ADLab2019Ä갲ȫ×êÑлØÊ×

°ä²¼¹¦·ò 2019-12-31

2019Äê £¬£¬£¬OG¶«·½ÌüADLab×êÑз½ÏòÖØµãÔ̺¬Ö÷Á÷²Ù×÷ϵͳ¼°ÀûÓð²È«×êÑС¢¡¢¡¢Web°²È«×êÑС¢¡¢¡¢Òƶ¯»¥ÁªÍø°²È«×êÑС¢¡¢¡¢ÎïÁªÍø°²È«×êÑС¢¡¢¡¢¹¤¿Ø»¥ÁªÍø°²È«×êÑкÍÇø¿éÁ´°²È«×êÑÐ £¬£¬£¬ÆäÖв¿ÃÅ×êÑÐÎÄÕÂÒÑͨ¹ýADLab¹«¼Òƽ̨°ä²¼ £¬£¬£¬Îª·½±ã¸÷È˲éÔÄÎÒÃǶÔÕûÄê°ä²¼µÄÖØÒª×êÑÐÎÄÕ½øÐÐÁËÕû¶Ù¡£¡£¡£


ÈȵãÊÂÎñ¹«¸æ


¡¾Ô­´´·ì϶¡¿Adobe ColdFusion ·´ÐòÁл¯RCE·ì϶·ÖÎö


OG¶«·½ÌüADLab·¢ÏÖAdobe ColdFusionÖÐFlashGateway·þÎñ´æÔÚCritical£¨Î£»ú£©·´ÐòÁл¯·ì϶£¨CVE-2019-7091£© £¬£¬£¬ÀûÓø÷ì϶¹¥»÷Õß¿ÉÔ¶³ÌÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£


¡¾·ì϶¹«¸æ¡¿LinuxÄں˴æÔÚ±¾µØÌáȨ·ì϶£¨CVE-2019-8912£©


¡¾Ô­´´·ì϶¡¿LinuxÄÚºËMarvell WI-FIоƬÇý¶¯·ì϶£¨CVE-2019-3846/CVE-2019-10126£©


¡¾Ô­´´·ì϶¡¿LinuxÄÚºËMarvell WI-FIоƬÇý¶¯¶à¸öÔ¶³Ì·ì϶


Linux git´æÔÚ±¾µØÌáȨ·ì϶ £¬£¬£¬Äܹ»µ¼Ö±¾µØ´úÂëִǰ½øÐÐȨÏÞÌáÉý¡£¡£¡£LinuxÄÚºËMarvell WI-FIоƬÇý¶¯´æÔÚ¶à¸öÔ¶³ÌÒç³ö·ì϶ºÍ±¾µØÒç³ö·ì϶ £¬£¬£¬¿Éµ¼Ö»ؾø·þÎñ£¨ÏµÍ³±ÀÀ££©»òËÁÒâ´úÂëÖ´ÐС£¡£¡£·ì϶ӰÏìÁìÓò½Ï¹ã¡£¡£¡£


¡¾Ô­´´·ì϶¡¿WebLogicËÁÒâÎļþ¶ÁÈ¡·ì϶£¨CVE-2019-2615£©


¡¾Ô­´´·ì϶¡¿WebLogic Blind XXE·ì϶£¨CVE-2019-2647£©


¡¾Ô­´´·ì϶¡¿WebLogic Ô¶³ÌºÅÁîÖ´Ðзì϶£¨CVE-2019-2725²¹¶¡Èƹý£©


¡¾Ô­´´·ì϶¡¿WebLogic ·´ÐòÁл¯·ì϶£¨CVE-2019-2890£©


¡¾Ô­´´·ì϶¡¿WebLogic Blind XXE·ì϶£¨CVE-2019-2887£©


OG¶«·½ÌüADLab·¢ÏÖWebLogic´æÔÚÉÏÊö·ì϶ £¬£¬£¬¹¥»÷Õß¿ÉÔÚÒÑÖªÓû§ÃûÃÜÂëµÄÇé¿ö϶ÁÈ¡WebLogic·þÎñÆ÷ÖеÄËÁÒâÎļþ£»£»£»¿ÉÔÚδÊÚȨµÄÇé¿öÏÂʵÏÖ¶Ô´æÔÚ·ì϶µÄWebLogic×é¼þ½øÐÐÔ¶³ÌBlind XXE¹¥»÷£»£»£»¿ÉÔڵͰ汾JDKµÄ»·¾³ÖÐÈÆ¹ý²¹¶¡È±µãµ¼ÖÂËÁÒâÔ¶³ÌºÅÁîÖ´ÐУ»£»£»¿Éͨ¹ýT3ºÍ̸¶Ô´æÔÚ·ì϶µÄWebLogic×é¼þÖ´ÐÐÔ¶³ÌËÁÒâ´úÂë¹¥»÷¡£¡£¡£


