ADLab2019Ä갲ȫ×êÑлØÊ×
°ä²¼¹¦·ò 2019-12-312019Ä꣬£¬£¬OG¶«·½ÌüADLab×êÑз½ÏòÖØµãÔ̺¬Ö÷Á÷²Ù×÷ϵͳ¼°ÀûÓð²È«×êÑС¢¡¢¡¢Web°²È«×êÑС¢¡¢¡¢Òƶ¯»¥ÁªÍø°²È«×êÑС¢¡¢¡¢ÎïÁªÍø°²È«×êÑС¢¡¢¡¢¹¤¿Ø»¥ÁªÍø°²È«×êÑкÍÇø¿éÁ´°²È«×êÑУ¬£¬£¬ÆäÖв¿ÃÅ×êÑÐÎÄÕÂÒÑͨ¹ýADLab¹«¼Òƽ̨°ä²¼£¬£¬£¬Îª·½±ã¸÷È˲éÔÄÎÒÃǶÔÕûÄê°ä²¼µÄÖØÒª×êÑÐÎÄÕ½øÐÐÁËÕû¶Ù¡£¡£¡£
ÈȵãÊÂÎñ¹«¸æ
¡¾Ô´´·ì϶¡¿Adobe ColdFusion ·´ÐòÁл¯RCE·ì϶·ÖÎö
OG¶«·½ÌüADLab·¢ÏÖAdobe ColdFusionÖÐFlashGateway·þÎñ´æÔÚCritical£¨Î£»ú£©·´ÐòÁл¯·ì϶£¨CVE-2019-7091£©£¬£¬£¬ÀûÓø÷ì϶¹¥»÷Õß¿ÉÔ¶³ÌÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£
¡¾·ì϶¹«¸æ¡¿LinuxÄں˴æÔÚ±¾µØÌáȨ·ì϶£¨CVE-2019-8912£©
¡¾Ô´´·ì϶¡¿LinuxÄÚºËMarvell WI-FIоƬÇý¶¯·ì϶£¨CVE-2019-3846/CVE-2019-10126£©
¡¾Ô´´·ì϶¡¿LinuxÄÚºËMarvell WI-FIоƬÇý¶¯¶à¸öÔ¶³Ì·ì϶
Linux git´æÔÚ±¾µØÌáȨ·ì϶£¬£¬£¬Äܹ»µ¼Ö±¾µØ´úÂëִǰ½øÐÐȨÏÞÌáÉý¡£¡£¡£LinuxÄÚºËMarvell WI-FIоƬÇý¶¯´æÔÚ¶à¸öÔ¶³ÌÒç³ö·ì϶ºÍ±¾µØÒç³ö·ì϶£¬£¬£¬¿Éµ¼Ö»ؾø·þÎñ£¨ÏµÍ³±ÀÀ££©»òËÁÒâ´úÂëÖ´ÐС£¡£¡£·ì϶ӰÏìÁìÓò½Ï¹ã¡£¡£¡£
¡¾Ô´´·ì϶¡¿WebLogicËÁÒâÎļþ¶ÁÈ¡·ì϶£¨CVE-2019-2615£©
¡¾Ô´´·ì϶¡¿WebLogic Blind XXE·ì϶£¨CVE-2019-2647£©
¡¾Ô´´·ì϶¡¿WebLogic Ô¶³ÌºÅÁîÖ´Ðзì϶£¨CVE-2019-2725²¹¶¡Èƹý£©
¡¾Ô´´·ì϶¡¿WebLogic ·´ÐòÁл¯·ì϶£¨CVE-2019-2890£©
¡¾Ô´´·ì϶¡¿WebLogic Blind XXE·ì϶£¨CVE-2019-2887£©
