ÐÅÏ¢Çå¾²Öܱ¨-2018ÄêµÚ35ÖÜ

Ðû²¼Ê±¼ä 2018-09-03

Ò»¡¢±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


        2018Äê08ÔÂ27ÈÕÖÁ9ÔÂ02ÈÕ¹²ÊÕ¼Çå¾²Îó²î54¸ö£¬£¬ £¬ÖµµÃ¹Ø×¢µÄÊÇÌÚѶFoxmailÏÂÁî×¢ÈëÎó²î£» £»£»£»£»£»OpenSSH auth-gss2.cÓû§Ã¶¾ÙÎó²î£» £»£»£»£»£»Google Chrome Blob API»º³åÇøÒç³öÎó²î£» £»£»£»£»£»Emerson DeltaV DCS Workstation»º³åÇøÒç³öÎó²î£» £»£»£»£»£»Adobe Acrobat/Reader CVE-2018-12808Ô½½çдí§Òâ´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£


        ±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊǰ®¶ûÀ¼µçÐŹ«Ë¾EirµÄһ̨Ìõ¼Ç±¾±»µÁ£¬£¬ £¬µ¼ÖÂÔ¼3.7ÍòÓû§µÄÐÅϢй¶;AppleÔÚÏßÊÐËÁÖеÄÎó²îµ¼ÖÂÁè¼Ý7700ÍòT-MobileÓû§ÕË»§µÄPINÂë̻¶;AbbyyÒòÊý¾Ý¿âÉèÖùýʧµ¼ÖÂ20¶àÍò¸ö¿Í»§Îļþй¶;Î÷°àÑÀÒøÐйÙÍøÔâµ½DDoS¹¥»÷£¬£¬ £¬ÍøÕ¾ÔÝʱÎÞ·¨»á¼û;¼ÓÄô󺽿չ«Ë¾ÔâºÚ¿ÍÈëÇÖ£¬£¬ £¬Ô¼2ÍòÃûÓû§µÄÐÅÏ¢ÒÉй¶¡£¡£¡£¡£


        ƾ֤ÒÔÉÏ×ÛÊö£¬£¬ £¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£


 


¶þ¡¢Ö÷ÒªÇå¾²Îó²îÁбí


1¡¢ÌÚѶFoxmailÏÂÁî×¢ÈëÎó²î


        Tencent Foxmail URI´¦Öóͷ£±£´æÊäÈëÑéÖ¤Îó²î£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþ»òÒ³ÃæÇëÇ󣬣¬ £¬ÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£


        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://www.zerodayinitiative.com/advisories/ZDI-18-584/


2¡¢OpenSSH auth-gss2.cÓû§Ã¶¾ÙÎó²î


        OpenSSH auth-gss2.c±£´æÇå¾²Îó²î£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬ £¬ÅжÏÓû§Ãû¡£¡£¡£¡£


        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttp://seclists.org/oss-sec/2018/q3/180


3¡¢Google Chrome Blob API»º³åÇøÒç³öÎó²î


        Google Chrome Blob API±£´æ¶ÑÒç³öÎó²î£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄWEBÒ³£¬£¬ £¬ÓÕʹÓû§ÆÊÎö£¬£¬ £¬¿ÉʹӦÓóÌÐò±ÀÀ£» £»£»£»£»£»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£


        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://chromereleases.googleblog.com/2017/12/stable-channel-update-for-desktop.html


4¡¢Emerson DeltaV DCS Workstation»º³åÇøÒç³öÎó²î


        Emerson Electric DeltaV¿ª·ÅͨѶ¶Ë¿Ú±£´æÕ»Òç³öÎó²î£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬ £¬¿ÉʹӦÓóÌÐò±ÀÀ£» £»£»£»£»£»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£


        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://ics-cert.us-cert.gov/advisories/ICSA-18-228-01


5¡¢Adobe Acrobat/Reader CVE-2018-12808Ô½½çдí§Òâ´úÂëÖ´ÐÐÎó²î


        Adobe Acrobat/Reader´¦Öóͷ£PDFÎļþ±£´æÔ½½çдÎó²î£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþÇëÇ󣬣¬ £¬ÓÕʹÓû§ÆÊÎö£¬£¬ £¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£


        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://helpx.adobe.com/security/products/acrobat/apsb18-29.html


 


