ÐÅÏ¢Çå¾²Öܱ¨-2020ÄêµÚ03ÖÜ

Ðû²¼Ê±¼ä 2020-01-20


±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


2020Äê01ÔÂ13ÈÕÖÁ19ÈÕ¹²ÊÕ¼Çå¾²Îó²î53¸ö £¬ÖµµÃ¹Ø×¢µÄÊÇMicrosoft Windows CryptoAPIÑéÖ¤ÈÆ¹ýÎó²î; Apache XML-RPC XMLRPC client´úÂëÖ´ÐÐÎó²î £»Oracle E-Business Suite Human Resources CVE-2020-2587δÃ÷´úÂëÖ´ÐÐÎó²î £»Adobe Illustrator CC CVE-2020-3710ÄÚ´æ¹ýʧÒýÓôúÂëÖ´ÐÐÎó²î £»Microsoft .NET Core CVE-2020-0602Ô¶³Ì´úÂëÖ´ÐÐÎó²î¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇÒÔÉ«ÁÐÆô¶¯Ãñº½ÍøÂçÇå¾²ÍýÏë £¬½«¸ÄÉÆº½¿ÕÍøÂç·ÀÓùÄÜÁ¦ £»Î¢ÈíÕýʽÖÕÖ¹¶ÔWindows 7¡¢Server 2008ºÍ2008 R2Ìṩ֧³Ö £»ÃÀ¹úLimeLeads¹«Ë¾4900ÍòÌõÓû§¼Í¼ÔÚ°µÍøÂÛ̳³öÊÛ £»ÊÔÓÃAppÐ¶ÔØºóÖ±½Ó¿Û·Ñ £¬È«Çò½ü6ÒÚAndroidÓû§ÖÐÕÐ £»Êý°Ù¸öҽѧ³ÉÏñϵͳÔÚÍøÉÏ̻¶ÁËÊý°ÙÍò»¼ÕßµÄÊý¾Ý¡£


ƾ֤ÒÔÉÏ×ÛÊö £¬±¾ÖÜÇå¾²ÍþвΪÖС£



Ö÷ÒªÇå¾²Îó²îÁбí


1. Microsoft Windows CryptoAPIÑéÖ¤ÈÆ¹ýÎó²î


Microsoft Windows CryptoAPI´¦Öóͷ£ECCÍÖÔ²ÇúÏß¼ÓÃܱ£´æÇå¾²Îó²î £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó £¬¿ÉÒÔʹÓÃαÔìµÄÖ¤Êé¶Ô¶ñÒâµÄ¿ÉÖ´ÐÐÎļþ¾ÙÐÐÊðÃû £¬Ê¹Îļþ¿´ÆðÀ´À´×Ô¿ÉÐŵÄȪԴ £¬»òÕß¾ÙÐÐÖÐÐÄÈ˹¥»÷²¢½âÃÜÓû§ÅþÁ¬µ½ÊÜÓ°ÏìÈí¼þµÄÉñÃØÐÅÏ¢¡£

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0601


2. Apache XML-RPC XMLRPC client´úÂëÖ´ÐÐÎó²î


Apache XML-RPC XMLRPC clientʵÏÖXMLRPC¹ýʧÐÂÎÅfaultCauseÊôÐÔ´¦Öóͷ£±£´æÇå¾²Îó²î £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²î¹¹½¨¶ñÒâXMLRPC·þÎñÇëÇó £¬¿ÉʹӦÓóÌÐò±ÀÀ £»òÕßÖ´ÐÐí§Òâ´úÂë¡£

https://access.redhat.com/security/cve/cve-2019-17570


3. Oracle E-Business Suite Human Resources CVE-2020-2587δÃ÷´úÂëÖ´ÐÐÎó²î


Oracle E-Business Suite Human Resources±£´æÎ´Ã÷Çå¾²Îó²î £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó £¬¿ÉʹӦÓóÌÐò±ÀÀ £»òÖ´ÐÐí§Òâ´úÂë¡£

