ÐÅÏ¢Äþ¾²Öܱ¨-2018ÄêµÚ25ÖÜ
Ðû²¼Ê±¼ä 2018-06-25
Ò»¡¢±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö
2018Äê06ÔÂ18ÈÕÖÁ24ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´46¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇCisco FXOS/NX-OS Software Fabric ServicesÔ¶³Ì´úÂëÖ´ÐЩ¶´£»Cisco NX-OS Software NX-APIÈÎÒâ´úÂëÖ´ÐЩ¶´£»NTP ntpqºÍntpdc CVE-2018-12327Õ»»º³åÇø´íÎ󩶴£»CA Privileged Access Manager CVE-2015-4664ÊäÈëÑéÖ¤ÈÎÒâÃüÁîÖ´ÐЩ¶´£»QEMU slirp/mbuf.c/m_cat¶Ñ»º³åÇøÒç³ö©¶´¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇÑо¿ÈËÔ±¾¯¸æ³Æ¶ñÒâÈí¼þͨ¹ýαװ³Éµï±¤Ö®Ò¹°²×¿°æ½øÐÐÁ÷´«£»Ñо¿ÈËÔ±³ÆmacOSµÄQuickLook¹¦Ð§¿Éµ¼Ö¼ÓÃÜ´ÅÅ̵ÄÊý¾Ýй¶£»º«¹ú¼ÓÃÜ»õ±Ò½»Ò×ËùBithumbÒ»ÄêÄÚµÚ¶þ´ÎÔâºÚ¿ÍÈëÇÖ£¬Ô¼3100ÍòÃÀÔª±»ÇÔ£»Flightradar24ÔâºÚ¿ÍÈëÇÖ£¬Ô¼23ÍòÓû§µÄÐÅϢй¶£»Ñо¿ÈËÔ±·¢ÏÖÁè¼Ý3000¸öappµÄFirebaseÊý¾Ý¿â¿É¹ûÈ»·ÃÎÊ¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£
¶þ¡¢ÖØÒªÄþ¾²Â©¶´Áбí
1¡¢Cisco FXOS/NX-OS Software Fabric ServicesÔ¶³Ì´úÂëÖ´ÐЩ¶´
Cisco FXOS/NX-OS Software Fabric Services×é¼þδÓÐЧÑéÖ¤Fabric ServicesÊý¾Ý°üÄڵıêÍ·Öµ£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó£¬ÒÔϵͳÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÄþ¾²²¹¶¡ÒÔÐÞ¸´¸Ã©¶´£ºhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180620-fxnxos-fab-ace
2¡¢Cisco NX-OS Software NX-APIÈÎÒâ´úÂëÖ´ÐЩ¶´
Cisco NX-OS Software NX-API×Ó·¨Ê½ÖеÄÉí·ÝÑé֤ģ¿éûÓÐÕýÈ·µÄÖ´ÐÐÊäÈëÑéÖ¤£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó£¬ÒÔrootÓû§Éí·ÝÖ´ÐÐÈÎÒâ´úÂë¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÄþ¾²²¹¶¡ÒÔÐÞ¸´¸Ã©¶´£ºhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180620-nxos-bo
3¡¢NTP ntpqºÍntpdc CVE-2018-12327Õ»»º³åÇø´íÎ󩶴
NTP ntpqºÍntpdc´¦Öýϳ¤µÄ×Ö·û´®×÷ΪIPv4»òIPv6ÃüÁîÐеIJÎÊý´æÔÚÄþ¾²ÎÊÌ⣬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó£¬ÒÔÓ¦Ó÷¨Ê½Ö´ÐÐÈÎÒâ´úÂë¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÄþ¾²²¹¶¡ÒÔÐÞ¸´¸Ã©¶´£ºhttps://gist.github.com/fakhrizulkifli/9b58ed8e0354e8deee50b0eebd1c011f
4¡¢CA Privileged Access Manager CVE-2015-4664ÊäÈëÑéÖ¤ÈÎÒâÃüÁîÖ´ÐЩ¶´
CA Privileged Access Manager´æÔÚÊäÈëÑé֤©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó£¬ÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâÃüÁî¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÄþ¾²²¹¶¡ÒÔÐÞ¸´¸Ã©¶´£ºhttps://support.ca.com/us/product-content/recommended-reading/security-notices/ca20180614-01--security-notice-for-ca-privileged-access-manager.html
5¡¢QEMU slirp/mbuf.c/m_cat¶Ñ»º³åÇøÒç³ö©¶´
QEMUÔÚslirp/mbuf.c/m_catÖдæÔÚ»ùÓڶѵĻº³åÇøÒç³ö©¶´£¬ÔÊÐíµ±µØ¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉʹϵͳÍ߽⡣
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÄþ¾²²¹¶¡ÒÔÐÞ¸´¸Ã©¶´£ºhttps://bugzilla.redhat.com/show_bug.cgi?id=1586245
Èý¡¢ÖØÒªÄþ¾²Ê¼þ×ÛÊö
1¡¢Ñо¿ÈËÔ±¾¯¸æ³Æ¶ñÒâÈí¼þͨ¹ýαװ³Éµï±¤Ö®Ò¹°²×¿°æ½øÐÐÁ÷´«

ESETµÄ¶ñÒâÈí¼þÑо¿ÈËÔ±Lukas Stefanko·¢ÏÖ²¿ÃŶñÒâÈí¼þͨ¹ýαװ³Éµï±¤Ö®Ò¹µÄ°²×¿°æ½øÐÐÁ÷´«¡£µï±¤Ö®Ò¹ÔÚÈ«ÇòÓµÓÐÁè¼Ý1.25ÒÚÍæ¼Ò£¬µ«Æä¹Ù·½°²×¿°æ±¾ÉÐδÐû²¼¡£Ñо¿ÈËÔ±·¢ÏÖGoogleºÍYouTubeÉϵÄһЩÊÓƵºÍÁ´½ÓÉù³ÆÆä°üÂ޵ﱤ֮ҹµÄAPKÎļþ£¬»òÊÇÒýµ¼Óû§°²×°Ò»Ð©ÆäËüÓ¦ÓÃÒÔ½âËø¸ÃÓÎÏ·£¬Õ⽫¸ø¶ñÒâÈí¼þ¿ª·¢ÈËÔ±´øÀ´ÊÕÈë»òËðº¦Óû§µÄ°²×¿É豸¡£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/06/fortnite-for-android-apk.html
2¡¢Ñо¿ÈËÔ±³ÆmacOSµÄQuickLook¹¦Ð§¿Éµ¼Ö¼ÓÃÜ´ÅÅ̵ÄÊý¾Ýй¶

Digita SecurityµÄÑо¿ÈËÔ±Patrick Wardle¾¯¸æ³ÆmacOSÓû§´æ´¢ÔÚ¼ÓÃÜ´ÅÅÌÉϵÄÊý¾Ý²¢Ã»Óеõ½ºÜºÃµÄ±£»¤£¬ÒòΪmacOSµÄQuickLook¹¦Ð§¿ÉÒÔÉú´æͼƬµÈÎļþµÄÔ¤ÀÀ¡£µ±Í¨¹ýUI¼ì²ìĿ¼ʱ£¬QuickLook½«×Ô¶¯´´½¨ºÍ»º´æÎļþµÄËõÂÔͼ£¬ÕâЩËõÂÔͼÉú´æÔÚSQLiteÊý¾Ý¿âÖУ¬¿Éͨ¹ýÏà¹ØÃüÁî½øÐÐÌáÈ¡¡£¼´Ê¹ÔʼÎļþ±»É¾³ý£¬ÕâЩ»º´æÒÀ¾É´æÔÚ¡£
ÔÎÄÁ´½Ó£ºhttps://threatpost.com/macos-quicklook-feature-leaks-data-despite-encrypted-drive/132905/
3¡¢º«¹ú¼ÓÃÜ»õ±Ò½»Ò×ËùBithumbÒ»ÄêÄÚµÚ¶þ´ÎÔâºÚ¿ÍÈëÇÖ£¬Ô¼3100ÍòÃÀÔª±»ÇÔ

ƾ¾Ýº«¹ú¼ÓÃÜ»õ±Ò½»Ò×ËùBithumbµÄÉùÃ÷£¬¸Ã¹«Ë¾ÔÚ6ÔÂ19ÈÕÖÁ20ÈÕµÄÒ¹¼äÔâµ½ºÚ¿ÍÈëÇÖ£¬¼ÛÖµÔ¼350ÒÚº«Ôª£¨3160ÍòÃÀÔª£©µÄ¼ÓÃÜ»õ±Ò±»ÇÔ¡£BithumbûÓÐ͸¶¹ØÓڴ˴ι¥»÷µÄ¸ü¶àϸ½Ú£¬°üÂÞºÚ¿ÍÈçºÎ½øÈëϵͳºÍÈçºÎÇÔÈ¡×ʽ𡣸ù«Ë¾ÌåÏּƻ®ÀûÓô¢Ðî»ù½ðÀ´Åâ³¥ÊÜËðʧµÄÓû§¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/bithumb-hacked-second-time-in-a-year-hackers-steal-31-million/
4¡¢Flightradar24ÔâºÚ¿ÍÈëÇÖ£¬Ô¼23ÍòÓû§µÄÐÅϢй¶

Èðµä¹«Ë¾Flightradar24֤ʵÆäһ̨·þÎñÆ÷ÓÚÉÏÖÜÄ©ÔâºÚ¿ÍÈëÇÖ£¬Ô¼23ÍòÓû§µÄµç×ÓÓʼþµØÖ·ºÍ¹þÏ£ÃÜÂëй¶¡£Flightradar24ÊÇÒ»¼ÒÌṩº½°à×·×Ù·þÎñµÄ¹«Ë¾£¬¸Ã¹«Ë¾ÌåÏÖ´Ë´Îй¶ӰÏìÁË2016Äê3ÔÂ16ÈÕ֮ǰע²áµÄÓû§¡£Flightradar24ÒÑÏòÓû§·¢ËÍÁË°üÂÞÃÜÂëÖØÖÃÁ´½ÓµÄÓʼþ£¬ÒªÇóÕâЩÓû§¸ü¸ÄÃÜÂë¡£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/06/flightradar24-data-breach.html
5¡¢Ñо¿ÈËÔ±·¢ÏÖÁè¼Ý3000¸öappµÄFirebaseÊý¾Ý¿â¿É¹ûÈ»·ÃÎÊ

Äþ¾²Ñо¿ÈËÔ±·¢ÏÖÁè¼Ý3000¸öapp£¨°üÂÞ2446¸öAndroid appºÍ600¸öiOS app£©µÄÔ¼2300¸öFirebaseÊý¾Ý¿â¿É¹ûÈ»·ÃÎÊ£¬Áè¼Ý1ÒÚÌõÓû§ÐÅϢй¶£¨Áè¼Ý113GB£©¡£ÕâЩ鶵ÄÐÅÏ¢°üÂÞÃ÷ÎÄÃÜÂë¡¢Óû§ID¡¢Î»ÖÃÒÔ¼°²¿ÃŲÆÕþ¼Ç¼£¨ÒøÐС¢¼ÓÃÜ»õ±Ò½»Ò×£©µÈ¡£GoogleµÄFirebaseÊÇ×îÊÜ»¶ÓµÄÒƶ¯ºÍWebÓ¦Óõĺó¶Ë¿ª·¢Æ½Ì¨Ö®Ò»£¬ËüΪ¿ª·¢ÈËÔ±ÌṩÁË»ùÓÚÔƵÄÊý¾Ý¿â£¬²¢ÒÔJSON¸ñʽ´æ´¢Êý¾Ý¡£Ñо¿ÈËÔ±·¢ÏÖÐí¶à¿ª·¢ÈËԱδÍ×ÉƱ£»¤ÆäFirebaseÊý¾Ý¿â£¬Ê¹µÃ¹¥»÷ÕßÖ»ÐèÔÚÖ÷»úÃûĩβÌí¼Ó¿ÕÊý¾Ý¿âÃû+¡°/.json¡±¼´¿É·ÃÎÊÕâЩÊý¾Ý¡£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/06/mobile-security-firebase-hosting.html