Èý¡¢Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢°®¶ûÀ¼µçÐŹ«Ë¾EirµÄһ̨Ìõ¼Ç±¾±»µÁ£¬£¬ £¬µ¼ÖÂÔ¼3.7ÍòÓû§µÄÐÅϢй¶



c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


        ƾ֤°®¶ûÀ¼µçÐŹ«Ë¾Eir¹ÙÍøÉϵÄ֪ͨ£¬£¬ £¬¸Ã¹«Ë¾µÄһ̨°üÀ¨Óû§Êý¾ÝµÄδ¼ÓÃܵÄÌõ¼Ç±¾µçÄÔÔâÇÔ£¬£¬ £¬µ¼ÖÂÔ¼3.7ÍòÓû§µÄСÎÒ˽¼ÒÐÅϢй¶¡£¡£¡£¡£Ð¹Â¶µÄÊý¾Ý°üÀ¨ÐÕÃû¡¢µç×ÓÓʼþµØµã¡¢µç»°ºÅÂëºÍeirÕ˺Å¡£¡£¡£¡£¸Ã¹«Ë¾³ÆÐ¹Â¶µÄÊý¾Ý²»°üÀ¨ÈκÎÓû§µÄ²ÆÎñÊý¾Ý¡£¡£¡£¡£ÏÖÔڸù«Ë¾ÒÑÏòÊý¾Ý±£» £»£»£»£»£»¤×¨Ô±ºÍ°®¶ûÀ¼¾¯Ô±×ª´ïÁË´Ë´ÎÊÂÎñ¡£¡£¡£¡£


        Ô­ÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/75655/data-breach/eir-data-breach.html


2¡¢AppleÔÚÏßÊÐËÁÖеÄÎó²îµ¼ÖÂÁè¼Ý7700ÍòT-MobileÓû§ÕË»§µÄPINÂë̻¶



c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


        ƾ֤ÃÀýBuzzFeedNewsµÄ±¨µÀ£¬£¬ £¬AppleÔÚÏßÊÐËÁÖеÄÎó²îµ¼ÖÂÁè¼Ý7700ÍòT-MobileÓû§ÕË»§µÄPINÂë̻¶¡£¡£¡£¡£±ðµÄ£¬£¬ £¬ÊÖ»ú°ü¹Ü¹«Ë¾AsurionµÄ¹ÙÍøÒ²±£´æÒ»¸öÎó²î£¬£¬ £¬µ¼ÖÂAsurionµÄAT£¦T¿Í»§µÄPINÂë̻¶¡£¡£¡£¡£ÕâÁ½¸öÎó²îÊÇÓÉÇå¾²Ñо¿Ö°Ô±PhobiaºÍNicholas ¡°Convict¡± Ceraolo·¢Ã÷µÄ¡£¡£¡£¡£AppleÍøÕ¾ÉϵÄÎó²î¿ÉÄÜÓ뼯³ÉT-MobileµÄÕÊ»§ÑéÖ¤APIʱµÄ¹¤³Ì¹ýʧÓйØ¡£¡£¡£¡£AppleºÍAsurionÒѾ­ÐÞ¸´ÁËÏà¹ØÎó²î¡£¡£¡£¡£


        Ô­ÎÄÁ´½Ó£ºhttps://www.buzzfeednews.com/article/nicolenguyen/tmobile-att-account-pin-security-flaw-apple


3¡¢AbbyyÒòÊý¾Ý¿âÉèÖùýʧµ¼ÖÂ20¶àÍò¸ö¿Í»§Îļþй¶

c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


        8ÔÂ19ÈÕÇå¾²Ñо¿Ö°Ô±Bob DiachenkoÔÚAWSÔÆÆ½Ì¨ÉÏ·¢Ã÷ÊôÓÚOCRÈí¼þ¿ª·¢ÉÌAbbyyµÄÒ»¸öMongoDBЧÀÍÆ÷ÎÞÐèµÇ¼¼´¿É¹ûÕæ»á¼û¡£¡£¡£¡£¸ÃÊý¾Ý¿â¾ÞϸΪ142GB£¬£¬ £¬°üÀ¨¶àÖÖÃô¸ÐÎļþµÄɨÃè¼þ£¬£¬ £¬ÈçÌõÔ¼¡¢±£ÃÜЭÒé¡¢ÄÚ²¿Ðżþ¼°±¸Íü¼µÈ¡£¡£¡£¡£ÆäÖаüÀ¨ÊôÓÚAbbyy¿Í»§µÄ20¶àÍò¸öÎļþ¡£¡£¡£¡£¸ÃÊý¾Ý¿â¿ÉÄÜÊÇAbbyyµÄ»ù´¡ÉèÊ©µÄÒ»²¿·Ö¡£¡£¡£¡£AbbyyµÄÇå¾²ÍŶÓÔÚ½Óµ½Í¨ÖªÁ½ÌìºóÐÞ¸´Á˸ÃÊý¾Ý¿âµÄÉèÖùýʧÎÊÌâ¡£¡£¡£¡£


        Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/ocr-software-dev-exposes-200-000-customer-documents/


4¡¢Î÷°àÑÀÒøÐйÙÍøÔâµ½DDoS¹¥»÷£¬£¬ £¬ÍøÕ¾ÔÝʱÎÞ·¨»á¼û



c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


        ƾ֤·͸ÉçµÄ±¨µÀ£¬£¬ £¬´Ó8ÔÂ26ÈÕÐÇÆÚÈÕ×îÏÈÎ÷°àÑÀÒøÐеĹÙÍøÔâµ½ÁËÂþÑÜʽ¾Ü¾øÐ§À͹¥»÷£¨DDoS£©£¬£¬ £¬ÆäÍøÕ¾ÔÝʱÎÞ·¨»á¼û¡£¡£¡£¡£¸ÃÒøÐеĽ²»°ÈËÌåÏÖ£¬£¬ £¬´Ë´Î¹¥»÷¶Ô¸ÃÒøÐеÄЧÀÍ»ò¸ÃÒøÐÐÓëÅ·ÖÞÖÐÑëÒøÐлòÆäËü»ú¹¹µÄͨѶûÓÐÔì³ÉÈκÎÓ°Ï죬£¬ £¬²¢ÇÒûÓÐÈκÎÊý¾Ýй¶µÄΣº¦¡£¡£¡£¡£×èÖ¹ÖܶþÏÂÖ磬£¬ £¬¸ÃÒøÐеÄÍøÕ¾ÈÔ´¦ÓÚÀëÏß״̬¡£¡£¡£¡£


        Ô­ÎÄÁ´½Ó£ºhttps://uk.reuters.com/article/us-spain-cyber-cenbank/bank-of-spains-website-hit-by-cyber-attack-idUKKCN1LC23B


5¡¢¼ÓÄô󺽿չ«Ë¾ÔâºÚ¿ÍÈëÇÖ£¬£¬ £¬Ô¼2ÍòÃûÓû§µÄÐÅÏ¢ÒÉй¶


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú



        8ÔÂ22ÈÕÖÁ24ÈÕʱ´ú£¬£¬ £¬¼ÓÄô󺽿չ«Ë¾·¢Ã÷Òì³£µÄµÇ¼»î¶¯£¬£¬ £¬ÎªÁ˱£» £»£»£»£»£»¤Óû§µÄÊý¾Ý£¬£¬ £¬¸Ã¹«Ë¾Ëø¶¨ÁËËùÓÐ170ÍòÒÆ¶¯appÓû§µÄÕË»§¡£¡£¡£¡£29ÈÕ£¬£¬ £¬¸Ã¹«Ë¾Í¨ÖªÔ¼2ÍòÃûÓû§£¬£¬ £¬³ÆÆäСÎÒ˽¼Ò×ÊÁÏ¿ÉÄÜÔ⵽δÊÚȨµÄ»á¼û¡£¡£¡£¡£ÕâЩ×ÊÁÏÖÁÉÙ°üÀ¨ÐÕÃû¡¢µç×ÓÓʼþµØµãºÍµç»°ºÅÂ룬£¬ £¬Ò²¿ÉÄܰüÀ¨ÐԱ𡢳öÉúÈÕÆÚ¡¢¹ú¼®¡¢»¤ÕÕºÅÂëµÈÐÅÏ¢¡£¡£¡£¡£ÔÚÒ»·Ý¹ØÓÚ¸ÃÊÂÎñµÄÉùÃ÷Öиù«Ë¾ÌåÏÖÓû§µÄÒøÐп¨Êý¾ÝÒÔ¼°aircanada.comÕÊ»§²»ÊÜÓ°Ïì¡£¡£¡£¡£


        Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/air-canada-mobile-app-users-affected-by-data-breach/