ÐÅÏ¢Çå¾²Öܱ¨-2020ÄêµÚ36ÖÜ
Ðû²¼Ê±¼ä 2020-09-08> ±¾ÖÜÇ徲̬ÊÆ×ÛÊö
2020Äê08ÔÂ31ÈÕÖÁ09ÔÂ06ÈÕ¹²ÊÕ¼Çå¾²Îó²î56¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇGigadevice GD32F103´úÂëÖ´ÐÐÎó²î£»Gigadevice GD32F103¹Ì¼þÌáÈ¡Îó²î£»NETGEAR R8300ÏÂÁî×¢ÈëÎó²î£»Education openSIS SQL×¢ÈëÎó²î£»Education openSIS EmailCheck.php SQL×¢ÈëÎó²î¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊǹ¤ÐŲ¿×ª´ï101¿îAPPÇÖÕ¼Óû§È¨Ò棬ÇáËɳïµÈƽ̨ÉÏ°ñ£»Å²ÍþÒé»áÓʼþϵͳÔâ¹¥»÷£¬¹¤µ³ºÍÖÐÐĵ³¾ùÊÜÓ°Ï죻CiscoÖÒÑÔÆäIOS XR±£´æ0day²¢Òѱ»ÔÚҰʹÓã»Cisco Jabber±£´æÔ¶³ÌÖ´ÐдúÂëÎó²î£¬ÏÖÒѱ»ÐÞ¸´£»Ó¢ÌضûÐû²¼Î¢´úÂëÇå¾²¸üУ¬Ö÷ÒªÊÊÓÃÓÚWin10ϵÁС£
ƾ֤ÒÔÉÏ×ÛÊö£¬±¾ÖÜÇå¾²ÍþвΪÖС£
> Ö÷ÒªÇå¾²Îó²îÁбí
1.Gigadevice GD32F103´úÂëÖ´ÐÐÎó²î
Gigadevice GD32F103Çå¾²±£»¤±£´æÇå¾²Îó²î£¬ÔÊÐíÎïÀíÄÜ»á¼û¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó£¬Öض¨Ïò¿ØÖÆÁ÷Ö´ÐÐí§Òâ´úÂë¡£
https://www.usenix.org/system/files/woot20-paper-obermaier.pdf
2. Gigadevice GD32F103¹Ì¼þÌáÈ¡Îó²î
Gigadevice GD32F103ÉÁ´æ¶Á³ö±£»¤±£´æÇå¾²Îó²î£¬ÔÊÐíÎïÀíÄÜ»á¼û¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ɴӵ÷ÊÔ½Ó¿Ú»ñÈ¡¹Ì¼þ¡£
https://www.usenix.org/system/files/woot20-paper-obermaier.pdf
3.NETGEAR R8300ÏÂÁî×¢ÈëÎó²î
NETGEAR R8300±£´æÊäÈëÑéÖ¤Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£
https://kb.netgear.com/000062158/Security-Advisory-for-Pre-Authentication-Command-Injection-on-R8300-PSV-2020-0211
4. Education openSIS SQL×¢ÈëÎó²î
Open Solutions for Education openSIS±£´æSQL×¢ÈëÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄSQLÇëÇ󣬲Ù×÷Êý¾Ý¿â£¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢»òÖ´ÐÐí§Òâ´úÂë¡£
https://talosintelligence.com/vulnerability_reports/TALOS-2020-1081
5. Education openSIS EmailCheck.php SQL×¢ÈëÎó²î
Open Solutions for Education EmailCheck.php±£´æSQL×¢ÈëÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄSQLÇëÇ󣬲Ù×÷Êý¾Ý¿â£¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢»òÖ´ÐÐí§Òâ´úÂë¡£¡£
https://talosintelligence.com/vulnerability_reports/TALOS-2020-1073
> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö
1¡¢¹¤ÐŲ¿×ª´ï101¿îAPPÇÖÕ¼Óû§È¨Ò棬ÇáËɳïµÈƽ̨ÉÏ°ñ