OG¶«·½ÌüADLab·¢ÏÖWebLogic´æÔÚÉÏÊö·ì϶£¬£¬£¬¹¥»÷Õß¿ÉÔÚÒÑÖªÓû§ÃûÃÜÂëµÄÇé¿ö϶ÁÈ¡WebLogic·þÎñÆ÷ÖеÄËÁÒâÎļþ£»£»£»¿ÉÔÚδÊÚȨµÄÇé¿öÏÂʵÏÖ¶Ô´æÔÚ·ì϶µÄWebLogic×é¼þ½øÐÐÔ¶³ÌBlind XXE¹¥»÷£»£»£»¿ÉÔڵͰ汾JDKµÄ»·¾³ÖÐÈÆ¹ý²¹¶¡È±µãµ¼ÖÂËÁÒâÔ¶³ÌºÅÁîÖ´ÐУ»£»£»¿Éͨ¹ýT3ºÍ̸¶Ô´æÔÚ·ì϶µÄWebLogic×é¼þÖ´ÐÐÔ¶³ÌËÁÒâ´úÂë¹¥»÷¡£¡£¡£
¡¾·ì϶¹«¸æ¡¿²©Í¨Wi-FiÇý¶¯´æÔÚ¶à¸ö°²È«·ì϶
²©Í¨wlÇý¶¯ÖдæÔÚÁ½¸ö¶ÑÒç³ö·ì϶£¨CVE-2019-9501¡¢¡¢¡¢CVE-2019-9502£©£¬£¬£¬¿ªÔ´µÄbrcmfmacÇý¶¯ÖдæÔÚÊý¾ÝÖ¡ÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2019-9503£©ºÍ¶ÑÒç³ö·ì϶(CVE-2019-9500£©¡£¡£¡£Î´¾ÊÚȨµÄ¹¥»÷Õßͨ¹ýÔ¶³Ì·¢ËͶñÒâµÄwifi°ü£¬£¬£¬ÔÚ×îÑÏÖØµÄÇé¿öÏ£¬£¬£¬Äܹ»ÔÚÊÜÓ°ÏìϵͳÖÐÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£
¡¾Ô´´·ì϶¡¿WebSphere·ì϶£¨CVE-2019-4505£©
OG¶«·½ÌüADLab·¢ÏÖWebsphere´æÔÚËÁÒâÎļþ¶ÁÈ¡·ì϶CVE-2019-4505¡£¡£¡£Í¨¹ý¸Ã·ì϶£¬£¬£¬¹¥»÷ÕßÄܹ»»ñÈ¡Ãô¸ÐÐÅÏ¢¶øµ¼Ö½øÒ»²½ÀûÓᣡ£¡£·ì϶Σº£º¦Ë®Æ½½Ï´ó¡£¡£¡£
ÎïÁªÍø×¨Ìâ·ÖÎö
¹¤¿ØÊ®´óÍøÂç¹¥»÷±øÆ÷·ÖÎö»ã±¨
OG¶«·½ÌüADLab¶Ô2000ÄêÖ®ºóµÄ¹¤¿ØÍøÂç¹¥»÷ÊÂÎñ½øÐÐÊáÀí£¬£¬£¬²¢É¸Ñ¡³öÊ®´ó¹¤¿ØÍøÂç¹¥»÷±øÆ÷£º£ºStuxnet¡¢¡¢¡¢Duqu¡¢¡¢¡¢Flame¡¢¡¢¡¢Havex¡¢¡¢¡¢Dragonfly2.0¡¢¡¢¡¢ BlackEnergy¡¢¡¢¡¢Industroyer¡¢¡¢¡¢GreyEnergy¡¢¡¢¡¢VPNFilterºÍTriton
£¬£¬£¬Éî¶È·ÖÎöÆä¹¥»÷²¼¾°¡¢¡¢¡¢Ö¸±ê¡¢¡¢¡¢ÊÖ·¨ÒÔ¼°¼¼Êõ¸öÐÔ£¬£¬£¬ÒÔ±ã¸÷È˶Թ¤Òµ½ÚÖÆÏµÍ³ËùÃæ¶ÔµÄ°²È«ÍþвÓÐÒ»¸ö¸üÎªÈ«ÃæµÄÒâʶ¡£¡£¡£
ºÚȸ¹¥»÷£º£ºÉî¶È·ÖÎö²¢ËÝÔ´Dofloo½©Ê¬ÎïÁªÍø±³ºóµÄ¡°ºÚȸ¡±
