ÐÅÏ¢Çå¾²Öܱ¨-2019ÄêµÚ19ÖÜ

Ðû²¼Ê±¼ä 2019-05-13

±¾ÖÜÇ徲̬ÊÆ×ÛÊö



2019Äê5ÔÂ6ÈÕÖÁ12ÈÕ¹²ÊÕ¼Çå¾²Îó²î44¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇAlpine Linux Docker CVE-2019-5021Ó²±àÂëƾ֤ÑéÖ¤ÈƹýÎó²î £»NGINX njs¶Ñ»º³åÇøÒç³öÎó²î; Hisilicon HI3516 hisilicon streaming server CVE-2019-11560»º³åÇøÒç³öÎó²î £»Android libpacÀàÐÍ»ìÏý´úÂëÖ´ÐÐÎó²î £»CyberArk Software Enterprise Password Vault XXE×¢ÈëÎó²î¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇÃÀ¹úÄÜÔ´²¿Ðû²¼2019ÄêQ1µçÁ¦ÍøÂç½ôÆÈÇéÐκÍ×ÌÈű¨¸æ £»Watertown Daily TimesÔâµ½ÀÕË÷Èí¼þRyuk¹¥»÷ £»AIHS¹«Ë¾²¿·Ö»¼Õß¼°¹©Ó¦É̵ÄÃô¸ÐÐÅϢй¶ £»VerizonÐû²¼2019ÄêÊý¾Ýй¶ÊӲ챨¸æ £»Freedom MobileÒâÍâй¶½ü500ÍòÌõÓû§¼Í¼¡£


ƾ֤ÒÔÉÏ×ÛÊö£¬±¾ÖÜÇå¾²ÍþвΪÖС£


Ö÷ÒªÇå¾²Îó²îÁбí



1. Alpine Linux Docker CVE-2019-5021Ó²±àÂëƾ֤ÑéÖ¤ÈƹýÎó²î
Alpine Linux Docker±£´æµÄrootÃÜÂëΪNULL£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó£¬Î´ÊÚȨÌáȨ»á¼û¡£
https://www.alpinelinux.org/posts/Docker-image-vulnerability-CVE-2019-5021.html

2. NGINX njs¶Ñ»º³åÇøÒç³öÎó²î
NGINX njs Array.prototype.push±£´æ¶ÑÒç³öÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉʹӦÓóÌÐò±ÀÀ £»òÖ´ÐÐí§Òâ´úÂë¡£
https://github.com/nginx/njs/commit/b0f23dbc4d4713f65470272768ef79b7cb47db78

3. Hisilicon HI3516 hisilicon streaming server CVE-2019-11560»º³åÇøÒç³öÎó²î
Hisilicon HI3516 hisilicon streaming server±£´æ»º³åÇøÒç³öÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉʹӦÓóÌÐò±ÀÀ £»òÖ´ÐÐí§Òâ´úÂë¡£
https://gist.github.com/vulnfan1337/e95c2dba75ad93a1a325c6ace950eba9

4. Android libpacÀàÐÍ»ìÏý´úÂëÖ´ÐÐÎó²î
Android libpac±£´æÀàÐÍ»ìÏýÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄPACÎļþÇëÇ󣬿Éʹϵͳ±ÀÀ £»òÖ´ÐÐí§Òâ´úÂë¡£
https://source.android.com/security/bulletin/2019-05-01

5. CyberArk Software Enterprise Password Vault XXE×¢ÈëÎó²î
CyberArk Software Enterprise Password Vault Password Vault Web Access (PVWA) ±£´æXMLÍⲿʵÌå×¢ÈëÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ɻñÈ¡Ãô¸ÐÐÅÏ¢£¬»òÈƹýÑéÖ¤¡£
https://www.octority.com/2019/05/07/cyberark-enterprise-password-vault-xml-external-entity-xxe-injection/


 Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö



1¡¢ÃÀ¹úÄÜÔ´²¿Ðû²¼2019ÄêQ1µçÁ¦ÍøÂç½ôÆÈÇéÐκÍ×ÌÈű¨¸æ

ÓÅ·¢¹ú¼Ê¡¤ËæÓŶø¶¯Ò»´¥¼´·¢

ƾ֤ÃÀ¹úÄÜÔ´²¿Ðû²¼µÄ2019ÄêµÚÒ»¼¾¶ÈµçÁ¦ÍøÂç½ôÆÈÇéÐκÍ×ÌÈű¨¸æ£¬3ÔÂ5ÈÕÉÏÎç9:12µ½ÏÂÖç6:57ʱ´ú±±ÃÀµçÍøÔâÓöµ½Ò»¸ö¡°µ¼ÖµçÁ¦ÏµÍ³ÔËÓªÖÐÖ¹µÄÍøÂçÊÂÎñ¡±£¬ÊÜÓ°ÏìµÄµØÇø°üÀ¨¼ÓÖݵĿ˶÷ÏغÍÂåɼí¶ÏØ¡¢ÓÌËûÖݵÄÑκþÏغͻ³¶íÃ÷ÖݵĿµ¸¥Ë¹ÏØ¡£Æ¾Ö¤ÃÀ¹úÄÜÔ´²¿µÄ½ç˵£¬¡°ÍøÂçÊÂÎñ¡±ÊÇÖ¸¡°Î´ÊÚȨ»á¼û¡±µ¼ÖµÄÍøÂçÖÐÖ¹£¬µ«Ã»Óиü¶àÐÅÏ¢Åú×¢¸ÃÊÂÎñÊÇÔ¶³ÌºÚ¿Í¹¥»÷ÕÕ¾ÉÆóÒµÄÚ²¿µÄ¹¥»÷¡£´ÓÀúÊ·ÉÏ¿´£¬±±ÃÀµçÍø´ÓδÔâµ½ÍøÂç¹¥»÷µ¼ÖµÄÆÆËð»òÖÐÖ¹£¬ÈôÊÇÊÂÇéÊôʵ£¬ÕâÒ»ÊÂÎñ¿ÉÄܳÉΪÀúÊ·ÐÔµÄÊÂÎñ¡£

Ô­ÎÄÁ´½Ó£º
https://blog.avast.com/western-us-power-grid-hit-by-cyber-event

2¡¢Watertown Daily TimesÔâµ½ÀÕË÷Èí¼þRyuk¹¥»÷

ÓÅ·¢¹ú¼Ê¡¤ËæÓŶø¶¯Ò»´¥¼´·¢


Ô¼º²Ñ·±¨Òµ¹«Ë¾Ôâµ½ÀÕË÷Èí¼þRyuk¹¥»÷£¬ÆäÄÚ²¿ÓÃÓÚÔÚWatertown¡¢HudsonºÍMassenaÉú²ú±¨Ö½µÄÄÚÈݹ²Ïí·þÎñÆ÷Êܵ½Ñ¬È¾£¬°üÀ¨µç×ÓÓʼþ·þÎñÆ÷ºÍÁªÍøµç»°¡£Watertown Daily TimesÔÚ4ÔÂ27ÈÕÔâµ½µÚÒ»´Î¹¥»÷£¬²¢ÔÚ5ÔÂ2ÈÕÔٴμì²âµ½Ñ¬È¾¡£ÏÖÔÚ»¹²»ÇåÎúÕâÊÇÁ½´Î¹¥»÷ÕվɵÚÒ»´Î¹¥»÷µÄÑÓÐø¡£¸Ã¹«Ë¾ÕýÔÚÓëÍøÂçÇ徲ר¼ÒÏàÖúÒÔÈ·¶¨Ñ¬È¾µÄ»ù´¡Ôµ¹ÊÔ­Óɲ¢É¾³ýÀÕË÷Èí¼þ¡£

Ô­ÎÄÁ´½Ó£º
https://cyware.com/news/watertown-daily-times-again-gets-hit-with-ryuk-ransomware-attack-36f62397

3¡¢AIHS¹«Ë¾²¿·Ö»¼Õß¼°¹©Ó¦É̵ÄÃô¸ÐÐÅϢй¶

ÓÅ·¢¹ú¼Ê¡¤ËæÓŶø¶¯Ò»´¥¼´·¢


ÃÀ¹úÓ¡¶È¿µ½¡Óë·þÎñ¹«Ë¾£¨AIHS£©±¬·¢Êý¾Ýй¶ÊÂÎñ£¬Æ¾Ö¤¸Ã¹«Ë¾Ðû²¼µÄ֪ͨ£¬Ò»ÃûÇ°¹ÍÔ±ÔÚÈÎְʱ´ú½«²¿·ÖAIHSµç×ÓÓʼþת·¢µ½ÆäСÎÒ˽¼ÒÓÊÏ䣬µ¼Ö²¿·Ö»¼Õß¡¢Ô±¹¤¼°¹©Ó¦É̵ÄÃô¸ÐÐÅϢй¶¡£ÊÜËðµÄ»¼ÕßÐÅÏ¢°üÀ¨ÐÕÃû¡¢Õ˵¥Ã÷ϸ¡¢Ò½ÁÆ°ü¹ÜÊý¾Ý¡¢½ÓÊÜAIHS·þÎñµÄÈÕÆÚ¼°Ö§¸¶½ð¶îµÈ£¬ÏÖÔÚÉв»ÇåÎúÊÇ·ñÓл¼ÕßÊý¾Ý±»ÀÄÓá£ÕâÒ»ÊÂÎñ±¬·¢ÔÚ2ÔÂ26ÈÕÖÁ3ÔÂ6ÈÕʱ´ú¡£AIHS½«ÎªÊÜÓ°ÏìµÄ»¼ÕßÌṩ12¸öÔµÄÉí·Ý͵ÇÔ± £»¤·þÎñ¡£

