ÐÅÏ¢°²È«Öܱ¨-2021ÄêµÚ48ÖÜ

°ä²¼¹¦·ò 2021-11-29

>±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


±¾Öܹ²ÊÕ¼°²È«·ì϶50¸ö£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇDell Networking X-Series firmwareÑéÖ¤ÈÆ¹ý·ì϶£»£»D-Link DWR-932C E1 debug_fcgi OSºÅÁî×¢Èë·ì϶£»£»Commvault CommCell AppStudioUploadHandlerËÁÒâÎļþÉÏ´«·ì϶£»£»HejHome GKW-IC052 IP CameraÓ²±àÂë·ì϶£»£»QNAP QVR²»ÕýÈ·ÑéÖ¤·ì϶¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇRedCurlÍÅ»ï»Ø¹é£¬£¬£¬ÐµĹ¥»÷Ö¸±êÉæ¼°¸÷Ðи÷Òµ£»£»LinuxºóÃÅlinux_avp¿ÉÈÆ¹ýµçÉÌÆ½Ì¨µÄ°²È«¼ì²â£»£»CloudLinuxÐÞ¸´Imunify360ÖеÄPHP·´ÐòÁл¯·ì϶£»£»AppGalleryÖжà¿îÓÎÏ·ÀûÓôæÔÚľÂí£¬£¬£¬ÒÑϰȾ900¶àÍòÉ豸£»£»Kaspersky°ä²¼2021ÄêºÚÎåÆÚ¼äÚ¿Æ­»î¶¯µÄ·ÖÎö»ã±¨¡£¡£¡£¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬±¾Öܰ²È«ÍþвΪÖС£¡£¡£¡£


>ÖØÒª°²È«·ì϶Áбí


1. Dell Networking X-Series firmwareÑéÖ¤ÈÆ¹ý·ì϶


Dell Networking X-Series firmware´æÔÚÑéÖ¤ÈÆ¹ý·ì϶£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬¿É½Ù³Ö»á»°£¬£¬£¬Í¨¹ýαÔì»á»°id½Ó¼ûweb·þÎñÆ÷¡£¡£¡£¡£


https://www.dell.com/support/kbdoc/en-us/000193230/dsa-2021-191-dell-networking-x-series-security-update-for-multiple-security-vulnerabilities


2. D-Link DWR-932C E1 debug_fcgi OSºÅÁî×¢Èë·ì϶


D-Link DWR-932C E1 debug_fcgi´æÔÚÊäÈëÑéÖ¤·ì϶£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£


https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10246


3. Commvault CommCell AppStudioUploadHandlerËÁÒâÎļþÉÏ´«·ì϶


Commvault CommCell AppStudioUploadHandlerÀà´æÔÚ°²È«·ì϶£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÉÏ´«Îļþ²¢Ö´ÐС£¡£¡£¡£


https://www.zerodayinitiative.com/advisories/ZDI-21-1332/


4. HejHome GKW-IC052 IP CameraÓ²±àÂë·ì϶


HejHome GKW-IC052 IP Camera´æÔÚÓ²±àÂë·ì϶£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬¿É½ÚÖÆÏµÍ³Î´ÊÚȨ½øÐвÙ×÷¡£¡£¡£¡£


https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=36359


5. QNAP QVR²»ÕýÈ·ÑéÖ¤·ì϶


NAP QVR´æÔÚ²»ÕýÈ·ÑéÖ¤·ì϶£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬¿ÉδÊÚȨ½Ó¼ûϵͳ¡£¡£¡£¡£


