ÐÅÏ¢°²È«Öܱ¨-2020ÄêµÚ38ÖÜ

°ä²¼¹¦·ò 2020-09-21

> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2020Äê09ÔÂ14ÈÕÖÁ09ÔÂ20ÈÕ¹²ÊÕ¼°²È«·ì϶57¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇAdobe Media Encoder CVE-2020-9745Ô½½ç¶ÁÐÅϢй¶·ì϶£»£»Gallagher Group Command Centre¿Í»§¶Ë¹ÒÆð·ì϶£»£»Hyland OnBase CVE-2020-25248Ŀ¼±éÀú·ì϶£»£»IPTV/H.264/H.265ÊÓÆµ±àÂëÆ÷ºóÃÅÃÜÂëÖÎÀíÔ±½Ó¼û·ì϶£»£»Google Android Framework CVE-2020-0275ȨÏÞÌáÉý·ì϶¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇRazerÊý¾Ý¿â¶³öµ¼ÖÂÆäÔ¼10ÍòÓû§ÐÅϢй¶£»£»Redgate°ä²¼2020Äê¶ÈÊý¾Ý¿â״̬¼à²â»ã±¨£»£»Ó¢¹ú¹ú¶ÈÍøÂ簲ȫÖÐÐÄ£¨NCSC£©°ä²¼·ì϶Åû¶ָÄÏ£»£»¿¨°Í˹»ù°ä²¼2020Äê¹¤ÒµÍøÂ簲ȫµ÷²é×êÑл㱨£»£»µÂ¹ú¹ºÎïÍøÕ¾windeln.deÊý¾Ý¿â¶³ö£¬Ð¹Â¶60Òڱʼͼ¡£¡£¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖС£¡£¡£


ÖØÒª°²È«·ì϶Áбí


1.Adobe Media Encoder CVE-2020-9745Ô½½ç¶ÁÐÅϢй¶·ì϶


Adobe Media Encoder´æÔÚÔ½½ç¶Á°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ɻñÈ¡Ãô¸ÐÐÅÏ¢¡£¡£¡£

https://helpx.adobe.com/security/products/media-encoder/apsb20-57.html


2. Gallagher Group Command Centre¿Í»§¶Ë¹ÒÆð·ì϶


Gallagher Group Command Centre´´½¨Guard TourÊÂÎñ´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿Éʹ¿Í»§¶ËÁÙʱ¹ÒÆð»ò¶Ï¿ªÏνÓ¡£¡£¡£

https://security.gallagher.com/Security-Advisories/CVE-2020-16099


3.Hyland OnBase CVE-2020-25248Ŀ¼±éÀú·ì϶


Hyland OnBase´æÔÚõè¾¶±éÀú·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬ÒÔÀûÓ÷¨Ê½¸ßµÍÎĶÁȡϵͳÎļþ»òдÈëϵͳµ½Îļþ¡£¡£¡£

https://seclists.org/fulldisclosure/2020/Sep/21


4. IPTV/H.264/H.265ÊÓÆµ±àÂëÆ÷ºóÃÅÃÜÂëÖÎÀíÔ±½Ó¼û·ì϶


IPTV/H.264/H.265ÊÓÆµ±àÂëÆ÷´æÔÚºóÃÅÃÜÂë·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉδÊÚȨÆëÈ«½ÚÖÆÀûÓᣡ£¡£

