ÐÅÏ¢°²È«Öܱ¨-2018ÄêµÚ47ÖÜ

°ä²¼¹¦·ò 2018-11-26

 ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2018Äê11ÔÂ19ÈÕÖÁ25ÈÕ¹²ÊÕ¼°²È«·ì϶48¸ö£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇApache Sparkµ¥»ú×ÊÔ´ÖÎÀíÆ÷ËÁÒâ´úÂëÖ´Ðзì϶£»£»£»£»£»£»Dell EMC Avamar Server/EMC Integrated Data Protection Appliance CVE-2018-11077ºÅÁî×¢Èë·ì϶£»£»£»£»£»£»TP-Link TL-R600VPN HTTP Server CVE-2018-3950»º³åÇøÒç¶Âí½Å£»£»£»£»£»£»Adobe Flash PlayerÀàÐÍ»ìºÏÔ¶³Ì´úÂëÖ´Ðзì϶£»£»£»£»£»£»Google Chrome GPU¿ªÊͺóʹÓ÷ì϶¡£¡£¡£¡£¡£



±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊǰµÍøÍйܷþÎñÉÌDaniel's HostingÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬³¬¹ý6500¸öÍøÕ¾±»É¾£»£»£»£»£»£»×êÑлú¹¹Åû¶ͨ¹ýÀ¶ÑÀÈëÇÔìû³µµÄCarsBlues¹¥»÷£¬£¬£¬£¬£¬ÒÉÓ°ÏìÊýǧÍòÆû³µ£»£»£»£»£»£»¿¨°Í˹»ù°ä²¼2019ÄêÍøÂçÍþвÇ÷ÏòµÄÔ¤²â»ã±¨£»£»£»£»£»£»VMware°ä²¼¸üУ¬£¬£¬£¬£¬½¨¸´Ðé¹¹»úÌÓÒÝ·ì϶CVE-2018-6983£»£»£»£»£»£»¼ÓÃÜÓʼþ·þÎñÉÌProtonMailÔâµ½ÒÉËÆÀÕË÷Èí¼þڲƭ¹¥»÷¡£¡£¡£¡£¡£



ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖС£¡£¡£¡£¡£




³ÁÒª°²È«·ì϶Áбí


1. Apache Sparkµ¥»ú×ÊÔ´ÖÎÀíÆ÷ËÁÒâ´úÂëÖ´Ðзì϶


Apache Sparkµ¥»ú×ÊÔ´ÖÎÀíÆ÷´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬ÔÚ¡®master¡¯Ö÷»úÉÏÖ´ÐдúÂë¡£¡£¡£¡£¡£

https://lists.apache.org/thread.html/341c3187f15cdb0d353261d2bfecf2324d56cb7db1339bfc7b30f6e5@%3Cdev.spark.apache.org%3E



2. Dell EMC Avamar Server/EMC Integrated Data Protection Appliance CVE-2018-11077ºÅÁî×¢Èë·ì϶


Dell EMC Avamar Server/EMC Integrated Data Protection Appliance´æÔÚÊäÈëÑéÖ¤·ì϶£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬ÒÔrootȨÏÞÖ´ÐÐËÁÒâºÅÁî¡£¡£¡£¡£¡£

http://packetstormsecurity.com/files/150420/Dell-EMC-Avamar-IDPA-Command-Injection.html



3. TP-Link TL-R600VPN HTTP Server CVE-2018-3950»º³åÇøÒç¶Âí½Å


TP-Link TL-R600VPN HTTP Server´æÔÚ»º³åÇøÒç¶Âí½Å£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬¿Éʹϵͳ±ÀÀ£»£»£»£»£»£»ò¿ÉÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£

https://www.tp-link.com/us/products/details/cat-4909_TL-R600VPN.html



4. Adobe Flash PlayerÀàÐÍ»ìºÏÔ¶³Ì´úÂëÖ´Ðзì϶


Adobe Flash Player´æÔÚÀàÐÍ»ìºÏ·ì϶£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇ󣬣¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬£¬£¬¿ÉÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£

https://helpx.adobe.com/security/products/flash-player/apsb18-44.html



5. Google Chrome GPU¿ªÊͺóʹÓ÷ì϶


Google Chrome GPU´æÔÚ¿ªÊͺóʹÓ÷ì϶£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄWEBÒªÇ󣬣¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»£»òÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£

https://chromereleases.googleblog.com/2018/11/stable-channel-update-for-desktop_19.html





 ³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢°µÍøÍйܷþÎñÉÌDaniel's HostingÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬³¬¹ý6500¸öÍøÕ¾±»É¾

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


11ÔÂ15ÈÕ°µÍø×î´óµÄÍøÂçÍйܷþÎñÉÌDaniel's HostingÔâµ½ºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬¹¥»÷Õßɾ³ýÁË6500¶à¸öÍøÕ¾£¬£¬£¬£¬£¬²¢ÇÒÕâÐ©ÍøÕ¾¶¼Ã»Óб¸·Ý¡£¡£¡£¡£¡£¸ÃÍйܷþÎñÉ̱³ºóµÄ¿ª·¢ÈËÔ±Daniel Winzen֤ʵ³Æ£¬£¬£¬£¬£¬·þÎñÆ÷µÄrootÕË»§Ò²±»É¾³ýÁË£¬£¬£¬£¬£¬²¢ÇÒÆ½Ì¨ÉÏÍйܵij¬¹ý6500¸öÍøÕ¾µÄÊý¾Ý¶¼Òѳ¹µ×ÃÔʧ¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÄÜÊÇÀûÓÃÁËphpÖеÄÁãÈÕ·ì϶£¬£¬£¬£¬£¬µ«Ò²ÓпÉÄÜÊÇÀûÓÃÁËÆäËüµÄ·ì϶¡£¡£¡£¡£¡£Ä¿Ç°»¹Ã»Óй¥»÷ÕßÐû³Æ¶Ô´ËÊÂÕÆ¹Ü¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/78165/cyber-crime/daniels-hosting-hacked.html


2¡¢×êÑлú¹¹Åû¶ͨ¹ýÀ¶ÑÀÈëÇÔìû³µµÄCarsBlues¹¥»÷£¬£¬£¬£¬£¬ÒÉÓ°ÏìÊýǧÍòÆû³µ

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Privacy4Cars·¢ÏÖÒ»ÖÖͨ¹ýÀ¶ÑÀÈëÇÔìû³µµÄCarsBlues¹¥»÷£¬£¬£¬£¬£¬¸Ã¹¥»÷²½ÖèÓëÏÖ´ú³µÁ¾ÖеijµÔØÓéÀÖϵͳÓйأ¬£¬£¬£¬£¬Í¨¹ýÀ¶ÑÀºÍ̸£¬£¬£¬£¬£¬¹¥»÷Õ߿ɻñµÃÓû§µÄÁªÏµÈËÁÐ±í¡¢Í¨»°¼Í¼¡¢ÎĽñÌìÖ¾ÉõÖÁÊǶÌÐÅÄÚÈݵÈÓ×ÎÒÐÅÏ¢¡£¡£¡£¡£¡£Privacy4Cars³ÆÕâÖÖ¹¥»÷Ö»±ØÒªÊ¹ÓÃÁ®¼ÛÇÒÒ×ÓÚ»ñµÃµÄÓ²¼þ/Èí¼þÔÚ¼¸·ÖÖÓÄÚ¼´¿ÉʵÏÖ£¬£¬£¬£¬£¬²¢ÇÒ²»±ØÒªÉîåäµÄ¼¼Êõ֪ʶ¡£¡£¡£¡£¡£È«ÇòÊýǧÍòÁ¾Æû³µÒÉÊܵ½Ó°Ï죬£¬£¬£¬£¬²¿Ãų§ÉÌÒѾ­°ä²¼Á˸üС£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.privacy4cars.com/can-my-car-be-hacked/default.aspx


3¡¢¿¨°Í˹»ù°ä²¼2019ÄêÍøÂçÍþвÇ÷ÏòµÄÔ¤²â»ã±¨

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


¿¨°Í˹»ù³¢ÊÔÊÒ°ä²¼¶Ô2019ÄêÍøÂçÍþвÇ÷ÏòµÄÒ»¸öÔ¤²â·ÖÎö£¬£¬£¬£¬£¬ÖØÒªÄÚÈÝÔ̺¬£º»òÐí²»»áÔÙ·¢ÏÖ¸ü¶àµÄ´óÐÍAPT×éÖ¯£»£»£»£»£»£»ÍøÂçÓ²¼þÓëÎïÁªÍøÍþв½«»á²»ÐݼÓÇ¿£»£»£»£»£»£»Óë±í½»ºÍÕþÖÎÓйصĹ«¿ª±¨³ð£»£»£»£»£»£»¶«ÄÏÑǺÍÖж«µØÓò»òÐí»á³öÏÖ¸ü¶àµÄ¹¥»÷×éÖ¯£»£»£»£»£»£»£¨Ring -£©È¨ÏÞ£¬£¬£¬£¬£¬±ÈRing 0¸ü¸ßµÄȨÏÞ£»£»£»£»£»£»×îÊÜ»¶Ó­µÄϰȾý½é-´¹µö£»£»£»£»£»£»»ò½«³öÏÖ¸ü¶àÀàËÆ¡°°ÂÔ˱÷³ý½¢¡±µÄ¹¥»÷£»£»£»£»£»£»¹©¸øÁ´¹¥»÷½«³ÖÐø£»£»£»£»£»£»Òƶ¯¶ñÒâÈí¼þ²»»á³öÏÖ´ó·¢×÷£¬£¬£¬£¬£¬µ«¸ß¼¶¹¥»÷Õß»á³ÖÐøÑ°ÕÒÈëÇÖÉ豸µÄ²½Öè¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º
https://securelist.com/kaspersky-security-bulletin-threat-predictions-for-2019/88878/


4¡¢VMware°ä²¼¸üУ¬£¬£¬£¬£¬½¨¸´Ðé¹¹»úÌÓÒÝ·ì϶CVE-2018-6983

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


VMware½¨¸´Ì츮±­ÉÏÅû¶µÄÐé¹¹»úÌÓÒÝ·ì϶£¨CVE-2018-6983£©£¬£¬£¬£¬£¬¸Ã·ì϶ÊÇÒ»¸öÕûÊýÒç¶Âí½Å£¬£¬£¬£¬£¬³É¹¦ÀûÓø÷ì϶¿Éµ¼ÖÂÐé¹¹»úÌÓÒݲ¢ÔÚËÞÖ÷»úÉÏÖ´ÐдúÂë¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄ²úÆ·Ô̺¬VMware Workstation¡¢VMware FusionµÈ£¬£¬£¬£¬£¬VMwareÔÚWorkstation°æ±¾ 14.1.2/15.0.2¼°Fusion°æ±¾10.1.5/11.0.2Öн¨¸´Á˸÷ì϶£¬£¬£¬£¬£¬½¨ÒéÓû§¾¡¿ì½øÐиüС£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º
https://www.vmware.com/security/advisories/VMSA-2018-0030.html


5¡¢¼ÓÃÜÓʼþ·þÎñÉÌProtonMailÔâµ½ÒÉËÆÀÕË÷Èí¼þڲƭ¹¥»÷

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Ê¢ÐеļÓÃܵç×ÓÓʼþ·þÎñProtonMailÔâµ½ÒÉËÆÀÕË÷Èí¼þڲƭµÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¹¥»÷ÕßAmFearLiathMorÐû³ÆÈëÇÖÁ˸ù«Ë¾²¢ÇÔÈ¡ÁË¡°´óÁ¿¡±µÄÓû§Êý¾Ý¡£¡£¡£¡£¡£¹¥»÷Õß½«ÆäÊê½ðÒªÇó°ä²¼ÔÚPastebinÉÏ£¬£¬£¬£¬£¬²¢ÍþвҪÏòÈ«ÊÀ½ç°ä²¼»òÏúÊÛÕâЩÊý¾Ý£¬£¬£¬£¬£¬µ«²¢Î´Ìṩ±»µÁÊý¾ÝµÄÑù±¾¡£¡£¡£¡£¡£ProtonMailÔÚµ÷²éÖ®ºó·ñ¶¨ÁËÕâÆð¹¥»÷ÊÂÎñ£¬£¬£¬£¬£¬Ðû³ÆÕâÖ»ÊÇÒ»¸öÊÔͼڲƭµÄȦÌס£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/78133/hacking/protonmail-hacked-hoax.html


ÉêÃ÷£º±¾×ÊѶÓÉ8827Ì«Ñô¼¯ÍÅάËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù