ÐÅÏ¢Çå¾²Öܱ¨-2019ÄêµÚ5ÖÜ

Ðû²¼Ê±¼ä 2019-03-04

±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


2019Äê1ÔÂ28ÈÕÖÁ2ÔÂ03ÈÕ¹²ÊÕ¼Çå¾²Îó²î42¸ö£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇApache Hadoop CVE-2018-1296Çå¾²ÈÆ¹ýÎó²î£»£»£»£»£»D-Link DIR-823G HNAP1ÇëÇóÏÂÁî×¢ÈëÎó²î£»£»£»£»£»ACD Systems Canvas Draw CVE-2018-3976»º³åÇøÒç³öÎó²î£»£»£»£»£»ARM Trusted Firmware-AÐÅϢй¶Îó²î£»£»£»£»£»Google Chrome PDFium CVE-2019-5772ÊͷźóʹÓôúÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£¡£

±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇÊý¾ÝÖÎÀí¹«Ë¾RubrikÒâÍâй¶´ó×Ú¿Í»§Êý¾Ý£»£»£»£»£»FaceTimeÆØÖØ´óÇÔÌýÎó²î£¬£¬£¬£¬£¬£¬AppleÌåÏÖ½«ÔÚ±¾ÖÜÐÞ¸´£»£»£»£»£»Å·ÖÞÍøÂçÐÅÏ¢Çå¾²¾ÖENISAÐû²¼2018ÄêÍøÂçÍþв¾°¹Û±¨¸æ£»£»£»£»£»Ó¡¶È¹ú¼ÒÒøÐÐSBIÒâÍâй¶Êý°ÙÍò¿Í»§ÐÅÏ¢£»£»£»£»£»ºÉÀ¼DPAÐû²¼2018ÄêÊý¾Ýй¶ͳ¼Æ±¨¸æ¡£¡£¡£¡£¡£¡£¡£

ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£¡£¡£¡£

Ö÷ÒªÇå¾²Îó²îÁбí


1. Apache Hadoop CVE-2018-1296Çå¾²ÈÆ¹ýÎó²î
Apache Hadoop±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬ÈƹýÇå¾²ÏÞÖÆ£¬£¬£¬£¬£¬£¬Ö´ÐÐδÊÚȨµÄ²Ù×÷¡£¡£¡£¡£¡£¡£¡£
https://hadoop.apache.org/cve_list.html#cve-2018-8009-http-cve-mitre-org-cgi-bin-cvename-cgi-name-cve-2018-8009-zip-slip-impact-on-apache-hadoop

2. D-Link DIR-823G HNAP1ÇëÇóÏÂÁî×¢ÈëÎó²î
D-Link DIR-823G±£´æ´úÂë×¢ÈëÎó²î£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄHNAP1ÇëÇ󣬣¬£¬£¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐOSÏÂÁî¡£¡£¡£¡£¡£¡£¡£
https://github.com/leonW7/D-Link/blob/master/Vul_1.md

3. ACD Systems Canvas Draw CVE-2018-3976»º³åÇøÒç³öÎó²î
ACD Systems Canvas Draw CALS RasterÎļþÆÊÎö¹¦Ð§±£´æÔ½½çдÈëÎó²î£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþÇëÇ󣬣¬£¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»£»£»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£
https://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0642

4. ARM Trusted Firmware-AÐÅϢй¶Îó²î
ARM Trusted Firmware-A±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬£¬ÔÊÐíÍâµØ¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£
https://github.com/ARM-software/arm-trusted-firmware/wiki/Trusted-Firmware-A-Security-Advisory-TFV-8

5. Google Chrome PDFium CVE-2019-5772ÊͷźóʹÓôúÂëÖ´ÐÐÎó²î
Google Chrome PDFium±£´æÊͷźóʹÓÃÎó²î£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄWEBÒ³ÇëÇ󣬣¬£¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬£¬£¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£
https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html

 Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢Êý¾ÝÖÎÀí¹«Ë¾RubrikÒâÍâй¶´ó×Ú¿Í»§Êý¾Ý

