ÐÅÏ¢°²È«Öܱ¨-2020ÄêµÚ03ÖÜ

°ä²¼¹¦·ò 2020-01-20


±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2020Äê01ÔÂ13ÈÕÖÁ19ÈÕ¹²ÊÕ¼°²È«·ì϶53¸ö£¬£¬£¬£¬£¬£¬ £¬ÖµµÃ¹Ø×¢µÄÊÇMicrosoft Windows CryptoAPIÑéÖ¤ÈÆ¹ý·ì϶; Apache XML-RPC XMLRPC client´úÂëÖ´Ðзì϶£»£»£»£»£»Oracle E-Business Suite Human Resources CVE-2020-2587δÃ÷´úÂëÖ´Ðзì϶£»£»£»£»£»Adobe Illustrator CC CVE-2020-3710ÄÚ´æÃýÎóÒýÓôúÂëÖ´Ðзì϶£»£»£»£»£»Microsoft .NET Core CVE-2020-0602Ô¶³Ì´úÂëÖ´Ðзì϶¡£¡£¡£¡£¡£ ¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇÒÔÉ«ÁÐÆô¶¯Ãñº½ÍøÂ簲ȫ´òË㣬£¬£¬£¬£¬£¬ £¬½«¸ÄÉÆº½¿ÕÍøÂç·ÀÓùÄÜÁ¦£»£»£»£»£»Î¢ÈíÕýʽÖÕÖ¹¶ÔWindows 7¡¢Server 2008ºÍ2008 R2Ìṩ֧³Ö£»£»£»£»£»ÃÀ¹úLimeLeads¹«Ë¾4900ÍòÌõÓû§¼Í¼ÔÚ°µÍøÂÛ̳ÏúÊÛ£»£»£»£»£»ÊÔÓÃAppÐ¶ÔØºóÖ±½Ó¿Û·Ñ£¬£¬£¬£¬£¬£¬ £¬È«Çò½ü6ÒÚAndroidÓû§ÖÐÕУ»£»£»£»£»Êý°Ù¸öҽѧ³ÉÏñϵͳÔÚÍøÉ϶³öÁËÊý°ÙÍò»¼ÕßµÄÊý¾Ý¡£¡£¡£¡£¡£ ¡£¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬ £¬±¾Öܰ²È«ÍþвΪÖС£¡£¡£¡£¡£ ¡£¡£



³ÁÒª°²È«·ì϶Áбí


1. Microsoft Windows CryptoAPIÑéÖ¤ÈÆ¹ý·ì϶


Microsoft Windows CryptoAPI´¦ÖÃECCÍÖÔ²ÇúÏß¼ÓÃÜ´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬ £¬Äܹ»Ê¹ÓÃαÔìµÄÖ¤Êé¶Ô¶ñÒâµÄ¿ÉÖ´ÐÐÎļþ½øÐÐÊðÃû£¬£¬£¬£¬£¬£¬ £¬Ê¹Îļþ¿´ÆðÀ´À´×Ô¿ÉÐŵįðÔ´£¬£¬£¬£¬£¬£¬ £¬»òÕß½øÐÐÖÐÑëÈ˹¥»÷²¢½âÃÜÓû§Ïνӵ½ÊÜÓ°ÏìÈí¼þµÄ»úÃÜÐÅÏ¢¡£¡£¡£¡£¡£ ¡£¡£

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0601


2. Apache XML-RPC XMLRPC client´úÂëÖ´Ðзì϶


Apache XML-RPC XMLRPC clientʵÏÖXMLRPCÃýÎóÐÂÎÅfaultCauseÊôÐÔ´¦ÖôæÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶¹¹½¨¶ñÒâXMLRPC·þÎñÒªÇ󣬣¬£¬£¬£¬£¬ £¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»òÕßÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£ ¡£¡£

https://access.redhat.com/security/cve/cve-2019-17570


3. Oracle E-Business Suite Human Resources CVE-2020-2587δÃ÷´úÂëÖ´Ðзì϶


Oracle E-Business Suite Human Resources´æÔÚδÃ÷°²È«·ì϶£¬£¬£¬£¬£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬ £¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»òÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£ ¡£¡£

https://www.oracle.com/security-alerts/cpujan2020.html


4. Adobe Illustrator CC CVE-2020-3710ÄÚ´æÃýÎóÒýÓôúÂëÖ´Ðзì϶


Adobe Illustrator CC´¦ÖÃÎļþ´æÔÚÄÚ´æ·ÛËé·ì϶£¬£¬£¬£¬£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬ £¬ÓÕʹÓû§½âÎö£¬£¬£¬£¬£¬£¬ £¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£ ¡£¡£

https://helpx.adobe.com/security/products/illustrator/apsb20-03.html


5. Microsoft .NET Core CVE-2020-0602Ô¶³Ì´úÂëÖ´Ðзì϶


Microsoft .NET CoreʵÏÖ´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬ £¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£ ¡£¡£