¡¾·ì϶¹«¸æ¡¿²©Í¨Wi-FiÇý¶¯´æÔÚ¶à¸ö°²È«·ì϶


²©Í¨wlÇý¶¯ÖдæÔÚÁ½¸ö¶ÑÒç³ö·ì϶£¨CVE-2019-9501¡¢¡¢¡¢CVE-2019-9502£© £¬£¬£¬¿ªÔ´µÄbrcmfmacÇý¶¯ÖдæÔÚÊý¾ÝÖ¡ÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2019-9503£©ºÍ¶ÑÒç³ö·ì϶(CVE-2019-9500£©¡£¡£¡£Î´¾­ÊÚȨµÄ¹¥»÷Õßͨ¹ýÔ¶³Ì·¢ËͶñÒâµÄwifi°ü £¬£¬£¬ÔÚ×îÑÏÖØµÄÇé¿öÏ £¬£¬£¬Äܹ»ÔÚÊÜÓ°ÏìϵͳÖÐÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£


¡¾Ô­´´·ì϶¡¿WebSphere·ì϶£¨CVE-2019-4505£©


OG¶«·½ÌüADLab·¢ÏÖWebsphere´æÔÚËÁÒâÎļþ¶ÁÈ¡·ì϶CVE-2019-4505¡£¡£¡£Í¨¹ý¸Ã·ì϶ £¬£¬£¬¹¥»÷ÕßÄܹ»»ñÈ¡Ãô¸ÐÐÅÏ¢¶øµ¼Ö½øÒ»²½ÀûÓᣡ£¡£·ì϶Σº£º¦Ë®Æ½½Ï´ó¡£¡£¡£


ÎïÁªÍø×¨Ìâ·ÖÎö


¹¤¿ØÊ®´óÍøÂç¹¥»÷±øÆ÷·ÖÎö»ã±¨


OG¶«·½ÌüADLab¶Ô2000ÄêÖ®ºóµÄ¹¤¿ØÍøÂç¹¥»÷ÊÂÎñ½øÐÐÊáÀí £¬£¬£¬²¢É¸Ñ¡³öÊ®´ó¹¤¿ØÍøÂç¹¥»÷±øÆ÷£º£ºStuxnet¡¢¡¢¡¢Duqu¡¢¡¢¡¢Flame¡¢¡¢¡¢Havex¡¢¡¢¡¢Dragonfly2.0¡¢¡¢¡¢ BlackEnergy¡¢¡¢¡¢Industroyer¡¢¡¢¡¢GreyEnergy¡¢¡¢¡¢VPNFilterºÍTriton

£¬£¬£¬Éî¶È·ÖÎöÆä¹¥»÷²¼¾°¡¢¡¢¡¢Ö¸±ê¡¢¡¢¡¢ÊÖ·¨ÒÔ¼°¼¼Êõ¸öÐÔ £¬£¬£¬ÒÔ±ã¸÷È˶Թ¤Òµ½ÚÖÆÏµÍ³ËùÃæ¶ÔµÄ°²È«ÍþвÓÐÒ»¸ö¸üÎªÈ«ÃæµÄÒâʶ¡£¡£¡£


ºÚȸ¹¥»÷£º£ºÉî¶È·ÖÎö²¢ËÝÔ´Dofloo½©Ê¬ÎïÁªÍø±³ºóµÄ¡°ºÚȸ¡±


OG¶«·½ÌüADLab·¢ÏÖConfluenceÔ¶³Ì´úÂëÖ´Ðзì϶CVE-2019-3396±»Dofloo½©Ê¬ÍøÂç¼Ò×åÓÃÓÚ¹¥Õ¼É豸×ÊÔ´ £¬£¬£¬Dofloo½©Ê¬¼Ò×å²»½öÆðÍ·ÀûÓøßΣ·ì϶½øÐй¥»÷ £¬£¬£¬ÇÒÆä±³ºóµÄºÚ¿Í»¹ÀûÓÃÒ»ÖÖ¸ü¾ßÓ°ÏìÁ¦µÄ¡°ºÚȸ¹¥»÷¡±À´ÈëÇÖ²úÒµÁ´¡£¡£¡£±¾ÎľßÌåÂÛÊöÁ˺Úȸ¹¥»÷µÄ×îз¢ÏÖ¹ý³Ì £¬£¬£¬²¢Éî¿Ì·ÖÎöÁËDofloo½©Ê¬ÍøÂç¼Ò×åÖÐËù´æÔڵġ°ºÚȸ¾°Ïó¡±£»£»£»Í¬Ê±¶Ô°µ²ØÔÚÆä±³ºóµÄºÚȸ½øÐÐÉî¶ÈÍÚ¾òºÍ¶¨Î» £¬£¬£¬·ÖÎö¸Ã½©Ê¬ÓëMrBlack¡¢¡¢¡¢DnsAmp¡¢¡¢¡¢Flood.AÖ®¼äµÄͬԴ¸öÐÔ¡£¡£¡£