https://www.oracle.com/security-alerts/cpujan2020.html


4. Adobe Illustrator CC CVE-2020-3710ÄÚ´æ¹ýʧÒýÓôúÂëÖ´ÐÐÎó²î


Adobe Illustrator CC´¦Öóͷ£Îļþ±£´æÄÚ´æÆÆËðÎó²î £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó £¬ÓÕʹÓû§ÆÊÎö £¬¿ÉʹӦÓóÌÐò±ÀÀ £»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£

https://helpx.adobe.com/security/products/illustrator/apsb20-03.html


5. Microsoft .NET Core CVE-2020-0602Ô¶³Ì´úÂëÖ´ÐÐÎó²î


Microsoft .NET CoreʵÏÖ±£´æÇå¾²Îó²î £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó £¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0602


Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢ÒÔÉ«ÁÐÆô¶¯Ãñº½ÍøÂçÇå¾²ÍýÏë £¬½«¸ÄÉÆº½¿ÕÍøÂç·ÀÓùÄÜÁ¦


Ò«ÊÀÓéÀÖ-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ¡£


¾ÝÉÏÖÜÈÕÒÔÉ«Áйú¼ÒÍøÂç¹ÜÀí¾Ö£¨INCD£©±¨µÀ £¬ÒÔÉ«ÁÐÕþ¸®Åú×¼ÁËÒ»ÏîÃñº½ÍøÂçÇå¾²ÍýÏë¡£×÷Ϊ¸ÃÍýÏëµÄÒ»²¿·Ö £¬ÒÔÉ«Áн«½¨ÉèÒ»¸ö¹ú¼ÒÖ¸µ¼Î¯Ô±»áÀ´¸ÄÉÆ¸Ã¹ú¼ÒµÄº½¿ÕÍøÂç·ÀÓùÄÜÁ¦¡£¸ÃίԱ»áÓÉINCDÏòµ¼ £¬²¢ÇÒÓÉÒÔÉ«Áн»Í¨²¿¡¢Ãñº½¾Ö¡¢»ú³¡¹ÜÀí¾Ö¡¢Çå¾²¾Ö¡¢¹ú·À²¿¡¢¹ú¼ÒÇ徲ίԱ»áºÍÒÔÉ«Áйú·À¾üµÄ´ú±í×é³É¡£¸ÃÍýÏëµÄÄÚÈݰüÀ¨£ºÍþвӳÉäÏ¢Õù¾ö¼Æ»®ÏîÄ¿¡¢Ôڸ߿Ƽ¼ºÍÍøÂçÐÐÒµÒÔ¼°Ñ§Êõ½çÍÆ¶¯Ç°ÑØÊÖÒÕÑо¿ºÍ¹ú·À½â¾ö¼Æ»®µÄÑз¢¡¢Ó벨Òô¾ÙÐкÏ×÷¡¢½¨ÉèÔËÊä¿ØÖÆÖÐÐÄ¡¢¿ª·¢º½ÐÐÔ±Åàѵ¿Î³ÌµÈ¡£


Ô­ÎÄÁ´½Ó£º

http://www.xinhuanet.com/english/2020-01/13/c_138699304.htm


2¡¢Î¢ÈíÕýʽÖÕÖ¹¶ÔWindows 7¡¢Server 2008ºÍ2008 R2Ìṩ֧³Ö


Ò«ÊÀÓéÀÖ-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ¡£


΢ÈíÓÚ1ÔÂ14ÈÕÕýʽÖÕÖ¹¶ÔWindows 7¡¢Server 2008ºÍServer 2008 R2Ìṩ֧³Ö¡£ÔÚ´ËÖ®ºóÕâЩ²Ù×÷ϵͳÈԿɼÌÐøÊÂÇé £¬µ«½«²»ÔÙÊÕµ½Çå¾²¸üС£¶ÔWindows Server 2008µÄÖÕÖ¹Ö§³ÖÒâζ×ÅÆäÌØÁíÍâÃâ·ÑÇå¾²¸üС¢·ÇÇå¾²¸üС¢Ãâ·ÑµÄÖ§³Ö·þÎñÒÔ¼°ÔÚÏßÊÖÒÕÄÚÈݸüж¼ÒÑ¿¢Ê¡£Î¢Èí±Þ²ßÓû§½«Æä²úÆ·ºÍ·þÎñǨáãµ½Azure»òÊÇÉý¼¶µ½×îа汾Server 2016¡£ÎÞ·¨ÔÚÖ§³ÖÖÕÖ¹ÏÞÆÚ֮ǰÍê³ÉÉý¼¶µÄÈË¿ÉÒÔ¹ºÖÃÀ©Õ¹Çå¾²¸üР£¬ÒÔ± £»¤·þÎñÆ÷ÊÂÇé¸ºÔØÖ±ÖÁÉý¼¶ÎªÖ¹¡£


