ÐÅÏ¢Çå¾²Öܱ¨-2018ÄêµÚ34ÖÜ

Ðû²¼Ê±¼ä 2018-08-27

Ò»¡¢±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


        2018Äê08ÔÂ20ÈÕÖÁ26ÈÕ¹²ÊÕ¼Çå¾²Îó²î51¸ö £¬£¬£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇApache Struts 2 CVE-2018-11776´úÂëÖ´ÐÐÎó²î£»£» £»£»£»£»£»£»Adobe Photoshop CC CVE-2018-12811ÄÚ´æÆÆËðÎó²î£»£» £»£»£»£»£»£»Philips IntelliSpace CardiovascularÉèÖÃÖÎÀíȨÏÞÌáÉýÎó²î£»£» £»£»£»£»£»£»SambaĿ¼ÁÐ±í³¤Îļþ¼ì²é´úÂëÖ´ÐÐÎó²î£»£» £»£»£»£»£»£»Emerson Electric DeltaV CVE-2018-14793»º³åÇøÒç³öÎó²î¡£¡£¡£¡£¡£


        ±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇÑо¿ÍŶӷ¢Ã÷³¯ÏÊAPT×éÖ¯DarkhotelʹÓÃVBScript¾ç±¾ÒýÇæ0dayµÄ¹¥»÷»î¶¯£»£» £»£»£»£»£»£»Ñо¿Åú×¢GDPRʵÑéºóÅ·ÃËÐÂÎÅÍøÕ¾ÉϵĵÚÈý·½cookieÊýĿϽµÁË22%£»£» £»£»£»£»£»£»ÃÀAugustaÒ½ÁÆÖÐÐÄÈ·ÈÏ2017Äê9ÔÂÔ¼41.7Íò»¼ÕßµÄÐÅϢй¶£»£» £»£»£»£»£»£»±£Ä·Ð§ÀÍSitterÒòMongoDBÉèÖùýʧµ¼ÖÂÁè¼Ý9.3ÍòÓû§µÄÐÅϢй¶£»£» £»£»£»£»£»£»Cheddar Scratch KitchenÔâºÚ¿ÍÈëÇÖ £¬£¬£¬£¬£¬£¬£¬£¬Ô¼56ÍòÓû§µÄÒøÐп¨ÐÅϢй¶¡£¡£¡£¡£¡£


        ƾ֤ÒÔÉÏ×ÛÊö £¬£¬£¬£¬£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£¡£


 


¶þ¡¢Ö÷ÒªÇå¾²Îó²îÁбí


1¡¢Apache Struts 2 CVE-2018-11776´úÂëÖ´ÐÐÎó²î


        Apache Struts½ç˵XMLÉèÖÃnamespaceֵΪͨÅä·û(¡°/*¡±) £¬£¬£¬£¬£¬£¬£¬£¬»òÔÚÉϲãactionÖÐnamespaceֵȱʡʱ £¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó £¬£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£


        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://cwiki.apache.org/confluence/display/WW/S2-057
2¡¢Adobe Photoshop CC CVE-2018-12811ÄÚ´æÆÆËðÎó²î


        Adobe Photoshop CC´¦Öóͷ£Îļþ±£´æÄÚ´æÆÆËðÎó²î £¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþÇëÇó £¬£¬£¬£¬£¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö £¬£¬£¬£¬£¬£¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£» £»£»£»£»£»£»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£


        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://helpx.adobe.com/security/products/photoshop/apsb18-28.html


3¡¢Philips IntelliSpace CardiovascularÉèÖÃÖÎÀíȨÏÞÌáÉýÎó²î


        Philips IntelliSpace CardiovascularûÓоÙÐÐ׼ȷµÄȨÏÞÖÎÀí £¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó £¬£¬£¬£¬£¬£¬£¬£¬ÌáÉýȨÏÞ¡£¡£¡£¡£¡£


        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://ics-cert.us-cert.gov/advisories/ICSMA-18-226-01
4¡¢SambaĿ¼ÁÐ±í³¤Îļþ¼ì²é´úÂëÖ´ÐÐÎó²î


        samba¿Í»§¶ËûÓгä·ÖµÄ¼ì²âĿ¼ÁбíÖйý³¤µÄÎļþÃû £¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄ¶ñÒâSAMBAЧÀÍÆ÷ÇëÇó £¬£¬£¬£¬£¬£¬£¬£¬Ö´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£


        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://www.samba.org/samba/security/CVE-2018-10858.html


5¡¢Emerson Electric DeltaV CVE-2018-14793»º³åÇøÒç³öÎó²î


        Emerson Electric DeltaV±£´æ»ùÓÚÕ»µÄ»º³åÇøÒç³öÎó²î £¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó £¬£¬£¬£¬£¬£¬£¬£¬Ö´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£


        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://ics-cert.us-cert.gov/advisories/ICSA-18-228-01


 


