Apple°²È«¸üУ¬£¬£¬ £¬£¬½¨¸´Ó°ÏìiOSºÍiPadOSµÄ11¸ö·ì϶£»£»£»£»£»£»GmailÔÚ24Ó×ʱÄÚ²úÉúµÚ¶þ´ÎÖжϣ¬£¬£¬ £¬£¬Ä¿Ç°Ô­Òòδ֪

°ä²¼¹¦·ò 2020-12-16

1.Apple°²È«¸üУ¬£¬£¬ £¬£¬½¨¸´Ó°ÏìiOSºÍiPadOSµÄ11¸ö·ì϶


1.jpg


Apple°ä²¼ÁËiOSºÍiPadOSµÄ°²È«¸üУ¬£¬£¬ £¬£¬½¨¸´Ô̺¬´úÂëÖ´Ðзì϶ÔÚÄÚµÄ11¸ö·ì϶¡£¡£¡£¡£¡£¡£Õâ´Î½¨¸´µÄ×îΪÑϳÁµÄÊÇ´úÂëÖ´Ðзì϶£¨CVE-2020-27943ºÍCVE-2020-27944£©£¬£¬£¬ £¬£¬¹¥»÷Õß¿ÉÀûÓöñÒâ×ÖÌåÎļþÔÚApple iPhoneºÍiPadÉÏÖ´ÐжñÒâ´úÂë¡£¡£¡£¡£¡£¡£Æä´ÎΪÈý¸öÓ°ÏìÁËImageIO±à³Ì½Ó¿Ú¿ò¼ÜµÄ·ì϶CVE-2020-29617¡¢CVE-2020-29618ºÍCVE-2020-29619£¬£¬£¬ £¬£¬¹¥»÷Õß¿ÉÀûÓÃÕâЩ·ì϶ͨ¹ýÌØÔìͼÏñÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/112304/security/ios-ipados-flaws.html


2.Golang XML½âÎöÆ÷´æÔÚ¿ÉÈÆ¹ýSAMLÉí·ÝÑéÖ¤µÄ·ì϶


2.jpg


MattermostÓëGolang½áºÏÅû¶ÁËGolang XML½âÎöÆ÷ÖеÄ3¸ö¹Ø¼ü·ì϶¡£¡£¡£¡£¡£¡£ÕâЩ·ì϶±ðÀëΪGo±àÂë/XMLÖеÄXMLÊôÐÔ²»²»±ä£¨CVE-2020-29509£©¡¢Ö¸Áî²»²»±ä£¨CVE-2020-29510£©ºÍÔªËØ²»²»±ä£¨CVE-2020-29511£©·ì϶¡£¡£¡£¡£¡£¡£ÕâÈý¸ö·ì϶ÊÇÇ×êÇÓйص쬣¬£¬ £¬£¬¶¼ÊÇÓÉÓÚ¶ñÒâXMLÏóÕ÷ÔÚͨ¹ýGoµÄ½âÂëÆ÷ºÍ±àÂëÆ÷ʵÏÖµÄÍù·µ¹ý³ÌÖвúÉúÁ˱äÒìËùµ¼ÖµÄ¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÀûÓÃÕâЩ·ì϶ºýŪÒÀÀµÓÚXML½âÎöÆ÷µÄ¸÷ÀàSAMLʵÏÖ£¬£¬£¬ £¬£¬ÒÔÆëÈ«ÈÆ¿ªSAMLÉí·ÝÑéÖ¤¡£¡£¡£¡£¡£¡£  


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/critical-golang-xml-parser-bugs-can-cause-saml-authentication-bypass/


3.GmailÔÚ24Ó×ʱÄÚ²úÉúµÚ¶þ´ÎÖжϣ¬£¬£¬ £¬£¬Ä¿Ç°Ô­Òòδ֪


3.png


GmailÔÚ24Ó×ʱÄÚÓÖ²úÉúÖжϣ¬£¬£¬ £¬£¬Óû§Äܹ»½Ó¼ûÆäµç×ÓÓʼþ£¬£¬£¬ £¬£¬µ«ÎÞ·¨·¢Ë͸øÆäËûGmailÓû§¡£¡£¡£¡£¡£¡£µ±Óû§½«µç×ÓÓʼþ·¢Ë͵½GmailµØÖ·Ê±£¬£¬£¬ £¬£¬»áÁ¢¼´ÊÕµ½Ò»Ìõ´«µÝʧ°ÜÐÂÎÅ£¬£¬£¬ £¬£¬²¢ÌáÐÑÕÒ²»µ½µØÖ·¡£¡£¡£¡£¡£¡£µ«ÊÇ£¬£¬£¬ £¬£¬ÏòʹÓÃ×Ô½ç˵ÓòµÄGSuite¿Í»§·¢Ë͵ç×ÓÓʼþûÓÐÈκÎÎÊÌâ¡£¡£¡£¡£¡£¡£Æ¾¾ÝDownDetectorÊý¾Ý£¬£¬£¬ £¬£¬Õâ´ÎGmailÖжÏÖØÒªÓ°ÏìÁËÃÀ¹úµÄÓû§¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬ £¬£¬GoogleÉêÃ÷ÎÊÌâÒѽâ¾ö£¬£¬£¬ £¬£¬µ«ÖжÏÔ­ÒòÉв»Ã÷È·¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/google/gmail-hit-by-a-second-outage-within-a-single-day/


