ÐÅÏ¢°²È«Öܱ¨-2019ÄêµÚ39ÖÜ

°ä²¼¹¦·ò 2019-10-08

> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö



2019Äê9ÔÂ30ÈÕÖÁ10ÔÂ06ÈÕÊÕ¼°²È«·ì϶42¸ö£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇExim ¡®string_vformat¡¯º¯Êý»º³åÇøÒç¶Âí½Å; Linux kernel cfg80211_mgd_wext_giwessid»º³åÇøÒç¶Âí½Å£»£»£»£»£»£»£» £»Liferay Portal JSON¸ºÔØ·´ÐòÁл¯´úÂëÖ´Ðзì϶£»£»£»£»£»£»£» £»Cisco Security Manager Java·´ÐòÁл¯ËÁÒâ´úÂëÖ´Ðзì϶£»£»£»£»£»£»£» £»WhatsApp DDGifSlurpÄÚ´æÃýÎóÒýÓ÷ì϶¡£¡£¡£¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊǺڿÍÇÔÈ¡³¬¹ý2.18ÒÚWords With FriendsÍæ¼ÒÊý¾Ý£»£»£»£»£»£»£» £»µ¤Âó¹«Ë¾DemantÔâµ½ÀÕË÷Èí¼þ¹¥»÷Ëðʧ9500ÍòÃÀÔª£»£»£»£»£»£»£» £»eGobblerжñÒâ¸æ°×»î¶¯½Ù³Ö³¬¹ý10ÒÚÓû§»á»°£»£»£»£»£»£»£» £»¶íÂÞ˹³¬¹ý2000Íò¹«ÃñµÄ˰Êռͼ¼°PIIÔÚÍøÉÏй¶£»£»£»£»£»£»£» £»×êÑÐÈËÔ±Åû¶AndroidϵͳÖеÄÐÂLPE 0day¡£¡£¡£¡£¡£¡£¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖÓ×£¡£¡£¡£¡£¡£¡£

> ³ÁÒª°²È«·ì϶Áбí


1. Exim ¡®string_vformat¡¯º¯Êý»º³åÇøÒç¶Âí½Å


Exim ¡®string_vformat¡¯º¯Êý´æÔÚ»º³åÇøÒç¶Âí½Å£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»£»£» £»òÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£
https://lists.exim.org/lurker/message/20190927.032457.c1044d4c.en.html

2. Linux kernel cfg80211_mgd_wext_giwessid»º³åÇøÒç¶Âí½Å


Linux kernel net/wireless/wext-sme.c cfg80211_mgd_wext_giwessid´¦Ö󬳤SSID IE´æÔÚ»º³åÇøÒç¶Âí½Å£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬¿Éʹϵͳ±ÀÀ£»£»£»£»£»£»£» £»òÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£
https://marc.info/?l=linux-wireless&m=157018270915487&w=2

3. Liferay Portal JSON¸ºÔØ·´ÐòÁл¯´úÂëÖ´Ðзì϶


Liferay Portal´¦ÖÃJSON¸ºÔØ´æÔÚ·´ÐòÁл¯·ì϶£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬¿ÉÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£
https://sec.vnpt.vn/2019/09/liferay-deserialization-json-deserialization-part-4/

4. Cisco Security Manager Java·´ÐòÁл¯ËÁÒâ´úÂëÖ´Ðзì϶


Cisco Security Manager Java·´ÐòÁл¯º¯Êý´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬ÔÊÐíͨ¹ýÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬¿ÉÖ´ÐÐËÁÒâºÅÁî¡£¡£¡£¡£¡£¡£¡£
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20191002-sm-java-deserial

5. WhatsApp DDGifSlurpÄÚ´æÃýÎóÒýÓ÷ì϶


WhatsApp decoding.cÖеÄDDGifSlurp´æÔÚÁ½´Î¿ªÊÍ·ì϶£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬¿ÉÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£
https://www.facebook.com/security/advisories/cve-2019-11932


