Firefox½ôÆÈÐÞ¸´RCE 0day£¨CVE-2019-11707£©£»£»£»£»TP-Link Wi-FiÖÐ¼ÌÆ÷RCEÎó²î

Ðû²¼Ê±¼ä 2019-06-19

¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20190619



1¡¢Firefox½ôÆÈÐÞ¸´RCE 0day£¨CVE-2019-11707£©

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨
 
MozillaÐû²¼Firefox 67.0.3ºÍFirefox ESR 60.7.1£¬£¬£¬£¬£¬£¬£¬ÓÃÓÚ½ôÆÈÐÞ¸´¿Éµ¼ÖÂRCEµÄ0day£¨CVE-2019-11707£©¡£ ¡£¡£¡£¡£¡£¸ÃÎó²îÓÉGoogle Project ZeroÍŶӷ¢Ã÷²¢±¨¸æ£¬£¬£¬£¬£¬£¬£¬ÊÇÒ»¸öÀàÐÍ»ìÏýÎó²î£¬£¬£¬£¬£¬£¬£¬Îó²î±íÊöΪ£ºÓÉÓÚArray.popÖеÄÎÊÌ⣬£¬£¬£¬£¬£¬£¬²Ù×÷JavaScript¹¤¾ßʱ¿ÉÄܻᴥ·¢Îó²î£¬£¬£¬£¬£¬£¬£¬µ¼Ö¿ÉʹÓõÄÍ߽⡣ ¡£¡£¡£¡£¡£¸ÃÎó²îÒÑÔÚÒ°ÍⱻʹÓ㬣¬£¬£¬£¬£¬£¬½¨ÒéÓû§¾¡¿ì¸üС£ ¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/mozilla-firefox-6703-patches-actively-exploited-zero-day/


2¡¢TP-Link Wi-FiÖÐ¼ÌÆ÷RCEÎó²î£¬£¬£¬£¬£¬£¬£¬Ó°Ïì¶à¸öÐͺÅ

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨
 
IBM X-ForceÑо¿Ô±Grzegorz WypychmembersÅû¶TP-Link Wi-Fi Extender£¨ÖÐ¼ÌÆ÷£©ÖеÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£ ¡£¡£¡£¡£¡£¸ÃÎó²îÓ°ÏìÁ˲úÆ·ÐͺÅRE365¡¢RE650¡¢RE350ºÍRE500£¬£¬£¬£¬£¬£¬£¬ÊÜÓ°ÏìµÄ¹Ì¼þ°æ±¾ÊÇ1.0.2£¬£¬£¬£¬£¬£¬£¬buildΪ20180213¡£ ¡£¡£¡£¡£¡£TP-Link Wi-FiÖÐ¼ÌÆ÷ÔÚMIPS¼Ü¹¹ÉÏÔËÐУ¬£¬£¬£¬£¬£¬£¬ÔÚ·¢ËÍ×°±¸Ê¹ÓúÍÔËÐÐshellÏÂÁîµÄÇëÇóʱ£¬£¬£¬£¬£¬£¬£¬¿Éͨ¹ý¸Ä¶¯HTTPÍ·ÖеÄuser agent×ֶδ¥·¢Îó²î£¬£¬£¬£¬£¬£¬£¬´Ó¶øÊ¹Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÓÐʱ»úÐ®ÖÆ×°±¸²¢»ñµÃÍêÈ«¿ØÖÆÈ¨¡£ ¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/critical-remote-execution-flaw-lurks-in-tp-link-wi-fi-extenders/


3¡¢Facebook WordPress²å¼þÁ½¸öCSRF 0day£¬£¬£¬£¬£¬£¬£¬PoCÒÑÐû²¼

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨
 
Plugin VulnerabilitiesÑо¿Ö°Ô±Åû¶Facebook WordPress²å¼þÖеÄÁ½¸öCSRF 0day¡£ ¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄÁ½¸ö²å¼þ»®·ÖÊÇMessenger Customer ChatºÍFacebook for WooCommerce£¬£¬£¬£¬£¬£¬£¬ÆäÖÐǰÕßÔÚÁè¼Ý2Íò¸öÕ¾µãÉÏ×°Ö㬣¬£¬£¬£¬£¬£¬ºóÕßµÄ×°ÖÃÁ¿Áè¼Ý20Íò´Î¡£ ¡£¡£¡£¡£¡£Îó²îÔÊÐí¾­ÓÉÉí·ÝÑéÖ¤µÄÓû§¸ü¸ÄWordPressÕ¾µãµÄÉèÖÃÑ¡Ï£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±ÒѾ­Ðû²¼ÁËÏà¹ØÏ¸½ÚºÍPoC´úÂë¡£ ¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/researchers-disclose-two-zero-day-vulnerabilities-impacting-two-facebook-wordpress-plugins-c304d71c


