ÐÅÏ¢Çå¾²Öܱ¨-2019ÄêµÚ12ÖÜ

Ðû²¼Ê±¼ä 2019-03-25

±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


2019Äê3ÔÂ18ÈÕÖÁ24ÈÕ¹²ÊÕ¼Çå¾²Îó²î57¸ö£¬£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇMozilla Firefox IonMonkey JIT±àÒëÆ÷ÀàÐÍ»ìÏýÎó²î£» £»£»£»£» £»£»£»Cisco IP Phone 7800/8800 Series sipÔ¶³Ì´úÂëÖ´ÐÐÎó²î; CUJO Smart Firewall DHCPÖ÷»úÃûÏÂÁî×¢ÈëÎó²î£» £»£»£»£» £»£»£»Adobe Photoshop CC¶ÑÒç³öí§Òâ´úÂëÖ´ÐÐÎó²î£» £»£»£»£» £»£»£»Wifi-soft UniBox controller CVE-2019-3495Ô¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇFacebookÃ÷ÎÄ´æ´¢ÊýÒÚÓû§ÃÜÂ룬£¬£¬£¬£¬£¬£¬±»Ô±¹¤Éó²é900Íò´Î£» £»£»£»£» £»£»£»¹È¸èÒò¹ã¸æÂ¢¶ÏÔÙ±»Å·ÃË·£¿£¿£¿î17ÒÚÃÀÔª£» £»£»£»£» £»£»£»Nork Hydro¹«Ë¾Ôâµ½ÀÕË÷Èí¼þLockerGoga¹¥»÷£» £»£»£»£» £»£»£»89£¥µÄÅ·ÃËÕþ¸®ÍøÕ¾±£´æµÚÈý·½¹ã¸æ¸ú×پ籾£» £»£»£»£» £»£»£»Epic GamesÍøÂçSteamÓû§Òþ˽ÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬ÔÊÐí½«¾ÙÐÐÐÞ¸´¡£¡£¡£¡£

ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£


Ö÷ÒªÇå¾²Îó²îÁбí


1. Mozilla Firefox IonMonkey JIT±àÒëÆ÷ÀàÐÍ»ìÏýÎó²î
Mozilla Firefox IonMonkey JIT±àÒëÆ÷±£´æÀàÐÍ»ìÏýÎó²î£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄwebÇëÇ󣬣¬£¬£¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬£¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£» £»£»£»£» £»£»£»òÖ´ÐÐí§Òâ´úÂ룬£¬£¬£¬£¬£¬£¬
https://www.mozilla.org/en-US/security/advisories/mfsa2019-07/

2. Cisco IP Phone 7800/8800 Series sipÔ¶³Ì´úÂëÖ´ÐÐÎó²î
Cisco IP Phone 7800/8800 WEB½Ó¿Ú´¦Öóͷ£¶ñÒâsipÐÂÎű£´æÇå¾²Îó²î£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬¿ÉÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190320-ip-phone-rce

3. CUJO Smart Firewall DHCPÖ÷»úÃûÏÂÁî×¢ÈëÎó²î
CUJO Smart Firewall dhcpÊØ»¤Àú³Ì±£´æÊäÈëÑéÖ¤Îó²î£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬¿É×¢Èëí§ÒâÏÂÁî²¢Ö´ÐС£¡£¡£¡£
https://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0703

4. Adobe Photoshop CC¶ÑÒç³öí§Òâ´úÂëÖ´ÐÐÎó²î
Adobe Photoshop CC´¦Öóͷ£Îļþ±£´æ¶ÑÒç³öÎó²î£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþÇëÇ󣬣¬£¬£¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬£¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£» £»£»£»£» £»£»£»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£
https://helpx.adobe.com/security/products/photoshop/apsb19-15.html

5. Wifi-soft UniBox controller CVE-2019-3495Ô¶³Ì´úÂëÖ´ÐÐÎó²î
Wifi-soft UniBox controller±£´æÔ¶³Ì´úÂë×¢ÈëÎó²î£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬¿ÉÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£
https://packetstormsecurity.com/files/151077/Wifi-soft-Unibox-2.x-Remote-Command-Code-Injection.html

 Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢FacebookÃ÷ÎÄ´æ´¢ÊýÒÚÓû§ÃÜÂ룬£¬£¬£¬£¬£¬£¬±»Ô±¹¤Éó²é900Íò´Î

ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾

±¾ÖÜËÄFacebookÈÏ¿ÉÊýÒÔÒڼƵÄFacebookºÍInstagramÓû§µÄÃÜÂë¶àÄêÀ´Ò»Ö±ÒÔÃ÷ÎĵÄÐÎʽ´æ´¢ÔÚÄÚ²¿Êý¾ÝϵͳÖС£¡£¡£¡£FacebookÔÚ1Ô·ݵÄÀýÐÐÇå¾²Éó²éʱ´ú·¢Ã÷ÁËÕâÒ»ÎÊÌ⣬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÌåÏÖÕâЩÊý¾Ý²¢Î´Ôâµ½ÀÄÓᣡ£¡£¡£Æ¾Ö¤Çå¾²¼ÇÕßBrian KrebsµÄÒ»·Ý±¨¸æ£¬£¬£¬£¬£¬£¬£¬Ô¼2000Ãû¹¤³Ìʦ»ò¿ª·¢Ö°Ô±¶ÔÕâЩÊý¾Ý¾ÙÐÐÁËԼĪ900Íò´ÎÄÚ²¿ÅÌÎÊ¡£¡£¡£¡£FacebookÉÐδÅû¶ÊÜÓ°ÏìµÄÏêϸÓû§ÈËÊý£¬£¬£¬£¬£¬£¬£¬µ«KrebsµÄ±¨¸æÖгÆÕâÒ»Êý×ÖΪ2ÒÚÖÁ6ÒÚÖ®¼ä¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/facebook-employees-could-access-unencrypted-passwords-for-millions-of-users/

2¡¢¹È¸èÒò¹ã¸æÂ¢¶ÏÔÙ±»Å·ÃË·£¿£¿£¿î17ÒÚÃÀÔª


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


3ÔÂ20ÈÕÅ·ÃËίԱ»áÐû²¼ÉùÃ÷¶Ô¹È¸èµÄ¹ã¸æÂ¢¶ÏÐÐΪ·£¿£¿£¿î14.9ÒÚÅ·Ôª£¨Ô¼17ÒÚÃÀÔª£©£¬£¬£¬£¬£¬£¬£¬ÕâÊÇÁ½ÄêÄÚÅ·Ã˶Թȸ迪³öµÄµÚÈýÕÅ´ó¶î·´Â¢¶Ï·£µ¥¡£¡£¡£¡£Å·ÃËίԱ»áÌåÏÖÕâÒ»·£¿£¿£¿îµÄÔµ¹ÊÔ­ÓÉÊǹȸèÀÄÓÃÆäÊг¡Ö÷µ¼Ö°Î»£¬£¬£¬£¬£¬£¬£¬×èÖ¹ÍøÒ³Ê¹ÓÃAdSenseƽ̨ÒÔÍâµÄ¹ã¸æÐ§ÀÍ£¬£¬£¬£¬£¬£¬£¬ÕâÒ»·£½ðÏ൱Óڹȸè2018ÄêÓªÒµ¶îµÄ1.29%¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/google-fined-17-billion-for-anti-competitive-practices-in-online-advertising/

3¡¢Nork Hydro¹«Ë¾Ôâµ½ÀÕË÷Èí¼þLockerGoga¹¥»÷


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


±¾ÖÜÒ»£¨3ÔÂ18ÈÕ£©Íí¼äŲÍþÂÁÒµ¾ÞÍ·Norsk HydroÔâµ½´ó¹æÄ£ÍøÂç¹¥»÷£¬£¬£¬£¬£¬£¬£¬¼¸¼Ò¹¤³§±»ÔÝʱ¹Ø±Õ¡£¡£¡£¡£ÔÚÐÂÎÅÐû²¼»áÉÏ£¬£¬£¬£¬£¬£¬£¬Norsk HydroÊ×ϯ²ÆÎñ¹ÙEivind Kallevik͸¶¸Ã¹«Ë¾Ôâµ½½ÏеÄÀÕË÷Èí¼þLockerGogaµÄ¹¥»÷£¬£¬£¬£¬£¬£¬£¬ÆäÉú²ú¼°ÔËÓª¾ùÊܵ½Ó°Ïì¡£¡£¡£¡£¸Ã¹«Ë¾±»ÆÈÔÚŲÍþ¡¢¿¨Ëþ¶ûºÍ°ÍÎ÷µÈ¹ú¼ÒÇл»ÖÁÈ˹¤²Ù×÷£¬£¬£¬£¬£¬£¬£¬ÒÔ»Ö¸´ÆäÔËÓª»î¶¯¡£¡£¡£¡£Kallevik»¹ÌåÏָù«Ë¾ÒѾ­Äܹ»´¦Öóͷ£ËùÓпͻ§µÄ¶©µ¥²¢½»¸¶£¬£¬£¬£¬£¬£¬£¬µ«Î´À´µÄ¶©µ¥¿ÉÄÜ»áÊܵ½Ó°Ï죬£¬£¬£¬£¬£¬£¬ÓÉÓÚ¹«Ë¾ÍøÂçÈÔδ»Ö¸´¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/lockergoga-ransomware-sends-norsk-hydro-into-manual-mode/

4¡¢89£¥µÄÅ·ÃËÕþ¸®ÍøÕ¾±£´æµÚÈý·½¹ã¸æ¸ú×پ籾


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


µ¤Âóä¯ÀÀÆ÷ÆÊÎö¹«Ë¾CookiebotÔÚ25¸öÅ·Ã˳ÉÔ±¹úµÄÕþ¸®¹ÙÍøÉÏ·¢Ã÷¹ã¸æ¸ú×پ籾£¬£¬£¬£¬£¬£¬£¬Õâ»òÐíÕ¼×ܹ²28¸ö³ÉÔ±¹úµÄ89%£¬£¬£¬£¬£¬£¬£¬Ö»Óе¹ú¡¢Î÷°àÑÀºÍºÉÀ¼µÄÕþ¸®ÍøÕ¾Ã»ÓÐÉÌÒµ¹ã¸æ¸ú×ÙÆ÷¡£¡£¡£¡£·¨¹úÕþ¸®ÍøÕ¾ÉÏµÄ¹ã¸æ¸ú×ÙÆ÷×î¶à£¬£¬£¬£¬£¬£¬£¬ÓÐ52¼Ò²î±ðµÄ¹«Ë¾ÔÚ¸ú×ÙÓû§µÄÐÐΪ¡£¡£¡£¡£ÕâЩ¹ã¸æ¸ú×ÙÆ÷Ö÷ÒªÊÇÔÚµÚÈý·½²å¼þµÄ×ÊÖúÏÂÉøÍ¸½øÕþ¸®ÍøÕ¾£¬£¬£¬£¬£¬£¬£¬ÀýÈçÊÓÆµ²¥·ÅÆ÷²å¼þ¡¢ÍøÕ¾ÆÊÎö¼°Í¼±í²å¼þµÈ¡£¡£¡£¡£ÕâÏÔȻΥ·´ÁËÅ·Ã˵ÄÊý¾Ý±£» £»£»£»£» £»£»£»¤¹æÔòGDPR¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/89-percent-of-eu-government-sites-infiltrated-by-ad-tracking-scripts/

5¡¢Epic GamesÍøÂçSteamÓû§Òþ˽ÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬ÔÊÐí½«¾ÙÐÐÐÞ¸´


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


Epic GamesÕë¶Ô¶àÏîÇÖÕ¼Óû§Òþ˽µÄÖ¸¿Ø×ö³ö»ØÓ¦£¬£¬£¬£¬£¬£¬£¬²¢ÔÊÐí¶Ô¸ÃÎÊÌâ¾ÙÐÐÐÞ¸´¡£¡£¡£¡£ÓÎÏ·Íæ¼ÒÔÚRedditÉÏ·¢Ìû³Æ£¬£¬£¬£¬£¬£¬£¬Epic Games LauncherÔÚδ¾­Óû§ÔÊÐíµÄÇéÐÎÏÂɨÃè²¢ÍøÂçÓû§µÄSteamÐÅÏ¢¡£¡£¡£¡£Epic Games¹¤³Ì¸±×ܲÃDaniel Vogel»ØÓ¦³ÆEpic Games Store¿Í»§¶Ë½¨ÉèÁËSteamÎļþlocalconfig.vdfµÄÍâµØ¼ÓÃܸ±±¾£¬£¬£¬£¬£¬£¬£¬µ±Óû§Ñ¡Ôñµ¼ÈëSteamÁªÏµÈËʱ£¬£¬£¬£¬£¬£¬£¬½«»á°ÑÓû§µÄÁªÏµÈ˹þÏ£ID·¢ËÍ»ØEpic¡£¡£¡£¡£Epic Games CEO Tim SweeneyÌåÏÖ½«¶ÔÓÐÕùÒéµÄÓû§Êý¾ÝÍøÂçÐÐΪ¾ÙÐÐÐÞ¸´¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/epic-promises-to-fix-game-launcher-after-privacy-concerns/

ÉùÃ÷£º±¾×ÊѶÓÉÍòÀû¹ú¼Ê¹ÙÍøÎ¬ËûÃüÇ徲С×é·­ÒëºÍÕûÀí