> ³ÁÒª°²È«ÊÂÎñ×ÛÊö



1¡¢ºÚ¿ÍÇÔÈ¡³¬¹ý2.18ÒÚWords With FriendsÍæ¼ÒÊý¾Ý

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ºÚ¿ÍGnosticplayers´ÓÒÆ¶¯Éç½»ÓÎÏ·¹«Ë¾Zynga Inc¿ª·¢µÄWords With FriendsÖÐÇÔÈ¡Á˳¬¹ý2.18ÒÚÌõÍæ¼Ò¼Í¼¡£¡£¡£¡£¡£¡£¡£GnosticplayersÔøÔÚ2ÔÂÖÁ4ÔÂÆÚ¼äÏúÊÛÁË´Ó45¼Ò¹«Ë¾ÇÔÈ¡µÄ½ü10ÒÚÌõÓû§ÐÅÏ¢£¬£¬£¬£¬£¬£¬ÕâÒ»´ÎËû¶Ô×¼ÁËÃÀ¹úÉç½»ÓÎÏ·¿ª·¢ÉÌZynga¡£¡£¡£¡£¡£¡£¡£Æ¾¾ÝGnosticplayers·ÖÏíµÄ¼Í¼£¬£¬£¬£¬£¬£¬¸ÃÊý¾Ý¼¯Ô̺¬Óû§µÄÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢µÇ¼ID¡¢¼ÓÑιþÏ£ÃÜÂë¡¢ÃÜÂë³ÁÖÃÁîÅÆ¡¢µç»°ºÅÂë¡¢Facebook IDÒÔ¼°ZyngaÕÊ»§ID¡£¡£¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄÓû§Îª2019Äê9ÔÂ2ÈÕ֮ǰװÖò¢×¢²á¸ÃÓÎÏ·µÄAndroidºÍiOSÍæ¼Ò¡£¡£¡£¡£¡£¡£¡£ZyngaÈ·ÈÏÁËÕâÒ»ÊÂÎñ£¬£¬£¬£¬£¬£¬µ«°µÊ¾Ã»ÓвÆÕþÐÅϢй¶¡£¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/91850/data-breach/zynga-game-data-breach.html

2¡¢µ¤Âó¹«Ë¾DemantÔâµ½ÀÕË÷Èí¼þ¹¥»÷Ëðʧ9500ÍòÃÀÔª

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


×÷ΪȫÇò×î´óµÄÖúÌýÆ÷Ôì×÷ÉÌÖ®Ò»£¬£¬£¬£¬£¬£¬DemantÔ¤¼Æ±¾Ô³õϰȾÀÕË÷Èí¼þÖ®ºó£¬£¬£¬£¬£¬£¬½«Ôâ·ê¸ß´ï9500ÍòÃÀÔªµÄËðʧ¡£¡£¡£¡£¡£¡£¡£ÆäʱÔÚÆäÍøÕ¾Éϵļò¶ÌÉêÃ÷ÖУ¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾°µÊ¾£¬£¬£¬£¬£¬£¬ÔÚ×î³õÃèÊöΪ¡°ÑϳÁÊÂÎñ¡±Ö®ºó£¬£¬£¬£¬£¬£¬Ëü½«¹Ø¹ØÆäÕû¸öÄÚ²¿IT»ù´¡ÍøÂç¡£¡£¡£¡£¡£¡£¡£ÆäÖÐÔ̺¬¸Ã¹«Ë¾µÄERPϵͳ£¬£¬£¬£¬£¬£¬ÔÚ²¨À¼µÄ³ö²úºÍÏúÊÛÉèÊ©£¬£¬£¬£¬£¬£¬ÔÚÄ«Î÷¸çµÄ³ö²úºÍ·þÎñÖÐÐÄ£¬£¬£¬£¬£¬£¬ÔÚ·¨¹úµÄ¶úÎÏÖ²ÈëÎï³ö²ú»ùµØ£¬£¬£¬£¬£¬£¬ÔÚµ¤ÂóµÄ·Å´óÆ÷³ö²ú»ùµØÒÔ¼°Õû¸öÑÇÌ«µØÓòÍøÂç¡£¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.zdnet.com/article/ransomware-incident-to-cost-danish-company-a-whopping-95-million/