OG¶«·½ÌüADLab·¢ÏÖConfluenceÔ¶³Ì´úÂëÖ´Ðзì϶CVE-2019-3396±»Dofloo½©Ê¬ÍøÂç¼Ò×åÓÃÓÚ¹¥Õ¼É豸×ÊÔ´£¬£¬£¬Dofloo½©Ê¬¼Ò×å²»½öÆðÍ·ÀûÓøßΣ·ì϶½øÐй¥»÷£¬£¬£¬ÇÒÆä±³ºóµÄºÚ¿Í»¹ÀûÓÃÒ»ÖÖ¸ü¾ßÓ°ÏìÁ¦µÄ¡°ºÚȸ¹¥»÷¡±À´ÈëÇÖ²úÒµÁ´¡£¡£¡£±¾ÎľßÌåÂÛÊöÁ˺Úȸ¹¥»÷µÄ×îз¢ÏÖ¹ý³Ì£¬£¬£¬²¢Éî¿Ì·ÖÎöÁËDofloo½©Ê¬ÍøÂç¼Ò×åÖÐËù´æÔڵġ°ºÚȸ¾°Ïó¡±£»£»£»Í¬Ê±¶Ô°µ²ØÔÚÆä±³ºóµÄºÚȸ½øÐÐÉî¶ÈÍÚ¾òºÍ¶¨Î»£¬£¬£¬·ÖÎö¸Ã½©Ê¬ÓëMrBlack¡¢¡¢¡¢DnsAmp¡¢¡¢¡¢Flood.AÖ®¼äµÄͬԴ¸öÐÔ¡£¡£¡£
ÖÇÄÜÒôÏäÍøÂ簲ȫÓëÒþÖÔ×êÑл㱨
±¾»ã±¨Öصã·ÖÎöÁËÖÇÄÜÒôÏäÃæ¶ÔµÄ°²È«·çÏÕºÍÒþÖÔ·çÏÕ¡£¡£¡£Í¨¹ý¶ÔÖÇÄÜÒôÏäµÄ×êÑУ¬£¬£¬OG¶«·½ÌüADLab·¢ÏÖÁ˲úÆ·ÖдæÔÚÓÐÓ²¼þµ÷ÊÔ½Ó¿Ú·ì϶¡¢¡¢¡¢DLNA·þÎñԽȨ·ì϶¡¢¡¢¡¢·þÎñ¶Ë¿ÚԽȨ·ì϶µÈÊ®Óà¸ö°²È«·ì϶£¬£¬£¬ÕâЩ·ì϶¿ÉÔì³ÉδÊÚȨÉ豸½ÚÖÆ¡¢¡¢¡¢ÓïÒôÇÔÌý¡¢¡¢¡¢Ãô¸ÐÐÅϢй¶µÈ¡£¡£¡£ADLabÒѵÚÒ»¹¦·òÏòCNVDºÍCNNVD½øÐÐÁË·ì϶´«µÝ£¬£¬£¬²¢ÓëICSCERT½áºÏ°ä²¼ÁË¡¶ÖÇÄÜÒôÏäÒþÖÔÓëÍøÂ簲ȫ·ÖÎö»ã±¨¡·¡£¡£¡£
VxWorks¶à¸öÔ¶³Ì·ì϶·ÖÎö
ÔÚ¹¤Òµ¡¢¡¢¡¢µçÁ¦¡¢¡¢¡¢ÄÜÔ´£¬£¬£¬º½¿Õº½ÌìµÈÐÐÒµ¹Ø¼ü»ù´¡ÉèÊ©ÖÐ¿í·ºÊ¹ÓõÄVxWorks±»·¢ÏÖ´æÔÚ11¸ö0day·ì϶±»³ÆÎªURGENT/11£¬£¬£¬ÆäÖÐ6¸ö·ì϶ΪÑÏÖØ·ì϶²¢Äܹ»Ô¶³ÌÖ´ÐдúÂ루RCE£©£¬£¬£¬ÆäÓà5¸ö·ì϶Ô̺¬»Ø¾ø·þÎñ¡¢¡¢¡¢ÐÅϢй¶ºÍÂ߼ȱµã·ì϶¡£¡£¡£ÕâЩ·ì϶¿ÉÄÜʹ¹¥»÷ÕßÔ¶³ÌÊÕÊÜÉ豸£¬£¬£¬¶øÎÞÐè½»»¥£¬£¬£¬ÉõÖÁÄܹ»Èƹý·À»ðǽµÈÖܱ߰²È«É豸£¬£¬£¬ÕâÒâζ×ÅËüÃÇ¿ÉÓÃÓÚ½«¶ñÒâÈí¼þ´«²¼µ½ÍøÂçÄÚ²¿£¬£¬£¬ÕâÖÖ¹¥»÷ÓµÓкܴóµÄDZÁ¦£¬£¬£¬ÀàËÆÓÚWannaCry¶ñÒâÈí¼þµÄ´«²¼·½Ê½¡£¡£¡£
ºÚ¿Í¹¥»÷ÓëÍþв·ÖÎö
¡°BankThief¡±- Õë¶Ô²¨À¼ºÍ½Ý¿ËµÄÐÂÐÍÒøÐд¹µö¹¥»÷
