ÐÅÏ¢°²È«Öܱ¨-2020ÄêµÚ16ÖÜ

°ä²¼¹¦·ò 2020-04-20

> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2020Äê04ÔÂ13ÈÕÖÁ19ÈÕ¹²ÊÕ¼°²È«·ì϶72¸ö£¬ £¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇGoogle Chrome speech recognizer´úÂëÖ´Ðзì϶; VeeamOne Agent PerformHandshake´úÂëÖ´Ðзì϶£»£»£»£»£»£»£»Apache Heron·´ÐòÁл¯´úÂëÖ´Ðзì϶£»£»£»£»£»£»£»Cisco UCS Director ApplianceStorageUtil unzipĿ¼±éÀú´úÂëÖ´Ðзì϶£»£»£»£»£»£»£»Triangle MicroWorks SCADA Data Gateway DNP3 GET_FILE_INFOÕ»Òç¶Âí½Å¡£¡£¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊǰͻù˹̹1.15ÒÚÒÆ¶¯Óû§Êý¾ÝÔÚ°µÍøÏúÊÛ£»£»£»£»£»£»£»µ¤ÂóË®±ÃÔì×÷ÉÌDESMIÔâÍøÂç¹¥»÷£¬ £¬£¬£¬£¬£¬£¬ÏµÍ³ÈÔδ¸´Ô­£»£»£»£»£»£»£»Oracle°ä²¼4Ô³ÁÒª²¹¶¡¸üУ¬ £¬£¬£¬£¬£¬£¬½¨¸´397¸ö·ì϶£»£»£»£»£»£»£»Ó¢Ìضû°ä²¼4Ô°²È«¸üУ¬ £¬£¬£¬£¬£¬£¬½¨¸´¶à¿î²úÆ·ÖеÄ9¸ö·ì϶£»£»£»£»£»£»£»EA SportsÔâ´ó¹æÄ£DDoS¹¥»÷£¬ £¬£¬£¬£¬£¬£¬È«Çò·þÎñÖжϡ£¡£¡£¡£¡£¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬ £¬£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖÓ×£¡£¡£¡£¡£¡£


>³ÁÒª°²È«·ì϶Áбí


1. Google Chrome speech recognizer´úÂëÖ´Ðзì϶


Google Chrome speech recognizer´æÔÚ¿ªÊͺóʹÓ÷ì϶£¬ £¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄWEBÒªÇó£¬ £¬£¬£¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬ £¬£¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»£»£»òÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£

https://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop_15.html


2. Veeam One Agent PerformHandshake´úÂëÖ´Ðзì϶


Veeam One Agent PerformHandshake²½Öè´æÔÚ·´ÐòÁл¯·ì϶£¬ £¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬ £¬£¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»£»£»òÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£

https://www.zerodayinitiative.com/advisories/ZDI-20-545/


3. Apache Heron·´ÐòÁл¯´úÂëÖ´Ðзì϶


Apache Heron´æÔÚ·´ÐòÁл¯·ì϶£¬ £¬£¬£¬£¬£¬£¬ÔÊÐíͨ¹ýÑéÖ¤µÄÖÎÀíÔ±Óû§ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬ £¬£¬£¬£¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£

https://lists.apache.org/thread.html/r16dd39f4180e4443ef4ca774a3a5a3d7ac69f91812c183ed2a99e959%40%3Cdev.heron.apache.org%3E


4. Cisco UCS Director ApplianceStorageUtil unzipĿ¼±éÀú´úÂëÖ´Ðзì϶


Cisco UCS Director ApplianceStorageUtil unzip´¦ÖÃÎļþ²Ù×÷´æÔÚĿ¼±éÀú·ì϶£¬ £¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬ £¬£¬£¬£¬£¬£¬Äܹ»rootÕË»§¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£

https://www.zerodayinitiative.com/advisories/ZDI-20-539/


5. Triangle MicroWorks SCADA Data Gateway DNP3 GET_FILE_INFOÕ»Òç¶Âí½Å


Triangle MicroWorks SCADA Data Gateway´¦ÖÃDNP3 GET_FILE_INFO´æÔÚÕ»Òç¶Âí½Å£¬ £¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬ £¬£¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»£»£»òÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£

https://www.zerodayinitiative.com/advisories/ZDI-20-547


> ³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢°Í»ù˹̹1.15ÒÚÒÆ¶¯Óû§Êý¾ÝÔÚ°µÍøÏúÊÛ


