ÐÅÏ¢Çå¾²Öܱ¨-2018ÄêµÚ25ÖÜ

Ðû²¼Ê±¼ä 2018-06-25

Ò»¡¢±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö
        2018Äê06ÔÂ18ÈÕÖÁ24ÈÕ¹²ÊÕ¼Çå¾²Îó²î46¸ö£¬£¬£¬ £¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇCisco FXOS/NX-OS Software Fabric ServicesÔ¶³Ì´úÂëÖ´ÐÐÎó²î£»£»£»£»£»£»Cisco NX-OS Software NX-APIí§Òâ´úÂëÖ´ÐÐÎó²î£»£»£»£»£»£»NTP ntpqºÍntpdc CVE-2018-12327Õ»»º³åÇø¹ýʧÎó²î£»£»£»£»£»£»CA Privileged Access Manager CVE-2015-4664ÊäÈëÑéÖ¤í§ÒâÏÂÁîÖ´ÐÐÎó²î£»£»£»£»£»£»QEMU slirp/mbuf.c/m_cat¶Ñ»º³åÇøÒç³öÎó²î¡£ ¡£¡£¡£¡£

        ±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇÑо¿Ö°Ô±ÖÒÑԳƶñÒâÈí¼þͨ¹ýαװ³É±¤ÀÝÖ®Ò¹°²×¿°æ¾ÙÐÐÈö²¥£»£»£»£»£»£»Ñо¿Ö°Ô±³ÆmacOSµÄQuickLook¹¦Ð§¿Éµ¼ÖÈÎÃüÜ´ÅÅ̵ÄÊý¾Ýй¶£»£»£»£»£»£»º«¹ú¼ÓÃÜÇ®±ÒÉúÒâËùBithumbÒ»ÄêÄÚµÚ¶þ´ÎÔâºÚ¿ÍÈëÇÖ£¬£¬£¬ £¬£¬£¬£¬Ô¼3100ÍòÃÀÔª±»ÇÔ£»£»£»£»£»£»Flightradar24ÔâºÚ¿ÍÈëÇÖ£¬£¬£¬ £¬£¬£¬£¬Ô¼23ÍòÓû§µÄÐÅϢй¶£»£»£»£»£»£»Ñо¿Ö°Ô±·¢Ã÷Áè¼Ý3000¸öappµÄFirebaseÊý¾Ý¿â¿É¹ûÕæ»á¼û¡£ ¡£¡£¡£¡£

        ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬ £¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£ ¡£¡£¡£¡£

 

¶þ¡¢Ö÷ÒªÇå¾²Îó²îÁбí
1¡¢Cisco FXOS/NX-OS Software Fabric ServicesÔ¶³Ì´úÂëÖ´ÐÐÎó²î

        Cisco FXOS/NX-OS Software Fabric Services×é¼þδÓÐÓÃÑéÖ¤Fabric ServicesÊý¾Ý°üÄڵıêÍ·Öµ£¬£¬£¬ £¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬ £¬£¬£¬£¬ÒÔϵͳÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£ ¡£¡£¡£¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180620-fxnxos-fab-ace
2¡¢Cisco NX-OS Software NX-APIí§Òâ´úÂëÖ´ÐÐÎó²î

        Cisco NX-OS Software NX-API×Ó³ÌÐòÖеÄÉí·ÝÑé֤ģ¿£¿£¿£¿éûÓÐ׼ȷµÄÖ´ÐÐÊäÈëÑéÖ¤£¬£¬£¬ £¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬ £¬£¬£¬£¬ÒÔrootÓû§Éí·ÝÖ´ÐÐí§Òâ´úÂë¡£ ¡£¡£¡£¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180620-nxos-bo
3¡¢NTP ntpqºÍntpdc CVE-2018-12327Õ»»º³åÇø¹ýʧÎó²î

        NTP ntpqºÍntpdc´¦Öóͷ£½Ï³¤µÄ×Ö·û´®×÷ΪIPv4»òIPv6ÏÂÁîÐеIJÎÊý±£´æÇå¾²ÎÊÌ⣬£¬£¬ £¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬ £¬£¬£¬£¬ÒÔÓ¦ÓóÌÐòÖ´ÐÐí§Òâ´úÂë¡£ ¡£¡£¡£¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://gist.github.com/fakhrizulkifli/9b58ed8e0354e8deee50b0eebd1c011f
4¡¢CA Privileged Access Manager CVE-2015-4664ÊäÈëÑéÖ¤í§ÒâÏÂÁîÖ´ÐÐÎó²î