https://www.kb.cert.org/vuls/id/896979


5. Google Android Framework CVE-2020-0275ȨÏÞÌáÉý·ì϶


Google Android Framework´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£

https://source.android.com/security/bulletin/android-11


> ÖØÒª°²È«ÊÂÎñ×ÛÊö


1¡¢¡¢¡¢RazerÊý¾Ý¿â¶³öµ¼ÖÂÆäÔ¼10ÍòÓû§ÐÅϢй¶


1.jpg


8ÔÂ19ÈÕ£¬×êÑÐÔ±Bob Diachenko·¢ÏÖÓÎÏ·Ó²¼þÖÆ×÷ÉÌRazerµÄÔÚÏßÉ̵êµÄÊý¾Ý¿â¶³ö£¬µ¼ÖÂÆäÔ¼10ÍòÓû§ÐÅϢй¶¡£¡£¡£Õâ´Îй¶µÄÐÅÏ¢Ô̺¬¿Í»§µÄÐÕÃû¡¢¡¢¡¢µç×ÓÓʼþµØÖ·¡¢¡¢¡¢µç»°ºÅÂë¡¢¡¢¡¢¶©µ¥ºÅ¡¢¡¢¡¢¶©µ¥Ã÷ϸÒÔ¼°Õʵ¥ºÍËÍ»õµØÖ·µÈ¡£¡£¡£RazerÓÚÔÚ9ÔÂ9ÈÕÐÞ¸´Á˸ÃÊý¾Ý¿â·þÎñÆ÷£¬²¢°µÊ¾¸ÃÊÂÎñÖв¢Ã»ÓÐÆäËûÃô¸ÐÊý¾Ýй¶£¬ÀýÈçÐÅÓþ¿¨ºÅ»òÃÜÂëµÈÐÅÏ¢¡£¡£¡£


Ô­ÎÄÁ´½Ó£º£º

https://www.bleepingcomputer.com/news/security/razer-data-leak-exposes-personal-information-of-gamers/


2¡¢¡¢¡¢Redgate°ä²¼2020Äê¶ÈÊý¾Ý¿â״̬¼à²â»ã±¨


2.jpg


Redgate×îа䲼ÁË2020Äê¶ÈÊý¾Ý¿â״̬¼à²â»ã±¨¡£¡£¡£»ã±¨ÏÔʾ£¬ÎÞÂÛÊÇÔÚѡȡÊý¾Ý¿âDevOps·½Ã棬»¹ÊÇÔÚʹÓÃ¼à¿ØÀ´¸ú×ÙÊý¾Ý¿â»úÄܺͲ¿Êð·½Ã棬½ðÈÚ·þÎñÐÐÒµµÄ²û·¢¶¼ÓÅÓÚÆäËûÐÐÒµ¡£¡£¡£ÆäÖУ¬61%µÄ½ðÈÚ·þÎñÐÐÒµÔ±¹¤Ã¿ÖܸüÐÂÖÁÉÙÒ»´ÎÊý¾Ý¿â£¬¶øÆäËûÐÐÒµÖ»ÓÐ43%µÄÔ±¹¤»áÕâÑù×ö¡£¡£¡£½ðÈÚ·þÎñµÄ·þÎñÆ÷ÊýÁ¿Ò²¸ü¶à£¬36%µÄ·þÎñÆ÷Õ¼ÓÐ50µ½500¸öʵÀý£¬¶øÆäËû²¿ÃÅÖ»ÓÐ26%¡£¡£¡£


Ô­ÎÄÁ´½Ó£º£º

https://www.helpnetsecurity.com/2020/09/14/database-monitoring-improves-devops-success/


3¡¢¡¢¡¢Ó¢¹ú¹ú¶ÈÍøÂ簲ȫÖÐÐÄ£¨NCSC£©°ä²¼·ì϶Åû¶ָÄÏ


3.jpg


Ó¢¹ú¹ú¶ÈÍøÂ簲ȫÖÐÐÄ£¨NCSC£©°ä²¼ÁË·ì϶Åû¶ָÄÏ£¬ÒÔÔ®ÊÖ¹«Ë¾Ö´Ðзì϶Åû¶Á÷³Ì»òÔÚÒѾ­³ÉÁ¢·ì϶Åû¶Á÷³ÌµÄÇé¿öÏÂ¶ÔÆä½øÐиĽø¡£¡£¡£NCSC°µÊ¾£¬¸ÃÖ¸Äϲ¢²»ÊÇÒ»¸ö·ì϶Åû¶µÄ¹æ¶¨Êֲᣬ¶øÊÇΪ¸üºÃµÄÖ´ÐÐÌṩÁ˱ØÒªµÄÐÅÏ¢¡£¡£¡£ÆäÖØÒª·ÖΪÈý¸öÖØÒª²¿ÃÅ£¬ÃèÊöÁËÈôºÎ½«Íⲿ·ì϶ÐÅÏ¢¶¨Ïò¸øÏàÒ˵ÄÈË£¬ÒÔ¼°»ã±¨Ðè×ñÑ­¹Ø±Õ·ì϶µÄ¿ò¼Ü³ß¶È¡£¡£¡£


