ÐÅÏ¢Äþ¾²Öܱ¨-2018ÄêµÚ47ÖÜ

Ðû²¼Ê±¼ä 2018-11-26

 ±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


2018Äê11ÔÂ19ÈÕÖÁ25ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´48¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇApache Sparkµ¥»ú×ÊÔ´¹ÜÀíÆ÷ÈÎÒâ´úÂëÖ´ÐЩ¶´ £»Dell EMC Avamar Server/EMC Integrated Data Protection Appliance CVE-2018-11077ÃüÁî×¢È멶´ £»TP-Link TL-R600VPN HTTP Server CVE-2018-3950»º³åÇøÒç³ö©¶´ £»Adobe Flash PlayerÀàÐÍ»ìÏýÔ¶³Ì´úÂëÖ´ÐЩ¶´ £»Google Chrome GPUÊͷźóʹÓ鶴¡£



±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇ°µÍøÍйܷþÎñÉÌDaniel's HostingÔâºÚ¿ÍÈëÇÖ£¬Áè¼Ý6500¸öÍøÕ¾±»É¾ £»Ñо¿»ú¹¹Åû¶ͨ¹ýÀ¶ÑÀÈëÇÖÆû³µµÄCarsBlues¹¥»÷£¬ÒÉÓ°ÏìÊýǧÍòÆû³µ £»¿¨°Í˹»ùÐû²¼2019ÄêÍøÂçÍþвÇ÷ÊƵÄÔ¤²â³ÂËß £»VMwareÐû²¼¸üУ¬ÐÞ¸´ÐéÄâ»úÌÓÒÝ©¶´CVE-2018-6983 £»¼ÓÃÜÓʼþ·þÎñÉÌProtonMailÔâµ½ÒÉËÆÀÕË÷Èí¼þÇÃÕ©¹¥»÷¡£



ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£




ÖØÒªÄþ¾²Â©¶´Áбí


1. Apache Sparkµ¥»ú×ÊÔ´¹ÜÀíÆ÷ÈÎÒâ´úÂëÖ´ÐЩ¶´


Apache Sparkµ¥»ú×ÊÔ´¹ÜÀíÆ÷´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó£¬ÔÚ¡®master¡¯Ö÷»úÉÏÖ´ÐдúÂë¡£

https://lists.apache.org/thread.html/341c3187f15cdb0d353261d2bfecf2324d56cb7db1339bfc7b30f6e5@%3Cdev.spark.apache.org%3E



2. Dell EMC Avamar Server/EMC Integrated Data Protection Appliance CVE-2018-11077ÃüÁî×¢È멶´


Dell EMC Avamar Server/EMC Integrated Data Protection Appliance´æÔÚÊäÈëÑé֤©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó£¬ÒÔrootȨÏÞÖ´ÐÐÈÎÒâÃüÁî¡£

http://packetstormsecurity.com/files/150420/Dell-EMC-Avamar-IDPA-Command-Injection.html



3. TP-Link TL-R600VPN HTTP Server CVE-2018-3950»º³åÇøÒç³ö©¶´


TP-Link TL-R600VPN HTTP Server´æÔÚ»º³åÇøÒç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿Éʹϵͳ±ÀÀ £»ò¿ÉÖ´ÐÐÈÎÒâ´úÂë¡£

https://www.tp-link.com/us/products/details/cat-4909_TL-R600VPN.html



4. Adobe Flash PlayerÀàÐÍ»ìÏýÔ¶³Ì´úÂëÖ´ÐЩ¶´


Adobe Flash Player´æÔÚÀàÐÍ»ìÏý©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÎļþÇëÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉÖ´ÐÐÈÎÒâ´úÂë¡£

https://helpx.adobe.com/security/products/flash-player/apsb18-44.html



5. Google Chrome GPUÊͷźóʹÓ鶴


Google Chrome GPU´æÔÚÊͷźóʹÓ鶴£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄWEBÇëÇ󣬿ÉʹӦÓ÷¨Ê½±ÀÀ £»òÖ´ÐÐÈÎÒâ´úÂë¡£

https://chromereleases.googleblog.com/2018/11/stable-channel-update-for-desktop_19.html





 ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢°µÍøÍйܷþÎñÉÌDaniel's HostingÔâºÚ¿ÍÈëÇÖ£¬Áè¼Ý6500¸öÍøÕ¾±»É¾

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


11ÔÂ15ÈÕ°µÍø×î´óµÄÍøÂçÍйܷþÎñÉÌDaniel's HostingÔâµ½ºÚ¿ÍÈëÇÖ£¬¹¥»÷Õßɾ³ýÁË6500¶à¸öÍøÕ¾£¬¶øÇÒÕâЩÍøÕ¾¶¼Ã»Óб¸·Ý¡£¸ÃÍйܷþÎñÉ̱³ºóµÄ¿ª·¢ÈËÔ±Daniel Winzen֤ʵ³Æ£¬·þÎñÆ÷µÄrootÕË»§Ò²±»É¾³ýÁË£¬¶øÇÒƽ̨ÉÏÍйܵÄÁè¼Ý6500¸öÍøÕ¾µÄÊý¾Ý¶¼Òѳ¹µ×¶ªÊ§¡£¹¥»÷Õß¿ÉÄÜÊÇÀûÓÃÁËphpÖеÄÁãÈÕ©¶´£¬µ«Ò²ÓпÉÄÜÊÇÀûÓÃÁËÆäËüµÄ©¶´¡£Ä¿Ç°»¹Ã»Óй¥»÷ÕßÐû³Æ¶Ô´ËÊÂÂôÁ¦¡£

Ô­ÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/78165/cyber-crime/daniels-hosting-hacked.html


2¡¢Ñо¿»ú¹¹Åû¶ͨ¹ýÀ¶ÑÀÈëÇÖÆû³µµÄCarsBlues¹¥»÷£¬ÒÉÓ°ÏìÊýǧÍòÆû³µ

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Privacy4Cars·¢ÏÖÒ»ÖÖͨ¹ýÀ¶ÑÀÈëÇÖÆû³µµÄCarsBlues¹¥»÷£¬¸Ã¹¥»÷ÒªÁìÓëÏÖ´ú³µÁ¾ÖеijµÔØÓéÀÖϵͳÓйØ£¬Í¨¹ýÀ¶ÑÀЭÒ飬¹¥»÷Õß¿É»ñµÃÓû§µÄÁªÏµÈËÁÐ±í¡¢Í¨»°¼Ç¼¡¢Îı¾ÈÕÖ¾ÉõÖÁÊǶÌÐÅÄÚÈݵȸöÈËÐÅÏ¢¡£Privacy4Cars³ÆÕâÖÖ¹¥»÷Ö»ÐèҪʹÓÃÁ®¼ÛÇÒÒ×ÓÚ»ñµÃµÄÓ²¼þ/Èí¼þÔÚ¼¸·ÖÖÓÄÚ¼´¿ÉÍê³É£¬¶øÇÒ²»ÐèÒª¸ßÉîµÄ¼¼Êõ֪ʶ¡£È«ÇòÊýǧÍòÁ¾Æû³µÒÉÊܵ½Ó°Ï죬²¿Ãų§ÉÌÒѾ­Ðû²¼Á˸üС£