Ô­ÎÄÁ´½Ó£º

https://www.darkreading.com/risk/microsoft-to-officially-end-support-for-windows-7-server-2008/d/d-id/1336791


3¡¢ÃÀ¹úLimeLeads¹«Ë¾4900ÍòÌõÓû§¼Í¼ÔÚ°µÍøÂÛ̳³öÊÛ


Ò«ÊÀÓéÀÖ-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ¡£


¾ÝZDNet±¨µÀ £¬ºÚ¿ÍOmnichorusÕýÔÚ°µÍøÂÛ̳ÉϳöÊÛÃÀ¹úÊý¾Ý¾­¼ÍÉÌLimeLeadsµÄ4900ÍòÌõÓû§¼Í¼¡£Çå¾²Ñо¿Ô±Bob DiachenkoÈ·ÈÏÕâЩÊý¾ÝÊÇÓɸù«Ë¾µÄÄÚ²¿Elasticsearch·þÎñÆ÷̻¶ÔÚInternetÉÏй¶µÄ¡£Æ¾Ö¤DiachenkoµÄ˵·¨ £¬ÖÁÉÙ´Ó2019Äê7ÔÂ27ÈÕÆðLimeLeadsµÄһ̨·þÎñÆ÷¾Í¿É¹ûÕæ»á¼û £¬ËûÓÚÈ¥Äê9ÔÂ16ÈÕ֪ͨÁ˸ù«Ë¾ £¬¸Ã¹«Ë¾ÔÚµÚ¶þÌìѸËÙ¶Ô·þÎñÆ÷¾ÙÐÐÁ˱ £»¤ £¬µ«ÏÔÈ»OmnichorusÒѾ­ÇÔÈ¡ÁËÕâЩÊý¾Ý £¬²¢ÇÒ´ÓÈ¥Äê10ÔÂÒÔÀ´Ò»Ö±ÔÚÍøÉϳöÊÛ¡£Æ¾Ö¤OmnichorusÐû²¼µÄÊý¾ÝÑù±¾ £¬ÕâЩÊý¾Ý°üÀ¨Óû§µÄÐÕÃû¡¢Ö°Îñ¡¢µç×ÓÓʼþ¡¢¹ÍÖ÷/¹«Ë¾Ãû³Æ¡¢¹«Ë¾µØÖ·¡¢¶¼»á¡¢ÖÝ¡¢ÓÊÕþ±àÂë¡¢µç»°ºÅÂë¡¢ÍøÕ¾URL¡¢¹«Ë¾×ÜÊÕÈëÒÔ¼°¹«Ë¾µÄÔ¤¼ÆÔ±¹¤ÈËÊýµÈÐÅÏ¢¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/49-million-user-records-from-us-data-broker-limeleads-put-up-for-sale-online/


4¡¢ÊÔÓÃAppÐ¶ÔØºóÖ±½Ó¿Û·Ñ £¬È«Çò½ü6ÒÚAndroidÓû§ÖÐÕÐ


Ò«ÊÀÓéÀÖ-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ¡£


SophosÇå¾²Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»×éеÄfleeceware APP £¬ÕâЩAPPÒѾ­±»Áè¼Ý6ÒÚAndroidÓû§ÏÂÔØ×°Öá£fleecewareÊÇÖ¸¹È¸èPlayÊÐËÁÖб£´æµÄÒ»ÖÖÐÂÐͽðÈÚڲƭÐÐΪ £¬ÕâЩAPPÀÄÓÃAndroidÓ¦ÓõÄÊÔÓÃÆÚ¹¦Ð§ÏòÓû§ÊÕ·Ñ¡£Ä¬ÈÏÇéÐÎÏÂAndroidÓû§ÔÚ×¢²áʹÓþßÓÐÊÔÓÃÆÚµÄAPPʱ±ØÐèÊÖ¾Ù´ë·ÏÊÔÓà £¬È»¶ø´ó´ó¶¼Óû§Ö»ÊÇÔÚ²»Ï²»¶µÄʱ¼äÐ¶ÔØAPP £¬¾ø´ó´ó¶¼¿ª·¢Õß½«ÕâÖÖÐ¶ÔØÐÐΪÊÓΪ×÷·ÏÊÔÓà £¬µ«Ò»Ð©¿ª·¢ÕßÔÚÓû§Ð¶ÔغóûÓÐ×÷·ÏÊÔÓò¢ÇÒ¼ÌÐøÊÕ·Ñ¡£Sophos×î³õ·¢Ã÷µÄ24¸öAPP°üÀ¨¶þάÂëɨÃèÆ÷¡¢ÅÌËãÆ÷µÈ £¬ËüÃÇÒÔÕâÖÖ·½·¨ÏòÓû§ÊÕȡÿÄê100ÃÀÔªµ½240ÃÀÔªµÄ¶©ÔÄÓöÈ¡£ÔÚ¿ËÈÕÐû²¼µÄÒ»·Ý±¨¸æÖÐ £¬Sophos·¢Ã÷ÁËÁíÍâ25¸ö´ËÀàAPP £¬Æä×Ü×°ÖÃÁ¿Áè¼Ý6ÒÚ £¬ÍêÕûµÄAPPÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/more-than-600-million-users-installed-android-fleeceware-apps-from-the-play-store/


5¡¢Êý°Ù¸öҽѧ³ÉÏñϵͳÔÚÍøÉÏ̻¶ÁËÊý°ÙÍò»¼ÕßµÄÊý¾Ý


Ò«ÊÀÓéÀÖ-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ¡£


µÂ¹úÇå¾²³§ÉÌGreenbone³ÆÊý°Ù¸ö¿É¹ûÕæ»á¼ûµÄҽѧ³ÉÏñϵͳÔÚ»¥ÁªÍøÉÏ̻¶ÁËÈ«ÇòÊý°ÙÍò»¼ÕßµÄÊý¾Ý¡£¸ÃÏîÑо¿ÖصãÆÊÎöÔÚÍøÉÏ̻¶µÄҽѧͼƬ´æµµºÍͨѶϵͳ£¨PACS£© £¬ÔÚËùÓÐÊÜÆÊÎöµÄPACS·þÎñÆ÷ÖÐ £¬ÓпìÒª1/4µÄϵͳ½«Êý¾Ý̻¶ÔÚ»¥ÁªÍøÉÏ¡£ÏêϸÀ´Ëµ £¬ÔÚ2019Äê7ÔÂÖÁ2019Äê9ÔÂÖ®¼äÆÊÎöµÄ2300¸öϵͳÖÐ £¬ÓÐ590¸ö¿É´ÓInternet»á¼û²¢ÇÒδÉèÃÜÂë £¬¹²ÓÐÁè¼Ý2450ÍòÌõ»¼ÕßÊý¾Ý̻¶ £¬ÔÚ11Ô·ݵÄÑо¿ÖÐ £¬¸Ã¹«Ë¾Í¸Â¶ÓÐ3500ÍòÌõ»¼Õ߼ͼ¿É¹ûÕæ»á¼û¡£ÔÚ9ÔÂÖÁ11ÔÂÖ®¼ä £¬°üÀ¨Ò½ÁÆÍ¼ÏñµÄ̻¶»¼Õ߼ͼÊýÄ¿ÒÑ´Ó440ÍòÔöÌíÁËÒ»±¶ £¬µÖ´ï900Íò¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/unprotected-medical-systems-expose-data-millions-patients