ÖÇÄÜÒôÏäÍøÂ簲ȫÓëÒþÖÔ×êÑл㱨


±¾»ã±¨Öصã·ÖÎöÁËÖÇÄÜÒôÏäÃæ¶ÔµÄ°²È«·çÏÕºÍÒþÖÔ·çÏÕ¡£¡£¡£Í¨¹ý¶ÔÖÇÄÜÒôÏäµÄ×êÑÐ £¬£¬£¬OG¶«·½ÌüADLab·¢ÏÖÁ˲úÆ·ÖдæÔÚÓÐÓ²¼þµ÷ÊÔ½Ó¿Ú·ì϶¡¢¡¢¡¢DLNA·þÎñԽȨ·ì϶¡¢¡¢¡¢·þÎñ¶Ë¿ÚԽȨ·ì϶µÈÊ®Óà¸ö°²È«·ì϶ £¬£¬£¬ÕâЩ·ì϶¿ÉÔì³ÉδÊÚȨÉ豸½ÚÖÆ¡¢¡¢¡¢ÓïÒôÇÔÌý¡¢¡¢¡¢Ãô¸ÐÐÅϢй¶µÈ¡£¡£¡£ADLabÒѵÚÒ»¹¦·òÏòCNVDºÍCNNVD½øÐÐÁË·ì϶´«µÝ £¬£¬£¬²¢ÓëICSCERT½áºÏ°ä²¼ÁË¡¶ÖÇÄÜÒôÏäÒþÖÔÓëÍøÂ簲ȫ·ÖÎö»ã±¨¡·¡£¡£¡£


VxWorks¶à¸öÔ¶³Ì·ì϶·ÖÎö


ÔÚ¹¤Òµ¡¢¡¢¡¢µçÁ¦¡¢¡¢¡¢ÄÜÔ´ £¬£¬£¬º½¿Õº½ÌìµÈÐÐÒµ¹Ø¼ü»ù´¡ÉèÊ©ÖÐ¿í·ºÊ¹ÓõÄVxWorks±»·¢ÏÖ´æÔÚ11¸ö0day·ì϶±»³ÆÎªURGENT/11 £¬£¬£¬ÆäÖÐ6¸ö·ì϶ΪÑÏÖØ·ì϶²¢Äܹ»Ô¶³ÌÖ´ÐдúÂ루RCE£© £¬£¬£¬ÆäÓà5¸ö·ì϶Ô̺¬»Ø¾ø·þÎñ¡¢¡¢¡¢ÐÅϢй¶ºÍÂß¼­È±µã·ì϶¡£¡£¡£ÕâЩ·ì϶¿ÉÄÜʹ¹¥»÷ÕßÔ¶³ÌÊÕÊÜÉ豸 £¬£¬£¬¶øÎÞÐè½»»¥ £¬£¬£¬ÉõÖÁÄܹ»Èƹý·À»ðǽµÈÖܱ߰²È«É豸 £¬£¬£¬ÕâÒâζ×ÅËüÃÇ¿ÉÓÃÓÚ½«¶ñÒâÈí¼þ´«²¼µ½ÍøÂçÄÚ²¿ £¬£¬£¬ÕâÖÖ¹¥»÷ÓµÓкܴóµÄDZÁ¦ £¬£¬£¬ÀàËÆÓÚWannaCry¶ñÒâÈí¼þµÄ´«²¼·½Ê½¡£¡£¡£



ºÚ¿Í¹¥»÷ÓëÍþв·ÖÎö



¡°BankThief¡±- Õë¶Ô²¨À¼ºÍ½Ý¿ËµÄÐÂÐÍÒøÐд¹µö¹¥»÷


OG¶«·½ÌüADLab·¢ÏÖÁËÒ»¿îȫеÄAndroidÒøÐд¹µöľÂí¡±BankThief¡° £¬£¬£¬¸ÃľÂí½«×ÔÉí¼Ù×°³É¡°Google Play¡±ÀûÓà £¬£¬£¬¿ÉÇÔÈ¡Êܺ¦Óû§µÄÒøÐеǼƾ֤¡£¡£¡£¹¥»÷Õß½«½ÚÖÆÖ¸Áî°µ²ØÔÚ°²È«µÄFirebaseͨѶËíµÀÖÐ £¬£¬£¬Ê¹Æä¹¥»÷ÐÐΪԽ·¢Òñ±Î¡£¡£¡£Õâ´Î¹¥»÷µÄÖ¸±êÒøÐÐĬÈÏÔ̺¬Ô̺¬»¨ÆìÒøÐÐÔÚÄÚµÄÈýÊ®¶à¼ÒÒøÐС£¡£¡£


