Å·Ã˳ÉÔ±¹úÐû²¼ÓйØ5GÍøÂçÇå¾²µÄÁªºÏ±¨¸æ£»£»£»£»£»£»Ó¡¶ÈËÑË÷ÒýÇæJustdial APIÎó²î£»£»£»£»£»£»NitroPDF¶à¸öRCEÎó²î

Ðû²¼Ê±¼ä 2019-10-11
1¡¢Å·Ã˳ÉÔ±¹úÐû²¼ÓйØ5GÍøÂçÇå¾²µÄÁªºÏ±¨¸æ

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

Å·ÃË£¨EU£©³ÉÔ±¹úÐû²¼ÁËÒ»·ÝÓйØ5GÍøÂçÇå¾²µÄΣº¦ÆÀ¹ÀÁªºÏ±¨¸æ£¬£¬£¬È·¶¨ÁË5GÍøÂçµÄÖ÷ÒªÍþв¼°Íþв¹¥»÷Õß¡¢×îÃô¸ÐµÄ×ʲúÒÔ¼°Æä±³ºóµÄÖ÷ÒªÎó²î¡£¡£¡£ ¡£¡£¡£¸Ã±¨¸æÇ¿µ÷ÁËÒÀÀµÓÚ¼òµ¥×°±¸¹©Ó¦É̵ÄÒþ»¼ÒÔ¼°×°±¸Ç·È±ºÍ5G½â¾ö¼Æ»®¶àÑùÐÔµÄÎÊÌâ¡£¡£¡£ ¡£¡£¡£ÕâЩÎÊÌ⼫´óµØÀ©Õ¹ÁËEU¼°¹ú¼Ò²ãÃæµÄ5G»ù´¡ÉèÊ©µÄÕûÌåųÈõÐÔ¡£¡£¡£ ¡£¡£¡£Ì«¹ýÒÀÀµ¼òµ¥×°±¸¹©Ó¦É̵ÄÅ·ÃËÔËÓªÉÌÃæÁÙןù©Ó¦ÉÌ´øÀ´µÄÒ»Á¬ÉÌҵѹÁ¦£¬£¬£¬ÎÞÂÛÊÇÉÌҵʧ°Ü¡¢ºÏ²¢ÕÕ¾ÉÊÕ¹º¡¢»òÊDZ»ÖƲᣡ£¡£ ¡£¡£¡£Å·Ã˵ı¨¸æÌåÏÖ£¬£¬£¬5GÍøÂç±³ºóµÄÇå¾²ÌôÕ½»¹ÓëÍøÂçÓëµÚÈý·½ÏµÍ³Ö®¼äµÄÅþÁ¬ÒÔ¼°µÚÈý·½¹©Ó¦É̶ÔÅ·ÃË5GÍøÂçµÄ»á¼ûȨÏÞµÄÔöÌíÓйØ¡£¡£¡£ ¡£¡£¡£

   

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/eu-member-states-publish-joint-report-on-5g-networks-security/

2¡¢Ó¡¶ÈËÑË÷ÒýÇæJustdial APIÎó²îµ¼ÖÂ1.56ÒÚÓû§ÕÊ»§Ì»Â¶

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Ó¡¶ÈÍâµØËÑË÷ÒýÇæJustdial±£´æÇå¾²Îó²î£¬£¬£¬µ¼ÖºڿͿÉÒԵǼÆä1.56ÒÚÓû§ÕÊ»§ÖеÄÈκÎÒ»¸ö¡£¡£¡£ ¡£¡£¡£³ýÁË»á¼ûÓû§ÐÅÏ¢£¨ÀýÈçÐÕÃû¡¢µç»°ºÅÂëºÍµç×ÓÓʼþµØµã£©Í⣬£¬£¬¹¥»÷Õß»¹¿ÉÒÔͨ¹ý¸Ã¹«Ë¾µÄÖ§¸¶Ð§ÀÍJustDial PayÀ´Éó²éÓû§µÄ²ÆÎñÐÅÏ¢£¬£¬£¬°üÀ¨ÕÊ»§µÄÓà¶îºÍÉúÒâ¼Í¼¡£¡£¡£ ¡£¡£¡£¸ÃÎó²îÓÉÇå¾²Ñо¿Ô±Ehraz Ahmed·¢Ã÷£¬£¬£¬ËüʹÓÃÁ˸ÃÍøÕ¾µÄ×¢²áAPI¡£¡£¡£ ¡£¡£¡£¹¥»÷ÕßÉõÖÁ¿ÉÒÔʹÓøÃÎó²î¸ü¸ÄÓû§µÄJustDial PayÕË»§ÐÅÏ¢£¬£¬£¬´Ó¶øµ¼Ö·¢ËÍÖÁ¸ÃÕË»§µÄËùÓÐ×ʽ𶼱»Öض¨Ïò£¬£¬£¬µ«¹¥»÷ÕßÎÞ·¨¾ÙÐлã¿î²Ù×÷£¬£¬£¬ÓÉÓÚÕâÐèÒªÌØÁíÍâPINÂë¡£¡£¡£ ¡£¡£¡£JustDialÔÚÒ»·ÝÉùÃ÷ÖÐÌåÏÖ¸ÃÎó²îÒѱ»ÐÞ¸´¡£¡£¡£ ¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://thenextweb.com/security/2019/10/10/a-bug-in-indian-local-search-app-exposed-over-156-million-accounts/

