ÐÅÏ¢°²È«Öܱ¨-2019ÄêµÚ38ÖÜ

°ä²¼¹¦·ò 2019-09-30

±¾Öܰ²È«Ì¬ÊÆ×ÛÊö



2019Äê9ÔÂ23ÈÕÖÁ29ÈÕ¹²ÊÕ¼°²È«·ì϶43¸ö£¬£¬£¬£¬£¬ £¬£¬ £¬ÖµµÃ¹Ø×¢µÄÊÇRIOT MQTT-SN CVE-2019-16754¿ÕÖ¸Õë¼ä½ÓÒýÓ÷ì϶; vBulletin widgetConfig[code]Ô¶³Ì´úÂëÖ´Ðзì϶ £»£»£» £»£»Adobe ColdFusionËÁÒâ´úÂëÖ´Ðзì϶ £»£»£» £»£»Microsoft Internet ExplorerÄÚ´æ¶ÔÏó´¦ÖÃÔ¶³Ì´úÂëÖ´Ðзì϶ £»£»£» £»£»phpstudyºóÃÅÖ²Èë·ì϶¡£ ¡£¡£¡£¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇTescoÍ£³µÀûÓôæÔÚ·ì϶µ¼ÖÂÊýǧÍò³µÅÆÍ¼Ïñй¶ £»£»£» £»£»Î¢Èí´¹Î£½¨¸´IEÖеÄRCE 0day¼°DefenderÖеÄDoS·ì϶ £»£»£» £»£»¾Ýͳ¼Æ2019ÄêÃÀ¹úÒÑÓжà´ï500ËùѧÌÃÔâÀÕË÷Èí¼þ¹¥»÷ £»£»£» £»£»iOS 13ºÍiPadOS·ì϶¿Éµ¼ÖµÚÈý·½¼üÅÌ»ñÈ¡ÆëÈ«½Ó¼ûȨÏÞ £»£»£» £»£»iOS·ì϶Checkm8¿Éµ¼ÖÂiPhone4µ½XÓÀÔ¶Ô½Óü¡£ ¡£¡£¡£¡£¡£¡£¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬ £¬£¬ £¬±¾Öܰ²È«ÍþвΪÖС£ ¡£¡£¡£¡£¡£¡£¡£



³ÁÒª°²È«·ì϶Áбí



1. RIOT MQTT-SN CVE-2019-16754¿ÕÖ¸Õë¼ä½ÓÒýÓ÷ì϶
RIOT MQTT-SNʵÏÖ´æÔÚ¿ÕÖ¸ÕëÒýÓ÷ì϶£¬£¬£¬£¬£¬ £¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬ £¬£¬ £¬¿Éʹϵͳ±ÀÀ£¡£ ¡£¡£¡£¡£¡£¡£¡£
https://github.com/RIOT-OS/RIOT/pull/12293

2. vBulletin widgetConfig[code]Ô¶³Ì´úÂëÖ´Ðзì϶
vBulletin ajax/render/widget_php routestring´¦ÖÃwidgetConfig[code]´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬ £¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬ £¬£¬ £¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâºÅÁî¡£ ¡£¡£¡£¡£¡£¡£¡£
https://seclists.org/fulldisclosure/2019/Sep/31

3. Adobe ColdFusionËÁÒâ´úÂëÖ´Ðзì϶
Adobe ColdFusionij×é¼þ´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬ £¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬ £¬£¬ £¬¿É×¢ÈëËÁÒâºÅÁî²¢Ö´ÐС£ ¡£¡£¡£¡£¡£¡£¡£
https://helpx.adobe.com/security/products/coldfusion/apsb19-47.html

