ÐÅÏ¢Çå¾²Öܱ¨-2018ÄêµÚ35ÖÜ

Ðû²¼Ê±¼ä 2018-09-03

Ò»¡¢±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


        2018Äê08ÔÂ27ÈÕÖÁ9ÔÂ02ÈÕ¹²ÊÕ¼Çå¾²Îó²î54¸ö£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇÌÚѶFoxmailÏÂÁî×¢ÈëÎó²î£»£»OpenSSH auth-gss2.cÓû§Ã¶¾ÙÎó²î£»£»Google Chrome Blob API»º³åÇøÒç³öÎó²î£»£»Emerson DeltaV DCS Workstation»º³åÇøÒç³öÎó²î£»£»Adobe Acrobat/Reader CVE-2018-12808Ô½½çдí§Òâ´úÂëÖ´ÐÐÎó²î¡£¡£¡£


        ±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊǰ®¶ûÀ¼µçÐŹ«Ë¾EirµÄһ̨Ìõ¼Ç±¾±»µÁ£¬£¬£¬£¬£¬£¬µ¼ÖÂÔ¼3.7ÍòÓû§µÄÐÅϢй¶;AppleÔÚÏßÊÐËÁÖеÄÎó²îµ¼ÖÂÁè¼Ý7700ÍòT-MobileÓû§ÕË»§µÄPINÂë̻¶;AbbyyÒòÊý¾Ý¿âÉèÖùýʧµ¼ÖÂ20¶àÍò¸ö¿Í»§Îļþй¶;Î÷°àÑÀÒøÐйÙÍøÔâµ½DDoS¹¥»÷£¬£¬£¬£¬£¬£¬ÍøÕ¾ÔÝʱÎÞ·¨»á¼û;¼ÓÄô󺽿չ«Ë¾ÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬Ô¼2ÍòÃûÓû§µÄÐÅÏ¢ÒÉй¶¡£¡£¡£


        ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£


 


¶þ¡¢Ö÷ÒªÇå¾²Îó²îÁбí


1¡¢ÌÚѶFoxmailÏÂÁî×¢ÈëÎó²î


        Tencent Foxmail URI´¦Öóͷ£±£´æÊäÈëÑéÖ¤Îó²î£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþ»òÒ³ÃæÇëÇ󣬣¬£¬£¬£¬£¬ÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£


        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://www.zerodayinitiative.com/advisories/ZDI-18-584/


2¡¢OpenSSH auth-gss2.cÓû§Ã¶¾ÙÎó²î


        OpenSSH auth-gss2.c±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬ÅжÏÓû§Ãû¡£¡£¡£


        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttp://seclists.org/oss-sec/2018/q3/180


3¡¢Google Chrome Blob API»º³åÇøÒç³öÎó²î


        Google Chrome Blob API±£´æ¶ÑÒç³öÎó²î£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄWEBÒ³£¬£¬£¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£


        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://chromereleases.googleblog.com/2017/12/stable-channel-update-for-desktop.html


4¡¢Emerson DeltaV DCS Workstation»º³åÇøÒç³öÎó²î


        Emerson Electric DeltaV¿ª·ÅͨѶ¶Ë¿Ú±£´æÕ»Òç³öÎó²î£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£


        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://ics-cert.us-cert.gov/advisories/ICSA-18-228-01


5¡¢Adobe Acrobat/Reader CVE-2018-12808Ô½½çдí§Òâ´úÂëÖ´ÐÐÎó²î


        Adobe Acrobat/Reader´¦Öóͷ£PDFÎļþ±£´æÔ½½çдÎó²î£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþÇëÇ󣬣¬£¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£


        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://helpx.adobe.com/security/products/acrobat/apsb18-29.html


 


Èý¡¢Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢°®¶ûÀ¼µçÐŹ«Ë¾EirµÄһ̨Ìõ¼Ç±¾±»µÁ£¬£¬£¬£¬£¬£¬µ¼ÖÂÔ¼3.7ÍòÓû§µÄÐÅϢй¶



