ÐÅÏ¢Çå¾²Öܱ¨-2020ÄêµÚ38ÖÜ

Ðû²¼Ê±¼ä 2020-09-21

> ±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


2020Äê09ÔÂ14ÈÕÖÁ09ÔÂ20ÈÕ¹²ÊÕ¼Çå¾²Îó²î57¸ö £¬ÖµµÃ¹Ø×¢µÄÊÇAdobe Media Encoder CVE-2020-9745Ô½½ç¶ÁÐÅϢй¶Îó²î£»Gallagher Group Command Centre¿Í»§¶Ë¹ÒÆðÎó²î£»Hyland OnBase CVE-2020-25248Ŀ¼±éÀúÎó²î£»IPTV/H.264/H.265ÊÓÆµ±àÂëÆ÷ºóÃÅÃÜÂë¹ÜÀíÔ±»á¼ûÎó²î£»Google Android Framework CVE-2020-0275ȨÏÞÌáÉýÎó²î¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇRazerÊý¾Ý¿â̻¶µ¼ÖÂÆäÔ¼10ÍòÓû§ÐÅϢй¶£»RedgateÐû²¼2020Äê¶ÈÊý¾Ý¿â״̬¼à²â±¨¸æ£»Ó¢¹ú¹ú¼ÒÍøÂçÇå¾²ÖÐÐÄ£¨NCSC£©Ðû²¼Îó²îÅû¶ָÄÏ£»¿¨°Í˹»ùÐû²¼2020Äê¹¤ÒµÍøÂçÇå¾²ÊÓ²ìÑо¿±¨¸æ£»µÂ¹ú¹ºÎïÍøÕ¾windeln.deÊý¾Ý¿â̻¶ £¬Ð¹Â¶60ÒÚÌõ¼Í¼¡£


ƾ֤ÒÔÉÏ×ÛÊö £¬±¾ÖÜÇå¾²ÍþвΪÖС£


Ö÷ÒªÇå¾²Îó²îÁбí


1.Adobe Media Encoder CVE-2020-9745Ô½½ç¶ÁÐÅϢй¶Îó²î


Adobe Media Encoder±£´æÔ½½ç¶ÁÇå¾²Îó²î £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó £¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢¡£

https://helpx.adobe.com/security/products/media-encoder/apsb20-57.html


2. Gallagher Group Command Centre¿Í»§¶Ë¹ÒÆðÎó²î


Gallagher Group Command Centre½¨ÉèGuard TourÊÂÎñ±£´æÇå¾²Îó²î £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó £¬¿Éʹ¿Í»§¶ËÔÝʱ¹ÒÆð»ò¶Ï¿ªÅþÁ¬¡£

https://security.gallagher.com/Security-Advisories/CVE-2020-16099


3.Hyland OnBase CVE-2020-25248Ŀ¼±éÀúÎó²î


Hyland OnBase±£´æÂ·¾¶±éÀúÎó²î £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó £¬ÒÔÓ¦ÓóÌÐòÉÏÏÂÎĶÁȡϵͳÎļþ»òдÈëϵͳµ½Îļþ¡£

https://seclists.org/fulldisclosure/2020/Sep/21


4. IPTV/H.264/H.265ÊÓÆµ±àÂëÆ÷ºóÃÅÃÜÂë¹ÜÀíÔ±»á¼ûÎó²î


IPTV/H.264/H.265ÊÓÆµ±àÂëÆ÷±£´æºóÃÅÃÜÂëÎó²î £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó £¬¿ÉδÊÚȨÍêÈ«¿ØÖÆÓ¦Óá£

https://www.kb.cert.org/vuls/id/896979


5. Google Android Framework CVE-2020-0275ȨÏÞÌáÉýÎó²î


Google Android Framework±£´æÇå¾²Îó²î £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó £¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£

https://source.android.com/security/bulletin/android-11


> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢RazerÊý¾Ý¿â̻¶µ¼ÖÂÆäÔ¼10ÍòÓû§ÐÅϢй¶


