ÐÅÏ¢Çå¾²Öܱ¨-2018ÄêµÚ27ÖÜ
Ðû²¼Ê±¼ä 2018-07-09Ò»¡¢±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö
2018Äê07ÔÂ02ÈÕÖÁ08ÈÕ¹²ÊÕ¼Çå¾²Îó²î54¸ö£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇSchneider Electric U.motion Builder CVE-2018-7777Ô¶³Ì´úÂëÖ´ÐÐÎó²î£»£»£»£»Medtronic MyCareLink Patient MonitorÓ²±àÂëÃÜÂëÎó²î£»£»£»£»GraphicsMagick coders/png.cÎļþµÄ¡®ReadMNGImage¡¯º¯Êý»º³åÇøÒç³öÎó²î£»£»£»£»Mozilla Firefox/Firefox ESR¶à¸öÄÚ´æÆÆËðÎó²î£»£»£»£»Linux kernel fs/xfs/libxfs/xfs_inode_buf.c¾Ü¾øÐ§ÀÍÎó²î¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇÃÀ¹ú¹ú¼ÒÇå¾²¾Ö£¨NSA£©ÉÏÖÜÐû²¼½«É¾³ýÊýÒÔÒڼƵĵ绰ºÍ¶ÌÐżÍ¼£»£»£»£»FacebookÈÏ¿ÉÏò61¼Ò¹«Ë¾Ìṩ¶ÔÆäÓû§Êý¾ÝµÄÌØÊâ»á¼ûȨÏÞ£»£»£»£»Ñо¿»ú¹¹Ðû²¼2018ÄêÏÄÈÕ»¥ÁªÍøÇå¾²±¨¸æ£¬£¬£¬£¬£¬£¬ÖØµã¹Ø×¢DDoS¹¥»÷£»£»£»£»Gentoo LinuxÍŶӳƹ¥»÷Õßͨ¹ýÃÜÂëÍÆ²â»ñµÃÆäGitHubÕË»§µÄÃÜÂ룻£»£»£»Ñо¿Ö°Ô±·¢Ã÷ʹÓÃPROPagate´úÂë×¢ÈëÊÖÒյĶñÒâ¹¥»÷»î¶¯¡£¡£
ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£
¶þ¡¢Ö÷ÒªÇå¾²Îó²îÁбí
1¡¢Schneider Electric U.motion Builder CVE-2018-7777Ô¶³Ì´úÂëÖ´ÐÐÎó²î
Schneider Electric U.motion Builder software±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬¶ñÒâ¿Í»§¶Ë¿ÉÉÏ´«²¢Ê¹smbdЧÀÍÆ÷Ö´Ðй²Ïí¿â¡£¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£º
https://www.schneider-electric.com/en/download/document/SEVD-2018-095-01/
2¡¢Medtronic MyCareLink Patient MonitorÓ²±àÂëÃÜÂëÎó²î
Medtronic MyCareLink Patient Monitor±£´æÓ²±àÂëÃÜÂëÎó²î£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬Ö´ÐÐí§Òâ´úÂë¡£¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://ics-cert.us-cert.gov/advisories/ICSMA-18-179-01
3¡¢GraphicsMagick coders/png.cÎļþµÄ¡®ReadMNGImage¡¯º¯Êý»º³åÇøÒç³öÎó²î
