Libarchive´úÂëÖ´ÐÐÎó²îÓ°ÏìLinux¼°BSD¿¯Ðа棻£»£»£»£»£»Ç÷ÊÆ¿Æ¼¼ÄÚ²¿Ô±¹¤ÇÔÈ¡Áè¼Ý12ÍòÓû§ÐÅÏ¢²¢³öÊÛ
Ðû²¼Ê±¼ä 2019-11-07
¹È¸èÇå¾²Ñо¿Ö°Ô±ÔÚLibarchiveÖз¢Ã÷Ò»¸ö´úÂëÖ´ÐÐÎó²î£¨CVE-2019-18408£©£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÓÕʹÓû§·¿ª¶ñÒâ´æµµÎļþÔÚÆäϵͳÉÏÖ´ÐдúÂë¡£¡£Debian¡¢Ubuntu¡¢Gentoo¡¢Arch LinuxÒÔ¼°FreeBSDºÍNetBSD¿¯Ðаæ¾ùÊÜÓ°Ï죬£¬£¬£¬£¬µ«WindowsºÍmacOS²»ÊÜÓ°Ïì¡£¡£LibarchiveÍŶÓÔÚа汾3.4.0ÖÐÐÞ¸´Á˸ÃÎó²î£¬£¬£¬£¬£¬ÏÖÔÚÉÐδÔÚÒ°Íâ·¢Ã÷¸ÃÎó²îµÄPoC»òʹÓôúÂë¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/libarchive-vulnerability-can-lead-to-code-execution-on-linux-freebsd-netbsd/2¡¢¹È¸èÐû²¼11ÔÂAndroidÇå¾²¸üУ¬£¬£¬£¬£¬ÐÞ¸´40¸öÎó²î
¹È¸è±¾ÖÜÐû²¼11ÔÂAndroidÇå¾²¸üУ¬£¬£¬£¬£¬ÐÞ¸´Á˽ü40¸öÎó²î¡£¡£¹È¸èÔÚ2019-11-01Çå¾²²¹¶¡³ÌÐò¼¶±ðÖÐÐÞ¸´ÁËFramework¡¢Library¡¢Ã½Ìå¿ò¼ÜºÍϵͳÖеÄ17¸öÎó²î£¬£¬£¬£¬£¬ÆäÖÐ×îÑÏÖØµÄÎó²îÊÇϵͳ×é¼þÖеÄÈý¸öRCEÎó²î£¨CVE-2019-2204~CVE-2019-2206£©£¬£¬£¬£¬£¬ÊÜÓ°ÏìµÄϵͳ°æ±¾Îª8.0¡¢8.1¡¢9ºÍ10¡£¡£¹È¸è»¹ÔÚ2019-11-05Çå¾²²¹¶¡³ÌÐò¼¶±ðÖÐÐÞ¸´ÁË21¸öÎó²î£¬£¬£¬£¬£¬ÆäÖÐ×îÑÏÖØµÄÊǸßͨ×é¼þÖеÄ5¸öÎó²î¡£¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/google-patches-critical-flaws-androids-system-component3¡¢NVIDIAÐÞ¸´ÏÔ¿¨Çý¶¯¼°GeForce Experience 12¸öÎó²î
NVIDIAÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬ÐÞ¸´ÆäÏÔ¿¨Çý¶¯³ÌÐòºÍGFEÈí¼þÖеÄ12¸öÎó²î£¬£¬£¬£¬£¬Îó²î¹æÄ£º¸Ç´úÂëÖ´ÐС¢È¨ÏÞÌáÉý¡¢ÐÅϢй¶ºÍ¾Ü¾øÐ§ÀÍ¡£¡£ËùÓеÄÎó²î¶¼²»¿É±»Ô¶³ÌʹÓ㬣¬£¬£¬£¬±ØÐèÍâµØÓû§»á¼û£¬£¬£¬£¬£¬²¢ÇÒ¹¥»÷Õß±ØÐèÒÀÀµÓû§½»»¥À´Ê¹ÓÃËüÃÇ¡£¡£ÕâЩÎó²îµÄCVSS V3ÆÀ·ÖΪ5.1µ½7.8Ö®¼ä£¬£¬£¬£¬£¬ÆäÖÐ4¸ö¸ßΣÎó²îΪÏÔ¿¨Çý¶¯ÖеĻº³åÇøÒç³ö£¨CVE?2019?5690£©¡¢¿ÕÖ¸Õë½âÒýÓã¨CVE?2019?5691£©¡¢Êý×éË÷ÒýÔ½½ç£¨CVE?2019?5692£©ÒÔ¼°GFEÖеÄDLLÐ®ÖÆ£¨CVE?2019?5701£©¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/nvidia-fixes-security-flaws-in-gpu-driver-geforce-experience/4¡¢FacebookÔÙÆØÒþ˽й¶£¬£¬£¬£¬£¬¿ª·¢Ö°Ô±Î¥¹æ»á¼ûÓû§ÐÅÏ¢