¹¤ÒµºÍÐÅÏ¢»¯²¿¹ÙÍøÐû²¼¹ØÓÚËðº¦Óû§È¨ÒæÐÐΪµÄAPPת´ï¡£µ°¿Ç¹«Ô¢¡¢ÇáËɳ±¦±¦Ê÷ÔÐÓý¡¢ZAKERÐÂÎÅ¡¢ÍøÒ×¹ûÕæ¿Î¡¢¼Ý¿¼±¦µä¡¢Æ¯ÁÁ˵¡¢ÂìÒ϶Ì×â¡¢¿ì¼ô¼¡¢360ÕûÀí¾Þ½³¡¢µÃÎï¡¢ËѺüÊÓƵ¡¢Ó³¿ÍÖ±²¥µÈ101¿îAPP±£´æËðº¦Óû§È¨ÒæÐÐΪ¡£ÕâЩӦÓÃÈí¼þÖ÷ÒªÉæ¼°ÎÊÌâÊÇÎ¥¹æÍøÂçСÎÒ˽¼ÒÐÅÏ¢£¬ÁíÍ⻹Éæ¼°APPÇ¿ÖÆ¡¢ÆµÈÔ¡¢Ì«¹ýË÷ȡȨÏÞ£¬Ç¿ÖÆÓû§Ê¹Óö¨ÏòÍÆË͹¦Ð§£¬³¬¹æÄ£ÍøÂçСÎÒ˽¼ÒÐÅÏ¢µÈÎÊÌâ¡£
ÔÎÄÁ´½Ó£º
http://tech.cnr.cn/techgd/20200831/t20200831_525234083.shtml
2¡¢Å²ÍþÒé»áÓʼþϵͳÔâ¹¥»÷£¬¹¤µ³ºÍÖÐÐĵ³¾ùÊÜÓ°Ïì
ŲÍþÒé»á£¨Storting£©Ðû²¼ÉùÃ÷£¬ÌåÏÖÓкڿ͹¥»÷Æä³ÉÔ±µÄµç×ÓÓʼþÕÊ»§²¢ÇÔÈ¡Êý¾Ý¡£¸ÃÊÂÎñÕýÔÚÊÓ²ìÖУ¬ÏÖÔÚÉв»ÇåÎú±»µÁÊý¾ÝµÄÊýÄ¿¡¢ÖÖÀàÒÔ¼°¹¥»÷µÄÆÆËðˮƽ¡£Å²Íþ¹¤µ³µÄJarle RoheimH?konsen֤ʵ£¬¹¤µ³³ÉÔ±ºÍÕþ¿ÍÔÚÕâ´Î¹¥»÷ÖоùÊܵ½Ó°Ï죬ͬʱÖÐÐĵ³Ò²È·ÈÏÆä´ú±íºÍÔ±¹¤Êܵ½ÁËÓ°Ïì¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/hackers-breached-norwegian-parliament-emails-to-steal-data/
3¡¢CiscoÖÒÑÔÆäIOS XR±£´æ0day²¢Òѱ»ÔÚҰʹÓÃ
˼¿ÆÉÏÖÜÁùÖÒÑÔ˵£¬ÆäIOS XR±£´æÒ»¸öеÄ0day£¬ÏÖÔÚÒѱ»ºÚ¿ÍÔÚҰʹÓ᣸ÃÎó²î±»¸ú×ÙCVE-2020-3566£¬Ó°ÏìÁ˲Ù×÷ϵͳIOS XR°æ±¾¸½´øµÄ¾àÀëʸÁ¿×鲥·ÓÉÐÒé(DVMRP)¹¦Ð§£¬¸Ã°æ±¾µÄ²Ù×÷ϵͳͨ³£×°ÖÃÔÚµçÐż¶ºÍÊý¾ÝÖÐÐÄ·ÓÉÆ÷ÉÏ¡£Ë¼¿ÆÌåÏÖ£¬¸ÃÎó²îÊÇÓÉÓÚInternet×éÖÎÀíÐÒ飨IGMP£©Êý¾Ý°üµÄÐÐÁÐÖÎÀíȱ·¦ËùÖ£¬¹¥»÷Õß¿ÉÒÔͨ¹ý·¢ËÍÌØÖƵÄIGMPÁ÷Á¿À´Ê¹ÓôËÎó²î¡£ÀÖ³ÉʹÓøÃÎó²î¿Éµ¼ÖÂÄÚ´æºÄ¾¡£¬´Ó¶øµ¼ÖÂÆäËûÀú³Ì£¨ÈçÄÚ²¿ºÍÍⲿ·ÓÉÐÒ飩²»Îȹ̡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/cisco-warns-of-actively-exploited-ios-xr-zero-day/
4¡¢Cisco Jabber±£´æÔ¶³ÌÖ´ÐдúÂëÎó²î£¬ÏÖÒѱ»ÐÞ¸´
WatchcomµÄOlav Sortland Thoresen·¢Ã÷Windows°æCisco JabberÖб£´æÑÏÖصĴúÂëÖ´ÐÐÎó²î£¬ÏÖÒѱ»ÐÞ¸´¡£¸ÃÎó²î±»¸ú×ÙΪCVE-2020-3495£¬ CVSSΪ9.9·Ö£¬ÊÇÓÉÓÚ´«ÈëÐÂÎÅÄÚÈݵÄÊäÈëÑéÖ¤²»×¼È·ÒýÆðµÄ¡£¾ÓÉÉí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓöñÒâµÄ¿ÉÀ©Õ¹ÐÂÎźÍ״̬ÐÒ飨XMPP£©ÐÂÎÅʹÓøÃÎó²î£¬ÀÖ³ÉʹÓú󹥻÷Õß¿ÉÔÚÄ¿µÄϵͳÉÏÖ´ÐÐí§Òâ³ÌÐò¡£Ë¼¿Æ²úÆ·Çå¾²ÊÂÎñÏìӦС×飨PSIRT£©ÌåÏÖ£¬¸ÃÎó²îÏÖÔÚÉÐδ±»ÆÕ±éʹÓá£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/cisco-fixes-critical-code-execution-bug-in-jabber-for-windows/
5¡¢Ó¢ÌضûÐû²¼Î¢´úÂëÇå¾²¸üУ¬Ö÷ÒªÊÊÓÃÓÚWin10ϵÁÐ
MicrosoftÐû²¼ÁËIntel΢´úÂë¸üУ¬ÒÔÐÞ¸´Intel CPUÖеÄÓ²¼þÎó²î¡£´Ë´Î¸üÐÂÐû²¼Á˰˸ö¿ÉÑ¡¸üУ¬Ö÷ÒªÕë¶ÔWindows 10 2004¡¢1909¡¢1903¡¢1809¡¢1803¡¢1709¡¢1703ºÍ1607µÈ°æ±¾£¬ÐÞ¸´ÁËAmber Lake¡¢Avoton¡¢BroadwellºÍCascade LakeµÈ56¿îCPUÖÐÎó²î¡£±ðµÄ£¬Ó¢Ìضû΢Âë¸üв¢²»¿Éͨ¹ýWindows Update×°Ö㬱ØÐèÊÖ¶¯×°Öá£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/microsoft/new-intel-microcode-updates-for-windows-10-fix-cpu-hardware-bugs/