3¡¢eGobblerжñÒâ¸æ°×»î¶¯½Ù³Ö³¬¹ý10ÒÚÓû§»á»°


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


×êÑÐÈËÔ±·¢ÏÖÁËÓÉÍþв×éÖ¯eGobblerÌáÒéµÄÐÂÒ»²¨¹¥»÷»î¶¯£¬£¬£¬£¬£¬£¬ÆäÖÐÊܺ¦Õß±»³Á¶¨Ïòµ½´øÓжñÒâµÄÍøÕ¾¡£¡£¡£¡£¡£¡£¡£°²È«×¨¼ÒÒÔΪ£¬£¬£¬£¬£¬£¬eGobblerÊǽñÄêÐÂÉú½Ú¶à·¢ÐÔ¶ñÒâ¹¥»÷µÄÄ»ºóºÚÊÖ¡£¡£¡£¡£¡£¡£¡£Õâ´Î£¬£¬£¬£¬£¬£¬Ê¹ÓÃWebkitä¯ÀÀÆ÷ÒýÇæ·ì϶½Ù³ÖÁ˳¬¹ý10ÒÚ¸ö¸æ°×չʾ¡£¡£¡£¡£¡£¡£¡£×îеĻ»¹Åú×¢£¬£¬£¬£¬£¬£¬Õë¶ÔÒÔÇ°ÔøÒÔÒÆ¶¯É豸Ϊ¹¥»÷Ö¸±êµÄÍþв²Î¼ÓÕߵĴëÊ©ÓÐËùŤת£ºÔÚ´ËÆÚ¼ä£¬£¬£¬£¬£¬£¬eGobbler¶Ǫ̂ʽ»úµÄÆ«ÐÄÖ§³ÖÁËËûÃÇ×îеÄWebKitÀûÓᣡ£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/malvertising-attack-hijacks-1b-sessions-with-webkit-exploit/148795/

4¡¢¶íÂÞ˹³¬¹ý2000Íò¹«ÃñµÄ˰Êռͼ¼°PIIÔÚÍøÉÏй¶

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


×êÑÐÈËԱ˵£¬£¬£¬£¬£¬£¬³¬¹ý2000Íò·ÝÊôÓÚ¶íÂÞ˹¹«ÃñµÄ˰ÊռͼûÓÐÊܵ½±£»£»£»£»£»£»£» £»¤£¬£¬£¬£¬£¬£¬²¢Í¨¹ýÒ»¸ö¿É¹©¹«¼Ò½Ó¼ûµÄÔÚÏßÊý¾Ý¿â½øÐй«¿ª¡£¡£¡£¡£¡£¡£¡£¸Ã·þÎñÆ÷Ô̺¬ÁË´Ó2009Äêµ½2016ÄêµÄ¸ß¶ÈÃô¸ÐµÄÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£´ó²¿ÃżÍÂ¼ËÆºõÓëÀ´×ÔĪ˹¿Æ¼°³ÇÊÐÖܱߵØÓòµÄ¹«ÃñÓйء£¡£¡£¡£¡£¡£¡£Êý¾Ý¿âÔ̺¬ÐÕÃû£¬£¬£¬£¬£¬£¬µØÖ·£¬£¬£¬£¬£¬£¬¾Óס״̬£¬£¬£¬£¬£¬£¬»¤ÕÕºÅÂ룬£¬£¬£¬£¬£¬Òƶ¯µç»°£¬£¬£¬£¬£¬£¬Ë°ºÅ£¬£¬£¬£¬£¬£¬¹ÍÖ÷Ãû³ÆºÍ¹Ì¶¨µç»°ÒÔ¼°Ë°Öµ¡£¡£¡£¡£¡£¡£¡£ 


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/plaintext-tax-records-of-20-million-russians-leaked-online/

5¡¢×êÑÐÈËÔ±Åû¶AndroidϵͳÖеÄÐÂLPE 0day

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


×êÑÐÈËÔ±Maddie Stone·¢ÏÖÒ»¸ö佨¸´µÄAndroid 0dayÒѾ­±»ÀûÓ㬣¬£¬£¬£¬£¬¸Ã·ì϶Äܹ»Ê¹±¾µØÌØÈ¨¹¥»÷Õß»òÀûÓ÷¨Ê½Éý¼¶ÆäÌØÈ¨£¬£¬£¬£¬£¬£¬ÒÔ»ñµÃ¶ÔÒ×Êܹ¥»÷µÄÉ豸µÄ¸ù½Ó¼ûȨÏÞ£¬£¬£¬£¬£¬£¬²¢ÓпÉÄÜÆëÈ«½ÚÔì¸ÃÉ豸¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶ÔÚÈ¥Äê4ÔÂ֮ǰ°ä²¼µÄAndroidÄں˰汾ÖУ¬£¬£¬£¬£¬£¬¸Ã²¹¶¡ÒÑÔ̺¬ÔÚ2017Äê12Ô°䲼µÄ4.14 LTS LinuxÄÚºËÖУ¬£¬£¬£¬£¬£¬µ«½öÔ̺¬ÔÚAOSP AndroidÄں˰汾3.18¡¢4.4ºÍ4.9ÖÓ×£¡£¡£¡£¡£¡£¡£Google½«ÔÚ½«À´¼¸ÌìµÄ10Ô¡¶ Android°²È«²¼¸æ¡·Öа䲼´Ë·ì϶µÄ²¹¶¡·¨Ê½£¬£¬£¬£¬£¬£¬²¢Í¨ÖªOEM¡£¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://thehackernews.com/2019/10/android-kernel-vulnerability.html