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

Çå¾²Ñо¿Ô±Oliver Hough·¢Ã÷ÊôÓÚÊý¾ÝÖÎÀí¹«Ë¾RubrikµÄÒ»¸öElasticsearchЧÀÍÆ÷δÊÜÃÜÂë±£»£»£»£»£»¤£¬£¬£¬£¬£¬£¬¸ÃÊý¾Ý¿â´æ´¢ÁËÊýÊ®GBµÄÊý¾Ý£¬£¬£¬£¬£¬£¬°üÀ¨ÆóÒµ¿Í»§µÄÃû³Æ¡¢ÁªÏµÐÅÏ¢ºÍÊÂÇé°¸Àý¡£¡£¡£¡£¡£¡£¡£Æ¾Ö¤Ê±¼ä´Á£¬£¬£¬£¬£¬£¬ÕâЩÊý¾Ý¿É×·ËÝÖÁ2018Äê10Ô¡£¡£¡£¡£¡£¡£¡£¾­ÓÉÊӲ죬£¬£¬£¬£¬£¬Rubrik³ÆÕâÒ»ÊÂÎñÊÇÓÉÈËΪ¹ýʧµ¼ÖµÄ¡£¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://techcrunch.com/2019/01/29/rubrik-data-leak/

2¡¢FaceTimeÆØÖØ´óÇÔÌýÎó²î£¬£¬£¬£¬£¬£¬AppleÌåÏÖ½«ÔÚ±¾ÖÜÐÞ¸´

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


¾ÝÍâý±¨µÀ£¬£¬£¬£¬£¬£¬Apple FaceTime±£´æÖØ´óÇå¾²Îó²î£¬£¬£¬£¬£¬£¬¿ÉÔÊÐí¹¥»÷ÕßÔÚÄ¿µÄ½ÓÌý»ò¾Ü¾øFaceTimeͨ»°Ö®Ç°¼àÌý¶Ô·½µÄÉùÒô¡£¡£¡£¡£¡£¡£¡£ÈôÊǶԷ½°´ÏÂÒôÁ¿½µµÍ°´Å¥»òµçÔ´°´Å¥À´¾²Òô»ò×÷·Ïͨ»°£¬£¬£¬£¬£¬£¬ÔòÆäǰÖÃÉãÏñÍ·Ò²»á·­¿ª£¬£¬£¬£¬£¬£¬²¢½«ÊÓÆµÐźŷ¢Ë͸ø¹¥»÷Õß¡£¡£¡£¡£¡£¡£¡£¾ÝϤ£¬£¬£¬£¬£¬£¬¸ÃÎó²î»á·ºÆðÔÚiOS 12.1»ò¸ü¸ß°æ±¾µÄiOS×°±¸ÖС£¡£¡£¡£¡£¡£¡£AppleÒѾ­ÔÝʱ½ûÓÃÁËFaceTimeÖеÄȺ×éͨ»°¹¦Ð§£¬£¬£¬£¬£¬£¬²¢ÌåÏÖ½«ÔÚ±¾ÖÜÍíЩʱ¼äÐû²¼ÐÞ¸´²¹¶¡¡£¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://thehackernews.com/2019/01/apple-facetime-privacy-hack.html