OG¶«·½ÌüADLab·¢ÏÖÁËÒ»¿îȫеÄAndroidÒøÐд¹µöľÂí¡±BankThief¡°£¬£¬£¬¸ÃľÂí½«×ÔÉí¼Ù×°³É¡°Google Play¡±ÀûÓ㬣¬£¬¿ÉÇÔÈ¡Êܺ¦Óû§µÄÒøÐеǼƾ֤¡£¡£¡£¹¥»÷Õß½«½ÚÖÆÖ¸Áî°µ²ØÔÚ°²È«µÄFirebaseͨѶËíµÀÖУ¬£¬£¬Ê¹Æä¹¥»÷ÐÐΪԽ·¢Òñ±Î¡£¡£¡£Õâ´Î¹¥»÷µÄÖ¸±êÒøÐÐĬÈÏÔ̺¬Ô̺¬»¨ÆìÒøÐÐÔÚÄÚµÄÈýÊ®¶à¼ÒÒøÐС£¡£¡£
¾¯Ì裺£ººÚ¿ÍÀûÓá°Á÷ÀëµØÇòƱ·¿ºì°ü¡±ÔÚ΢ÐÅÖд«²¼¶ñÒâڿƸæ°×
OG¶«·½ÌüADLabÊÕµ½¿Í»§·´À¡£¡£¡£º£ºÔÚʹÓÃ΢ÐŵĹý³ÌÖÐÒÉËÆ³öÏÖ¡°Öж¾¡±¾°Ï󣬣¬£¬Óû§ÔÚȺÁÄÖÐÊÕµ½¡°Î¢ÐÅÓïÒô¡±£¬£¬£¬µã¿ªºóÈ´ÌáÐÑÁìÈ¡¡°Á÷ÀëµØÇòµçӰƱ·¿ºì°ü¡±¡£¡£¡£²»Ã÷ÕæÏàµÄÓû§·×·×ÖÐÕУ¬£¬£¬Ôì³ÉÖî¶àȺÁÄÖгöÏÖÁË¡°ÈºÔ¼Ç롱 ¡¢¡¢¡¢¡°ÓïÒô¡±ºÍ¡°¸æ°×¡±µÈºýŪÐÔ·ÖÏíÁ´½Ó£¬£¬£¬²¢³É²¡¶¾Ê½¼±¾ç´«²¼¡£¡£¡£Á´½ÓÖ¸Ïò¡°ÀÏÖÐÒ½¡±¡¢¡¢¡¢¡°Í¶×ÊÁìµ¼¡±ºÍ¡°µÍË×С˵¡±µÈ¶ñÒâ¸æ°×£¬£¬£¬ÓÕµ¼Óû§Ôö³¤Î¢ÐÅ»ò¹Ø×¢¹«¼ÒºÅ£¬£¬£¬Ö®ºóÒ»²½²½Í¨¹ýÆÈ¡¶¨½ð»ò²ÊƱˢµ¥µÈ¼¿Á©Ú¿ÆÓû§²Æ¸»£¬£¬£¬ÉÔÓÐʧÉ÷¾Í»áÂäÈëȦÌס£¡£¡£
¡¾¾¯Ìè¡¿¡°ÏÀµÁ¡±ÀÕË÷²¡¶¾V5.3бäÖÖÈ«Ãæ·Ö½â
2019Äê4Ô£¬£¬£¬OG¶«·½ÌüADLab²¶»ñµ½ÁË¡°ÏÀµÁ¡±²¡¶¾×îбäÖÖ£¬£¬£¬¸Ã²¡¶¾µÄ°æ±¾ºÅΪV5.3£¬£¬£¬±àÒ빦·òΪ4ÔÂ14ÈÕ£¬£¬£¬¾àÀëÆäÉÏÒ»¸ö°æ±¾V5.2ÔÚÖйúËÁŰ½ö½öÒ»¸ö¶àÔ¡£¡£¡£×ÔÆäÓÚ2018Äê1Ôµ®ÉúÖÁ½ñÒѾ¸üеü´úÁË5¸ö´óµÄ°æ±¾¡¢¡¢¡¢20¼¸¸öС°æ±¾¡£¡£¡£¡°ÏÀµÁ¡±ÆðÍ·ËÁŰÖйúµÄ¹¦·òΪ2019Äê3ÔÂ11ÈÕ£¬£¬£¬²¢ÒÑϰȾÁËÎÒ¹úÉÏǧ̨µ±¾Ö¡¢¡¢¡¢ÆóÒµºÍÓйؿÆÑлú¹¹µÄÍÆËã»ú¡£¡£¡£
ºÚʨÐж¯£º£ºÕë¶ÔÎ÷°àÑÀÓïµØÓòµÄ¹¥»÷»î¶¯·ÖÎö
