ÐÅÏ¢Çå¾²Öܱ¨-2020ÄêµÚ03ÖÜ

Ðû²¼Ê±¼ä 2020-01-20


±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


2020Äê01ÔÂ13ÈÕÖÁ19ÈÕ¹²ÊÕ¼Çå¾²Îó²î53¸ö£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇMicrosoft Windows CryptoAPIÑéÖ¤ÈÆ¹ýÎó²î; Apache XML-RPC XMLRPC client´úÂëÖ´ÐÐÎó²î£»£» £»£»£»Oracle E-Business Suite Human Resources CVE-2020-2587δÃ÷´úÂëÖ´ÐÐÎó²î£»£» £»£»£»Adobe Illustrator CC CVE-2020-3710ÄÚ´æ¹ýʧÒýÓôúÂëÖ´ÐÐÎó²î£»£» £»£»£»Microsoft .NET Core CVE-2020-0602Ô¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£ ¡£¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇÒÔÉ«ÁÐÆô¶¯Ãñº½ÍøÂçÇå¾²ÍýÏ룬£¬£¬£¬£¬½«¸ÄÉÆº½¿ÕÍøÂç·ÀÓùÄÜÁ¦£»£» £»£»£»Î¢ÈíÕýʽÖÕÖ¹¶ÔWindows 7¡¢Server 2008ºÍ2008 R2Ìṩ֧³Ö£»£» £»£»£»ÃÀ¹úLimeLeads¹«Ë¾4900ÍòÌõÓû§¼Í¼ÔÚ°µÍøÂÛ̳³öÊÛ£»£» £»£»£»ÊÔÓÃAppÐ¶ÔØºóÖ±½Ó¿Û·Ñ£¬£¬£¬£¬£¬È«Çò½ü6ÒÚAndroidÓû§ÖÐÕУ»£» £»£»£»Êý°Ù¸öҽѧ³ÉÏñϵͳÔÚÍøÉÏ̻¶ÁËÊý°ÙÍò»¼ÕßµÄÊý¾Ý¡£¡£ ¡£¡£¡£¡£¡£


ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£ ¡£¡£¡£¡£¡£



Ö÷ÒªÇå¾²Îó²îÁбí


1. Microsoft Windows CryptoAPIÑéÖ¤ÈÆ¹ýÎó²î


Microsoft Windows CryptoAPI´¦Öóͷ£ECCÍÖÔ²ÇúÏß¼ÓÃܱ£´æÇå¾²Îó²î£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬¿ÉÒÔʹÓÃαÔìµÄÖ¤Êé¶Ô¶ñÒâµÄ¿ÉÖ´ÐÐÎļþ¾ÙÐÐÊðÃû£¬£¬£¬£¬£¬Ê¹Îļþ¿´ÆðÀ´À´×Ô¿ÉÐŵÄȪԴ£¬£¬£¬£¬£¬»òÕß¾ÙÐÐÖÐÐÄÈ˹¥»÷²¢½âÃÜÓû§ÅþÁ¬µ½ÊÜÓ°ÏìÈí¼þµÄÉñÃØÐÅÏ¢¡£¡£ ¡£¡£¡£¡£¡£

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0601


2. Apache XML-RPC XMLRPC client´úÂëÖ´ÐÐÎó²î


Apache XML-RPC XMLRPC clientʵÏÖXMLRPC¹ýʧÐÂÎÅfaultCauseÊôÐÔ´¦Öóͷ£±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²î¹¹½¨¶ñÒâXMLRPCЧÀÍÇëÇ󣬣¬£¬£¬£¬¿ÉʹӦÓóÌÐòÍ߽⻣» £»£»£»òÕßÖ´ÐÐí§Òâ´úÂë¡£¡£ ¡£¡£¡£¡£¡£

https://access.redhat.com/security/cve/cve-2019-17570


3. Oracle E-Business Suite Human Resources CVE-2020-2587δÃ÷´úÂëÖ´ÐÐÎó²î


Oracle E-Business Suite Human Resources±£´æÎ´Ã÷Çå¾²Îó²î£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬¿ÉʹӦÓóÌÐòÍ߽⻣» £»£»£»òÖ´ÐÐí§Òâ´úÂë¡£¡£ ¡£¡£¡£¡£¡£

https://www.oracle.com/security-alerts/cpujan2020.html


4. Adobe Illustrator CC CVE-2020-3710ÄÚ´æ¹ýʧÒýÓôúÂëÖ´ÐÐÎó²î


Adobe Illustrator CC´¦Öóͷ£Îļþ±£´æÄÚ´æÆÆËðÎó²î£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬£¬¿ÉʹӦÓóÌÐòÍ߽⻣» £»£»£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£ ¡£¡£¡£¡£¡£

https://helpx.adobe.com/security/products/illustrator/apsb20-03.html


5. Microsoft .NET Core CVE-2020-0602Ô¶³Ì´úÂëÖ´ÐÐÎó²î


Microsoft .NET CoreʵÏÖ±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£ ¡£¡£¡£¡£¡£