3¡¢Å·ÖÞÍøÂçÐÅÏ¢Çå¾²¾ÖENISAÐû²¼2018ÄêÍøÂçÍþв¾°¹Û±¨¸æ

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Å·ÖÞÍøÂçÐÅÏ¢Çå¾²¾Ö£¨ENISA£©Ðû²¼2018ÄêÍþв¾°¹Û±¨¸æ£¬£¬£¬£¬£¬£¬¸Ã±¨¸æÖصãÏÈÈÝÁË2018ÄêµÄÍøÂçÍþвÇ÷ÊÆ×ª±ä£¬£¬£¬£¬£¬£¬°üÀ¨µç×ÓÓʼþºÍ´¹ÂÚ¶ÌÐÅÒѾ­³ÉΪÖ÷ÒªµÄ¶ñÒâÈí¼þѬȾǰÑÔ£»£»£»£»£»¶ñÒâ¿ó¹¤³ÉΪ·¸·¨·Ö×ÓµÄÖ÷Ҫ׬ǮÊֶΣ»£»£»£»£»¹ú¼Ò×ÊÖúµÄ·¸·¨ÍÅ»ïÔ½À´Ô½¶àµØÃé×¼ÒøÐУ»£»£»£»£»ÓÉÓÚȱ°±ÉͶËÎïÁªÍø×°±¸ºÍЧÀ͵ı£»£»£»£»£»¤»úÖÆ£¬£¬£¬£¬£¬£¬¶ÔͨÓÃÎïÁªÍø±£»£»£»£»£»¤¼Ü¹¹/ÓÅÒìʵ¼ùµÄÐèÇóÈÔÈ»ÊÇÒ»¸ö½ôÆÈµÄÎÊÌ⣻£»£»£»£»ÍþвÇ鱨ÐèҪʹÓÃеÄ×Ô¶¯»¯¹¤¾ßºÍÒªÁìÀ´Ó¦¶Ô×Ô¶¯»¯µÄ¹¥»÷£»£»£»£»£»Çå¾²ÁìÓòÓ¦¸ÃÖØµã¹Ø×¢È˲źÍÊÖÒÕµÄÅàѵ¡£¡£¡£¡£¡£¡£¡£¸Ã±¨¸æ»¹´ÓÕþ²ß¡¢ÆóÒµÒÔ¼°ÊÖÒÕ¡¢Ñо¿ºÍ½ÌÓý·½ÃæÌá³öÁ˽¨Òé¡£¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.enisa.europa.eu/publications/enisa-threat-landscape-report-2018/

4¡¢Ó¡¶È¹ú¼ÒÒøÐÐSBIÒâÍâй¶Êý°ÙÍò¿Í»§ÐÅÏ¢

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ÄäÃûÇå¾²Ñо¿Ö°Ô±·¢Ã÷һ̨ÓÃÓÚÒøÐмÓËÙЧÀ͵ÄЧÀÍÆ÷£¬£¬£¬£¬£¬£¬ÕâÊÇÒ»ÖÖ»ùÓÚÒÆ¶¯µÄÐÅϢЧÀÍ¡£¡£¡£¡£¡£¡£¡£¸ÃÊý¾Ý¿âÔÚûÓб£»£»£»£»£»¤µÄÇéÐÎϱ»¹ûÕæ£¬£¬£¬£¬£¬£¬¸ÃÊý¾Ý¿â°üÀ¨Êý°ÙÍòÌõ¶ÌÐÅ£¬£¬£¬£¬£¬£¬¿É×·Ëݵ½12Ô·Ý£¬£¬£¬£¬£¬£¬°üÀ¨¿Í»§µÄµç»°ºÅÂ룬£¬£¬£¬£¬£¬²¿·ÖÒøÐÐÕ˺Å£¬£¬£¬£¬£¬£¬ÒøÐÐÓà¶îºÍÉúÒâ¼Í¼¡£¡£¡£¡£¡£¡£¡£ºÃÐÂÎÅÊÇ£¬£¬£¬£¬£¬£¬Ó¡¶È¹ú¼ÒÒøÐÐÔÚµÃÖªÎÊÌâºóÊýСʱÄÚѸËÙ½â¾öÁËÕâ¸öÎÊÌ⣬£¬£¬£¬£¬£¬Òź¶µÄÊÇ£¬£¬£¬£¬£¬£¬²»ÖªµÀÊý¾ÝÔÚÍøÉÏ̻¶Á˶೤ʱ¼ä¡£¡£¡£¡£¡£¡£¡£ÕâЩÐÅÏ¢µÄ¿ÉÓÃÐÔ¸øÒøÐпͻ§´øÀ´ÁËÑÏÖØµÄΣº¦£¬£¬£¬£¬£¬£¬ÍþвÐÐΪÕß¿ÉÒÔʹÓÃËüÀ´Ãé×¼ÒøÐпͻ§¡£¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/80555/data-breach/state-bank-of-india-leak.html

