ÐÅÏ¢Çå¾²Öܱ¨-2018ÄêµÚ35ÖÜ

Ðû²¼Ê±¼ä 2018-09-03

Ò»¡¢±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


        2018Äê08ÔÂ27ÈÕÖÁ9ÔÂ02ÈÕ¹²ÊÕ¼Çå¾²Îó²î54¸ö£¬£¬£¬£¬ £¬ÖµµÃ¹Ø×¢µÄÊÇÌÚѶFoxmailÏÂÁî×¢ÈëÎó²î£»£»OpenSSH auth-gss2.cÓû§Ã¶¾ÙÎó²î£»£»Google Chrome Blob API»º³åÇøÒç³öÎó²î£»£»Emerson DeltaV DCS Workstation»º³åÇøÒç³öÎó²î£»£»Adobe Acrobat/Reader CVE-2018-12808Ô½½çдí§Òâ´úÂëÖ´ÐÐÎó²î¡£¡£¡£


        ±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊǰ®¶ûÀ¼µçÐŹ«Ë¾EirµÄһ̨Ìõ¼Ç±¾±»µÁ£¬£¬£¬£¬ £¬µ¼ÖÂÔ¼3.7ÍòÓû§µÄÐÅϢй¶;AppleÔÚÏßÊÐËÁÖеÄÎó²îµ¼ÖÂÁè¼Ý7700ÍòT-MobileÓû§ÕË»§µÄPINÂë̻¶;AbbyyÒòÊý¾Ý¿âÉèÖùýʧµ¼ÖÂ20¶àÍò¸ö¿Í»§Îļþй¶;Î÷°àÑÀÒøÐйÙÍøÔâµ½DDoS¹¥»÷£¬£¬£¬£¬ £¬ÍøÕ¾ÔÝʱÎÞ·¨»á¼û;¼ÓÄô󺽿չ«Ë¾ÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬ £¬Ô¼2ÍòÃûÓû§µÄÐÅÏ¢ÒÉй¶¡£¡£¡£


        ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬ £¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£


 


¶þ¡¢Ö÷ÒªÇå¾²Îó²îÁбí


1¡¢ÌÚѶFoxmailÏÂÁî×¢ÈëÎó²î


        Tencent Foxmail URI´¦Öóͷ£±£´æÊäÈëÑéÖ¤Îó²î£¬£¬£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþ»òÒ³ÃæÇëÇ󣬣¬£¬£¬ £¬ÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£


        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://www.zerodayinitiative.com/advisories/ZDI-18-584/


2¡¢OpenSSH auth-gss2.cÓû§Ã¶¾ÙÎó²î


        OpenSSH auth-gss2.c±£´æÇå¾²Îó²î£¬£¬£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬ £¬ÅжÏÓû§Ãû¡£¡£¡£


        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttp://seclists.org/oss-sec/2018/q3/180


3¡¢Google Chrome Blob API»º³åÇøÒç³öÎó²î


        Google Chrome Blob API±£´æ¶ÑÒç³öÎó²î£¬£¬£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄWEBÒ³£¬£¬£¬£¬ £¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬ £¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£


        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://chromereleases.googleblog.com/2017/12/stable-channel-update-for-desktop.html


4¡¢Emerson DeltaV DCS Workstation»º³åÇøÒç³öÎó²î


        Emerson Electric DeltaV¿ª·ÅͨѶ¶Ë¿Ú±£´æÕ»Òç³öÎó²î£¬£¬£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬ £¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£


        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://ics-cert.us-cert.gov/advisories/ICSA-18-228-01


5¡¢Adobe Acrobat/Reader CVE-2018-12808Ô½½çдí§Òâ´úÂëÖ´ÐÐÎó²î


        Adobe Acrobat/Reader´¦Öóͷ£PDFÎļþ±£´æÔ½½çдÎó²î£¬£¬£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþÇëÇ󣬣¬£¬£¬ £¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬ £¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£


        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://helpx.adobe.com/security/products/acrobat/apsb18-29.html


 


Èý¡¢Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢°®¶ûÀ¼µçÐŹ«Ë¾EirµÄһ̨Ìõ¼Ç±¾±»µÁ£¬£¬£¬£¬ £¬µ¼ÖÂÔ¼3.7ÍòÓû§µÄÐÅϢй¶



ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


        ƾ֤°®¶ûÀ¼µçÐŹ«Ë¾Eir¹ÙÍøÉϵÄ֪ͨ£¬£¬£¬£¬ £¬¸Ã¹«Ë¾µÄһ̨°üÀ¨Óû§Êý¾ÝµÄδ¼ÓÃܵÄÌõ¼Ç±¾µçÄÔÔâÇÔ£¬£¬£¬£¬ £¬µ¼ÖÂÔ¼3.7ÍòÓû§µÄСÎÒ˽¼ÒÐÅϢй¶¡£¡£¡£Ð¹Â¶µÄÊý¾Ý°üÀ¨ÐÕÃû¡¢µç×ÓÓʼþµØµã¡¢µç»°ºÅÂëºÍeirÕ˺𣡣¡£¸Ã¹«Ë¾³ÆÐ¹Â¶µÄÊý¾Ý²»°üÀ¨ÈκÎÓû§µÄ²ÆÎñÊý¾Ý¡£¡£¡£ÏÖÔڸù«Ë¾ÒÑÏòÊý¾Ý±£»£»¤×¨Ô±ºÍ°®¶ûÀ¼¾¯Ô±×ª´ïÁË´Ë´ÎÊÂÎñ¡£¡£¡£


        Ô­ÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/75655/data-breach/eir-data-breach.html


2¡¢AppleÔÚÏßÊÐËÁÖеÄÎó²îµ¼ÖÂÁè¼Ý7700ÍòT-MobileÓû§ÕË»§µÄPINÂë̻¶



ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


        ƾ֤ÃÀýBuzzFeedNewsµÄ±¨µÀ£¬£¬£¬£¬ £¬AppleÔÚÏßÊÐËÁÖеÄÎó²îµ¼ÖÂÁè¼Ý7700ÍòT-MobileÓû§ÕË»§µÄPINÂë̻¶¡£¡£¡£±ðµÄ£¬£¬£¬£¬ £¬ÊÖ»ú°ü¹Ü¹«Ë¾AsurionµÄ¹ÙÍøÒ²±£´æÒ»¸öÎó²î£¬£¬£¬£¬ £¬µ¼ÖÂAsurionµÄAT£¦T¿Í»§µÄPINÂë̻¶¡£¡£¡£ÕâÁ½¸öÎó²îÊÇÓÉÇå¾²Ñо¿Ö°Ô±PhobiaºÍNicholas ¡°Convict¡± Ceraolo·¢Ã÷µÄ¡£¡£¡£AppleÍøÕ¾ÉϵÄÎó²î¿ÉÄÜÓ뼯³ÉT-MobileµÄÕÊ»§ÑéÖ¤APIʱµÄ¹¤³Ì¹ýʧÓйء£¡£¡£AppleºÍAsurionÒѾ­ÐÞ¸´ÁËÏà¹ØÎó²î¡£¡£¡£


        Ô­ÎÄÁ´½Ó£ºhttps://www.buzzfeednews.com/article/nicolenguyen/tmobile-att-account-pin-security-flaw-apple


3¡¢AbbyyÒòÊý¾Ý¿âÉèÖùýʧµ¼ÖÂ20¶àÍò¸ö¿Í»§Îļþй¶

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


        8ÔÂ19ÈÕÇå¾²Ñо¿Ö°Ô±Bob DiachenkoÔÚAWSÔÆÆ½Ì¨ÉÏ·¢Ã÷ÊôÓÚOCRÈí¼þ¿ª·¢ÉÌAbbyyµÄÒ»¸öMongoDBЧÀÍÆ÷ÎÞÐèµÇ¼¼´¿É¹ûÕæ»á¼û¡£¡£¡£¸ÃÊý¾Ý¿â¾ÞϸΪ142GB£¬£¬£¬£¬ £¬°üÀ¨¶àÖÖÃô¸ÐÎļþµÄɨÃè¼þ£¬£¬£¬£¬ £¬ÈçÌõÔ¼¡¢±£ÃÜЭÒé¡¢ÄÚ²¿Ðżþ¼°±¸Íü¼µÈ¡£¡£¡£ÆäÖаüÀ¨ÊôÓÚAbbyy¿Í»§µÄ20¶àÍò¸öÎļþ¡£¡£¡£¸ÃÊý¾Ý¿â¿ÉÄÜÊÇAbbyyµÄ»ù´¡ÉèÊ©µÄÒ»²¿·Ö¡£¡£¡£AbbyyµÄÇå¾²ÍŶÓÔÚ½Óµ½Í¨ÖªÁ½ÌìºóÐÞ¸´Á˸ÃÊý¾Ý¿âµÄÉèÖùýʧÎÊÌâ¡£¡£¡£


        Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/ocr-software-dev-exposes-200-000-customer-documents/


4¡¢Î÷°àÑÀÒøÐйÙÍøÔâµ½DDoS¹¥»÷£¬£¬£¬£¬ £¬ÍøÕ¾ÔÝʱÎÞ·¨»á¼û



ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


        ƾ֤·͸ÉçµÄ±¨µÀ£¬£¬£¬£¬ £¬´Ó8ÔÂ26ÈÕÐÇÆÚÈÕ×îÏÈÎ÷°àÑÀÒøÐеĹÙÍøÔâµ½ÁËÂþÑÜʽ¾Ü¾øÐ§À͹¥»÷£¨DDoS£©£¬£¬£¬£¬ £¬ÆäÍøÕ¾ÔÝʱÎÞ·¨»á¼û¡£¡£¡£¸ÃÒøÐеĽ²»°ÈËÌåÏÖ£¬£¬£¬£¬ £¬´Ë´Î¹¥»÷¶Ô¸ÃÒøÐеÄЧÀÍ»ò¸ÃÒøÐÐÓëÅ·ÖÞÖÐÑëÒøÐлòÆäËü»ú¹¹µÄͨѶûÓÐÔì³ÉÈκÎÓ°Ï죬£¬£¬£¬ £¬²¢ÇÒûÓÐÈκÎÊý¾Ýй¶µÄΣº¦¡£¡£¡£×èÖ¹ÖܶþÏÂÖ磬£¬£¬£¬ £¬¸ÃÒøÐеÄÍøÕ¾ÈÔ´¦ÓÚÀëÏß״̬¡£¡£¡£


        Ô­ÎÄÁ´½Ó£ºhttps://uk.reuters.com/article/us-spain-cyber-cenbank/bank-of-spains-website-hit-by-cyber-attack-idUKKCN1LC23B


5¡¢¼ÓÄô󺽿չ«Ë¾ÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬ £¬Ô¼2ÍòÃûÓû§µÄÐÅÏ¢ÒÉй¶


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾



        8ÔÂ22ÈÕÖÁ24ÈÕʱ´ú£¬£¬£¬£¬ £¬¼ÓÄô󺽿չ«Ë¾·¢Ã÷Òì³£µÄµÇ¼»î¶¯£¬£¬£¬£¬ £¬ÎªÁ˱£»£»¤Óû§µÄÊý¾Ý£¬£¬£¬£¬ £¬¸Ã¹«Ë¾Ëø¶¨ÁËËùÓÐ170ÍòÒÆ¶¯appÓû§µÄÕË»§¡£¡£¡£29ÈÕ£¬£¬£¬£¬ £¬¸Ã¹«Ë¾Í¨ÖªÔ¼2ÍòÃûÓû§£¬£¬£¬£¬ £¬³ÆÆäСÎÒ˽¼Ò×ÊÁÏ¿ÉÄÜÔ⵽δÊÚȨµÄ»á¼û¡£¡£¡£ÕâЩ×ÊÁÏÖÁÉÙ°üÀ¨ÐÕÃû¡¢µç×ÓÓʼþµØµãºÍµç»°ºÅÂ룬£¬£¬£¬ £¬Ò²¿ÉÄܰüÀ¨ÐԱ𡢳öÉúÈÕÆÚ¡¢¹ú¼®¡¢»¤ÕÕºÅÂëµÈÐÅÏ¢¡£¡£¡£ÔÚÒ»·Ý¹ØÓÚ¸ÃÊÂÎñµÄÉùÃ÷Öиù«Ë¾ÌåÏÖÓû§µÄÒøÐп¨Êý¾ÝÒÔ¼°aircanada.comÕÊ»§²»ÊÜÓ°Ïì¡£¡£¡£


        Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/air-canada-mobile-app-users-affected-by-data-breach/