        CA Privileged Access Manager±£´æÊäÈëÑéÖ¤Îó²î£¬£¬£¬ £¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬ £¬£¬£¬£¬ÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§ÒâÏÂÁî¡£ ¡£¡£¡£¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://support.ca.com/us/product-content/recommended-reading/security-notices/ca20180614-01--security-notice-for-ca-privileged-access-manager.html
5¡¢QEMU slirp/mbuf.c/m_cat¶Ñ»º³åÇøÒç³öÎó²î

        QEMUÔÚslirp/mbuf.c/m_catÖб£´æ»ùÓڶѵĻº³åÇøÒç³öÎó²î£¬£¬£¬ £¬£¬£¬£¬ÔÊÐíÍâµØ¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬ £¬£¬£¬£¬¿ÉʹϵͳÍ߽⡣ ¡£¡£¡£¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://bugzilla.redhat.com/show_bug.cgi?id=1586245

 

Èý¡¢Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö
1¡¢Ñо¿Ö°Ô±ÖÒÑԳƶñÒâÈí¼þͨ¹ýαװ³É±¤ÀÝÖ®Ò¹°²×¿°æ¾ÙÐÐÈö²¥

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

        ESETµÄ¶ñÒâÈí¼þÑо¿Ö°Ô±Lukas Stefanko·¢Ã÷²¿·Ö¶ñÒâÈí¼þͨ¹ýαװ³É±¤ÀÝÖ®Ò¹µÄ°²×¿°æ¾ÙÐÐÈö²¥¡£ ¡£¡£¡£¡£±¤ÀÝÖ®Ò¹ÔÚÈ«ÇòÓµÓÐÁè¼Ý1.25ÒÚÍæ¼Ò£¬£¬£¬ £¬£¬£¬£¬µ«Æä¹Ù·½°²×¿°æ±¾ÉÐδÐû²¼¡£ ¡£¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷GoogleºÍYouTubeÉϵÄһЩÊÓÆµºÍÁ´½ÓÉù³ÆÆä°üÀ¨±¤ÀÝÖ®Ò¹µÄAPKÎļþ£¬£¬£¬ £¬£¬£¬£¬»òÊÇÖ¸µ¼Óû§×°ÖÃһЩÆäËüÓ¦ÓÃÒÔ½âËø¸ÃÓÎÏ·£¬£¬£¬ £¬£¬£¬£¬Õ⽫¸ø¶ñÒâÈí¼þ¿ª·¢Ö°Ô±´øÀ´ÊÕÈë»òËðº¦Óû§µÄ°²×¿×°±¸¡£ ¡£¡£¡£¡£

        Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/06/fortnite-for-android-apk.html

2¡¢Ñо¿Ö°Ô±³ÆmacOSµÄQuickLook¹¦Ð§¿Éµ¼ÖÈÎÃüÜ´ÅÅ̵ÄÊý¾Ýй¶

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

        Digita SecurityµÄÑо¿Ö°Ô±Patrick WardleÖÒÑÔ³ÆmacOSÓû§´æ´¢ÔÚ¼ÓÃÜ´ÅÅÌÉϵÄÊý¾Ý²¢Ã»ÓлñµÃºÜºÃµÄ±£»£»£»£»£»£»¤£¬£¬£¬ £¬£¬£¬£¬ÓÉÓÚmacOSµÄQuickLook¹¦Ð§¿ÉÒÔÉúÑÄͼƬµÈÎļþµÄÔ¤ÀÀ¡£ ¡£¡£¡£¡£µ±Í¨¹ýUIÉó²éĿ¼ʱ£¬£¬£¬ £¬£¬£¬£¬QuickLook½«×Ô¶¯½¨É軺ºÍ´æÎļþµÄËõÂÔͼ£¬£¬£¬ £¬£¬£¬£¬ÕâЩËõÂÔͼÉúÑÄÔÚSQLiteÊý¾Ý¿âÖУ¬£¬£¬ £¬£¬£¬£¬¿Éͨ¹ýÏà¹ØÏÂÁî¾ÙÐÐÌáÈ¡¡£ ¡£¡£¡£¡£×ÝȻԭʼÎļþ±»É¾³ý£¬£¬£¬ £¬£¬£¬£¬ÕâЩ»º´æÒÀ¾É±£´æ¡£ ¡£¡£¡£¡£