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0602


³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢ÒÔÉ«ÁÐÆô¶¯Ãñº½ÍøÂ簲ȫ´òË㣬£¬£¬£¬£¬£¬ £¬½«¸ÄÉÆº½¿ÕÍøÂç·ÀÓùÄÜÁ¦


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


¾ÝÉÏÖÜÈÕÒÔÉ«Áйú¶ÈÍøÂçÖÎÀí¾Ö£¨INCD£©±¨Â·£¬£¬£¬£¬£¬£¬ £¬ÒÔÉ«Áе±¾ÖºË×¼ÁËÒ»ÏîÃñº½ÍøÂ簲ȫ´òËã¡£¡£¡£¡£¡£ ¡£¡£×÷Ϊ¸Ã´òËãµÄÒ»²¿ÃÅ£¬£¬£¬£¬£¬£¬ £¬ÒÔÉ«Áн«³ÉÁ¢Ò»¸ö¹ú¶ÈÁ쵼ίԱ»áÀ´¸ÄÉÆ¸Ã¹ú¶ÈµÄº½¿ÕÍøÂç·ÀÓùÄÜÁ¦¡£¡£¡£¡£¡£ ¡£¡£¸ÃίԱ»áÓÉINCD¸¨µ¼£¬£¬£¬£¬£¬£¬ £¬²¢ÇÒÓÉÒÔÉ«Áн»Í¨²¿¡¢Ãñº½¾Ö¡¢»ú³¡ÖÎÀí¾Ö¡¢°²È«¾Ö¡¢¹ú·À²¿¡¢¹ú¶È°²È«Î¯Ô±»áºÍÒÔÉ«Áйú·À¾üµÄ´ú±í×é³É¡£¡£¡£¡£¡£ ¡£¡£¸Ã´òËãµÄÄÚÈÝÔ̺¬£ºÍþвӳÉäºÍ½â¾ö¹æ»®ÏîÄ¿¡¢Ôڸ߿Ƽ¼ºÍÍøÂçÐÐÒµÒÔ¼°Ñ§Êõ½çÍÆ¶¯Ç°Ñؼ¼Êõ×êÑк͹ú·À½â¾ö¹æ»®µÄÑз¢¡¢Ó벨Òô½øÐкÏ×÷¡¢³ÉÁ¢ÔËÊä½ÚÔìÖÐÐÄ¡¢¿ª·¢·ÉÐÐÔ±Åàѵ¿Î³ÌµÈ¡£¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

http://www.xinhuanet.com/english/2020-01/13/c_138699304.htm


2¡¢Î¢ÈíÕýʽÖÕÖ¹¶ÔWindows 7¡¢Server 2008ºÍ2008 R2Ìṩ֧³Ö


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


΢ÈíÓÚ1ÔÂ14ÈÕÕýʽÖÕÖ¹¶ÔWindows 7¡¢Server 2008ºÍServer 2008 R2Ìṩ֧³Ö¡£¡£¡£¡£¡£ ¡£¡£ÔÚ´ËÖ®ºóÕâЩ²Ù×÷ϵͳÈԿɳÖÐø¹¤×÷£¬£¬£¬£¬£¬£¬ £¬µ«½«²»ÔÙÊÕµ½°²È«¸üС£¡£¡£¡£¡£ ¡£¡£¶ÔWindows Server 2008µÄÖÕÖ¹Ö§³ÖÒâζ×ÅÆä¶î±íµÄÃâ·Ñ°²È«¸üС¢·Ç°²È«¸üС¢Ãâ·ÑµÄÖ§³Ö·þÎñÒÔ¼°ÔÚÏß¼¼ÊõÄÚÈݸüж¼ÒÑʵÏÖ¡£¡£¡£¡£¡£ ¡£¡£Î¢Èí¶½´ÙÓû§½«Æä²úÆ·ºÍ·þÎñǨáãµ½Azure»òÊÇÉý¼¶µ½×îа汾Server 2016¡£¡£¡£¡£¡£ ¡£¡£ÎÞ·¨ÔÚÖ§³ÖÖÕÖ¹ÆÚÏÞ֮ǰʵÏÖÉý¼¶µÄÈËÄܹ»²É°ìÀ©´ó°²È«¸üУ¬£¬£¬£¬£¬£¬ £¬ÒÔ±£»£»£»£»£»¤·þÎñÆ÷¹¤×÷¸ºÔØÖ±ÖÁÉý¼¶ÎªÖ¹¡£¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.darkreading.com/risk/microsoft-to-officially-end-support-for-windows-7-server-2008/d/d-id/1336791


3¡¢ÃÀ¹úLimeLeads¹«Ë¾4900ÍòÌõÓû§¼Í¼ÔÚ°µÍøÂÛ̳ÏúÊÛ


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


¾ÝZDNet±¨Â·£¬£¬£¬£¬£¬£¬ £¬ºÚ¿ÍOmnichorusÔÚ°µÍøÂÛ̳ÉÏÏúÊÛÃÀ¹úÊý¾Ý¾­¼ÍÉÌLimeLeadsµÄ4900ÍòÌõÓû§¼Í¼¡£¡£¡£¡£¡£ ¡£¡£°²È«×êÑÐÔ±Bob DiachenkoÈ·ÈÏÕâЩÊý¾ÝÊÇÓɸù«Ë¾µÄÄÚ²¿Elasticsearch·þÎñÆ÷¶³öÔÚInternetÉÏй¶µÄ¡£¡£¡£¡£¡£ ¡£¡£Æ¾¾ÝDiachenkoµÄ˵·¨£¬£¬£¬£¬£¬£¬ £¬ÖÁÉÙ´Ó2019Äê7ÔÂ27ÈÕÆðLimeLeadsµÄһ̨·þÎñÆ÷¾Í¿É¹«¿ª½Ó¼û£¬£¬£¬£¬£¬£¬ £¬ËûÓÚÈ¥Äê9ÔÂ16ÈÕ֪ͨÁ˸ù«Ë¾£¬£¬£¬£¬£¬£¬ £¬¸Ã¹«Ë¾ÔÚµÚ¶þÌìѸËÙ¶Ô·þÎñÆ÷½øÐÐÁ˱£»£»£»£»£»¤£¬£¬£¬£¬£¬£¬ £¬µ«ÏÔÈ»OmnichorusÒѾ­ÇÔÈ¡ÁËÕâЩÊý¾Ý£¬£¬£¬£¬£¬£¬ £¬²¢ÇÒ´ÓÈ¥Äê10ÔÂÒÔÀ´Ò»ÏòÔÚÍøÉÏÏúÊÛ¡£¡£¡£¡£¡£ ¡£¡£Æ¾¾ÝOmnichorus°ä²¼µÄÊý¾ÝÑù±¾£¬£¬£¬£¬£¬£¬ £¬ÕâЩÊý¾ÝÔ̺¬Óû§µÄÐÕÃû¡¢Ö°Îñ¡¢µç×ÓÓʼþ¡¢¹ÍÖ÷/¹«Ë¾Ãû³Æ¡¢¹«Ë¾µØÖ·¡¢³ÇÊÓ×¢ÖÝ¡¢ÓÊÕþ±àÂë¡¢µç»°ºÅÂë¡¢ÍøÕ¾URL¡¢¹«Ë¾×ÜÊÕÈëÒÔ¼°¹«Ë¾µÄÔ¤¼ÆÔ±¹¤ÈËÊýµÈÐÅÏ¢¡£¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/49-million-user-records-from-us-data-broker-limeleads-put-up-for-sale-online/


4¡¢ÊÔÓÃAppÐ¶ÔØºóÖ±½Ó¿Û·Ñ£¬£¬£¬£¬£¬£¬ £¬È«Çò½ü6ÒÚAndroidÓû§ÖÐÕÐ


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Sophos°²È«×êÑÐÈËÔ±·¢ÏÖÁËÒ»×éеÄfleeceware APP£¬£¬£¬£¬£¬£¬ £¬ÕâЩAPPÒѾ­±»³¬¹ý6ÒÚAndroidÓû§ÏÂÔØ×°Öᣡ£¡£¡£¡£ ¡£¡£fleecewareÊÇÖ¸¹È¸èPlayÉ̵êÖдæÔÚµÄÒ»ÖÖÐÂÐͽðÈÚڲƭÐÐΪ£¬£¬£¬£¬£¬£¬ £¬ÕâЩAPPÀÄÓÃAndroidÀûÓõÄÊÔÓÃÆÚÖ°ÄÜÏòÓû§ÊÕ·Ñ¡£¡£¡£¡£¡£ ¡£¡£Ä¬ÈÏÇé¿öÏÂAndroidÓû§ÔÚ×¢²áʹÆ÷ÓµÓÐÊÔÓÃÆÚµÄAPPʱ±ØÐëÊÖ¶¯È¡µÞÊÔÓ㬣¬£¬£¬£¬£¬ £¬È»¶ø´óÎÞÊýÓû§Ö»ÊÇÔÚ²»Ï²»¶µÄʱ³½Ð¶ÔØAPP£¬£¬£¬£¬£¬£¬ £¬¾ø´óÎÞÊý¿ª·¢Õß½«ÕâÖÖÐ¶ÔØÐÐΪÊÓΪȡµÞÊÔÓ㬣¬£¬£¬£¬£¬ £¬µ«Ò»Ð©¿ª·¢ÕßÔÚÓû§Ð¶ÔغóûÓÐÈ¡µÞÊÔÓò¢ÇÒ³ÖÐøÊÕ·Ñ¡£¡£¡£¡£¡£ ¡£¡£Sophos×î³õ·¢ÏÖµÄ24¸öAPPÔ̺¬¶þάÂëɨÃèÆ÷¡¢ÍÆËãÆ÷µÈ£¬£¬£¬£¬£¬£¬ £¬ËüÃÇÒÔÕâÖÖ·½Ê½ÏòÓû§ÊÕȡÿÄê100ÃÀÔªµ½240ÃÀÔªµÄ¶©ÔÄÓöÈ¡£¡£¡£¡£¡£ ¡£¡£ÔÚ½üÈÕ°ä²¼µÄÒ»·Ý»ã±¨ÖУ¬£¬£¬£¬£¬£¬ £¬Sophos·¢ÏÖÁËÁí±í25¸ö´ËÀàAPP£¬£¬£¬£¬£¬£¬ £¬Æä×Ü×°ÖÃÁ¿³¬¹ý6ÒÚ£¬£¬£¬£¬£¬£¬ £¬ÆëÈ«µÄAPPÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/more-than-600-million-users-installed-android-fleeceware-apps-from-the-play-store/


5¡¢Êý°Ù¸öҽѧ³ÉÏñϵͳÔÚÍøÉ϶³öÁËÊý°ÙÍò»¼ÕßµÄÊý¾Ý


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


µÂ¹ú°²È«³§ÉÌGreenbone³ÆÊý°Ù¸ö¿É¹«¿ª½Ó¼ûµÄҽѧ³ÉÏñϵͳÔÚ»¥ÁªÍøÉ϶³öÁËÈ«ÇòÊý°ÙÍò»¼ÕßµÄÊý¾Ý¡£¡£¡£¡£¡£ ¡£¡£¸ÃÏî×êÑгÁµã·ÖÎöÔÚÍøÉ϶³öµÄҽѧͼƬ´æµµºÍͨѶϵͳ£¨PACS£©£¬£¬£¬£¬£¬£¬ £¬ÔÚËùÓÐÊÜ·ÖÎöµÄPACS·þÎñÆ÷ÖУ¬£¬£¬£¬£¬£¬ £¬Óн«½ü1/4µÄϵͳ½«Êý¾Ý¶³öÔÚ»¥ÁªÍøÉÏ¡£¡£¡£¡£¡£ ¡£¡£¾ßÌåÀ´Ëµ£¬£¬£¬£¬£¬£¬ £¬ÔÚ2019Äê7ÔÂÖÁ2019Äê9ÔÂÖ®¼ä·ÖÎöµÄ2300¸öϵͳÖУ¬£¬£¬£¬£¬£¬ £¬ÓÐ590¸ö¿É´ÓInternet½Ó¼û²¢ÇÒδÉèÃÜÂ룬£¬£¬£¬£¬£¬ £¬¹²Óг¬¹ý2450ÍòÌõ»¼ÕßÊý¾Ý¶³ö£¬£¬£¬£¬£¬£¬ £¬ÔÚ11Ô·ݵÄ×êÑÐÖУ¬£¬£¬£¬£¬£¬ £¬¸Ã¹«Ë¾Ð¹Â©ÓÐ3500ÍòÌõ»¼Õ߼ͼ¿É¹«¿ª½Ó¼û¡£¡£¡£¡£¡£ ¡£¡£ÔÚ9ÔÂÖÁ11ÔÂÖ®¼ä£¬£¬£¬£¬£¬£¬ £¬Ô̺¬Ò½ÁÆÍ¼ÏñµÄ¶³ö»¼Õ߼ͼÊýÁ¿ÒÑ´Ó440ÍòÔö³¤ÁËÒ»±¶£¬£¬£¬£¬£¬£¬ £¬´ïµ½900Íò¡£¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/unprotected-medical-systems-expose-data-millions-patients