https://www.qnap.com.cn/en/security-advisory/qsa-21-52


>ÖØÒª°²È«ÊÂÎñ×ÛÊö


1¡¢¡¢¡¢RedCurlÍÅ»ï»Ø¹é£¬£¬£¬ÐµĹ¥»÷Ö¸±êÉæ¼°¸÷Ðи÷Òµ


Group-IBÔÚ11ÔÂ18ÈÕÅû¶Á˺ڿÍÍÅ»ïRedCurlµÄл¡£¡£¡£¡£ÍøÂç¼äµýºÚ¿Í×éÖ¯RedCurlÔÚ2018ÄêÖÁ2020ÄêÆÚ¼ä£¬£¬£¬ÌáÒéÁËÖÁÉÙ26´Î¹¥»÷£¬£¬£¬Éæ¼°Ó¢¹ú¡¢¡¢¡¢µÂ¹ú¡¢¡¢¡¢¼ÓÄô󡢡¢¡¢Å²Íþ¡¢¡¢¡¢¶íÂÞ˹ºÍÎÚ¿ËÀ¼µÈµØÓòµÄ¹¹Öþ¡¢¡¢¡¢½ðÈÚ¡¢¡¢¡¢Õ÷ѯ¡¢¡¢¡¢ÁãÊÛ¡¢¡¢¡¢±£ÏÕºÍ˾·¨ÐÐÒµµÄ¹«Ë¾¡£¡£¡£¡£¸ÃÍÅ»ïÔÚÖжÏ7¸öÔºó¶«É½ÔÙÆð£¬£¬£¬×Ô2021ËêÊ×ÒÔÀ´Õë¶Ô4¼Ò¹«Ë¾ÌáÒéÁËÐµĹ¥»÷£¬£¬£¬ÆäÖÐÔ̺¬¶íÂÞ˹×î´óµÄÅú·¢É̵ꡣ¡£¡£¡£Group-IB³Æ£¬£¬£¬RedCurlÔÚÿ´Î¹¥»÷ÖгÇÊÐʹÓÃÆä×Ô½ç˵¶ñÒâÈí¼þÈÆ¹ý¼ì²â¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º£º£º

https://www.group-ib.com/media/red-curl-threat-report/


2¡¢¡¢¡¢LinuxºóÃÅlinux_avp¿ÉÈÆ¹ýµçÉÌÆ½Ì¨µÄ°²È«¼ì²â


SansecÍþв×êÑÐÍŶÓÔÚ11ÔÂ18µÄ×îÐÂ×êÑз¢ÏÖÁËLinuxºóÃÅlinux_avp¡£¡£¡£¡£×êÑÐÈËÔ±³Æ£¬£¬£¬¹¥»÷ÕßÔÚµçÉÌÍøÕ¾×¢ÈëÐÅÓþ¿¨ÇÔÈ¡Æ÷ºó£¬£¬£¬»¹»áÔÚ±»ÈëÇֵķþÎñÆ÷ÉÏ×°ÖÃLinuxºóÃÅ¡£¡£¡£¡£linux_avpÒ»µ©Æô¶¯£¬£¬£¬¾ÍÁ¢¼´½«×Ô¼º´Ó´ÅÅÌÖÐɾ³ý£¬£¬£¬¼Ù×°³Éps -ef¹ý³Ì£¬£¬£¬ÓÃÓÚ»ñÈ¡µ±Ç°ÕýÔÚÔËÐеĹý³ÌÁÐ±í²¢ÈÆ¹ý¼ì²â¡£¡£¡£¡£¸ÃÑù±¾ÓÚ10ÔÂ8ÈÕ³õ´ÎÉÏ´«£¬£¬£¬Ä¿Ç°VirusTotalµÄ·´¶ñÒâÈí¼þÒýÇæÈÔδ¼ì²âµ½Ëü¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º£º£º

https://www.bleepingcomputer.com/news/security/hackers-deploy-linux-malware-web-skimmer-on-e-commerce-servers/


3¡¢¡¢¡¢CloudLinuxÐÞ¸´Imunify360ÖеÄPHP·´ÐòÁл¯·ì϶


Cisco TaloÔÚ11ÔÂ22ÈÕÅû¶ÁËCloudLinuxµÄ²úÆ·Imunify360ÖеÄPHP·´ÐòÁл¯·ì϶¡£¡£¡£¡£¸Ã²úÆ·ÊÇ»ùÓÚLinuxµÄWeb·þÎñÆ÷µÄ°²È«Æ½Ì¨£¬£¬£¬Óû§¿ÉÀûÓÃÆäͨ¹ý¸÷ÀàÅäÖÃÀ´ÊµÊ±±£»£»¤ÍøÕ¾ºÍWeb·þÎñÆ÷µÄ°²È«¡£¡£¡£¡£¸Ã·ì϶(CVE-2021-21956)CVSSÆÀ·ÖΪ8.2£¬£¬£¬´æÔÚÓÚAi-BolitÖ°ÄÜÖУ¬£¬£¬¹¥»÷ÕßÄܹ»Í¨¹ý¸Ã·ì϶ÔÚÖ¸±êϵͳÖÐÖ´ÐÐËÁÒâ´úÂ룬£¬£¬»òÆëÈ«½ÚÀñ·þÎñÆ÷¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬CloudLinuxÒÑÐÞ¸´¸Ã·ì϶¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º£º£º

https://blog.talosintelligence.com/2021/11/vulnerability-spotlight-php-deserialize.html


