ÐÅÏ¢Äþ¾²Öܱ¨-2019ÄêµÚ35ÖÜ

Ðû²¼Ê±¼ä 2019-09-09

 > ±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö



2019Äê9ÔÂ02ÈÕÖÁ08ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´46¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇBD PyxisδÊÚȨ·ÃÎÊ©¶´ £»Mozilla Firefox CVE-2019-11741ͨÓÿçÕ¾½Å±¾¹¥»÷©¶´ £»CA Automic Workload Automation DIA CA Common Services´úÂëÖ´ÐЩ¶´ £»Aruba Mobility Controller WEB×é¼þÃüÁî×¢È멶´ £»Samba CVE-2019-10197Ŀ¼±éÀú©¶´¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇÈýÐÇ¡¢»ªÎªµÈÊÖ»úÒ×ÊÜOMA CP¶ÌÐÅÖ¸ÁîÆÛÆ­¹¥»÷ £»FacebookÓû§µç»°ºÅÂëÊý¾Ý¿âй¶£¬Éæ¼°4.19ÒÚÌõ¼Ç¼ £»FacebookÓû§µç»°ºÅÂëÊý¾Ý¿âй¶£¬Éæ¼°4.19ÒÚÌõ¼Ç¼ £»Ó¢¹ú¹ú»áÒéÔ±ÔÚ2019²ÆÄê½ÓÊÕµ½½ü2100Íò·âÀ¬»øÓʼþ £»Windows 10 KB4512941¸üе¼ÖÂCortanaÕ¼ÓÃCPU¹ý¸ß¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£


> ÖØÒªÄþ¾²Â©¶´Áбí



1. BD PyxisδÊÚȨ·ÃÎÊ©¶´


BD PyxisÊÚȨ»úÖÆ´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó£¬Î´ÊÚȨ·ÃÎÊÓ¦Óá£
https://www.us-cert.gov/ics/advisories/icsma-19-248-01

2. Mozilla Firefox CVE-2019-11741ͨÓÿçÕ¾½Å±¾¹¥»÷©¶´


Mozilla FirefoxʵÏÖ´æÔÚͨÓÿçÕ¾½Å±¾Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄWEB£¬ÓÕʹÓû§½âÎö£¬²Ù¿Øaddons.mozilla.org¼°accounts.firefox.com¿ÉÐÞ¸ÄÓû§ÅäÖõȡ£
https://www.mozilla.org/en-US/security/advisories/mfsa2019-25/

3. CA Automic Workload Automation DIA CA Common Services´úÂëÖ´ÐЩ¶´


CA Automic Workload Automation DIA CA Common ServicesʵÏÖ´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÖ´ÐдúÂë¡£
https://www.auscert.org.au/bulletins/ESB-2019.3374/

4. Aruba Mobility Controller WEB×é¼þÃüÁî×¢È멶´


Aruba Mobility Controller WEB×é¼þ´æÔÚÃüÁî×¢È멶´£¬ÔÊÐíͨ¹ýÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÖ´ÐÐÈÎÒâÃüÁî¡£
https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2019-004.txt

5. Samba CVE-2019-10197Ŀ¼±éÀú©¶´


SambaijЩ²ÎÊýÅäÖÃÏ´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÈƹýĿ¼ÏÞÖÆ£¬Î´ÊÚȨ·ÃÎÊ¡£
https://www.samba.org/samba/security/CVE-2019-10197.html


