Android libpac¿âRCE·ì϶£»£»£»£»£»£»Intel CPU TPM-FAIL·ì϶ʹÊýÊ®ÒŲ́Éè±¸Ãæ¶Ô·çÏÕ

°ä²¼¹¦·ò 2019-11-18
1¡¢NowSecureÅû¶Android libpac¿âÖеÄRCE·ì϶

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

NowSecure×êÑÐÈËÔ±·¢ÏÖAndroidϵͳʹÓõÄlibpac¿âÖдæÔÚRCE·ì϶£¨CVE-2019-2205£©¡£ ¡£¡£¡£¡£¡£libpacÊÇÒ»¸ö»ùÓÚChromiumÏîÄ¿´úÂëµÄ¿â£¬£¬£¬£¬£¬£¬£¬£¬¸Ã¿âʹÓþ²Ì¬Á´½ÓµÄV8 JSÒýÇæÀ´½âÎöJavaScript£¬£¬£¬£¬£¬£¬£¬£¬ÕâΪƽ̨ÀûÓ÷¨Ê½´øÀ´Á˾޴óµÄ¹¥»÷Ãæ¡£ ¡£¡£¡£¡£¡£×êÑÐÈËÔ±·¢ÏÖJSº¯ÊýFindProxyForUrl¸ßµÍÎÄÖеÄArrayBuffers·ÖÅäÆ÷ÉêÃ÷²»ÕýÈ·£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÖÂÕ»ÉϵÄVPTR±»¸²¸Ç£¬£¬£¬£¬£¬£¬£¬£¬Õâ¿ÉÄܱ»ÓÃÓÚÖ´ÐÐËÁÒâ´úÂë¡£ ¡£¡£¡£¡£¡£¹È¸èÔÚ11ÔÂAndroid°²È«¸üÐÂÖн¨¸´Á˸÷ì϶¡£ ¡£¡£¡£¡£¡£

   

Ô­ÎÄÁ´½Ó£º

https://www.nowsecure.com/blog/2019/11/13/nowsecure-discovers-critical-android-vuln-that-may-lead-to-remote-code-execution/

2¡¢Intel CPU TPM-FAIL·ì϶ʹÊýÊ®ÒŲ́Éè±¸Ãæ¶Ô·çÏÕ

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

×êÑÐÈËÔ±ÔÚ»ùÓÚÓ¢ÌØ¶û¹Ì¼þµÄTPM£¨fTPM£©ºÍSTMicroelectronicsµÄTPMоƬÖз¢ÏÖÁËÁ½¸ö±»³ÆÎªTPM-FAILµÄзì϶£¬£¬£¬£¬£¬£¬£¬£¬ÕâÁ½¸ö·ì϶£¨CVE-2019-11090ºÍCVE-2019-16863£©Ê¹ºÚ¿ÍÄܹ»¶ã±Ü°²È«·®À飬£¬£¬£¬£¬£¬£¬£¬²¢ÇÔÈ¡TPMÖд洢µÄÃô¸ÐÊý¾Ý£¬£¬£¬£¬£¬£¬£¬£¬Ô̺¬ÊðÃûÃÜÔ¿µÈ¡£ ¡£¡£¡£¡£¡£ÌáÈ¡µ½ÃÜÔ¿ºó£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¾ÍÄÜÀûÓÃËüαÔìÊý×ÖÊðÃû¡¢´Û¸Ä²Ù×÷ϵͳ»òÈÆ¹ýÉí·ÝÑéÖ¤¡£ ¡£¡£¡£¡£¡£´óÎÞÊý±ãÐ¯Ê½ÍÆËã»ú¡¢Ì¨Ê½»úºÍ·þÎñÆ÷¶¼ÈÝÒ×Êܵ½TPM-FAIL¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬Ô̺¬´÷¶û¡¢»ÝÆÕºÍåÚÏëµÈÆ·ÅÆÔì×÷ÉÌ¡£ ¡£¡£¡£¡£¡£ÕâÁ½¸ö·ì϶¶¼ÒÑÔÚеĹ̼þ»òTPMоƬÖн¨¸´¡£ ¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/tpm-fail-security-flaws-impact-modern-devices-with-intel-cpus/

