ÐÅÏ¢Äþ¾²Öܱ¨-2020ÄêµÚ03ÖÜ

Ðû²¼Ê±¼ä 2020-01-20


±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


2020Äê01ÔÂ13ÈÕÖÁ19ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´53¸ö £¬ÖµµÃ¹Ø×¢µÄÊÇMicrosoft Windows CryptoAPIÑéÖ¤Èƹý©¶´; Apache XML-RPC XMLRPC client´úÂëÖ´ÐЩ¶´£»Oracle E-Business Suite Human Resources CVE-2020-2587δÃ÷´úÂëÖ´ÐЩ¶´£»Adobe Illustrator CC CVE-2020-3710ÄÚ´æ´íÎóÒýÓôúÂëÖ´ÐЩ¶´£»Microsoft .NET Core CVE-2020-0602Ô¶³Ì´úÂëÖ´ÐЩ¶´¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇÒÔÉ«ÁÐÆô¶¯Ãñº½ÍøÂçÄþ¾²¼Æ»® £¬½«¸ÄÉƺ½¿ÕÍøÂç·ÀÓùÄÜÁ¦£»Î¢ÈíÕýʽÖÕÖ¹¶ÔWindows 7¡¢Server 2008ºÍ2008 R2Ìṩ֧³Ö£»ÃÀ¹úLimeLeads¹«Ë¾4900ÍòÌõÓû§¼Ç¼ÔÚ°µÍøÂÛ̳³öÊÛ£»ÊÔÓÃAppжÔغóÖ±½Ó¿Û·Ñ £¬È«Çò½ü6ÒÚAndroidÓû§ÖÐÕУ»Êý°Ù¸öҽѧ³ÉÏñϵͳÔÚÍøÉÏ̻¶ÁËÊý°ÙÍò»¼ÕßµÄÊý¾Ý¡£


ƾ¾ÝÒÔÉÏ×ÛÊö £¬±¾ÖÜÄþ¾²ÍþвΪÖС£



ÖØÒªÄþ¾²Â©¶´Áбí


1. Microsoft Windows CryptoAPIÑéÖ¤Èƹý©¶´


Microsoft Windows CryptoAPI´¦ÖÃECCÍÖÔ²ÇúÏß¼ÓÃÜ´æÔÚÄþ¾²Â©¶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬¿ÉÒÔʹÓÃαÔìµÄÖ¤Êé¶Ô¶ñÒâµÄ¿ÉÖ´ÐÐÎļþ½øÐÐÇ©Ãû £¬Ê¹Îļþ¿´ÆðÀ´À´×Ô¿ÉÐŵÄÀ´Ô´ £¬»òÕß½øÐÐÖмäÈ˹¥»÷²¢½âÃÜÓû§Á¬½Óµ½ÊÜÓ°ÏìÈí¼þµÄ»úÃÜÐÅÏ¢¡£

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0601


2. Apache XML-RPC XMLRPC client´úÂëÖ´ÐЩ¶´


Apache XML-RPC XMLRPC clientʵÏÖXMLRPC´íÎóÏûÏ¢faultCauseÊôÐÔ´¦ÖôæÔÚÄþ¾²Â©¶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴¹¹½¨¶ñÒâXMLRPC·þÎñÇëÇó £¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÕßÖ´ÐÐÈÎÒâ´úÂë¡£

https://access.redhat.com/security/cve/cve-2019-17570


3. Oracle E-Business Suite Human Resources CVE-2020-2587δÃ÷´úÂëÖ´ÐЩ¶´


Oracle E-Business Suite Human Resources´æÔÚδÃ÷Äþ¾²Â©¶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐÈÎÒâ´úÂë¡£

https://www.oracle.com/security-alerts/cpujan2020.html


4. Adobe Illustrator CC CVE-2020-3710ÄÚ´æ´íÎóÒýÓôúÂëÖ´ÐЩ¶´


Adobe Illustrator CC´¦ÖÃÎļþ´æÔÚÄÚ´æÆÆ»µÂ©¶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬ÓÕʹÓû§½âÎö £¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£

https://helpx.adobe.com/security/products/illustrator/apsb20-03.html


5. Microsoft .NET Core CVE-2020-0602Ô¶³Ì´úÂëÖ´ÐЩ¶´


Microsoft .NET CoreʵÏÖ´æÔÚÄþ¾²Â©¶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬¿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0602


ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢ÒÔÉ«ÁÐÆô¶¯Ãñº½ÍøÂçÄþ¾²¼Æ»® £¬½«¸ÄÉƺ½¿ÕÍøÂç·ÀÓùÄÜÁ¦


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¾ÝÉÏÖÜÈÕÒÔÉ«Áйú¼ÒÍøÂç¹ÜÀí¾Ö£¨INCD£©±¨µÀ £¬ÒÔÉ«ÁÐÕþ¸®Åú×¼ÁËÒ»ÏîÃñº½ÍøÂçÄþ¾²¼Æ»®¡£×÷Ϊ¸Ã¼Æ»®µÄÒ»²¿ÃÅ £¬ÒÔÉ«Áн«½¨Á¢Ò»¸ö¹ú¼ÒÖ¸µ¼Î¯Ô±»áÀ´¸ÄÉƸùú¼ÒµÄº½¿ÕÍøÂç·ÀÓùÄÜÁ¦¡£¸ÃίԱ»áÓÉINCDÁìµ¼ £¬¶øÇÒÓÉÒÔÉ«Áн»Í¨²¿¡¢Ãñº½¾Ö¡¢»ú³¡¹ÜÀí¾Ö¡¢Äþ¾²¾Ö¡¢¹ú·À²¿¡¢¹ú¼ÒÄþ¾²Î¯Ô±»áºÍÒÔÉ«Áйú·À¾üµÄ´ú±í×é³É¡£¸Ã¼Æ»®µÄÄÚÈÝ°üÂÞ£ºÍþвӳÉäºÍ½â¾ö·½°¸ÏîÄ¿¡¢Ôڸ߿Ƽ¼ºÍÍøÂçÐÐÒµÒÔ¼°Ñ§Êõ½çÍƶ¯Ç°Ñؼ¼ÊõÑо¿ºÍ¹ú·À½â¾ö·½°¸µÄÑз¢¡¢Ó벨Òô½øÐкÏ×÷¡¢½¨Á¢ÔËÊä¿ØÖÆÖÐÐÄ¡¢¿ª·¢·ÉÐÐÔ±Åàѵ¿Î³ÌµÈ¡£


Ô­ÎÄÁ´½Ó£º

http://www.xinhuanet.com/english/2020-01/13/c_138699304.htm


2¡¢Î¢ÈíÕýʽÖÕÖ¹¶ÔWindows 7¡¢Server 2008ºÍ2008 R2Ìṩ֧³Ö


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


΢ÈíÓÚ1ÔÂ14ÈÕÕýʽÖÕÖ¹¶ÔWindows 7¡¢Server 2008ºÍServer 2008 R2Ìṩ֧³Ö¡£ÔÚ´ËÖ®ºóÕâЩ²Ù×÷ϵͳÈԿɼÌÐøÊÂÇé £¬µ«½«²»ÔÙÊÕµ½Äþ¾²¸üС£¶ÔWindows Server 2008µÄÖÕÖ¹Ö§³ÖÒâζ×ÅÆäÌرðµÄÃâ·ÑÄþ¾²¸üС¢·ÇÄþ¾²¸üС¢Ãâ·ÑµÄÖ§³Ö·þÎñÒÔ¼°ÔÚÏß¼¼ÊõÄÚÈݸüж¼ÒѽáÊø¡£Î¢Èí¶Ø´ÙÓû§½«Æä²úÎïºÍ·þÎñǨÒƵ½Azure»òÊÇÉý¼¶µ½×îа汾Server 2016¡£ÎÞ·¨ÔÚÖ§³ÖÖÕÖ¹ÆÚÏÞ֮ǰÍê³ÉÉý¼¶µÄÈË¿ÉÒÔ¹ºÖÃÀ©Õ¹Äþ¾²¸üР£¬ÒÔ±£»¤·þÎñÆ÷ÊÂÇ鸺ÔØÖ±ÖÁÉý¼¶ÎªÖ¹¡£


Ô­ÎÄÁ´½Ó£º

https://www.darkreading.com/risk/microsoft-to-officially-end-support-for-windows-7-server-2008/d/d-id/1336791


3¡¢ÃÀ¹úLimeLeads¹«Ë¾4900ÍòÌõÓû§¼Ç¼ÔÚ°µÍøÂÛ̳³öÊÛ


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¾ÝZDNet±¨µÀ £¬ºÚ¿ÍOmnichorusÕýÔÚ°µÍøÂÛ̳ÉϳöÊÛÃÀ¹úÊý¾Ý¾­¼ÍÉÌLimeLeadsµÄ4900ÍòÌõÓû§¼Ç¼¡£Äþ¾²Ñо¿Ô±Bob DiachenkoÈ·ÈÏÕâЩÊý¾ÝÊÇÓɸù«Ë¾µÄÄÚ²¿Elasticsearch·þÎñÆ÷̻¶ÔÚInternetÉÏ鶵Ä¡£Æ¾¾ÝDiachenkoµÄ˵·¨ £¬ÖÁÉÙ´Ó2019Äê7ÔÂ27ÈÕÆðLimeLeadsµÄһ̨·þÎñÆ÷¾Í¿É¹ûÈ»·ÃÎÊ £¬ËûÓÚÈ¥Äê9ÔÂ16ÈÕ֪ͨÁ˸ù«Ë¾ £¬¸Ã¹«Ë¾ÔÚµÚ¶þÌìѸËÙ¶Ô·þÎñÆ÷½øÐÐÁ˱£»¤ £¬µ«ÏÔÈ»OmnichorusÒѾ­ÇÔÈ¡ÁËÕâЩÊý¾Ý £¬¶øÇÒ´ÓÈ¥Äê10ÔÂÒÔÀ´Ò»Ö±ÔÚÍøÉϳöÊÛ¡£Æ¾¾ÝOmnichorusÐû²¼µÄÊý¾ÝÑù±¾ £¬ÕâЩÊý¾Ý°üÂÞÓû§µÄÐÕÃû¡¢Ö°Îñ¡¢µç×ÓÓʼþ¡¢¹ÍÖ÷/¹«Ë¾Ãû³Æ¡¢¹«Ë¾µØÖ·¡¢¶¼ÊС¢ÖÝ¡¢ÓÊÕþ±àÂë¡¢µç»°ºÅÂë¡¢ÍøÕ¾URL¡¢¹«Ë¾×ÜÊÕÈëÒÔ¼°¹«Ë¾µÄÔ¤¼ÆÔ±¹¤ÈËÊýµÈÐÅÏ¢¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/49-million-user-records-from-us-data-broker-limeleads-put-up-for-sale-online/


