ÐÅÏ¢°²È«Öܱ¨-2018ÄêµÚ35ÖÜ

°ä²¼¹¦·ò 2018-09-03

Ò»¡¢±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


        2018Äê08ÔÂ27ÈÕÖÁ9ÔÂ02ÈÕ¹²ÊÕ¼°²È«·ì϶54¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇÌÚѶFoxmailºÅÁî×¢Èë·ì϶ £»OpenSSH auth-gss2.cÓû§Ã¶¾Ù·ì϶ £»Google Chrome Blob API»º³åÇøÒç¶Âí½Å £»Emerson DeltaV DCS Workstation»º³åÇøÒç¶Âí½Å £»Adobe Acrobat/Reader CVE-2018-12808Ô½½çдËÁÒâ´úÂëÖ´Ðзì϶¡£


        ±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊǰ®¶ûÀ¼µçÐŹ«Ë¾EirµÄһ̨±Ê¼Ç±¾±»µÁ£¬µ¼ÖÂÔ¼3.7ÍòÓû§µÄÐÅϢй¶;AppleÔÚÏßÉ̵êÖеķì϶µ¼Ö³¬¹ý7700ÍòT-MobileÓû§ÕË»§µÄPINÂë¶³ö;AbbyyÒòÊý¾Ý¿âÅäÖÃÃýÎóµ¼ÖÂ20¶àÍò¸ö¿Í»§Îļþй¶;Î÷°àÑÀÒøÐйÙÍøÔâµ½DDoS¹¥»÷£¬ÍøÕ¾ÁÙʱÎÞ·¨½Ó¼û;¼ÓÄô󺽿չ«Ë¾ÔâºÚ¿ÍÈëÇÖ£¬Ô¼2ÍòÃûÓû§µÄÐÅÏ¢ÒÉй¶¡£


        ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖС£


 


¶þ¡¢³ÁÒª°²È«·ì϶Áбí


1¡¢ÌÚѶFoxmailºÅÁî×¢Èë·ì϶


        Tencent Foxmail URI´¦ÖôæÔÚÊäÈëÑéÖ¤·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþ»òÒ³ÃæÒªÇó£¬ÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâºÅÁî¡£


        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://www.zerodayinitiative.com/advisories/ZDI-18-584/


2¡¢OpenSSH auth-gss2.cÓû§Ã¶¾Ù·ì϶


        OpenSSH auth-gss2.c´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬ÅжÏÓû§Ãû¡£


        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttp://seclists.org/oss-sec/2018/q3/180


3¡¢Google Chrome Blob API»º³åÇøÒç¶Âí½Å


        Google Chrome Blob API´æÔÚ¶ÑÒç¶Âí½Å£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄWEBÒ³£¬ÓÕʹÓû§½âÎö£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ £»òÖ´ÐÐËÁÒâ´úÂë¡£


        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://chromereleases.googleblog.com/2017/12/stable-channel-update-for-desktop.html


4¡¢Emerson DeltaV DCS Workstation»º³åÇøÒç¶Âí½Å


        Emerson Electric DeltaVÊ¢¿ªÍ¨Ñ¶¶Ë¿Ú´æÔÚÕ»Òç¶Âí½Å£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉʹÀûÓ÷¨Ê½±ÀÀ £»òÖ´ÐÐËÁÒâ´úÂë¡£


        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://ics-cert.us-cert.gov/advisories/ICSA-18-228-01


5¡¢Adobe Acrobat/Reader CVE-2018-12808Ô½½çдËÁÒâ´úÂëÖ´Ðзì϶


        Adobe Acrobat/Reader´¦ÖÃPDFÎļþ´æÔÚÔ½½çд·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇó£¬ÓÕʹÓû§½âÎö£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£


        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://helpx.adobe.com/security/products/acrobat/apsb18-29.html


 


Èý¡¢³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢°®¶ûÀ¼µçÐŹ«Ë¾EirµÄһ̨±Ê¼Ç±¾±»µÁ£¬µ¼ÖÂÔ¼3.7ÍòÓû§µÄÐÅϢй¶



GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


        ƾ¾Ý°®¶ûÀ¼µçÐŹ«Ë¾Eir¹ÙÍøÉϵÄ֪ͨ£¬¸Ã¹«Ë¾µÄһ̨Ô̺¬Óû§Êý¾ÝµÄδ¼ÓÃܵıʼDZ¾µçÄÔÔâÇÔ£¬µ¼ÖÂÔ¼3.7ÍòÓû§µÄÓ×ÎÒÐÅϢй¶¡£Ð¹Â¶µÄÊý¾ÝÔ̺¬ÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂëºÍeirÕ˺Å¡£¸Ã¹«Ë¾³ÆÐ¹Â¶µÄÊý¾Ý²»Ô̺¬ÈκÎÓû§µÄ²ÆÕþÊý¾Ý¡£Ä¿Ç°¸Ã¹«Ë¾ÒÑÏòÊý¾Ý± £»¤×¨Ô±ºÍ°®¶ûÀ¼¾¯Ô±´«µÝÁËÕâ´ÎÊÂÎñ¡£


        Ô­ÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/75655/data-breach/eir-data-breach.html


2¡¢AppleÔÚÏßÉ̵êÖеķì϶µ¼Ö³¬¹ý7700ÍòT-MobileÓû§ÕË»§µÄPINÂë¶³ö



GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


        ƾ¾ÝÃÀýBuzzFeedNewsµÄ±¨Â·£¬AppleÔÚÏßÉ̵êÖеķì϶µ¼Ö³¬¹ý7700ÍòT-MobileÓû§ÕË»§µÄPINÂë¶³ö¡£´Ë±í£¬ÊÖ»ú±£ÏÕ¹«Ë¾AsurionµÄ¹ÙÍøÒ²´æÔÚÒ»¸ö·ì϶£¬µ¼ÖÂAsurionµÄAT£¦T¿Í»§µÄPINÂë¶³ö¡£ÕâÁ½¸ö·ì϶ÊÇÓɰ²È«×êÑÐÈËÔ±PhobiaºÍNicholas ¡°Convict¡± Ceraolo·¢Ïֵġ£AppleÍøÕ¾Éϵķì϶¿ÉÄÜÓ뼯³ÉT-MobileµÄÕÊ»§ÑéÖ¤APIʱµÄ¹¤³ÌÃýÎóÓйØ¡£AppleºÍAsurionÒѾ­½¨¸´ÁËÓйطì϶¡£


        Ô­ÎÄÁ´½Ó£ºhttps://www.buzzfeednews.com/article/nicolenguyen/tmobile-att-account-pin-security-flaw-apple


3¡¢AbbyyÒòÊý¾Ý¿âÅäÖÃÃýÎóµ¼ÖÂ20¶àÍò¸ö¿Í»§Îļþй¶

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


        8ÔÂ19ÈÕ°²È«×êÑÐÈËÔ±Bob DiachenkoÔÚAWSÔÆÆ½Ì¨ÉÏ·¢ÏÖÊôÓÚOCRÈí¼þ¿ª·¢ÉÌAbbyyµÄÒ»¸öMongoDB·þÎñÆ÷ÎÞÐèµÇ¼¼´¿É¹«¿ª½Ó¼û¡£¸ÃÊý¾Ý¿â´óÓ×Ϊ142GB£¬Ô̺¬¶àÖÖÃô¸ÐÎļþµÄɨÃè¼þ£¬ÈçºÏͬ¡¢±£ÃܺÍ̸¡¢ÄÚ²¿º¯¼þ¼°±¸Íü¼µÈ¡£ÆäÖÐÔ̺¬ÊôÓÚAbbyy¿Í»§µÄ20¶àÍò¸öÎļþ¡£¸ÃÊý¾Ý¿â¿ÉÄÜÊÇAbbyyµÄ»ù´¡ÉèÊ©µÄÒ»²¿ÃÅ¡£AbbyyµÄ°²È«ÍŶÓÔÚ½Óµ½Í¨ÖªÁ½Ììºó½¨¸´Á˸ÃÊý¾Ý¿âµÄÅäÖÃÃýÎóÎÊÌâ¡£


        Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/ocr-software-dev-exposes-200-000-customer-documents/


4¡¢Î÷°àÑÀÒøÐйÙÍøÔâµ½DDoS¹¥»÷£¬ÍøÕ¾ÁÙʱÎÞ·¨½Ó¼û



GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


        ƾ¾Ý·͸ÉçµÄ±¨Â·£¬´Ó8ÔÂ26ÈÕÐÇÆÚÈÕÆðÍ·Î÷°àÑÀÒøÐеĹÙÍøÔâµ½ÁËÉ¢²¼Ê½»Ø¾ø·þÎñ¹¥»÷£¨DDoS£©£¬ÆäÍøÕ¾ÁÙʱÎÞ·¨½Ó¼û¡£¸ÃÒøÐеĽ²»°È˰µÊ¾£¬Õâ´Î¹¥»÷¶Ô¸ÃÒøÐеķþÎñ»ò¸ÃÒøÐÐÓëÅ·ÖÞÖÐÑëÒøÐлòÆäËü»ú¹¹µÄͨѼû»ÓÐÔì³ÉÈκÎÓ°Ï죬²¢ÇÒûÓÐÈκÎÊý¾Ýй¶µÄ·çÏÕ¡£½ØÖÁÖܶþÏÂÎ磬¸ÃÒøÐеÄÍøÕ¾ÈÔ´¦ÓÚÀëÏß״̬¡£


        Ô­ÎÄÁ´½Ó£ºhttps://uk.reuters.com/article/us-spain-cyber-cenbank/bank-of-spains-website-hit-by-cyber-attack-idUKKCN1LC23B


5¡¢¼ÓÄô󺽿չ«Ë¾ÔâºÚ¿ÍÈëÇÖ£¬Ô¼2ÍòÃûÓû§µÄÐÅÏ¢ÒÉй¶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



        8ÔÂ22ÈÕÖÁ24ÈÕÆÚ¼ä£¬¼ÓÄô󺽿չ«Ë¾·¢ÏÖÒì³£µÄµÇ¼»î¶¯£¬ÎªÁ˱ £»¤Óû§µÄÊý¾Ý£¬¸Ã¹«Ë¾Ëø¶¨ÁËËùÓÐ170ÍòÒÆ¶¯appÓû§µÄÕË»§¡£29ÈÕ£¬¸Ã¹«Ë¾Í¨ÖªÔ¼2ÍòÃûÓû§£¬³ÆÆäÓ×ÎÒ×ÊÁÏ¿ÉÄÜÔ⵽δÊÚȨµÄ½Ó¼û¡£ÕâЩ×ÊÁÏÖÁÉÙÔ̺¬ÐÕÃû¡¢µç×ÓÓʼþµØÖ·ºÍµç»°ºÅÂ룬Ҳ¿ÉÄÜÔ̺¬ÐԱ𡢵®ÉúÈÕÆÚ¡¢¹ú¼®¡¢»¤ÕÕºÅÂëµÈÐÅÏ¢¡£ÔÚÒ»·Ý¹ØÓÚ¸ÃÊÂÎñµÄÉêÃ÷Öиù«Ë¾°µÊ¾Óû§µÄÒøÐп¨Êý¾ÝÒÔ¼°aircanada.comÕÊ»§²»ÊÜÓ°Ïì¡£


        Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/air-canada-mobile-app-users-affected-by-data-breach/