ÐÅÏ¢Äþ¾²Öܱ¨-2019ÄêµÚ12ÖÜ

Ðû²¼Ê±¼ä 2019-03-25

±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


2019Äê3ÔÂ18ÈÕÖÁ24ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´57¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇMozilla Firefox IonMonkey JIT±àÒëÆ÷ÀàÐÍ»ìÏý©¶´ £»Cisco IP Phone 7800/8800 Series sipÔ¶³Ì´úÂëÖ´ÐЩ¶´; CUJO Smart Firewall DHCPÖ÷»úÃûÃüÁî×¢È멶´ £»Adobe Photoshop CC¶ÑÒç³öÈÎÒâ´úÂëÖ´ÐЩ¶´ £»Wifi-soft UniBox controller CVE-2019-3495Ô¶³Ì´úÂëÖ´ÐЩ¶´ ¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇFacebookÃ÷ÎÄ´æ´¢ÊýÒÚÓû§ÃÜÂ룬±»Ô±¹¤¼ì²ì900Íò´Î £»¹È¸èÒò¹ã¸æ¢¶ÏÔÙ±»Å·ÃË·£¿î17ÒÚÃÀÔª £»Nork Hydro¹«Ë¾Ôâµ½ÀÕË÷Èí¼þLockerGoga¹¥»÷ £»89£¥µÄÅ·ÃËÕþ¸®ÍøÕ¾´æÔÚµÚÈý·½¹ã¸æ¸ú×ٽű¾ £»Epic GamesÊÕ¼¯SteamÓû§Òþ˽ÐÅÏ¢£¬ÔÊÐí½«½øÐÐÐÞ¸´ ¡£

ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖÐ ¡£


ÖØÒªÄþ¾²Â©¶´Áбí


1. Mozilla Firefox IonMonkey JIT±àÒëÆ÷ÀàÐÍ»ìÏý©¶´
Mozilla Firefox IonMonkey JIT±àÒëÆ÷´æÔÚÀàÐÍ»ìÏý©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄwebÇëÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹӦÓ÷¨Ê½±ÀÀ £»òÖ´ÐÐÈÎÒâ´úÂ룬
https://www.mozilla.org/en-US/security/advisories/mfsa2019-07/

2. Cisco IP Phone 7800/8800 Series sipÔ¶³Ì´úÂëÖ´ÐЩ¶´
Cisco IP Phone 7800/8800 WEB½Ó¿Ú´¦ÖöñÒâsipÏûÏ¢´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÖ´ÐÐÈÎÒâ´úÂë ¡£
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190320-ip-phone-rce

3. CUJO Smart Firewall DHCPÖ÷»úÃûÃüÁî×¢È멶´
CUJO Smart Firewall dhcpÊØ»¤½ø³Ì´æÔÚÊäÈëÑé֤©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿É×¢ÈëÈÎÒâÃüÁî²¢Ö´ÐÐ ¡£
https://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0703

4. Adobe Photoshop CC¶ÑÒç³öÈÎÒâ´úÂëÖ´ÐЩ¶´
Adobe Photoshop CC´¦ÖÃÎļþ´æÔÚ¶ÑÒç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÎļþÇëÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹӦÓ÷¨Ê½±ÀÀ £»òÖ´ÐÐÈÎÒâ´úÂë ¡£
https://helpx.adobe.com/security/products/photoshop/apsb19-15.html

5. Wifi-soft UniBox controller CVE-2019-3495Ô¶³Ì´úÂëÖ´ÐЩ¶´
Wifi-soft UniBox controller´æÔÚÔ¶³Ì´úÂë×¢È멶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÖ´ÐÐÈÎÒâ´úÂë ¡£
https://packetstormsecurity.com/files/151077/Wifi-soft-Unibox-2.x-Remote-Command-Code-Injection.html

 ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢FacebookÃ÷ÎÄ´æ´¢ÊýÒÚÓû§ÃÜÂ룬±»Ô±¹¤¼ì²ì900Íò´Î