¾¯Ì裺£ººÚ¿ÍÀûÓá°Á÷ÀëµØÇòƱ·¿ºì°ü¡±ÔÚ΢ÐÅÖд«²¼¶ñÒâÚ¿Æ­¸æ°×


OG¶«·½ÌüADLabÊÕµ½¿Í»§·´À¡£¡£¡£º£ºÔÚʹÓÃ΢ÐŵĹý³ÌÖÐÒÉËÆ³öÏÖ¡°Öж¾¡±¾°Ïó £¬£¬£¬Óû§ÔÚȺÁÄÖÐÊÕµ½¡°Î¢ÐÅÓïÒô¡± £¬£¬£¬µã¿ªºóÈ´ÌáÐÑÁìÈ¡¡°Á÷ÀëµØÇòµçӰƱ·¿ºì°ü¡±¡£¡£¡£²»Ã÷ÕæÏàµÄÓû§·×·×ÖÐÕÐ £¬£¬£¬Ôì³ÉÖî¶àȺÁÄÖгöÏÖÁË¡°ÈºÔ¼Ç롱 ¡¢¡¢¡¢¡°ÓïÒô¡±ºÍ¡°¸æ°×¡±µÈºýŪÐÔ·ÖÏíÁ´½Ó £¬£¬£¬²¢³É²¡¶¾Ê½¼±¾ç´«²¼¡£¡£¡£Á´½ÓÖ¸Ïò¡°ÀÏÖÐÒ½¡±¡¢¡¢¡¢¡°Í¶×ÊÁìµ¼¡±ºÍ¡°µÍË×С˵¡±µÈ¶ñÒâ¸æ°× £¬£¬£¬ÓÕµ¼Óû§Ôö³¤Î¢ÐÅ»ò¹Ø×¢¹«¼ÒºÅ £¬£¬£¬Ö®ºóÒ»²½²½Í¨¹ýÆ­È¡¶¨½ð»ò²ÊƱˢµ¥µÈ¼¿Á©Ú¿Æ­Óû§²Æ¸» £¬£¬£¬ÉÔÓÐʧÉ÷¾Í»áÂäÈëȦÌס£¡£¡£


¡¾¾¯Ìè¡¿¡°ÏÀµÁ¡±ÀÕË÷²¡¶¾V5.3бäÖÖÈ«Ãæ·Ö½â


2019Äê4Ô £¬£¬£¬OG¶«·½ÌüADLab²¶»ñµ½ÁË¡°ÏÀµÁ¡±²¡¶¾×îбäÖÖ £¬£¬£¬¸Ã²¡¶¾µÄ°æ±¾ºÅΪV5.3 £¬£¬£¬±àÒ빦·òΪ4ÔÂ14ÈÕ £¬£¬£¬¾àÀëÆäÉÏÒ»¸ö°æ±¾V5.2ÔÚÖйúËÁŰ½ö½öÒ»¸ö¶àÔ¡£¡£¡£×ÔÆäÓÚ2018Äê1Ôµ®ÉúÖÁ½ñÒѾ­¸üеü´úÁË5¸ö´óµÄ°æ±¾¡¢¡¢¡¢20¼¸¸öС°æ±¾¡£¡£¡£¡°ÏÀµÁ¡±ÆðÍ·ËÁŰÖйúµÄ¹¦·òΪ2019Äê3ÔÂ11ÈÕ £¬£¬£¬²¢ÒÑϰȾÁËÎÒ¹úÉÏǧ̨µ±¾Ö¡¢¡¢¡¢ÆóÒµºÍÓйؿÆÑлú¹¹µÄÍÆËã»ú¡£¡£¡£