3¡¢Wizards of Coastй¶45ÍòÓÎÏ·Íæ¼ÒÊý¾Ý

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

¡¶Magic£ºThe Gathering¡·ÓÎÏ·µÄ¿ª·¢ÉÌWizards of CoastÒѾ­È·ÈÏÊýÊ®ÍòÓÎÏ·Íæ¼ÒµÄÊý¾ÝÔâй¶¡£ ¡£¡£¡£¡£¡£Ó¢¹ú°²È«³§ÉÌFidus Information Security·¢ÏÖÁ˶³öµÄÊý¾Ý¿âÎļþ£¬£¬£¬£¬£¬£¬£¬£¬ÕâЩÎļþ±»±£ÁôÔÚûÓÐÃÜÂëµÄAmazon´æ´¢Í°ÖÓ×£ ¡£¡£¡£¡£¡£Êý¾Ý¿âÖÐÒ»¹²Ô̺¬452634ÃûÍæ¼ÒµÄÊý¾Ý£¬£¬£¬£¬£¬£¬£¬£¬Éæ¼°ÐÕÃûºÍÓû§Ãû¡¢µç×ÓÓʼþµØÖ·¡¢ÕË»§µÄ´´½¨¹¦·òÒÔ¼°¾­¹ý¹þÏ£ºÍ¼ÓÑδ¦ÖõÄÃÜÂë¡£ ¡£¡£¡£¡£¡£Æ¾¾Ý×êÑÐÈËÔ±¶ÔÊý¾ÝµÄÉó²é£¬£¬£¬£¬£¬£¬£¬£¬ÕâЩÕË»§µÄÈÕÆÚ×îÔç¿É×·ÒäÖÁ2012Ä꣬£¬£¬£¬£¬£¬£¬£¬×îÐÂÔòΪ2018ÄêÖÐÆÚ¡£ ¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://techcrunch.com/2019/11/16/magic-the-gathering-wizards-data-exposure/

4¡¢Sunshine Behavioralй¶9.3Íò·Ý»¼Õßµµ°¸

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

Sunshine Behavioral HealthÊÇÃÀ¹úÒ»¼ÒÒ½Öζ¾Æ·ºÍ¾Æ¾«³Éñ«»¼ÕßµÄÒ½Áƹ«Ë¾£¬£¬£¬£¬£¬£¬£¬£¬É¢²¼ÔÚ¼ÓÀû¸£ÄáÑÇÖÝ¡¢µÂ¿ËÈøË¹ÖݺͿÆÂÞÀ­¶àÖÝ¡£ ¡£¡£¡£¡£¡£ÓÉÓÚAWS s3´æ´¢Í°ÅäÖÃÃýÎ󣬣¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾µÄԼĪ9.3Íò¸ö»¼Õßµµ°¸Ôâй¶¡£ ¡£¡£¡£¡£¡£µµ°¸ÖÐÔ̺¬µÄÐÅÏ¢Ô̺¬ÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢ÓÊÕþµØÖ·ºÍµç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂë¡¢ÆëÈ«µÄÐÅÓþ¿¨ºÅÂëºÍCVVÂë¼°²¿ÃÅÓÐЧÈÕÆÚ£¨ÔÂ/ÈÕ£©¡¢Ò½ÁƱ£ÏÕÕ˺š¢ÒÑÖ§¸¶½ð¶îµÈ¡£ ¡£¡£¡£¡£¡£¸Ã¹«Ë¾¶ÔÊý¾Ý¿â½øÐÐÁ˱£»£»£»£»£»£»¤£¬£¬£¬£¬£¬£¬£¬£¬µ«Ã»ÓÐÔÚÍøÕ¾Éϰ䲼й¶֪ͨ£¬£¬£¬£¬£¬£¬£¬£¬Ò²Î´°µÊ¾ÊÇ·ñÒÑ֪ͨ»¼Õß/¼à¹Ü»ú¹¹¡£ ¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.databreaches.net/exclusive-more-than-90000-patient-billing-files-from-an-alcohol-and-drug-addiction-treatment-network-exposed-online/