OG¶«·½ÌüADLab¼à²âµ½Ò»ÅúÕë¶ÔÎ÷°àÑÀÓïµØÓòÈ·µ±¾Ö»ú¹¹¼°ÄÜÔ´ÆóÒµµÈ²¿Ãŵ͍Ïò¹¥»÷»î¶¯£¬£¬£¬Í¨¹ý¶Ô¹¥»÷ÕßµÄÐÐΪºÍËùÓ÷þÎñÆ÷ÓйØÐÅÏ¢µÄ·ÖÎöºÍ×·×Ù£¬£¬£¬È·¶¨¸Ã´Î¹¥»÷ÆðÔ´ÓÚÒ»ÅúÒþÃØ¶àÄêµÄÍÁ¶úÆäºÚ¿Í×éÖ¯-KingSqlZºÚ¿Í×éÖ¯¡£¡£¡£ÆäÔø¹¥ÏÂ3ǧ¶à¸öÍøÕ¾·þÎñÆ÷£¬£¬£¬²¢¸ßµ÷µÄÔÚ±»¹¥»÷ÍøÕ¾ÉÏÁôÏÂ×éÖ¯µÄÃû³Æ£¬£¬£¬ËæºóÒþûÁ˶àÄê¡£¡£¡£ÎÒÃÇͨ¹ý¶Ô¡±ºÚʨÐж¯¡±µÄ×·×ÙÔÙ´ÎÍÚ³ö¸ÃºÚ¿Í×éÖ¯³ÉÔ±¼°»î¶¯¼£Ï󣬣¬£¬²¢¶Ô¹¥»÷Ö¸±êÒÔ¼°ÆäËùʹÓõĹ¥»÷±øÆ÷½øÐÐÈ«ÃæÁË·ÖÎö¡£¡£¡£
ÓÉÒ»¶ÎÉñÃØÎÄ×ÖËùÒý·¢µÄµ÷²éÓë·ÖÎö
OG¶«·½ÌüADLab¶Ô±ãÇ©ÍøÕ¾Pastebinƽ̨£¨¸Ãƽ̨ʱʱ±»ºÚ¿ÍÓÃÓÚ´æ´¢¹¥»÷³É¾Í£©ÄÚÈݽøÐÐɸѡºÍ·ÖÎö£¬£¬£¬·¢ÏÖÁËÒ»¶ÎÉñÃØ¶ø¹Å¹ÖµÄÖÐÎÄ×Ö·û¡£¡£¡£¸Ã¶ÎÎÄ×Ö±»´æ´¢ÔÚÒ»¸öÃûΪ¡°Unitled¡±µÄÓû§ÎļþÖУ¬£¬£¬´Ó×ÖÃæÉÏ¿´£¬£¬£¬ÕâÊÇÒ»¶ÎûÓÐÆëÈ«ÓïÒåµÄÎÄ×Ö£¬£¬£¬¿´ÆðÀ´¾ÍÏñÃÜÓïÒ»Ñù£¬£¬£¬ËƺõÆäÖаµ²Ø×ÅһЩ²»ÎªÈËÖªµÄÐÅÏ¢¡£¡£¡£ÄÇôÕâ»áÊÇij¸öºÚ¿Í×éÖ¯»òÕßµý±¨ÈËÔ±Ö®¼äµÄ°ÂÃØ¼ÇºÅÄØ£¬£¬£¬»¹ÊÇ˵½ö½öÖ»ÊÇËæ»úÊäÈëµÄºÁÎÞÒâ˼µÄÎÄ×Ö£¿£¿£¿±¾ÎĶÔÕâÆäÖаµ²ØµÄ°ÂÃØ½øÐÐÁË·ÖÎö²é¾¿¡£¡£¡£
Õë¶ÔÖÆÒ©ÐÐÒµ¼°ÕþÆóµÄºÚ¿Í×éÖ¯×îй¥»÷»î¶¯Éî¶È·ÖÎö
OG¶«·½ÌüADLab·¢ÏÖ´óÁ¿Ê¹ÓøßΣ·ì϶CVE-2017-11882½øÐÐÍøÂç¹¥»÷µÄÊÂÎñ£¬£¬£¬Í¨¹ý¶ÈÎöÎÒÃÇ·¢Ïֺڿ͵ÄÎѵ㲢ÕÒµ½ÁËÊܺ¦ÈËÓйØÐÅÏ¢£¬£¬£¬´ËÅúºÚ¿Í³É¹¦ÉøÈë½øÁ˵¹úºÍÓ¡¶ÈÄáÎ÷ÑǵĶà¼ÒÖÆÒ©ÆóÒµ£¬£¬£¬ÒÔ¼°Î÷°àÑÀÈ·µ±¾Ö¡¢¡¢¡¢ÆóÊÂÒµµ¥ÔªµÈ»ú¹¹£¬£¬£¬²¢ÇÒµÁÈ¡ÁË´óÁ¿µÄÃô¸Ðµý±¨¡£¡£¡£Í¨¹ýËÝÔ´·ÖÎöÈ·¶¨Õâ´Î¹¥»÷À´×ÔÓÚÄáÈÕÀûÑÇ£¬£¬£¬²¢Óɵ±Ç°¹¥»÷¹ØÁª³öÁ˸ü¶àºÚ¶ñÒâÓòÃûºÍÑù±¾¡£¡£¡£±¾ÎĶԺڿÍ×éÖ¯ËùÖ´ÐеĹ¥»÷¹ý³Ì½øÐоßÌ嵨·ÖÎöºÍËÝÔ´£¬£¬£¬²¢¶ÔÆäËùʹÓõļäµýÈí¼þºÍ»ù´¡ÉèÊ©½øÐÐ͸±ÙµØ·ÖÎö¡£¡£¡£