3¡¢Ó¡µÚ°²ÄÉÖÝijҽԺÔâµ½´¹ÂÚ¹¥»÷£¬£¬£¬»¼ÕßÐÅÏ¢¿ÉÄÜй¶

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

Ó¡µÚ°²ÄÉÖÝÎÀÀí¹«»áÒ½ÔºÌåÏÖÆäÁ½ÃûÔ±¹¤Ôâ´¹ÂÚ¹¥»÷£¬£¬£¬6.8Íò»¼ÕßµÄСÎÒ˽¼ÒºÍÒ½ÁÆÐÅÏ¢¿ÉÄÜй¶¡£¡£¡£ ¡£¡£¡£Æ¾Ö¤ÊӲ죬£¬£¬µÚÒ»ÃûÔ±¹¤µÄÕË»§ÔÚ6ÔÂ12ÈÕ¼°7ÔÂ1ÈÕÖÁ7ÔÂ8ÈÕÔâµÚÈý·½Î´ÊÚȨ»á¼û£¬£¬£¬µÚ¶þÃûÔ±¹¤µÄÕË»§ÔòÓÚ3ÔÂ13ÈÕÖÁ6ÔÂ12ÈÕÖ®¼ä̻¶¡£¡£¡£ ¡£¡£¡£ÎÀÀí¹«»áÒ½ÔºÌåÏÖËäȻûÓÐÖ¤¾ÝÅú×¢ÏÖʵ»òÊÔͼÀÄÓÃÔ±¹¤ÓÊÏäÕË»§Öб£´æµÄÈκÎÐÅÏ¢£¬£¬£¬µ«ÊӲ첻¿Éɨ³ý»á¼ûÕÊ»§Öб£´æµÄÊý¾ÝµÄ¿ÉÄÜÐÔ¡£¡£¡£ ¡£¡£¡£ÕâÁ½¸öÓÊÏäÕË»§ÖаüÀ¨»¼ÕßµÄÒÔÏÂÐÅÏ¢£ºÐÕÃû¡¢µØµã¡¢Éç»á°ü¹ÜºÅ¡¢¼ÝʻִÕÕ/ÖݱêʶºÅ¡¢»¤Õպš¢½ðÈÚÕʺš¢ÒøÐп¨ÐÅÏ¢¡¢µç×ÓÊðÃû¡¢Óû§ÃûºÍÃÜÂë¡¢³öÉúÈÕÆÚ¡¢Ò½ÁƼ°Õï¶ÏÐÅÏ¢µÈ¡£¡£¡£ ¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/phishing-incident-exposes-medical-personal-info-of-60k-patients/

