ÐÅÏ¢°²È«Öܱ¨-2018ÄêµÚ38ÖÜ

°ä²¼¹¦·ò 2018-09-25
 Ò»¡¢±¾Öܰ²È«Ì¬ÊÆ×ÛÊö

2018Äê09ÔÂ17ÈÕÖÁ23ÈÕ¹²ÊÕ¼°²È«·ì϶55¸ö£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇApache SpamAssassin meta ruleÓï·¨ËÁÒâ´úÂëÖ´Ðзì϶£»£»£»£»£» £»Rockwell Automation CIPÕ»Òç³ö´úÂëÖ´Ðзì϶£»£»£»£»£» £»Adobe ColdFusion CVE-2018-15965·´ÐòÁл¯´úÂëÖ´Ðзì϶£»£»£»£»£» £»Adobe AcrobatºÍReader CVE-2018-12848Ô½½çд·ì϶£»£»£»£»£» £»Apple iOS Core Bluetooth  CVE-2018-4330ËÁÒâ´úÂëÖ´Ðзì϶¡£¡£¡£¡£¡£¡£ ¡£¡£

±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇ×êÑÐÍŶӳƳ¬¹ý20ÒŲ́É豸ÈÔÊÜBlueBorne·ì϶µÄÓ°Ï죻£»£»£»£» £»Ó¢¹ú²¼Àï˹Íжû»ú³¡Ôâµ½ºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬£¬º½°àÐÅÏ¢ÏÔʾÆÁÒÑÖÕ³¡·þÎñÁ½Ì죻£»£»£»£» £»MongoDBÅäÖÃÃýÎóµ¼ÖÂÔ¼1100Íòµç×ÓÓʼþ¼Í¼¿É¹«¿ª½Ó¼û£»£»£»£»£» £»GovPayNet¹ÙÍø´æÔÚ·ì϶£¬£¬£¬£¬£¬£¬³¬¹ý1400ÍòÓû§¼Í¼ÒÉй¶£»£»£»£»£» £»ÃÀ¹ú¹úÎñÔºµç×ÓÓʼþϵͳÔâºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬£¬Ô¼1%Ô±¹¤µÄÐÅϢй¶¡£¡£¡£¡£¡£¡£ ¡£¡£

ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖС£¡£¡£¡£¡£¡£ ¡£¡£

¶þ¡¢³ÁÒª°²È«·ì϶Áбí


1. Apache SpamAssassin meta ruleÓï·¨ËÁÒâ´úÂëÖ´Ðзì϶


Apache SpamAssassin meta ruleÓï·¨´¦ÖôæÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬ÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£ ¡£¡£

https://lists.apache.org/thread.html/7f6a16bc0fd0fd5e67c7fd95bd655069a2ac7d1f88e42d3c853e601c@%3Cannounce.apache.org%3E


2. Rockwell Automation CIPÕ»Òç³ö´úÂëÖ´Ðзì϶


RSLinx Classic´¦ÖÃÌØÊâµÄCIP±¨ÎÄ´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇóµ½44818¶Ë¿Ú£¬£¬£¬£¬£¬£¬¿Éʹϵͳ±ÀÀ£»£»£»£»£» £»òÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£ ¡£¡£
https://rockwellautomation.custhelp.com/app/answers/detail/a_id/1075712


3. Adobe ColdFusion CVE-2018-15965·´ÐòÁл¯´úÂëÖ´Ðзì϶


Adobe ColdFusion·´ÐòÁл¯´¦ÖôæÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬ÒÔÀûÓ÷¨Ê½¸ßµÍÎÄȨÏÞÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£ ¡£¡£
https://helpx.adobe.com/security/products/coldfusion/apsb18-33.html


4. Adobe AcrobatºÍReader CVE-2018-12848Ô½½çд·ì϶


Adobe AcrobatºÍReader´æÔÚÔ½½çд·ì϶£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇ󣬣¬£¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬£¬£¬£¬¿ÉÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£ ¡£¡£
https://helpx.adobe.com/security/products/acrobat/apsb18-34.html


5. Apple iOS Core Bluetooth  CVE-2018-4330ËÁÒâ´úÂëÖ´Ðзì϶


Apple iOS Core Bluetooth×é¼þ´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£» £»òÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£ ¡£¡£
https://support.apple.com/en-us/HT208848

 Èý¡¢³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢×êÑÐÍŶӳƳ¬¹ý20ÒŲ́É豸ÈÔÊÜBlueBorne·ì϶µÄÓ°Ïì

