ÐÅÏ¢Çå¾²Öܱ¨-2020ÄêµÚ03ÖÜ
Ðû²¼Ê±¼ä 2020-01-20
±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö
2020Äê01ÔÂ13ÈÕÖÁ19ÈÕ¹²ÊÕ¼Çå¾²Îó²î53¸ö£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇMicrosoft Windows CryptoAPIÑéÖ¤ÈÆ¹ýÎó²î; Apache XML-RPC XMLRPC client´úÂëÖ´ÐÐÎó²î£»£»£»£»£»£»£»Oracle E-Business Suite Human Resources CVE-2020-2587δÃ÷´úÂëÖ´ÐÐÎó²î£»£»£»£»£»£»£»Adobe Illustrator CC CVE-2020-3710ÄÚ´æ¹ýʧÒýÓôúÂëÖ´ÐÐÎó²î£»£»£»£»£»£»£»Microsoft .NET Core CVE-2020-0602Ô¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇÒÔÉ«ÁÐÆô¶¯Ãñº½ÍøÂçÇå¾²ÍýÏ룬£¬£¬£¬£¬£¬½«¸ÄÉÆº½¿ÕÍøÂç·ÀÓùÄÜÁ¦£»£»£»£»£»£»£»Î¢ÈíÕýʽÖÕÖ¹¶ÔWindows 7¡¢Server 2008ºÍ2008 R2Ìṩ֧³Ö£»£»£»£»£»£»£»ÃÀ¹úLimeLeads¹«Ë¾4900ÍòÌõÓû§¼Í¼ÔÚ°µÍøÂÛ̳³öÊÛ£»£»£»£»£»£»£»ÊÔÓÃAppÐ¶ÔØºóÖ±½Ó¿Û·Ñ£¬£¬£¬£¬£¬£¬È«Çò½ü6ÒÚAndroidÓû§ÖÐÕУ»£»£»£»£»£»£»Êý°Ù¸öҽѧ³ÉÏñϵͳÔÚÍøÉÏ̻¶ÁËÊý°ÙÍò»¼ÕßµÄÊý¾Ý¡£¡£¡£
ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£
Ö÷ÒªÇå¾²Îó²îÁбí
1. Microsoft Windows CryptoAPIÑéÖ¤ÈÆ¹ýÎó²î
Microsoft Windows CryptoAPI´¦Öóͷ£ECCÍÖÔ²ÇúÏß¼ÓÃܱ£´æÇå¾²Îó²î£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬¿ÉÒÔʹÓÃαÔìµÄÖ¤Êé¶Ô¶ñÒâµÄ¿ÉÖ´ÐÐÎļþ¾ÙÐÐÊðÃû£¬£¬£¬£¬£¬£¬Ê¹Îļþ¿´ÆðÀ´À´×Ô¿ÉÐŵÄȪԴ£¬£¬£¬£¬£¬£¬»òÕß¾ÙÐÐÖÐÐÄÈ˹¥»÷²¢½âÃÜÓû§ÅþÁ¬µ½ÊÜÓ°ÏìÈí¼þµÄÉñÃØÐÅÏ¢¡£¡£¡£
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0601
2. Apache XML-RPC XMLRPC client´úÂëÖ´ÐÐÎó²î
Apache XML-RPC XMLRPC clientʵÏÖXMLRPC¹ýʧÐÂÎÅfaultCauseÊôÐÔ´¦Öóͷ£±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²î¹¹½¨¶ñÒâXMLRPCЧÀÍÇëÇ󣬣¬£¬£¬£¬£¬¿ÉʹӦÓóÌÐòÍ߽⻣»£»£»£»£»£»òÕßÖ´ÐÐí§Òâ´úÂë¡£¡£¡£