ºÚʨÐж¯£º£ºÕë¶ÔÎ÷°àÑÀÓïµØÓòµÄ¹¥»÷»î¶¯·ÖÎö


OG¶«·½ÌüADLab¼à²âµ½Ò»ÅúÕë¶ÔÎ÷°àÑÀÓïµØÓòÈ·µ±¾Ö»ú¹¹¼°ÄÜÔ´ÆóÒµµÈ²¿Ãŵ͍Ïò¹¥»÷»î¶¯ £¬£¬£¬Í¨¹ý¶Ô¹¥»÷ÕßµÄÐÐΪºÍËùÓ÷þÎñÆ÷ÓйØÐÅÏ¢µÄ·ÖÎöºÍ×·×Ù £¬£¬£¬È·¶¨¸Ã´Î¹¥»÷ÆðÔ´ÓÚÒ»ÅúÒþÃØ¶àÄêµÄÍÁ¶úÆäºÚ¿Í×éÖ¯-KingSqlZºÚ¿Í×éÖ¯¡£¡£¡£ÆäÔø¹¥ÏÂ3ǧ¶à¸öÍøÕ¾·þÎñÆ÷ £¬£¬£¬²¢¸ßµ÷µÄÔÚ±»¹¥»÷ÍøÕ¾ÉÏÁôÏÂ×éÖ¯µÄÃû³Æ £¬£¬£¬ËæºóÒþûÁ˶àÄê¡£¡£¡£ÎÒÃÇͨ¹ý¶Ô¡±ºÚʨÐж¯¡±µÄ×·×ÙÔÙ´ÎÍÚ³ö¸ÃºÚ¿Í×éÖ¯³ÉÔ±¼°»î¶¯¼£Ïó £¬£¬£¬²¢¶Ô¹¥»÷Ö¸±êÒÔ¼°ÆäËùʹÓõĹ¥»÷±øÆ÷½øÐÐÈ«ÃæÁË·ÖÎö¡£¡£¡£


ÓÉÒ»¶ÎÉñÃØÎÄ×ÖËùÒý·¢µÄµ÷²éÓë·ÖÎö


OG¶«·½ÌüADLab¶Ô±ãÇ©ÍøÕ¾Pastebinƽ̨£¨¸Ãƽ̨ʱʱ±»ºÚ¿ÍÓÃÓÚ´æ´¢¹¥»÷³É¾Í£©ÄÚÈݽøÐÐɸѡºÍ·ÖÎö £¬£¬£¬·¢ÏÖÁËÒ»¶ÎÉñÃØ¶ø¹Å¹ÖµÄÖÐÎÄ×Ö·û¡£¡£¡£¸Ã¶ÎÎÄ×Ö±»´æ´¢ÔÚÒ»¸öÃûΪ¡°Unitled¡±µÄÓû§ÎļþÖÐ £¬£¬£¬´Ó×ÖÃæÉÏ¿´ £¬£¬£¬ÕâÊÇÒ»¶ÎûÓÐÆëÈ«ÓïÒåµÄÎÄ×Ö £¬£¬£¬¿´ÆðÀ´¾ÍÏñÃÜÓïÒ»Ñù £¬£¬£¬ËƺõÆäÖаµ²Ø×ÅһЩ²»ÎªÈËÖªµÄÐÅÏ¢¡£¡£¡£ÄÇôÕâ»áÊÇij¸öºÚ¿Í×éÖ¯»òÕßµý±¨ÈËÔ±Ö®¼äµÄ°ÂÃØ¼ÇºÅÄØ £¬£¬£¬»¹ÊÇ˵½ö½öÖ»ÊÇËæ»úÊäÈëµÄºÁÎÞÒâ˼µÄÎÄ×Ö£¿£¿£¿±¾ÎĶÔÕâÆäÖаµ²ØµÄ°ÂÃØ½øÐÐÁË·ÖÎö²é¾¿¡£¡£¡£


Õë¶ÔÖÆÒ©ÐÐÒµ¼°ÕþÆóµÄºÚ¿Í×éÖ¯×îй¥»÷»î¶¯Éî¶È·ÖÎö


OG¶«·½ÌüADLab·¢ÏÖ´óÁ¿Ê¹ÓøßΣ·ì϶CVE-2017-11882½øÐÐÍøÂç¹¥»÷µÄÊÂÎñ £¬£¬£¬Í¨¹ý¶ÈÎöÎÒÃÇ·¢Ïֺڿ͵ÄÎѵ㲢ÕÒµ½ÁËÊܺ¦ÈËÓйØÐÅÏ¢ £¬£¬£¬´ËÅúºÚ¿Í³É¹¦ÉøÈë½øÁ˵¹úºÍÓ¡¶ÈÄáÎ÷ÑǵĶà¼ÒÖÆÒ©ÆóÒµ £¬£¬£¬ÒÔ¼°Î÷°àÑÀÈ·µ±¾Ö¡¢¡¢¡¢ÆóÊÂÒµµ¥ÔªµÈ»ú¹¹ £¬£¬£¬²¢ÇÒµÁÈ¡ÁË´óÁ¿µÄÃô¸Ðµý±¨¡£¡£¡£Í¨¹ýËÝÔ´·ÖÎöÈ·¶¨Õâ´Î¹¥»÷À´×ÔÓÚÄáÈÕÀûÑÇ £¬£¬£¬²¢Óɵ±Ç°¹¥»÷¹ØÁª³öÁ˸ü¶àºÚ¶ñÒâÓòÃûºÍÑù±¾¡£¡£¡£±¾ÎĶԺڿÍ×éÖ¯ËùÖ´ÐеĹ¥»÷¹ý³Ì½øÐоßÌ嵨·ÖÎöºÍËÝÔ´ £¬£¬£¬²¢¶ÔÆäËùʹÓõļäµýÈí¼þºÍ»ù´¡ÉèÊ©½øÐÐ͸±ÙµØ·ÖÎö¡£¡£¡£