4. Microsoft Internet ExplorerÄÚ´æ¶ÔÏó´¦ÖÃÔ¶³Ì´úÂëÖ´Ðзì϶
Microsoft Internet Explorer´¦ÖÃÄÚ´æ¶ÔÏó´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬ £¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄWEBÒªÇ󣬣¬£¬£¬£¬ £¬£¬ £¬ÓÕʹÓû§½âÎö£¬£¬£¬£¬£¬ £¬£¬ £¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ £»£»£» £»£»òÖ´ÐÐËÁÒâ´úÂë¡£ ¡£¡£¡£¡£¡£¡£¡£
https://support.microsoft.com/zh-cn/help/4522007/cumulative-security-update-for-internet-explorer

5. phpstudyºóÃÅÖ²Èë·ì϶
phpstudy±»×¢ÈëºóÃÅ£¬£¬£¬£¬£¬ £¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬ £¬£¬ £¬½ÚÔìÖ¸±êÀûÓÃϵͳ¡£ ¡£¡£¡£¡£¡£¡£¡£
https://www.xp.cn/


 ³ÁÒª°²È«ÊÂÎñ×ÛÊö



1¡¢TescoÍ£³µÀûÓôæÔÚ·ì϶µ¼ÖÂÊýǧÍò³µÅÆÍ¼Ïñй¶

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ÔÚ±íýThe Register±¨Â·ÊýǧÍòÕÅANPR£¨³µÅÆ×Ô¶¯¼ø±ð£©Í¼ÏñÔÚMicrosoft AzureÖж³öÖ®ºó£¬£¬£¬£¬£¬ £¬£¬ £¬TescoÒÑ¹Ø¹ØÆäÍ£³µÑéÖ¤WebÀûÓᣠ¡£¡£¡£¡£¡£¡£¡£ÕâЩͼÏñÓÉÓ¢¹ú¸÷µØµÄ19¸öTescoÍ£³µ³¡ËùÅÄÉãµÄ½øÈëºÍÍÑÀëµÄÆû³µÕÕÆ¬×é³É£¬£¬£¬£¬£¬ £¬£¬ £¬ÕÕÆ¬ÖÐ͹ÆðÏÔʾÁËÆû³µµÄ³µÅÆ£¬£¬£¬£¬£¬ £¬£¬ £¬¹ÌÈ»ÓÉÓÚ·Ö±æÂʽϵͶø¿´²»µ½¼ÝʻԱ¡£ ¡£¡£¡£¡£¡£¡£¡£ANPRͼÏñÒÔ´øÓй¦·ò´ÁµÄjpegÌåʽ±£ÁôÔÚAzure blobÖУ¬£¬£¬£¬£¬ £¬£¬ £¬²¢ÇÒͼÏñÎļþÃûÒ²Ô̺¬¹¦·òÐÅÏ¢£¬£¬£¬£¬£¬ £¬£¬ £¬´Ó¶øÊ¹µÃÈκÎÕýÈ·´§¶È³öËùÐèHTTP POSTÒªÇóÌåʽµÄÈËÄܹ»ÅúÁ¿»ñÈ¡ÕâЩͼÏñÒÔ¹©·¸·¨Ê¹Óᣠ¡£¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.theregister.co.uk/2019/09/20/tesco_parking_app_10s_millions_anpr_photos_exposed/