¹ØÓÚÃÅÂÞ±Ò¹©¸øÁ´¹¥»÷ÊÂÎñ·ÖÎö
2019Äê11ÔÂ19ÈÕ£¬£¬£¬ÃÅÂÞ±Ò¹Ù·½githubÉϳöÏÖ¶ÔÃÅÂÞ±Òrelease°æÓë¹ÙÍøÉϳöÏÖ²»Ò»ÖÂÎÊÌâµÄissues£¬£¬£¬ÆäÖÐÌá¼°³öÏÖÎÊÌâµÄÃÅÂޱҰ汾Ϊ×îаæ0.15.0.0¡£¡£¡£ÃÅÂÞ±Ò¹Ù·½ÈÏ¿ÉÆä¹ÙÍøÊܵ½ºÚ¿ÍÈëÇÖ£¬£¬£¬ÕâÊdzõ´Î±»·¢ÏÖÕë¶Ô¼ÓÃÜÇ®±Ò¿Í»§¶ËµÄ¹©¸øÁ´¹¥»÷¡£¡£¡£±¾ÎľßÌå·ÖÎöÁ˱»´Û¸ÄµÄmonero-wallet-cli¶ñÒâÎļþ£¬£¬£¬²¢¶ÔºÚ¿ÍµÄ»ù´¡ÉèÊ©½øÐÐ×·×Ù·ÖÎö£¬£¬£¬·¢ÏÖÁ˺ڿÍËùʹÓùýµÄÆäËû»ù´¡ÉèÊ©¡£¡£¡£
°²È«·ì϶·ÖÎö
LinuxÄÚºËCVE-2017-11176·ì϶·ÖÎöÓ븴ÏÖ
LinuxÄÚºËÖеÄPOSIX ÐÂÎŶÓÁÐʵÏÖÖдæÔÚÒ»¸öUAF·ì϶CVE-2017-11176¡£¡£¡£¹¥»÷ÕßÄܹ»ÀûÓø÷ì϶µ¼Ö»ؾø·þÎñ»òÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£±¾ÎĽ«´Ó·ì϶³ÉÒò¡¢¡¢¡¢²¹¶¡·ÖÎöÒÔ¼°·ì϶¸´Ïֵȶà¸ö½Ç¶È¶Ô¸Ã·ì϶½øÐоßÌå·ÖÎö¡£¡£¡£
ThinkPHP5Ö÷ÌâÀàRequestÔ¶³Ì´úÂë·ì϶·ÖÎö
ThinkPHPÍŶӰ䲼²¹¶¡¸üУ¬£¬£¬ÐÞ¸´ÁËÒ»´¦ÓÉÓÚ²»°²È«µÄ¶¯Ì¬º¯ÊýŲÓõ¼ÖµÄÔ¶³Ì´úÂëÖ´Ðзì϶£¬£¬£¬¸Ã·ì϶Σº£º¦Ë®Æ½¼«¶È¸ß¡£¡£¡£OG¶«·½ÌüADLab¶ÔThinkPHP¶à¸ö°æ±¾½øÐÐÁËÔ´Âë·ÖÎöºÍÑéÖ¤£¬£¬£¬ÊÜÓ°Ïì°æ±¾ÎªThinkPHP5.0-5.0.23ÆëÈ«°æ¡£¡£¡£
Windows DHCP ServerÔ¶³Ì´úÂëÖ´Ðзì϶·ÖÎö£¨CVE-2019-0626£©
Windows DHCP Server´æÔÚÔ¶³Ì´úÂëÖ´ÐиßΣ·ì϶CVE-2019-0626£¬£¬£¬µ±¹¥»÷ÕßÏòDHCP·þÎñÆ÷·¢Ë;«ÐÄÉè¼ÆµÄÊý¾Ý°ü²¢³É¹¦ÀûÓú󣬣¬£¬¾ÍÄܹ»ÔÚDHCP·þÎñÖÐÖ´ÐÐËÁÒâ´úÂ룬£¬£¬·ì϶ӰÏìÁìÓò½Ï´ó¡£¡£¡£
Windows RDP·þÎñ¸ßΣ·ì϶·ÖÎö£¨CVE-2019-0708£©