FacebookÔÙÆØÒþ˽й¶ÊÂÎñ£¬£¬£¬£¬£¬Ô¼100Ãû¿ª·¢Ö°Ô±¿ÉÎ¥¹æ»á¼ûÓû§ÐÅÏ¢¡£¡£±¾ÖܶþFacebookƽ̨ÏàÖú×ܼàKonstantinos PapamiltiadisÔÚһƪ²©ÎÄÖÐ͸¶£¬£¬£¬£¬£¬Ö»¹Ü2018Äê4ÔÂÔø¶ÔÆäȨÏÞ¾ÙÐÐÏÞÖÆ£¬£¬£¬£¬£¬µ«²¿·Ö¿ª·¢Ö°Ô±ÈÔ¿ÉÒÔ»á¼ûÓû§µÄÐÕÃû¡¢Ð¡ÎÒ˽¼Ò×ÊÁÏͼƬÒÔ¼°ÏµÍ³APIµÈÐÅÏ¢¡£¡£×ܹ²Ô¼ÓÐ100Ãû¿ª·¢Ö°Ô±¿ÉÒÔ»á¼û´ËÐÅÏ¢£¬£¬£¬£¬£¬FacebookÈ·ÈÏÖÁÉÙÓÐ11Ãû¿ª·¢Ö°Ô±ÔÚÒÑÍù60ÌìÄÚ»á¼ûÁËÕâЩÊý¾Ý¡£¡£¸Ã¹«Ë¾ÌåÏÖÒѾ×÷·ÏÁËÕâÒ»»á¼ûȨÏÞ£¬£¬£¬£¬£¬²¢ÌåÏÖ»á¶ÔÏà¹ØÇéÐξÙÐÐÉó²é¡£¡£¸Ã¹«Ë¾Ã»ÓÐ͸¶Óм¸¶àÓû§Êܵ½Ó°Ïì¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/facebook-reveals-another-data-breach-this-time-involving-developers/
5¡¢Ç÷ÊÆ¿Æ¼¼ÄÚ²¿Ô±¹¤ÇÔÈ¡Áè¼Ý12ÍòÓû§ÐÅÏ¢²¢³öÊÛ
Ç÷ÊÆ¿Æ¼¼ÄÚ²¿Ô±¹¤ÇÔÈ¡¹«Ë¾¿Í»§ÐÅÏ¢²¢½«Æä³öÊÛ¸øµÚÈý·½Õ©ÆÍŻ¡£ÔÚ¿Í»§Ôâµ½ÊÖÒÕÖ§³Öթƺ󣬣¬£¬£¬£¬Ç÷ÊÆ¿Æ¼¼Õö¿ªÊӲ첢·¢Ã÷¸ÃÔ±¹¤²»·¨»á¼ûÁ˿ͻ§Ö§³ÖÊý¾Ý¿â¡£¡£¿£¿£¿ÉÄܱ»ÇÔµÄÐÅÏ¢°üÀ¨¿Í»§µÄÐÕÃû¡¢µç×ÓÓʼþµØµã¡¢ÊÖÒÕÖ§³Öµ¥ºÅÒÔ¼°µç»°ºÅÂ룬£¬£¬£¬£¬µ«¸Ã¹«Ë¾Ç¿µ÷ûÓм£ÏóÅú×¢²ÆÎñ»òÐÅÓÿ¨ÐÅÏ¢±»ÇÔ£¬£¬£¬£¬£¬²¢ÇÒûÓÐÉæ¼°µ½ÆóÒµ»òÕþ¸®¿Í»§¡£¡£Æ¾Ö¤ÆäÄÚ²¿ÊӲ죬£¬£¬£¬£¬ÊÜÓ°ÏìµÄ¿Í»§Ö»Õ¼Ç÷ÊÆ¿Æ¼¼1200Íò¿Í»§ÈºµÄ²»µ½1%£¬£¬£¬£¬£¬¼´12Íò¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/trendmicro-employee-sold-customer-info-to-tech-support-scammers/
6¡¢AnonymousºÍLulzSecITAÈëÇÖÒâ´óÀûÔËÓªÉÌLyca Mobile
AnonymousºÍLulzSecITAÈëÇÖÒâ´óÀûͨѶÔËÓªÉÌLyca Mobile£¬£¬£¬£¬£¬´Ó¸Ã¹«Ë¾ÇÔÈ¡ÁË5.4GBµÄÎļþ¡£¡£´Óй¶µÄÎļþÀ´¿´£¬£¬£¬£¬£¬ÎĵµÖаüÀ¨Lyca MobileÓû§µÄ¹«¹²ID¡¢»¤ÕÕ¡¢¼ÝÕÕ¡¢µç»°¼Í¼¼°ÐÅÓÿ¨ÐÅÏ¢µÈ¡£¡£ÆäÖÐÒ»¸öÎļþ¼ÐµÄÄÚÈÝËÆºõÊôÓڸù«Ë¾µÄ¹Ù·½ÓÊÏäÕË»§lycamobile[at]lycamobile[.]it¡£¡£ÏÖÔÚÉÐÎÞ·¨ÑéÖ¤ÕâЩÎĵµµÄÕæÊµÐÔ¡£¡£ÐÒÔ˵ÄÊǺڿÍ×éÖ¯ÌᳫÕâЩ¹¥»÷Ö»ÊÇΪÁËÑéÖ¤ÆäÇå¾²ÐÔ£¬£¬£¬£¬£¬¶ø²»ÊǶÔÓû§¾ÙÐÐڲơ£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/93474/hacktivism/lulzsecita-lyca-mobile.html


¾©¹«Íø°²±¸11010802024551ºÅ