ÐÅÏ¢°²È«Öܱ¨-2019ÄêµÚ46ÖÜ

°ä²¼¹¦·ò 2019-11-25

>±¾Öܰ²È«Ì¬ÊÆ×ÛÊö



2019Äê11ÔÂ18ÈÕÖÁ24ÈÕ¹²ÊÕ¼°²È«·ì϶50¸ö£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇApache Solr solr.in.shÔ¶³Ì´úÂëÖ´Ðзì϶; Apache Shiro "remember me" Oracle Padding¹¥»÷·ì϶£» £»£»£»£»ISC BIND TCP¿Í»§¶ËÊýÁ¿Ï޶Ȼؾø·þÎñ·ì϶£» £»£»£»£»Fortinet FortiOS SSL VPNÃÅ»§»Ø¾ø·þÎñ·ì϶£» £»£»£»£»Qualcomm QCA6174_9377 Bluetooth HOSTȨÏÞÌáÉý·ì϶¡£¡£¡£¡£¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇNowSecureÅû¶Android libpac¿âÖеÄRCE·ì϶£» £»£»£»£»AndroidÏà»ú·ì϶¿É°ÂÃØÅÄÕÕ¼°Â¼ÔìÊÓÆµ£» £»£»£»£»ºÚ¿ÍÔÚÍøÉϰ䲼¿ªÂüÒøÐеÄ2TBÊý¾Ý£» £»£»£»£»WordPress Jetpack²å¼þ·ì϶ӰÏìÊý°ÙÍòÍøÕ¾£» £»£»£»£»Oracle EBS½Ó¼û½ÚÔì²»µ±·ì϶ӰÏìÉÏÍò¼ÒÆóÒµ¡£¡£¡£¡£¡£¡£¡£¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖÓ×£¡£¡£¡£¡£¡£¡£¡£


>³ÁÒª°²È«·ì϶Áбí



1. Apache Solr solr.in.shÔ¶³Ì´úÂëÖ´Ðзì϶
Apache SolrûÓа²È«µØÉèÖÃĬÈÏsolr.in.shÅäÖÃÎļþµÄENABLE_REMOTE_JMX_OPTSÅäÖÃÑ¡Ï£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬Î´ÊÚȨÉÏ´«´úÂë²¢Ö´ÐÓ×£¡£¡£¡£¡£¡£¡£¡£
https://lists.apache.org/thread.html/6640c7e370fce2b74e466a605a46244ccc40666ad9e3064a4e04a85d@%3Csolr-user.lucene.apache.org%3E

2. Apache Shiro "remember me" Oracle Padding¹¥»÷·ì϶
Apache Shiro "remember me"´æÔÚOracle Padding·ì϶£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£
https://lists.apache.org/thread.html/c9db14cfebfb8e74205884ed2bf2e2b30790ce24b7dde9191c82572c@%3Cdev.shiro.apache.org%3E

3. ISC BIND TCP¿Í»§¶ËÊýÁ¿Ï޶Ȼؾø·þÎñ·ì϶
ISC BIND TCP¿Í»§¶ËÊýÁ¿ÏÞ¶È´¦ÖôæÔÚ°²È«·ì϶£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»µ¥¸öÁ´½ÓÉÏͨ¹ýÒ»¸öTCP¿Í»§¶Ë·¢ËÍ´óÁ¿DNSÒªÇ󣬣¬£¬£¬£¬¿Éʹϵͳ±ÀÀ£¡£¡£¡£¡£¡£¡£¡£¡£
https://access.redhat.com/security/cve/cve-2019-6477

4. Fortinet FortiOS SSL VPNÃÅ»§»Ø¾ø·þÎñ·ì϶
Fortinet FortiOS SSL VPN´æÔÚÊäÈëÑéÖ¤·ì϶£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬¿ÉʹSSL VPN·þÎñ±ÀÀ£¡£¡£¡£¡£¡£¡£¡£¡£
https://www.auscert.org.au/bulletins/ESB-2019.4388/

5. Qualcomm QCA6174_9377 Bluetooth HOSTȨÏÞÌáÉý·ì϶
Qualcomm QCA6174_9377 Bluetooth HOSTȨÏÞ´¦ÖôæÔÚ°²È«·ì϶£¬£¬£¬£¬£¬ÔÊÐíµÍȨÏÞ¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬Ð´¶ñÒâ×¢²áÊý¾Ý£¬£¬£¬£¬£¬ÌáÉýȨÏÞ¡£¡£¡£¡£¡£¡£¡£¡£
https://www.qualcomm.com/company/product-security/bulletins/october-2019-bulletin