4¡¢¡¢¡¢AppGalleryÖжà¿îÓÎÏ·ÀûÓôæÔÚľÂí£¬£¬£¬ÒÑϰȾ900¶àÍòÉ豸


11ÔÂ23ÈÕ£¬£¬£¬Dr. WebµÄ×êÑÐÈËÔ±Åû¶»ªÎªÀûÓÃÉ̵êAppGalleryÖеÄ190¿îÓÎÏ·ÖдæÔÚľÂíAndroid.Cynos.7.origin£¬£¬£¬ÒÑ×°ÖÃÔ¼9300000´Î¡£¡£¡£¡£¸ÃľÂíÊǶñÒâÈí¼þCynosµÄ±äÌ壬£¬£¬Ö¼ÔÚÍøÂçÓû§µÄÐÅÏ¢¡£¡£¡£¡£ÕâЩÓÎÏ·ÖØÒªÊ¹ÓöíÓï¡¢¡¢¡¢ÖÐÎĺÍÓ¢Ó£¬£¬ÆäÖÐÓÎÏ·¡°¿ìµã¶ãÆðÀ´¡±µÄÏÂÔØÁ¿¸ß´ï2000000´Î¡£¡£¡£¡£×êÑÐÈËÔ±³Æ£¬£¬£¬¸ÃľÂí¿É·¢ËͺÍÀ¹½Ø¶ÌÐÅ¡¢¡¢¡¢ÏÂÔØºÍÆô¶¯ÆäËüÄ£¿é£¬£¬£¬ÒÔ¼°ÏÂÔØºÍ×°ÖÃÆäËûÀûÓᣡ£¡£¡£Ä¿Ç°£¬£¬£¬»ªÎª¹«Ë¾Òѽ«ÕâЩÓÎϷϼܡ£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º£º£º

https://securityaffairs.co/wordpress/124927/malware/android-cynos-7-origin-trojan-infections.html


5¡¢¡¢¡¢Kaspersky°ä²¼2021ÄêºÚÎåÆÚ¼äÚ¿Æ­»î¶¯µÄ·ÖÎö»ã±¨


11ÔÂ22ÈÕ£¬£¬£¬Kaspersky°ä²¼2021ÄêºÚÎåÆÚ¼äÚ¿Æ­»î¶¯µÄ·ÖÎö»ã±¨¡£¡£¡£¡£»ã±¨ÖØÒª·ÖÎöÁËÓëÈ«Çò½Ó¼ûÁ¿×î´óµÄÎå¸öÁãÊÛÆ½Ì¨£º£º£ºÎÖ¶ûÂê¡¢¡¢¡¢eBay¡¢¡¢¡¢ÑÇÂíÑ·¡¢¡¢¡¢°¢Àï°Í°ÍºÍ Mercado Libre¡£¡£¡£¡£×êÑз¢ÏÖ£¬£¬£¬2021Äêǰ10¸öÔ¼ì²âµ½40584415ÆðÕë¶ÔµçÉÌÆ½Ì¨ÒÔ¼°ÒøÐлú¹¹µÄ´¹µö¹¥»÷£»£»Õë¶Ôµç×ÓÖ§¸¶ÏµÍ³µÄ´¹µö»î¶¯Ôö³¤ÁË208%£»£»10ÔÂ27ÈÕÖÁ11ÔÂ19ÈÕ·¢ÏÖÁË221745·âÓëºÚÎåÓйصÄÓʼþ¡£¡£¡£¡£»ã±¨Ö¸³ö£¬£¬£¬ÐþÉ«ÐÇÆÚÎå²»½ö¶Ô¹ºÎïÕßÀ´ËµÊÇÖØÒªµÄÒ»Ì죬£¬£¬¶Ô¹¥»÷ÕßÀ´ËµÒ²ÊÇÈç´Ë¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º£º£º

https://securelist.com/black-friday-2021/104915/