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

±¾ÖÜËÄFacebookÈÏ¿ÉÊýÒÔÒڼƵÄFacebookºÍInstagramÓû§µÄÃÜÂë¶àÄêÀ´Ò»Ö±ÒÔÃ÷ÎĵÄÐÎʽ´æ´¢ÔÚÄÚ²¿Êý¾ÝϵͳÖÐ ¡£FacebookÔÚ1Ô·ݵÄÀýÐÐÄþ¾²Éó²éÆڼ䷢ÏÖÁËÕâÒ»ÎÊÌ⣬¸Ã¹«Ë¾ÌåÏÖÕâЩÊý¾Ý²¢Î´Ôâµ½ÀÄÓà ¡£Æ¾¾ÝÄþ¾²¼ÇÕßBrian KrebsµÄÒ»·Ý³ÂËߣ¬Ô¼2000Ãû¹¤³Ìʦ»ò¿ª·¢ÈËÔ±¶ÔÕâЩÊý¾Ý½øÐÐÁËԼĪ900Íò´ÎÄÚ²¿²éѯ ¡£FacebookÉÐδÅû¶ÊÜÓ°ÏìµÄ¾ßÌåÓû§ÈËÊý£¬µ«KrebsµÄ³ÂËßÖгÆÕâÒ»Êý×ÖΪ2ÒÚÖÁ6ÒÚÖ®¼ä ¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/facebook-employees-could-access-unencrypted-passwords-for-millions-of-users/

2¡¢¹È¸èÒò¹ã¸æ¢¶ÏÔÙ±»Å·ÃË·£¿î17ÒÚÃÀÔª


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


3ÔÂ20ÈÕÅ·ÃËίԱ»áÐû²¼ÉùÃ÷¶Ô¹È¸èµÄ¹ã¸æ¢¶ÏÐÐΪ·£¿î14.9ÒÚÅ·Ôª£¨Ô¼17ÒÚÃÀÔª£©£¬ÕâÊÇÁ½ÄêÄÚÅ·Ã˶Թȸ迪³öµÄµÚÈýÕÅ´ó¶î·´Â¢¶Ï·£µ¥ ¡£Å·ÃËίԱ»áÌåÏÖÕâÒ»·£¿îµÄÔ­ÒòÊǹȸèÀÄÓÃÆäÊг¡Ö÷µ¼Ö°Î»£¬×èÖ¹ÍøҳʹÓÃAdSenseƽ̨ÒÔÍâµÄ¹ã¸æ·þÎñ£¬ÕâÒ»·£½ðÏ൱Óڹȸè2018ÄêÓªÒµ¶îµÄ1.29% ¡£


Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/google-fined-17-billion-for-anti-competitive-practices-in-online-advertising/

3¡¢Nork Hydro¹«Ë¾Ôâµ½ÀÕË÷Èí¼þLockerGoga¹¥»÷


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


±¾ÖÜÒ»£¨3ÔÂ18ÈÕ£©Íí¼äŲÍþÂÁÒµ¾ÞÍ·Norsk HydroÔâµ½´ó¹æÄ£ÍøÂç¹¥»÷£¬¼¸¼Ò¹¤³§±»ÁÙʱ¹Ø±Õ ¡£ÔÚÐÂÎÅÐû²¼»áÉÏ£¬Norsk HydroÊ×ϯ²ÆÕþ¹ÙEivind Kallevik͸¶¸Ã¹«Ë¾Ôâµ½½ÏеÄÀÕË÷Èí¼þLockerGogaµÄ¹¥»÷£¬ÆäÉú²ú¼°ÔËÓª¾ùÊܵ½Ó°Ïì ¡£¸Ã¹«Ë¾±»ÆÈÔÚŲÍþ¡¢¿¨Ëþ¶ûºÍ°ÍÎ÷µÈ¹ú¼ÒÇл»ÖÁÈ˹¤²Ù×÷£¬ÒÔ»Ö¸´ÆäÔËÓª»î¶¯ ¡£Kallevik»¹ÌåÏָù«Ë¾ÒѾ­Äܹ»´¦ÖÃËùÓпͻ§µÄ¶©µ¥²¢½»¸¶£¬µ«Î´À´µÄ¶©µ¥¿ÉÄÜ»áÊܵ½Ó°Ï죬ÒòΪ¹«Ë¾ÍøÂçÈÔδ»Ö¸´ ¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/lockergoga-ransomware-sends-norsk-hydro-into-manual-mode/

4¡¢89£¥µÄÅ·ÃËÕþ¸®ÍøÕ¾´æÔÚµÚÈý·½¹ã¸æ¸ú×ٽű¾


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


µ¤Âóä¯ÀÀÆ÷·ÖÎö¹«Ë¾CookiebotÔÚ25¸öÅ·Ã˳ÉÔ±¹úµÄÕþ¸®¹ÙÍøÉÏ·¢ÏÖ¹ã¸æ¸ú×ٽű¾£¬Õâ´ó¸ÅÕ¼×ܹ²28¸ö³ÉÔ±¹úµÄ89%£¬Ö»Óе¹ú¡¢Î÷°àÑÀºÍºÉÀ¼µÄÕþ¸®ÍøվûÓÐÉÌÒµ¹ã¸æ¸ú×ÙÆ÷ ¡£·¨¹úÕþ¸®ÍøÕ¾ÉϵĹã¸æ¸ú×ÙÆ÷×î¶à£¬ÓÐ52¼Ò²îÒìµÄ¹«Ë¾ÔÚ¸ú×ÙÓû§µÄÐÐΪ ¡£ÕâЩ¹ã¸æ¸ú×ÙÆ÷Ö÷ÒªÊÇÔÚµÚÈý·½²å¼þµÄ×ÊÖúÏÂÉø͸½øÕþ¸®ÍøÕ¾£¬ÀýÈçÊÓƵ²¥·ÅÆ÷²å¼þ¡¢ÍøÕ¾·ÖÎö¼°Í¼±í²å¼þµÈ ¡£ÕâÏÔȻΥ·´ÁËÅ·Ã˵ÄÊý¾Ý± £»¤¹æÔòGDPR ¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/89-percent-of-eu-government-sites-infiltrated-by-ad-tracking-scripts/

5¡¢Epic GamesÊÕ¼¯SteamÓû§Òþ˽ÐÅÏ¢£¬ÔÊÐí½«½øÐÐÐÞ¸´


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Epic GamesÕë¶Ô¶àÏîÇÖ·¸Óû§Òþ˽µÄÖ¸¿Ø×ö³ö»ØÓ¦£¬²¢ÔÊÐí¶Ô¸ÃÎÊÌâ½øÐÐÐÞ¸´ ¡£ÓÎÏ·Íæ¼ÒÔÚRedditÉÏ·¢Ìû³Æ£¬Epic Games LauncherÔÚδ¾­Óû§Ðí¿ÉµÄÇé¿öÏÂɨÃè²¢ÊÕ¼¯Óû§µÄSteamÐÅÏ¢ ¡£Epic Games¹¤³Ì¸±×ܲÃDaniel Vogel»ØÓ¦³ÆEpic Games Store¿Í»§¶Ë´´½¨ÁËSteamÎļþlocalconfig.vdfµÄµ±µØ¼ÓÃܸ±±¾£¬µ±Óû§Ñ¡Ôñµ¼ÈëSteamÁªÏµÈËʱ£¬½«»á°ÑÓû§µÄÁªÏµÈ˹þÏ£ID·¢ËÍ»ØEpic ¡£Epic Games CEO Tim SweeneyÌåÏÖ½«¶ÔÓÐÕùÒéµÄÓû§Êý¾ÝÊÕ¼¯ÐÐΪ½øÐÐÐÞ¸´ ¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/epic-promises-to-fix-game-launcher-after-privacy-concerns/

ÉùÃ÷£º±¾×ÊѶÓɶ«É­Æ½Ì¨Î¬ËûÃüÄþ¾²Ð¡×é·­ÒëºÍÕûÀí