ÐÅÏ¢°²È«Öܱ¨-2021ÄêµÚ45ÖÜ

°ä²¼¹¦·ò 2021-11-08

>±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


±¾Öܹ²ÊÕ¼°²È«·ì϶60¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇCisco Policy Suite¾²Ì¬SSHÃÜÔ¿·ì϶ £»Mozilla Firefox ESR  HTTP2 session objectÄÚ´æÃýÎóÒýÓôúÂëÖ´Ðзì϶ £»Apache Traffic Server stats-over-http²å¼þÄڴ渲¸Ç·ì϶ £»D-Link DIR-823G HNAP1ºÅÁî×¢Èë·ì϶ £»Beckhoff Automation TwinCAT OPC UA ServerĿ¼±éÀú·ì϶ ¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊDz¿ÃÅMacÉ豸Éý¼¶ÖÁmacOS MontereyºóÎÞ·¨Õý³£Æô¶¯ £»×êÑÐÍŶӷ¢ÏÖÏÕЩÍþвËùÓдúÂëµÄ·ì϶Trojan Source £»×êÑÐÍŶӳƽ©Ê¬ÍøÂçPinkÒÑϰȾ³¬¹ý160Íǫ̀ÖйúµÄÉ豸 £»Google°ä²¼Android 11Ô¸üУ¬×ܼƽ¨¸´39¸ö·ì϶ £»BlackMatterÍÅ»ï°ä·¢ÆÅ×Ú·¨Âɲ¿ÃŵÄѹÁ¦½«ÖÕ³¡ÔËÓª ¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖÐ ¡£


>³ÁÒª°²È«·ì϶Áбí


1. Cisco Policy Suite¾²Ì¬SSHÃÜÔ¿·ì϶


Cisco Policy Suite´æÔÚ¾²Ì¬SSHÃÜÔ¿·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Î´ÊÚȨ½Ó¼ûϵͳ ¡£


https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cps-static-key-JmS92hNv



2. Mozilla Firefox ESR  HTTP2 session objectÄÚ´æÃýÎóÒýÓôúÂëÖ´Ðзì϶


Mozilla Firefox ESR  HTTP2 session object´æÔÚ¿ªÊͺóʹÓ÷ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄWEBÒªÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ £»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë ¡£


https://www.mozilla.org/en-US/security/advisories/mfsa2021-49/



3. Apache Traffic Server stats-over-http²å¼þÄڴ渲¸Ç·ì϶


Apache Traffic Server stats-over-http²å¼þ´æÔÚÄڴ渲¸Ç·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë ¡£


https://lists.apache.org/thread/k01797hyncx53659wr3o72s5cvkc3164



4. D-Link DIR-823G HNAP1ºÅÁî×¢Èë·ì϶


D-Link DIR-823G HNAP1´æÔÚÊäÈëÑéÖ¤·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâSHELLºÅÁî ¡£


https://www.dlink.com/en/security-bulletin/



5. Beckhoff Automation TwinCAT OPC UA ServerĿ¼±éÀú·ì϶


Beckhoff Automation TwinCAT OPC UA Server´æÔÚĿ¼±éÀú·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄ´´½¨»òɾ³ýϵͳÉϵÄÈκÎÎļþ ¡£


https://download.beckhoff.com/download/document/product-security/Advisories/advisory-2021-003.pdf



>³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢²¿ÃÅMacÉ豸Éý¼¶ÖÁmacOS MontereyºóÎÞ·¨Õý³£Æô¶¯


½üÆÚ£¬Ô½À´Ô½¶àµÄMacºÍMacbookÓû§»ã±¨£¬µ±Æä¸üе½ÉÏÖܰ䲼µÄ×îаæmacOS Montereyºó£¬É豸ÎÞ·¨Õý³£Æô¶¯ ¡£´ËÎÊÌâËÆºõ½öÓ°ÏìÁË2019Äê֮ǰµÄMacÉ豸£¬²»»áÓ°ÏìʹÓÃM1оƬµÄпîMac ¡£´Ë±í£¬¹ÌÈ»²¿ÃÅÓû§³ÆËûÃǵÄϵͳÒѾ­±äש£¬µ«´óÎÞÊýÓû§Äܹ»Í¨¹ýApple Configurator¹¤¾ß¸´Ô­É豸 ¡£ÆäËûÓû§ÔòÕÒµ½ÁËÁíÒ»ÖÖ²½Ö裬¾ÍÊÇͨ¹ýÆô¶¯DFUÀ´¸´Ô­É豸 ¡£    


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/apple/macos-monterey-update-causes-some-macs-to-become-unbootable/