1.jpg


8ÔÂ19ÈÕ £¬Ñо¿Ô±Bob Diachenko·¢Ã÷ÓÎÏ·Ó²¼þÖÆÔìÉÌRazerµÄÔÚÏßÊÐËÁµÄÊý¾Ý¿â̻¶ £¬µ¼ÖÂÆäÔ¼10ÍòÓû§ÐÅϢй¶¡£´Ë´Îй¶µÄÐÅÏ¢°üÀ¨¿Í»§µÄÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂë¡¢¶©µ¥ºÅ¡¢¶©µ¥Ã÷ϸÒÔ¼°Õʵ¥ºÍËÍ»õµØÖ·µÈ¡£RazerÓÚÔÚ9ÔÂ9ÈÕÐÞ¸´Á˸ÃÊý¾Ý¿â·þÎñÆ÷ £¬²¢ÌåÏÖ¸ÃÊÂÎñÖв¢Ã»ÓÐÆäËûÃô¸ÐÊý¾Ýй¶ £¬ÀýÈçÐÅÓÿ¨ºÅ»òÃÜÂëµÈÐÅÏ¢¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/razer-data-leak-exposes-personal-information-of-gamers/


2¡¢RedgateÐû²¼2020Äê¶ÈÊý¾Ý¿â״̬¼à²â±¨¸æ


2.jpg


Redgate×îÐÂÐû²¼ÁË2020Äê¶ÈÊý¾Ý¿â״̬¼à²â±¨¸æ¡£±¨¸æÏÔʾ £¬ÎÞÂÛÊÇÔÚ½ÓÄÉÊý¾Ý¿âDevOps·½Ãæ £¬ÕÕ¾ÉÔÚʹÓÃ¼à¿ØÀ´¸ú×ÙÊý¾Ý¿âÐÔÄܺͰ²ÅÅ·½Ãæ £¬½ðÈÚ·þÎñÐÐÒµµÄÌåÏÖ¶¼ÓÅÓÚÆäËûÐÐÒµ¡£ÆäÖÐ £¬61%µÄ½ðÈÚ·þÎñÐÐÒµÔ±¹¤Ã¿ÖܸüÐÂÖÁÉÙÒ»´ÎÊý¾Ý¿â £¬¶øÆäËûÐÐÒµÖ»ÓÐ43%µÄÔ±¹¤»áÕâÑù×ö¡£½ðÈÚ·þÎñµÄ·þÎñÆ÷ÊýĿҲ¸ü¶à £¬36%µÄ·þÎñÆ÷ÓµÓÐ50µ½500¸öʵÀý £¬¶øÆäËû²¿·ÖÖ»ÓÐ26%¡£


Ô­ÎÄÁ´½Ó£º

https://www.helpnetsecurity.com/2020/09/14/database-monitoring-improves-devops-success/


3¡¢Ó¢¹ú¹ú¼ÒÍøÂçÇå¾²ÖÐÐÄ£¨NCSC£©Ðû²¼Îó²îÅû¶ָÄÏ


3.jpg


Ó¢¹ú¹ú¼ÒÍøÂçÇå¾²ÖÐÐÄ£¨NCSC£©Ðû²¼ÁËÎó²îÅû¶ָÄÏ £¬ÒÔ×ÊÖú¹«Ë¾ÊµÑéÎó²îÅû¶Á÷³Ì»òÔÚÒѾ­½¨ÉèÎó²îÅû¶Á÷³ÌµÄÇéÐÎÏÂ¶ÔÆä¾ÙÐÐˢС£NCSCÌåÏÖ £¬¸ÃÖ¸Äϲ¢²»ÊÇÒ»¸öÎó²îÅû¶µÄ¹æÔòÊÖ²á £¬¶øÊÇΪ¸üºÃµÄʵÑéÌṩÁËÐëÒªµÄÐÅÏ¢¡£ÆäÖ÷Òª·ÖΪÈý¸öÖ÷Òª²¿·Ö £¬ÐÎòÁËÔõÑù½«ÍⲿÎó²îÐÅÏ¢¶¨Ïò¸øºÏÊʵÄÈË £¬ÒÔ¼°±¨¸æÐè×ñÕչرÕÎó²îµÄ¿ò¼Ü±ê×¼¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/uk-government-releases-toolkit-to-easily-disclose-vulnerabilities/