5¡¢ºÉÀ¼DPAÐû²¼2018ÄêÊý¾Ýй¶ͳ¼Æ±¨¸æ

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


2019Äê1ÔÂ29ÈÕ£¬£¬£¬£¬£¬£¬ºÉÀ¼Êý¾Ý±£»£»£»£»£»¤¾Ö£¨Autoriteit Persoonsgegevens£¬£¬£¬£¬£¬£¬¡°ºÉÀ¼DPA¡±£©½ÒÏþÁËÒ»·Ý±¨¸æ¹ØÓÚ2018ÄêÊÕµ½µÄСÎÒ˽¼ÒÊý¾Ýй¶֪ͨ£¨¡°±¨¸æ¡±£©¡£¡£¡£¡£¡£¡£¡£Å·ÃËͨÓÃÊý¾Ý±£»£»£»£»£»¤¹æÔò£¨¡°GDPR¡±£©ÒªÇóÊý¾ÝÖÎÀíÔ±ÔÚ֪ϤºóµÄ72СʱÄÚ½«Êý¾Ýй¶֪ͨÖ÷¹ÜÊý¾Ý±£»£»£»£»£»¤¾Ö£¨¡°DPA¡±£©¡£¡£¡£¡£¡£¡£¡£ÔÚºÉÀ¼£¬£¬£¬£¬£¬£¬×Ô2016Äê1ÔÂ1ÈÕÆð£¬£¬£¬£¬£¬£¬¸ÃÎ¥¹æÍ¨ÖªÒªÇóÒѾ­ÊµÑé¡£¡£¡£¡£¡£¡£¡£¿ÉÊÇ£¬£¬£¬£¬£¬£¬GDPR»®¶¨ÁËÌØÁíÍâÒªÇ󣬣¬£¬£¬£¬£¬°üÀ¨£ºÔÚÎ¥¹æÍ¨ÖªÖÐÌṩijЩÐÅÏ¢; ÈôÊÇÎ¥¹æÐÐΪ¿ÉÄܶÔÕâЩÈ˵ÄȨÁ¦ºÍ×ÔÓÉÔì³É¸ßΣº¦£¬£¬£¬£¬£¬£¬Êý¾ÝÖÎÀíÔ±ÓÐÒåÎñ֪ͨÊÜÓ°ÏìµÄСÎÒ˽¼Ò; ¹«Ë¾ÓÐÒåÎñ¼Í¼ÈκÎСÎÒ˽¼ÒÊý¾Ýй¶ÊÂÎñ¡£¡£¡£¡£¡£¡£¡£2018Ä꣬£¬£¬£¬£¬£¬ºÉÀ¼DPAÊÕµ½µÄÊý¾Ýй¶֪ͨÊýÄ¿ÔöÌíÁËÒ»±¶£¬£¬£¬£¬£¬£¬¹²¼Æ20,881´ÎÎ¥¹æÍ¨Öª¡£¡£¡£¡£¡£¡£¡£ÊÜÓ°Ïì×î´óµÄ²¿·ÖÊÇ¿µ½¡ºÍ¸£Àû²¿·Ö£¨×ª´ïµÄÎ¥¹æÐÐΪµÄ29£¥£©£¬£¬£¬£¬£¬£¬½ðÈÚ²¿·Ö£¨Í¨ÖªµÄÎ¥¹æÐÐΪµÄ26£¥£©ºÍ¹«¹²²¿·Ö£¨17£¥µÄÎ¥¹æÍ¨Öª£©¡£¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.databreaches.net/dutch-dpa-publishes-2018-report-on-data-breach-statistics/

ÉùÃ÷£º±¾×ÊѶÓɼøºÚµ£±£ÍøÎ¬ËûÃüÇ徲С×é·­ÒëºÍÕûÀí