ÐÅÏ¢Çå¾²Öܱ¨-2020ÄêµÚ41ÖÜ

Ðû²¼Ê±¼ä 2020-10-13

> ±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


2020Äê10ÔÂ05ÈÕÖÁ10ÔÂ11ÈÕ¹²ÊÕ¼Çå¾²Îó²î57¸ö£¬£¬£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇGoogle Android Qualcomm±ÕÔ´×é¼þCVE-2020-3654´úÂëÖ´ÐÐÎó²î£»£»£»Google Android Qualcomm±ÕÔ´×é¼þCVE-2020-3657´úÂëÖ´ÐÐÎó²î£»£»£»Google Android system×é¼þCVE-2020-0416´úÂëÖ´ÐÐÎó²î£»£»£»D-Link DAP-136 IP²ÎÊýÏÂÁîÖ´ÐÐÎó²î£»£»£»Facebook WhatsApp RTP ExtensionÕ»Òç³öÎó²î¡£ ¡£¡£¡£¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇ£ºCISAÐû²¼2019²ÆÄêΣº¦Îó²îÆÀ¹ÀµÄÐÅϢͼ£»£»£»Çå¾²¹«Ë¾Arctic WolfÐû²¼Çå¾²ÔËÓªÄê¶È±¨¸æ£»£»£»GoogleÐû²¼µÄChromeÇå¾²¸üÐÂÐÞ¸´¶à¸öÎó²î£»£»£»AdobeÒòЧÀÍÖÐÖ¹µ¼ÖÂÓû§ÎÞ·¨µÇ¼Creative Cloud£»£»£»Android°æFacebookÖб£´æÎó²î£¬£¬£¬£¬£¬£¬£¬£¬»ò½«µ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£ ¡£¡£¡£¡£¡£¡£¡£


ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£ ¡£¡£¡£¡£¡£¡£¡£


Ö÷ÒªÇå¾²Îó²îÁбí


1.Google Android Qualcomm±ÕÔ´×é¼þCVE-2020-3654´úÂëÖ´ÐÐÎó²î


Google Android Qualcomm±ÕÔ´×é¼þʵÏÖ±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬£¬¿ÉʹЧÀͳÌÐò±ÀÀ£»£»£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£ ¡£¡£¡£¡£¡£¡£¡£

https://source.android.com/security/bulletin/2020-10-01


2.Google Android Qualcomm±ÕÔ´×é¼þCVE-2020-3657´úÂëÖ´ÐÐÎó²î


Google Android Qualcomm±ÕÔ´×é¼þʵÏÖ±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬£¬¿ÉʹЧÀͳÌÐò±ÀÀ£»£»£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£ ¡£¡£¡£¡£¡£¡£¡£

https://source.android.com/security/bulletin/2020-10-01


3.Google Android system×é¼þCVE-2020-0416´úÂëÖ´ÐÐÎó²î


Google Android Framework×é¼þʵÏÖ±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬£¬¿ÉʹЧÀͳÌÐò±ÀÀ£»£»£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£ ¡£¡£¡£¡£¡£¡£¡£

https://source.android.com/security/bulletin/2020-10-01


4.D-Link DAP-136 IP²ÎÊýÏÂÁîÖ´ÐÐÎó²î


D-Link DAP-136´¦Öóͷ£IP²ÎÊý±£´æÊäÈëÑéÖ¤Îó²î£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§ÒâÏÂÁî¡£ ¡£¡£¡£¡£¡£¡£¡£

https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10191


5.Facebook WhatsApp RTP ExtensionÕ»Òç³öÎó²î


Facebook WhatsApp RTP ExtensionÆÊÎö±£´æÕ»Òç³öÎó²î£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£ ¡£¡£¡£¡£¡£¡£¡£

https://www.whatsapp.com/security/advisories/2020/


> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢CISAÐû²¼2019²ÆÄêΣº¦Îó²îÆÀ¹ÀµÄÐÅϢͼ