2¡¢Î¢Èí´¹Î£½¨¸´IEÖеÄRCE 0day¼°DefenderÖеÄDoS·ì϶


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


΢Èí°ä²¼´¹Î£°²È«¸üУ¬£¬£¬£¬£¬ £¬£¬ £¬½¨¸´IEÖеÄRCE 0day¼°Windows DefenderÖеÄDoS·ì϶¡£ ¡£¡£¡£¡£¡£¡£¡£ÆäÖÐIE 0dayΪ¹È¸è×êÑÐÈËÔ±Cl¨¦mentLecigne·¢Ïֵľ籾ÒýÇæÄÚ´æ°Ü»µ·ì϶£¨CVE-2019-1367£©£¬£¬£¬£¬£¬ £¬£¬ £¬¹¥»÷Õß¿ÉÀûÓø÷ì϶ÔÚµ±Ç°Óû§µÄ¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂë¡£ ¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶Äܹ»Í¨¹ý½«Ö¸±êÓû§³Á¶¨ÏòÖÁ¶ñÒâÍøÕ¾À´ÀûÓ㬣¬£¬£¬£¬ £¬£¬ £¬ÊÜÓ°ÏìµÄ°æ±¾Ô̺¬IE9¡¢10ºÍ11¡£ ¡£¡£¡£¡£¡£¡£¡£ÁíÒ»¸ö·ì϶ÊÇWindows DefenderÖеĻؾø·þÎñ·ì϶£¨CVE-2019-1255£©£¬£¬£¬£¬£¬ £¬£¬ £¬¸Ã·ì϶ÓëDefender´¦ÖÃÎļþµÄ·½Ê½ÓйØ£¬£¬£¬£¬£¬ £¬£¬ £¬¹¥»÷Õß¿ÉÀûÓø÷ì϶×èÖ¹ºÏ·¨ÕË»§Ö´ÐкϷ¨µÄϵͳÎļþ¡£ ¡£¡£¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄDefender°æ±¾Îª1.1.16300.1£¬£¬£¬£¬£¬ £¬£¬ £¬²¢ÒÑÔÚ1.1.16400.2Öн¨¸´¡£ ¡£¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.zdnet.com/article/microsoft-releases-out-of-band-security-update-to-fix-ie-zero-day-defender-bug/

3¡¢¾Ýͳ¼Æ2019ÄêÃÀ¹úÒÑÓжà´ï500ËùѧÌÃÔâÀÕË÷Èí¼þ¹¥»÷


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ƾ¾ÝÔÆ°²È«¹«Ë¾ArmorµÄµ÷ÑУ¬£¬£¬£¬£¬ £¬£¬ £¬ÃÀ¹úÒÑÓÐ49¸öÑ§ÇøµÄ½ÌÓý»ú¹¹Ôâµ½ÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬ £¬£¬ £¬Ê¹µÃ½ÌÓýÐÐÒµ³ÉΪ½ö´ÎÓÚ´¦Ëùµ±¾ÖµÄµÚ¶þ´óÒ×Êܹ¥»÷Ö¸±ê¡£ ¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾·ÖÎöÁË×Ô2019Äê1ÔÂÒÔÀ´¹«¿ª±¨Â·µÄ¹¥»÷£¬£¬£¬£¬£¬ £¬£¬ £¬·¢´Ë¿Ì2019Äêǰ9¸öÔÂÒÑÓжà´ï500ËùK-12ѧÌÃÔâµ½¹¥»÷£¬£¬£¬£¬£¬ £¬£¬ £¬¶øÈ¥ÄêÖ»ÓÐ11ËùѧÌᣠ¡£¡£¡£¡£¡£¡£¡£½öÔÚ9ÔÂÖÐÑ®µÄÒ»Öܶ๦·òÀï¾ÍÓÐ9¸öÐÂÑ§ÇøºÍ1Ëù´óѧÊܵ½¹¥»÷£¬£¬£¬£¬£¬ £¬£¬ £¬²¨¼°Ô¼100ËùK-12ѧÌᣠ¡£¡£¡£¡£¡£¡£¡£¿£¿ £¿£¿£¿£¿£¿£¿µÄùµÒ¸ñÖݵÄÑ§ÇøÊܵ½µÄÍþв×îΪÑϳÁ£¬£¬£¬£¬£¬ £¬£¬ £¬¸ÃÖݹ²Ôâ·êÁË7´Î¹¥»÷£¬£¬£¬£¬£¬ £¬£¬ £¬º­¸Ç104ËùѧÌᣠ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/hundreds-of-us-schools-hit-by/

4¡¢iOS 13ºÍiPadOS·ì϶¿Éµ¼ÖµÚÈý·½¼üÅÌ»ñÈ¡ÆëÈ«½Ó¼ûȨÏÞ

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Æ»¹û¹Ù·½°ä²¼ÁËÒ»·ÝеÄÖ§³ÖÎĵµ£¬£¬£¬£¬£¬ £¬£¬ £¬ÖÒ¸æÓû§ÓйØiOS 13ºÍiPadOSµÚÈý·½¼üÅÌ´æÔڵݲȫ·ì϶¡£ ¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾°µÊ¾£¬£¬£¬£¬£¬ £¬£¬ £¬Ò»Ð©µÚÈý·½¼üÅÌÈí¼þ¼´±ãδ±»ºË×¼ÆëÈ«½Ó¼ûȨÏÞÒ²¿ÉÄÜ»áÓÉÓÚiOS 13ºÍiPadOSÖеķì϶¶ø±»ÊÚÓèÆëÈ«½Ó¼ûȨÏÞ¡£ ¡£¡£¡£¡£¡£¡£¡£ÕâÒ»ÎÊÌâÓ°ÏìÁËiPhone¡¢iPad»òiPod touch×°ÖõļüÅÌ£¬£¬£¬£¬£¬ £¬£¬ £¬µ«²»Ó°ÏìÆ»¹ûµÄÄÚÖüüÅÌ£¬£¬£¬£¬£¬ £¬£¬ £¬Ò²²»»áÓ°ÏìδÀûÓÃÆëÈ«½Ó¼ûȨÏ޵ĵÚÈý·½¼üÅÌ£¬£¬£¬£¬£¬ £¬£¬ £¬Æ»¹û½«ÔÚ¼´½«µ½À´µÄÈí¼þ¸üÐÂÖн¨¸´´Ë·ì϶¡£ ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/bug-granting-full-access-keyboards/148638/

5¡¢iOS·ì϶Checkm8¿Éµ¼ÖÂiPhone4µ½XÓÀÔ¶Ô½Óü


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


°²È«×êÑÐÔ±axi0mXÅû¶iOSÖеݲȫ·ì϶checkm8£¬£¬£¬£¬£¬ £¬£¬ £¬¸Ã·ì϶Äܹ»Ê¹iPhone4S£¨A5оƬ£©µ½iPhone8¡¢iPhoneX£¨A11оƬ£©µÄËùÓÐÆ»¹ûÊÖ»ú¼°Í¬¿îAϵÁд¦ÖÃÆ÷µÄiPad¡¢iPod touchµÈiOSÉ豸ÓÀÔ¶Ô½Óü¡£ ¡£¡£¡£¡£¡£¡£¡£Ã»ÓÐÌáµ½×îеÄA12ºÍA13ÊÇ·ñÊܵ½Ó°Ïì¡£ ¡£¡£¡£¡£¡£¡£¡£¸Ã¹¥»÷ÀûÓÃÁËbootrom·ì϶£¬£¬£¬£¬£¬ £¬£¬ £¬¼´´æ´¢ÁËiPhoneÆô¶¯Ö¸ÁîµÄÖ»¶Á´æ´¢Æ÷£¨ROM£©·ì϶£¬£¬£¬£¬£¬ £¬£¬ £¬ÓÉÓڸò¿ÃÅÄÚ´æÊÇÖ»¶ÁµÄ£¬£¬£¬£¬£¬ £¬£¬ £¬Òò¶øÎÞ·¨Í¨¹ý°²È«¸üÐÂÀ´½¨¸´·ì϶¡£ ¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±ÔÚGithubÉϰ䲼ÁËÓйطì϶ÀûÓ㬣¬£¬£¬£¬ £¬£¬ £¬µ«ÉÐÎÞ¹«¿ª¿ÉÓõÄÔ½Óü·¨Ê½¡£ ¡£¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://threatpost.com/ios-exploit-checkm8-could-allow-permanent-iphone-jailbreaks/148762/