Ô­ÎÄÁ´½Ó£º

https://www.privacy4cars.com/can-my-car-be-hacked/default.aspx


3¡¢¿¨°Í˹»ùÐû²¼2019ÄêÍøÂçÍþвÇ÷ÊƵÄÔ¤²â³ÂËß

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¿¨°Í˹»ùʵÑéÊÒÐû²¼¶Ô2019ÄêÍøÂçÍþвÇ÷ÊƵÄÒ»¸öÔ¤²â·ÖÎö£¬Ö÷ÒªÄÚÈÝ°üÂÞ£º»òÐí²»»áÔÙ·¢ÏÖ¸ü¶àµÄ´óÐÍAPT×éÖ¯ £»ÍøÂçÓ²¼þÓëÎïÁªÍøÍþв½«»á²»Í£ÔöÇ¿ £»ÓëÍâ½»ºÍÕþÖÎÓйصĹûÈ»Åê»÷ £»¶«ÄÏÑǺÍÖж«µØÓò»òÐí»á·ºÆð¸ü¶àµÄ¹¥»÷×éÖ¯ £»£¨Ring -£©È¨ÏÞ£¬±ÈRing 0¸ü¸ßµÄȨÏÞ £»×îÊÜ»¶Ó­µÄѬȾý½é-µöÓã £»»ò½«·ºÆð¸ü¶àÀàËÆ¡°°ÂÔËÇýÖ𽢡±µÄ¹¥»÷ £»¹©Ó¦Á´¹¥»÷½«¼ÌÐø £»Òƶ¯¶ñÒâÈí¼þ²»»á·ºÆð´ó·¢×÷£¬µ«¸ß¼¶¹¥»÷Õß»á¼ÌÐøÑ°ÕÒÈëÇÖÉ豸µÄÒªÁì¡£


Ô­ÎÄÁ´½Ó£º
https://securelist.com/kaspersky-security-bulletin-threat-predictions-for-2019/88878/


4¡¢VMwareÐû²¼¸üУ¬ÐÞ¸´ÐéÄâ»úÌÓÒÝ©¶´CVE-2018-6983

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


VMwareÐÞ¸´Ì츮±­ÉÏÅû¶µÄÐéÄâ»úÌÓÒÝ©¶´£¨CVE-2018-6983£©£¬¸Ã©¶´ÊÇÒ»¸öÕûÊýÒç³ö©¶´£¬ÀÖ³ÉÀûÓø鶴¿Éµ¼ÖÂÐéÄâ»úÌÓÒݲ¢ÔÚËÞÖ÷»úÉÏÖ´ÐдúÂë¡£ÊÜÓ°ÏìµÄ²úÎï°üÂÞVMware Workstation¡¢VMware FusionµÈ£¬VMwareÔÚWorkstation°æ±¾ 14.1.2/15.0.2¼°Fusion°æ±¾10.1.5/11.0.2ÖÐÐÞ¸´Á˸鶴£¬½¨ÒéÓû§¾¡¿ì½øÐиüС£


Ô­ÎÄÁ´½Ó£º
https://www.vmware.com/security/advisories/VMSA-2018-0030.html


5¡¢¼ÓÃÜÓʼþ·þÎñÉÌProtonMailÔâµ½ÒÉËÆÀÕË÷Èí¼þÇÃÕ©¹¥»÷

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Á÷ÐеļÓÃܵç×ÓÓʼþ·þÎñProtonMailÔâµ½ÒÉËÆÀÕË÷Èí¼þÇÃÕ©µÄ¹¥»÷»î¶¯¡£¹¥»÷ÕßAmFearLiathMorÉù³ÆÈëÇÖÁ˸ù«Ë¾²¢ÇÔÈ¡ÁË¡°´óÁ¿¡±µÄÓû§Êý¾Ý¡£¹¥»÷Õß½«ÆäÊê½ðÒªÇóÐû²¼ÔÚPastebinÉÏ£¬²¢ÍþвҪÏòÈ«ÊÀ½çÐû²¼»òÏúÊÛÕâЩÊý¾Ý£¬µ«²¢Î´Ìṩ±»µÁÊý¾ÝµÄÑù±¾¡£ProtonMailÔÚÊÓ²ìÖ®ºó·ñÈÏÁËÕâÆð¹¥»÷ʼþ£¬Éù³ÆÕâÖ»ÊÇÒ»¸öÊÔͼÇÃÕ©µÄÆ­¾Ö¡£


Ô­ÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/78133/hacking/protonmail-hacked-hoax.html


ÉùÃ÷£º±¾×ÊѶÓɶ«É­Æ½Ì¨Î¬ËûÃüÄþ¾²Ð¡×é·­ÒëºÍÕûÀí