ÐÅÏ¢Çå¾²Öܱ¨-2019ÄêµÚ3ÖÜ
Ðû²¼Ê±¼ä 2019-01-21±¾ÖÜÇ徲̬ÊÆ×ÛÊö
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇ»úƱԤ¶©ÏµÍ³AmadeusÑÏÖØÎó²î£¬Ó°ÏìÈ«Çò141¼Òº½¿Õ¹«Ë¾;ÃÀOklahomaÖÝÕþ¸®·þÎñÆ÷ÒâÍâ̻¶3TBÃô¸ÐÊý¾Ý;Ó¢¹úBSIAÐû²¼»¥ÁªÇ徲ϵͳ×î¼Ñʵ¼ùÖ¸ÄÏ;VoIP·þÎñÉÌVOIPOÒâÍâй¶ÒÑÍùËÄÄêµÄ¿Í»§Êý¾Ý;ESÎļþä¯ÀÀÆ÷Á½¸öÎó²îʹµÃÁè¼Ý1ÒÚAndroidÓû§ÃæÁÙΣº¦¡£
ƾ֤ÒÔÉÏ×ÛÊö£¬±¾ÖÜÇå¾²ÍþвΪÖС£
Ö÷ÒªÇå¾²Îó²îÁбí
Brocade Network Advisor±£´æÓ²±àÂëÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ɵǼµ½JBoss Administration½çÃæ²¢×°ÖÃÆäËûJEEÓ¦ÓóÌÐò¡£
https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2018-743
2. systemd-journaldÕ»»º³åÇøÒç³öÎó²î
systemd-journaldʵÏÖ±£´æ»º³åÇøÒç³öÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó£¬Ê¹systemd-journald±ÀÀ£»òÒÔjournaldȨÏÞÖ´ÐдúÂë¡£
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16864
3. SAS Web Infrastructure Platform·´ÐòÁл¯´úÂëÖ´ÐÐÎó²î
SAS Web Infrastructure PlatformµÄ·´ÐòÁл¯Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉÖ´ÐÐí§Òâ´úÂë¡£
https://support.sas.com/kb/63/391.html
4. IDenticard PremisysÊý¾Ý¿âĬÈÏƾ֤Îó²î
IDenticard Premisys Identicard·þÎñÔÚ×°ÖÃʱʹÓÃĬÈϵÄÊý¾Ý¿âÓû§ÃûºÍÃÜÂ룬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó£¬Î´ÊÚȨ»á¼ûÊý¾Ý¿âȨÏÞ¡£
http://www.securityfocus.com/bid/106552
5. LCDS LAquis SCADAδÊÚȨ»á¼ûÎó²î
LCDS LAquis SCADAʵÏÖ±£´æÇå¾²Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó£¬ÈƹýÉí·ÝÑéÖ¤£¬»ñÈ¡Ãô¸ÐÐÅÏ¢¡£
https://ics-cert.us-cert.gov/advisories/ICSA-19-015-01
Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö

ÒÔÉ«ÁÐÇå¾²Ñо¿Ô±Noam Rotem·¢Ã÷»úƱԤ¶©ÏµÍ³Amadeus±£´æÒ»¸öÑÏÖصÄÇå¾²Îó²î£¬¿Éµ¼ÖÂÓû§ÐÅϢй¶ºÍÕË»§¸ü¸Ä¡£RotemÔÚÒÔÉ«Áк½¿Õ¹«Ë¾ELALÔ¤¶©»úƱʱ·¢Ã÷ÁËÕâÒ»ÎÊÌ⣬ÔÚÔ¤¶©º½°àºó£¬ÓοͻáÊÕµ½PNRºÅÂëºÍÓÃÓÚÉó²éÔ¤¶©ÐÅÏ¢µÄÁ´½Ó¡£Rotem·¢Ã÷ͨ¹ý½«¸ÃÁ´½ÓÉϵÄRULE_SOURCE_1_ID²ÎÊýÐÞ¸ÄΪÆäËüÈ˵ÄPNRºÅÂë¼´¿ÉÉó²éËûÈ˵ÄÔ¤¶©ÐÅÏ¢£¬¹¥»÷Õß»¹¿ÉʹÓÃÕâЩÐÅÏ¢»á¼ûELALÃÅ»§ÍøÕ¾²¢¸ü¸ÄÊܺ¦ÕßµÄÕË»§ÐÅÏ¢£¬°üÀ¨¶Ò»»Àï³Ì¡¢¸ü¸ÄÓʼþµØµãºÍµç»°ºÅÂëµÈ¡£ÓÉÓÚAmadeus¿ª·¢µÄ»úƱԤ¶©ÏµÍ³±»È«ÇòÖÁÉÙ141¼Òº½¿Õ¹«Ë¾Ê¹Ó㨰üÀ¨ÃÀ¹úÍŽẽ¿Õ¹«Ë¾¡¢µÂ¹úººÉ¯º½¿Õ¹«Ë¾ºÍ¼ÓÄô󺽿չ«Ë¾µÈ£©£¬Òò´Ë¸ÃÎó²î¿ÉÄÜÓ°ÏìÁËÊýÒÚÓο͡£ÏÖÔÚAmadeusÒѾÐÞ¸´Á˸ÃÎÊÌâ¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/01/airlines-flight-hacking.html
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/01/oklahoma-fbi-data-leak.html
3¡¢Ó¢¹úBSIAÐû²¼»¥ÁªÇ徲ϵͳ×î¼Ñʵ¼ùÖ¸ÄÏ
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/bsia-guidelines-digital-sabotage/
4¡¢VoIP·þÎñÉÌVOIPOÒâÍâй¶ÒÑÍùËÄÄêµÄ¿Í»§Êý¾Ý
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/01/voip-service-database-hacking.html
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/es-file-explorer-flaws-put-100-million-users-data-at-risk-fix-promised/
ÉùÃ÷£º±¾×ÊѶÓÉÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøάËûÃüÇ徲С×é·ÒëºÍÕûÀí