò/×ÓÓòµÄÖظ´Ïî £¬Òò´ËÊÜÓ°ÏìÖ¤ÊéµÄʵ¼ÊÊýÁ¿Ô¼Îª200Íò¸ö¡£ÔÚ3ÔÂ4ÈÕ00:00Ö®ºóËùÓÐÊÜÓ°ÏìµÄÖ¤Ê鶼½«´¥·¢ä¯ÀÀÆ÷ºÍÆäËûÓ¦Ó÷¨Ê½ÖеĴíÎó £¬ÓòÃûËùÓÐÕß½«±ØÐëÇëÇóеÄTLSÖ¤Êé²¢Ìæ»»¾ÉµÄTLSÖ¤Êé¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/lets-encrypt-to-revoke-3-million-certificates-on-march-4-due-to-bug/


3¡¢CrowdStrikeÐû²¼¡¶2020ÄêÈ«ÇòÍþв³ÂËß¡·


×ðÁú¶¶È¦ - Ϊdu¶øÉú


CrowdStrikeµÄ¡¶2020ÄêÈ«ÇòÍþв³ÂËß¡·¶Ô¹ýÈ¥Ò»ÄêÖж¥¼¶ÍøÂçÍþвÇ÷ÊƽøÐÐÁËÉîÈë·ÖÎö £¬¸Ã³ÂËßµÄÒªµã°üÂÞ£º´óÐ͹¥»÷»î¶¯£¨BGH£©²»Í£Éý¼¶ £¬Êê½ðÒªÇóì­ÉýÖÁÊý°ÙÍò £¬¶øÇÒÔì³É¼«´óµÄÆÆ»µ £»ÍøÂç·¸×ï·Ö×ÓÕýÔÚʹÃô¸ÐÊý¾ÝÎäÆ÷»¯ £¬ÒÔÔö¼Ó¶ÔÀÕË÷Èí¼þÊܺ¦ÕßµÄѹÁ¦ £»eCrimeÉú̬ϵͳ²»Í£Éú³¤ £¬±äµÃ³ÉÊìºÍרҵ»¯Ë®Æ½²»Í£Ìá¸ß £»ÔÚBGHÖ®Íâ £¬Õë¶ÔÈ«Çò½ðÈÚ»ú¹¹µÄeCrime»î¶¯ÓÐËùÔö¼Ó £»³¯ÏòÎÞ¶ñÒâÈí¼þ¼ÆıµÄÇ÷ÊÆÕýÔÚ¼ÓËÙ £»¹ú¼Ò×ÊÖúµÄÓÐÕë¶ÔÐÔµÄÈëÇֻ¼ÌÐøÕë¶Ô֪ʶ²úȨ/¾ºÕùÇ鱨 £¬´Ù½øÉçÇøÄÚ²¿µÄÆÆÁÑ £¬²¢ÊӲ쵽ÁËÓëÏȽøeCrime¹¥»÷ÕߵĺÏ×÷¡£


Ô­ÎÄÁ´½Ó£º

https://www.crowdstrike.com/resources/reports/2020-crowdstrike-global-threat-report/