¹ØÓÚÃÅÂÞ±Ò¹©¸øÁ´¹¥»÷ÊÂÎñ·ÖÎö


2019Äê11ÔÂ19ÈÕ £¬£¬£¬ÃÅÂÞ±Ò¹Ù·½githubÉϳöÏÖ¶ÔÃÅÂÞ±Òrelease°æÓë¹ÙÍøÉϳöÏÖ²»Ò»ÖÂÎÊÌâµÄissues £¬£¬£¬ÆäÖÐÌá¼°³öÏÖÎÊÌâµÄÃÅÂޱҰ汾Ϊ×îаæ0.15.0.0¡£¡£¡£ÃÅÂÞ±Ò¹Ù·½ÈÏ¿ÉÆä¹ÙÍøÊܵ½ºÚ¿ÍÈëÇÖ £¬£¬£¬ÕâÊdzõ´Î±»·¢ÏÖÕë¶Ô¼ÓÃÜÇ®±Ò¿Í»§¶ËµÄ¹©¸øÁ´¹¥»÷¡£¡£¡£±¾ÎľßÌå·ÖÎöÁ˱»´Û¸ÄµÄmonero-wallet-cli¶ñÒâÎļþ £¬£¬£¬²¢¶ÔºÚ¿ÍµÄ»ù´¡ÉèÊ©½øÐÐ×·×Ù·ÖÎö £¬£¬£¬·¢ÏÖÁ˺ڿÍËùʹÓùýµÄÆäËû»ù´¡ÉèÊ©¡£¡£¡£


°²È«·ì϶·ÖÎö


LinuxÄÚºËCVE-2017-11176·ì϶·ÖÎöÓ븴ÏÖ


LinuxÄÚºËÖеÄPOSIX ÐÂÎŶÓÁÐʵÏÖÖдæÔÚÒ»¸öUAF·ì϶CVE-2017-11176¡£¡£¡£¹¥»÷ÕßÄܹ»ÀûÓø÷ì϶µ¼Ö»ؾø·þÎñ»òÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£±¾ÎĽ«´Ó·ì϶³ÉÒò¡¢¡¢¡¢²¹¶¡·ÖÎöÒÔ¼°·ì϶¸´Ïֵȶà¸ö½Ç¶È¶Ô¸Ã·ì϶½øÐоßÌå·ÖÎö¡£¡£¡£


ThinkPHP5Ö÷ÌâÀàRequestÔ¶³Ì´úÂë·ì϶·ÖÎö


ThinkPHPÍŶӰ䲼²¹¶¡¸üР£¬£¬£¬ÐÞ¸´ÁËÒ»´¦ÓÉÓÚ²»°²È«µÄ¶¯Ì¬º¯ÊýŲÓõ¼ÖµÄÔ¶³Ì´úÂëÖ´Ðзì϶ £¬£¬£¬¸Ã·ì϶Σº£º¦Ë®Æ½¼«¶È¸ß¡£¡£¡£OG¶«·½ÌüADLab¶ÔThinkPHP¶à¸ö°æ±¾½øÐÐÁËÔ´Âë·ÖÎöºÍÑéÖ¤ £¬£¬£¬ÊÜÓ°Ïì°æ±¾ÎªThinkPHP5.0-5.0.23ÆëÈ«°æ¡£¡£¡£


Windows DHCP ServerÔ¶³Ì´úÂëÖ´Ðзì϶·ÖÎö£¨CVE-2019-0626£©


Windows DHCP Server´æÔÚÔ¶³Ì´úÂëÖ´ÐиßΣ·ì϶CVE-2019-0626 £¬£¬£¬µ±¹¥»÷ÕßÏòDHCP·þÎñÆ÷·¢Ë;«ÐÄÉè¼ÆµÄÊý¾Ý°ü²¢³É¹¦ÀûÓÃºó £¬£¬£¬¾ÍÄܹ»ÔÚDHCP·þÎñÖÐÖ´ÐÐËÁÒâ´úÂë £¬£¬£¬·ì϶ӰÏìÁìÓò½Ï´ó¡£¡£¡£


Windows RDP·þÎñ¸ßΣ·ì϶·ÖÎö£¨CVE-2019-0708£©


Windows RDP·þÎñµÄÔ¶³Ì´úÂëÖ´ÐиßΣ·ì϶ӰÏìÁËijЩ¾É°æ±¾µÄWindowsϵͳ £¬£¬£¬ÓÉÓڸ÷ì϶ÎÞÐèÉí·ÝÑéÖ¤ÇÒÎÞÐèÓû§½»»¥ £¬£¬£¬ËùÒÔÄܹ»Í¨¹ýÍøÂçÈ䳿µÄ·½Ê½±»ÀûÓà £¬£¬£¬ÀûÓô˷ì϶µÄ¶ñÒâÈí¼þÄܹ»´Ó±»Ï°È¾µÄÍÆËã»ú´«²¼µ½ÍøÂçÖÐÆäËûÒ×Êܹ¥»÷µÄÍÆËã»ú £¬£¬£¬´«²¼·½Ê½Óë2017ÄêWannaCry¶ñÒâÈí¼þµÄ´«²¼·½Ê½ÀàËÆ¡£¡£¡£


LinuxÄÚºËSCTPºÍ̸·ì϶·ÖÎöÓ븴ÏÖ


LinuxÄÚºËSCTPºÍ̸ʵÏÖÖдæÔÚÒ»¸ö°²È«·ì϶CVE-2019-8956 £¬£¬£¬Äܹ»µ¼Ö»ؾø·þÎñ¡£¡£¡£¸Ã·ì϶´æÔÚÓÚnet/sctp/socket.cÖеÄsctp_sendmsg()º¯Êý £¬£¬£¬¸Ãº¯ÊýÔÚ´¦ÖÃSENDALL±êÖ¾²Ù×÷¹ý³Ìʱ´æÔÚuse-after-free·ì϶¡£¡£¡£


LinuxÄÚºËTCPºÍ̸¶à¸öSACKÖ°Äܻؾø·þÎñ·ì϶·ÖÎö


LinuxÄÚºËTCP/IPºÍ̸ջ´æÔÚ3¸ö°²È«·ì϶£¨CVE-2019-11477¡¢¡¢¡¢CVE-2019-11478¡¢¡¢¡¢CVE-2019-11479£© £¬£¬£¬ÕâЩ·ì϶Óë×î´ó·Ö¶Î´óС£¡£¡£¨MSS£©ºÍTCPÑ¡ÔñÐÔÈ·ÈÏ£¨SACK£©Ö°ÄÜÓÐ¹Ø £¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß½øÐлؾø·þÎñ¹¥»÷¡£¡£¡£


Advantech WebAccess¶à¸ö·ì϶·ÖÎö


ZDI°ä²¼¶à¸öWebAccess·ì϶ £¬£¬£¬ÆäÖÐÔ̺¬¶à¸öÄÚ´æ·ÛËé·ì϶ºÍÕ»Òç³ö·ì϶¡£¡£¡£²¿ÃÅÄÚ´æ·ÛËé·ì϶Äܹ»ÔÚÊÜÓ°ÏìµÄϵͳÖÐÖ´ÐÐËÁÒâ´úÂë £¬£¬£¬µ«ÊÇ´ó²¿ÃÅÄÚ´æ·ÛËé·ì϶ÀûÓÃǰÌá½ÏΪ¿Ì±¡¡£¡£¡£Í¬Ê± £¬£¬£¬ÓÉÓÚAdvantech WebAccessºÜ¶àÄ£¿£¿£¿é²¢Ã»ÓпªÆôASLR¡¢¡¢¡¢DEPµÈϵͳÓйذ²È«»úÖÆ £¬£¬£¬Ê¹µÃÕ»Òç³öµÈ·ì϶ÔÚÊÜÓ°ÏìµÄϵͳÖÐÈÝÒ×Ôì³É´úÂëÖ´ÐС£¡£¡£


¿ªÔ´Ñ¹Ëõ¿âlibarchive´úÂëÖ´Ðзì϶£¨CVE-2019-18408£©·ÖÎö


¹È¸è°²È«×êÑÐÔ±·¢ÏÖlibarchive¿âÖдæÔÚ·ì϶CVE-2019-18408¡£¡£¡£¹¥»÷Õß¿ÉÀûÓþ«ÐÄ»ú¹ØµÄѹËõÎļþ £¬£¬£¬¶ÔÊÜÓ°ÏìÓû§Ôì³ÉѹËõ·¨Ê½»Ø¾ø·þÎñ»òÖ´ÐжñÒâ´úÂë¡£¡£¡£Õâ´Î±»ÆØ³öµÄ°²È«·ì϶¼ä½ÓÓ°Ïìµ½ÁË´óÁ¿ÏîÄ¿ºÍ²úÆ·¡£¡£¡£