4¡¢¿¨°Í˹»ùÐû²¼2020Äê¹¤ÒµÍøÂçÇå¾²ÊÓ²ìÑо¿±¨¸æ


4.jpg


¿¨°Í˹»ù¶ÔÒßÇéʱ´úµÄ¹¤ÒµÍøÂçÇ徲״̬¾ÙÐÐÁËÑо¿ £¬²¢Ðû²¼ÁË2020Äê¹¤ÒµÍøÂçÇå¾²ÊÓ²ìÑо¿±¨¸æ¡£±¨¸æÏÔʾ £¬Áè¼ÝÒ»°ë(53%)µÄÊÜ·ÃÕßÈÏ¿É £¬COVID-19µ¼Ö¸ü¶àÔ±¹¤ÔڼҰ칫 £¬ÕâÒѳÉΪ¶ÔÐÅÏ¢Çå¾²·þÎñµÄÒ»ÖÖѹÁ¦²âÊÔ¡£ÓÉÓÚÍⲿÅþÁ¬ÊýÄ¿ÖÚ¶à £¬ÏÖÔÚ¾ø´ó´ó¶¼¹«Ë¾¶¼ÔÚ¶ÔOTÍøÂçµÄÇå¾²¼¶±ð¾ÙÐа´ÆÚÆÀ¹À¡£Ðí¶à×éÖ¯²»µÃ²»ÖØÐÂ˼Á¿ËûÃÇÄÚÍøµÄ±£»¤ÒªÁì £¬Ö»ÓÐ7%µÄÊÜ·ÃÕßÌåÏÖ £¬ËûÃǵÄÍøÂçÇå¾²Õ½ÂÔÔÚCOVID-19ʱ´úÏ൱ÓÐÓá£


Ô­ÎÄÁ´½Ó£º

https://www.kaspersky.com/blog/industrial-cybersecurity-2020/37031/


5¡¢µÂ¹ú¹ºÎïÍøÕ¾windeln.deÊý¾Ý¿â̻¶ £¬Ð¹Â¶60ÒÚÌõ¼Í¼


5.jpg


Safety DetectivesµÄÑо¿Ö°Ô±ÔÚÍøÂçÉÏ·¢Ã÷ÁËÒ»¸ö̻¶µÄÊý¾Ý¿â £¬¾­ÊÓ²ì¸ÃÊý¾Ý¿âÊôÓڵ¹úÔÚÏß¹ºÎïÍøÕ¾windeln.de¡£Æä̻¶ÁË6.4TBµÄÊý¾Ý £¬ÆäÖаüÀ¨60ÒÚÌõ¼Í¼ £¬Ð¹Â¶ÁËÁè¼Ý700000Ãû¿Í»§µÄСÎÒ˽¼ÒÐÅÏ¢¡£´Ë´ÎÊÂÎñµÄй¶ÐÅÏ¢°üÀ¨Ð¡ÎÒ˽¼ÒÉí·ÝÐÅÏ¢£¨PII£©ºÍÆäËûÊý¾Ý £¬ÀýÈ緢Ʊ¡¢È«Ãû¡¢IPµØÖ·¡¢ÄÚ²¿ÈÕÖ¾¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØÖ·¡¢¼ÒÍ¥µØÖ·¡¢É¢ÁÐÃÜÂë¡¢¸¶¿î·½·¨ºÍÓû§µÄº¢×ÓСÎÒ˽¼ÒÐÅÏ¢µÈ¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/shopping-site-leaks-miners-data-database-mess-up/