Ô­ÎÄÁ´½Ó£º£º

https://www.bleepingcomputer.com/news/security/uk-government-releases-toolkit-to-easily-disclose-vulnerabilities/


4¡¢¡¢¡¢¿¨°Í˹»ù°ä²¼2020Äê¹¤ÒµÍøÂ簲ȫµ÷²é×êÑл㱨


4.jpg


¿¨°Í˹»ù¶ÔÒßÇéÆÚ¼äµÄ¹¤ÒµÍøÂ簲ȫÇé¿ö½øÐÐÁË×êÑУ¬²¢°ä²¼ÁË2020Äê¹¤ÒµÍøÂ簲ȫµ÷²é×êÑл㱨¡£¡£¡£»ã±¨ÏÔʾ£¬³¬¹ýÒ»°ë(53%)µÄÊÜ·ÃÕßÈϿɣ¬COVID-19µ¼Ö¸ü¶àÔ±¹¤ÔڼҰ칫£¬ÕâÒѳÉΪ¶ÔÐÅÏ¢°²È«·þÎñµÄÒ»ÖÖѹÁ¦²âÊÔ¡£¡£¡£ÓÉÓÚÍⲿÏνÓÊýÁ¿Öڶ࣬´Ë¿Ì¾ø´óÎÞÊý¹«Ë¾¶¼ÔÚ¶ÔOTÍøÂçµÄ°²È«¼¶±ð½øÐж¨ÆÚÆÀ¹À¡£¡£¡£ºÜ¶à×éÖ¯²»µÃ²»ÖØÐÂ˼¿¼ËûÃÇÄÚÍøµÄ±£»£»¤²½Ö裬ֻÓÐ7%µÄÊÜ·ÃÕß°µÊ¾£¬ËûÃǵÄÍøÂ簲ȫսÊõÔÚCOVID-19ÆÚ¼äÏ൱ÓÐЧ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º£º

https://www.kaspersky.com/blog/industrial-cybersecurity-2020/37031/


5¡¢¡¢¡¢µÂ¹ú¹ºÎïÍøÕ¾windeln.deÊý¾Ý¿â¶³ö£¬Ð¹Â¶60Òڱʼͼ


5.jpg


Safety DetectivesµÄ×êÑÐÈËÔ±ÔÚÍøÂçÉÏ·¢ÏÖÁËÒ»¸ö¶³öµÄÊý¾Ý¿â£¬¾­µ÷²é¸ÃÊý¾Ý¿âÊôÓڵ¹úÔÚÏß¹ºÎïÍøÕ¾windeln.de¡£¡£¡£Æä¶³öÁË6.4TBµÄÊý¾Ý£¬ÆäÖÐÔ̺¬60Òڱʼͼ£¬Ð¹Â¶Á˳¬¹ý700000Ãû¿Í»§µÄСÎÒÐÅÏ¢¡£¡£¡£Õâ´ÎÊÂÎñµÄй¶ÐÅÏ¢Ô̺¬Ð¡ÎÒÉí·ÝÐÅÏ¢£¨PII£©ºÍÆäËûÊý¾Ý£¬ÀýÈ緢Ʊ¡¢¡¢¡¢È«Ãû¡¢¡¢¡¢IPµØÖ·¡¢¡¢¡¢ÄÚ²¿ÈÕÖ¾¡¢¡¢¡¢µç»°ºÅÂë¡¢¡¢¡¢µç×ÓÓʼþµØÖ·¡¢¡¢¡¢¼ÒÍ¥µØÖ·¡¢¡¢¡¢É¢ÁÐÃÜÂë¡¢¡¢¡¢¸¶¿î·½Ê½ºÍÓû§µÄº¢×ÓСÎÒÐÅÏ¢µÈ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º£º

https://www.hackread.com/shopping-site-leaks-miners-data-database-mess-up/