4¡¢¹¥»÷ÕßʹÓÃWindows°æiTunesÖеÄÎó²î·Ö·¢BitPaymer

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ÀÕË÷Èí¼þBitPaymer±»·¢Ã÷ÔÚ¹¥»÷»î¶¯ÖÐʹÓÃWindows°æiTunesÖеÄ0dayÀ´ÈƹýÊÜѬȾÖ÷»úÉϵķÀ²¡¶¾¼ì²â¡£¡£¡£ ¡£¡£¡£Çå¾²³§ÉÌMorphisecÔÚ8Ô·ÝÕë¶ÔÒ»¼ÒÆû³µÆóÒµµÄBitPaymer¹¥»÷Öз¢Ã÷ÁËÕâÖÖÐÐΪ¡£¡£¡£ ¡£¡£¡£¸ÃÎó²î±£´æÓÚWindows°æiTunesºÍiCloudÖУ¬£¬£¬Æ»¹ûÓÚ±¾ÖÜÐÞ¸´Á˸Ã0day¡£¡£¡£ ¡£¡£¡£ÏÖʵµÄÎó²î±£´æÓÚ²úÆ·Ëæ¸½µÄBonjour¸üÐÂ×é¼þÖУ¬£¬£¬¹¥»÷Õß¿ÉÒÔÆô¶¯Bonjour×é¼þ²¢Ð®ÖÆÆäÖ´Ðз¾¶£¬£¬£¬½«ÆäÖ¸ÏòBitPaymerÀÕË÷Èí¼þ¡£¡£¡£ ¡£¡£¡£¸ÃÎó²î²¢²»¿ÉʹBitPaymer»ñµÃÖÎÀíԱȨÏÞ£¬£¬£¬µ«Ëüȷʵ¿ÉÒÔÓÕÆ­ÍâµØ×°ÖõķÀ²¡¶¾Èí¼þ¡£¡£¡£ ¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.zdnet.com/article/ransomware-gang-uses-itunes-zero-day/

5¡¢Ë¼¿ÆTalosÍŶӷ¢Ã÷NitroPDF±£´æ¶à¸öRCEÎó²î


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


˼¿ÆTalosÅû¶NitroPDFÖеĶà¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£ ¡£¡£¡£Nitro PDFÔÊÐíÓû§ÔÚÆäÅÌËã»úÉÏÉúÑÄ¡¢ÔĶÁºÍ±à¼­PDFÎļþ£¬£¬£¬¸Ã²úÆ··ÖΪÃâ·Ñ°æºÍÊշѰæ¡£¡£¡£ ¡£¡£¡£´Ë´Î·¢Ã÷µÄÎó²î¶¼±£´æÓÚÊշѵÄPro°æÖС£¡£¡£ ¡£¡£¡£Îó²î°üÀ¨jpeg2000 ssizDepthÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2019-5045£©¡¢Page KidsÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2019-5050£©¡¢ICCBasedÉ«²Ê¿Õ¼äÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2019-5048£©¡¢CharProcsÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2019-5047£©¡¢ jpeg2000 yTsizÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2019-5046£©¼°Á÷³¤¶ÈÆÊÎö¹¦Ð§ÄÚ´æËð»µÎó²î£¨CVE-2019-5053£©¡£¡£¡£ ¡£¡£¡£ÊÜÓ°ÏìµÄ°æ±¾ÎªNitroPDF 12.12.1.522¡£¡£¡£ ¡£¡£¡£NitroPDFÉÐδÐû²¼Ïà¹ØÐÞ¸´²¹¶¡¡£¡£¡£ ¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://blog.talosintelligence.com/2019/10/vuln-spotlight-Nitro-PDF-RCE-bugs-sept-19.html

6¡¢HPÐÞ¸´Touchpoint AnalyticsÈí¼þÖеÄLPEÎó²î


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


SafeBreach LabsÇå¾²Ñо¿Ô±Peleg Hadar·¢Ã÷HPµÄTouchPoint Analytics±£´æLPEÎó²î£¨CVE-2019-6333£¬£¬£¬CVSS 3ÆÀ·ÖΪ6.7·Ö£©¡£¡£¡£ ¡£¡£¡£HP TouchPoint AnalyticsÒÔWindowsЧÀ͵ÄÐÎʽԤװÔÚ´ó´ó¶¼HPÅÌËã»úÉÏ£¬£¬£¬Ö¼ÔÚÄäÃûÍøÂçÓ²¼þÐÔÄÜÕï¶ÏÐÅÏ¢¡£¡£¡£ ¡£¡£¡£¸ÃWindowsЧÀ;ßÓÐ×î¸ß¼¶±ðµÄNT AUTHORITY\SYSTEMȨÏÞ¡£¡£¡£ ¡£¡£¡£HadarÌåÏÖ¸ÃÎó²îÊÇÓɲ»Çå¾²µÄDLL¼ÓÔØËùÒýÆðµÄ£¬£¬£¬Touchpoint Analytics Client°æ±¾4.1.4.2827ÒÔÏÂÊܵ½Ó°Ïì¡£¡£¡£ ¡£¡£¡£HPÔÚTouchpoint Analytics Client 4.1.4.2827ÖÐÐÞ¸´ÁË´ËÎó²î¡£¡£¡£ ¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/hp-touchpoint-analytics-lpe-vulnerability-affects-most-hp-pcs