ÐÅÏ¢°²È«Öܱ¨-2018ÄêµÚ35ÖÜ

°ä²¼¹¦·ò 2018-09-03

Ò»¡¢±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


        2018Äê08ÔÂ27ÈÕÖÁ9ÔÂ02ÈÕ¹²ÊÕ¼°²È«·ì϶54¸ö£¬£¬ £¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇÌÚѶFoxmailºÅÁî×¢Èë·ì϶£»£»£»£»£»OpenSSH auth-gss2.cÓû§Ã¶¾Ù·ì϶£»£»£»£»£»Google Chrome Blob API»º³åÇøÒç¶Âí½Å£»£»£»£»£»Emerson DeltaV DCS Workstation»º³åÇøÒç¶Âí½Å£»£»£»£»£»Adobe Acrobat/Reader CVE-2018-12808Ô½½çдËÁÒâ´úÂëÖ´Ðзì϶¡£¡£¡£¡£¡£¡£¡£ ¡£


        ±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊǰ®¶ûÀ¼µçÐŹ«Ë¾EirµÄһ̨±Ê¼Ç±¾±»µÁ£¬£¬ £¬£¬£¬£¬£¬µ¼ÖÂÔ¼3.7ÍòÓû§µÄÐÅϢй¶;AppleÔÚÏßÉ̵êÖеķì϶µ¼Ö³¬¹ý7700ÍòT-MobileÓû§ÕË»§µÄPINÂë¶³ö;AbbyyÒòÊý¾Ý¿âÅäÖÃÃýÎóµ¼ÖÂ20¶àÍò¸ö¿Í»§Îļþй¶;Î÷°àÑÀÒøÐйÙÍøÔâµ½DDoS¹¥»÷£¬£¬ £¬£¬£¬£¬£¬ÍøÕ¾ÁÙʱÎÞ·¨½Ó¼û;¼ÓÄô󺽿չ«Ë¾ÔâºÚ¿ÍÈëÇÖ£¬£¬ £¬£¬£¬£¬£¬Ô¼2ÍòÃûÓû§µÄÐÅÏ¢ÒÉй¶¡£¡£¡£¡£¡£¡£¡£ ¡£


        ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬ £¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖÓ×£¡£¡£¡£¡£¡£¡£ ¡£


 


¶þ¡¢³ÁÒª°²È«·ì϶Áбí


1¡¢ÌÚѶFoxmailºÅÁî×¢Èë·ì϶


        Tencent Foxmail URI´¦ÖôæÔÚÊäÈëÑéÖ¤·ì϶£¬£¬ £¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþ»òÒ³ÃæÒªÇ󣬣¬ £¬£¬£¬£¬£¬ÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâºÅÁî¡£¡£¡£¡£¡£¡£¡£ ¡£


        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://www.zerodayinitiative.com/advisories/ZDI-18-584/


2¡¢OpenSSH auth-gss2.cÓû§Ã¶¾Ù·ì϶


        OpenSSH auth-gss2.c´æÔÚ°²È«·ì϶£¬£¬ £¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬ £¬£¬£¬£¬£¬ÅжÏÓû§Ãû¡£¡£¡£¡£¡£¡£¡£ ¡£


        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttp://seclists.org/oss-sec/2018/q3/180


3¡¢Google Chrome Blob API»º³åÇøÒç¶Âí½Å


        Google Chrome Blob API´æÔÚ¶ÑÒç¶Âí½Å£¬£¬ £¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄWEBÒ³£¬£¬ £¬£¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬ £¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»òÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£ ¡£


        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://chromereleases.googleblog.com/2017/12/stable-channel-update-for-desktop.html


4¡¢Emerson DeltaV DCS Workstation»º³åÇøÒç¶Âí½Å


        Emerson Electric DeltaVÊ¢¿ªÍ¨Ñ¶¶Ë¿Ú´æÔÚÕ»Òç¶Âí½Å£¬£¬ £¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬ £¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»òÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£ ¡£


        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://ics-cert.us-cert.gov/advisories/ICSA-18-228-01


5¡¢Adobe Acrobat/Reader CVE-2018-12808Ô½½çдËÁÒâ´úÂëÖ´Ðзì϶


        Adobe Acrobat/Reader´¦ÖÃPDFÎļþ´æÔÚÔ½½çд·ì϶£¬£¬ £¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇ󣬣¬ £¬£¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬ £¬£¬£¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£ ¡£


        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://helpx.adobe.com/security/products/acrobat/apsb18-29.html


 


Èý¡¢³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢°®¶ûÀ¼µçÐŹ«Ë¾EirµÄһ̨±Ê¼Ç±¾±»µÁ£¬£¬ £¬£¬£¬£¬£¬µ¼ÖÂÔ¼3.7ÍòÓû§µÄÐÅϢй¶



8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


        ƾ¾Ý°®¶ûÀ¼µçÐŹ«Ë¾Eir¹ÙÍøÉϵÄ֪ͨ£¬£¬ £¬£¬£¬£¬£¬¸Ã¹«Ë¾µÄһ̨Ô̺¬Óû§Êý¾ÝµÄδ¼ÓÃܵıʼDZ¾µçÄÔÔâÇÔ£¬£¬ £¬£¬£¬£¬£¬µ¼ÖÂÔ¼3.7ÍòÓû§µÄÓ×ÎÒÐÅϢй¶¡£¡£¡£¡£¡£¡£¡£ ¡£Ð¹Â¶µÄÊý¾ÝÔ̺¬ÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂëºÍeirÕ˺𣡣¡£¡£¡£¡£¡£ ¡£¸Ã¹«Ë¾³ÆÐ¹Â¶µÄÊý¾Ý²»Ô̺¬ÈκÎÓû§µÄ²ÆÕþÊý¾Ý¡£¡£¡£¡£¡£¡£¡£ ¡£Ä¿Ç°¸Ã¹«Ë¾ÒÑÏòÊý¾Ý±£»£»£»£»£»¤×¨Ô±ºÍ°®¶ûÀ¼¾¯Ô±´«µÝÁËÕâ´ÎÊÂÎñ¡£¡£¡£¡£¡£¡£¡£ ¡£


        Ô­ÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/75655/data-breach/eir-data-breach.html


2¡¢AppleÔÚÏßÉ̵êÖеķì϶µ¼Ö³¬¹ý7700ÍòT-MobileÓû§ÕË»§µÄPINÂë¶³ö



8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


        ƾ¾ÝÃÀýBuzzFeedNewsµÄ±¨Â·£¬£¬ £¬£¬£¬£¬£¬AppleÔÚÏßÉ̵êÖеķì϶µ¼Ö³¬¹ý7700ÍòT-MobileÓû§ÕË»§µÄPINÂë¶³ö¡£¡£¡£¡£¡£¡£¡£ ¡£´Ë±í£¬£¬ £¬£¬£¬£¬£¬ÊÖ»ú±£ÏÕ¹«Ë¾AsurionµÄ¹ÙÍøÒ²´æÔÚÒ»¸ö·ì϶£¬£¬ £¬£¬£¬£¬£¬µ¼ÖÂAsurionµÄAT£¦T¿Í»§µÄPINÂë¶³ö¡£¡£¡£¡£¡£¡£¡£ ¡£ÕâÁ½¸ö·ì϶ÊÇÓɰ²È«×êÑÐÈËÔ±PhobiaºÍNicholas ¡°Convict¡± Ceraolo·¢Ïֵġ£¡£¡£¡£¡£¡£¡£ ¡£AppleÍøÕ¾Éϵķì϶¿ÉÄÜÓ뼯³ÉT-MobileµÄÕÊ»§ÑéÖ¤APIʱµÄ¹¤³ÌÃýÎóÓйء£¡£¡£¡£¡£¡£¡£ ¡£AppleºÍAsurionÒѾ­½¨¸´ÁËÓйطì϶¡£¡£¡£¡£¡£¡£¡£ ¡£


        Ô­ÎÄÁ´½Ó£ºhttps://www.buzzfeednews.com/article/nicolenguyen/tmobile-att-account-pin-security-flaw-apple


3¡¢AbbyyÒòÊý¾Ý¿âÅäÖÃÃýÎóµ¼ÖÂ20¶àÍò¸ö¿Í»§Îļþй¶

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


        8ÔÂ19ÈÕ°²È«×êÑÐÈËÔ±Bob DiachenkoÔÚAWSÔÆÆ½Ì¨ÉÏ·¢ÏÖÊôÓÚOCRÈí¼þ¿ª·¢ÉÌAbbyyµÄÒ»¸öMongoDB·þÎñÆ÷ÎÞÐèµÇ¼¼´¿É¹«¿ª½Ó¼û¡£¡£¡£¡£¡£¡£¡£ ¡£¸ÃÊý¾Ý¿â´óÓ×Ϊ142GB£¬£¬ £¬£¬£¬£¬£¬Ô̺¬¶àÖÖÃô¸ÐÎļþµÄɨÃè¼þ£¬£¬ £¬£¬£¬£¬£¬ÈçºÏͬ¡¢±£ÃܺÍ̸¡¢ÄÚ²¿º¯¼þ¼°±¸Íü¼µÈ¡£¡£¡£¡£¡£¡£¡£ ¡£ÆäÖÐÔ̺¬ÊôÓÚAbbyy¿Í»§µÄ20¶àÍò¸öÎļþ¡£¡£¡£¡£¡£¡£¡£ ¡£¸ÃÊý¾Ý¿â¿ÉÄÜÊÇAbbyyµÄ»ù´¡ÉèÊ©µÄÒ»²¿ÃÅ¡£¡£¡£¡£¡£¡£¡£ ¡£AbbyyµÄ°²È«ÍŶÓÔÚ½Óµ½Í¨ÖªÁ½Ììºó½¨¸´Á˸ÃÊý¾Ý¿âµÄÅäÖÃÃýÎóÎÊÌâ¡£¡£¡£¡£¡£¡£¡£ ¡£


        Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/ocr-software-dev-exposes-200-000-customer-documents/


4¡¢Î÷°àÑÀÒøÐйÙÍøÔâµ½DDoS¹¥»÷£¬£¬ £¬£¬£¬£¬£¬ÍøÕ¾ÁÙʱÎÞ·¨½Ó¼û



8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


        ƾ¾Ý·͸ÉçµÄ±¨Â·£¬£¬ £¬£¬£¬£¬£¬´Ó8ÔÂ26ÈÕÐÇÆÚÈÕÆðÍ·Î÷°àÑÀÒøÐеĹÙÍøÔâµ½ÁËÉ¢²¼Ê½»Ø¾ø·þÎñ¹¥»÷£¨DDoS£©£¬£¬ £¬£¬£¬£¬£¬ÆäÍøÕ¾ÁÙʱÎÞ·¨½Ó¼û¡£¡£¡£¡£¡£¡£¡£ ¡£¸ÃÒøÐеĽ²»°È˰µÊ¾£¬£¬ £¬£¬£¬£¬£¬Õâ´Î¹¥»÷¶Ô¸ÃÒøÐеķþÎñ»ò¸ÃÒøÐÐÓëÅ·ÖÞÖÐÑëÒøÐлòÆäËü»ú¹¹µÄͨѼû»ÓÐÔì³ÉÈκÎÓ°Ï죬£¬ £¬£¬£¬£¬£¬²¢ÇÒûÓÐÈκÎÊý¾Ýй¶µÄ·çÏÕ¡£¡£¡£¡£¡£¡£¡£ ¡£½ØÖÁÖܶþÏÂÎ磬£¬ £¬£¬£¬£¬£¬¸ÃÒøÐеÄÍøÕ¾ÈÔ´¦ÓÚÀëÏß״̬¡£¡£¡£¡£¡£¡£¡£ ¡£


        Ô­ÎÄÁ´½Ó£ºhttps://uk.reuters.com/article/us-spain-cyber-cenbank/bank-of-spains-website-hit-by-cyber-attack-idUKKCN1LC23B


5¡¢¼ÓÄô󺽿չ«Ë¾ÔâºÚ¿ÍÈëÇÖ£¬£¬ £¬£¬£¬£¬£¬Ô¼2ÍòÃûÓû§µÄÐÅÏ¢ÒÉй¶


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website



        8ÔÂ22ÈÕÖÁ24ÈÕÆÚ¼ä£¬£¬ £¬£¬£¬£¬£¬¼ÓÄô󺽿չ«Ë¾·¢ÏÖÒì³£µÄµÇ¼»î¶¯£¬£¬ £¬£¬£¬£¬£¬ÎªÁ˱£»£»£»£»£»¤Óû§µÄÊý¾Ý£¬£¬ £¬£¬£¬£¬£¬¸Ã¹«Ë¾Ëø¶¨ÁËËùÓÐ170ÍòÒÆ¶¯appÓû§µÄÕË»§¡£¡£¡£¡£¡£¡£¡£ ¡£29ÈÕ£¬£¬ £¬£¬£¬£¬£¬¸Ã¹«Ë¾Í¨ÖªÔ¼2ÍòÃûÓû§£¬£¬ £¬£¬£¬£¬£¬³ÆÆäÓ×ÎÒ×ÊÁÏ¿ÉÄÜÔ⵽δÊÚȨµÄ½Ó¼û¡£¡£¡£¡£¡£¡£¡£ ¡£ÕâЩ×ÊÁÏÖÁÉÙÔ̺¬ÐÕÃû¡¢µç×ÓÓʼþµØÖ·ºÍµç»°ºÅÂ룬£¬ £¬£¬£¬£¬£¬Ò²¿ÉÄÜÔ̺¬ÐԱ𡢵®ÉúÈÕÆÚ¡¢¹ú¼®¡¢»¤ÕÕºÅÂëµÈÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ ¡£ÔÚÒ»·Ý¹ØÓÚ¸ÃÊÂÎñµÄÉêÃ÷Öиù«Ë¾°µÊ¾Óû§µÄÒøÐп¨Êý¾ÝÒÔ¼°aircanada.comÕÊ»§²»ÊÜÓ°Ïì¡£¡£¡£¡£¡£¡£¡£ ¡£


        Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/air-canada-mobile-app-users-affected-by-data-breach/