ÐÅÏ¢°²È«Öܱ¨-2019ÄêµÚ12ÖÜ

°ä²¼¹¦·ò 2019-03-25

±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2019Äê3ÔÂ18ÈÕÖÁ24ÈÕ¹²ÊÕ¼°²È«·ì϶57¸ö£¬£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇMozilla Firefox IonMonkey JIT±àÒëÆ÷ÀàÐÍ»ìºÏ·ì϶£» £»£»£»£»£»£» £»Cisco IP Phone 7800/8800 Series sipÔ¶³Ì´úÂëÖ´Ðзì϶; CUJO Smart Firewall DHCPÖ÷»úÃûºÅÁî×¢Èë·ì϶£» £»£»£»£»£»£» £»Adobe Photoshop CC¶ÑÒç³öËÁÒâ´úÂëÖ´Ðзì϶£» £»£»£»£»£»£» £»Wifi-soft UniBox controller CVE-2019-3495Ô¶³Ì´úÂëÖ´Ðзì϶¡£¡£¡£¡£ ¡£¡£¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇFacebookÃ÷ÎÄ´æ´¢ÊýÒÚÓû§ÃÜÂ룬£¬£¬£¬£¬£¬£¬±»Ô±¹¤²é¿´900Íò´Î£» £»£»£»£»£»£» £»¹È¸èÒò¸æ°×¢¶ÏÔÙ±»Å·ÃË·£¿£¿£¿£¿£¿£¿î17ÒÚÃÀÔª£» £»£»£»£»£»£» £»Nork Hydro¹«Ë¾Ôâµ½ÀÕË÷Èí¼þLockerGoga¹¥»÷£» £»£»£»£»£»£» £»89£¥µÄÅ·Ã˵±¾ÖÍøÕ¾´æÔÚµÚÈý·½¸æ°×¸ú×پ籾£» £»£»£»£»£»£» £»Epic GamesÍøÂçSteamÓû§ÒþÖÔÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬³Ðŵ½«½øÐн¨¸´¡£¡£¡£¡£ ¡£¡£¡£¡£

ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖС£¡£¡£¡£ ¡£¡£¡£¡£


³ÁÒª°²È«·ì϶Áбí


1. Mozilla Firefox IonMonkey JIT±àÒëÆ÷ÀàÐÍ»ìºÏ·ì϶
Mozilla Firefox IonMonkey JIT±àÒëÆ÷´æÔÚÀàÐÍ»ìºÏ·ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄwebÒªÇ󣬣¬£¬£¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£» £»£»£»£»£»£» £»òÖ´ÐÐËÁÒâ´úÂ룬£¬£¬£¬£¬£¬£¬
https://www.mozilla.org/en-US/security/advisories/mfsa2019-07/

2. Cisco IP Phone 7800/8800 Series sipÔ¶³Ì´úÂëÖ´Ðзì϶
Cisco IP Phone 7800/8800 WEB½Ó¿Ú´¦ÖöñÒâsipÐÂÎÅ´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬¿ÉÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£ ¡£¡£¡£¡£
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190320-ip-phone-rce

3. CUJO Smart Firewall DHCPÖ÷»úÃûºÅÁî×¢Èë·ì϶
CUJO Smart Firewall dhcpÊØ»¤¹ý³Ì´æÔÚÊäÈëÑéÖ¤·ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬¿É×¢ÈëËÁÒâºÅÁî²¢Ö´ÐС£¡£¡£¡£ ¡£¡£¡£¡£
https://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0703

4. Adobe Photoshop CC¶ÑÒç³öËÁÒâ´úÂëÖ´Ðзì϶
Adobe Photoshop CC´¦ÖÃÎļþ´æÔÚ¶ÑÒç¶Âí½Å£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇ󣬣¬£¬£¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£» £»£»£»£»£»£» £»òÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£ ¡£¡£¡£¡£
https://helpx.adobe.com/security/products/photoshop/apsb19-15.html

5. Wifi-soft UniBox controller CVE-2019-3495Ô¶³Ì´úÂëÖ´Ðзì϶
Wifi-soft UniBox controller´æÔÚÔ¶³Ì´úÂë×¢Èë·ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬¿ÉÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£ ¡£¡£¡£¡£
https://packetstormsecurity.com/files/151077/Wifi-soft-Unibox-2.x-Remote-Command-Code-Injection.html

 ³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢FacebookÃ÷ÎÄ´æ´¢ÊýÒÚÓû§ÃÜÂ룬£¬£¬£¬£¬£¬£¬±»Ô±¹¤²é¿´900Íò´Î

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

±¾ÖÜËÄFacebookÈÏ¿ÉÊýÒÔÒڼƵÄFacebookºÍInstagramÓû§µÄÃÜÂë¶àÄêÀ´Ò»ÏòÒÔÃ÷ÎĵĴó¾Ö´æ´¢ÔÚÄÚ²¿Êý¾ÝϵͳÖС£¡£¡£¡£ ¡£¡£¡£¡£FacebookÔÚ1Ô·ݵÄÀýÐа²È«Éó²éÆÚ¼ä·¢ÏÖÁËÕâÒ»ÎÊÌ⣬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾°µÊ¾ÕâЩÊý¾Ý²¢Î´Ôâµ½ÀÄÓᣡ£¡£¡£ ¡£¡£¡£¡£Æ¾¾Ý°²È«¼ÇÕßBrian KrebsµÄÒ»·Ý»ã±¨£¬£¬£¬£¬£¬£¬£¬Ô¼2000Ãû¹¤³Ìʦ»ò¿ª·¢ÈËÔ±¶ÔÕâЩÊý¾Ý½øÐÐÁËԼĪ900Íò´ÎÄÚ²¿²éÎÊ¡£¡£¡£¡£ ¡£¡£¡£¡£FacebookÉÐδÅû¶ÊÜÓ°ÏìµÄ¾ßÌåÓû§ÈËÊý£¬£¬£¬£¬£¬£¬£¬µ«KrebsµÄ»ã±¨ÖгÆÕâÒ»Êý×ÖΪ2ÒÚÖÁ6ÒÚÖ®¼ä¡£¡£¡£¡£ ¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/facebook-employees-could-access-unencrypted-passwords-for-millions-of-users/

2¡¢¹È¸èÒò¸æ°×¢¶ÏÔÙ±»Å·ÃË·£¿£¿£¿£¿£¿£¿î17ÒÚÃÀÔª


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


3ÔÂ20ÈÕÅ·ÃËίԱ»á°ä²¼ÉêÃ÷¶Ô¹È¸èµÄ¸æ°×¢¶ÏÐÐΪ·£¿£¿£¿£¿£¿£¿î14.9ÒÚÅ·Ôª£¨Ô¼17ÒÚÃÀÔª£©£¬£¬£¬£¬£¬£¬£¬ÕâÊÇÁ½ÄêÄÚÅ·Ã˶Թȸ迪³öµÄµÚÈýÕÅ´ó¶î·´Â¢¶Ï·£µ¥¡£¡£¡£¡£ ¡£¡£¡£¡£Å·ÃËίԱ»á°µÊ¾ÕâÒ»·£¿£¿£¿£¿£¿£¿îµÄÔ­ÒòÊǹȸèÀÄÓÃÆäÊг¡Ö÷µ¼Ö°Î»£¬£¬£¬£¬£¬£¬£¬×èÖ¹ÍøÒ³Ê¹ÓÃAdSenseƽ̨ÒÔ±íµÄ¸æ°×·þÎñ£¬£¬£¬£¬£¬£¬£¬ÕâÒ»·£½ðÏ൱Óڹȸè2018Äê½»Ò×¶îµÄ1.29%¡£¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/google-fined-17-billion-for-anti-competitive-practices-in-online-advertising/

3¡¢Nork Hydro¹«Ë¾Ôâµ½ÀÕË÷Èí¼þLockerGoga¹¥»÷


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


±¾ÖÜÒ»£¨3ÔÂ18ÈÕ£©Íí¼äŲÍþÂÁÒµ¾ÞÍ·Norsk HydroÔâµ½´ó¹æÄ£ÍøÂç¹¥»÷£¬£¬£¬£¬£¬£¬£¬¼¸¼Ò¹¤³§±»Ò»Ê±¹Ø¹Ø¡£¡£¡£¡£ ¡£¡£¡£¡£ÔÚÐÂÎŰ䲼»áÉÏ£¬£¬£¬£¬£¬£¬£¬Norsk HydroÊ×ϯ²ÆÕþ¹ÙEivind Kallevikй©¸Ã¹«Ë¾Ôâµ½½ÏеÄÀÕË÷Èí¼þLockerGogaµÄ¹¥»÷£¬£¬£¬£¬£¬£¬£¬Æä³ö²ú¼°ÔËÓª¾ùÊܵ½Ó°Ïì¡£¡£¡£¡£ ¡£¡£¡£¡£¸Ã¹«Ë¾±»ÆÈÔÚŲÍþ¡¢¿¨Ëþ¶ûºÍ°ÍÎ÷µÈ¹ú¶ÈÇл»ÖÁÈËΪ²Ù×÷£¬£¬£¬£¬£¬£¬£¬ÒÔ¸´Ô­ÆäÔËÓª»î¶¯¡£¡£¡£¡£ ¡£¡£¡£¡£Kallevik»¹°µÊ¾¸Ã¹«Ë¾ÒѾ­¿ÉÄÜ´¦ÖÃËùÓпͻ§µÄ¶©µ¥²¢½»¸¶£¬£¬£¬£¬£¬£¬£¬µ«½«À´µÄ¶©µ¥¿ÉÄÜ»áÊܵ½Ó°Ï죬£¬£¬£¬£¬£¬£¬ÓÉÓÚ¹«Ë¾ÍøÂçÈÔδ¸´Ô­¡£¡£¡£¡£ ¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/lockergoga-ransomware-sends-norsk-hydro-into-manual-mode/

4¡¢89£¥µÄÅ·Ã˵±¾ÖÍøÕ¾´æÔÚµÚÈý·½¸æ°×¸ú×پ籾


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


µ¤Âóä¯ÀÀÆ÷·ÖÎö¹«Ë¾CookiebotÔÚ25¸öÅ·Ã˳ÉÔ±¹úÈ·µ±¾Ö¹ÙÍøÉÏ·¢ÏÖ¸æ°×¸ú×پ籾£¬£¬£¬£¬£¬£¬£¬Õâ»òÐíÕ¼×ܹ²28¸ö³ÉÔ±¹úµÄ89%£¬£¬£¬£¬£¬£¬£¬Ö»Óе¹ú¡¢Î÷°àÑÀºÍºÉÀ¼È·µ±¾ÖÍøÕ¾Ã»ÓÐóÒ׸æ°×¸ú×ÙÆ÷¡£¡£¡£¡£ ¡£¡£¡£¡£·¨¹úµ±¾ÖÍøÕ¾Éϵĸæ°×¸ú×ÙÆ÷×î¶à£¬£¬£¬£¬£¬£¬£¬ÓÐ52¼Ò·ÖÆçµÄ¹«Ë¾ÔÚ¸ú×ÙÓû§µÄÐÐΪ¡£¡£¡£¡£ ¡£¡£¡£¡£ÕâЩ¸æ°×¸ú×ÙÆ÷ÖØÒªÊÇÔÚµÚÈý·½²å¼þµÄÔ®ÊÖÏÂÉøÈë½øµ±¾ÖÍøÕ¾£¬£¬£¬£¬£¬£¬£¬ÀýÈçÊÓÆµ²¥·ÅÆ÷²å¼þ¡¢ÍøÕ¾·ÖÎö¼°Í¼±í²å¼þµÈ¡£¡£¡£¡£ ¡£¡£¡£¡£ÕâÏÔȻΥ·´ÁËÅ·Ã˵ÄÊý¾Ý±£» £»£»£»£»£»£» £»¤ÂÉÀýGDPR¡£¡£¡£¡£ ¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/89-percent-of-eu-government-sites-infiltrated-by-ad-tracking-scripts/

5¡¢Epic GamesÍøÂçSteamÓû§ÒþÖÔÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬³Ðŵ½«½øÐн¨¸´


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Epic GamesÕë¶Ô¶àÏî¼Óº¦Óû§ÒþÖÔµÄÖ¸¿Ø×ö³ö»ØÓ¦£¬£¬£¬£¬£¬£¬£¬²¢³Ðŵ¶Ô¸ÃÎÊÌâ½øÐн¨¸´¡£¡£¡£¡£ ¡£¡£¡£¡£ÓÎÏ·Íæ¼ÒÔÚRedditÉÏ·¢Ìû³Æ£¬£¬£¬£¬£¬£¬£¬Epic Games LauncherÔÚδ¾­Óû§Ðí¿ÉµÄÇé¿öÏÂɨÃè²¢ÍøÂçÓû§µÄSteamÐÅÏ¢¡£¡£¡£¡£ ¡£¡£¡£¡£Epic Games¹¤³Ì¸±×ܲÃDaniel Vogel»ØÓ¦³ÆEpic Games Store¿Í»§¶Ë´´½¨ÁËSteamÎļþlocalconfig.vdfµÄ±¾µØ¼ÓÃܸ±±¾£¬£¬£¬£¬£¬£¬£¬µ±Óû§Ñ¡Ôñµ¼ÈëSteamÁªÏµÈËʱ£¬£¬£¬£¬£¬£¬£¬½«»á°ÑÓû§µÄÁªÏµÈ˹þÏ£ID·¢ËÍ»ØEpic¡£¡£¡£¡£ ¡£¡£¡£¡£Epic Games CEO Tim Sweeney°µÊ¾½«¶ÔÓÐÕùÒéµÄÓû§Êý¾ÝÍøÂçÐÐΪ½øÐн¨¸´¡£¡£¡£¡£ ¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/epic-promises-to-fix-game-launcher-after-privacy-concerns/

ÉêÃ÷£º±¾×ÊѶÓÉ8827Ì«Ñô¼¯ÍÅάËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù