ÐÅÏ¢Äþ¾²Öܱ¨-2019ÄêµÚ39ÖÜ

Ðû²¼Ê±¼ä 2019-10-08

> ±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö



2019Äê9ÔÂ30ÈÕÖÁ10ÔÂ06ÈÕÊÕ¼Äþ¾²Â©¶´42¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇExim ¡®string_vformat¡¯º¯Êý»º³åÇøÒç³ö©¶´; Linux kernel cfg80211_mgd_wext_giwessid»º³åÇøÒç³ö©¶´£»Liferay Portal JSON¸ºÔØ·´ÐòÁл¯´úÂëÖ´ÐЩ¶´£»Cisco Security Manager Java·´ÐòÁл¯ÈÎÒâ´úÂëÖ´ÐЩ¶´£»WhatsApp DDGifSlurpÄÚ´æ´íÎóÒýÓ鶴¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊǺڿÍÇÔÈ¡Áè¼Ý2.18ÒÚWords With FriendsÍæ¼ÒÊý¾Ý£»µ¤Âó¹«Ë¾DemantÔâµ½ÀÕË÷Èí¼þ¹¥»÷Ëðʧ9500ÍòÃÀÔª£»eGobblerжñÒâ¹ã¸æ»î¶¯½Ù³ÖÁè¼Ý10ÒÚÓû§»á»°£»¶íÂÞ˹Áè¼Ý2000Íò¹«ÃñµÄË°ÊռǼ¼°PIIÔÚÍøÉÏй¶£»Ñо¿ÈËÔ±Åû¶AndroidϵͳÖеÄÐÂLPE 0day¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£

> ÖØÒªÄþ¾²Â©¶´Áбí


1. Exim ¡®string_vformat¡¯º¯Êý»º³åÇøÒç³ö©¶´


Exim ¡®string_vformat¡¯º¯Êý´æÔÚ»º³åÇøÒç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐÈÎÒâ´úÂë¡£
https://lists.exim.org/lurker/message/20190927.032457.c1044d4c.en.html

2. Linux kernel cfg80211_mgd_wext_giwessid»º³åÇøÒç³ö©¶´


Linux kernel net/wireless/wext-sme.c cfg80211_mgd_wext_giwessid´¦Ö󬳤SSID IE´æÔÚ»º³åÇøÒç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿Éʹϵͳ±ÀÀ£»òÖ´ÐÐÈÎÒâ´úÂë¡£
https://marc.info/?l=linux-wireless&m=157018270915487&w=2

3. Liferay Portal JSON¸ºÔØ·´ÐòÁл¯´úÂëÖ´ÐЩ¶´


Liferay Portal´¦ÖÃJSON¸ºÔØ´æÔÚ·´ÐòÁл¯Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÖ´ÐÐÈÎÒâ´úÂë¡£
https://sec.vnpt.vn/2019/09/liferay-deserialization-json-deserialization-part-4/

4. Cisco Security Manager Java·´ÐòÁл¯ÈÎÒâ´úÂëÖ´ÐЩ¶´


Cisco Security Manager Java·´ÐòÁл¯º¯Êý´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíͨ¹ýÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÖ´ÐÐÈÎÒâÃüÁî¡£
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20191002-sm-java-deserial

5. WhatsApp DDGifSlurpÄÚ´æ´íÎóÒýÓ鶴


WhatsApp decoding.cÖеÄDDGifSlurp´æÔÚÁ½´ÎÊÍ·Å©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÖ´ÐÐÈÎÒâ´úÂë¡£
https://www.facebook.com/security/advisories/cve-2019-11932


> ÖØÒªÄþ¾²Ê¼þ×ÛÊö



1¡¢ºÚ¿ÍÇÔÈ¡Áè¼Ý2.18ÒÚWords With FriendsÍæ¼ÒÊý¾Ý

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ºÚ¿ÍGnosticplayers´ÓÒƶ¯Éç½»ÓÎÏ·¹«Ë¾Zynga Inc¿ª·¢µÄWords With FriendsÖÐÇÔÈ¡ÁËÁè¼Ý2.18ÒÚÌõÍæ¼Ò¼Ç¼¡£GnosticplayersÔøÔÚ2ÔÂÖÁ4ÔÂÆÚ¼ä³öÊÛÁË´Ó45¼Ò¹«Ë¾ÇÔÈ¡µÄ½ü10ÒÚÌõÓû§ÐÅÏ¢£¬ÕâÒ»´ÎËûÃé×¼ÁËÃÀ¹úÉç½»ÓÎÏ·¿ª·¢ÉÌZynga¡£Æ¾¾ÝGnosticplayers·ÖÏíµÄ¼Ç¼£¬¸ÃÊý¾Ý¼¯°üÂÞÓû§µÄÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢µÇ¼ID¡¢¼ÓÑιþÏ£ÃÜÂë¡¢ÃÜÂëÖØÖÃÁîÅÆ¡¢µç»°ºÅÂë¡¢Facebook IDÒÔ¼°ZyngaÕÊ»§ID¡£ÊÜÓ°ÏìµÄÓû§Îª2019Äê9ÔÂ2ÈÕ֮ǰ°²×°²¢×¢²á¸ÃÓÎÏ·µÄAndroidºÍiOSÍæ¼Ò¡£ZyngaÈ·ÈÏÁËÕâһʼþ£¬µ«ÌåÏÖûÓвÆÕþÐÅϢй¶¡£

Ô­ÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/91850/data-breach/zynga-game-data-breach.html

2¡¢µ¤Âó¹«Ë¾DemantÔâµ½ÀÕË÷Èí¼þ¹¥»÷Ëðʧ9500ÍòÃÀÔª

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


×÷ΪȫÇò×î´óµÄÖúÌýÆ÷ÖÆÔìÉÌÖ®Ò»£¬DemantÔ¤¼Æ±¾Ô³õѬȾÀÕË÷Èí¼þÖ®ºó£¬½«ÔâÊܸߴï9500ÍòÃÀÔªµÄËðʧ¡£ÆäʱÔÚÆäÍøÕ¾Éϵļò¶ÌÉùÃ÷ÖУ¬¸Ã¹«Ë¾ÌåÏÖ£¬ÔÚ×î³õÃèÊöΪ¡°ÑÏÖØʼþ¡±Ö®ºó£¬Ëü½«¹Ø±ÕÆäÕû¸öÄÚ²¿IT»ù´¡ÍøÂç¡£ÆäÖаüÂ޸ù«Ë¾µÄERPϵͳ£¬ÔÚ²¨À¼µÄÉú²úºÍÏúÊÛÉèÊ©£¬ÔÚÄ«Î÷¸çµÄÉú²úºÍ·þÎñÖÐÐÄ£¬ÔÚ·¨¹úµÄ¶úÎÏÖ²ÈëÎïÉú²ú»ùµØ£¬ÔÚµ¤ÂóµÄ·Å´óÆ÷Éú²ú»ùµØÒÔ¼°Õû¸öÑÇÌ«µØÓòÍøÂç¡£

Ô­ÎÄÁ´½Ó£º
https://www.zdnet.com/article/ransomware-incident-to-cost-danish-company-a-whopping-95-million/