4¡¢Çóְƽ̨TalantonÒâÍâй¶½ü160Íò¹ÍÖ÷ºÍÇóÖ°ÕßÐÅÏ¢

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨
 
SafetyDetectiveÑо¿Ö°Ô±·¢Ã÷Ò»¸öÎÞ±£»£»£»£»¤µÄÊý¾Ý¿âй¶´ó×Ú¹ÍÖ÷ºÍÇóÖ°ÕßµÄСÎÒ˽¼ÒÐÅÏ¢¡£ ¡£¡£¡£¡£¡£¸ÃÊý¾Ý¿âÊôÓÚÓ¡¶ÈÇóְƽ̨Talanton£¬£¬£¬£¬£¬£¬£¬Êý¾Ý¿âÖÐ̻¶ÁËÀ´×ÔÃÀ¹ú¡¢Ó¡¶È¡¢Ó¢¹ú¡¢°Ä´óÀûÑǵȹú¼ÒµÄ½ü160Íò¹ÍÖ÷ºÍÇóÖ°ÕßµÄСÎÒ˽¼ÒÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬Èçµç»°ºÅÂë¡¢µç×ÓÓʼþµØµã¡¢¹ú¼®¡¢ÐÔ±ð¡¢×¡Ö·¡¢Ä¿½ñ¹ÍÖ÷¡¢ÈËΪԤÆÚ¡¢ÇóÖú״̬µÈ¡£ ¡£¡£¡£¡£¡£¸ÃÊý¾Ý¿â»¹°üÀ¨Áè¼Ý5Íò¸ö¼ÓÃÜÃÜÂë¡£ ¡£¡£¡£¡£¡£Êý¾Ý¿âÓÚ5ÔÂ17ÈÕÖÁ6ÔÂ15ÈÕÖ®¼ä̻¶£¬£¬£¬£¬£¬£¬£¬ÔÚ½Óµ½±¨¸æºó£¬£¬£¬£¬£¬£¬£¬ÍйÜЧÀÍÉÌTata Communications½«¸ÃÊý¾Ý¿âÍÑ»ú¡£ ¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/job-searching-platform-exposes-personal-information-of-16-million-employers-and-job-seekers-6faf633f


5¡¢X Social Media¹«Ë¾ÒâÍâй¶15Íò·ÝΣÏÕË÷Åâ¼Í¼

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨
 
Çå¾²Ñо¿Ö°Ô±Noam RotemºÍRan Locar·¢Ã÷¹ã¸æ¹«Ë¾X Social MediaµÄÒ»¸öÎÞ±£»£»£»£»¤µÄÊý¾Ý¿âй¶ÁË15Íò·ÝΣÏÕË÷Åâ¼Í¼¡£ ¡£¡£¡£¡£¡£¸Ã¹«Ë¾×ÊÖú״ʦÊÂÎñËùÓëÊܺ¦ÕßÇ©ÊðЭÒ飬£¬£¬£¬£¬£¬£¬Êý¾Ý¿âй¶µÄÐÅÏ¢°üÀ¨ÐÕÃû¡¢µØµã¡¢µç»°ºÅÂëÒÔ¼°Ê¹ʡ¢Î£ÏÕ»ò¼²²¡ÇéÐεÄÚ¹ÊÍ£¬£¬£¬£¬£¬£¬£¬»¹°üÀ¨Ð¡ÎÒ˽¼Ò¿µ½¡ÐÅÏ¢¡¢Ò½ÁÆÐÅÏ¢¡¢ÖÎÁÆÏ¸½ÚµÈ¡£ ¡£¡£¡£¡£¡£¸ÃÊý¾Ý¿â»¹°üÀ¨300¶à¼Ò״ʦÊÂÎñËùÏò¹ã¸æ¹«Ë¾Ö§¸¶µÄÏêϸÓöÈÇåµ¥¡£ ¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/unprotected-database-belonging-to-an-ad-agency-has-exposed-150000-records-of-injury-claims-b1e38d28


6¡¢EatStreetÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬Áè¼Ý600ÍòÌõÓû§¼Í¼±»ÇÔ

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨
 
ʳÎï¶©¹ºÐ§À͹«Ë¾EatstreetÈ·ÈÏÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬¿Í»§¼°ÏàÖúͬ°éµÄÏêϸÐÅÏ¢±»ÇÔ¡£ ¡£¡£¡£¡£¡£Æ¾Ö¤EatStreetµÄ±íÊö£¬£¬£¬£¬£¬£¬£¬ºÚ¿ÍÓÚ5ÔÂ3ÈÕÈëÇÖÆäÅÌËã»úÍøÂç²¢»á¼ûºÍÏÂÔØÊý¾Ý¿âÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬Ö±ÖÁ5ÔÂ17Èոù«Ë¾¼ì²âµ½ÈëÇÖ²¢×èÖ¹ºÚ¿ÍµÄ»á¼û¡£ ¡£¡£¡£¡£¡£ºÚ¿ÍÇÔÈ¡µÄÐÅÏ¢°üÀ¨¶©¹ºÊ³ÎïµÄ¿Í»§ÐÅÏ¢¼°µÚÈý·½ËÍ»õЧÀ͵ÄÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬ÈçÐÕÃû¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØµã¡¢ÒøÐÐÕË»§µÈ£¬£¬£¬£¬£¬£¬£¬Óû§µÄÐÅÓÿ¨Ö§¸¶ÏêϸÐÅÏ¢Ò²Ôâй¶¡£ ¡£¡£¡£¡£¡£¸Ã¹«Ë¾²¢Î´Í¸Â¶Óм¸¶àÓû§Êܵ½Ó°Ï죬£¬£¬£¬£¬£¬£¬µ«ºÚ¿ÍÉù³Æ¹²ÇÔÈ¡ÁË600¶àÍòÌõÓû§¼Í¼¡£ ¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/eatstreet-food-ordering-service-discloses-security-breach/