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0602


Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢ÒÔÉ«ÁÐÆô¶¯Ãñº½ÍøÂçÇå¾²ÍýÏ룬£¬£¬£¬£¬½«¸ÄÉÆº½¿ÕÍøÂç·ÀÓùÄÜÁ¦


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


¾ÝÉÏÖÜÈÕÒÔÉ«Áйú¼ÒÍøÂçÖÎÀí¾Ö£¨INCD£©±¨µÀ£¬£¬£¬£¬£¬ÒÔÉ«ÁÐÕþ¸®Åú×¼ÁËÒ»ÏîÃñº½ÍøÂçÇå¾²ÍýÏë¡£¡£ ¡£¡£¡£¡£¡£×÷Ϊ¸ÃÍýÏëµÄÒ»²¿·Ö£¬£¬£¬£¬£¬ÒÔÉ«Áн«½¨ÉèÒ»¸ö¹ú¼ÒÖ¸µ¼Î¯Ô±»áÀ´¸ÄÉÆ¸Ã¹ú¼ÒµÄº½¿ÕÍøÂç·ÀÓùÄÜÁ¦¡£¡£ ¡£¡£¡£¡£¡£¸ÃίԱ»áÓÉINCDÏòµ¼£¬£¬£¬£¬£¬²¢ÇÒÓÉÒÔÉ«Áн»Í¨²¿¡¢Ãñº½¾Ö¡¢»ú³¡ÖÎÀí¾Ö¡¢Çå¾²¾Ö¡¢¹ú·À²¿¡¢¹ú¼ÒÇ徲ίԱ»áºÍÒÔÉ«Áйú·À¾üµÄ´ú±í×é³É¡£¡£ ¡£¡£¡£¡£¡£¸ÃÍýÏëµÄÄÚÈݰüÀ¨£ºÍþвӳÉäÏ¢Õù¾ö¼Æ»®ÏîÄ¿¡¢Ôڸ߿Ƽ¼ºÍÍøÂçÐÐÒµÒÔ¼°Ñ§Êõ½çÍÆ¶¯Ç°ÑØÊÖÒÕÑо¿ºÍ¹ú·À½â¾ö¼Æ»®µÄÑз¢¡¢Ó벨Òô¾ÙÐÐÏàÖú¡¢½¨ÉèÔËÊä¿ØÖÆÖÐÐÄ¡¢¿ª·¢º½ÐÐÔ±Åàѵ¿Î³ÌµÈ¡£¡£ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

http://www.xinhuanet.com/english/2020-01/13/c_138699304.htm


2¡¢Î¢ÈíÕýʽÖÕÖ¹¶ÔWindows 7¡¢Server 2008ºÍ2008 R2Ìṩ֧³Ö


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


΢ÈíÓÚ1ÔÂ14ÈÕÕýʽÖÕÖ¹¶ÔWindows 7¡¢Server 2008ºÍServer 2008 R2Ìṩ֧³Ö¡£¡£ ¡£¡£¡£¡£¡£ÔÚ´ËÖ®ºóÕâЩ²Ù×÷ϵͳÈԿɼÌÐøÊÂÇ飬£¬£¬£¬£¬µ«½«²»ÔÙÊÕµ½Çå¾²¸üС£¡£ ¡£¡£¡£¡£¡£¶ÔWindows Server 2008µÄÖÕÖ¹Ö§³ÖÒâζ×ÅÆäÌØÁíÍâÃâ·ÑÇå¾²¸üС¢·ÇÇå¾²¸üС¢Ãâ·ÑµÄÖ§³ÖЧÀÍÒÔ¼°ÔÚÏßÊÖÒÕÄÚÈݸüж¼ÒÑ¿¢Ê¡£¡£ ¡£¡£¡£¡£¡£Î¢Èí±Þ²ßÓû§½«Æä²úÆ·ºÍЧÀÍǨáãµ½Azure»òÊÇÉý¼¶µ½×îа汾Server 2016¡£¡£ ¡£¡£¡£¡£¡£ÎÞ·¨ÔÚÖ§³ÖÖÕÖ¹ÏÞÆÚ֮ǰÍê³ÉÉý¼¶µÄÈË¿ÉÒÔ¹ºÖÃÀ©Õ¹Çå¾²¸üУ¬£¬£¬£¬£¬ÒÔ±£»£» £»£»£»¤Ð§ÀÍÆ÷ÊÂÇé¸ºÔØÖ±ÖÁÉý¼¶ÎªÖ¹¡£¡£ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.darkreading.com/risk/microsoft-to-officially-end-support-for-windows-7-server-2008/d/d-id/1336791


