ÐÅÏ¢°²È«Öܱ¨-2018ÄêµÚ25ÖÜ
°ä²¼¹¦·ò 2018-06-25
Ò»¡¢±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
2018Äê06ÔÂ18ÈÕÖÁ24ÈÕ¹²ÊÕ¼°²È«·ì϶46¸ö£¬£¬£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇCisco FXOS/NX-OS Software Fabric ServicesÔ¶³Ì´úÂëÖ´Ðзì϶£»£»£»£»£»£»Cisco NX-OS Software NX-APIËÁÒâ´úÂëÖ´Ðзì϶£»£»£»£»£»£»NTP ntpqºÍntpdc CVE-2018-12327Õ»»º³åÇøÃýÎó·ì϶£»£»£»£»£»£»CA Privileged Access Manager CVE-2015-4664ÊäÈëÑéÖ¤ËÁÒâºÅÁîÖ´Ðзì϶£»£»£»£»£»£»QEMU slirp/mbuf.c/m_cat¶Ñ»º³åÇøÒç¶Âí½Å¡£¡£¡£¡£¡£¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇ×êÑÐÈËÔ±ÖÒ¸æ³Æ¶ñÒâÈí¼þͨ¹ý¼Ù×°³Éµï±¤Ö®Ò¹°²×¿°æ½øÐд«²¼£»£»£»£»£»£»×êÑÐÈËÔ±³ÆmacOSµÄQuickLookÖ°Äܿɵ¼Ö¼ÓÃÜ´ÅÅ̵ÄÊý¾Ýй¶£»£»£»£»£»£»º«¹ú¼ÓÃÜÇ®±ÒÂòÂôËùBithumbÒ»ÄêÄÚµÚ¶þ´ÎÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬£¬Ô¼3100ÍòÃÀÔª±»ÇÔ£»£»£»£»£»£»Flightradar24ÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬£¬Ô¼23ÍòÓû§µÄÐÅϢй¶£»£»£»£»£»£»×êÑÐÈËÔ±·¢ÏÖ³¬¹ý3000¸öappµÄFirebaseÊý¾Ý¿â¿É¹«¿ª½Ó¼û¡£¡£¡£¡£¡£¡£¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖС£¡£¡£¡£¡£¡£¡£
¶þ¡¢³ÁÒª°²È«·ì϶Áбí
1¡¢Cisco FXOS/NX-OS Software Fabric ServicesÔ¶³Ì´úÂëÖ´Ðзì϶
Cisco FXOS/NX-OS Software Fabric Services×é¼þδÓÐЧÑéÖ¤Fabric ServicesÊý¾Ý°üÄڵıêͷֹܬ£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬ÒÔϵͳ¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180620-fxnxos-fab-ace
2¡¢Cisco NX-OS Software NX-APIËÁÒâ´úÂëÖ´Ðзì϶
Cisco NX-OS Software NX-API×Ó·¨Ê½ÖеÄÉí·ÝÑé֤ģ¿£¿£¿£¿£¿£¿éûÓÐÕýÈ·µÄÖ´ÐÐÊäÈëÑéÖ¤£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬ÒÔrootÓû§Éí·ÝÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180620-nxos-bo
3¡¢NTP ntpqºÍntpdc CVE-2018-12327Õ»»º³åÇøÃýÎó·ì϶
NTP ntpqºÍntpdc´¦Öýϳ¤µÄ×Ö·û´®×÷ΪIPv4»òIPv6ºÅÁîÐеIJÎÊý´æÔÚ°²È«ÎÊÌ⣬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬ÒÔÀûÓ÷¨Ê½Ö´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://gist.github.com/fakhrizulkifli/9b58ed8e0354e8deee50b0eebd1c011f
4¡¢CA Privileged Access Manager CVE-2015-4664ÊäÈëÑéÖ¤ËÁÒâºÅÁîÖ´Ðзì϶
CA Privileged Access Manager´æÔÚÊäÈëÑéÖ¤·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬ÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâºÅÁî¡£¡£¡£¡£¡£¡£¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://support.ca.com/us/product-content/recommended-reading/security-notices/ca20180614-01--security-notice-for-ca-privileged-access-manager.html
5¡¢QEMU slirp/mbuf.c/m_cat¶Ñ»º³åÇøÒç¶Âí½Å
QEMUÔÚslirp/mbuf.c/m_catÖдæÔÚ»ùÓڶѵĻº³åÇøÒç¶Âí½Å£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐí±¾µØ¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬¿Éʹϵͳ±ÀÀ£¡£¡£¡£¡£¡£¡£¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://bugzilla.redhat.com/show_bug.cgi?id=1586245
Èý¡¢³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢×êÑÐÈËÔ±ÖÒ¸æ³Æ¶ñÒâÈí¼þͨ¹ý¼Ù×°³Éµï±¤Ö®Ò¹°²×¿°æ½øÐд«²¼

ESETµÄ¶ñÒâÈí¼þ×êÑÐÈËÔ±Lukas Stefanko·¢ÏÖ²¿ÃŶñÒâÈí¼þͨ¹ý¼Ù×°³Éµï±¤Ö®Ò¹µÄ°²×¿°æ½øÐд«²¼¡£¡£¡£¡£¡£¡£¡£µï±¤Ö®Ò¹ÔÚÈ«ÇòÕ¼Óг¬¹ý1.25ÒÚÍæ¼Ò£¬£¬£¬£¬£¬£¬£¬£¬µ«Æä¹Ù·½°²×¿°æ±¾ÉÐδ°ä²¼¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±·¢ÏÖGoogleºÍYouTubeÉϵÄһЩÊÓÆµºÍÁ´½ÓÐû³ÆÆäÔ̺¬µï±¤Ö®Ò¹µÄAPKÎļþ£¬£¬£¬£¬£¬£¬£¬£¬»òÊÇÊèµ¼Óû§×°ÖÃһЩÆäËüÀûÓÃÒÔ½âËø¸ÃÓÎÏ·£¬£¬£¬£¬£¬£¬£¬£¬Õ⽫¸ø¶ñÒâÈí¼þ¿ª·¢ÈËÔ±´øÀ´ÊÕÈë»òÇÖº¦Óû§µÄ°²×¿É豸¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/06/fortnite-for-android-apk.html
2¡¢×êÑÐÈËÔ±³ÆmacOSµÄQuickLookÖ°Äܿɵ¼Ö¼ÓÃÜ´ÅÅ̵ÄÊý¾Ýй¶

Digita SecurityµÄ×êÑÐÈËÔ±Patrick WardleÖÒ¸æ³ÆmacOSÓû§´æ´¢ÔÚ¼ÓÃÜ´ÅÅÌÉϵÄÊý¾Ý²¢Ã»Óеõ½ºÜºÃµÄ±£»£»£»£»£»£»¤£¬£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚmacOSµÄQuickLookÖ°ÄÜÄܹ»±£ÁôͼƬµÈÎļþµÄÔ¤ÀÀ¡£¡£¡£¡£¡£¡£¡£µ±Í¨¹ýUI²é¿´Ä¿Â¼Ê±£¬£¬£¬£¬£¬£¬£¬£¬QuickLook½«×Ô¶¯´´½¨»ººÍ´æÎļþµÄËõÂÔͼ£¬£¬£¬£¬£¬£¬£¬£¬ÕâЩËõÂÔͼ±£ÁôÔÚSQLiteÊý¾Ý¿âÖУ¬£¬£¬£¬£¬£¬£¬£¬¿Éͨ¹ýÓйغÅÁî½øÐÐÌáÈ¡¡£¡£¡£¡£¡£¡£¡£¼´±ãÔʼÎļþ±»É¾³ý£¬£¬£¬£¬£¬£¬£¬£¬ÕâЩ»º´æÈԾɴæÔÚ¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://threatpost.com/macos-quicklook-feature-leaks-data-despite-encrypted-drive/132905/
3¡¢º«¹ú¼ÓÃÜÇ®±ÒÂòÂôËùBithumbÒ»ÄêÄÚµÚ¶þ´ÎÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬£¬Ô¼3100ÍòÃÀÔª±»ÇÔ

ƾ¾Ýº«¹ú¼ÓÃÜÇ®±ÒÂòÂôËùBithumbµÄÉêÃ÷£¬£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÔÚ6ÔÂ19ÈÕÖÁ20ÈÕµÄÒ¹¼äÔâµ½ºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬£¬¼ÛÖµÔ¼350ÒÚº«Ôª£¨3160ÍòÃÀÔª£©µÄ¼ÓÃÜÇ®±Ò±»ÇÔ¡£¡£¡£¡£¡£¡£¡£BithumbûÓÐй©¹ØÓÚÕâ´Î¹¥»÷µÄ¸ü¶àϸ½Ú£¬£¬£¬£¬£¬£¬£¬£¬Ô̺¬ºÚ¿ÍÈôºÎ½øÈëϵͳºÍÈôºÎÇÔÈ¡×ʽ𡣡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾°µÊ¾´òËãÀûÓô¢Ðî»ù½ðÀ´Åâ³¥ÊÜËðʧµÄÓû§¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/bithumb-hacked-second-time-in-a-year-hackers-steal-31-million/
4¡¢Flightradar24ÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬£¬Ô¼23ÍòÓû§µÄÐÅϢй¶

Èðµä¹«Ë¾Flightradar24֤ʵÆäһ̨·þÎñÆ÷ÓÚÉÏÖÜÄ©ÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬£¬Ô¼23ÍòÓû§µÄµç×ÓÓʼþµØÖ·ºÍ¹þÏ£ÃÜÂëй¶¡£¡£¡£¡£¡£¡£¡£Flightradar24ÊÇÒ»¼ÒÌṩº½°à×·×Ù·þÎñµÄ¹«Ë¾£¬£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾°µÊ¾Õâ´Îй¶ӰÏìÁË2016Äê3ÔÂ16ÈÕ֮ǰע²áµÄÓû§¡£¡£¡£¡£¡£¡£¡£Flightradar24ÒÑÏòÓû§·¢ËÍÁËÔ̺¬ÃÜÂë³ÁÖÃÁ´½ÓµÄÓʼþ£¬£¬£¬£¬£¬£¬£¬£¬ÒªÇóÕâЩÓû§¸ü¸ÄÃÜÂë¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/06/flightradar24-data-breach.html
5¡¢×êÑÐÈËÔ±·¢ÏÖ³¬¹ý3000¸öappµÄFirebaseÊý¾Ý¿â¿É¹«¿ª½Ó¼û

°²È«×êÑÐÈËÔ±·¢ÏÖ³¬¹ý3000¸öapp£¨Ô̺¬2446¸öAndroid appºÍ600¸öiOS app£©µÄÔ¼2300¸öFirebaseÊý¾Ý¿â¿É¹«¿ª½Ó¼û£¬£¬£¬£¬£¬£¬£¬£¬³¬¹ý1ÒÚÌõÓû§ÐÅϢй¶£¨³¬¹ý113GB£©¡£¡£¡£¡£¡£¡£¡£ÕâЩй¶µÄÐÅÏ¢Ô̺¬Ã÷ÎÄÃÜÂë¡¢Óû§ID¡¢µØÎ»ÒÔ¼°²¿ÃŲÆÕþ¼Í¼£¨ÒøÐÓ×¢¼ÓÃÜÇ®±ÒÂòÂô£©µÈ¡£¡£¡£¡£¡£¡£¡£GoogleµÄFirebaseÊÇ×îÊÜ»¶ÓµÄÒÆ¶¯ºÍWebÀûÓõĺó¶Ë¿ª·¢Æ½Ì¨Ö®Ò»£¬£¬£¬£¬£¬£¬£¬£¬ËüΪ¿ª·¢ÈËÔ±ÌṩÁË»ùÓÚÔÆµÄÊý¾Ý¿â£¬£¬£¬£¬£¬£¬£¬£¬²¢ÒÔJSONÌåʽ´æ´¢Êý¾Ý¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±·¢Ïֺܶ࿪·¢ÈËԱδÍ×ÉÆ±£»£»£»£»£»£»¤ÆäFirebaseÊý¾Ý¿â£¬£¬£¬£¬£¬£¬£¬£¬Ê¹µÃ¹¥»÷ÕßÖ»ÐèÔÚÖ÷»úÃûĩβÔö³¤¿ÕÊý¾Ý¿âÃû+¡°/.json¡±¼´¿É½Ó¼ûÕâЩÊý¾Ý¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/06/mobile-security-firebase-hosting.html


¾©¹«Íø°²±¸11010802024551ºÅ