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Armis Labs×êÑÐÍŶӳƳ¬¹ý20ÒÚÉ豸ÈÔÊÜÒ»ÄêǰÅû¶µÄBlueBorne·ì϶µÄÓ°Ïì¡£¡£¡£¡£¡£¡£ ¡£¡£BlueBorneÔ̺¬9¸öÀ¶ÑÀ·ì϶£¬£¬£¬£¬£¬£¬ÓÚ2017Äê9Ô±»Åû¶²¢Ëæºó½øÐн¨¸´¡£¡£¡£¡£¡£¡£ ¡£¡£µ½Ò»ÄêºóµÄ½ñÌ죬£¬£¬£¬£¬£¬Ô¼Èý·ÖÖ®¶þµÄÊÜÓ°ÏìÉ豸ÒѾ­½øÐÐÁ˸üУ¬£¬£¬£¬£¬£¬µ«ÈÔÓдóÁ¿µÄ·þÎñÆ÷¡¢ÖÇÄÜÍó±í¡¢Ò½ÁÆÉ豸ºÍ¹¤ÒµÉ豸µÈ»¹Î´½øÐн¨¸´£¬£¬£¬£¬£¬£¬Ô̺¬7.68ÒŲ́LinuxÉ豸¡¢7.34ÒŲ́ÔËÐÐAndroid5.1¼°¸üÔç°æ±¾µÄÉ豸¡¢2.61ÒŲ́ÔËÐÐAndroid6¼°¸üÔç°æ±¾µÄÉ豸¡¢2ÒŲ́WindowsÉ豸ÒÔ¼°5000Íǫ̀ÔËÐÐiOS9.3.5¼°¸üÔç°æ±¾µÄÉ豸¡£¡£¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º
https://www.armis.com/blueborne-one-year-later/


2¡¢Ó¢¹ú²¼Àï˹Íжû»ú³¡Ôâµ½ºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬£¬º½°àÐÅÏ¢ÏÔʾÆÁÒÑÖÕ³¡·þÎñÁ½Ìì


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Ó¢¹ú²¼Àï˹Íжû»ú³¡Ôâµ½ÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬£¬Æäº½°àÐÅÏ¢ÏÔʾÆÁÒÑÖÕ³¡·þÎñÁ½Ìì¡£¡£¡£¡£¡£¡£ ¡£¡£¸Ã»ú³¡µÄ½²»°È˰µÊ¾º½°à²»ÊÜÓ°Ï죬£¬£¬£¬£¬£¬µ«±ØÐëʹÓÃÓ¦¼±´ëÊ©ºÍÊÖ¶¯µÄÁ÷³Ì£¬£¬£¬£¬£¬£¬Ô̺¬°×°åºÍ¼ÇºÅ±ÊµÈÀ´°ü°ìÏÔʾÆÁ¡£¡£¡£¡£¡£¡£ ¡£¡£¸Ã»ú³¡Ã»ÓÐÏò¹¥»÷ÕßÖ§¸¶Êê½ð¡£¡£¡£¡£¡£¡£ ¡£¡£Õâ²»ÊÇÒ»´ÎÕë¶ÔÐԵĹ¥»÷£¬£¬£¬£¬£¬£¬¶øÊÇËæ»úµÄ¹¥»÷¡£¡£¡£¡£¡£¡£ ¡£¡£¸Ã»ú³¡ÔÚÈ·±£Æäº½°àÐÅϢϵͳÔÚ³ÁÐÂÉÏÏß֮ǰÊǰ²È«µÄ¡£¡£¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/76248/breaking-news/bristol-airport-cyber-attack.html