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


°Í»ù˹̹°²È«³§ÉÌRewterz·¢ÏÖ£¬ £¬£¬£¬£¬£¬£¬Ä¿Ç°ÓÐ1.15ÒÚ°Í»ùË¹Ì¹ÒÆ¶¯Óû§µÄÊý¾ÝÔÚ°µÍøÂÛ̳ÏúÊÛ£¬ £¬£¬£¬£¬£¬£¬¼ÛֵΪ300 BTC£¨Ô¼ºÏ210ÍòÃÀÔª£©¡£¡£¡£¡£¡£¡£ÕâЩÊý¾ÝÔ̺¬Óû§µÄ¾ßÌåÓ×ÎÒÐÅÏ¢£¬ £¬£¬£¬£¬£¬£¬ÀýÈçÐÕÃû¡¢ÆëÈ«µØÖ·¡¢ÊÖ»úºÅÂëÒÔ¼°NICºÅºÍ˰ÎñºÅÂë¡£¡£¡£¡£¡£¡£RewterzÍþвµý±¨×¨¼ÒÒÔΪÕâЩÊý¾Ý¿ÉÄÜÊÇÒ»´Î»òÂÅ´Îй¶µÄÁ˾Ö£¬ £¬£¬£¬£¬£¬£¬Ä¿Ç°»¹²»Ã÷ÏÔÊÇ·ñÓÐÈκÎÌØ¶¨µÄµçÐÅÔËÓªÉÌ»òÊÇËùÓеçÐÅÔËÓªÉ̳ÉΪÕâ´Î¹¥»÷µÄÊܺ¦Õß¡£¡£¡£¡£¡£¡£¸Ãй¶Êý¾ÝµÄ¹æÄ£Òý·¢Á˶ԵçÐŹ«Ë¾Êý¾Ý°²È«ÐÔºÍÒþÖÔÐÔµÄÓÇÓô¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

http://www.rewterz.com/articles/115-million-pakistani-mobile-users-data-go-on-sale-on-dark-web


2¡¢µ¤ÂóË®±ÃÔì×÷ÉÌDESMIÔâÍøÂç¹¥»÷£¬ £¬£¬£¬£¬£¬£¬ÏµÍ³ÈÔδ¸´Ô­


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


µ¤ÂóË®±ÃÔì×÷ÉÌDESMIÔâµ½ÍøÂç¹¥»÷£¬ £¬£¬£¬£¬£¬£¬¸Ã¹¥»÷ÊÂÎñ²úÉúÔÚÉÏÖÜËĵÄÍíÉÏ£¬ £¬£¬£¬£¬£¬£¬Ôâµ½¹¥»÷ºó¹«Ë¾µÄËùÓÐϵͳ¾ù±»¹Ø¹Ø¡£¡£¡£¡£¡£¡£Æ¾¾Ý¸Ã¹«Ë¾ÔÚ¹ÙÍøÉϰ䲼µÄÖҸ棬 £¬£¬£¬£¬£¬£¬¹«Ë¾µÄËùÓÐϵͳ¾ù±»¹Ø¹Ø£¬ £¬£¬£¬£¬£¬£¬²¢ÇÒÔÚ»¹Ô­¹ý³ÌÖУ¬ £¬£¬£¬£¬£¬£¬Ê×Åú²¿ÃÅϵͳ½«ÔÚ¼¸ÌìÄÚÆô¶¯²¢ÔËÐУ¬ £¬£¬£¬£¬£¬£¬ÆäÓàµÄϵͳ½«ÔÚ¼¸ÖÜÖ®ÄÚÔËÐÓ×£¡£¡£¡£¡£¡£Ä¿Ç°µ÷²éÈÔÔÚ½øÐÐÖ®ÖУ¬ £¬£¬£¬£¬£¬£¬Éв»Ã÷ÏÔ¹¥»÷µÄˮƽ£¬ £¬£¬£¬£¬£¬£¬DESMIÒѽ«ÊÂÎñ»ã±¨¸øµ¤Â󵱾ֺ;¯Ô±¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/101495/hacking/desmi-discloses-cyber-attack.html


3¡¢Oracle°ä²¼4Ô³ÁÒª²¹¶¡¸üУ¬ £¬£¬£¬£¬£¬£¬½¨¸´397¸ö·ì϶


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


OracleÔÚÆä4Ô³ÁÒª²¹¶¡¸üÐÂÖн¨¸´ÁË397¸ö·ì϶£¬ £¬£¬£¬£¬£¬£¬ÆäÖÐOracle Database Server²úÆ·Öн¨¸´ÁË8¸ö·ì϶£»£»£»£»£»£»£»µç×ÓÉÌÎñÌ×¼þÖн¨¸´ÁË74¸ö·ì϶£¬ £¬£¬£¬£¬£¬£¬Ô̺¬70¸öÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓõķì϶£»£»£»£»£»£»£»OracleÈÚºÏÖÐÑë¼þÖн¨¸´ÁË51¸ö·ì϶£¬ £¬£¬£¬£¬£¬£¬ÆäÖÐ44¸öÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓ㻣»£»£»£»£»£»Java SEÖн¨¸´ÁË15¸ö·ì϶£¬ £¬£¬£¬£¬£¬£¬ËùÓзì϶¾ùÄܹ»ÔÚ²»½øÐÐÉí·ÝÑéÖ¤µÄÇé¿öϽøÐÐÔ¶³ÌÀûÓ㻣»£»£»£»£»£»MySQLÖн¨¸´ÁË45¸ö·ì϶£¬ £¬£¬£¬£¬£¬£¬ÆäÖÐ9¸ö·ì϶ÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌÀûÓᣡ£¡£¡£¡£¡£ÆëÈ«·ì϶ÁбíÇë²Î¿¼ÒÔϹٷ½Á´½Ó£¬ £¬£¬£¬£¬£¬£¬½¨ÒéÓû§¾¡¿ìÀûÓøüС£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.oracle.com/security-alerts/cpuapr2020.html


4¡¢Ó¢Ìضû°ä²¼4Ô°²È«¸üУ¬ £¬£¬£¬£¬£¬£¬½¨¸´¶à¿î²úÆ·ÖеÄ9¸ö·ì϶


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Ó¢ÌØ¶ûÔÚ4Ô²¹¶¡¸üÐÂÖн¨¸´ÁË9¸ö·ì϶£¬ £¬£¬£¬£¬£¬£¬ÕâЩ·ì϶¾ùΪÖиßΣ·ì϶£¬ £¬£¬£¬£¬£¬£¬Ó°Ïì¶à¸öÈí¼þ¡¢¹Ì¼þ¼°Æ½Ì¨¡£¡£¡£¡£¡£¡£Ó¢Ìضû½¨¸´ÁËPROSet/ÎÞÏßWiFi²úÆ·ÔÚWindows 10ÉϵÄÁ½¸ö·ì϶-¾­¹ýÉí·ÝÑéÖ¤µÄ¹¥»÷ÕßÓÉÓÚ²»°²È«µÄ¼Ì³ÐȨÏÞ¶ø¿ÉÄÜͨ¹ý±¾µØ½Ó¼û½øÐÐÌØÈ¨Éý¼¶£¨CVE-2020-0557£©£»£»£»£»£»£»£»ÓÉÓÚÄÚºËÇý¶¯·¨Ê½ÖеĻº³åÇøÏ޶Ȳ»µ±£¬ £¬£¬£¬£¬£¬£¬ÎÞÌØÈ¨µÄ¹¥»÷Õß¿ÉÄÜͨ¹ýÏàÁÚÍøÂç½Ó¼ûÀ´µ¼Ö»ؾø·þÎñ£¨CVE-2020-0558£©¡£¡£¡£¡£¡£¡£Ó¢Ìضû»¹½¨¸´ÁËNUC mini PCµÄϵͳ¹Ì¼þÖкÍÄ£¿£¿£¿£¿£¿£¿£¿é»¯·þÎñÆ÷MFS2600KISPPÍÆËãÄ£¿£¿£¿£¿£¿£¿£¿éÖеÄÁ½¸ö·ì϶£¬ £¬£¬£¬£¬£¬£¬Ô̺¬²»ÕýÈ·µÄ»º³åÇøÏ޶ȵ¼ÖµÄLPE·ì϶£¨CVE-2020-0600£©ºÍǰÌá²é³­²»µ±µ¼ÖµÄÌáȨ·ì϶£¨CVE-2020-0578£©¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/intel-april-platform-update-fixes-high-severity-security-issues/


5¡¢EA SportsÔâ´ó¹æÄ£DDoS¹¥»÷£¬ £¬£¬£¬£¬£¬£¬È«Çò·þÎñÖжÏ


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ÓÎÏ·¹«Ë¾EA SportsÓÖÒ»´ÎÔâµ½´ó¹æÄ£µÄDDoS¹¥»÷£¬ £¬£¬£¬£¬£¬£¬µ¼Ö¸ù«Ë¾µÄ·þÎñÆ÷ÔÚÈ«ÇòÁìÓòÄÚÍÑ»ú¡£¡£¡£¡£¡£¡£Õâ´Î¹¥»÷²úÉúÔÚ4ÔÂ14ÈÕÏÂÎç4:19¡£¡£¡£¡£¡£¡£Æ¾¾ÝDown DetectorµÄʵʱµØÍ¼£¬ £¬£¬£¬£¬£¬£¬Õâ´Î¹¥»÷ÖØÒªÓ°ÏìÁËÅ·ÖÞµØÓòµÄ¿Í»§£¬ £¬£¬£¬£¬£¬£¬µ«¼ÓÄô󡢰£¼°¡¢ÄϷǵȵصĿͻ§Ò²Êܵ½ÁË»ò¶à»òÉÙµÄÓ°Ïì¡£¡£¡£¡£¡£¡£4ÔÂ15ÈÕÁ賿1µã25·Ö£¬ £¬£¬£¬£¬£¬£¬EA SportsÈϿɸù«Ë¾¡°¾­ÀúÁËһϵÁÐDDoS¹¥»÷¡±¡£¡£¡£¡£¡£¡£ÔÚ°ä²¼±¾ÎÄʱ£¬ £¬£¬£¬£¬£¬£¬EA SportsµÄ¿Í»§ÈÔÔÚ±§Ô¹·þÎñå´»ú£¬ £¬£¬£¬£¬£¬£¬ÕâÅú×¢¸Ã¹«Ë¾ÈÔÔÚÔâ·ê¹¥»÷¡£¡£¡£¡£¡£¡£ÖµÍ×ÌùÐĵÄÊÇ£¬ £¬£¬£¬£¬£¬£¬±©Ñ©Ò²ÔÚ4ÔÂ14ÈÕÁ賿4µã15·Ö×óÓÒÔ⵽һϵÁÐDDoS¹¥»÷£¬ £¬£¬£¬£¬£¬£¬µ¼ÖÂÈ«Çò·þÎñÖжϡ£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/ea-sports-down-gaming-giant-hit-by-ddos-attacks/