4.ÓÊÂÖ¹«Ë¾HurtigrutenÔâµ½¹¥»÷£¬£¬£¬ £¬£¬µ¼Ö¹ؼüϵͳ崻ú


4.png


ŲÍþÓÊÂÖ¹«Ë¾HurtigrutenÔÚ12ÔÂ14ÈÕÔâµ½ÁËÍøÂç¹¥»÷£¬£¬£¬ £¬£¬µ¼Ö¶à¸ö¹Ø¼üϵͳ崻ú¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÖØÒªÔÚÔÚŲƽ¶¥É½°¶¾­Óª¶ÉÂÖ£¬£¬£¬ £¬£¬²¢ÔÚ±±¼«ºÍÄϼ«½øÐк½ÐС£¡£¡£¡£¡£¡£¸Ã¹«Ë¾°µÊ¾£¬£¬£¬ £¬£¬Ô¤¼ÆÕâ´Î¹¥»÷²»»á¶Ô¹«Ë¾Ôì³É³Á´óµÄ²ÆÕþÓ°Ï죬£¬£¬ £¬£¬µ«Ä¿Ç°Óм¸¸ö¹Ø¼üϵͳ³öÏÖ¹ÊÕÏ¡£¡£¡£¡£¡£¡£HurtigrutenµÄITÖ÷¹ÜOle-Marius Moe-HelgesenÔÚ°µÊ¾£¬£¬£¬ £¬£¬ÆäÈ«ÇòIT»ù´¡¼Ü¹¹ËƺõÊܵ½ÁËÓ°Ï죬£¬£¬ £¬£¬¶ø¹«Ë¾Ò²ÒѲÉÈ¡×ۺϴëÊ©ÒÔÏ޶ȹ¥»÷Ôì³ÉµÄ·çÏÕ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.hospitalityireland.com/general-industry/norwegian-cruise-company-hurtigruten-experiences-cyber-attack-116826


5.unit42°ä²¼Ä¾ÂíPyMICROPSIAµÄ·ÖÎö»ã±¨


5.png


unit42°ä²¼ÓйØÐÅÏ¢ÇÔȡľÂíPyMICROPSIAµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¸ÃľÂíÀ´×ÔÕë¶ÔÖж«µØÓòµÄºÚ¿Í×éÖ¯AridViper£¬£¬£¬ £¬£¬Óë¶ñÒâÈí¼þ¼Ò×åMICROPSIAÓйØ¡£¡£¡£¡£¡£¡£PyMICROPSIAÓµÓзá˶µÄÐÅÏ¢ÇÔÈ¡ºÍ½ÚÔìÖ°ÄÜ£¬£¬£¬ £¬£¬Ô̺¬ÎļþÉÏ´«¡¢ÓÐЧ¸ºÔØÏÂÔØºÍÖ´ÐÓ×¢ä¯ÀÀÆ÷ƾ֤ÇÔÈ¡¡¢¶Ï¸ùä¯ÀÀº¹Çà¼Í¼ºÍÅäÖÃÎļþ¡¢½ØÆÁ¡¢¼üÅ̼ͼºÍÖ´ÐкÅÁîµÈÖ°ÄÜ¡£¡£¡£¡£¡£¡£ËüÓÉPython±àд£¬£¬£¬ £¬£¬Ê¹ÓÃPyInstallerÔì³ÉWindows¿ÉÖ´ÐÐÎļþ£¬£¬£¬ £¬£¬²¢Í¨¹ýÔËÐÐÑ­»·À´ÊµÏÔìäÖØÒªÖ°ÄÜ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://unit42.paloaltonetworks.com/pymicropsia/


6.Bugcrowd°ä²¼½«À´Ê®Äê¶à°ü°²È«µÄÔ¤²â»ã±¨


6.png


Bugcrowd°ä²¼Á˽«À´Ê®Äê¶à°ü°²È«µÄÔ¤²â»ã±¨¡£¡£¡£¡£¡£¡£¸Ã»ã±¨È«Ãæ½éÉÜÁËCOVID-19ÈôºÎ³Áнç˵¿çÐÐÒµµÄÍøÂ簲ȫʵ¼Ê¡£¡£¡£¡£¡£¡£Óë2019ÄêÕûÄêÏà±È£¬£¬£¬ £¬£¬Ç°Ê®¸öÔÂÌá½»µÄ·ì϶ÊýÁ¿Ôö³¤ÁË24£¥¡£¡£¡£¡£¡£¡£ÔÚ2020ÄêÌá½»µÄÊ®´ó·ì϶ÖУ¬£¬£¬ £¬£¬Óа˸öÒ²³Ê´Ë¿Ì2019ÄêÁбíÖУ¬£¬£¬ £¬£¬Õâ×¢Ã÷ÖÎÀíÒÑÖª·çÏÕÒÀÈ»ÊÇ´óÎÞÊýÆóÒµÃæ¶ÔµÄÌôÕ½¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬ £¬£¬Ìá½»µÄ×î¶àµÄ·ì϶ÊÇÓÉÓÚ½Ó¼û½ÚÔì×÷³ÉµÄ·ÛË飬£¬£¬ £¬£¬Æä´ÎÊÇ¿çÕ¾µã¾ç±¾·ì϶£¨XSS£©¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bugcrowd.com/resources/reports/bugcrowd-priority-one-report/