3¡¢ÃÀ¹úLimeLeads¹«Ë¾4900ÍòÌõÓû§¼Í¼ÔÚ°µÍøÂÛ̳³öÊÛ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


¾ÝZDNet±¨µÀ£¬£¬£¬£¬£¬ºÚ¿ÍOmnichorusÕýÔÚ°µÍøÂÛ̳ÉϳöÊÛÃÀ¹úÊý¾Ý¾­¼ÍÉÌLimeLeadsµÄ4900ÍòÌõÓû§¼Í¼¡£¡£ ¡£¡£¡£¡£¡£Çå¾²Ñо¿Ô±Bob DiachenkoÈ·ÈÏÕâЩÊý¾ÝÊÇÓɸù«Ë¾µÄÄÚ²¿ElasticsearchЧÀÍÆ÷̻¶ÔÚInternetÉÏй¶µÄ¡£¡£ ¡£¡£¡£¡£¡£Æ¾Ö¤DiachenkoµÄ˵·¨£¬£¬£¬£¬£¬ÖÁÉÙ´Ó2019Äê7ÔÂ27ÈÕÆðLimeLeadsµÄһ̨ЧÀÍÆ÷¾Í¿É¹ûÕæ»á¼û£¬£¬£¬£¬£¬ËûÓÚÈ¥Äê9ÔÂ16ÈÕ֪ͨÁ˸ù«Ë¾£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÔÚµÚ¶þÌìѸËÙ¶ÔЧÀÍÆ÷¾ÙÐÐÁ˱£»£» £»£»£»¤£¬£¬£¬£¬£¬µ«ÏÔÈ»OmnichorusÒѾ­ÇÔÈ¡ÁËÕâЩÊý¾Ý£¬£¬£¬£¬£¬²¢ÇÒ´ÓÈ¥Äê10ÔÂÒÔÀ´Ò»Ö±ÔÚÍøÉϳöÊÛ¡£¡£ ¡£¡£¡£¡£¡£Æ¾Ö¤OmnichorusÐû²¼µÄÊý¾ÝÑù±¾£¬£¬£¬£¬£¬ÕâЩÊý¾Ý°üÀ¨Óû§µÄÐÕÃû¡¢Ö°Îñ¡¢µç×ÓÓʼþ¡¢¹ÍÖ÷/¹«Ë¾Ãû³Æ¡¢¹«Ë¾µØµã¡¢¶¼»á¡¢ÖÝ¡¢ÓÊÕþ±àÂë¡¢µç»°ºÅÂë¡¢ÍøÕ¾URL¡¢¹«Ë¾×ÜÊÕÈëÒÔ¼°¹«Ë¾µÄÔ¤¼ÆÔ±¹¤ÈËÊýµÈÐÅÏ¢¡£¡£ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/49-million-user-records-from-us-data-broker-limeleads-put-up-for-sale-online/


4¡¢ÊÔÓÃAppÐ¶ÔØºóÖ±½Ó¿Û·Ñ£¬£¬£¬£¬£¬È«Çò½ü6ÒÚAndroidÓû§ÖÐÕÐ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