4¡¢ÊÔÓÃAppжÔغóÖ±½Ó¿Û·Ñ £¬È«Çò½ü6ÒÚAndroidÓû§ÖÐÕÐ


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


SophosÄþ¾²Ñо¿ÈËÔ±·¢ÏÖÁËÒ»×éеÄfleeceware APP £¬ÕâЩAPPÒѾ­±»Áè¼Ý6ÒÚAndroidÓû§ÏÂÔØ°²×°¡£fleecewareÊÇÖ¸¹È¸èPlayÉ̵êÖдæÔÚµÄÒ»ÖÖÐÂÐͽðÈÚÆÛÕ©ÐÐΪ £¬ÕâЩAPPÀÄÓÃAndroidÓ¦ÓõÄÊÔÓÃÆÚ¹¦Ð§ÏòÓû§ÊÕ·Ñ¡£Ä¬ÈÏÇé¿öÏÂAndroidÓû§ÔÚ×¢²áʹÓþßÓÐÊÔÓÃÆÚµÄAPPʱ±ØÐëÊÖ¶¯È¡ÏûÊÔÓà £¬È»¶ø´ó¶àÊýÓû§Ö»ÊÇÔÚ²»Ï²»¶µÄʱºòжÔØAPP £¬¾ø´ó¶àÊý¿ª·¢Õß½«ÕâÖÖжÔØÐÐΪÊÓΪȡÏûÊÔÓà £¬µ«Ò»Ð©¿ª·¢ÕßÔÚÓû§Ð¶ÔغóûÓÐÈ¡ÏûÊÔÓöøÇÒ¼ÌÐøÊÕ·Ñ¡£Sophos×î³õ·¢ÏÖµÄ24¸öAPP°üÂÞ¶þάÂëɨÃèÆ÷¡¢¼ÆËãÆ÷µÈ £¬ËüÃÇÒÔÕâÖÖ·½Ê½ÏòÓû§ÊÕȡÿÄê100ÃÀÔªµ½240ÃÀÔªµÄ¶©ÔÄÓöÈ¡£ÔÚ½üÈÕÐû²¼µÄÒ»·Ý³ÂËßÖÐ £¬Sophos·¢ÏÖÁËÁíÍâ25¸ö´ËÀàAPP £¬Æä×Ü°²×°Á¿Áè¼Ý6ÒÚ £¬ÍêÕûµÄAPPÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/more-than-600-million-users-installed-android-fleeceware-apps-from-the-play-store/


5¡¢Êý°Ù¸öҽѧ³ÉÏñϵͳÔÚÍøÉÏ̻¶ÁËÊý°ÙÍò»¼ÕßµÄÊý¾Ý


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


µÂ¹úÄþ¾²³§ÉÌGreenbone³ÆÊý°Ù¸ö¿É¹ûÈ»·ÃÎʵÄҽѧ³ÉÏñϵͳÔÚ»¥ÁªÍøÉÏ̻¶ÁËÈ«ÇòÊý°ÙÍò»¼ÕßµÄÊý¾Ý¡£¸ÃÏîÑо¿Öصã·ÖÎöÔÚÍøÉÏ̻¶µÄҽѧͼƬ´æµµºÍͨÐÅϵͳ£¨PACS£© £¬ÔÚËùÓÐÊÜ·ÖÎöµÄPACS·þÎñÆ÷ÖÐ £¬Óн«½ü1/4µÄϵͳ½«Êý¾Ý̻¶ÔÚ»¥ÁªÍøÉÏ¡£¾ßÌåÀ´Ëµ £¬ÔÚ2019Äê7ÔÂÖÁ2019Äê9ÔÂÖ®¼ä·ÖÎöµÄ2300¸öϵͳÖÐ £¬ÓÐ590¸ö¿É´ÓInternet·ÃÎʶøÇÒδÉèÃÜÂë £¬¹²ÓÐÁè¼Ý2450ÍòÌõ»¼ÕßÊý¾Ý̻¶ £¬ÔÚ11Ô·ݵÄÑо¿ÖÐ £¬¸Ã¹«Ë¾Í¸Â¶ÓÐ3500ÍòÌõ»¼Õ߼Ǽ¿É¹ûÈ»·ÃÎÊ¡£ÔÚ9ÔÂÖÁ11ÔÂÖ®¼ä £¬°üÂÞÒ½ÁÆͼÏñµÄ̻¶»¼Õ߼ǼÊýÁ¿ÒÑ´Ó440ÍòÔö¼ÓÁËÒ»±¶ £¬µ½´ï900Íò¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/unprotected-medical-systems-expose-data-millions-patients