Èý¡¢Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢Ñо¿ÍŶӷ¢Ã÷³¯ÏÊAPT×éÖ¯DarkhotelʹÓÃVBScript¾ç±¾ÒýÇæ0dayµÄ¹¥»÷»î¶¯ 



MG±ùÇòÍ»ÆÆÊÔÍæ--ÊÖ»ú°æapp¹ÙÍø


        Ç÷ÊÆ¿Æ¼¼µÄÇå¾²Ñо¿ÍŶӷ¢Ã÷³¯ÏÊAPT×éÖ¯DarkhotelÕýÔÚʹÓÃ΢ÈíVBScript¾ç±¾ÒýÇæÖеÄÁãÈÕÎó²î£¨CVE-2018-8373£©Ìᳫ¹¥»÷»î¶¯ £¬£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²îÊÇÒ»¸öuse-after-freeÎó²î £¬£¬£¬£¬£¬£¬£¬£¬¿ÉÔÊÐí¹¥»÷ÕßÔÚÄ¿µÄÅÌËã»úÉÏÔËÐÐshellcode¡£¡£¡£¡£¡£ÔÚ×îа汾µÄWindowsÖÐ £¬£¬£¬£¬£¬£¬£¬£¬Î¢ÈíÔÚä¯ÀÀÆ÷µÄĬÈÏÉèÖÃÖнûÓÃÁËVBScript £¬£¬£¬£¬£¬£¬£¬£¬Ê¹Æä²»Ò×Êܵ½¹¥»÷¡£¡£¡£¡£¡£Î¢ÈíÒÑÔÚ8ÔÂÇå¾²¸üÐÂÖÐÐÞ¸´ÁË´ËÎó²î¡£¡£¡£¡£¡£


        Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/zero-day-in-microsofts-vbscript-engine-used-by-darkhotel-apt/


2¡¢Ñо¿Åú×¢GDPRʵÑéºóÅ·ÃËÐÂÎÅÍøÕ¾ÉϵĵÚÈý·½cookieÊýĿϽµÁË22%



MG±ùÇòÍ»ÆÆÊÔÍæ--ÊÖ»ú°æapp¹ÙÍø



        ƾ֤ţ½ò´óѧReuters InstituteµÄÒ»·Ý±¨¸æ £¬£¬£¬£¬£¬£¬£¬£¬Å·ÃËÐÂÎÅÍøÕ¾ÉϵĵÚÈý·½cookieµÄÊýÄ¿ÔÚGDPRʵÑéºóϽµÁË22%¡£¡£¡£¡£¡£¸Ã±¨¸æ»®·ÖÆÊÎöÁË2018Äê4ÔÂÒÔ¼°7ÔµÄÊý¾Ý £¬£¬£¬£¬£¬£¬£¬£¬º­¸ÇÁË·ÒÀ¼¡¢·¨¹ú¡¢µÂ¹ú¡¢Òâ´óÀû¡¢²¨À¼¡¢Î÷°àÑÀºÍÓ¢¹úÆß¸ö¹ú¼ÒµÄ200¸öÐÂÎÅÍøÕ¾¡£¡£¡£¡£¡£Ï½µ·ù¶È×î´óµÄÊÇÓ¢¹ú £¬£¬£¬£¬£¬£¬£¬£¬ÆäÐÂÎÅÍøÕ¾Ê¹Óõĸú×Ùcookie±ÈGDPRʵÑéǰïÔÌ­ÁË45%¡£¡£¡£¡£¡£Ï½µ·ù¶È×îСµÄÊǵ¹ú £¬£¬£¬£¬£¬£¬£¬£¬Îª6%¡£¡£¡£¡£¡£¶ø²¨À¼ÔòÊÇΨÖðÒ»¸öcookieÊýÄ¿ÔöÌíµÄ¹ú¼Ò £¬£¬£¬£¬£¬£¬£¬£¬ÔöÌí·ù¶ÈΪ20%¡£¡£¡£¡£¡£


        Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/technology/number-of-third-party-cookies-on-eu-news-sites-dropped-by-22-percent-post-gdpr/


