Python¿âÇÔÈ¡SSHºÍGPGÃÜÔ¿£»£»£»£»£»£»£»£»AvastºÍAVG²å¼þ¼à¶½ChromeºÍFirefoxÓû§£»£»£»£»£»£»£»£»ÉúÎï¼ø±ðÊý¾ÝÍþв»ã±¨
°ä²¼¹¦·ò 2019-12-051.GoAhead Web·þÎñÆ÷RCE·ì϶ӰÏì´óÁ¿IoTÉ豸
˼¿ÆTalosµÄ°²È«×¨¼ÒÔÚGoAheadǶÈëʽWeb·þÎñÆ÷Öз¢ÏÖÁËÁ½¸ö·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬Ò»¸ö¹Ø¼üµÄÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2019-5096£©¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶ÓëGoAhead´¦ÖÃmulti-part/form-dataÒªÇóµÄ·½Ê½Óйأ¬£¬£¬£¬£¬£¬£¬£¬Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÀûÓø÷ì϶´¥·¢use-after-free£¬£¬£¬£¬£¬£¬£¬£¬²¢Í¨¹ý·¢ËͶñÒâHTTPÒªÇóÔÚ·þÎñÆ÷ÉÏÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£µÚ¶þ¸ö·ì϶£¨CVE-2019-5097£©´æÔÚÓÚͳһ×é¼þÖУ¬£¬£¬£¬£¬£¬£¬£¬¿Éµ¼Ö»ؾø·þÎñ¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄ°æ±¾Ô̺¬v5.0.1¡¢v.4.1.1ºÍv3.6.5¡£¡£¡£¡£¡£¡£¡£¡£Æ¾¾ÝShodanµÄËÑË÷Á˾֣¬£¬£¬£¬£¬£¬£¬£¬Â¶³öÔÚ¹«ÍøÉϵÄGoAhead·þÎñÆ÷ÊýÁ¿Òѳ¬¹ý130Íò¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/12/goahead-web-server-hacking.html
2.˼¿ÆTalosÅû¶Accusoft ImageGear¿âÖеÄRCE·ì϶
˼¿ÆTalos·¢ÏÖAccusoftµÄÎĵµºÍͼƬ´¦ÖÿâImageGear´æÔÚ¶à¸öRCE·ì϶¡£¡£¡£¡£¡£¡£¡£¡£µÚÒ»¸ö·ì϶£¨CVE-2019-5083£©Óëigcore19d.dllÖеÄTIF_decode_thunderscanº¯ÊýÓйأ¬£¬£¬£¬£¬£¬£¬£¬ÊÇÒ»¸öÔ½½çдÈëÎÊÌ⣬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÀûÓöñÒâTIFFÎļþ´¥·¢Ô¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£¡£¡£¡£µÚ¶þ¸ö·ì϶£¨CVE-2019-5076£©Ó°ÏìÁËPNG±êÍ·½âÎöÆ÷£¬£¬£¬£¬£¬£¬£¬£¬µÚÈý¸ö·ì϶£¨CVE-2019-5132£©ÊÇGEM Raster½âÎöÆ÷ÖеÄÔ½½çд·ì϶£¬£¬£¬£¬£¬£¬£¬£¬µÚËĸö·ì϶£¨CVE-2019-5133£©ÓëBMP½âÎöÆ÷Óйء£¡£¡£¡£¡£¡£¡£¡£ÎªÁËÀûÓÃÕâЩ·ì϶£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß±ØÒªÓÕʹÓû§´ò¿ª¶ñÒâÎĵµ¡£¡£¡£¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄ°æ±¾Ô̺¬Accusoft ImageGear 19.3.0£¬£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÒѾ°ä²¼ÁËÓйؽ¨¸´²¹¶¡¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/code-execution-vulnerabilities-patched-accusoft-imagegear
3.Á½¸ö¶ñÒâPython¿â±»·¢ÏÖÇÔÈ¡SSHºÍGPGÃÜÔ¿
Python°²È«ÍŶӴÓPyPI£¨PythonÈí¼þ°üË÷Òý£©ÖÐɾ³ýÁËÁ½¸öÇÔÈ¡SSHºÍGPGÃÜÔ¿µÄ¶ñÒâPython¿â¡£¡£¡£¡£¡£¡£¡£¡£ÕâÁ½¸ö¿âÊÇÓÉͳһλ¿ª·¢ÈËÔ±´´½¨µÄ£¬£¬£¬£¬£¬£¬£¬£¬µÚÒ»¸öÊÇpython3-dateutil£¬£¬£¬£¬£¬£¬£¬£¬·ÂÕÕÁËÊ¢ÐеÄdateutil¿â£¬£¬£¬£¬£¬£¬£¬£¬µÚ¶þ¸ö¿âÊÇjeIlyfish¿â£¬£¬£¬£¬£¬£¬£¬£¬·ÂÕÕÁËjellyfish¿â¡£¡£¡£¡£¡£¡£¡£¡£¹ÌÈ»python3-dateutilÊÇÔÚÁ½Ììǰ´´½¨²¢ÉÏ´«µ½PyPIÉϵ쬣¬£¬£¬£¬£¬£¬£¬µ«jeIlyfish¿âÔò´æÔÚÁ˽«½üÒ»ÄêµÄ¹¦·ò¡£¡£¡£¡£¡£¡£¡£¡£Æ¾¾Ý×êÑÐÈËÔ±µÄ·¢ÏÖ£¬£¬£¬£¬£¬£¬£¬£¬¶ñÒâ´úÂë½ö´æÔÚÓÚjeIlyfish¿âÖУ¬£¬£¬£¬£¬£¬£¬£¬python3-dateutilÈí¼þ°üÖе¼ÈëÁËjeIlyfish¿â¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâ´úÂëÊÔͼ´ÓÓû§ÍÆËã»úÖÐÇÔÈ¡SSHºÍGPGÃÜÔ¿£¬£¬£¬£¬£¬£¬£¬£¬²¢½«ËüÃÇ·¢Ë͵½ÒÔÏÂIPµØÖ·£ºhttp://68.183.212.246:32258¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/two-malicious-python-libraries-removed-from-pypi/
4.AvastºÍAVG²å¼þ±»·¢ÏּලChromeºÍFirefoxÓû§
°²È«×êÑÐÈËÔ±Wladimir Palant·¢ÏÖAvastºÍAVGµÄËĸöä¯ÀÀÆ÷²å¼þ´æÔÚ¸ú×ÙChromeºÍFirefoxÓû§µÄÐÐΪ£¬£¬£¬£¬£¬£¬£¬£¬²¢ÏòMozillaºÍ¹È¸è»ã±¨Á˸÷¢ÏÖ£¬£¬£¬£¬£¬£¬£¬£¬MozillaÒѾһʱɾ³ýÁËÕâЩ²å¼þ¡£¡£¡£¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄ²å¼þÔ̺¬Avast Online Security¡¢AVG Online Security¡¢Avast SafePriceºÍAVG SafePrice£¬£¬£¬£¬£¬£¬£¬£¬ÕâЩ²å¼þÖ¼ÔÚµ±Óû§½Ó¼û¶ñÒâÍøÕ¾»ò´¹µöÍøÕ¾Ê±ÏòÓû§·¢³öÖҸ棬£¬£¬£¬£¬£¬£¬£¬SafePrice²å¼þ¿ÉÔ®ÊÖ¹ºÎïÕß½øÐбȼۡ£¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±·¢ÏÖÕâЩ²å¼þÍøÂç´óÁ¿ÓйØÓû§ä¯ÀÀϰ¹ßµÄÊý¾Ý·¢Ë͵½¹«Ë¾µÄ·þÎñÆ÷£¬£¬£¬£¬£¬£¬£¬£¬Ô̺¬URL¡¢UID¡¢Ò³Ãæ±êÌâ¡¢ÆðÔ´ÍøÖ·¡¢ÈôºÎ½Ó¼û¸ÃÒ³Ãæ£¨ÀýÈçÖ±½ÓÊäÈëµØÖ·»òʹÓÃÊéÇ©»òµã»÷Á´½Ó£©¡¢¹ú¶È´úÂë¡¢ä¯ÀÀÆ÷Ãû³Æ¼°°æ±¾ºÅ¡¢²Ù×÷ϵͳ¼°°æ±¾ºÅµÈ¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/12/avast-and-avg-browser-plugins.html