> ÖØÒªÄþ¾²Ê¼þ×ÛÊö



1¡¢ÈýÐÇ¡¢»ªÎªµÈÊÖ»úÒ×ÊÜOMA CP¶ÌÐÅÖ¸ÁîÆÛÆ­¹¥»÷


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Check PointÑо¿ÈËÔ±·¢ÏÖËļÒÖÇÄÜÊÖ»úÖÆÔìÉÌ£¨°üÂÞÈýÐÇ¡¢»ªÎª¡¢LGºÍË÷ÄᣩδÔÚÆäÉ豸ÉÏʵʩÄþ¾²µÄOMA CPÖ¸Áî³ß¶È£¬Ê¹µÃ¹¥»÷Õß¿ÉÒÔͨ¹ýαÔìOMA CP¶ÌÐÅÖ¸ÁîÓÕÆ­Óû§ÐÞ¸ÄÉ豸ÅäÖ㬴ӶøÀ¹½ØÆäµç×ÓÓʼþ»òÍøÂçÁ÷Á¿¡£OMA CP´ú±í¿ª·ÅÒƶ¯ÁªÃË¿Í»§¶ËÅäÖã¬ËüÖ¸µÄÊÇÒƶ¯ÔËÓªÉÌ¿Éͨ¹ýÌض¨¶ÌÐŽ«ÍøÂçÉèÖ÷¢Ë͵½Óû§É豸µÄÒ»Öֳ߶ȡ£Ñо¿ÈËÔ±³ÆÈýÐǵÄÊÖ»ú×î²»Äþ¾²£¬ÒòΪËü¿ÉÒÔ½ÓÊÜÈκÎÀàÐ͵ÄOMA CPÏûÏ¢¶øÇÒûÓÐÈÏÖ¤»òÑéÖ¤»úÖÆ¡£ÈýÐǺÍLG·Ö±ðÓÚ5Ô·ݺÍ7Ô·ÝÐû²¼ÁËÐÞ¸´²¹¶¡£¬»ªÎªÌåÏÖ½«ÔÚÏÂÒ»´úMate»òPϵÁÐÊÖ»úÖмÓÈëÐÞ¸´²¹¶¡£¬µ«Ë÷Äá¾Ü¾øÈϿɸ鶴¡£

Ô­ÎÄÁ´½Ó£º
https://www.zdnet.com/article/samsung-huawei-lg-and-sony-phones-vulnerable-to-rogue-provisioning-messages/

2¡¢FacebookÓû§µç»°ºÅÂëÊý¾Ý¿âй¶£¬Éæ¼°4.19ÒÚÌõ¼Ç¼


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ñо¿ÈËÔ±·¢ÏÖÒ»¸ö´æ´¢ÁËÊýÒÚFacebookÓû§µç»°ºÅÂë¼Ç¼µÄÊý¾Ý¿âÔÚÍøÉÏ̻¶¡£ÕâЩÊý¾Ý×ÜÊýÁè¼Ý4.19ÒÚÌõ¼Ç¼£¬º­¸Ç¶à¸öµØÓò£¬ÆäÖаüÂÞ1.33ÒÚÌõÃÀ¹úFacebookÓû§¼Ç¼¡¢1800ÍòÓ¢¹úÓû§¼Ç¼ÒÔ¼°5000¶àÍòÔ½ÄÏÓû§¼Ç¼¡£¾ßÌå¶øÑÔ£¬Ã¿Ìõ¼Ç¼¶¼°üÂÞÓû§µÄΨһFacebook IDºÍÕË»§¹ØÁªµÄµç»°ºÅÂë¡£ÓÉÓÚ´æ´¢ÕâЩÊý¾ÝµÄ·þÎñÆ÷ûÓÐÊÜÃÜÂë± £»¤£¬µ¼ÖÂÈκÎÈ˶¼¿ÉÒÔÕÒµ½²¢·ÃÎʸÃÊý¾Ý¿â¡£Ã½ÌåÒѾ­¶ÔÆäÖÐһЩ¼Ç¼½øÐÐÑéÖ¤£¬»¹·¢ÏÖ²¿ÃżÇ¼°üÂÞÓû§µÄÐÕÃû¡¢ÐÔ±ðºÍ¹ú¼Ò/µØÓòλÖá£

Ô­ÎÄÁ´½Ó£º
https://threatpost.com/leaky-server-exposes-419m-phone-numbers-of-facebook-users/148029/

3¡¢FacebookÓû§µç»°ºÅÂëÊý¾Ý¿âй¶£¬Éæ¼°4.19ÒÚÌõ¼Ç¼

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ñо¿ÈËÔ±·¢ÏÖÒ»¸ö´æ´¢ÁËÊýÒÚFacebookÓû§µç»°ºÅÂë¼Ç¼µÄÊý¾Ý¿âÔÚÍøÉÏ̻¶¡£ÕâЩÊý¾Ý×ÜÊýÁè¼Ý4.19ÒÚÌõ¼Ç¼£¬º­¸Ç¶à¸öµØÓò£¬ÆäÖаüÂÞ1.33ÒÚÌõÃÀ¹úFacebookÓû§¼Ç¼¡¢1800ÍòÓ¢¹úÓû§¼Ç¼ÒÔ¼°5000¶àÍòÔ½ÄÏÓû§¼Ç¼¡£¾ßÌå¶øÑÔ£¬Ã¿Ìõ¼Ç¼¶¼°üÂÞÓû§µÄΨһFacebook IDºÍÕË»§¹ØÁªµÄµç»°ºÅÂë¡£ÓÉÓÚ´æ´¢ÕâЩÊý¾ÝµÄ·þÎñÆ÷ûÓÐÊÜÃÜÂë± £»¤£¬µ¼ÖÂÈκÎÈ˶¼¿ÉÒÔÕÒµ½²¢·ÃÎʸÃÊý¾Ý¿â¡£Ã½ÌåÒѾ­¶ÔÆäÖÐһЩ¼Ç¼½øÐÐÑéÖ¤£¬»¹·¢ÏÖ²¿ÃżÇ¼°üÂÞÓû§µÄÐÕÃû¡¢ÐÔ±ðºÍ¹ú¼Ò/µØÓòλÖá£

Ô­ÎÄÁ´½Ó£º
https://threatpost.com/leaky-server-exposes-419m-phone-numbers-of-facebook-users/148029/

4¡¢Ó¢¹ú¹ú»áÒéÔ±ÔÚ2019²ÆÄê½ÓÊÕµ½½ü2100Íò·âÀ¬»øÓʼþ


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾ÝÒ»ÏîFOIÉêÇëÅû¶µÄÐÅÏ¢£¬Ó¢¹ú¹ú»áÒéÔ±ºÍÒé»áÊÂÇéÈËÔ±ÔÚ2019²ÆÄê¶ÈÊÕµ½Á˽ü2100Íò·âÀ¬»øÓʼþ¡£ÕâЩÀ¬»øÓʼþ°üÂÞÁ˶àÖÖDZÔڵĶñÒâÍþв£¬°üÂÞÍøÂçµöÓã¡¢¶ñÒâÁ´½Ó¡¢¶ñÒ⸽¼þÒÔ¼°ÆäËü¹¥»÷¼ÆıµÈ¡£2018²ÆÄêµÄ¼Ç¼²¢²»ÍêÕû£¬È»¶øÔÚÓмǼµÄ°ëÄêÄÚ¸ÃÊý×ÖΪ1430Íò·â¡£Õâ±íÃ÷2019²ÆÄê¶ÈÕâЩÀ¬»øÓʼþµÄÊýÁ¿ÓÐËù¼õÉÙ£¬Ò²¿ÉÄÜÊÇÓʼþÄþ¾²Íø¹ØµÄÐÔÄÜÕýÔÚϽµ¡£


Ô­ÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/mps-bombarded-spam-brexit-no-deal/

5¡¢Windows 10 KB4512941¸üе¼ÖÂCortanaÕ¼ÓÃCPU¹ý¸ß


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÔÚ°²×°ÁËÉÏÖÜÕë¶ÔWindows 10 v1903µÄKB4512941ÀÛ»ý¸üкó£¬Ò»Ð©Óû§³ÂËß³ÆCortanaµÄSearchUI.exe½ø³ÌÌåÏÖ³ö¹ý¸ßµÄCPUÕ¼ÓÃÂÊ¡£ÕâÊÇÓÉÓڸð汾CortanaÖеĴíÎóµ¼Ö£¬µ±Óû§½ûÓÃÁËÏòBing·¢Ë͵±µØËÑË÷µÄÄÜÁ¦Ê±£¨ÎÞÂÛÊÇͨ¹ý×¢²á±í»¹ÊÇͨ¹ý×é¼Æı£©£¬Cortana½«Õ¼ÓôóÁ¿CPU¶øÇÒWindowsËÑË÷¿ÉÄÜ»áÏÔʾ¿ÕËÑË÷½á¹û¡£Òª½â¾ö´ËÎÊÌ⣬Óû§¿ÉÒÔÑ¡Ôñ£ºÆôÓÃBingSearch£¬½«Cortana CacheÎļþ¼ÐÌ滻Ϊ¾É°æ±¾£¬»òжÔظüС£µ±Ç°Î¢ÈíÉÐδÔÚKB4512941µÄÖ§³Öͨ¸æÖÐÈ·ÈϸÃÎÊÌâ¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/microsoft/windows-10-kb4512941-update-causing-high-cpu-usage-in-cortana/