ÐÅÏ¢°²È«Öܱ¨-2018ÄêµÚ18ÖÜ
°ä²¼¹¦·ò 2018-05-07
Ò»¡¢±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
2018Äê04ÔÂ30ÈÕÖÁ05ÔÂ06ÈÕ¹²ÊÕ¼°²È«·ì϶45¸ö£¬£¬£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇF5 BIG-IP http/2ÒªÇ󻨾ø·þÎñ°²È«·ì϶£»£»£»£»£»£»Xen 'x86/x86_64/entry.S'»Ø¾ø·þÎñ·ì϶£»£»£»£»£»£»Apache Ambari CVE-2018-8003Ŀ¼±éÀú·ì϶£»£»£»£»£»£»TP-Link EAP ControllerºÍOmada ControllerȨÏÞÌáÉý·ì϶£»£»£»£»£»£»Microsoft Windows Host Compute Service Shim´úÂëÖ´Ðзì϶¡£¡£¡£¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇ×êÑÐÈËÔ±·¢ÏÖGPON·ÓÉÆ÷´æÔÚRCE·ì϶£¬£¬£¬£¬£¬£¬£¬£¬³¬¹ý100ÍòÓû§ÊÜÓ°Ï죻£»£»£»£»£»ÃÀICS-CERT³ÆBD¹«Ë¾µÄ¶à¸öÒ½ÁÆÉ豸Ò×ÊÜKRACK·ì϶µÄÓ°Ï죻£»£»£»£»£»GitHubÄÚ²¿ÈÕÖ¾³öÏÖbug£¬£¬£¬£¬£¬£¬£¬£¬²¿ÃÅÓû§µÄÃÜÂë¶³ö£»£»£»£»£»£»×êÑÐÍŶӷ¢ÏÖ³¯ÏÊ·´²¡¶¾Èí¼þSiliVaccineÔ̺¬¶ñÒâÈí¼þJAKU£»£»£»£»£»£»Ëæ×ÅWebStresserÍøÕ¾±»¹Ø¹Ø£¬£¬£¬£¬£¬£¬£¬£¬Õû¸öÅ·ÖÞµÄDDoS¹¥»÷½µÂä60%¡£¡£¡£¡£¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖÓ×£¡£¡£¡£¡£
¶þ¡¢³ÁÒª°²È«·ì϶Áбí
1¡¢F5 BIG-IP http/2ÒªÇ󻨾ø·þÎñ°²È«·ì϶
F5 BIG-IP´¦ÖÃÌØÊâµÄhttp/2ÒªÇó´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬½øÐлؾø·þÎñ¹¥»÷¡£¡£¡£¡£¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://support.f5.com/csp/article/K45320419
2¡¢Xen 'x86/x86_64/entry.S'»Ø¾ø·þÎñ·ì϶
Xen 'x86/x86_64/entry.S' x86 PV guest OSÓû§´¦ÖÃINT 80´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐí±¾µØ¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬Ê¹ÏµÍ³±ÀÀ£¡£¡£¡£¡£¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://xenbits.xen.org/xsa/advisory-259.html
3¡¢Apache Ambari CVE-2018-8003Ŀ¼±éÀú·ì϶
Apache Ambari´æÔÚĿ¼±éÀúÒªÇó·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ìÏ¶ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬Î´ÊÚȨ½Ó¼ûϵͳÎļþ¡£¡£¡£¡£¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://cwiki.apache.org/confluence/display/AMBARI/Ambari+Vulnerabilities#AmbariVulnerabilities-CVE-2018-8003
4¡¢TP-Link EAP ControllerºÍOmada ControllerȨÏÞÌáÉý·ì϶
TP-Link EAP ControllerºÍOmada ControllerûÓнÚÔìWeb APIµÄʹÓÃȨÏÞ£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ìÏ¶ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬ÒÔÖÎÀíÔ±Éí·Ý·¢ËÍÒªÇ󡣡£¡£¡£¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://www.coresecurity.com/advisories/tp-link-eap-controller-multiple-vulnerabilities
5¡¢Microsoft Windows Host Compute Service Shim´úÂëÖ´Ðзì϶
Microsoft Windows Host Compute Service Shim´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ìÏ¶ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬Ö´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8115
Èý¡¢³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢×êÑÐÈËÔ±·¢ÏÖGPON·ÓÉÆ÷´æÔÚRCE·ì϶£¬£¬£¬£¬£¬£¬£¬£¬³¬¹ý100ÍòÓû§ÊÜÓ°Ïì

VPNMentorµÄ°²È«×êÑÐÈËÔ±·¢ÏÖGPON¼ÒÓ÷ÓÉÆ÷´æÔÚRCE·ì϶£¬£¬£¬£¬£¬£¬£¬£¬³¬¹ý100ÍòÓû§ÊÜÓ°Ïì¡£¡£¡£¡£¡£×êÑÐÈËÔ±½«Éí·ÝÈÏÖ¤ÈÆ¹ý·ì϶£¨CVE-2018-10561£©ºÍºÅÁî×¢Èë·ì϶£¨CVE-2018-10562£©Ïà½áºÏ£¬£¬£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐкÍÊÕÊÜÉ豸¡£¡£¡£¡£¡£×êÑÐÈËÔ±Åû¶ÁËÓйØPoCÊÓÆµ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/71987/hacking/gpon-home-routers-hack.html
2¡¢ÃÀICS-CERT³ÆBD¹«Ë¾µÄ¶à¸öÒ½ÁÆÉ豸Ò×ÊÜKRACK·ì϶µÄÓ°Ïì

ÃÀICS-CERT³ÆÒ½ÁƼ¼Êõ¹«Ë¾BDµÄÒ©ÎïºÍ¹©¸øÖÎÀíϵͳBD PyxisµÄ¶à¸ö°æ±¾Êܵ½KRACK·ì϶µÄÓ°Ï죬£¬£¬£¬£¬£¬£¬£¬Ô̺¬BD Pyxis Anesthesia ES¡¢BD Pyxis SupplyStationºÍBD Pyxis ParxÊÖ³ÖÉ豸µÈ12¸ö°æ±¾¡£¡£¡£¡£¡£ÕâÒâζ×Å»¼ÕßµÄÐÅÏ¢¿ÉÄÜͨ¹ýWi-Fiй¶¡£¡£¡£¡£¡£BD¹«Ë¾°µÊ¾ÆäÒÑΪ´óÎÞÊýÉ豸ִÐÐÁ˵ÚÈý·½¹©¸øÉ̲¹¶¡£¡£¡£¡£¡£¬£¬£¬£¬£¬£¬£¬£¬²¢ÔÚ¶½´ÙÓû§½øÐв¿Ê𡣡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://threatpost.com/krack-vulnerability-puts-medical-devices-at-risk/131552/
3¡¢GitHubÄÚ²¿ÈÕÖ¾³öÏÖbug£¬£¬£¬£¬£¬£¬£¬£¬²¿ÃÅÓû§µÄÃÜÂë¶³ö

GitHubÏò²¿ÃÅÓû§ÖÒ¸æ³ÆÆäÒ»¸öbugµ¼ÖÂÓû§µÄÃ÷ÎÄÃÜÂë±»¼Í¼ÔÚ¹«Ë¾µÄÄÚ²¿ÈÕÖ¾ÖÓ×£¡£¡£¡£¡£Ö»ÓÐÉÙÊýµÄGitHubÔ±¹¤ÓµÓÐÕâЩÈÕÖ¾µÄ½Ó¼ûȨÏÞ¡£¡£¡£¡£¡£GitHubÔ¤¼ÆÊÜÓ°ÏìµÄÓû§ÊýÁ¿ºÜµÍ£¬£¬£¬£¬£¬£¬£¬£¬µ«²¢Ã»Óа䲼¾ßÌåÊý×Ö¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/github-accidentally-recorded-some-plaintext-passwords-in-its-internal-logs/
4¡¢×êÑÐÍŶӷ¢ÏÖ³¯ÏÊ·´²¡¶¾Èí¼þSiliVaccineÔ̺¬¶ñÒâÈí¼þJAKU

Check PointµÄ×êÑÐÈËÔ±·ÖÎöÁ˳¯ÏÊ·´²¡¶¾Èí¼þSiliVaccineµÄÒ»¸öÑù±¾£¬£¬£¬£¬£¬£¬£¬£¬·¢ÏÖSiliVaccineÊÇ»ùÓÚÈÕ±¾Ç÷Ïò¿Æ¼¼¹«Ë¾10Äêǰ¿ª·¢µÄ·´¶ñÒâÈí¼þÒýÇæ¡£¡£¡£¡£¡£Ç÷Ïò¿Æ¼¼Ö¤ÊµSiliVaccineÔ̺¬ÊôÓÚÇ÷Ïò¿Æ¼¼µÄ´óÁ¿10¶àÄêǰµÄ·À²¡¶¾ÒýÇæ´úÂë¡£¡£¡£¡£¡£×êÑÐÈËÔ±»¹·¢ÏÖSiliVaccine½«Ìض¨¶ñÒâÈí¼þµÄÊðÃû²ÎÓë°×Ãûµ¥£¬£¬£¬£¬£¬£¬£¬£¬²¢ÇÒ»¹°ó¸¿Á˶ñÒâÈí¼þJAKU¡£¡£¡£¡£¡£JAKUÊÇÒ»¸öϰȾÁËÔ¼1.9Íò¸öϵͳµÄ½©Ê¬ÍøÂ磬£¬£¬£¬£¬£¬£¬£¬ÖØÒªÕë¶Ôº«¹úºÍÈÕ±¾¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://research.checkpoint.com/silivaccine-a-look-inside-north-koreas-anti-virus/
5¡¢Ëæ×ÅWebStresserÍøÕ¾±»¹Ø¹Ø£¬£¬£¬£¬£¬£¬£¬£¬Õû¸öÅ·ÖÞµÄDDoS¹¥»÷½µÂä60%

DDoS·À»¤¹«Ë¾Link11Ö¸³ö£¬£¬£¬£¬£¬£¬£¬£¬WebStresserÍøÕ¾µÄ¹Ø¹Ø¶ÔDDoS¹¥»÷»î¶¯ÓгÁ´óµÄÓ°Ï죬£¬£¬£¬£¬£¬£¬£¬³ö¸ñÊÇÔÚÅ·ÖÞ¡£¡£¡£¡£¡£Link11½²»°È˳ÆËæ×ŸÃÍøÕ¾µÄ¹Ø¹Ø£¬£¬£¬£¬£¬£¬£¬£¬Å·ÖÞµÄDDoS¹¥»÷½µÂäÁËÔ¼60%£¬£¬£¬£¬£¬£¬£¬£¬Ïà±È·åÖµ½µÂäÁË64%¡£¡£¡£¡£¡£µ«DDoS¹¥»÷µÄ»ººÍ¿ÉÄÜÖ»ÊÇÁÙʱµÄ£¬£¬£¬£¬£¬£¬£¬£¬Ëæ×ÅеÄDDoS·þÎñ½«Ìí²¹WebStresserµÄ¿Õȱ£¬£¬£¬£¬£¬£¬£¬£¬Ô¤¼ÆDDoS¹¥»÷½«»áÔÙ´ÎÔö³¤¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/ddos-attacks-go-down-60-percent-across-europe-following-webstressers-takedown/


¾©¹«Íø°²±¸11010802024551ºÅ