ÐÅÏ¢Äþ¾²Öܱ¨-2019ÄêµÚ35ÖÜ
Ðû²¼Ê±¼ä 2019-09-09> ±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö
2019Äê9ÔÂ02ÈÕÖÁ08ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´46¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇBD PyxisδÊÚȨ·ÃÎÊ©¶´£»Mozilla Firefox CVE-2019-11741ͨÓÿçÕ¾½Å±¾¹¥»÷©¶´£»CA Automic Workload Automation DIA CA Common Services´úÂëÖ´ÐЩ¶´£»Aruba Mobility Controller WEB×é¼þÃüÁî×¢È멶´£»Samba CVE-2019-10197Ŀ¼±éÀú©¶´¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇÈýÐÇ¡¢»ªÎªµÈÊÖ»úÒ×ÊÜOMA CP¶ÌÐÅÖ¸ÁîÆÛƹ¥»÷£»FacebookÓû§µç»°ºÅÂëÊý¾Ý¿âй¶£¬Éæ¼°4.19ÒÚÌõ¼Ç¼£»FacebookÓû§µç»°ºÅÂëÊý¾Ý¿âй¶£¬Éæ¼°4.19ÒÚÌõ¼Ç¼£»Ó¢¹ú¹ú»áÒéÔ±ÔÚ2019²ÆÄê½ÓÊÕµ½½ü2100Íò·âÀ¬»øÓʼþ£»Windows 10 KB4512941¸üе¼ÖÂCortanaÕ¼ÓÃCPU¹ý¸ß¡£
> ÖØÒªÄþ¾²Â©¶´Áбí
1. BD PyxisδÊÚȨ·ÃÎÊ©¶´
https://www.us-cert.gov/ics/advisories/icsma-19-248-01
2. Mozilla Firefox CVE-2019-11741ͨÓÿçÕ¾½Å±¾¹¥»÷©¶´
https://www.mozilla.org/en-US/security/advisories/mfsa2019-25/
3. CA Automic Workload Automation DIA CA Common Services´úÂëÖ´ÐЩ¶´
https://www.auscert.org.au/bulletins/ESB-2019.3374/
4. Aruba Mobility Controller WEB×é¼þÃüÁî×¢È멶´
https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2019-004.txt
5. Samba CVE-2019-10197Ŀ¼±éÀú©¶´
https://www.samba.org/samba/security/CVE-2019-10197.html
> ÖØÒªÄþ¾²Ê¼þ×ÛÊö
Check PointÑо¿ÈËÔ±·¢ÏÖËļÒÖÇÄÜÊÖ»úÖÆÔìÉÌ£¨°üÂÞÈýÐÇ¡¢»ªÎª¡¢LGºÍË÷ÄᣩδÔÚÆäÉ豸ÉÏʵʩÄþ¾²µÄOMA CPÖ¸Áî³ß¶È£¬Ê¹µÃ¹¥»÷Õß¿ÉÒÔͨ¹ýαÔìOMA CP¶ÌÐÅÖ¸ÁîÓÕÆÓû§ÐÞ¸ÄÉ豸ÅäÖ㬴ӶøÀ¹½ØÆäµç×ÓÓʼþ»òÍøÂçÁ÷Á¿¡£OMA CP´ú±í¿ª·ÅÒƶ¯ÁªÃË¿Í»§¶ËÅäÖã¬ËüÖ¸µÄÊÇÒƶ¯ÔËÓªÉÌ¿Éͨ¹ýÌض¨¶ÌÐŽ«ÍøÂçÉèÖ÷¢Ë͵½Óû§É豸µÄÒ»Öֳ߶ȡ£Ñо¿ÈËÔ±³ÆÈýÐǵÄÊÖ»ú×î²»Äþ¾²£¬ÒòΪËü¿ÉÒÔ½ÓÊÜÈκÎÀàÐ͵ÄOMA CPÏûÏ¢¶øÇÒûÓÐÈÏÖ¤»òÑéÖ¤»úÖÆ¡£ÈýÐǺÍLG·Ö±ðÓÚ5Ô·ݺÍ7Ô·ÝÐû²¼ÁËÐÞ¸´²¹¶¡£¬»ªÎªÌåÏÖ½«ÔÚÏÂÒ»´úMate»òPϵÁÐÊÖ»úÖмÓÈëÐÞ¸´²¹¶¡£¬µ«Ë÷Äá¾Ü¾øÈϿɸ鶴¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/samsung-huawei-lg-and-sony-phones-vulnerable-to-rogue-provisioning-messages/
2¡¢FacebookÓû§µç»°ºÅÂëÊý¾Ý¿âй¶£¬Éæ¼°4.19ÒÚÌõ¼Ç¼
Ñо¿ÈËÔ±·¢ÏÖÒ»¸ö´æ´¢ÁËÊýÒÚFacebookÓû§µç»°ºÅÂë¼Ç¼µÄÊý¾Ý¿âÔÚÍøÉÏ̻¶¡£ÕâЩÊý¾Ý×ÜÊýÁè¼Ý4.19ÒÚÌõ¼Ç¼£¬º¸Ç¶à¸öµØÓò£¬ÆäÖаüÂÞ1.33ÒÚÌõÃÀ¹úFacebookÓû§¼Ç¼¡¢1800ÍòÓ¢¹úÓû§¼Ç¼ÒÔ¼°5000¶àÍòÔ½ÄÏÓû§¼Ç¼¡£¾ßÌå¶øÑÔ£¬Ã¿Ìõ¼Ç¼¶¼°üÂÞÓû§µÄΨһFacebook IDºÍÕË»§¹ØÁªµÄµç»°ºÅÂë¡£ÓÉÓÚ´æ´¢ÕâЩÊý¾ÝµÄ·þÎñÆ÷ûÓÐÊÜÃÜÂë±£»¤£¬µ¼ÖÂÈκÎÈ˶¼¿ÉÒÔÕÒµ½²¢·ÃÎʸÃÊý¾Ý¿â¡£Ã½ÌåÒѾ¶ÔÆäÖÐһЩ¼Ç¼½øÐÐÑéÖ¤£¬»¹·¢ÏÖ²¿ÃżÇ¼°üÂÞÓû§µÄÐÕÃû¡¢ÐÔ±ðºÍ¹ú¼Ò/µØÓòλÖá£
ÔÎÄÁ´½Ó£º
https://threatpost.com/leaky-server-exposes-419m-phone-numbers-of-facebook-users/148029/
3¡¢FacebookÓû§µç»°ºÅÂëÊý¾Ý¿âй¶£¬Éæ¼°4.19ÒÚÌõ¼Ç¼
ÔÎÄÁ´½Ó£º
https://threatpost.com/leaky-server-exposes-419m-phone-numbers-of-facebook-users/148029/
4¡¢Ó¢¹ú¹ú»áÒéÔ±ÔÚ2019²ÆÄê½ÓÊÕµ½½ü2100Íò·âÀ¬»øÓʼþ
ƾ¾ÝÒ»ÏîFOIÉêÇëÅû¶µÄÐÅÏ¢£¬Ó¢¹ú¹ú»áÒéÔ±ºÍÒé»áÊÂÇéÈËÔ±ÔÚ2019²ÆÄê¶ÈÊÕµ½Á˽ü2100Íò·âÀ¬»øÓʼþ¡£ÕâЩÀ¬»øÓʼþ°üÂÞÁ˶àÖÖDZÔڵĶñÒâÍþв£¬°üÂÞÍøÂçµöÓã¡¢¶ñÒâÁ´½Ó¡¢¶ñÒ⸽¼þÒÔ¼°ÆäËü¹¥»÷¼ÆıµÈ¡£2018²ÆÄêµÄ¼Ç¼²¢²»ÍêÕû£¬È»¶øÔÚÓмǼµÄ°ëÄêÄÚ¸ÃÊý×ÖΪ1430Íò·â¡£Õâ±íÃ÷2019²ÆÄê¶ÈÕâЩÀ¬»øÓʼþµÄÊýÁ¿ÓÐËù¼õÉÙ£¬Ò²¿ÉÄÜÊÇÓʼþÄþ¾²Íø¹ØµÄÐÔÄÜÕýÔÚϽµ¡£
https://www.infosecurity-magazine.com/news/mps-bombarded-spam-brexit-no-deal/
5¡¢Windows 10 KB4512941¸üе¼ÖÂCortanaÕ¼ÓÃCPU¹ý¸ß
ÔÚ°²×°ÁËÉÏÖÜÕë¶ÔWindows 10 v1903µÄKB4512941ÀÛ»ý¸üкó£¬Ò»Ð©Óû§³ÂËß³ÆCortanaµÄSearchUI.exe½ø³ÌÌåÏÖ³ö¹ý¸ßµÄCPUÕ¼ÓÃÂÊ¡£ÕâÊÇÓÉÓڸð汾CortanaÖеĴíÎóµ¼Ö£¬µ±Óû§½ûÓÃÁËÏòBing·¢Ë͵±µØËÑË÷µÄÄÜÁ¦Ê±£¨ÎÞÂÛÊÇͨ¹ý×¢²á±í»¹ÊÇͨ¹ý×é¼Æı£©£¬Cortana½«Õ¼ÓôóÁ¿CPU¶øÇÒWindowsËÑË÷¿ÉÄÜ»áÏÔʾ¿ÕËÑË÷½á¹û¡£Òª½â¾ö´ËÎÊÌ⣬Óû§¿ÉÒÔÑ¡Ôñ£ºÆôÓÃBingSearch£¬½«Cortana CacheÎļþ¼ÐÌ滻Ϊ¾É°æ±¾£¬»òжÔظüС£µ±Ç°Î¢ÈíÉÐδÔÚKB4512941µÄÖ§³Öͨ¸æÖÐÈ·ÈϸÃÎÊÌâ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/microsoft/windows-10-kb4512941-update-causing-high-cpu-usage-in-cortana/