SophosÇå¾²Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»×éеÄfleeceware APP£¬£¬£¬£¬£¬ÕâЩAPPÒѾ­±»Áè¼Ý6ÒÚAndroidÓû§ÏÂÔØ×°Öᣡ£ ¡£¡£¡£¡£¡£fleecewareÊÇÖ¸¹È¸èPlayÊÐËÁÖб£´æµÄÒ»ÖÖÐÂÐͽðÈÚڲƭÐÐΪ£¬£¬£¬£¬£¬ÕâЩAPPÀÄÓÃAndroidÓ¦ÓõÄÊÔÓÃÆÚ¹¦Ð§ÏòÓû§ÊÕ·Ñ¡£¡£ ¡£¡£¡£¡£¡£Ä¬ÈÏÇéÐÎÏÂAndroidÓû§ÔÚ×¢²áʹÓþßÓÐÊÔÓÃÆÚµÄAPPʱ±ØÐèÊÖ¾Ù´ë·ÏÊÔÓ㬣¬£¬£¬£¬È»¶ø´ó´ó¶¼Óû§Ö»ÊÇÔÚ²»Ï²»¶µÄʱ¼äÐ¶ÔØAPP£¬£¬£¬£¬£¬¾ø´ó´ó¶¼¿ª·¢Õß½«ÕâÖÖÐ¶ÔØÐÐΪÊÓΪ×÷·ÏÊÔÓ㬣¬£¬£¬£¬µ«Ò»Ð©¿ª·¢ÕßÔÚÓû§Ð¶ÔغóûÓÐ×÷·ÏÊÔÓò¢ÇÒ¼ÌÐøÊÕ·Ñ¡£¡£ ¡£¡£¡£¡£¡£Sophos×î³õ·¢Ã÷µÄ24¸öAPP°üÀ¨¶þάÂëɨÃèÆ÷¡¢ÅÌËãÆ÷µÈ£¬£¬£¬£¬£¬ËüÃÇÒÔÕâÖÖ·½·¨ÏòÓû§ÊÕȡÿÄê100ÃÀÔªµ½240ÃÀÔªµÄ¶©ÔÄÓöÈ¡£¡£ ¡£¡£¡£¡£¡£ÔÚ¿ËÈÕÐû²¼µÄÒ»·Ý±¨¸æÖУ¬£¬£¬£¬£¬Sophos·¢Ã÷ÁËÁíÍâ25¸ö´ËÀàAPP£¬£¬£¬£¬£¬Æä×Ü×°ÖÃÁ¿Áè¼Ý6ÒÚ£¬£¬£¬£¬£¬ÍêÕûµÄAPPÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/more-than-600-million-users-installed-android-fleeceware-apps-from-the-play-store/


5¡¢Êý°Ù¸öҽѧ³ÉÏñϵͳÔÚÍøÉÏ̻¶ÁËÊý°ÙÍò»¼ÕßµÄÊý¾Ý


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


µÂ¹úÇå¾²³§ÉÌGreenbone³ÆÊý°Ù¸ö¿É¹ûÕæ»á¼ûµÄҽѧ³ÉÏñϵͳÔÚ»¥ÁªÍøÉÏ̻¶ÁËÈ«ÇòÊý°ÙÍò»¼ÕßµÄÊý¾Ý¡£¡£ ¡£¡£¡£¡£¡£¸ÃÏîÑо¿ÖصãÆÊÎöÔÚÍøÉÏ̻¶µÄҽѧͼƬ´æµµºÍͨѶϵͳ£¨PACS£©£¬£¬£¬£¬£¬ÔÚËùÓÐÊÜÆÊÎöµÄPACSЧÀÍÆ÷ÖУ¬£¬£¬£¬£¬ÓпìÒª1/4µÄϵͳ½«Êý¾Ý̻¶ÔÚ»¥ÁªÍøÉÏ¡£¡£ ¡£¡£¡£¡£¡£ÏêϸÀ´Ëµ£¬£¬£¬£¬£¬ÔÚ2019Äê7ÔÂÖÁ2019Äê9ÔÂÖ®¼äÆÊÎöµÄ2300¸öϵͳÖУ¬£¬£¬£¬£¬ÓÐ590¸ö¿É´ÓInternet»á¼û²¢ÇÒδÉèÃÜÂ룬£¬£¬£¬£¬¹²ÓÐÁè¼Ý2450ÍòÌõ»¼ÕßÊý¾Ý̻¶£¬£¬£¬£¬£¬ÔÚ11Ô·ݵÄÑо¿ÖУ¬£¬£¬£¬£¬¸Ã¹«Ë¾Í¸Â¶ÓÐ3500ÍòÌõ»¼Õ߼ͼ¿É¹ûÕæ»á¼û¡£¡£ ¡£¡£¡£¡£¡£ÔÚ9ÔÂÖÁ11ÔÂÖ®¼ä£¬£¬£¬£¬£¬°üÀ¨Ò½ÁÆÍ¼ÏñµÄ̻¶»¼Õ߼ͼÊýÄ¿ÒÑ´Ó440ÍòÔöÌíÁËÒ»±¶£¬£¬£¬£¬£¬µÖ´ï900Íò¡£¡£ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/unprotected-medical-systems-expose-data-millions-patients