¿­Ðý¹ú¼ÊÓÎÏ·(Öйú)¹Ù·½ÍøÕ¾


        ƾ֤°®¶ûÀ¼µçÐŹ«Ë¾Eir¹ÙÍøÉϵÄ֪ͨ£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾µÄһ̨°üÀ¨Óû§Êý¾ÝµÄδ¼ÓÃܵÄÌõ¼Ç±¾µçÄÔÔâÇÔ£¬£¬£¬£¬£¬£¬µ¼ÖÂÔ¼3.7ÍòÓû§µÄСÎÒ˽¼ÒÐÅϢй¶¡£¡£¡£Ð¹Â¶µÄÊý¾Ý°üÀ¨ÐÕÃû¡¢µç×ÓÓʼþµØµã¡¢µç»°ºÅÂëºÍeirÕ˺𣡣¡£¸Ã¹«Ë¾³ÆÐ¹Â¶µÄÊý¾Ý²»°üÀ¨ÈκÎÓû§µÄ²ÆÎñÊý¾Ý¡£¡£¡£ÏÖÔڸù«Ë¾ÒÑÏòÊý¾Ý±£»£»¤×¨Ô±ºÍ°®¶ûÀ¼¾¯Ô±×ª´ïÁË´Ë´ÎÊÂÎñ¡£¡£¡£


        Ô­ÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/75655/data-breach/eir-data-breach.html


2¡¢AppleÔÚÏßÊÐËÁÖеÄÎó²îµ¼ÖÂÁè¼Ý7700ÍòT-MobileÓû§ÕË»§µÄPINÂë̻¶



¿­Ðý¹ú¼ÊÓÎÏ·(Öйú)¹Ù·½ÍøÕ¾


        ƾ֤ÃÀýBuzzFeedNewsµÄ±¨µÀ£¬£¬£¬£¬£¬£¬AppleÔÚÏßÊÐËÁÖеÄÎó²îµ¼ÖÂÁè¼Ý7700ÍòT-MobileÓû§ÕË»§µÄPINÂë̻¶¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬ÊÖ»ú°ü¹Ü¹«Ë¾AsurionµÄ¹ÙÍøÒ²±£´æÒ»¸öÎó²î£¬£¬£¬£¬£¬£¬µ¼ÖÂAsurionµÄAT£¦T¿Í»§µÄPINÂë̻¶¡£¡£¡£ÕâÁ½¸öÎó²îÊÇÓÉÇå¾²Ñо¿Ö°Ô±PhobiaºÍNicholas ¡°Convict¡± Ceraolo·¢Ã÷µÄ¡£¡£¡£AppleÍøÕ¾ÉϵÄÎó²î¿ÉÄÜÓ뼯³ÉT-MobileµÄÕÊ»§ÑéÖ¤APIʱµÄ¹¤³Ì¹ýʧÓйء£¡£¡£AppleºÍAsurionÒѾ­ÐÞ¸´ÁËÏà¹ØÎó²î¡£¡£¡£


        Ô­ÎÄÁ´½Ó£ºhttps://www.buzzfeednews.com/article/nicolenguyen/tmobile-att-account-pin-security-flaw-apple


3¡¢AbbyyÒòÊý¾Ý¿âÉèÖùýʧµ¼ÖÂ20¶àÍò¸ö¿Í»§Îļþй¶

¿­Ðý¹ú¼ÊÓÎÏ·(Öйú)¹Ù·½ÍøÕ¾


        8ÔÂ19ÈÕÇå¾²Ñо¿Ö°Ô±Bob DiachenkoÔÚAWSÔÆÆ½Ì¨ÉÏ·¢Ã÷ÊôÓÚOCRÈí¼þ¿ª·¢ÉÌAbbyyµÄÒ»¸öMongoDBЧÀÍÆ÷ÎÞÐèµÇ¼¼´¿É¹ûÕæ»á¼û¡£¡£¡£¸ÃÊý¾Ý¿â¾ÞϸΪ142GB£¬£¬£¬£¬£¬£¬°üÀ¨¶àÖÖÃô¸ÐÎļþµÄɨÃè¼þ£¬£¬£¬£¬£¬£¬ÈçÌõÔ¼¡¢±£ÃÜЭÒé¡¢ÄÚ²¿Ðżþ¼°±¸Íü¼µÈ¡£¡£¡£ÆäÖаüÀ¨ÊôÓÚAbbyy¿Í»§µÄ20¶àÍò¸öÎļþ¡£¡£¡£¸ÃÊý¾Ý¿â¿ÉÄÜÊÇAbbyyµÄ»ù´¡ÉèÊ©µÄÒ»²¿·Ö¡£¡£¡£AbbyyµÄÇå¾²ÍŶÓÔÚ½Óµ½Í¨ÖªÁ½ÌìºóÐÞ¸´Á˸ÃÊý¾Ý¿âµÄÉèÖùýʧÎÊÌâ¡£¡£¡£


        Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/ocr-software-dev-exposes-200-000-customer-documents/


4¡¢Î÷°àÑÀÒøÐйÙÍøÔâµ½DDoS¹¥»÷£¬£¬£¬£¬£¬£¬ÍøÕ¾ÔÝʱÎÞ·¨»á¼û



¿­Ðý¹ú¼ÊÓÎÏ·(Öйú)¹Ù·½ÍøÕ¾


        ƾ֤·͸ÉçµÄ±¨µÀ£¬£¬£¬£¬£¬£¬´Ó8ÔÂ26ÈÕÐÇÆÚÈÕ×îÏÈÎ÷°àÑÀÒøÐеĹÙÍøÔâµ½ÁËÂþÑÜʽ¾Ü¾øÐ§À͹¥»÷£¨DDoS£©£¬£¬£¬£¬£¬£¬ÆäÍøÕ¾ÔÝʱÎÞ·¨»á¼û¡£¡£¡£¸ÃÒøÐеĽ²»°ÈËÌåÏÖ£¬£¬£¬£¬£¬£¬´Ë´Î¹¥»÷¶Ô¸ÃÒøÐеÄЧÀÍ»ò¸ÃÒøÐÐÓëÅ·ÖÞÖÐÑëÒøÐлòÆäËü»ú¹¹µÄͨѶûÓÐÔì³ÉÈκÎÓ°Ï죬£¬£¬£¬£¬£¬²¢ÇÒûÓÐÈκÎÊý¾Ýй¶µÄΣº¦¡£¡£¡£×èÖ¹ÖܶþÏÂÖ磬£¬£¬£¬£¬£¬¸ÃÒøÐеÄÍøÕ¾ÈÔ´¦ÓÚÀëÏß״̬¡£¡£¡£


        Ô­ÎÄÁ´½Ó£ºhttps://uk.reuters.com/article/us-spain-cyber-cenbank/bank-of-spains-website-hit-by-cyber-attack-idUKKCN1LC23B


5¡¢¼ÓÄô󺽿չ«Ë¾ÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬Ô¼2ÍòÃûÓû§µÄÐÅÏ¢ÒÉй¶


¿­Ðý¹ú¼ÊÓÎÏ·(Öйú)¹Ù·½ÍøÕ¾



        8ÔÂ22ÈÕÖÁ24ÈÕʱ´ú£¬£¬£¬£¬£¬£¬¼ÓÄô󺽿չ«Ë¾·¢Ã÷Òì³£µÄµÇ¼»î¶¯£¬£¬£¬£¬£¬£¬ÎªÁ˱£»£»¤Óû§µÄÊý¾Ý£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾Ëø¶¨ÁËËùÓÐ170ÍòÒÆ¶¯appÓû§µÄÕË»§¡£¡£¡£29ÈÕ£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾Í¨ÖªÔ¼2ÍòÃûÓû§£¬£¬£¬£¬£¬£¬³ÆÆäСÎÒ˽¼Ò×ÊÁÏ¿ÉÄÜÔ⵽δÊÚȨµÄ»á¼û¡£¡£¡£ÕâЩ×ÊÁÏÖÁÉÙ°üÀ¨ÐÕÃû¡¢µç×ÓÓʼþµØµãºÍµç»°ºÅÂ룬£¬£¬£¬£¬£¬Ò²¿ÉÄܰüÀ¨ÐԱ𡢳öÉúÈÕÆÚ¡¢¹ú¼®¡¢»¤ÕÕºÅÂëµÈÐÅÏ¢¡£¡£¡£ÔÚÒ»·Ý¹ØÓÚ¸ÃÊÂÎñµÄÉùÃ÷Öиù«Ë¾ÌåÏÖÓû§µÄÒøÐп¨Êý¾ÝÒÔ¼°aircanada.comÕÊ»§²»ÊÜÓ°Ïì¡£¡£¡£


        Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/air-canada-mobile-app-users-affected-by-data-breach/