2¡¢×êÑÐÍŶӷ¢ÏÖÏÕЩÍþвËùÓдúÂëµÄ·ì϶Trojan Source


½£ÇÅ´óѧµÄ×êÑÐÈËÔ±ÔÚ11ÔÂ1ÈÕ¹«¿ªÁËÒ»¸öÓ°Ïì´óÎÞÊýÍÆËã»ú´úÂë±àÒëÆ÷ºÍºÜ¶àÈí¼þ¿ª·¢»·¾³µÄ·ì϶Trojan Source ¡£¸Ã·ì϶´æÔÚÓÚUnicodeÖУ¬ÓÐÁ½ÖÖÀûÓò½Ö裺ÆäÒ»ÊÇʹÓÃUnicodeµÄBidiËã·¨£¨CVE-2021-42574£©£¬¶Ô×Ö·û½øÐÐÊÓ¾õÉϵijÁÐÂÅÅÐò£¬Ê¹Æä³öÏÖÓë±àÒëÆ÷ºÍÚ¹ÊÍÆ÷Ëù·ÖÆçµÄÂß¼­°¤´Î £»ÁíÒ»ÖÖÊÇͬÐÎÎÄ×Ö¹¥»÷(CVE-2021-42694)£¬¼´ÀûÓÃÔÚÊÓ¾õÉÏ¿´ÆðÀ´ÀàËÆµÄ·ÖÆç×Ö·û ¡£¸Ã·ì϶ºÏÓÃÓÚC¡¢C++¡¢C#¡¢JavaScript¡¢JavaµÈ¿í·ºÊ¹ÓõÄ˵»°£¬¿ÉÓÃÓÚ¹©¸øÁ´¹¥»÷ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.trojansource.codes/


3¡¢×êÑÐÍŶӳƽ©Ê¬ÍøÂçPinkÒÑϰȾ³¬¹ý160Íǫ̀ÖйúµÄÉ豸


×êÑÐÍŶÓÔÚ10ÔÂ29ÈÕÅû¶ÁËÔÚ´ÓǰÁùÄê·¢ÏÖµÄ×î´ó½©Ê¬ÍøÂçµÄϸ½Ú ¡£ÓÉÓÚÆä´óÁ¿µÄº¯ÊýÃû³ÆÒÔpinkΪÊ×£¬ËùÒÔÈ¡ÃûPinkbot ¡£¸Ã½©Ê¬ÍøÂçÒÑϰȾÁ˳¬¹ý160Íǫ̀É豸£¬ÆäÖÐ96%λÓÚÖйú ¡£ËüÖØÒªÕë¶Ô»ùÓÚMIPSµÄ¹âÏË·ÓÉÆ÷£¬ÀûÓõÚÈý·½·þÎñµÄ×éºÏ£¬ÀýÈçGitHub¡¢P2PÍøÂçºÍC2·þÎñÆ÷£¬»¹¶Ô²¿ÃÅÓòÃûµÄ½âÎö²éÎʲÉÈ¡ÁËDNS-Over-HTTPSµÄ·½Ê½ ¡£×êÑÐÈËÔ±³Æ£¬Æù½ñΪֹ£¬PinkBotÌáÒéÁ˽ü°Ù´ÎDDoS¹¥»÷ ¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/11/researchers-uncover-pink-botnet-malware.html


4¡¢Google°ä²¼Android 11Ô¸üУ¬×ܼƽ¨¸´39¸ö·ì϶


GoogleÔÚ±¾ÖÜÒ»°ä²¼ÁËAndroid 11Ô·ݵĸüУ¬×ܼƽ¨¸´39¸ö·ì϶ ¡£Õâ´Î¸üн¨¸´ÁËÒ»¸öÒѱ»ÔÚÒ°ÀûÓõÄ0day£¬ÊÇÓÉ¿ªÊͺóʹÓõ¼Öµı¾µØÌáȨ·ì϶CVE-2021-1048 ¡£´Ë±í£¬»¹½¨¸´Á˶à¸öÑϳÁµÄ·ì϶£¬Ô̺¬Ô¶³Ì´úÂëÖ´Ðзì϶CVE-2021-0918ºÍCVE-2021-0930£¬Ó°Ïì¸ßͨ×é¼þµÄCVE-2021-1924ºÍCVE-2021-1975£¬ÒÔ¼°Android TVÔ¶³Ì·þÎñÖеÄÔ¶³Ì´úÂëÖ´Ðзì϶CVE-2021-0889µÈ ¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/android-patches-exploited-kernel-bug/175931/


5¡¢BlackMatterÍÅ»ï°ä·¢ÆÅ×Ú·¨Âɲ¿ÃŵÄѹÁ¦½«ÖÕ³¡ÔËÓª


11ÔÂ1ÈÕ£¬ÀÕË÷ÔËÓªÍÅ»ïBlackMatterÔÚÆäÊý¾ÝÐ¹Â¶ÍøÕ¾Éϰ䲼ÐÂÎÅ£¬³ÆÆÅ×Ú·¨Âɲ¿ÃŵÄѹÁ¦ËûÃǽ«ÔÚ48Ó×ʱÄڹعØÕû¸ö»ù´¡ÉèÊ© ¡£×êÑÐÍŶӰµÊ¾£¬Õâ¿ÉÄÜÓë×î½üµÄÒ»´Î¹ú¼Ê·¨ÂÉÐж¯ÓйØ£¬Õâ´ÎÐж¯¹²¿ÛÁôÁË12¸öÉæ¼°1800ÆðÀÕË÷¹¥»÷»î¶¯µÄÏÓÒÉÈË ¡£È»¶ø£¬¼´±ãBlackMatter´Ë¿ÌÖÕ³¡ÆäÔËÓª£¬ÔÚ½«À´Ò²½«»áÒÔеÄÃû³Æ»Ø¹é£¬ÕýÈçBlackMatter×ÔÉí¾ÍÊÇDarkSideÔÚ¹¥»÷Colonial PipelineºóÆÅ×ÚѹÁ¦¸ÄÃû¶øÀ´µÄ ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/124135/cyber-crime/blackmatter-ransomware-shutting-down-operations.html