5¡¢°Ä´óÀûÑǹú»áÔÚ2019ËêÊ×Ôâµ½ºÚ¿ÍÈëÇÖ

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

ƾ¾Ý°Ä´óÀûÑǹ㲥¹«Ë¾£¨ABC£©µÄ±¨Â·£¬£¬£¬£¬£¬£¬£¬£¬°Ä´óÀûÑǹú»áµÄÍÆËã»úÍøÂçÔÚ½ñÄêÔçЩʱ³½±»ºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬£¬²¢´Ó¼¸Î»µ±Ñ¡¹ÙÔ±µÄÍÆËã»úÖÐÇÔÈ¡ÁËÊý¾Ý¡£ ¡£¡£¡£¡£¡£¸Ã¹¥»÷²úÉúÔÚ2019Äê1ÔÂ31ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Æäʱ°Ä´óÀûÑǰ²È«»ú¹¹·¢ÏÖÁËÈëÇÖ²¢¶ÔÆä½øÐÐÒ»Öܵļල£¬£¬£¬£¬£¬£¬£¬£¬¶øºó¹Ø¹ØÍøÂç²¢ÊÔͼ׷²¶¹¥»÷Õß¡£ ¡£¡£¡£¡£¡£°Ä´óÀûÑǵ±¾ÖδÌṩÓйظúڿ͹¥»÷µÄ¸ü¶à¾ßÌåÐÅÏ¢¡£ ¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/93898/cyber-warfare-2/australian-parliament-hacked.html

6¡¢Î¢Èí°ä²¼Intel CPUÇý¶¯·¨Ê½·ì϶µÄ½¨¸´Ö¸ÄÏ

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

΢Èí°ä²¼ÁËÔ®ÊÖÓû§½¨¸´Intel CPU»Ø¾ø·þÎñ·ì϶£¨CVE-2018-12207£©ºÍTSXÒì²½¶ôÖÆ·ì϶£¨CVE-2019-11135£©µÄÖ¸ÄÏ¡£ ¡£¡£¡£¡£¡£¸ÃDoS·ì϶ӰÏìÁ˵Ú8´ú¼°ÒÔϵÄIntel¿á¦ÖÃÆ÷£¬£¬£¬£¬£¬£¬£¬£¬Î¢ÈíÔÚ11Ô°²È«¸üÐÂÖн¨¸´Á˸÷ì϶£¬£¬£¬£¬£¬£¬£¬£¬µ«ÔÚĬÈÏÇé¿öϸñ£»£»£»£»£»£»¤Ö°Äܱ»½ûÓ㬣¬£¬£¬£¬£¬£¬£¬Óû§±ØÐëÉèÖÃÌØ¶¨µÄ×¢²á±íÏîÆôÓøÃÖ°ÄÜ¡£ ¡£¡£¡£¡£¡£¶øTSXÖ°ÄÜÖеĴ§Ä¦Ö´Ðзì϶ÔòÓ°ÏìÁËIntelµÚ10´ú֮ǰµÄ´¦ÖÃÆ÷£¬£¬£¬£¬£¬£¬£¬£¬Î¢ÈíÁìµ¼Óû§ÔÚÒ×Êܹ¥»÷µÄIntel´¦ÖÃÆ÷ÉϽûÓÃIntel TSXÖ°ÄÜ£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ×èֹDZÔÚµÄZombieload 2¹¥»÷¡£ ¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/microsoft-issues-guidance-for-intel-cpu-driver-security-flaws/