Windows RDP·þÎñµÄÔ¶³Ì´úÂëÖ´ÐиßΣ·ì϶ӰÏìÁËijЩ¾É°æ±¾µÄWindowsϵͳ£¬£¬£¬ÓÉÓڸ÷ì϶ÎÞÐèÉí·ÝÑéÖ¤ÇÒÎÞÐèÓû§½»»¥£¬£¬£¬ËùÒÔÄܹ»Í¨¹ýÍøÂçÈ䳿µÄ·½Ê½±»ÀûÓ㬣¬£¬ÀûÓô˷ì϶µÄ¶ñÒâÈí¼þÄܹ»´Ó±»Ï°È¾µÄÍÆËã»ú´«²¼µ½ÍøÂçÖÐÆäËûÒ×Êܹ¥»÷µÄÍÆËã»ú£¬£¬£¬´«²¼·½Ê½Óë2017ÄêWannaCry¶ñÒâÈí¼þµÄ´«²¼·½Ê½ÀàËÆ¡£¡£¡£
LinuxÄÚºËSCTPºÍ̸·ì϶·ÖÎöÓ븴ÏÖ
LinuxÄÚºËSCTPºÍ̸ʵÏÖÖдæÔÚÒ»¸ö°²È«·ì϶CVE-2019-8956£¬£¬£¬Äܹ»µ¼Ö»ؾø·þÎñ¡£¡£¡£¸Ã·ì϶´æÔÚÓÚnet/sctp/socket.cÖеÄsctp_sendmsg()º¯Êý£¬£¬£¬¸Ãº¯ÊýÔÚ´¦ÖÃSENDALL±êÖ¾²Ù×÷¹ý³Ìʱ´æÔÚuse-after-free·ì϶¡£¡£¡£
LinuxÄÚºËTCPºÍ̸¶à¸öSACKÖ°Äܻؾø·þÎñ·ì϶·ÖÎö
LinuxÄÚºËTCP/IPºÍ̸ջ´æÔÚ3¸ö°²È«·ì϶£¨CVE-2019-11477¡¢¡¢¡¢CVE-2019-11478¡¢¡¢¡¢CVE-2019-11479£©£¬£¬£¬ÕâЩ·ì϶Óë×î´ó·Ö¶Î´óС£¡£¡£¨MSS£©ºÍTCPÑ¡ÔñÐÔÈ·ÈÏ£¨SACK£©Ö°ÄÜÓйأ¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß½øÐлؾø·þÎñ¹¥»÷¡£¡£¡£
Advantech WebAccess¶à¸ö·ì϶·ÖÎö
ZDI°ä²¼¶à¸öWebAccess·ì϶£¬£¬£¬ÆäÖÐÔ̺¬¶à¸öÄÚ´æ·ÛËé·ì϶ºÍÕ»Òç³ö·ì϶¡£¡£¡£²¿ÃÅÄÚ´æ·ÛËé·ì϶Äܹ»ÔÚÊÜÓ°ÏìµÄϵͳÖÐÖ´ÐÐËÁÒâ´úÂ룬£¬£¬µ«ÊÇ´ó²¿ÃÅÄÚ´æ·ÛËé·ì϶ÀûÓÃǰÌá½ÏΪ¿Ì±¡¡£¡£¡£Í¬Ê±£¬£¬£¬ÓÉÓÚAdvantech WebAccessºÜ¶àÄ£¿£¿£¿é²¢Ã»ÓпªÆôASLR¡¢¡¢¡¢DEPµÈϵͳÓйذ²È«»úÖÆ£¬£¬£¬Ê¹µÃÕ»Òç³öµÈ·ì϶ÔÚÊÜÓ°ÏìµÄϵͳÖÐÈÝÒ×Ôì³É´úÂëÖ´ÐС£¡£¡£
¿ªÔ´Ñ¹Ëõ¿âlibarchive´úÂëÖ´Ðзì϶£¨CVE-2019-18408£©·ÖÎö
¹È¸è°²È«×êÑÐÔ±·¢ÏÖlibarchive¿âÖдæÔÚ·ì϶CVE-2019-18408¡£¡£¡£¹¥»÷Õß¿ÉÀûÓþ«ÐÄ»ú¹ØµÄѹËõÎļþ£¬£¬£¬¶ÔÊÜÓ°ÏìÓû§Ôì³ÉѹËõ·¨Ê½»Ø¾ø·þÎñ»òÖ´ÐжñÒâ´úÂë¡£¡£¡£Õâ´Î±»ÆØ³öµÄ°²È«·ì϶¼ä½ÓÓ°Ïìµ½ÁË´óÁ¿ÏîÄ¿ºÍ²úÆ·¡£¡£¡£
Çø¿éÁ´×¨Ìâ·ÖÎö
Çø¿éÁ´ÖÇÄܺÏÔ¼½ÚÖÆÁ÷¼ø±ð´ó¹æÄ£³¢ÊÔ×êÑÐ
OG¶«·½ÌüADLab½áºÏµç×ӿƼ¼´óÑ§ÍÆËã»úѧԺ³ÂÌü½ÌÊÚ¶ÔÒÔÌ«·»Çø¿éÁ´ÖÇÄܺÏÔ¼½ÚÖÆÁ÷µÄ¼ø±ð½øÐÐÁË´ó¹æÄ£×êÑУ¬£¬£¬¸Ã×êÑзÖÎöÁ˵±Ç°6¸öÖ÷Á÷µÄÖÇÄܺÏÔ¼¾²Ì¬·ÖÎö¹¤¾ß£¬£¬£¬Í¨¹ý¶ÔÒÔÌ«·»Çø¿éÁ´ÉÏÒѲ¿ÊðµÄºÏÔ¼£¨½ü500Íò£©Ö´ÐÐÖ´Ðиú×ÙÀ´ÆÀ¹ÀËûÃǵľ²Ì¬½ÚÖÆÁ÷¼ø±ðÄÜÁ¦¡£¡£¡£×êÑгɾÍÒѰ䷢ÔÚCCFÍÆ¼öµÄ2019ÄêBÀàѧÊõ»áÒéÉÏ£¬£¬£¬²¢»ñµÃÁË×î¼ÑÂÛÎÄÌáÃû½±¡£¡£¡£
Ô¤·À¡°¶çÊÖ¡±ØÍÆ·£¿£¿£¿Çø¿éÁ´Á´ÉÏÁ´ÏÂÊý¾ÝÐͬ·ÖÎö
OG¶«·½ÌüADLabÒÔΪ£¬£¬£¬Çø¿éÁ´µÄϵͳµÄ¿ÉÓÃÐÔÎÊÌâÊÇÉæ¼°Ö°ÄÜʵÏÖÐÔµÄÎÊÌ⣬£¬£¬¶øÊµÏÖÐÔÎÊÌâÐÔÖÊÊÇÆÓËØµÄ°²È«ÐÔÎÊÌ⣬£¬£¬²¢Õë¶Ô¡°Á´ÉÏÁ´ÏÂÊý¾ÝÐͬ¼¼Êõ¡±½øÐÐÁ˳ÖÐø×êÑС£¡£¡£µ±Ç°£¬£¬£¬Á´ÉÏÁ´ÏÂÊý¾ÝÐͬ¼¼Êõ²¢²»ÃÀÂú£¬£¬£¬µ¼ÖÂÇø¿éÁ´ÎÞ·¨Ðγɱջ·£¬£¬£¬ÊÇÏÞ¶ÈÇø¿éÁ´ÀûÓó¡¾°µÄÖØÒª¹ÊÕÏ¡£¡£¡£
OG¶«·½Ìü»ý¼«·ÀÓù³¢ÊÔÊÒ£¨ADLab£©
ADLab³ÉÁ¢ÓÚ1999Ä꣬£¬£¬ÊÇÖйú°²È«ÐÐÒµ×îÔç³ÉÁ¢µÄ¹¥·À¼¼Êõ×êÑг¢ÊÔÊÒÖ®Ò»£¬£¬£¬Î¢ÈíMAPP´òËãÖ÷Ìâ³ÉÔ±£¬£¬£¬¡°ºÚȸ¹¥»÷¡±¸ÅÄîÊ×ÍÆÕß¡£¡£¡£½ØÖ¹Ä¿Ç°£¬£¬£¬ADLabÒÑͨ¹ýCVEÀۼư䲼°²È«·ì϶1000Óà¸ö£¬£¬£¬Í¨¹ý CNVD/CNNVDÀۼư䲼°²È«·ì϶600Óà¸ö£¬£¬£¬³ÖÐøÎ¬³Ö¹ú¼ÊÍøÂ簲ȫÁìÓòÒ»Á÷Ë®×¼¡£¡£¡£³¢ÊÔÊÒ×êÑз½Ïòº¸Ç²Ù×÷ϵͳÓëÀûÓÃϵͳ°²È«×êÑС¢¡¢¡¢Òƶ¯ÖÇÄÜÖն˰²È«×êÑС¢¡¢¡¢ÎïÁªÍøÖÇÄÜÉ豸°²È«×êÑС¢¡¢¡¢Web°²È«×êÑС¢¡¢¡¢¹¤¿ØÏµÍ³°²È«×êÑС¢¡¢¡¢Ôư²È«×êÑС£¡£¡£×êÑгɾÍÀûÓÃÓÚ²úÆ·Ö÷Ìâ¼¼Êõ×êÑС¢¡¢¡¢¹ú¶ÈÖØµã¿Æ¼¼ÏîÄ¿¹¥¹Ø¡¢¡¢¡¢×¨Òµ°²È«·þÎñµÈ¡£¡£¡£


¾©¹«Íø°²±¸11010802024551ºÅ