5.¿¨°Í˹»ù°ä²¼Õë¶ÔÉúÎï¼ø±ðÊý¾ÝµÄÍþвÇ÷Ïò»ã±¨
¿¨°Í˹»ù×êÑÐÈËÔ±·¢ÏÖ£¬£¬£¬£¬£¬£¬£¬£¬ÔÚµÚÈý¼¾¶Å×ÃÓÚÍøÂç¡¢´¦Öúʹ洢ÉúÎï¼ø±ðÊý¾ÝµÄÍÆËã»úÖÐÓÐÈý·ÖÖ®Ò»£¨37£¥£©Ôâµ½¶ñÒâÈí¼þ¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬ËùÉæ¼°µÄ¶ñÒâÈí¼þÔ̺¬¼äµýÈí¼þºÍÔ¶¿ØÄ¾Âí£¨5.4%£©¡¢´¹µö¹¥»÷ÖÐʹÓõĶñÒâÈí¼þ-ÖØÒªÊǼäµýÈí¼þDownloaderºÍDropper£¨5.1%£©¡¢ÀÕË÷Èí¼þ£¨1.9£¥£©ºÍÒøÐÐľÂí£¨1.5£¥£©¡£¡£¡£¡£¡£¡£¡£¡£ÔÚÍþвÆðÔ´·½Ã棬£¬£¬£¬£¬£¬£¬£¬»¥ÁªÍø£¨14.4£¥£©ÊÇÉúÎï¼ø±ðÊý¾Ý´¦ÖÃϵͳµÄÖØÒªÍþвԴ£¬£¬£¬£¬£¬£¬£¬£¬Æä´ÎÊÇ¿ÉÒÆ¶¯Ã½Ì壨8£¥£©ºÍÍøÂç¹²ÏíÎļþ¼Ð£¨6.1£¥£©¡£¡£¡£¡£¡£¡£¡£¡£Ëæ×ÅÉúÎï¼ø±ðÈÏÖ¤¼¼ÊõÔ½À´Ô½¶àµØ±»ÓÃÓÚµ±¾ÖºÍóÒװ칫ÊÒ¡¢¹¤Òµ×Ô¶¯»¯ÏµÍ³¡¢¹«Ë¾ºÍÓ×ÎұʼDZ¾µçÄÔÒÔ¼°ÊÖ»úµÈ£¬£¬£¬£¬£¬£¬£¬£¬ÉúÎï¼ø±ðÊý¾ÝµÄ°²È«½ü¿ö±ØÒªÒýÆðÐÐÒµºÍµ±¾ÐÄà¹Ü»ú¹¹¡¢°²È«ÉçÇø¼°¹«¼ÒÈ·°ÑÎÈ¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securelist.com/biometric-data-processing-and-storage-system-threats/95364/
6.Ó¢¹ú»î¶¯ÁãÊÛÉÌSweaty BettyÔâµ½Magecart¹¥»÷
Ó¢¹ú»î¶¯ÁãÊÛÉÌSweaty BettyµÄÍøÕ¾Ôâµ½ºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬¿Í»§µÄÖ§¸¶ÐÅÏ¢¿ÉÄܱ»ÇÔ¡£¡£¡£¡£¡£¡£¡£¡£´ËÀ๥»÷±»Í³³ÆÎªMagecart¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬Æ¾¾Ý¸Ã¹«Ë¾·¢Ë͸ø¿Í»§µÄ֪ͨÓʼþ£¬£¬£¬£¬£¬£¬£¬£¬¸ÃÊÂÎñÓ°ÏìÁË11ÔÂ19ÈÕÏÂÎç6:24£¨GMT£©µ½11ÔÂ27ÈÕÏÂÎç2:52 PM£¨GMT£©ÆÚ¼äÔÚ¸ÃÍøÕ¾ÉϹºÎïµÄ¿Í»§¡£¡£¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿£¿£¿ÉÄܱ»µÁµÄÐÅÏ¢Ô̺¬ÐÕÃû¡¢ÃÜÂë¡¢Õ˵¥µØÖ·¡¢½»¸¶µØÖ·¡¢µç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂë¡¢ÐÅÓþ¿¨/½è¼Ç¿¨ºÅ¡¢CVVÊý×ÖºÍÓÐЧÆÚ¡£¡£¡£¡£¡£¡£¡£¡£Sweaty BettyÖ¸³öʹÓÃPayPal»òApple Pay½øÐйºÎïµÄ¿Í»§²»ÊÜÓ°Ïì¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/uk-retailer-sweaty-betty-hacked-to-steal-customer-payment-info/


¾©¹«Íø°²±¸11010802024551ºÅ