ÐÅÏ¢Äþ¾²Öܱ¨-2019ÄêµÚ39ÖÜ
Ðû²¼Ê±¼ä 2019-10-08> ±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö
2019Äê9ÔÂ30ÈÕÖÁ10ÔÂ06ÈÕÊÕ¼Äþ¾²Â©¶´42¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇExim ¡®string_vformat¡¯º¯Êý»º³åÇøÒç³ö©¶´; Linux kernel cfg80211_mgd_wext_giwessid»º³åÇøÒç³ö©¶´£»Liferay Portal JSON¸ºÔØ·´ÐòÁл¯´úÂëÖ´ÐЩ¶´£»Cisco Security Manager Java·´ÐòÁл¯ÈÎÒâ´úÂëÖ´ÐЩ¶´£»WhatsApp DDGifSlurpÄÚ´æ´íÎóÒýÓ鶴¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊǺڿÍÇÔÈ¡Áè¼Ý2.18ÒÚWords With FriendsÍæ¼ÒÊý¾Ý£»µ¤Âó¹«Ë¾DemantÔâµ½ÀÕË÷Èí¼þ¹¥»÷Ëðʧ9500ÍòÃÀÔª£»eGobblerжñÒâ¹ã¸æ»î¶¯½Ù³ÖÁè¼Ý10ÒÚÓû§»á»°£»¶íÂÞ˹Áè¼Ý2000Íò¹«ÃñµÄË°ÊռǼ¼°PIIÔÚÍøÉÏй¶£»Ñо¿ÈËÔ±Åû¶AndroidϵͳÖеÄÐÂLPE 0day¡£
> ÖØÒªÄþ¾²Â©¶´Áбí
1. Exim ¡®string_vformat¡¯º¯Êý»º³åÇøÒç³ö©¶´
https://lists.exim.org/lurker/message/20190927.032457.c1044d4c.en.html
2. Linux kernel cfg80211_mgd_wext_giwessid»º³åÇøÒç³ö©¶´
https://marc.info/?l=linux-wireless&m=157018270915487&w=2
3. Liferay Portal JSON¸ºÔØ·´ÐòÁл¯´úÂëÖ´ÐЩ¶´
https://sec.vnpt.vn/2019/09/liferay-deserialization-json-deserialization-part-4/
4. Cisco Security Manager Java·´ÐòÁл¯ÈÎÒâ´úÂëÖ´ÐЩ¶´
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20191002-sm-java-deserial
5. WhatsApp DDGifSlurpÄÚ´æ´íÎóÒýÓ鶴
https://www.facebook.com/security/advisories/cve-2019-11932
> ÖØÒªÄþ¾²Ê¼þ×ÛÊö
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/91850/data-breach/zynga-game-data-breach.html
2¡¢µ¤Âó¹«Ë¾DemantÔâµ½ÀÕË÷Èí¼þ¹¥»÷Ëðʧ9500ÍòÃÀÔª
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/ransomware-incident-to-cost-danish-company-a-whopping-95-million/
3¡¢eGobblerжñÒâ¹ã¸æ»î¶¯½Ù³ÖÁè¼Ý10ÒÚÓû§»á»°
Ñо¿ÈËÔ±·¢ÏÖÁËÓÉÍþв×éÖ¯eGobblerÌᳫµÄÐÂÒ»²¨¹¥»÷»î¶¯£¬ÆäÖÐÊܺ¦Õß±»Öض¨Ïòµ½´øÓжñÒâµÄÍøÕ¾¡£Äþ¾²×¨¼ÒÈÏΪ£¬eGobblerÊǽñÄ긴Éú½Ú¶à·¢ÐÔ¶ñÒâ¹¥»÷µÄÄ»ºóºÚÊÖ¡£Õâ´Î£¬Ê¹ÓÃWebkitä¯ÀÀÆ÷ÒýÇ橶´½Ù³ÖÁËÁè¼Ý10ÒÚ¸ö¹ã¸æչʾ¡£×îеĻ»¹±íÃ÷£¬Õë¶ÔÒÔÇ°ÔøÒÔÒƶ¯É豸Ϊ¹¥»÷Ä¿±êµÄÍþв¼ÓÈëÕߵķ¨Ê½ÓÐËù¸Ä±ä£ºÔÚ´ËÆڼ䣬eGobbler¶Ǫ̂ʽ»úµÄÆ«°®Ö§³ÖÁËËûÃÇ×îеÄWebKitÀûÓá£
ÔÎÄÁ´½Ó£º
https://threatpost.com/malvertising-attack-hijacks-1b-sessions-with-webkit-exploit/148795/4¡¢¶íÂÞ˹Áè¼Ý2000Íò¹«ÃñµÄË°ÊռǼ¼°PIIÔÚÍøÉÏй¶
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/plaintext-tax-records-of-20-million-russians-leaked-online/5¡¢Ñо¿ÈËÔ±Åû¶AndroidϵͳÖеÄÐÂLPE 0day
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/10/android-kernel-vulnerability.html