https://access.redhat.com/security/cve/cve-2019-17570
3. Oracle E-Business Suite Human Resources CVE-2020-2587δÃ÷´úÂëÖ´ÐÐÎó²î
Oracle E-Business Suite Human Resources±£´æÎ´Ã÷Çå¾²Îó²î£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬¿ÉʹӦÓóÌÐòÍ߽⻣»£»£»£»£»£»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£
https://www.oracle.com/security-alerts/cpujan2020.html
4. Adobe Illustrator CC CVE-2020-3710ÄÚ´æ¹ýʧÒýÓôúÂëÖ´ÐÐÎó²î
Adobe Illustrator CC´¦Öóͷ£Îļþ±£´æÄÚ´æÆÆËðÎó²î£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬£¬£¬¿ÉʹӦÓóÌÐòÍ߽⻣»£»£»£»£»£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£
https://helpx.adobe.com/security/products/illustrator/apsb20-03.html
5. Microsoft .NET Core CVE-2020-0602Ô¶³Ì´úÂëÖ´ÐÐÎó²î
Microsoft .NET CoreʵÏÖ±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0602
Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö
1¡¢ÒÔÉ«ÁÐÆô¶¯Ãñº½ÍøÂçÇå¾²ÍýÏ룬£¬£¬£¬£¬£¬½«¸ÄÉÆº½¿ÕÍøÂç·ÀÓùÄÜÁ¦
¾ÝÉÏÖÜÈÕÒÔÉ«Áйú¼ÒÍøÂçÖÎÀí¾Ö£¨INCD£©±¨µÀ£¬£¬£¬£¬£¬£¬ÒÔÉ«ÁÐÕþ¸®Åú×¼ÁËÒ»ÏîÃñº½ÍøÂçÇå¾²ÍýÏë¡£¡£¡£×÷Ϊ¸ÃÍýÏëµÄÒ»²¿·Ö£¬£¬£¬£¬£¬£¬ÒÔÉ«Áн«½¨ÉèÒ»¸ö¹ú¼ÒÖ¸µ¼Î¯Ô±»áÀ´¸ÄÉÆ¸Ã¹ú¼ÒµÄº½¿ÕÍøÂç·ÀÓùÄÜÁ¦¡£¡£¡£¸ÃίԱ»áÓÉINCDÏòµ¼£¬£¬£¬£¬£¬£¬²¢ÇÒÓÉÒÔÉ«Áн»Í¨²¿¡¢Ãñº½¾Ö¡¢»ú³¡ÖÎÀí¾Ö¡¢Çå¾²¾Ö¡¢¹ú·À²¿¡¢¹ú¼ÒÇ徲ίԱ»áºÍÒÔÉ«Áйú·À¾üµÄ´ú±í×é³É¡£¡£¡£¸ÃÍýÏëµÄÄÚÈݰüÀ¨£ºÍþвӳÉäÏ¢Õù¾ö¼Æ»®ÏîÄ¿¡¢Ôڸ߿Ƽ¼ºÍÍøÂçÐÐÒµÒÔ¼°Ñ§Êõ½çÍÆ¶¯Ç°ÑØÊÖÒÕÑо¿ºÍ¹ú·À½â¾ö¼Æ»®µÄÑз¢¡¢Ó벨Òô¾ÙÐÐÏàÖú¡¢½¨ÉèÔËÊä¿ØÖÆÖÐÐÄ¡¢¿ª·¢º½ÐÐÔ±Åàѵ¿Î³ÌµÈ¡£¡£¡£
ÔÎÄÁ´½Ó£º
http://www.xinhuanet.com/english/2020-01/13/c_138699304.htm
2¡¢Î¢ÈíÕýʽÖÕÖ¹¶ÔWindows 7¡¢Server 2008ºÍ2008 R2Ìṩ֧³Ö
΢ÈíÓÚ1ÔÂ14ÈÕÕýʽÖÕÖ¹¶ÔWindows 7¡¢Server 2008ºÍServer 2008 R2Ìṩ֧³Ö¡£¡£¡£ÔÚ´ËÖ®ºóÕâЩ²Ù×÷ϵͳÈԿɼÌÐøÊÂÇ飬£¬£¬£¬£¬£¬µ«½«²»ÔÙÊÕµ½Çå¾²¸üС£¡£¡£¶ÔWindows Server 2008µÄÖÕÖ¹Ö§³ÖÒâζ×ÅÆäÌØÁíÍâÃâ·ÑÇå¾²¸üС¢·ÇÇå¾²¸üС¢Ãâ·ÑµÄÖ§³ÖЧÀÍÒÔ¼°ÔÚÏßÊÖÒÕÄÚÈݸüж¼ÒÑ¿¢Ê¡£¡£¡£Î¢Èí±Þ²ßÓû§½«Æä²úÆ·ºÍЧÀÍǨáãµ½Azure»òÊÇÉý¼¶µ½×îа汾Server 2016¡£¡£¡£ÎÞ·¨ÔÚÖ§³ÖÖÕÖ¹ÏÞÆÚ֮ǰÍê³ÉÉý¼¶µÄÈË¿ÉÒÔ¹ºÖÃÀ©Õ¹Çå¾²¸üУ¬£¬£¬£¬£¬£¬ÒÔ±£»£»£»£»£»£»£»¤Ð§ÀÍÆ÷ÊÂÇé¸ºÔØÖ±ÖÁÉý¼¶ÎªÖ¹¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.darkreading.com/risk/microsoft-to-officially-end-support-for-windows-7-server-2008/d/d-id/1336791
3¡¢ÃÀ¹úLimeLeads¹«Ë¾4900ÍòÌõÓû§¼Í¼ÔÚ°µÍøÂÛ̳³öÊÛ
¾ÝZDNet±¨µÀ£¬£¬£¬£¬£¬£¬ºÚ¿ÍOmnichorusÕýÔÚ°µÍøÂÛ̳ÉϳöÊÛÃÀ¹úÊý¾Ý¾¼ÍÉÌLimeLeadsµÄ4900ÍòÌõÓû§¼Í¼¡£¡£¡£Çå¾²Ñо¿Ô±Bob DiachenkoÈ·ÈÏÕâЩÊý¾ÝÊÇÓɸù«Ë¾µÄÄÚ²¿ElasticsearchЧÀÍÆ÷̻¶ÔÚInternetÉÏй¶µÄ¡£¡£¡£Æ¾Ö¤DiachenkoµÄ˵·¨£¬£¬£¬£¬£¬£¬ÖÁÉÙ´Ó2019Äê7ÔÂ27ÈÕÆðLimeLeadsµÄһ̨ЧÀÍÆ÷¾Í¿É¹ûÕæ»á¼û£¬£¬£¬£¬£¬£¬ËûÓÚÈ¥Äê9ÔÂ16ÈÕ֪ͨÁ˸ù«Ë¾£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÔÚµÚ¶þÌìѸËÙ¶ÔЧÀÍÆ÷¾ÙÐÐÁ˱£»£»£»£»£»£»£»¤£¬£¬£¬£¬£¬£¬µ«ÏÔÈ»OmnichorusÒѾÇÔÈ¡ÁËÕâЩÊý¾Ý£¬£¬£¬£¬£¬£¬²¢ÇÒ´ÓÈ¥Äê10ÔÂÒÔÀ´Ò»Ö±ÔÚÍøÉϳöÊÛ¡£¡£¡£Æ¾Ö¤OmnichorusÐû²¼µÄÊý¾ÝÑù±¾£¬£¬£¬£¬£¬£¬ÕâЩÊý¾Ý°üÀ¨Óû§µÄÐÕÃû¡¢Ö°Îñ¡¢µç×ÓÓʼþ¡¢¹ÍÖ÷/¹«Ë¾Ãû³Æ¡¢¹«Ë¾µØµã¡¢¶¼»á¡¢ÖÝ¡¢ÓÊÕþ±àÂë¡¢µç»°ºÅÂë¡¢ÍøÕ¾URL¡¢¹«Ë¾×ÜÊÕÈëÒÔ¼°¹«Ë¾µÄÔ¤¼ÆÔ±¹¤ÈËÊýµÈÐÅÏ¢¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/49-million-user-records-from-us-data-broker-limeleads-put-up-for-sale-online/
4¡¢ÊÔÓÃAppÐ¶ÔØºóÖ±½Ó¿Û·Ñ£¬£¬£¬£¬£¬£¬È«Çò½ü6ÒÚAndroidÓû§ÖÐÕÐ
