OracleÐû²¼1ÔÂÖ÷Òª²¹¶¡¸üР£¬ÐÞ¸´334¸öÎó²î£»IntelÐÞ¸´ÐÔÄÜÆÊÎö¹¤¾ßVTune ProfilerÖеÄÌáȨÎó²î

Ðû²¼Ê±¼ä 2020-01-16


1.OracleÐû²¼1ÔÂÖ÷Òª²¹¶¡¸üР£¬ÐÞ¸´334¸öÎó²î


Ò«ÊÀÓéÀÖ-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ¡£


OracleÔÚ2020Äê1Ôµļ¾¶ÈÖ÷Òª²¹¶¡¸üУ¨CPU£©ÖÐÐÞ¸´ÁËÆäËùÓвúƷϵÁеÄ334¸öÎó²î £¬ÆäÖÐÓÐ43¸öÎó²î±»±êΪÑÏÖØ¼¶±ð £¬ÆäCVSSÆÀ·ÖΪ9.1»ò¸ü¸ß¡£±¾´ÎCPUÖÐÐÞ¸´µÄÎó²îÊýÄ¿Óë2019Äê7ÔµÄÀúÊ·×î¸ß¼Í¼¼á³ÖÒ»Ö £¬Áè¼ÝÁË2017Äê7ÔµÄ308¸öÎó²îµÄ¼Í¼¡£ÕâЩ¸üк­¸ÇÁËOracle°²ÅÅ×îÆÕ±éµÄ²úÆ·ÐÞ¸´²¹¶¡ £¬°üÀ¨OracleÊý¾Ý¿â·þÎñÆ÷£¨¹²12¸ö²¹¶¡ £¬ÆäÖÐ3¸öÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌʹÓã©£»OracleͨѶӦÓóÌÐò£¨25¸ö²¹¶¡ £¬ÆäÖÐ23¸öÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌʹÓà £¬6¸öΪÑÏÖØ¼¶±ð£©£»OracleÆóÒµ¹ÜÀíÆ÷£¨50¸ö²¹¶¡ £¬ÆäÖÐ10¸öÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌʹÓà £¬4¸öΪÑÏÖØ¼¶±ð£©£»OracleÈÚºÏÖÐÐļþ£¨38¸ö²¹¶¡ £¬ÆäÖÐ30¸öÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌʹÓà £¬3¸öÑÏÖØ¼¶±ð£©£»ÊÊÓÃÓÚOracle MySQLµÄ19¸öÐÂÇå¾²²¹¶¡£¨6¸öÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌʹÓã©£»ÒÔ¼°Oracle E-Business Suite£¨23¸ö²¹¶¡ £¬ÆäÖÐ21¸öÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÔ¶³ÌʹÓà £¬2¸öΪÑÏÖØ¼¶±ð£©µÈ¡£


  Ô­ÎÄÁ´½Ó£º

https://threatpost.com/oracle-cpu-all-time-patch-high-january/151861/


2.InfiniteWPºÍWP Time Capsule²å¼þÎó²î £¬32Íò¸öÍøÕ¾ÊÜÓ°Ïì


Ò«ÊÀÓéÀÖ-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ¡£


WordPress²å¼þInfiniteWPºÍWP Time CapsuleÖеÄÑÏÖØÎó²îʹµÃ32Íò¸öÍøÕ¾Ò×Êܹ¥»÷¡£ÕâÁ½¸ö²å¼þÓÃÓÚ×ÊÖúÓû§¹ÜÀíһ̨·þÎñÆ÷ÉϵĶà¸öWordPressÍøÕ¾ £¬²¢ÔÚÐû²¼¸üÐÂʱΪÎļþºÍÊý¾Ý¿âÌõÄ¿½¨×°±¸·Ý¡£WebArxÇå¾²Ñо¿Ö°Ô±·¢Ã÷ËüÃǵĴúÂëÖб£´æÂß¼­¹ýʧ £¬Ê¹µÃ¹¥»÷Õß¿ÉÒÔÈÆ¹ýÃÜÂëÀ´µÇ¼¹ÜÀíÔ±ÕË»§¡£Æ¾Ö¤WordPress²å¼þ¿â £¬InfiniteWP±»×°ÖÃÔÚ30¶àÍò¸öÍøÕ¾ÉÏ£»¶øWP Time CapsuleµÄ×°ÖÃÁ¿ÖÁÉÙΪ2Íò¡£Ñо¿Ö°Ô±·¢Ã÷ÔÚµÍÓÚ°æ±¾1.9.4.5µÄInfiniteWPÖÐ £¬¹¥»÷Õß¿ÉÒÔʹÓôøÓÐJSONºÍBase64±àÂëµÄpayloadµÄPOSTÇëÇóÀ´ÈƹýÃÜÂë £¬Í¨¹ý½öÖªµÀ¹ÜÀíÔ±Óû§ÃûÀ´µÇ¼¡£¶øÔÚµÍÓÚ1.21.16µÄWP Time Capsule°æ±¾ÖÐ £¬¹¥»÷Õß¿Éͨ¹ýÔÚԭʼPOSTÇëÇóÖÐÌí¼Ó¶ñÒâ×Ö·û´®À´Å²Óú¯Êý²¶»ñ¿ÉÓõĹÜÀíÔ±ÕË»§ÁÐ±í²¢ÒÔµÚÒ»¸ö¹ÜÀíÔ±Éí·ÝµÇ¼¡£ÏÖÔÚÕâÁ½¸ö²å¼þ¶¼ÒÑÐû²¼¸üÐÂÐÞ¸´Á˸ÃÎÊÌâ¡£


 Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/critical-bugs-in-wordpress-plugins-infinitewp-wp-time-capsule-expose-300000-websites-to-attack/


3.AdobeÐû²¼1ÔÂÇå¾²¸üР£¬ÐÞ¸´¶à¿î²úÆ·ÖеÄ9¸öÎó²î


Ò«ÊÀÓéÀÖ-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ¡£


AdobeÐû²¼1ÔÂÇå¾²¸üР£¬ÐÞ¸´Adobe Experience ManagerºÍAdobe Illustrator CCÖеÄ9¸öÇå¾²Îó²î¡£ÕâÊÇAdobeÔÚ2020ÄêÐû²¼µÄÊ׸öÇå¾²¸üР£¬ÁîÈËÒâÍâµÄÊDZ¾´Î¸üв¢Î´°üÀ¨ÈκÎÕë¶ÔFlash ManagerµÄ²¹¶¡¡£´Ë´Î¸üÐÂÐÞ¸´ÁËAdobe Experience ManagerÖеÄ4¸öÐÅϢй¶Îó²î £¬µ«Ö»ÓÐ3¸ö±»¹éÀàΪ¡°Ö÷Òª¡± £¬ÁíÒ»¸ö±»¹éÀàΪ¡°Öеȡ±¡£´Ë´Î¸üл¹ÐÞ¸´ÁËAdobe IllustratorÖеÄ5¸ö¡°ÑÏÖØ¡±µÄÔ¶³ÌÖ´ÐдúÂëÎó²î£¨CVE-2020-3710~CVE-2020-3714£©¡£½¨ÒéËùÓÐÓû§¾¡¿ì×°ÖÃÊÊÓõĸüС£


 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/adobe-releases-their-january-2020-security-updates/


4.IntelÐÞ¸´ÐÔÄÜÆÊÎö¹¤¾ßVTune ProfilerÖеÄÌáȨÎó²î


Ò«ÊÀÓéÀÖ-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ¡£


IntelÐÞ¸´ÁËÆäÐÔÄÜÆÊÎö¹¤¾ßVTune ProfilerÖеÄÌáȨÎó²î£¨CVE-2019-14613£© £¬¸ÃÎó²î±»¹éÀàΪÑÏÖØ¼¶±ð £¬¿ÉÔÊÐí¾­ÓÉÉí·ÝÑéÖ¤µÄÍâµØ¹¥»÷ÕßDZÔÚµØÌáÉýÌØÈ¨¡£Ö»¹ÜVTune ProfilerÖ§³ÖWindows¡¢LinuxºÍAndroidƽ̨ £¬µ«IntelÌåÏÖÖ»ÓÐWindows°æ±¾Êܵ½Ó°Ïì £¬²¢ÇÒ¸ÃÎó²îÔ´ÓÚVTune AmplifierÇý¶¯³ÌÐòÖеIJ»µ±»á¼û¿ØÖÆ¡£³ý´ËÖ®Íâ £¬Intel»¹ÔÚ1Ô²¹¶¡¸üÐÂÖÐÐÞ¸´ÁË5¸öÎó²î £¬µ«ÕâЩÎó²îµÄÑÏÖØÐÔ¾ùΪ¡°ÖС±»ò¡°µÍ¡±¡£


 Ô­ÎÄÁ´½Ó£º

https://threatpost.com/intel-fixes-high-severity-flaw-in-performance-analysis-tool/151837/


5.°Ä´óÀûÑÇP£¦NÒøÐÐÔâµ½ÍøÂç¹¥»÷ £¬¿Í»§ÕË»§ÐÅϢй¶


Ò«ÊÀÓéÀÖ-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ¡£


°Ä´óÀûÑÇP£¦NÒøÐÐÌåÏÖËüÃÇÔÚ·þÎñÆ÷Éý¼¶Ê±´úÔâµ½ÍøÂç¹¥»÷ £¬µ¼Ö¿ͻ§µÄPIIºÍÕË»§ÐÅϢй¶¡£P£¦NÒøÐÐÊÇPolice£¦Nurses LimitedµÄÒ»¸ö²¿·Ö £¬ÔÚÎ÷°Ä´óÀûÑÇÖÝÔËÓª £¬ÆäÐû²¼µÄ֪ͨ³ÆÍ¨¹ýÆä¿Í»§¹ØÏµ¹ÜÀí£¨CRM£©Æ½Ì¨±¬·¢ÁËÐÅϢй¶ÊÂÎñ¡£¸ÃÒøÐÐÌåÏÖÔÚÈ¥Äê12ÔÂ12ÈÕǰºó¾ÙÐÐÁË·þÎñÆ÷Éý¼¶ £¬µ«ÔÚ´Ëʱ´úÔâµ½ÍøÂç¹¥»÷ £¬¾Ý³ÆÎª¸ÃÒøÐÐÌṩÍйܷþÎñµÄ¹«Ë¾Êǹ¥»÷Èë¿Úµã¡£¿ÉÄÜй¶µÄÐÅÏ¢°üÀ¨¿Í»§µÄÐÕÃû¡¢µØÖ·¡¢µç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂë¡¢¿Í»§±àºÅ¡¢ÄêËê¡¢ÕʺźÍÕÊ»§Óà¶îÒÔ¼°¿ÉÄܰüÀ¨ÔÚ»¥¶¯¼Í¼ÖеÄÐÅÏ¢ £¬µ«²»°üÀ¨ÃÜÂë¡¢Éç»áÇå¾²ºÅÂ롢˰ÎñÎļþ¡¢¼ÝÕÕ»òÐÅÓÿ¨ÐÅÏ¢¡£ÏÖÔÚÉв»ÇåÎúÓм¸¶à¿Í»§Êܵ½Ó°Ïì¡£


 Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/p-n-bank-discloses-data-breach-customer-pii-account-information-stolen/


6.Ó¢¹ú×Éѯ¹«Ë¾CHS ConsultingÒâÍâй¶ÊýǧԱ¹¤ÐÅÏ¢


Ò«ÊÀÓéÀÖ-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ¡£


vpnMentor·¢Ã÷Ò»¸öÉèÖùýʧµÄAWS S3´æ´¢Í°Ð¹Â¶ÁËÊýǧӢ¹úÉÌÎñÖ°Ô±µÄСÎÒ˽¼ÒÏêϸÐÅÏ¢¡£¸Ã´æ´¢Í°ÊôÓÚÓ¢¹ú×Éѯ¹«Ë¾CHS Consulting £¬²¢ÇÒδ¾­Éí·ÝÑéÖ¤¼´¿É¹ûÕæ»á¼û¡£µ«ÓÉÓڸù«Ë¾Ã»ÓÐÍøÕ¾ £¬Ñо¿Ö°Ô±ÉÐδÄÜÓë¸Ã¹«Ë¾¾ÙÐÐÈ·ÈÏ¡£Ð¹Â¶µÄÊý¾Ý¿âÖаüÀ¨¶à¼ÒÓ¢¹ú×Éѯ¹«Ë¾£¨°üÀ¨Eximius Consultants¡¢Dynamic PartnersºÍIQ Consulting£©µÄÈËÁ¦×ÊÔ´²¿·ÖÎļþ £¬Ö»¹ÜÓÐЩ¼Í¼¿ÉÒÔ×·Ëݵ½2011Äê £¬µ«´ó´ó¶¼Êý¾ÝÀ´×Ô2014-15Äê¡£¼Í¼ÖаüÀ¨»¤ÕÕɨÃè¼þ¡¢Ë°ÎñÎļþ¡¢·¸·¨ÐÅÏ¢¼Í¼ºÍÅä¾°ÊӲ졢ÓëHMRCÏà¹ØµÄÎÄÊéÊÂÇé¡¢µç×ÓÓʼþºÍ˽ÈËÐÂÎÅÒÔ¼°Ò»ÏµÁÐСÎÒ˽¼Òʶ±ðÐÅÏ¢ £¬°üÀ¨ÐÕÃû¡¢µç×ÓÓʼþºÍ¼Òͥסַ¡¢³öÉúÈÕÆÚºÍµç»°ºÅÂëµÈ¡£


 Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/uk-consultancies-leak-data/