Çø¿éÁ´×¨Ìâ·ÖÎö


Çø¿éÁ´ÖÇÄܺÏÔ¼½ÚÖÆÁ÷¼ø±ð´ó¹æÄ£³¢ÊÔ×êÑÐ


OG¶«·½ÌüADLab½áºÏµç×ӿƼ¼´óÑ§ÍÆËã»úѧԺ³ÂÌü½ÌÊÚ¶ÔÒÔÌ«·»Çø¿éÁ´ÖÇÄܺÏÔ¼½ÚÖÆÁ÷µÄ¼ø±ð½øÐÐÁË´ó¹æÄ£×êÑÐ £¬£¬£¬¸Ã×êÑзÖÎöÁ˵±Ç°6¸öÖ÷Á÷µÄÖÇÄܺÏÔ¼¾²Ì¬·ÖÎö¹¤¾ß £¬£¬£¬Í¨¹ý¶ÔÒÔÌ«·»Çø¿éÁ´ÉÏÒѲ¿ÊðµÄºÏÔ¼£¨½ü500Íò£©Ö´ÐÐÖ´Ðиú×ÙÀ´ÆÀ¹ÀËûÃǵľ²Ì¬½ÚÖÆÁ÷¼ø±ðÄÜÁ¦¡£¡£¡£×êÑгɾÍÒѰ䷢ÔÚCCFÍÆ¼öµÄ2019ÄêBÀàѧÊõ»áÒéÉÏ £¬£¬£¬²¢»ñµÃÁË×î¼ÑÂÛÎÄÌáÃû½±¡£¡£¡£


Ô¤·À¡°¶çÊÖ¡±ØÍÆ·£¿£¿£¿Çø¿éÁ´Á´ÉÏÁ´ÏÂÊý¾ÝЭͬ·ÖÎö


OG¶«·½ÌüADLabÒÔΪ £¬£¬£¬Çø¿éÁ´µÄϵͳµÄ¿ÉÓÃÐÔÎÊÌâÊÇÉæ¼°Ö°ÄÜʵÏÖÐÔµÄÎÊÌâ £¬£¬£¬¶øÊµÏÖÐÔÎÊÌâÐÔÖÊÊÇÆÓËØµÄ°²È«ÐÔÎÊÌâ £¬£¬£¬²¢Õë¶Ô¡°Á´ÉÏÁ´ÏÂÊý¾ÝЭͬ¼¼Êõ¡±½øÐÐÁ˳ÖÐø×êÑС£¡£¡£µ±Ç° £¬£¬£¬Á´ÉÏÁ´ÏÂÊý¾ÝЭͬ¼¼Êõ²¢²»ÃÀÂú £¬£¬£¬µ¼ÖÂÇø¿éÁ´ÎÞ·¨Ðγɱջ· £¬£¬£¬ÊÇÏÞ¶ÈÇø¿éÁ´ÀûÓó¡¾°µÄÖØÒª¹ÊÕÏ¡£¡£¡£


OG¶«·½Ìü»ý¼«·ÀÓù³¢ÊÔÊÒ£¨ADLab£©


ADLab³ÉÁ¢ÓÚ1999Äê £¬£¬£¬ÊÇÖйú°²È«ÐÐÒµ×îÔç³ÉÁ¢µÄ¹¥·À¼¼Êõ×êÑг¢ÊÔÊÒÖ®Ò» £¬£¬£¬Î¢ÈíMAPP´òËãÖ÷Ìâ³ÉÔ± £¬£¬£¬¡°ºÚȸ¹¥»÷¡±¸ÅÄîÊ×ÍÆÕß¡£¡£¡£½ØÖ¹Ä¿Ç° £¬£¬£¬ADLabÒÑͨ¹ýCVEÀۼư䲼°²È«·ì϶1000Óà¸ö £¬£¬£¬Í¨¹ý CNVD/CNNVDÀۼư䲼°²È«·ì϶600Óà¸ö £¬£¬£¬³ÖÐøÎ¬³Ö¹ú¼ÊÍøÂ簲ȫÁìÓòÒ»Á÷Ë®×¼¡£¡£¡£³¢ÊÔÊÒ×êÑз½Ïòº­¸Ç²Ù×÷ϵͳÓëÀûÓÃϵͳ°²È«×êÑС¢¡¢¡¢Òƶ¯ÖÇÄÜÖն˰²È«×êÑС¢¡¢¡¢ÎïÁªÍøÖÇÄÜÉ豸°²È«×êÑС¢¡¢¡¢Web°²È«×êÑС¢¡¢¡¢¹¤¿ØÏµÍ³°²È«×êÑС¢¡¢¡¢Ôư²È«×êÑС£¡£¡£×êÑгɾÍÀûÓÃÓÚ²úÆ·Ö÷Ìâ¼¼Êõ×êÑС¢¡¢¡¢¹ú¶ÈÖØµã¿Æ¼¼ÏîÄ¿¹¥¹Ø¡¢¡¢¡¢×¨Òµ°²È«·þÎñµÈ¡£¡£¡£