SophosÇå¾²Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»×éеÄfleeceware APP£¬£¬£¬£¬£¬£¬ÕâЩAPPÒѾ±»Áè¼Ý6ÒÚAndroidÓû§ÏÂÔØ×°Öᣡ£¡£fleecewareÊÇÖ¸¹È¸èPlayÊÐËÁÖб£´æµÄÒ»ÖÖÐÂÐͽðÈÚÚ²ÆÐÐΪ£¬£¬£¬£¬£¬£¬ÕâЩAPPÀÄÓÃAndroidÓ¦ÓõÄÊÔÓÃÆÚ¹¦Ð§ÏòÓû§ÊÕ·Ñ¡£¡£¡£Ä¬ÈÏÇéÐÎÏÂAndroidÓû§ÔÚ×¢²áʹÓþßÓÐÊÔÓÃÆÚµÄAPPʱ±ØÐèÊÖ¾Ù´ë·ÏÊÔÓ㬣¬£¬£¬£¬£¬È»¶ø´ó´ó¶¼Óû§Ö»ÊÇÔÚ²»Ï²»¶µÄʱ¼äÐ¶ÔØAPP£¬£¬£¬£¬£¬£¬¾ø´ó´ó¶¼¿ª·¢Õß½«ÕâÖÖÐ¶ÔØÐÐΪÊÓΪ×÷·ÏÊÔÓ㬣¬£¬£¬£¬£¬µ«Ò»Ð©¿ª·¢ÕßÔÚÓû§Ð¶ÔغóûÓÐ×÷·ÏÊÔÓò¢ÇÒ¼ÌÐøÊÕ·Ñ¡£¡£¡£Sophos×î³õ·¢Ã÷µÄ24¸öAPP°üÀ¨¶þάÂëɨÃèÆ÷¡¢ÅÌËãÆ÷µÈ£¬£¬£¬£¬£¬£¬ËüÃÇÒÔÕâÖÖ·½·¨ÏòÓû§ÊÕȡÿÄê100ÃÀÔªµ½240ÃÀÔªµÄ¶©ÔÄÓöȡ£¡£¡£ÔÚ¿ËÈÕÐû²¼µÄÒ»·Ý±¨¸æÖУ¬£¬£¬£¬£¬£¬Sophos·¢Ã÷ÁËÁíÍâ25¸ö´ËÀàAPP£¬£¬£¬£¬£¬£¬Æä×Ü×°ÖÃÁ¿Áè¼Ý6ÒÚ£¬£¬£¬£¬£¬£¬ÍêÕûµÄAPPÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/more-than-600-million-users-installed-android-fleeceware-apps-from-the-play-store/
5¡¢Êý°Ù¸öҽѧ³ÉÏñϵͳÔÚÍøÉÏ̻¶ÁËÊý°ÙÍò»¼ÕßµÄÊý¾Ý
µÂ¹úÇå¾²³§ÉÌGreenbone³ÆÊý°Ù¸ö¿É¹ûÕæ»á¼ûµÄҽѧ³ÉÏñϵͳÔÚ»¥ÁªÍøÉÏ̻¶ÁËÈ«ÇòÊý°ÙÍò»¼ÕßµÄÊý¾Ý¡£¡£¡£¸ÃÏîÑо¿ÖصãÆÊÎöÔÚÍøÉÏ̻¶µÄҽѧͼƬ´æµµºÍͨѶϵͳ£¨PACS£©£¬£¬£¬£¬£¬£¬ÔÚËùÓÐÊÜÆÊÎöµÄPACSЧÀÍÆ÷ÖУ¬£¬£¬£¬£¬£¬ÓпìÒª1/4µÄϵͳ½«Êý¾Ý̻¶ÔÚ»¥ÁªÍøÉÏ¡£¡£¡£ÏêϸÀ´Ëµ£¬£¬£¬£¬£¬£¬ÔÚ2019Äê7ÔÂÖÁ2019Äê9ÔÂÖ®¼äÆÊÎöµÄ2300¸öϵͳÖУ¬£¬£¬£¬£¬£¬ÓÐ590¸ö¿É´ÓInternet»á¼û²¢ÇÒδÉèÃÜÂ룬£¬£¬£¬£¬£¬¹²ÓÐÁè¼Ý2450ÍòÌõ»¼ÕßÊý¾Ý̻¶£¬£¬£¬£¬£¬£¬ÔÚ11Ô·ݵÄÑо¿ÖУ¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾Í¸Â¶ÓÐ3500ÍòÌõ»¼Õ߼ͼ¿É¹ûÕæ»á¼û¡£¡£¡£ÔÚ9ÔÂÖÁ11ÔÂÖ®¼ä£¬£¬£¬£¬£¬£¬°üÀ¨Ò½ÁÆÍ¼ÏñµÄ̻¶»¼Õ߼ͼÊýÄ¿ÒÑ´Ó440ÍòÔöÌíÁËÒ»±¶£¬£¬£¬£¬£¬£¬µÖ´ï900Íò¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/unprotected-medical-systems-expose-data-millions-patients


¾©¹«Íø°²±¸11010802024551ºÅ