1.png


ÍøÂçÇå¾²ºÍÐÅÏ¢Çå¾²»ú¹¹(CISA)Ðû²¼ÁË2019²ÆÄê¾ÙÐеÄ44ÏîΣº¦ºÍÎó²îÆÀ¹À£¨RVA£©£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°MITER¶Ô¿¹Õ½ÂÔ¡¢ÊÖÒÕºÍ֪ʶ£¨ATT£¦CK£©¿ò¼ÜµÄÆÊÎöÐÅϢͼ¡£ ¡£¡£¡£¡£¡£¡£¡£¸ÃÐÅϢͼ±íÈ·¶¨ÁËCISAÔÚ¿ç¶à¸ö²¿·ÖµÄRVAsʱ´úÊӲ쵽µÄͨÀýÀֳɹ¥»÷·¾¶£¬£¬£¬£¬£¬£¬£¬£¬ÍøÂç¹¥»÷Õß¿ÉÒÔʹÓÃÕâЩ¹¥»÷;¾¶À´¹¥»÷×éÖ¯¡£ ¡£¡£¡£¡£¡£¡£¡£CISAÃãÀøÍøÂçÖÎÀíÔ±ºÍITרҵְԱÉó²éÐÅϢͼ²¢Ó¦ÓÃÍÆ¼öµÄ·ÀÓùÕ½ÂÔ£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ±ÜÃâÊܵ½ÒÑÖªÕ½ÊõºÍÊÖÒյĹ¥»÷¡£ ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2020/10/07/cisa-releases-fy2019-risk-vulnerability-assessment-infographic


2¡¢Çå¾²¹«Ë¾Arctic WolfÐû²¼Çå¾²ÔËÓªÄê¶È±¨¸æ


2.png


Çå¾²¹«Ë¾Arctic WolfÐû²¼ÁËÒ»·ÝÇå¾²ÔËÓªÄê¶È±¨¸æ¡£ ¡£¡£¡£¡£¡£¡£¡£±¨¸æÏÔʾ£¬£¬£¬£¬£¬£¬£¬£¬×Ô3ÔÂÒÔÀ´£¬£¬£¬£¬£¬£¬£¬£¬°µÍøÉϹûÕæµÄ¹«Ë¾Æ¾Ö¤ÊýÄ¿ÔöÌíÁË429£¥¡£ ¡£¡£¡£¡£¡£¡£¡£ÔÚÊӲ쵽µÄ¸ßΣº¦Çå¾²ÊÂÎñÖУ¬£¬£¬£¬£¬£¬£¬£¬ÓÐ35£¥±¬·¢ÔÚ8:00 PMºÍ8:00 AMÖ®¼ä£¬£¬£¬£¬£¬£¬£¬£¬¶ø14£¥±¬·¢ÔÚÖÜÄ©£¬£¬£¬£¬£¬£¬£¬£¬ÕâÊÇÐí¶àÄÚ²¿Çå¾²ÍŶӲ»ÔÚÏßµÄʱ¼ä¡£ ¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬£¬ÍøÂç´¹ÂÚºÍÀÕË÷Èí¼þ¹¥»÷´ÎÊýÔöÌíÁË64£¥£¬£¬£¬£¬£¬£¬£¬£¬ºÚ¿Í¸ü¶àµÄÒÔCOVID-19Ö÷ÌâΪÓÕ¶ü£¬£¬£¬£¬£¬£¬£¬£¬À´Õë¶ÔÔ¶³ÌÊÂÇéÕß¡£ ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://arcticwolf.com/resources/analyst-reports/security-operations-annual-report


3¡¢GoogleÐû²¼µÄChromeÇå¾²¸üÐÂÐÞ¸´¶à¸öÎó²î


3.png


GoogleÐû²¼µÄChromeÇå¾²¸üÐÂÕë¶ÔWindows¡¢MacºÍLinux°æ±¾ÐÞ¸´ÁË35¸öÎó²î¡£ ¡£¡£¡£¡£¡£¡£¡£ÆäÖнÏΪÑÏÖØµÄÎó²îΪ֧¸¶ÖеÄÊͷźóʹÓÃÎó²î£¨CVE-2020-15967£©£¬£¬£¬£¬£¬£¬£¬£¬Æä´ÎΪBlink¡¢WebRTC¡¢NFC¡¢´òÓ¡¡¢ÒôƵ¡¢×Ô¶¯Ìî³äºÍÃÜÂëÖÎÀíÆ÷ÖеÄÊͷźóʹÓÃÎó²î£¨CVE-2020-15968¡¢CVE-2020-15969¡¢CVE-2020-15970¡¢CVE-2020-15971¡¢CVE-2020-15972¡¢CVE-2020-15990ºÍCVE-2020-15991£©¡£ ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2020/10/07/google-releases-security-updates-chrome


4¡¢AdobeÒòЧÀÍÖÐÖ¹µ¼ÖÂÓû§ÎÞ·¨µÇ¼Creative Cloud


4.png


AdobeÒòЧÀÍÖÐÖ¹£¬£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂÓû§ÎÞ·¨µÇ¼Creative Cloud»ò»á¼ûÆä¶©ÔĵÄÓ¦ÓóÌÐò»ò´æ´¢µÄÊý¾Ý¡£ ¡£¡£¡£¡£¡£¡£¡£×ÔÃÀ¹ú¶«²¿Ê±¼äÉÏÎç9:30ÒÔÀ´£¬£¬£¬£¬£¬£¬£¬£¬Adobe Creative CloudÓû§×îÏȱ¨¸æÎÞ·¨µÇ¼¸ÃЧÀÍ»ò»á¼ûÉúÑĵÄͼÏñºÍÊý¾Ý£¬£¬£¬£¬£¬£¬£¬£¬µ±ËûÃÇÊÔͼµÇ¼µÄʱ¼ä£¬£¬£¬£¬£¬£¬£¬£¬¾Í»áÏÔʾ¡°±¬·¢ÁËһЩ¹ýʧ¡±µÄÌáÐÑ¡£ ¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬£¬£¬AdobeÒÑÔÚstatus.adobe.comÒ³ÃæÉÏÐû²¼Í¨ÖªÈ·ÈÏÁËÖÐÖ¹£¬£¬£¬£¬£¬£¬£¬£¬µ«²¢Î´ÌṩÈκÎÓйش˴ÎÖÐÖ¹µÄÏêϸÐÅÏ¢¡£ ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/technology/adobe-creative-cloud-down-users-report-login-data-access-issues/


5¡¢Android°æFacebookÖб£´æÎó²î£¬£¬£¬£¬£¬£¬£¬£¬»ò½«µ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐ


5.png


Çå¾²Ñо¿Ô±Sayed Abdelhafiz·¢Ã÷£¬£¬£¬£¬£¬£¬£¬£¬Android°æFacebookÖб£´æÑÏÖØÎó²î£¬£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²î»ò½«µ¼ÖÂÔ¶³Ì´úÂëÖ´ÐУ¬£¬£¬£¬£¬£¬£¬£¬Ê¹ÓøÃÎó²î¿ÉÄܵ¼ÖÂÓ¦ÓÃÍß½âÒÔ¼°×°±¸½ÓÊÜ¡£ ¡£¡£¡£¡£¡£¡£¡£FacebookÔÊÐíͨ¹ýÁ½ÖÖ·½·¨ÏÂÔØÎļþ£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÒ»ÖÖÊÇʹÓá°Îļþ¡±Ñ¡Ï£¬£¬£¬£¬£¬£¬£¬£¬½«ÎļþÏÈÌáÈ¡µ½DownloadManager£¬£¬£¬£¬£¬£¬£¬£¬È»ºóÉúÑĵ½Download Director¡£ ¡£¡£¡£¡£¡£¡£¡£Abdelhafiz·¢Ã÷¿ÉÒÔ½¨Éè²¢ÏÂÔØÒ»¸ö¶ñÒâÎļþ£¬£¬£¬£¬£¬£¬£¬£¬È»ºóÔÚÄ¿µÄ×°±¸ÉÏÖ´ÐÐí§Òâ´úÂë¡£ ¡£¡£¡£¡£¡£¡£¡£FacebookÔÚ»ñµÃÎó²î±¨¸æºó£¬£¬£¬£¬£¬£¬£¬£¬ÒÑÓÚ2020Äê6ÔÂÐÞ¸´Á˸ÃÎó²î¡£ ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://latesthackingnews.com/2020/10/08/code-execution-vulnerability-found-in-facebook-for-android/