ÐÅÏ¢°²È«Öܱ¨-2018ÄêµÚ25ÖÜ
°ä²¼¹¦·ò 2018-06-25
Ò»¡¢±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
2018Äê06ÔÂ18ÈÕÖÁ24ÈÕ¹²ÊÕ¼°²È«·ì϶46¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇCisco FXOS/NX-OS Software Fabric ServicesÔ¶³Ì´úÂëÖ´Ðзì϶£»Cisco NX-OS Software NX-APIËÁÒâ´úÂëÖ´Ðзì϶£»NTP ntpqºÍntpdc CVE-2018-12327Õ»»º³åÇøÃýÎó·ì϶£»CA Privileged Access Manager CVE-2015-4664ÊäÈëÑéÖ¤ËÁÒâºÅÁîÖ´Ðзì϶£»QEMU slirp/mbuf.c/m_cat¶Ñ»º³åÇøÒç¶Âí½Å¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇ×êÑÐÈËÔ±ÖÒ¸æ³Æ¶ñÒâÈí¼þͨ¹ý¼Ù×°³Éµï±¤Ö®Ò¹°²×¿°æ½øÐд«²¼£»×êÑÐÈËÔ±³ÆmacOSµÄQuickLookÖ°Äܿɵ¼Ö¼ÓÃÜ´ÅÅ̵ÄÊý¾Ýй¶£»º«¹ú¼ÓÃÜÇ®±ÒÂòÂôËùBithumbÒ»ÄêÄÚµÚ¶þ´ÎÔâºÚ¿ÍÈëÇÖ£¬Ô¼3100ÍòÃÀÔª±»ÇÔ£»Flightradar24ÔâºÚ¿ÍÈëÇÖ£¬Ô¼23ÍòÓû§µÄÐÅϢй¶£»×êÑÐÈËÔ±·¢ÏÖ³¬¹ý3000¸öappµÄFirebaseÊý¾Ý¿â¿É¹«¿ª½Ó¼û¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖС£
¶þ¡¢³ÁÒª°²È«·ì϶Áбí
1¡¢Cisco FXOS/NX-OS Software Fabric ServicesÔ¶³Ì´úÂëÖ´Ðзì϶
Cisco FXOS/NX-OS Software Fabric Services×é¼þδÓÐЧÑéÖ¤Fabric ServicesÊý¾Ý°üÄڵıêÍ·Öµ£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬ÒÔϵͳ¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180620-fxnxos-fab-ace
2¡¢Cisco NX-OS Software NX-APIËÁÒâ´úÂëÖ´Ðзì϶
Cisco NX-OS Software NX-API×Ó·¨Ê½ÖеÄÉí·ÝÑé֤ģ¿éûÓÐÕýÈ·µÄÖ´ÐÐÊäÈëÑéÖ¤£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬ÒÔrootÓû§Éí·ÝÖ´ÐÐËÁÒâ´úÂë¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180620-nxos-bo
3¡¢NTP ntpqºÍntpdc CVE-2018-12327Õ»»º³åÇøÃýÎó·ì϶
NTP ntpqºÍntpdc´¦Öýϳ¤µÄ×Ö·û´®×÷ΪIPv4»òIPv6ºÅÁîÐеIJÎÊý´æÔÚ°²È«ÎÊÌ⣬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬ÒÔÀûÓ÷¨Ê½Ö´ÐÐËÁÒâ´úÂë¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://gist.github.com/fakhrizulkifli/9b58ed8e0354e8deee50b0eebd1c011f
4¡¢CA Privileged Access Manager CVE-2015-4664ÊäÈëÑéÖ¤ËÁÒâºÅÁîÖ´Ðзì϶
CA Privileged Access Manager´æÔÚÊäÈëÑéÖ¤·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬ÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâºÅÁî¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://support.ca.com/us/product-content/recommended-reading/security-notices/ca20180614-01--security-notice-for-ca-privileged-access-manager.html
5¡¢QEMU slirp/mbuf.c/m_cat¶Ñ»º³åÇøÒç¶Âí½Å
QEMUÔÚslirp/mbuf.c/m_catÖдæÔÚ»ùÓڶѵĻº³åÇøÒç¶Âí½Å£¬ÔÊÐí±¾µØ¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿Éʹϵͳ±ÀÀ£¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://bugzilla.redhat.com/show_bug.cgi?id=1586245
Èý¡¢³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢×êÑÐÈËÔ±ÖÒ¸æ³Æ¶ñÒâÈí¼þͨ¹ý¼Ù×°³Éµï±¤Ö®Ò¹°²×¿°æ½øÐд«²¼

ESETµÄ¶ñÒâÈí¼þ×êÑÐÈËÔ±Lukas Stefanko·¢ÏÖ²¿ÃŶñÒâÈí¼þͨ¹ý¼Ù×°³Éµï±¤Ö®Ò¹µÄ°²×¿°æ½øÐд«²¼¡£µï±¤Ö®Ò¹ÔÚÈ«ÇòÕ¼Óг¬¹ý1.25ÒÚÍæ¼Ò£¬µ«Æä¹Ù·½°²×¿°æ±¾ÉÐδ°ä²¼¡£×êÑÐÈËÔ±·¢ÏÖGoogleºÍYouTubeÉϵÄһЩÊÓÆµºÍÁ´½ÓÐû³ÆÆäÔ̺¬µï±¤Ö®Ò¹µÄAPKÎļþ£¬»òÊÇÊèµ¼Óû§×°ÖÃһЩÆäËüÀûÓÃÒÔ½âËø¸ÃÓÎÏ·£¬Õ⽫¸ø¶ñÒâÈí¼þ¿ª·¢ÈËÔ±´øÀ´ÊÕÈë»òÇÖº¦Óû§µÄ°²×¿É豸¡£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/06/fortnite-for-android-apk.html
2¡¢×êÑÐÈËÔ±³ÆmacOSµÄQuickLookÖ°Äܿɵ¼Ö¼ÓÃÜ´ÅÅ̵ÄÊý¾Ýй¶

Digita SecurityµÄ×êÑÐÈËÔ±Patrick WardleÖÒ¸æ³ÆmacOSÓû§´æ´¢ÔÚ¼ÓÃÜ´ÅÅÌÉϵÄÊý¾Ý²¢Ã»Óеõ½ºÜºÃµÄ±£»¤£¬ÓÉÓÚmacOSµÄQuickLookÖ°ÄÜÄܹ»±£ÁôͼƬµÈÎļþµÄÔ¤ÀÀ¡£µ±Í¨¹ýUI²é¿´Ä¿Â¼Ê±£¬QuickLook½«×Ô¶¯´´½¨»ººÍ´æÎļþµÄËõÂÔͼ£¬ÕâЩËõÂÔͼ±£ÁôÔÚSQLiteÊý¾Ý¿âÖУ¬¿Éͨ¹ýÓйغÅÁî½øÐÐÌáÈ¡¡£¼´±ãÔʼÎļþ±»É¾³ý£¬ÕâЩ»º´æÈԾɴæÔÚ¡£
ÔÎÄÁ´½Ó£ºhttps://threatpost.com/macos-quicklook-feature-leaks-data-despite-encrypted-drive/132905/
3¡¢º«¹ú¼ÓÃÜÇ®±ÒÂòÂôËùBithumbÒ»ÄêÄÚµÚ¶þ´ÎÔâºÚ¿ÍÈëÇÖ£¬Ô¼3100ÍòÃÀÔª±»ÇÔ

ƾ¾Ýº«¹ú¼ÓÃÜÇ®±ÒÂòÂôËùBithumbµÄÉêÃ÷£¬¸Ã¹«Ë¾ÔÚ6ÔÂ19ÈÕÖÁ20ÈÕµÄÒ¹¼äÔâµ½ºÚ¿ÍÈëÇÖ£¬¼ÛÖµÔ¼350ÒÚº«Ôª£¨3160ÍòÃÀÔª£©µÄ¼ÓÃÜÇ®±Ò±»ÇÔ¡£BithumbûÓÐй©¹ØÓÚÕâ´Î¹¥»÷µÄ¸ü¶àϸ½Ú£¬Ô̺¬ºÚ¿ÍÈôºÎ½øÈëϵͳºÍÈôºÎÇÔÈ¡×ʽ𡣸ù«Ë¾°µÊ¾´òËãÀûÓô¢Ðî»ù½ðÀ´Åâ³¥ÊÜËðʧµÄÓû§¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/bithumb-hacked-second-time-in-a-year-hackers-steal-31-million/
4¡¢Flightradar24ÔâºÚ¿ÍÈëÇÖ£¬Ô¼23ÍòÓû§µÄÐÅϢй¶

Èðµä¹«Ë¾Flightradar24֤ʵÆäһ̨·þÎñÆ÷ÓÚÉÏÖÜÄ©ÔâºÚ¿ÍÈëÇÖ£¬Ô¼23ÍòÓû§µÄµç×ÓÓʼþµØÖ·ºÍ¹þÏ£ÃÜÂëй¶¡£Flightradar24ÊÇÒ»¼ÒÌṩº½°à×·×Ù·þÎñµÄ¹«Ë¾£¬¸Ã¹«Ë¾°µÊ¾Õâ´Îй¶ӰÏìÁË2016Äê3ÔÂ16ÈÕ֮ǰע²áµÄÓû§¡£Flightradar24ÒÑÏòÓû§·¢ËÍÁËÔ̺¬ÃÜÂë³ÁÖÃÁ´½ÓµÄÓʼþ£¬ÒªÇóÕâЩÓû§¸ü¸ÄÃÜÂë¡£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/06/flightradar24-data-breach.html
5¡¢×êÑÐÈËÔ±·¢ÏÖ³¬¹ý3000¸öappµÄFirebaseÊý¾Ý¿â¿É¹«¿ª½Ó¼û

°²È«×êÑÐÈËÔ±·¢ÏÖ³¬¹ý3000¸öapp£¨Ô̺¬2446¸öAndroid appºÍ600¸öiOS app£©µÄÔ¼2300¸öFirebaseÊý¾Ý¿â¿É¹«¿ª½Ó¼û£¬³¬¹ý1ÒÚÌõÓû§ÐÅϢй¶£¨³¬¹ý113GB£©¡£ÕâЩй¶µÄÐÅÏ¢Ô̺¬Ã÷ÎÄÃÜÂë¡¢Óû§ID¡¢µØÎ»ÒÔ¼°²¿ÃŲÆÕþ¼Í¼£¨ÒøÐÓ×¢¼ÓÃÜÇ®±ÒÂòÂô£©µÈ¡£GoogleµÄFirebaseÊÇ×îÊÜÓ½ÓµÄÒÆ¶¯ºÍWebÀûÓõĺó¶Ë¿ª·¢Æ½Ì¨Ö®Ò»£¬ËüΪ¿ª·¢ÈËÔ±ÌṩÁË»ùÓÚÔÆµÄÊý¾Ý¿â£¬²¢ÒÔJSONÌåʽ´æ´¢Êý¾Ý¡£×êÑÐÈËÔ±·¢Ïֺܶ࿪·¢ÈËԱδÍ×ÉÆ±£»¤ÆäFirebaseÊý¾Ý¿â£¬Ê¹µÃ¹¥»÷ÕßÖ»ÐèÔÚÖ÷»úÃûĩβÔö³¤¿ÕÊý¾Ý¿âÃû+¡°/.json¡±¼´¿É½Ó¼ûÕâЩÊý¾Ý¡£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/06/mobile-security-firebase-hosting.html


¾©¹«Íø°²±¸11010802024551ºÅ