3¡¢MongoDBÅäÖÃÃýÎóµ¼ÖÂÔ¼1100Íòµç×ÓÓʼþ¼Í¼¿É¹«¿ª½Ó¼û


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


°²È«×êÑÐÈËÔ±Bob DiachenkoÔÚ»¥ÁªÍøÉÏ·¢ÏÖÒ»¸ö¿É¹«¿ª½Ó¼ûµÄMongoDB£¬£¬£¬£¬£¬£¬¸ÃÊý¾Ý¿âÖÐÔ̺¬Ô¼1100ÍòÌõµç×ÓÓʼþ¼Í¼¡£¡£¡£¡£¡£¡£ ¡£¡£Êý¾Ý¿âµÄ´óÓ×Ϊ43.5GB£¬£¬£¬£¬£¬£¬Ô̺¬ÁËÓû§µÄÑÅ»¢µç×ÓÓÊÏä¼Í¼ÒÔ¼°ÐÕÃû¡¢ÎïÀíµØÖ·¡¢ÓÊÕþ±àÂëºÍ¾Óס³ÇÊеÈÓ×ÎÒÐÅÏ¢¡£¡£¡£¡£¡£¡£ ¡£¡£¸ÃÊý¾Ý¿âÍйÜÔÚÃÀ¹úGrupo-SMSµÄ»ù´¡ÉèÊ©ÉÏ£¬£¬£¬£¬£¬£¬Ä¿Ç°»¹²»ÖªÂ·¸ÃÊý¾Ý¿âµÄËùÓÐÕßµÄÉí·Ý¡£¡£¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/database-with-11-million-email-records-exposed/


4¡¢GovPayNet¹ÙÍø´æÔÚ·ì϶£¬£¬£¬£¬£¬£¬³¬¹ý1400ÍòÓû§¼Í¼ÒÉй¶


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ΪÃÀ¹úÖݵ±¾ÖºÍ´¦Ëùµ±¾ÖÌṩÔÚÏßÖ§¸¶Æ½Ì¨µÄGovPayNow.com´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬³¬¹ý1400ÍòÓû§µÄÓ×ÎÒÐÅÏ¢ÒÉй¶¡£¡£¡£¡£¡£¡£ ¡£¡£¸ÃÍøÕ¾Îª36¸öÖݵÄ2000¶à¸öµ±¾Ö»ú¹¹Ìṩ·þÎñ£¬£¬£¬£¬£¬£¬¹«ÃñÄܹ»Í¨¹ýËüÀ´Ö§¸¶·£¿£¿£¿£¿£¿£¿î¡¢ÅÉ˾·ÑºÍÕ˵¥µÈ¡£¡£¡£¡£¡£¡£ ¡£¡£Æ¾¾ÝBrian KrebsµÄ˵·¨£¬£¬£¬£¬£¬£¬¸ÃÍøÕ¾µÄÔÚÏßÖ§¸¶ÊÕÌõÊǰ´°¤´Î±àºÅµÄ£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»Í¨¹ýÅú¸ÄURLÖеÄÊý×ÖÀ´²é¿´ÆäËüÈ˵ļͼ¡£¡£¡£¡£¡£¡£ ¡£¡£ÕâЩ¼Í¼Ô̺¬Óû§µÄÐÕÃû¡¢µØÖ·¡¢µç»°ºÅÂë¼°ÒøÐп¨ºóËÄλÊý×ֵȡ£¡£¡£¡£¡£¡£ ¡£¡£¸Ã¹«Ë¾°µÊ¾ÒÑÔÚÖÜÄ©½¨¸´ÁËÕâÒ»ÎÊÌâ¡£¡£¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/government-payment-service-exposes/


5¡¢ÃÀ¹ú¹úÎñÔºµç×ÓÓʼþϵͳÔâºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬£¬Ô¼1%Ô±¹¤µÄÐÅϢй¶


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ÃÀ¹ú¹úÎñÔºµÄµç×ÓÓʼþϵͳÔâµ½ºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬£¬ÉÙÊýÔ±¹¤£¨²»µ½1%£©µÄÓ×ÎÒÐÅÏ¢¿ÉÄÜй¶¡£¡£¡£¡£¡£¡£ ¡£¡£Æ¾¾Ý¹úÎñÔº°ä²¼µÄ²¼¸æ£¬£¬£¬£¬£¬£¬¸Ãµç×ÓÓʼþϵͳ³¤¶Ì»úÃÜÐÔµç×ÓÓʼþϵͳ£¬£¬£¬£¬£¬£¬Æä±»ÃèÊöΪÃô¸Ðµ«²»Éæ¼°»úÃÜ¡£¡£¡£¡£¡£¡£ ¡£¡£¹úÎñÔº½²»°ÈËNicole Thompson°µÊ¾ÕâÒ»ÊÂÎñ»¹ÔÚµ÷²éÖ®ÖУ¬£¬£¬£¬£¬£¬¹úÎñÔºÔÚÓëºÏ×÷ͬ°éºÍ˽Ӫ²¿ÃÅ·þÎñÉ̹²Í¬½øÐÐÈ«ÃæµÄÆÀ¹À¡£¡£¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º
https://www.politico.com/story/2018/09/17/state-department-email-personal-information-792665


ÉêÃ÷£º±¾×ÊѶÓÉ8827Ì«Ñô¼¯ÍÅάËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù