ÐÅÏ¢°²È«Öܱ¨-2018ÄêµÚ34ÖÜ

°ä²¼¹¦·ò 2018-08-27

Ò»¡¢±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


        2018Äê08ÔÂ20ÈÕÖÁ26ÈÕ¹²ÊÕ¼°²È«·ì϶51¸ö£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇApache Struts 2 CVE-2018-11776´úÂëÖ´Ðзì϶£»£» £» £»£»Adobe Photoshop CC CVE-2018-12811ÄÚ´æ·ÛËé·ì϶£»£» £» £»£»Philips IntelliSpace CardiovascularÅäÖÃÖÎÀíȨÏÞÌáÉý·ì϶£»£» £» £»£»SambaĿ¼ÁÐ±í³¤Îļþ²é³­´úÂëÖ´Ðзì϶£»£» £» £»£»Emerson Electric DeltaV CVE-2018-14793»º³åÇøÒç¶Âí½Å¡£¡£¡£¡£¡£¡£


        ±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇ×êÑÐÍŶӷ¢ÏÖ³¯ÏÊAPT×éÖ¯DarkhotelÀûÓÃVBScript¾ç±¾ÒýÇæ0dayµÄ¹¥»÷»î¶¯£»£» £» £»£»×êÑÐÅú×¢GDPRÖ´ÐкóÅ·ÃËÐÂÎÅÍøÕ¾ÉϵĵÚÈý·½cookieÊýÁ¿½µÂäÁË22%£»£» £» £»£»ÃÀAugustaÒ½ÁÆÖÐÐÄÈ·ÈÏ2017Äê9ÔÂÔ¼41.7Íò»¼ÕßµÄÐÅϢй¶£»£» £» £»£»±£Ä··þÎñSitterÒòMongoDBÅäÖÃÃýÎóµ¼Ö³¬¹ý9.3ÍòÓû§µÄÐÅϢй¶£»£» £» £»£»Cheddar Scratch KitchenÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬Ô¼56ÍòÓû§µÄÒøÐп¨ÐÅϢй¶¡£¡£¡£¡£¡£¡£


        ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖС£¡£¡£¡£¡£¡£


 


¶þ¡¢³ÁÒª°²È«·ì϶Áбí


1¡¢Apache Struts 2 CVE-2018-11776´úÂëÖ´Ðзì϶


        Apache Struts½ç˵XMLÅäÖÃnamespaceֵΪͨÅä·û(¡°/*¡±)£¬£¬£¬£¬£¬»òÔÚÉϲãactionÖÐnamespaceֵȱʡʱ£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£


        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://cwiki.apache.org/confluence/display/WW/S2-057
2¡¢Adobe Photoshop CC CVE-2018-12811ÄÚ´æ·ÛËé·ì϶


        Adobe Photoshop CC´¦ÖÃÎļþ´æÔÚÄÚ´æ·ÛËé·ì϶£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇ󣬣¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£» £» £»£»òÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£


        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://helpx.adobe.com/security/products/photoshop/apsb18-28.html


3¡¢Philips IntelliSpace CardiovascularÅäÖÃÖÎÀíȨÏÞÌáÉý·ì϶


        Philips IntelliSpace CardiovascularûÓнøÐÐÕýÈ·µÄȨÏÞÖÎÀí£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬ÌáÉýȨÏÞ¡£¡£¡£¡£¡£¡£


        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://ics-cert.us-cert.gov/advisories/ICSMA-18-226-01
4¡¢SambaĿ¼ÁÐ±í³¤Îļþ²é³­´úÂëÖ´Ðзì϶


        samba¿Í»§¶ËûÓгä·ÖµÄ¼ì²âĿ¼ÁбíÖйý³¤µÄÎļþÃû£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄ¶ñÒâSAMBA·þÎñÆ÷ÒªÇ󣬣¬£¬£¬£¬Ö´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£


        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://www.samba.org/samba/security/CVE-2018-10858.html


5¡¢Emerson Electric DeltaV CVE-2018-14793»º³åÇøÒç¶Âí½Å


        Emerson Electric DeltaV´æÔÚ»ùÓÚÕ»µÄ»º³åÇøÒç¶Âí½Å£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬Ö´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£


        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://ics-cert.us-cert.gov/advisories/ICSA-18-228-01


 


Èý¡¢³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢×êÑÐÍŶӷ¢ÏÖ³¯ÏÊAPT×éÖ¯DarkhotelÀûÓÃVBScript¾ç±¾ÒýÇæ0dayµÄ¹¥»÷»î¶¯ 



8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


        Ç÷Ïò¿Æ¼¼µÄ°²È«×êÑÐÍŶӷ¢ÏÖ³¯ÏÊAPT×éÖ¯DarkhotelÔÚÀûÓÃ΢ÈíVBScript¾ç±¾ÒýÇæÖеÄÁãÈÕ·ì϶£¨CVE-2018-8373£©ÌáÒé¹¥»÷»î¶¯£¬£¬£¬£¬£¬¸Ã·ì϶ÊÇÒ»¸öuse-after-free·ì϶£¬£¬£¬£¬£¬¿ÉÔÊÐí¹¥»÷ÕßÔÚÖ¸±êÍÆËã»úÉÏÔËÐÐshellcode¡£¡£¡£¡£¡£¡£ÔÚ×îа汾µÄWindowsÖУ¬£¬£¬£¬£¬Î¢ÈíÔÚä¯ÀÀÆ÷µÄĬÈÏÅäÖÃÖнûÓÃÁËVBScript£¬£¬£¬£¬£¬Ê¹Æä²»Ò×Êܵ½¹¥»÷¡£¡£¡£¡£¡£¡£Î¢ÈíÒÑÔÚ8Ô°²È«¸üÐÂÖн¨¸´ÁË´Ë·ì϶¡£¡£¡£¡£¡£¡£


        Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/zero-day-in-microsofts-vbscript-engine-used-by-darkhotel-apt/


2¡¢×êÑÐÅú×¢GDPRÖ´ÐкóÅ·ÃËÐÂÎÅÍøÕ¾ÉϵĵÚÈý·½cookieÊýÁ¿½µÂäÁË22%



8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website



        ƾ¾ÝÅ£½ò´óѧReuters InstituteµÄÒ»·Ý»ã±¨£¬£¬£¬£¬£¬Å·ÃËÐÂÎÅÍøÕ¾ÉϵĵÚÈý·½cookieµÄÊýÁ¿ÔÚGDPRÖ´Ðкó½µÂäÁË22%¡£¡£¡£¡£¡£¡£¸Ã»ã±¨±ðÀë·ÖÎöÁË2018Äê4ÔÂÒÔ¼°7ÔµÄÊý¾Ý£¬£¬£¬£¬£¬º­¸ÇÁË·ÒÀ¼¡¢·¨¹ú¡¢µÂ¹ú¡¢Òâ´óÀû¡¢²¨À¼¡¢Î÷°àÑÀºÍÓ¢¹úÆß¸ö¹ú¶ÈµÄ200¸öÐÂÎÅÍøÕ¾¡£¡£¡£¡£¡£¡£½µÂä·ù¶È×î´óµÄÊÇÓ¢¹ú£¬£¬£¬£¬£¬ÆäÐÂÎÅÍøÕ¾Ê¹Óõĸú×Ùcookie±ÈGDPRÖ´ÐÐǰÏ÷¼õÁË45%¡£¡£¡£¡£¡£¡£½µÂä·ù¶È×îÓ×µÄÊǵ¹ú£¬£¬£¬£¬£¬Îª6%¡£¡£¡£¡£¡£¡£¶ø²¨À¼ÔòÊÇΨÖðÒ»¸öcookieÊýÁ¿Ôö³¤µÄ¹ú¶È£¬£¬£¬£¬£¬Ôö³¤·ù¶ÈΪ20%¡£¡£¡£¡£¡£¡£


        Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/technology/number-of-third-party-cookies-on-eu-news-sites-dropped-by-22-percent-post-gdpr/


3¡¢ÃÀAugustaÒ½ÁÆÖÐÐÄÈ·ÈÏ2017Äê9ÔÂÔ¼41.7Íò»¼ÕßµÄÐÅϢй¶



8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


        ÃÀ¹úAugustaÒ½ÁÆÖÐÐÄ7ÔÂ31Èյĵ÷²éÁ˾ÖÏÔʾ£¬£¬£¬£¬£¬2017Äê9ÔÂÕë¶ÔÆäÒ½Áƹ¤×÷ÈËÔ±µÄÍøÂç´¹µö¹¥»÷µ¼ÖÂÔ¼41.7Íò»¼ÕßµÄÊý¾Ý±»ÇÔ¡£¡£¡£¡£¡£¡£Ð¹Â¶µÄÊý¾ÝÔ̺¬µØÖ·¡¢µ®ÉúÈÕÆÚ¡¢Ò½ÁƼͼ±àºÅ¡¢Ò½ÖκÍÊÖÊõÐÅÏ¢¡¢Õï¶ÏÁ˾֡¢Ò©ÎïÒÔ¼°±£ÏÕÐÅÏ¢µÈ£¬£¬£¬£¬£¬ÉõÖÁÔ̺¬²¿ÃÅ»¼ÕßµÄÉç±£ºÅÂëºÍ¼ÝÕÕºÅÂë¡£¡£¡£¡£¡£¡£ÕâЩÐÅÏ¢¿ÉÄܻᱻºóÐøµÄÍøÂç´¹µö¹¥»÷¡¢Éí·Ýڲƭ»î¶¯ÉõÖÁÀÕË÷»î¶¯ËùÀûÓᣡ£¡£¡£¡£¡£


        Ô­ÎÄÁ´½Ó£ºhttps://www.infosecurity-magazine.com/news/augusta-health-center-reveals/


4¡¢±£Ä··þÎñSitterÒòMongoDBÅäÖÃÃýÎóµ¼Ö³¬¹ý9.3ÍòÓû§µÄÐÅϢй¶



8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website



        8ÔÂ14ÈÕ°²È«×êÑÐÈËÔ±Bob Diachenko·¢ÏÖ±£Ä··þÎñSitterµÄÒ»¸öMongoDB¿Éͨ¹ý»¥ÁªÍø¹«¿ª½Ó¼û£¨ÎÞÐèµÇ¼ʹ´¦£©£¬£¬£¬£¬£¬³¬¹ý9.3ÍòÃûÓû§µÄÃô¸ÐÊý¾Ýй¶¡£¡£¡£¡£¡£¡£Ð¹Â¶µÄÊý¾ÝÔ̺¬ÕË»§µÄÃÜÂë¹þÏ£¡¢Ã¿¸ö¼ÒÍ¥µÄº¢×ÓÊý¡¢¼ÒÍ¥µØÖ·¡¢µç»°ºÅÂë¡¢ÁªÏµÈËÁÐ±í¡¢Ö§¸¶¿¨ºÅÒÔ¼°appÄÚµÄ̸ÌìÐÅÏ¢µÈ¡£¡£¡£¡£¡£¡£Êý¾Ý×ÜÁ¿³¬¹ý2GB¡£¡£¡£¡£¡£¡£


        Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/mongodb-server-exposes-babysitting-apps-database/


5¡¢Cheddar Scratch KitchenÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬Ô¼56ÍòÓû§µÄÒøÐп¨ÐÅϢй¶
8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website



        Cheddar Scratch KitchenÓÚ2018Äê8ÔÂ16ÈÕÊÕµ½Áª¹úµ±¾ÖµÄÖҸ棬£¬£¬£¬£¬³ÆÆäPoSϵͳÔâµ½ºÚ¿ÍÈëÇÖ¡£¡£¡£¡£¡£¡£Ä¿Ç°ÔÚ°µÍøÉÏÏúÊÛµÄÓйØÒøÐп¨ÐÅϢԼΪ56.7ÍòÕÅ¡£¡£¡£¡£¡£¡£µ÷²éÅú×¢£¬£¬£¬£¬£¬¹¥»÷ÕßÔøÓÚ2017Äê11ÔÂ3ÈÕÖÁ2018Äê1ÔÂ2ÈÕÆÚ¼äÈëÇÖÁ˸ù«Ë¾µÄÍøÂç¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾³Æ2018Äê4ÔÂ10ÈÕÒÔÀ´ÆäÒÑʹÓÃÁËеÄPoSϵͳ£¬£¬£¬£¬£¬ÕâÒâζ×ŵ±Ç°µÄÖ§¸¶ÏµÍ³ºÍÍøÂç²»ÊÜÓ°Ïì¡£¡£¡£¡£¡£¡£Cheddar Scratch KitchenÔÚ23¸öÖݶ¼Óзֵ꣬£¬£¬£¬£¬¸Ã¹«Ë¾ÔÚÏòÊÜÓ°ÏìµÄÓû§ÌṩÃâ·ÑµÄÉí·Ý±£»£» £» £»£»¤·þÎñ¡£¡£¡£¡£¡£¡£


        Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/cheddar-scratch-kitchen-exposes-card-data-of-over-500-000/