3¡¢ÃÀAugustaÒ½ÁÆÖÐÐÄÈ·ÈÏ2017Äê9ÔÂÔ¼41.7Íò»¼ÕßµÄÐÅϢй¶



MG±ùÇòÍ»ÆÆÊÔÍæ--ÊÖ»ú°æapp¹ÙÍø


        ÃÀ¹úAugustaÒ½ÁÆÖÐÐÄ7ÔÂ31ÈÕµÄÊÓ²ìЧ¹ûÏÔʾ £¬£¬£¬£¬£¬£¬£¬£¬2017Äê9ÔÂÕë¶ÔÆäÒ½ÁÆÊÂÇéÖ°Ô±µÄÍøÂç´¹ÂÚ¹¥»÷µ¼ÖÂÔ¼41.7Íò»¼ÕßµÄÊý¾Ý±»ÇÔ¡£¡£¡£¡£¡£Ð¹Â¶µÄÊý¾Ý°üÀ¨µØµã¡¢³öÉúÈÕÆÚ¡¢Ò½ÁƼͼ±àºÅ¡¢ÖÎÁƺÍÊÖÊõÐÅÏ¢¡¢Õï¶ÏЧ¹û¡¢Ò©ÎïÒÔ¼°°ü¹ÜÐÅÏ¢µÈ £¬£¬£¬£¬£¬£¬£¬£¬ÉõÖÁ°üÀ¨²¿·Ö»¼ÕßµÄÉç±£ºÅÂëºÍ¼ÝÕÕºÅÂë¡£¡£¡£¡£¡£ÕâЩÐÅÏ¢¿ÉÄܻᱻºóÐøµÄÍøÂç´¹ÂÚ¹¥»÷¡¢Éí·Ýڲƭ»î¶¯ÉõÖÁÀÕË÷»î¶¯ËùʹÓᣡ£¡£¡£¡£


        Ô­ÎÄÁ´½Ó£ºhttps://www.infosecurity-magazine.com/news/augusta-health-center-reveals/


4¡¢±£Ä·Ð§ÀÍSitterÒòMongoDBÉèÖùýʧµ¼ÖÂÁè¼Ý9.3ÍòÓû§µÄÐÅϢй¶



MG±ùÇòÍ»ÆÆÊÔÍæ--ÊÖ»ú°æapp¹ÙÍø



        8ÔÂ14ÈÕÇå¾²Ñо¿Ö°Ô±Bob Diachenko·¢Ã÷±£Ä·Ð§ÀÍSitterµÄÒ»¸öMongoDB¿Éͨ¹ý»¥ÁªÍø¹ûÕæ»á¼û£¨ÎÞÐèµÇ¼ƾ֤£© £¬£¬£¬£¬£¬£¬£¬£¬Áè¼Ý9.3ÍòÃûÓû§µÄÃô¸ÐÊý¾Ýй¶¡£¡£¡£¡£¡£Ð¹Â¶µÄÊý¾Ý°üÀ¨ÕË»§µÄÃÜÂë¹þÏ£¡¢Ã¿¸ö¼ÒÍ¥µÄº¢×ÓÊý¡¢¼ÒÍ¥µØµã¡¢µç»°ºÅÂë¡¢ÁªÏµÈËÁÐ±í¡¢Ö§¸¶¿¨ºÅÒÔ¼°appÄÚµÄ̸ÌìÐÅÏ¢µÈ¡£¡£¡£¡£¡£Êý¾Ý×ÜÁ¿Áè¼Ý2GB¡£¡£¡£¡£¡£


        Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/mongodb-server-exposes-babysitting-apps-database/


5¡¢Cheddar Scratch KitchenÔâºÚ¿ÍÈëÇÖ £¬£¬£¬£¬£¬£¬£¬£¬Ô¼56ÍòÓû§µÄÒøÐп¨ÐÅϢй¶
MG±ùÇòÍ»ÆÆÊÔÍæ--ÊÖ»ú°æapp¹ÙÍø



        Cheddar Scratch KitchenÓÚ2018Äê8ÔÂ16ÈÕÊÕµ½Áª°îÕþ¸®µÄÖÒÑÔ £¬£¬£¬£¬£¬£¬£¬£¬³ÆÆäPoSϵͳÔâµ½ºÚ¿ÍÈëÇÖ¡£¡£¡£¡£¡£ÏÖÔÚÔÚ°µÍøÉÏÏúÊÛµÄÏà¹ØÒøÐп¨ÐÅϢԼΪ56.7ÍòÕÅ¡£¡£¡£¡£¡£ÊÓ²ìÅú×¢ £¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÔøÓÚ2017Äê11ÔÂ3ÈÕÖÁ2018Äê1ÔÂ2ÈÕʱ´úÈëÇÖÁ˸ù«Ë¾µÄÍøÂç¡£¡£¡£¡£¡£¸Ã¹«Ë¾³Æ2018Äê4ÔÂ10ÈÕÒÔÀ´ÆäÒÑʹÓÃÁËеÄPoSϵͳ £¬£¬£¬£¬£¬£¬£¬£¬ÕâÒâζ×ÅÄ¿½ñµÄÖ§¸¶ÏµÍ³ºÍÍøÂç²»ÊÜÓ°Ïì¡£¡£¡£¡£¡£Cheddar Scratch KitchenÔÚ23¸öÖݶ¼ÓÐ·Öµê £¬£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÕýÔÚÏòÊÜÓ°ÏìµÄÓû§ÌṩÃâ·ÑµÄÉí·Ý±£»£» £»£»£»£»£»£»¤Ð§ÀÍ¡£¡£¡£¡£¡£


        Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/cheddar-scratch-kitchen-exposes-card-data-of-over-500-000/