ADLab2019ÄêÄþ¾²Ñо¿»Ø¹Ë

Ðû²¼Ê±¼ä 2019-12-31

2019Ä꣬¶«É­Æ½Ì¨ADLabÑо¿Æ«ÏòÖصã°üÂÞÖ÷Á÷²Ù×÷ϵͳ¼°Ó¦ÓÃÄþ¾²Ñо¿¡¢WebÄþ¾²Ñо¿¡¢Òƶ¯»¥ÁªÍøÄþ¾²Ñо¿¡¢ÎïÁªÍøÄþ¾²Ñо¿¡¢¹¤¿Ø»¥ÁªÍøÄþ¾²Ñо¿ºÍÇø¿éÁ´Äþ¾²Ñо¿£¬ÆäÖв¿ÃÅÑо¿ÎÄÕÂÒÑͨ¹ýADLab¹«ÖÚƽ̨Ðû²¼£¬Îª·½±ã¸÷È˲éÔÄÎÒÃǶÔÈ«ÄêÐû²¼µÄÖ÷ÒªÑо¿ÎÄÕ½øÐÐÁËÕûÀí¡£


Èȵãʼþͨ¸æ


¡¾Ô­´´Â©¶´¡¿Adobe ColdFusion ·´ÐòÁл¯RCE©¶´·ÖÎö


¶«É­Æ½Ì¨ADLab·¢ÏÖAdobe ColdFusionÖÐFlashGateway·þÎñ´æÔÚCritical£¨Î£¼±£©·´ÐòÁл¯Â©¶´£¨CVE-2019-7091£©£¬ÀûÓø鶴¹¥»÷Õß¿ÉÔ¶³ÌÖ´ÐÐÈÎÒâ´úÂë¡£


¡¾Â©¶´Í¨¸æ¡¿LinuxÄں˴æÔÚµ±µØÌáȨ©¶´£¨CVE-2019-8912£©


¡¾Ô­´´Â©¶´¡¿LinuxÄÚºËMarvell WI-FIоƬÇý¶¯Â©¶´£¨CVE-2019-3846/CVE-2019-10126£©


¡¾Ô­´´Â©¶´¡¿LinuxÄÚºËMarvell WI-FIоƬÇý¶¯¶à¸öÔ¶³Ì©¶´


Linux git´æÔÚµ±µØÌáȨ©¶´£¬¿ÉÒÔµ¼Öµ±µØ´úÂëÖ´ÐнøÐÐȨÏÞÌáÉý¡£LinuxÄÚºËMarvell WI-FIоƬÇý¶¯´æÔÚ¶à¸öÔ¶³ÌÒç³ö©¶´ºÍµ±µØÒç³ö©¶´£¬¿Éµ¼Ö¾ܾø·þÎñ£¨ÏµÍ³Í߽⣩»òÈÎÒâ´úÂëÖ´ÐС£Â©¶´Ó°Ï췶Χ½Ï¹ã¡£


¡¾Ô­´´Â©¶´¡¿WebLogicÈÎÒâÎļþ¶Áȡ©¶´£¨CVE-2019-2615£©


¡¾Ô­´´Â©¶´¡¿WebLogic Blind XXE©¶´£¨CVE-2019-2647£©


¡¾Ô­´´Â©¶´¡¿WebLogic Ô¶³ÌÃüÁîÖ´ÐЩ¶´£¨CVE-2019-2725²¹¶¡Èƹý£©


¡¾Ô­´´Â©¶´¡¿WebLogic ·´ÐòÁл¯Â©¶´£¨CVE-2019-2890£©


¡¾Ô­´´Â©¶´¡¿WebLogic Blind XXE©¶´£¨CVE-2019-2887£©


¶«É­Æ½Ì¨ADLab·¢ÏÖWebLogic´æÔÚÉÏÊö©¶´£¬¹¥»÷Õß¿ÉÔÚÒÑÖªÓû§ÃûÃÜÂëµÄÇé¿ö϶ÁÈ¡WebLogic·þÎñÆ÷ÖеÄÈÎÒâÎļþ £»¿ÉÔÚδÊÚȨµÄÇé¿öÏÂʵÏÖ¶Ô´æÔÚ©¶´µÄWebLogic×é¼þ½øÐÐÔ¶³ÌBlind XXE¹¥»÷ £»¿ÉÔڵͰ汾JDKµÄ»·¾³ÖÐÈƹý²¹¶¡È±Ïݵ¼ÖÂÈÎÒâÔ¶³ÌÃüÁîÖ´ÐÐ £»¿Éͨ¹ýT3ЭÒé¶Ô´æÔÚ©¶´µÄWebLogic×é¼þʵʩԶ³ÌÈÎÒâ´úÂë¹¥»÷¡£


¡¾Â©¶´Í¨¸æ¡¿²©Í¨Wi-FiÇý¶¯´æÔÚ¶à¸öÄþ¾²Â©¶´


²©Í¨wlÇý¶¯ÖдæÔÚÁ½¸ö¶ÑÒç³ö©¶´£¨CVE-2019-9501¡¢CVE-2019-9502£©£¬¿ªÔ´µÄbrcmfmacÇý¶¯ÖдæÔÚÊý¾ÝÖ¡ÑéÖ¤Èƹý©¶´£¨CVE-2019-9503£©ºÍ¶ÑÒç³ö©¶´(CVE-2019-9500£©¡£Î´¾­ÊÚȨµÄ¹¥»÷Õßͨ¹ýÔ¶³Ì·¢ËͶñÒâµÄwifi°ü£¬ÔÚ×îÑÏÖصÄÇé¿öÏ£¬¿ÉÒÔÔÚÊÜÓ°ÏìϵͳÖÐÖ´ÐÐÈÎÒâ´úÂë¡£


¡¾Ô­´´Â©¶´¡¿WebSphere©¶´£¨CVE-2019-4505£©


¶«É­Æ½Ì¨ADLab·¢ÏÖWebsphere´æÔÚÈÎÒâÎļþ¶Áȡ©¶´CVE-2019-4505¡£Í¨¹ý¸Ã©¶´£¬¹¥»÷Õß¿ÉÒÔ»ñÈ¡Ãô¸ÐÐÅÏ¢¶øµ¼Ö½øÒ»²½ÀûÓá£Â©¶´Î£º¦Ë®Æ½½Ï´ó¡£


ÎïÁªÍøרÌâ·ÖÎö


¹¤¿ØÊ®´óÍøÂç¹¥»÷ÎäÆ÷·ÖÎö³ÂËß


¶«É­Æ½Ì¨ADLab¶Ô2000ÄêÖ®ºóµÄ¹¤¿ØÍøÂç¹¥»÷ʼþ½øÐÐÊáÀí£¬²¢É¸Ñ¡³öÊ®´ó¹¤¿ØÍøÂç¹¥»÷ÎäÆ÷£ºStuxnet¡¢Duqu¡¢Flame¡¢Havex¡¢Dragonfly2.0¡¢ BlackEnergy¡¢Industroyer¡¢GreyEnergy¡¢VPNFilterºÍTriton

£¬Éî¶È·ÖÎöÆä¹¥»÷Åä¾°¡¢Ä¿±ê¡¢ÊÖ·¨ÒÔ¼°¼¼ÊõÌØÐÔ£¬ÒÔ±ã¸÷È˶Թ¤Òµ¿ØÖÆϵͳËùÃæÁÙµÄÄþ¾²ÍþвÓÐÒ»¸ö¸üΪȫÃæµÄÈÏʶ¡£


ºÚȸ¹¥»÷£ºÉî¶È·ÖÎö²¢ËÝÔ´Dofloo½©Ê¬ÎïÁªÍø±³ºóµÄ¡°ºÚȸ¡±


¶«É­Æ½Ì¨ADLab·¢ÏÖConfluenceÔ¶³Ì´úÂëÖ´ÐЩ¶´CVE-2019-3396±»Dofloo½©Ê¬ÍøÂç¼Ò×åÓÃÓÚ¹¥Õ¼É豸×ÊÔ´£¬Dofloo½©Ê¬¼Ò×å²»½ö¿ªÊ¼ÀûÓøßΣ©¶´½øÐй¥»÷£¬ÇÒÆä±³ºóµÄºÚ¿Í»¹ÀûÓÃÒ»ÖÖ¸ü¾ßÓ°ÏìÁ¦µÄ¡°ºÚȸ¹¥»÷¡±À´ÈëÇÖ¹¤ÒµÁ´¡£±¾ÎÄÏêϸÂÛÊöÁ˺Úȸ¹¥»÷µÄ×îз¢ÏÖ¹ý³Ì£¬²¢ÉîÈë·ÖÎöÁËDofloo½©Ê¬ÍøÂç¼Ò×åÖÐËù´æÔڵġ°ºÚȸÏÖÏó¡± £»Í¬Ê±¶ÔÒþ²ØÔÚÆä±³ºóµÄºÚȸ½øÐÐÉî¶ÈÍÚ¾òºÍ¶¨Î»£¬·ÖÎö¸Ã½©Ê¬ÓëMrBlack¡¢DnsAmp¡¢Flood.AÖ®¼äµÄͬԴÌØÐÔ¡£


ÖÇÄÜÒôÏäÍøÂçÄþ¾²ÓëÒþ˽Ñо¿³ÂËß


±¾³ÂËßÖصã·ÖÎöÁËÖÇÄÜÒôÏäÃæÁÙµÄÄþ¾²·çÏÕºÍÒþ˽·çÏÕ¡£Í¨¹ý¶ÔÖÇÄÜÒôÏäµÄÑо¿£¬¶«É­Æ½Ì¨ADLab·¢ÏÖÁ˲úÎïÖдæÔÚÓÐÓ²¼þµ÷ÊÔ½Ó¿Ú©¶´¡¢DLNA·þÎñԽȨ©¶´¡¢·þÎñ¶Ë¿ÚԽȨ©¶´µÈÊ®Óà¸öÄþ¾²Â©¶´£¬ÕâЩ©¶´¿ÉÔì³ÉδÊÚȨÉ豸¿ØÖÆ¡¢ÓïÒôÇÔÌý¡¢Ãô¸ÐÐÅϢ鶵È¡£ADLabÒѵÚһʱ¼äÏòCNVDºÍCNNVD½øÐÐÁË©¶´Í¨±¨£¬²¢ÓëICSCERTÁªºÏÐû²¼ÁË¡¶ÖÇÄÜÒôÏäÒþ˽ÓëÍøÂçÄþ¾²·ÖÎö³ÂËß¡·¡£


VxWorks¶à¸öÔ¶³Ì©¶´·ÖÎö


ÔÚ¹¤Òµ¡¢µçÁ¦¡¢ÄÜÔ´£¬º½¿Õº½ÌìµÈÐÐÒµÒªº¦»ù´¡ÉèÊ©Öй㷺ʹÓõÄVxWorks±»·¢ÏÖ´æÔÚ11¸ö0day©¶´±»³ÆΪURGENT/11£¬ÆäÖÐ6¸ö©¶´ÎªÑÏÖØ©¶´²¢¿ÉÒÔÔ¶³ÌÖ´ÐдúÂ루RCE£©£¬ÆäÓà5¸ö©¶´°üÂ޾ܾø·þÎñ¡¢ÐÅϢй¶ºÍÂß¼­È±ÏÝ©¶´¡£ÕâЩ©¶´Äܹ»Ê¹¹¥»÷ÕßÔ¶³Ì½Ó¹ÜÉ豸£¬¶øÎÞÐè½»»¥£¬ÉõÖÁ¿ÉÒÔÈƹý·À»ðǽµÈÖܱßÄþ¾²É豸£¬ÕâÒâζ×ÅËüÃÇ¿ÉÓÃÓÚ½«¶ñÒâÈí¼þÁ÷´«µ½ÍøÂçÄÚ²¿£¬ÕâÖÖ¹¥»÷¾ßÓкܴóµÄDZÁ¦£¬ÀàËÆÓÚWannaCry¶ñÒâÈí¼þµÄÁ÷´«·½Ê½¡£



ºÚ¿Í¹¥»÷ÓëÍþв·ÖÎö



¡°BankThief¡±- Õë¶Ô²¨À¼ºÍ½Ý¿ËµÄÐÂÐÍÒøÐеöÓã¹¥»÷


¶«É­Æ½Ì¨ADLab·¢ÏÖÁËÒ»¿îȫеÄAndroidÒøÐеöÓãľÂí¡±BankThief¡°£¬¸ÃľÂí½«×ÔÉíαװ³É¡°Google Play¡±Ó¦Ó㬿ÉÇÔÈ¡Êܺ¦Óû§µÄÒøÐеǼƾ֤¡£¹¥»÷Õß½«¿ØÖÆÖ¸ÁîÒþ²ØÔÚÄþ¾²µÄFirebaseͨÐÅËíµÀÖУ¬Ê¹Æä¹¥»÷ÐÐΪԽ·¢Òþ±Î¡£´Ë´Î¹¥»÷µÄÄ¿±êÒøÐÐĬÈÏ°üÂÞ°üÂÞ»¨ÆìÒøÐÐÔÚÄÚµÄÈýÊ®¶à¼ÒÒøÐС£


¾¯Ì裺ºÚ¿ÍÀûÓá°Á÷À˵ØÇòƱ·¿ºì°ü¡±ÔÚ΢ÐÅÖÐÁ÷´«¶ñÒâÕ©Æ­¹ã¸æ


¶«É­Æ½Ì¨ADLabÊÕµ½¿Í»§·´À¡£ºÔÚʹÓÃ΢ÐŵĹý³ÌÖÐÒÉËÆ·ºÆð¡°Öж¾¡±ÏÖÏó£¬Óû§ÔÚȺÁÄÖÐÊÕµ½¡°Î¢ÐÅÓïÒô¡±£¬µã¿ªºóÈ´ÌáʾÁìÈ¡¡°Á÷À˵ØÇòӰϷƱ·¿ºì°ü¡±¡£²»Ã÷ÕæÏàµÄÓû§·×·×ÖÐÕУ¬Ôì³ÉÖî¶àȺÁÄÖзºÆðÁË¡°ÈºÑûÇ롱 ¡¢¡°ÓïÒô¡±ºÍ¡°¹ã¸æ¡±µÈÆÛÆ­ÐÔ·ÖÏíÁ´½Ó£¬²¢³É²¡¶¾Ê½¿ìËÙÁ÷´«¡£Á´½ÓÖ¸Ïò¡°ÀÏÖÐÒ½¡±¡¢¡°Í¶×ÊÖ¸µ¼¡±ºÍ¡°µÍË×С˵¡±µÈ¶ñÒâ¹ã¸æ£¬ÓÕµ¼Óû§Ìí¼Ó΢ÐÅ»ò¹Ø×¢¹«Öںţ¬Ö®ºóÒ»²½²½Í¨¹ýÆ­È¡¶¨½ð»ò²ÊƱˢµ¥µÈÊÖ¶ÎÕ©Æ­Óû§¹¤Òµ£¬ÉÔÓв»É÷¾Í»áÂäÈëȦÌס£


¡¾¾¯Ìè¡¿¡°ÏÀµÁ¡±ÀÕË÷²¡¶¾V5.3бäÖÖÈ«ÃæÆÊÎö


2019Äê4Ô£¬¶«É­Æ½Ì¨ADLab²¶×½µ½ÁË¡°ÏÀµÁ¡±²¡¶¾×îбäÖÖ£¬¸Ã²¡¶¾µÄ°æ±¾ºÅΪV5.3£¬±àÒëʱ¼äΪ4ÔÂ14ÈÕ£¬¾àÀëÆäÉÏÒ»¸ö°æ±¾V5.2ÔÚÖйúËÁÅ°½ö½öÒ»¸ö¶àÔ¡£×ÔÆäÓÚ2018Äê1Ôµ®ÉúÖÁ½ñÒѾ­¸üеü´úÁË5¸ö´óµÄ°æ±¾¡¢20¼¸¸öС°æ±¾¡£¡°ÏÀµÁ¡±¿ªÊ¼ËÁÅ°ÖйúµÄʱ¼äΪ2019Äê3ÔÂ11ÈÕ£¬²¢ÒÑѬȾÁËÎÒ¹úÉÏǧ̨Õþ¸®¡¢ÆóÒµºÍÏà¹Ø¿ÆÑлú¹¹µÄ¼ÆËã»ú¡£


ºÚʨÐж¯£ºÕë¶ÔÎ÷°àÑÀÓïµØÓòµÄ¹¥»÷»î¶¯·ÖÎö


¶«É­Æ½Ì¨ADLab¼à²âµ½Ò»ÅúÕë¶ÔÎ÷°àÑÀÓïµØÓòµÄÕþ¸®»ú¹¹¼°ÄÜÔ´ÆóÒµµÈ²¿ÃŵĶ¨Ïò¹¥»÷»î¶¯£¬Í¨¹ý¶Ô¹¥»÷ÕßµÄÐÐΪºÍËùÓ÷þÎñÆ÷Ïà¹ØÐÅÏ¢µÄ·ÖÎöºÍ×·×Ù£¬È·¶¨¸Ã´Î¹¥»÷À´Ô´ÓÚÒ»ÅúÒþÃضàÄêµÄÍÁ¶úÆäºÚ¿Í×éÖ¯-KingSqlZºÚ¿Í×éÖ¯¡£ÆäÔø¹¥ÏÝ3ǧ¶à¸öÍøÕ¾·þÎñÆ÷£¬²¢¸ßµ÷µÄÔÚ±»¹¥»÷ÍøÕ¾ÉÏÁôÏÂ×éÖ¯µÄÃû³Æ£¬ËæºóÏûʧÁ˶àÄê¡£ÎÒÃÇͨ¹ý¶Ô¡±ºÚʨÐж¯¡±µÄ×·×ÙÔÙ´ÎÍÚ³ö¸ÃºÚ¿Í×éÖ¯³ÉÔ±¼°»î¶¯¼£Ï󣬲¢¶Ô¹¥»÷Ä¿±êÒÔ¼°ÆäËùʹÓõĹ¥»÷ÎäÆ÷½øÐÐÈ«ÃæÁË·ÖÎö¡£


ÓÉÒ»¶ÎÉñÃØÎÄ×ÖËùÒý·¢µÄÊÓ²ìÓë·ÖÎö


¶«É­Æ½Ì¨ADLab¶Ô±ãÇ©ÍøÕ¾Pastebinƽ̨£¨¸Ãƽ̨¾­³£±»ºÚ¿ÍÓÃÓÚ´æ´¢¹¥»÷½á¹û£©ÄÚÈݽøÐÐɸѡºÍ·ÖÎö£¬·¢ÏÖÁËÒ»¶ÎÉñÃضøÀëÆæµÄÖÐÎÄ×Ö·û¡£¸Ã¶ÎÎÄ×Ö±»´æ´¢ÔÚÒ»¸öÃûΪ¡°Unitled¡±µÄÓû§ÎļþÖУ¬´Ó×ÖÃæÉÏ¿´£¬ÕâÊÇÒ»¶ÎûÓÐÍêÕûÓïÒåµÄÎÄ×Ö£¬¿´ÆðÀ´¾ÍÏñÃÜÓïÒ»Ñù£¬ËƺõÆäÖÐÒþ²Ø×ÅһЩ²»ÎªÈËÖªµÄÐÅÏ¢¡£ÄÇôÕâ»áÊÇij¸öºÚ¿Í×éÖ¯»òÕßÇ鱨ÈËÔ±Ö®¼äµÄÃØÃܵƺÅÄØ£¬»¹ÊÇ˵½ö½öÖ»ÊÇËæ»úÊäÈëµÄºÁÎÞÒâÒåµÄÎÄ×Ö £¿±¾ÎĶÔÕâÆäÖÐÒþ²ØµÄÃØÃܽøÐÐÁË·ÖÎö×·²é¡£


Õë¶ÔÖÆÒ©ÐÐÒµ¼°ÕþÆóµÄºÚ¿Í×éÖ¯×îй¥»÷»î¶¯Éî¶È·ÖÎö


¶«É­Æ½Ì¨ADLab·¢ÏÖ´óÁ¿Ê¹ÓøßΣ©¶´CVE-2017-11882½øÐÐÍøÂç¹¥»÷µÄʼþ£¬Í¨¹ý·ÖÎöÎÒÃÇ·¢Ïֺڿ͵ÄÎѵ㲢ÕÒµ½ÁËÊܺ¦ÈËÏà¹ØÐÅÏ¢£¬´ËÅúºÚ¿ÍÀÖ³ÉÉø͸½øÁ˵¹úºÍÓ¡¶ÈÄáÎ÷ÑǵĶà¼ÒÖÆÒ©ÆóÒµ£¬ÒÔ¼°Î÷°àÑÀµÄÕþ¸®¡¢ÆóÊÂÒµµ¥ÔªµÈ»ú¹¹£¬¶øÇÒ͵ȡÁË´óÁ¿µÄÃôÇé¸Ð±¨¡£Í¨¹ýËÝÔ´·ÖÎöÈ·¶¨´Ë´Î¹¥»÷À´×ÔÓÚÄáÈÕÀûÑÇ£¬²¢Óɵ±Ç°¹¥»÷¹ØÁª³öÁ˸ü¶àºÚ¶ñÒâÓòÃûºÍÑù±¾¡£±¾ÎĶԺڿÍ×éÖ¯ËùʵʩµÄ¹¥»÷¹ý³Ì½øÐÐÏêϸµØ·ÖÎöºÍËÝÔ´£¬²¢¶ÔÆäËùʹÓõļäµýÈí¼þºÍ»ù´¡ÉèÊ©½øÐÐ͸³¹µØ·ÖÎö¡£


¹ØÓÚÃÅÂÞ±Ò¹©Ó¦Á´¹¥»÷ʼþ·ÖÎö


2019Äê11ÔÂ19ÈÕ£¬ÃÅÂÞ±Ò¹Ù·½githubÉÏ·ºÆð¶ÔÃÅÂÞ±Òrelease°æÓë¹ÙÍøÉÏ·ºÆð·×ÆçÖÂÎÊÌâµÄissues£¬ÆäÖÐÌá¼°·ºÆðÎÊÌâµÄÃÅÂޱҰ汾Ϊ×îаæ0.15.0.0¡£ÃÅÂÞ±Ò¹Ù·½ÈÏ¿ÉÆä¹ÙÍøÊܵ½ºÚ¿ÍÈëÇÖ£¬ÕâÊÇÊ״α»·¢ÏÖÕë¶Ô¼ÓÃÜ»õ±Ò¿Í»§¶ËµÄ¹©Ó¦Á´¹¥»÷¡£±¾ÎÄÏêϸ·ÖÎöÁ˱»¸Ä¶¯µÄmonero-wallet-cli¶ñÒâÎļþ£¬²¢¶ÔºÚ¿ÍµÄ»ù´¡ÉèÊ©½øÐÐ×·×Ù·ÖÎö£¬·¢ÏÖÁ˺ڿÍËùʹÓùýµÄÆäËû»ù´¡ÉèÊ©¡£


Äþ¾²Â©¶´·ÖÎö


LinuxÄÚºËCVE-2017-11176©¶´·ÖÎöÓ븴ÏÖ


LinuxÄÚºËÖеÄPOSIX ÏûÏ¢ÐÐÁÐʵÏÖÖдæÔÚÒ»¸öUAF©¶´CVE-2017-11176¡£¹¥»÷Õß¿ÉÒÔÀûÓø鶴µ¼Ö¾ܾø·þÎñ»òÖ´ÐÐÈÎÒâ´úÂë¡£±¾ÎĽ«´Ó©¶´³ÉÒò¡¢²¹¶¡·ÖÎöÒÔ¼°Â©¶´¸´Ïֵȶà¸ö½Ç¶È¶Ô¸Ã©¶´½øÐÐÏêϸ·ÖÎö¡£


ThinkPHP5ºËÐÄÀàRequestÔ¶³Ì´úÂ멶´·ÖÎö


ThinkPHPÍŶÓÐû²¼²¹¶¡¸üУ¬ÐÞ¸´ÁËÒ»´¦ÓÉÓÚ²»Äþ¾²µÄ¶¯Ì¬º¯Êýµ÷Óõ¼ÖµÄÔ¶³Ì´úÂëÖ´ÐЩ¶´£¬¸Ã©¶´Î£º¦Ë®Æ½·Ç³£¸ß¡£¶«É­Æ½Ì¨ADLab¶ÔThinkPHP¶à¸ö°æ±¾½øÐÐÁËÔ´Âë·ÖÎöºÍÑéÖ¤£¬ÊÜÓ°Ïì°æ±¾ÎªThinkPHP5.0-5.0.23ÍêÕû°æ¡£


Windows DHCP ServerÔ¶³Ì´úÂëÖ´ÐЩ¶´·ÖÎö£¨CVE-2019-0626£©


Windows DHCP Server´æÔÚÔ¶³Ì´úÂëÖ´ÐиßΣ©¶´CVE-2019-0626£¬µ±¹¥»÷ÕßÏòDHCP·þÎñÆ÷·¢Ë;«ÐÄÉè¼ÆµÄÊý¾Ý°ü²¢ÀÖ³ÉÀûÓú󣬾ͿÉÒÔÔÚDHCP·þÎñÖÐÖ´ÐÐÈÎÒâ´úÂ룬©¶´Ó°Ï췶Χ½Ï´ó¡£


Windows RDP·þÎñ¸ßΣ©¶´·ÖÎö£¨CVE-2019-0708£©


Windows RDP·þÎñµÄÔ¶³Ì´úÂëÖ´ÐиßΣ©¶´Ó°ÏìÁËijЩ¾É°æ±¾µÄWindowsϵͳ£¬ÓÉÓڸ鶴ÎÞÐèÉí·ÝÑéÖ¤ÇÒÎÞÐèÓû§½»»¥£¬ËùÒÔ¿ÉÒÔͨ¹ýÍøÂçÈä³æµÄ·½Ê½±»ÀûÓã¬ÀûÓôË©¶´µÄ¶ñÒâÈí¼þ¿ÉÒÔ´Ó±»Ñ¬È¾µÄ¼ÆËã»úÁ÷´«µ½ÍøÂçÖÐÆäËûÒ×Êܹ¥»÷µÄ¼ÆËã»ú£¬Á÷´«·½Ê½Óë2017ÄêWannaCry¶ñÒâÈí¼þµÄÁ÷´«·½Ê½ÀàËÆ¡£


LinuxÄÚºËSCTPЭÒ驶´·ÖÎöÓ븴ÏÖ


LinuxÄÚºËSCTPЭÒéʵÏÖÖдæÔÚÒ»¸öÄþ¾²Â©¶´CVE-2019-8956£¬¿ÉÒÔµ¼Ö¾ܾø·þÎñ¡£¸Ã©¶´´æÔÚÓÚnet/sctp/socket.cÖеÄsctp_sendmsg()º¯Êý£¬¸Ãº¯ÊýÔÚ´¦ÖÃSENDALL±êÖ¾²Ù×÷¹ý³Ìʱ´æÔÚuse-after-free©¶´¡£


LinuxÄÚºËTCPЭÒé¶à¸öSACK¹¦Ð§¾Ü¾ø·þÎñ©¶´·ÖÎö


LinuxÄÚºËTCP/IPЭÒéÕ»´æÔÚ3¸öÄþ¾²Â©¶´£¨CVE-2019-11477¡¢CVE-2019-11478¡¢CVE-2019-11479£©£¬ÕâЩ©¶´Óë×î´ó·Ö¶Î´óС£¨MSS£©ºÍTCPÑ¡ÔñÐÔÈ·ÈÏ£¨SACK£©¹¦Ð§Ïà¹Ø£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß½øÐоܾø·þÎñ¹¥»÷¡£


Advantech WebAccess¶à¸ö©¶´·ÖÎö


ZDIÐû²¼¶à¸öWebAccess©¶´£¬ÆäÖаüÂÞ¶à¸öÄÚ´æÆÆ»µÂ©¶´ºÍÕ»Òç³ö©¶´¡£²¿ÃÅÄÚ´æÆÆ»µÂ©¶´¿ÉÒÔÔÚÊÜÓ°ÏìµÄϵͳÖÐÖ´ÐÐÈÎÒâ´úÂ룬µ«ÊÇ´ó²¿ÃÅÄÚ´æÆÆ»µÂ©¶´ÀûÓÃÌõ¼þ½ÏΪ¿Á¿Ì¡£Í¬Ê±£¬ÓÉÓÚAdvantech WebAccessÐí¶àÄ £¿é²¢Ã»ÓпªÆôASLR¡¢DEPµÈϵͳÏà¹ØÄþ¾²»úÖÆ£¬Ê¹µÃÕ»Òç³öµÈ©¶´ÔÚÊÜÓ°ÏìµÄϵͳÖÐÈÝÒ×Ôì³É´úÂëÖ´ÐС£


¿ªÔ´Ñ¹Ëõ¿âlibarchive´úÂëÖ´ÐЩ¶´£¨CVE-2019-18408£©·ÖÎö


¹È¸èÄþ¾²Ñо¿Ô±·¢ÏÖlibarchive¿âÖдæÔÚ©¶´CVE-2019-18408¡£¹¥»÷Õß¿ÉÀûÓþ«ÐĽṹµÄѹËõÎļþ£¬¶ÔÊÜÓ°ÏìÓû§Ôì³ÉѹËõ·¨Ê½¾Ü¾ø·þÎñ»òÖ´ÐжñÒâ´úÂë¡£Õâ´Î±»ÆسöµÄÄþ¾²Â©¶´¼ä½ÓÓ°Ïìµ½ÁË´óÁ¿ÏîÄ¿ºÍ²úÎï¡£


Çø¿éÁ´×¨Ìâ·ÖÎö


Çø¿éÁ´ÖÇÄܺÏÔ¼¿ØÖÆÁ÷ʶ±ð´ó¹æģʵÑéÑо¿


¶«É­Æ½Ì¨ADLabÁªºÏµç×ӿƼ¼´óѧ¼ÆËã»úѧԺ³ÂÌü½ÌÊÚ¶ÔÒÔÌ«·»Çø¿éÁ´ÖÇÄܺÏÔ¼¿ØÖÆÁ÷µÄʶ±ð½øÐÐÁË´ó¹æÄ£Ñо¿£¬¸ÃÑо¿·ÖÎöÁ˵±Ç°6¸öÖ÷Á÷µÄÖÇÄܺÏÔ¼¾²Ì¬·ÖÎö¹¤¾ß£¬Í¨¹ý¶ÔÒÔÌ«·»Çø¿éÁ´ÉÏÒѲ¿ÊðµÄºÏÔ¼£¨½ü500Íò£©ÊµÊ©Ö´Ðиú×ÙÀ´ÆÀ¹ÀËûÃǵľ²Ì¬¿ØÖÆÁ÷ʶ±ðÄÜÁ¦¡£Ñо¿½á¹ûÒÑ·¢±íÔÚCCFÍƼöµÄ2019ÄêBÀàѧÊõ»áÒéÉÏ£¬²¢»ñµÃÁË×î¼ÑÂÛÎÄÌáÃû½±¡£


ÖÆÖ¹¡°¶çÊÖ¡±¼Ù»õ £¿Çø¿éÁ´Á´ÉÏÁ´ÏÂÊý¾ÝЭͬ·ÖÎö


¶«É­Æ½Ì¨ADLabÈÏΪ£¬Çø¿éÁ´µÄϵͳµÄ¿ÉÓÃÐÔÎÊÌâÊÇÉæ¼°¹¦Ð§ÊµÏÖÐÔµÄÎÊÌ⣬¶øʵÏÖÐÔÎÊÌâ±¾ÖÊÊÇÆÓËصÄÄþ¾²ÐÔÎÊÌ⣬²¢Õë¶Ô¡°Á´ÉÏÁ´ÏÂÊý¾ÝЭͬ¼¼Êõ¡±½øÐÐÁËÁ¬ÐøÑо¿¡£µ±Ç°£¬Á´ÉÏÁ´ÏÂÊý¾ÝЭͬ¼¼Êõ²¢²»ÍêÉÆ£¬µ¼ÖÂÇø¿éÁ´ÎÞ·¨Ðγɱջ·£¬ÊÇÏÞÖÆÇø¿éÁ´Ó¦Óó¡¾°µÄÖ÷Òª×è°­¡£


¶«É­Æ½Ì¨»ý¼«·ÀÓùʵÑéÊÒ£¨ADLab£©


ADLab½¨Á¢ÓÚ1999Ä꣬ÊÇÖйúÄþ¾²ÐÐÒµ×îÔ罨Á¢µÄ¹¥·À¼¼ÊõÑо¿ÊµÑéÊÒÖ®Ò»£¬Î¢ÈíMAPP¼Æ»®ºËÐijÉÔ±£¬¡°ºÚȸ¹¥»÷¡±¿´·¨Ê×ÍÆÕß¡£½ØֹĿǰ£¬ADLabÒÑͨ¹ýCVEÀÛ¼ÆÐû²¼Äþ¾²Â©¶´1000Óà¸ö£¬Í¨¹ý CNVD/CNNVDÀÛ¼ÆÐû²¼Äþ¾²Â©¶´600Óà¸ö£¬Á¬Ðø±£³Ö¹ú¼ÊÍøÂçÄþ¾²ÁìÓòÒ»Á÷Ë®×¼¡£ÊµÑéÊÒÑо¿Æ«Ïòº­¸Ç²Ù×÷ϵͳÓëÓ¦ÓÃϵͳÄþ¾²Ñо¿¡¢Òƶ¯ÖÇÄÜÖÕ¶ËÄþ¾²Ñо¿¡¢ÎïÁªÍøÖÇÄÜÉ豸Äþ¾²Ñо¿¡¢WebÄþ¾²Ñо¿¡¢¹¤¿ØϵͳÄþ¾²Ñо¿¡¢ÔÆÄþ¾²Ñо¿¡£Ñо¿½á¹ûÓ¦ÓÃÓÚ²úÎïºËÐļ¼ÊõÑо¿¡¢¹ú¼ÒÖصã¿Æ¼¼ÏîÄ¿¹¥¹Ø¡¢×¨ÒµÄþ¾²·þÎñµÈ¡£