GraphicsMagick coders/png.cÎļþµÄ¡®ReadMNGImage¡¯º¯Êý±£´æ¶Ñ»º³åÇøÒç³öÎó²î£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²î¹¹½¨¶ñÒâÎļþ£¬£¬£¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬£¬£¬¿ÉʹӦÓóÌÐòÍ߽⡣¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://sourceforge.net/p/graphicsmagick/bugs/535/
4¡¢Mozilla Firefox/Firefox ESR¶à¸öÄÚ´æÆÆËðÎó²î
Mozilla Firefox/Firefox ESR±£´æÄÚ´æÆÆËðÎó²î£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²î¹¹½¨¶ñÒâWEBÒ³£¬£¬£¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬£¬£¬¿ÉʹӦÓóÌÐòÍ߽⻣»£»£»òÕßÖ´ÐÐí§Òâ´úÂë¡£¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://www.mozilla.org/en-US/security/advisories/mfsa2018-15/
5¡¢Linux kernel fs/xfs/libxfs/xfs_inode_buf.c¾Ü¾øÐ§ÀÍÎó²î
Linux kernel fs/xfs/libxfs/xfs_inode_buf.c±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬£¬ÔÊÐíÍâµØ¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬Ê¹ÏµÍ³Í߽⡣¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://bugzilla.kernel.org/show_bug.cgi?id=199915
Èý¡¢Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö
1¡¢ÃÀ¹ú¹ú¼ÒÇå¾²¾Ö£¨NSA£©ÉÏÖÜÐû²¼½«É¾³ýÊýÒÔÒڼƵĵ绰ºÍ¶ÌÐżÍ¼
ÃÀ¹ú¹ú¼ÒÇå¾²¾Ö£¨NSA£©ÉÏÖÜÐû²¼£¬£¬£¬£¬£¬£¬ËüÕýÔÚ´ó×Úɾ³ýÊýÒÚÌõ¿É×·Ëݵ½2015ÄêµÄµç»°ºÍ¶ÌÐżÍ¼¡£¡£Ô×ÓÄÜ»ú¹¹ÌåÏÖ£¬£¬£¬£¬£¬£¬ÔÚÃÀ¹ú¹ú¼ÒÇå¾²¾ÖÆÊÎöÖ°Ô±·¢Ã÷¡°´ÓµçÐÅЧÀÍÌṩÉÌ´¦ÊÕµ½µÄһЩÊý¾Ý±£´æÊÖÒÕÎ¥¹æÐÐΪ¡±ºó£¬£¬£¬£¬£¬£¬Ëü½«´ÓÆäϵͳÖÐɾ³ýÊý¾Ý¡£¡£NSAÈÏ¿ÉËüÊÕµ½µÄÔªÊý¾Ý¶àÓÚÔÊÐíµÄÔªÊý¾Ý£¬£¬£¬£¬£¬£¬NSAɾ³ýÁ˽üÈýÄêµÄÔªÊý¾Ý¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/government/nsa-deletes-hundreds-of-millions-of-call-records-over-technical-irregularities/
2¡¢FacebookÈÏ¿ÉÏò61¼Ò¹«Ë¾Ìṩ¶ÔÆäÓû§Êý¾ÝµÄÌØÊâ»á¼ûȨÏÞ
FacebookÒѾÈϿɣ¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÒÑÏòÊýÊ®¼Ò¿Æ¼¼¹«Ë¾ºÍÓ¦Óÿª·¢ÉÌÌṩÁË¶ÔÆäÓû§Êý¾ÝµÄÌØÊâ»á¼ûȨÏÞ£¬£¬£¬£¬£¬£¬ÔÚ½ñÄê3ÔÂÐû²¼µÄCambridge Analytica³óÎÅʱ´ú£¬£¬£¬£¬£¬£¬FacebookÌåÏÖ£¬£¬£¬£¬£¬£¬ËüÒѾÔÚ2015Äê5ÔÂ×èÖ¹Á˵ÚÈý·½»á¼ûÆäÓû§Êý¾Ý¡£¡£È»¶øÔÚ½üÆÚÐû²¼µÄÒ»·Ý³¤´ï747Ò³µÄÎļþÖÐÈϿɣ¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÔÚ2015ÄêÖ®ºó¼ÌÐøÓë61¼ÒÓ²¼þºÍÈí¼þÖÆÔìÉÌÒÔ¼°Ó¦Óÿª·¢É̹²ÏíÊý¾Ý¡£¡£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/07/facebook-data-privacy.html
3¡¢Ñо¿»ú¹¹Ðû²¼2018ÄêÏÄÈÕ»¥ÁªÍøÇå¾²±¨¸æ£¬£¬£¬£¬£¬£¬ÖØµã¹Ø×¢DDoS¹¥»÷
±¾ÖܶþAkamaiÐû²¼2018ÄêÏÄÈÕ»¥ÁªÍøÇå¾²±¨¸æ£¬£¬£¬£¬£¬£¬ÖØµã¹Ø×¢DDoS¹¥»÷µÄÇ÷ÊÆ¡£¡£Æ¾Ö¤AkamaiµÄÑо¿£¬£¬£¬£¬£¬£¬2018ÄêÏÄÈÕÓë2017ÄêÏÄÈÕÏà±È×ÜÌåDDoS¹¥»÷ÔöÌíÁË16%£¬£¬£¬£¬£¬£¬»ù´¡¼Ü¹¹²ã£¨µÚ3²ãºÍµÚ4²ã£©µÄ¹¥»÷ÔöÌíÁË16%£¬£¬£¬£¬£¬£¬·´ÉäÐÍDDoS¹¥»÷ÔöÌíÁË4%£¬£¬£¬£¬£¬£¬Ó¦ÓòãµÄDDoS¹¥»÷ÔöÌíÁË38%¡£¡£Õë¶ÔGitHubµÄDDoS¹¥»÷ÊÂÎñ·åÖµÁ÷Á¿´ï1.35 Tbps£¬£¬£¬£¬£¬£¬´´Á¢ÁËеļͼ¡£¡£Mirai¹¥»÷ÈÔÔÚÒ»Á¬£¬£¬£¬£¬£¬£¬ÐµıäÖÖÒ»Ö±·ºÆð¡£¡£
ÔÎÄÁ´½Ó£ºhttps://threatpost.com/threatlist-top-ddos-trends-in-2018-so-far/133038/
4¡¢Gentoo LinuxÍŶӳƹ¥»÷Õßͨ¹ýÃÜÂëÍÆ²â»ñµÃÆäGitHubÕË»§µÄÃÜÂë
Gentoo Linux¿ª·¢ÍŶÓÐû²¼¹ØÓÚGitHubÕË»§ÔâºÚ¿ÍÈëÇÖÊÂÎñµÄÊӲ챨¸æ¡£¡£¸ÃÍŶӳƹ¥»÷Õßͨ¹ýÃÜÂëÍÆ²â»ñµÃÆäGitHubÕË»§µÄÃÜÂë¼°ÖÎÀíȨÏÞ£¬£¬£¬£¬£¬£¬ÊӲ췢Ã÷µÄÎÊÌ⻹°üÀ¨Î´½ÓÄÉË«ÒòËØÈÏÖ¤¡¢Î´ÉúÑÄGitHub OrganizationÏêϸÐÅÏ¢µÄ±¸·ÝÒÔ¼°systemd repoÖ±½Ó´æ´¢ÔÚGitHubÉÏ¡£¡£ÐÒÔ˵ÄÊÇ£¬£¬£¬£¬£¬£¬GentooºÍGithub¶Ô¸ÃÊÂÎñµÄÏìÓ¦½Ïʵʱ£¬£¬£¬£¬£¬£¬Ê¹µÃ¹¥»÷Ö»Ò»Á¬ÁËÔ¼70·ÖÖÓ¡£¡£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/07/github-hacking-gentoo-linux.html
5¡¢Ñо¿Ö°Ô±·¢Ã÷ʹÓÃPROPagate´úÂë×¢ÈëÊÖÒյĶñÒâ¹¥»÷»î¶¯
PROPagate´úÂë×¢ÈëÊÖÒÕ×îÔçÓÚ2017Äê11ÔÂÓÉHexacornÇå¾²Ñо¿Ö°Ô±·¢Ã÷£¬£¬£¬£¬£¬£¬¸ÃÑо¿Ö°Ô±Ö¤ÊµËü¿ÉÒÔÔÚËùÓÐ×îеÄWindows°æ±¾ÉÏÔËÐУ¬£¬£¬£¬£¬£¬²¢ÇÒ¿ÉÄÜÔÊÐí¹¥»÷Õß½«¶ñÒâ´úÂë×¢ÈëÆäËûÓ¦ÓóÌÐò¡£¡£×¨¼Ò³ÆÊÇÓÉÓÚSetWindowSubclassº¯ÊýÄÚ²¿Ê¹ÓõÄÕýµ±GUI´°¿ÚÊôÐÔ£¨UxSubclassInfoºÍCC32SubclassInfo£©ÔÚÆäËûÓ¦ÓóÌÐòÄÚ²¿¼ÓÔØºÍÖ´ÐжñÒâ´úÂë¡£¡£×î½ü£¬£¬£¬£¬£¬£¬FireEyeµÄר¼Ò·¢Ã÷ÁËÒ»¸öʹÓÃRIG Exploit Kitͨ¹ýPROPagate´úÂë×¢ÈëÊÖÒÕ¶ñÒâÍÚ¾òMoneroµÄ»î¶¯¡£¡£
ÔÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/74068/malware/propagate-code-injection-malware.html