>³ÁÒª°²È«ÊÂÎñ×ÛÊö



1¡¢NowSecureÅû¶Android libpac¿âÖеÄRCE·ì϶


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


NowSecure×êÑÐÈËÔ±·¢ÏÖAndroidϵͳʹÓõÄlibpac¿âÖдæÔÚRCE·ì϶£¨CVE-2019-2205£©¡£¡£¡£¡£¡£¡£¡£¡£libpacÊÇÒ»¸ö»ùÓÚChromiumÏîÄ¿´úÂëµÄ¿â£¬£¬£¬£¬£¬¸Ã¿âʹÓþ²Ì¬Á´½ÓµÄV8 JSÒýÇæÀ´½âÎöJavaScript£¬£¬£¬£¬£¬ÕâΪƽ̨ÀûÓ÷¨Ê½´øÀ´Á˾޴óµÄ¹¥»÷Ãæ¡£¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±·¢ÏÖJSº¯ÊýFindProxyForUrl¸ßµÍÎÄÖеÄArrayBuffers·ÖÅäÆ÷ÉêÃ÷²»ÕýÈ·£¬£¬£¬£¬£¬¿ÉÖÂÕ»ÉϵÄVPTR±»¸²¸Ç£¬£¬£¬£¬£¬Õâ¿ÉÄܱ»ÓÃÓÚÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£¹È¸èÔÚ11ÔÂAndroid°²È«¸üÐÂÖн¨¸´Á˸÷ì϶¡£¡£¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.nowsecure.com/blog/2019/11/13/nowsecure-discovers-critical-android-vuln-that-may-lead-to-remote-code-execution/

2¡¢AndroidÏà»ú·ì϶¿É°ÂÃØÅÄÕÕ¼°Â¼ÔìÊÓÆµ


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


CheckmarxµÄ×êÑÐÈËÔ±ÔÚAndroidÏà»úÀûÓÃÖз¢ÏÖÒ»¸öзì϶£¬£¬£¬£¬£¬¼´APP¿ÉÔÚûÓÐȨÏÞµÄÇé¿öÏÂÅÄÕÕ¡¢Â¼ÔìÊÓÆµ»ò»ñÈ¡É豸µÄµØÎ»¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶£¨CVE-2019-2234£©Ï൱ΣÏÕ£¬£¬£¬£¬£¬ÓÉÓÚËüÄܹ»Ê¹APPÔÚÊÖ»úËøÆÁµÄ״̬ϰÂÃØÅÄÕպͼÏñ£¬£¬£¬£¬£¬Ò²Äܹ»´Ó´æ´¢µÄÕÕÆ¬ÖÐÌáÈ¡GPSµØÎ»Êý¾Ý£¬£¬£¬£¬£¬»¹Äܹ»½«ÕâЩÊý¾Ý·¢Ëͻع¥»÷ÕßµÄÔ¶³Ì·þÎñÆ÷¡£¡£¡£¡£¡£¡£¡£¡£Æ¾¾ÝGoogleµÄ˵·¨£¬£¬£¬£¬£¬Ïà»úÀûÓÃÒÑÓÚ2019Äê7ÔÂͨ¹ýGoogle PlayÉ̵ê¸üн¨¸´ÁË´Ë·ì϶¡£¡£¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/android-camera-app-bug-lets-apps-record-video-without-permission/

3¡¢ºÚ¿ÍÔÚÍøÉϰ䲼¿ªÂüÒøÐеÄ2TBÊý¾Ý


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ºÚ¿Í´Ó¿ªÂüÒøÐÐÇÔÈ¡ÁË2TBµÄÊý¾Ý²¢°ä²¼ÔÚÍøÉÏ¡£¡£¡£¡£¡£¡£¡£¡£¾Ý³ÆÕâЩÊý¾ÝÊÇÓɺڿͻòºÚ¿ÍÍÅ»ïPhineas FisherÇÔÈ¡µÄ£¬£¬£¬£¬£¬²¢Í¨¹ýDistributed Denial of SecretsÏîÄ¿°ä²¼¡£¡£¡£¡£¡£¡£¡£¡£Êý¾Ý¼¯ÖÐÔ̺¬¿ªÂüÒøÐÐΪÆäÈ«Çò¿Í»§ÖÎÀíµÄ³¬¹ý3800¼Ò¹«Ë¾¡¢ÐÅÈκÍÓ×ÎÒÕË»§µÄ¾ßÌ岯ÕþÐÅÏ¢£¬£¬£¬£¬£¬ÉõÖÁÔ̺¬ÕË»§Óà¶î¡£¡£¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿£¿ªÂüÒøÐв¢Î´ÈÏ¿ÉÊý¾Ýй¶£¬£¬£¬£¬£¬µ«°²È«×¨¼Ò°ÑÎȵ½ÆäºÜ¶à·þÎñÓÚ11ÔÂ17ÈÕÒò¡°³Á´óÉý¼¶ºÍÊØ»¤¡±¶ø´¦ÓÚ²»³ÉÓÃ״̬¡£¡£¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/94136/data-breach/cayman-national-bank-data-leak.html

4¡¢WordPress Jetpack²å¼þ·ì϶ӰÏìÊý°ÙÍòÍøÕ¾


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Jetpack¿ª·¢ÍŶӶ½´ÙWordPressÍøÕ¾ÖÎÀíÔ±Á¢¿ÌÀûÓÃJetpack 7.9.1¹Ø¼ü°²È«¸üУ¬£¬£¬£¬£¬ÒÔ½¨¸´Ò»¸ö¹Ø¼ü·ì϶¡£¡£¡£¡£¡£¡£¡£¡£¹ÌÈ»¸ÃÍŶÓûÓÐÅû¶Óйظ÷ì϶µÄ¾ßÌåÐÅÏ¢£¬£¬£¬£¬£¬µ«Æ¾¾ÝJetpackµÄ²¼¸æ£¬£¬£¬£¬£¬¸Ã·ì϶ӰÏìÁË´Ó5.1µ½2017Äê7ÔÂÒÔÀ´µÄËùÓа汾¡£¡£¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿£¿ª·¢ÈËÔ±°µÊ¾Ã»Óз¢Ïָ÷ì϶±»Ò°±íÀûÓõÄÖ¤¾Ý¡£¡£¡£¡£¡£¡£¡£¡£JetpackÊÇÒ»¸öÊÜ»¶Ó­µÄWordPress²å¼þ£¬£¬£¬£¬£¬ËüΪÖÎÀíÔ±ÌṩÃâ·ÑµÄ°²È«ÐÔºÍÕ¾µãÖÎÀíÖ°ÄÜ£¬£¬£¬£¬£¬¸Ã²å¼þµÄ»îÔ¾×°ÖÃÁ¿Îª³¬¹ý500Íò£¬£¬£¬£¬£¬¿ª·¢ÍŶӰµÊ¾ÒÑÓг¬¹ý400ÍòÍøÕ¾×°ÖÃÁ˸üС£¡£¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/millions-of-sites-exposed-by-flaw-in-jetpack-wordpress-plugin/

5¡¢Oracle EBS½Ó¼û½ÚÔì²»µ±·ì϶ӰÏìÉÏÍò¼ÒÆóÒµ

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Oracleµç×ÓÉÌÎñÌ×¼þ£¨EBS£©ÖеÄÁ½¸ö¹Ø¼ü·ì϶¿Éµ¼Ö¹¥»÷Õ߯ëÈ«½ÚÔ칫˾µÄERP½â¾ö¹æ»®¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶±»¹éÀàΪCWE-284£º½Ó¼û½ÚÔì²»µ±£¬£¬£¬£¬£¬ÆäCVSSµÃ·ÖΪ9.9·Ö£¬£¬£¬£¬£¬±»¸ú×ÙΪCVE-2019-2638ºÍCVE-2019-2633¡£¡£¡£¡£¡£¡£¡£¡£ÈôÊdzɹ¦ÀûÓÃÕâÁ½¸ö·ì϶£¬£¬£¬£¬£¬Î´¾­ÊÚȨµÄ¹¥»÷Õ߿ɰѳֵç×Ó»ã¿îÁ÷³Ì²¢´òÓ¡ÒøÐÐ֧Ʊ¶ø²»±»·¢ÏÖ¡£¡£¡£¡£¡£¡£¡£¡£OracleÔÚ4Ô³ÁÒª²¹¶¡¸üÐÂÖн¨¸´Á˸÷ì϶£¬£¬£¬£¬£¬µ«Æ¾¾ÝOnapsis×êÑÐÍŶӵĹÀ¼Æ£¬£¬£¬£¬£¬µ±Ç°Ô¼ÓÐ50£¥µÄOracle EBS¿Í»§ÉÐδ²¿Êð²¹¶¡£¡£¡£¡£¡£¡£¡£¡£¨¿ÉÄܶà´ï1Íò¸öÆóÒµ£©¡£¡£¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/thousands-of-enterprises-at-risk-due-to-oracle-ebs-critical-flaws/