ÐÅÏ¢Çå¾²Öܱ¨-2018ÄêµÚ35ÖÜ

Ðû²¼Ê±¼ä 2018-09-03

Ò»¡¢±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


        2018Äê08ÔÂ27ÈÕÖÁ9ÔÂ02ÈÕ¹²ÊÕ¼Çå¾²Îó²î54¸ö£¬ £¬£¬ £¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇÌÚѶFoxmailÏÂÁî×¢ÈëÎó²î £» £»£»£»£»OpenSSH auth-gss2.cÓû§Ã¶¾ÙÎó²î £» £»£»£»£»Google Chrome Blob API»º³åÇøÒç³öÎó²î £» £»£»£»£»Emerson DeltaV DCS Workstation»º³åÇøÒç³öÎó²î £» £»£»£»£»Adobe Acrobat/Reader CVE-2018-12808Ô½½çдí§Òâ´úÂëÖ´ÐÐÎó²î¡£¡£ ¡£¡£¡£¡£¡£


        ±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊǰ®¶ûÀ¼µçÐŹ«Ë¾EirµÄһ̨Ìõ¼Ç±¾±»µÁ£¬ £¬£¬ £¬£¬£¬£¬µ¼ÖÂÔ¼3.7ÍòÓû§µÄÐÅϢй¶;AppleÔÚÏßÊÐËÁÖеÄÎó²îµ¼ÖÂÁè¼Ý7700ÍòT-MobileÓû§ÕË»§µÄPINÂë̻¶;AbbyyÒòÊý¾Ý¿âÉèÖùýʧµ¼ÖÂ20¶àÍò¸ö¿Í»§Îļþй¶;Î÷°àÑÀÒøÐйÙÍøÔâµ½DDoS¹¥»÷£¬ £¬£¬ £¬£¬£¬£¬ÍøÕ¾ÔÝʱÎÞ·¨»á¼û;¼ÓÄô󺽿չ«Ë¾ÔâºÚ¿ÍÈëÇÖ£¬ £¬£¬ £¬£¬£¬£¬Ô¼2ÍòÃûÓû§µÄÐÅÏ¢ÒÉй¶¡£¡£ ¡£¡£¡£¡£¡£


        ƾ֤ÒÔÉÏ×ÛÊö£¬ £¬£¬ £¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£ ¡£¡£¡£¡£¡£


 


¶þ¡¢Ö÷ÒªÇå¾²Îó²îÁбí


1¡¢ÌÚѶFoxmailÏÂÁî×¢ÈëÎó²î


        Tencent Foxmail URI´¦Öóͷ£±£´æÊäÈëÑéÖ¤Îó²î£¬ £¬£¬ £¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþ»òÒ³ÃæÇëÇó£¬ £¬£¬ £¬£¬£¬£¬ÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§ÒâÏÂÁî¡£¡£ ¡£¡£¡£¡£¡£


        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://www.zerodayinitiative.com/advisories/ZDI-18-584/


2¡¢OpenSSH auth-gss2.cÓû§Ã¶¾ÙÎó²î


        OpenSSH auth-gss2.c±£´æÇå¾²Îó²î£¬ £¬£¬ £¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó£¬ £¬£¬ £¬£¬£¬£¬ÅжÏÓû§Ãû¡£¡£ ¡£¡£¡£¡£¡£


        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttp://seclists.org/oss-sec/2018/q3/180


3¡¢Google Chrome Blob API»º³åÇøÒç³öÎó²î


        Google Chrome Blob API±£´æ¶ÑÒç³öÎó²î£¬ £¬£¬ £¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄWEBÒ³£¬ £¬£¬ £¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬ £¬£¬ £¬£¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ £» £»£»£»£»òÖ´ÐÐí§Òâ´úÂë¡£¡£ ¡£¡£¡£¡£¡£


        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://chromereleases.googleblog.com/2017/12/stable-channel-update-for-desktop.html


4¡¢Emerson DeltaV DCS Workstation»º³åÇøÒç³öÎó²î


        Emerson Electric DeltaV¿ª·ÅͨѶ¶Ë¿Ú±£´æÕ»Òç³öÎó²î£¬ £¬£¬ £¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó£¬ £¬£¬ £¬£¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ £» £»£»£»£»òÖ´ÐÐí§Òâ´úÂë¡£¡£ ¡£¡£¡£¡£¡£


        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://ics-cert.us-cert.gov/advisories/ICSA-18-228-01


5¡¢Adobe Acrobat/Reader CVE-2018-12808Ô½½çдí§Òâ´úÂëÖ´ÐÐÎó²î


        Adobe Acrobat/Reader´¦Öóͷ£PDFÎļþ±£´æÔ½½çдÎó²î£¬ £¬£¬ £¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþÇëÇó£¬ £¬£¬ £¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬ £¬£¬ £¬£¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£ ¡£¡£¡£¡£¡£


        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://helpx.adobe.com/security/products/acrobat/apsb18-29.html


 


Èý¡¢Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢°®¶ûÀ¼µçÐŹ«Ë¾EirµÄһ̨Ìõ¼Ç±¾±»µÁ£¬ £¬£¬ £¬£¬£¬£¬µ¼ÖÂÔ¼3.7ÍòÓû§µÄÐÅϢй¶



welcome-°ÙÀÖ²©


        ƾ֤°®¶ûÀ¼µçÐŹ«Ë¾Eir¹ÙÍøÉϵÄ֪ͨ£¬ £¬£¬ £¬£¬£¬£¬¸Ã¹«Ë¾µÄһ̨°üÀ¨Óû§Êý¾ÝµÄδ¼ÓÃܵÄÌõ¼Ç±¾µçÄÔÔâÇÔ£¬ £¬£¬ £¬£¬£¬£¬µ¼ÖÂÔ¼3.7ÍòÓû§µÄСÎÒ˽¼ÒÐÅϢй¶¡£¡£ ¡£¡£¡£¡£¡£Ð¹Â¶µÄÊý¾Ý°üÀ¨ÐÕÃû¡¢µç×ÓÓʼþµØµã¡¢µç»°ºÅÂëºÍeirÕ˺Å¡£¡£ ¡£¡£¡£¡£¡£¸Ã¹«Ë¾³ÆÐ¹Â¶µÄÊý¾Ý²»°üÀ¨ÈκÎÓû§µÄ²ÆÎñÊý¾Ý¡£¡£ ¡£¡£¡£¡£¡£ÏÖÔڸù«Ë¾ÒÑÏòÊý¾Ý± £» £»£»£»£»¤×¨Ô±ºÍ°®¶ûÀ¼¾¯Ô±×ª´ïÁË´Ë´ÎÊÂÎñ¡£¡£ ¡£¡£¡£¡£¡£


        Ô­ÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/75655/data-breach/eir-data-breach.html


2¡¢AppleÔÚÏßÊÐËÁÖеÄÎó²îµ¼ÖÂÁè¼Ý7700ÍòT-MobileÓû§ÕË»§µÄPINÂë̻¶



welcome-°ÙÀÖ²©


        ƾ֤ÃÀýBuzzFeedNewsµÄ±¨µÀ£¬ £¬£¬ £¬£¬£¬£¬AppleÔÚÏßÊÐËÁÖеÄÎó²îµ¼ÖÂÁè¼Ý7700ÍòT-MobileÓû§ÕË»§µÄPINÂë̻¶¡£¡£ ¡£¡£¡£¡£¡£±ðµÄ£¬ £¬£¬ £¬£¬£¬£¬ÊÖ»ú°ü¹Ü¹«Ë¾AsurionµÄ¹ÙÍøÒ²±£´æÒ»¸öÎó²î£¬ £¬£¬ £¬£¬£¬£¬µ¼ÖÂAsurionµÄAT£¦T¿Í»§µÄPINÂë̻¶¡£¡£ ¡£¡£¡£¡£¡£ÕâÁ½¸öÎó²îÊÇÓÉÇå¾²Ñо¿Ö°Ô±PhobiaºÍNicholas ¡°Convict¡± Ceraolo·¢Ã÷µÄ¡£¡£ ¡£¡£¡£¡£¡£AppleÍøÕ¾ÉϵÄÎó²î¿ÉÄÜÓ뼯³ÉT-MobileµÄÕÊ»§ÑéÖ¤APIʱµÄ¹¤³Ì¹ýʧÓйØ¡£¡£ ¡£¡£¡£¡£¡£AppleºÍAsurionÒѾ­ÐÞ¸´ÁËÏà¹ØÎó²î¡£¡£ ¡£¡£¡£¡£¡£


        Ô­ÎÄÁ´½Ó£ºhttps://www.buzzfeednews.com/article/nicolenguyen/tmobile-att-account-pin-security-flaw-apple


3¡¢AbbyyÒòÊý¾Ý¿âÉèÖùýʧµ¼ÖÂ20¶àÍò¸ö¿Í»§Îļþй¶

welcome-°ÙÀÖ²©


        8ÔÂ19ÈÕÇå¾²Ñо¿Ö°Ô±Bob DiachenkoÔÚAWSÔÆÆ½Ì¨ÉÏ·¢Ã÷ÊôÓÚOCRÈí¼þ¿ª·¢ÉÌAbbyyµÄÒ»¸öMongoDBЧÀÍÆ÷ÎÞÐèµÇ¼¼´¿É¹ûÕæ»á¼û¡£¡£ ¡£¡£¡£¡£¡£¸ÃÊý¾Ý¿â¾ÞϸΪ142GB£¬ £¬£¬ £¬£¬£¬£¬°üÀ¨¶àÖÖÃô¸ÐÎļþµÄɨÃè¼þ£¬ £¬£¬ £¬£¬£¬£¬ÈçÌõÔ¼¡¢±£ÃÜЭÒé¡¢ÄÚ²¿Ðżþ¼°±¸Íü¼µÈ¡£¡£ ¡£¡£¡£¡£¡£ÆäÖаüÀ¨ÊôÓÚAbbyy¿Í»§µÄ20¶àÍò¸öÎļþ¡£¡£ ¡£¡£¡£¡£¡£¸ÃÊý¾Ý¿â¿ÉÄÜÊÇAbbyyµÄ»ù´¡ÉèÊ©µÄÒ»²¿·Ö¡£¡£ ¡£¡£¡£¡£¡£AbbyyµÄÇå¾²ÍŶÓÔÚ½Óµ½Í¨ÖªÁ½ÌìºóÐÞ¸´Á˸ÃÊý¾Ý¿âµÄÉèÖùýʧÎÊÌâ¡£¡£ ¡£¡£¡£¡£¡£


        Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/ocr-software-dev-exposes-200-000-customer-documents/


4¡¢Î÷°àÑÀÒøÐйÙÍøÔâµ½DDoS¹¥»÷£¬ £¬£¬ £¬£¬£¬£¬ÍøÕ¾ÔÝʱÎÞ·¨»á¼û



welcome-°ÙÀÖ²©


        ƾ֤·͸ÉçµÄ±¨µÀ£¬ £¬£¬ £¬£¬£¬£¬´Ó8ÔÂ26ÈÕÐÇÆÚÈÕ×îÏÈÎ÷°àÑÀÒøÐеĹÙÍøÔâµ½ÁËÂþÑÜʽ¾Ü¾øÐ§À͹¥»÷£¨DDoS£©£¬ £¬£¬ £¬£¬£¬£¬ÆäÍøÕ¾ÔÝʱÎÞ·¨»á¼û¡£¡£ ¡£¡£¡£¡£¡£¸ÃÒøÐеĽ²»°ÈËÌåÏÖ£¬ £¬£¬ £¬£¬£¬£¬´Ë´Î¹¥»÷¶Ô¸ÃÒøÐеÄЧÀÍ»ò¸ÃÒøÐÐÓëÅ·ÖÞÖÐÑëÒøÐлòÆäËü»ú¹¹µÄͨѶûÓÐÔì³ÉÈκÎÓ°Ï죬 £¬£¬ £¬£¬£¬£¬²¢ÇÒûÓÐÈκÎÊý¾Ýй¶µÄΣº¦¡£¡£ ¡£¡£¡£¡£¡£×èÖ¹ÖܶþÏÂÖ磬 £¬£¬ £¬£¬£¬£¬¸ÃÒøÐеÄÍøÕ¾ÈÔ´¦ÓÚÀëÏß״̬¡£¡£ ¡£¡£¡£¡£¡£


        Ô­ÎÄÁ´½Ó£ºhttps://uk.reuters.com/article/us-spain-cyber-cenbank/bank-of-spains-website-hit-by-cyber-attack-idUKKCN1LC23B


5¡¢¼ÓÄô󺽿չ«Ë¾ÔâºÚ¿ÍÈëÇÖ£¬ £¬£¬ £¬£¬£¬£¬Ô¼2ÍòÃûÓû§µÄÐÅÏ¢ÒÉй¶


welcome-°ÙÀÖ²©



        8ÔÂ22ÈÕÖÁ24ÈÕʱ´ú£¬ £¬£¬ £¬£¬£¬£¬¼ÓÄô󺽿չ«Ë¾·¢Ã÷Òì³£µÄµÇ¼»î¶¯£¬ £¬£¬ £¬£¬£¬£¬ÎªÁ˱ £» £»£»£»£»¤Óû§µÄÊý¾Ý£¬ £¬£¬ £¬£¬£¬£¬¸Ã¹«Ë¾Ëø¶¨ÁËËùÓÐ170ÍòÒÆ¶¯appÓû§µÄÕË»§¡£¡£ ¡£¡£¡£¡£¡£29ÈÕ£¬ £¬£¬ £¬£¬£¬£¬¸Ã¹«Ë¾Í¨ÖªÔ¼2ÍòÃûÓû§£¬ £¬£¬ £¬£¬£¬£¬³ÆÆäСÎÒ˽¼Ò×ÊÁÏ¿ÉÄÜÔ⵽δÊÚȨµÄ»á¼û¡£¡£ ¡£¡£¡£¡£¡£ÕâЩ×ÊÁÏÖÁÉÙ°üÀ¨ÐÕÃû¡¢µç×ÓÓʼþµØµãºÍµç»°ºÅÂ룬 £¬£¬ £¬£¬£¬£¬Ò²¿ÉÄܰüÀ¨ÐԱ𡢳öÉúÈÕÆÚ¡¢¹ú¼®¡¢»¤ÕÕºÅÂëµÈÐÅÏ¢¡£¡£ ¡£¡£¡£¡£¡£ÔÚÒ»·Ý¹ØÓÚ¸ÃÊÂÎñµÄÉùÃ÷Öиù«Ë¾ÌåÏÖÓû§µÄÒøÐп¨Êý¾ÝÒÔ¼°aircanada.comÕÊ»§²»ÊÜÓ°Ïì¡£¡£ ¡£¡£¡£¡£¡£


        Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/air-canada-mobile-app-users-affected-by-data-breach/