Ô­ÎÄÁ´½Ó£º
https://cyware.com/news/aihs-reports-data-breach-involving-information-related-to-employees-patients-and-vendors-f823c1cd

4¡¢VerizonÐû²¼2019ÄêÊý¾Ýй¶ÊӲ챨¸æ


ÓÅ·¢¹ú¼Ê¡¤ËæÓŶø¶¯Ò»´¥¼´·¢


VerizonÐû²¼2019ÄêÊý¾Ýй¶ÊӲ챨¸æ£¨DBIR£©£¬¸Ã±¨¸æÆÊÎöÁË86¸ö¹ú¼Ò±¬·¢µÄ41000¶àÆðÍøÂçÇå¾²ÊÂÎñºÍ2000¶àÆðÊý¾Ýй¶ÊÂÎñ¡£¸Ã±¨¸æÖ¸³ö£¬´Ó2018Äê×îÏÈÔÆ´æ´¢ÉèÖùýʧ¡¢BECºÍ֪ʶ²úȨ͵ÇÔ¶¼´¦ÓÚÉÏÉýÇ÷ÊÆ¡£ÒÔÉÌÒµÌع¤Ô˶¯ÎªÄîÍ·µÄÍøÂç¹¥»÷ÓÐËùÔöÌí£¬ÔÚÒÑÍùµÄ12¸öÔÂÀÓÐ1/4µÄÍøÂçÈëÇÖÓëÕì̽ºÍÊý¾ÝÉø©Óйء£×ÜÌå¶øÑÔ´ó´ó¶¼ÍøÂç¹¥»÷¶¼ÊÇÒÔ¾­¼ÃÀûÒæ×÷ΪÇý¶¯¡£²»ÐÒµÄÊÇ£¬ÓÐÒ»°ëµÄÆóÒµÐèÒªÆÆ·ÑÊýÔÂÉõÖÁ¸ü³¤µÄʱ¼äÀ´·¢Ã÷ÈëÇÖÐÐΪ¡£

Ô­ÎÄÁ´½Ó£º
https://enterprise.verizon.com/resources/reports/2019-data-breach-investigations-report.pdf

5¡¢Freedom MobileÒâÍâй¶½ü500ÍòÌõÓû§¼Í¼


ÓÅ·¢¹ú¼Ê¡¤ËæÓŶø¶¯Ò»´¥¼´·¢


¼ÓÄôóµçÐŹ«Ë¾Freedom MobileµÄÒ»¸ö°üÀ¨¿Í»§Êý¾ÝµÄElasticSearchÊý¾Ý¿âÒòÉèÖùýʧÔÚÍøÉÏ̻¶£¬µ¼Ö½ü500ÍòÌõ¿Í»§¼Í¼й¶¡£Æ¾Ö¤Çå¾²Ñо¿Ô±Noam RotemºÍRan LocarµÄ·¢Ã÷£¬¸ÃÊý¾Ý¿âÊôÓÚFreedom MobileµÄµÚÈý·½·þÎñÌṩÉÌApptium¡£¸Ã¹«Ë¾½²»°ÈËÌåÏÖ£¬Ð¹Â¶ÊÂÎñÓ°ÏìÁË3ÔÂ25ÈÕÖÁ4ÔÂ15ÈÕʱ´úÔÚ17¸öFreedom MobileÓªÒµÌü¿ªÉè»ò¸ü¸ÄÕË»§µÄÓû§£¬Ô¼ÓÐ1.5ÍòÓû§Êܵ½Ó°Ï졣鶵ÄÐÅÏ¢²»µ«°üÀ¨Óû§µÄÐÕÃû¡¢ÓÊÏäµÈСÎÒ˽¼ÒÐÅÏ¢£¬»¹°üÀ¨ÐÅÓÿ¨ºÅµÈÖ§¸¶ÐÅÏ¢¡£

Ô­ÎÄÁ´½Ó£º
https://cyware.com/news/freedom-mobile-exposed-almost-5-million-customer-records-due-to-a-misconfigured-database-fddd4855