Android libpac¿âRCE·ì϶£»Intel CPU TPM-FAIL·ì϶ʹÊýÊ®ÒŲ́Éè±¸Ãæ¶Ô·çÏÕ
°ä²¼¹¦·ò 2019-11-18
NowSecure×êÑÐÈËÔ±·¢ÏÖAndroidϵͳʹÓõÄlibpac¿âÖдæÔÚRCE·ì϶£¨CVE-2019-2205£©¡£libpacÊÇÒ»¸ö»ùÓÚChromiumÏîÄ¿´úÂëµÄ¿â£¬¸Ã¿âʹÓþ²Ì¬Á´½ÓµÄV8 JSÒýÇæÀ´½âÎöJavaScript£¬ÕâΪƽ̨ÀûÓ÷¨Ê½´øÀ´Á˾޴óµÄ¹¥»÷Ãæ¡£×êÑÐÈËÔ±·¢ÏÖJSº¯ÊýFindProxyForUrl¸ßµÍÎÄÖеÄArrayBuffers·ÖÅäÆ÷ÉêÃ÷²»ÕýÈ·£¬¿ÉÖÂÕ»ÉϵÄVPTR±»¸²¸Ç£¬Õâ¿ÉÄܱ»ÓÃÓÚÖ´ÐÐËÁÒâ´úÂë¡£¹È¸èÔÚ11ÔÂAndroid°²È«¸üÐÂÖн¨¸´Á˸÷ì϶¡£
ÔÎÄÁ´½Ó£º
https://www.nowsecure.com/blog/2019/11/13/nowsecure-discovers-critical-android-vuln-that-may-lead-to-remote-code-execution/2¡¢Intel CPU TPM-FAIL·ì϶ʹÊýÊ®ÒŲ́Éè±¸Ãæ¶Ô·çÏÕ
×êÑÐÈËÔ±ÔÚ»ùÓÚÓ¢ÌØ¶û¹Ì¼þµÄTPM£¨fTPM£©ºÍSTMicroelectronicsµÄTPMоƬÖз¢ÏÖÁËÁ½¸ö±»³ÆÎªTPM-FAILµÄзì϶£¬ÕâÁ½¸ö·ì϶£¨CVE-2019-11090ºÍCVE-2019-16863£©Ê¹ºÚ¿ÍÄܹ»¶ã±Ü°²È«·®À飬²¢ÇÔÈ¡TPMÖд洢µÄÃô¸ÐÊý¾Ý£¬Ô̺¬ÊðÃûÃÜÔ¿µÈ¡£ÌáÈ¡µ½ÃÜÔ¿ºó£¬¹¥»÷Õß¾ÍÄÜÀûÓÃËüαÔìÊý×ÖÊðÃû¡¢´Û¸Ä²Ù×÷ϵͳ»òÈÆ¹ýÉí·ÝÑéÖ¤¡£´óÎÞÊý±ãÐ¯Ê½ÍÆËã»ú¡¢Ì¨Ê½»úºÍ·þÎñÆ÷¶¼ÈÝÒ×Êܵ½TPM-FAIL¹¥»÷£¬Ô̺¬´÷¶û¡¢»ÝÆÕºÍåÚÏëµÈÆ·ÅÆÔì×÷ÉÌ¡£ÕâÁ½¸ö·ì϶¶¼ÒÑÔÚеĹ̼þ»òTPMоƬÖн¨¸´¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/tpm-fail-security-flaws-impact-modern-devices-with-intel-cpus/3¡¢Wizards of Coastй¶45ÍòÓÎÏ·Íæ¼ÒÊý¾Ý
¡¶Magic£ºThe Gathering¡·ÓÎÏ·µÄ¿ª·¢ÉÌWizards of CoastÒѾȷÈÏÊýÊ®ÍòÓÎÏ·Íæ¼ÒµÄÊý¾ÝÔâй¶¡£Ó¢¹ú°²È«³§ÉÌFidus Information Security·¢ÏÖÁ˶³öµÄÊý¾Ý¿âÎļþ£¬ÕâЩÎļþ±»±£ÁôÔÚûÓÐÃÜÂëµÄAmazon´æ´¢Í°ÖС£Êý¾Ý¿âÖÐÒ»¹²Ô̺¬452634ÃûÍæ¼ÒµÄÊý¾Ý£¬Éæ¼°ÐÕÃûºÍÓû§Ãû¡¢µç×ÓÓʼþµØÖ·¡¢ÕË»§µÄ´´½¨¹¦·òÒÔ¼°¾¹ý¹þÏ£ºÍ¼ÓÑδ¦ÖõÄÃÜÂ롣ƾ¾Ý×êÑÐÈËÔ±¶ÔÊý¾ÝµÄÉó²é£¬ÕâЩÕË»§µÄÈÕÆÚ×îÔç¿É×·ÒäÖÁ2012Ä꣬×îÐÂÔòΪ2018ÄêÖÐÆÚ¡£
ÔÎÄÁ´½Ó£º
https://techcrunch.com/2019/11/16/magic-the-gathering-wizards-data-exposure/4¡¢Sunshine Behavioralй¶9.3Íò·Ý»¼Õßµµ°¸
Sunshine Behavioral HealthÊÇÃÀ¹úÒ»¼ÒÒ½Öζ¾Æ·ºÍ¾Æ¾«³Éñ«»¼ÕßµÄÒ½Áƹ«Ë¾£¬É¢²¼ÔÚ¼ÓÀû¸£ÄáÑÇÖÝ¡¢µÂ¿ËÈøË¹ÖݺͿÆÂÞÀ¶àÖÝ¡£ÓÉÓÚAWS s3´æ´¢Í°ÅäÖÃÃýÎ󣬸ù«Ë¾µÄԼĪ9.3Íò¸ö»¼Õßµµ°¸Ôâй¶¡£µµ°¸ÖÐÔ̺¬µÄÐÅÏ¢Ô̺¬ÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢ÓÊÕþµØÖ·ºÍµç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂë¡¢ÆëÈ«µÄÐÅÓþ¿¨ºÅÂëºÍCVVÂë¼°²¿ÃÅÓÐЧÈÕÆÚ£¨ÔÂ/ÈÕ£©¡¢Ò½ÁƱ£ÏÕÕ˺š¢ÒÑÖ§¸¶½ð¶îµÈ¡£¸Ã¹«Ë¾¶ÔÊý¾Ý¿â½øÐÐÁ˱£»¤£¬µ«Ã»ÓÐÔÚÍøÕ¾Éϰ䲼й¶֪ͨ£¬Ò²Î´°µÊ¾ÊÇ·ñÒÑ֪ͨ»¼Õß/¼à¹Ü»ú¹¹¡£
ÔÎÄÁ´½Ó£º
https://www.databreaches.net/exclusive-more-than-90000-patient-billing-files-from-an-alcohol-and-drug-addiction-treatment-network-exposed-online/
5¡¢°Ä´óÀûÑǹú»áÔÚ2019ËêÊ×Ôâµ½ºÚ¿ÍÈëÇÖ
ƾ¾Ý°Ä´óÀûÑǹ㲥¹«Ë¾£¨ABC£©µÄ±¨Â·£¬°Ä´óÀûÑǹú»áµÄÍÆËã»úÍøÂçÔÚ½ñÄêÔçЩʱ³½±»ºÚ¿ÍÈëÇÖ£¬²¢´Ó¼¸Î»µ±Ñ¡¹ÙÔ±µÄÍÆËã»úÖÐÇÔÈ¡ÁËÊý¾Ý¡£¸Ã¹¥»÷²úÉúÔÚ2019Äê1ÔÂ31ÈÕ£¬Æäʱ°Ä´óÀûÑǰ²È«»ú¹¹·¢ÏÖÁËÈëÇÖ²¢¶ÔÆä½øÐÐÒ»Öܵļල£¬¶øºó¹Ø¹ØÍøÂç²¢ÊÔͼ׷²¶¹¥»÷Õß¡£°Ä´óÀûÑǵ±¾ÖδÌṩÓйظúڿ͹¥»÷µÄ¸ü¶à¾ßÌåÐÅÏ¢¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/93898/cyber-warfare-2/australian-parliament-hacked.html
6¡¢Î¢Èí°ä²¼Intel CPUÇý¶¯·¨Ê½·ì϶µÄ½¨¸´Ö¸ÄÏ
΢Èí°ä²¼ÁËÔ®ÊÖÓû§½¨¸´Intel CPU»Ø¾ø·þÎñ·ì϶£¨CVE-2018-12207£©ºÍTSXÒì²½¶ôÖÆ·ì϶£¨CVE-2019-11135£©µÄÖ¸ÄÏ¡£¸ÃDoS·ì϶ӰÏìÁ˵Ú8´ú¼°ÒÔϵÄIntel¿á¦ÖÃÆ÷£¬Î¢ÈíÔÚ11Ô°²È«¸üÐÂÖн¨¸´Á˸÷ì϶£¬µ«ÔÚĬÈÏÇé¿öϸñ£»¤Ö°Äܱ»½ûÓã¬Óû§±ØÐëÉèÖÃÌØ¶¨µÄ×¢²á±íÏîÆôÓøÃÖ°ÄÜ¡£¶øTSXÖ°ÄÜÖеĴ§Ä¦Ö´Ðзì϶ÔòÓ°ÏìÁËIntelµÚ10´ú֮ǰµÄ´¦ÖÃÆ÷£¬Î¢ÈíÁìµ¼Óû§ÔÚÒ×Êܹ¥»÷µÄIntel´¦ÖÃÆ÷ÉϽûÓÃIntel TSXÖ°ÄÜ£¬ÒÔ×èֹDZÔÚµÄZombieload 2¹¥»÷¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/microsoft-issues-guidance-for-intel-cpu-driver-security-flaws/


¾©¹«Íø°²±¸11010802024551ºÅ