3¡¢eGobblerжñÒâ¹ã¸æ»î¶¯½Ù³ÖÁè¼Ý10ÒÚÓû§»á»°


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ñо¿ÈËÔ±·¢ÏÖÁËÓÉÍþв×éÖ¯eGobblerÌᳫµÄÐÂÒ»²¨¹¥»÷»î¶¯£¬ÆäÖÐÊܺ¦Õß±»Öض¨Ïòµ½´øÓжñÒâµÄÍøÕ¾¡£Äþ¾²×¨¼ÒÈÏΪ£¬eGobblerÊǽñÄ긴Éú½Ú¶à·¢ÐÔ¶ñÒâ¹¥»÷µÄÄ»ºóºÚÊÖ¡£Õâ´Î£¬Ê¹ÓÃWebkitä¯ÀÀÆ÷ÒýÇ橶´½Ù³ÖÁËÁè¼Ý10ÒÚ¸ö¹ã¸æչʾ¡£×îеĻ»¹±íÃ÷£¬Õë¶ÔÒÔÇ°ÔøÒÔÒƶ¯É豸Ϊ¹¥»÷Ä¿±êµÄÍþв¼ÓÈëÕߵķ¨Ê½ÓÐËù¸Ä±ä£ºÔÚ´ËÆڼ䣬eGobbler¶Ǫ̂ʽ»úµÄÆ«°®Ö§³ÖÁËËûÃÇ×îеÄWebKitÀûÓá£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/malvertising-attack-hijacks-1b-sessions-with-webkit-exploit/148795/

4¡¢¶íÂÞ˹Áè¼Ý2000Íò¹«ÃñµÄË°ÊռǼ¼°PIIÔÚÍøÉÏй¶

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ñо¿ÈËԱ˵£¬Áè¼Ý2000Íò·ÝÊôÓÚ¶íÂÞ˹¹«ÃñµÄË°ÊռǼûÓÐÊܵ½±£»¤£¬²¢Í¨¹ýÒ»¸ö¿É¹©¹«ÖÚ·ÃÎʵÄÔÚÏßÊý¾Ý¿â½øÐйûÈ»¡£¸Ã·þÎñÆ÷°üÂÞÁË´Ó2009Äêµ½2016ÄêµÄ¸ß¶ÈÃô¸ÐµÄÐÅÏ¢¡£´ó²¿ÃżÇ¼ËƺõÓëÀ´×ÔĪ˹¿Æ¼°¶¼ÊÐÖܱߵØÓòµÄ¹«ÃñÓйØ¡£Êý¾Ý¿â°üÂÞÐÕÃû£¬µØÖ·£¬¾Óס״̬£¬»¤ÕÕºÅÂ룬Òƶ¯µç»°£¬Ë°ºÅ£¬¹ÍÖ÷Ãû³ÆºÍÀι̵绰ÒÔ¼°Ë°Öµ¡£ 


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/plaintext-tax-records-of-20-million-russians-leaked-online/

5¡¢Ñо¿ÈËÔ±Åû¶AndroidϵͳÖеÄÐÂLPE 0day

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ñо¿ÈËÔ±Maddie Stone·¢ÏÖÒ»¸öδÐÞ¸´µÄAndroid 0dayÒѾ­±»ÀûÓ㬸鶴¿ÉÒÔʹµ±µØÌØȨ¹¥»÷Õß»òÓ¦Ó÷¨Ê½Éý¼¶ÆäÌØȨ£¬ÒÔ»ñµÃ¶ÔÒ×Êܹ¥»÷µÄÉ豸µÄ¸ù·ÃÎÊȨÏÞ£¬²¢ÓпÉÄÜÍêÈ«¿ØÖƸÃÉ豸¡£¸Ã©¶´ÔÚÈ¥Äê4ÔÂ֮ǰÐû²¼µÄAndroidÄں˰汾ÖУ¬¸Ã²¹¶¡ÒÑ°üÂÞÔÚ2017Äê12ÔÂÐû²¼µÄ4.14 LTS LinuxÄÚºËÖУ¬µ«½ö°üÂÞÔÚAOSP AndroidÄں˰汾3.18¡¢4.4ºÍ4.9ÖС£Google½«ÔÚδÀ´¼¸ÌìµÄ10Ô¡¶ AndroidÄþ¾²Í¨¸æ¡·ÖÐÐû²¼´Ë©¶´µÄ²¹¶¡·¨Ê½£¬²¢Í¨ÖªOEM¡£

Ô­ÎÄÁ´½Ó£º
https://thehackernews.com/2019/10/android-kernel-vulnerability.html