4¡¢Ó¢¹úÊý¾Ý¼à¹Ü»ú¹¹¶Ô¹úÌ©º½¿Õ´¦ÒÔ50ÍòÓ¢°÷·£¿î


×ðÁú¶¶È¦ - Ϊdu¶øÉú


Ó¢¹úÐÅϢרԱ°ì¹«ÊÒÒò2018Äê940Íò´î¿ÍÊý¾Ýй¶Ê¼þ¶Ô¹úÌ©º½¿Õ¹«Ë¾´¦ÒÔ50ÍòÓ¢°÷µÄ·£¿î¡£¸Ã¹¥»÷ÒÉËÆ·¢ÉúÔÚ2018Äê3Ô·Ý £¬²¢ÓÚ5Ô·ݵõ½È·ÈÏ £¬Æäʱ¹úÌ©º½¿ÕµÄÊý¾Ý¿âÔâµ½Á˱©Á¦Æƽ⹥»÷¡£ICOÊÓ²ì³Æ¹úÌ©µÄϵͳÊܵ½ÁËÊý¾ÝÊÕ¼¯Àà¶ñÒâÈí¼þµÄÓ°Ïì £¬²¢·¢ÏÖ¹úÌ©ÔÚÄþ¾²ÐÔ·½ÃæµÄһЩ²»×ã £¬°üÂÞ²»ÊÜÃÜÂë± £»¤µÄ±¸·ÝÎļþ¡¢Î´´ò²¹¶¡µÄWeb·þÎñÆ÷¡¢ÒѹýʱµÄ²Ù×÷ϵͳºÍȱ·¦·À²¡¶¾± £»¤µÈ¡£


Ô­ÎÄÁ´½Ó£º

https://www.theregister.co.uk/2020/03/04/ico_fines_cathay_pacific_500000/


5¡¢°Ä´óÀûÑÇACSCÐû²¼CMSϵͳÄþ¾²Ö¸ÄÏ


×ðÁú¶¶È¦ - Ϊdu¶øÉú


°Ä´óÀûÑÇÍøÂçÄþ¾²ÖÐÐÄ£¨ACSC£©Ðû²¼Ò»·ÝÓÃÓÚ± £»¤CMSϵͳµÄÍøÂçÄþ¾²Ö¸ÄÏ £¬¸ÃÖ¸ÄϸÅÊöÁËÈçºÎÔÚweb·þÎñÆ÷ÉÏʶ±ðºÍ×îС»¯Ç±ÔÚ·çÏյļÆı £¬ÆäÄ¿±êÊÜÖÚÊÇÂôÁ¦Ê¹ÓÃCMS¿ª·¢ºÍ± £»¤ÍøÕ¾»òWebÓ¦Ó÷¨Ê½µÄÈË¡£¹¥»÷Õß¿ÉÒÔʹÓÃ×Ô¶¯»¯¹¤¾ßɨÃèInternetÉϵÄÄþ¾²Â©¶´¡£Ò»µ©CMS±»ÈëÇÖ £¬¹¥»÷Õß¿ÉÒÔÀûÓÃÆäȨÏÞÀ´£º»ñµÃWebÓ¦Ó÷¨Ê½µÄÑéÖ¤ÇøÓòºÍÌØȨÇøÓòµÄ·ÃÎÊȨÏÞ £»ÉÏ´«¶ñÒâÈí¼þÀ´»ñµÃÔ¶³Ì·ÃÎÊ £¬ÀýÈçÉÏ´«Web Shell»òRAT £»ÔںϷ¨ÍøÒ³ÉÏ×¢Èë¶ñÒâÄÚÈÝ¡£¹¥»÷Õß»¹¿ÉÒÔ½«ÊÜѬȾµÄWeb·þÎñÆ÷ÓÃ×÷¡°Ë®¿Ó¡±¹¥»÷µÄÒ»²¿ÃÅ £¬»òÓÃ×÷C&CµÄ»ù´¡ÉèÊ©¡£ACSC½¨Òé½ÓÄɵĻº½â´ëÊ©°üÂÞ£ºÊ¹ÓÃCMSÍйܷþÎñ £»Á¼ºÃµÄ²¹¶¡¹ÜÀí £»Â©¶´ÆÀ¹À £»ÕË»§¹ÜÀí £»¼ÓÇ¿CMS°²×°µÄÄþ¾²ÐÔ¿ØÖÆ´ëÊ© £»¼à¿ØCMS°²×°É϶ÔÍйÜÄÚÈݵÄδÊÚȨ¸ü¸ÄµÈ¡£


Ô­ÎÄÁ´½Ó£º

https://www.cyber.gov.au/publications/securing-content-management-systems