        Ô­ÎÄÁ´½Ó£ºhttps://threatpost.com/macos-quicklook-feature-leaks-data-despite-encrypted-drive/132905/

3¡¢º«¹ú¼ÓÃÜÇ®±ÒÉúÒâËùBithumbÒ»ÄêÄÚµÚ¶þ´ÎÔâºÚ¿ÍÈëÇÖ£¬£¬£¬ £¬£¬£¬£¬Ô¼3100ÍòÃÀÔª±»ÇÔ

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

        ƾ֤º«¹ú¼ÓÃÜÇ®±ÒÉúÒâËùBithumbµÄÉùÃ÷£¬£¬£¬ £¬£¬£¬£¬¸Ã¹«Ë¾ÔÚ6ÔÂ19ÈÕÖÁ20ÈÕµÄÒ¹¼äÔâµ½ºÚ¿ÍÈëÇÖ£¬£¬£¬ £¬£¬£¬£¬¼ÛÖµÔ¼350ÒÚº«Ôª£¨3160ÍòÃÀÔª£©µÄ¼ÓÃÜÇ®±Ò±»ÇÔ¡£ ¡£¡£¡£¡£BithumbûÓÐ͸¶¹ØÓڴ˴ι¥»÷µÄ¸ü¶àϸ½Ú£¬£¬£¬ £¬£¬£¬£¬°üÀ¨ºÚ¿ÍÔõÑù½øÈëϵͳºÍÔõÑùÇÔÈ¡×ʽð¡£ ¡£¡£¡£¡£¸Ã¹«Ë¾ÌåÏÖÍýÏëʹÓô¢±¸»ù½ðÀ´Åâ³¥ÊÜËðʧµÄÓû§¡£ ¡£¡£¡£¡£

        Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/bithumb-hacked-second-time-in-a-year-hackers-steal-31-million/

4¡¢Flightradar24ÔâºÚ¿ÍÈëÇÖ£¬£¬£¬ £¬£¬£¬£¬Ô¼23ÍòÓû§µÄÐÅϢй¶

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

        Èðµä¹«Ë¾Flightradar24֤ʵÆäһ̨ЧÀÍÆ÷ÓÚÉÏÖÜÄ©ÔâºÚ¿ÍÈëÇÖ£¬£¬£¬ £¬£¬£¬£¬Ô¼23ÍòÓû§µÄµç×ÓÓʼþµØµãºÍ¹þÏ£ÃÜÂëй¶¡£ ¡£¡£¡£¡£Flightradar24ÊÇÒ»¼ÒÌṩº½°à×·×ÙЧÀ͵Ĺ«Ë¾£¬£¬£¬ £¬£¬£¬£¬¸Ã¹«Ë¾ÌåÏÖ´Ë´Îй¶ӰÏìÁË2016Äê3ÔÂ16ÈÕ֮ǰע²áµÄÓû§¡£ ¡£¡£¡£¡£Flightradar24ÒÑÏòÓû§·¢ËÍÁ˰üÀ¨ÃÜÂëÖØÖÃÁ´½ÓµÄÓʼþ£¬£¬£¬ £¬£¬£¬£¬ÒªÇóÕâЩÓû§¸ü¸ÄÃÜÂë¡£ ¡£¡£¡£¡£

        Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/06/flightradar24-data-breach.html

5¡¢Ñо¿Ö°Ô±·¢Ã÷Áè¼Ý3000¸öappµÄFirebaseÊý¾Ý¿â¿É¹ûÕæ»á¼û

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

        Çå¾²Ñо¿Ö°Ô±·¢Ã÷Áè¼Ý3000¸öapp£¨°üÀ¨2446¸öAndroid appºÍ600¸öiOS app£©µÄÔ¼2300¸öFirebaseÊý¾Ý¿â¿É¹ûÕæ»á¼û£¬£¬£¬ £¬£¬£¬£¬Áè¼Ý1ÒÚÌõÓû§ÐÅϢй¶£¨Áè¼Ý113GB£©¡£ ¡£¡£¡£¡£ÕâЩй¶µÄÐÅÏ¢°üÀ¨Ã÷ÎÄÃÜÂë¡¢Óû§ID¡¢Î»ÖÃÒÔ¼°²¿·Ö²ÆÎñ¼Í¼£¨ÒøÐС¢¼ÓÃÜÇ®±ÒÉúÒ⣩µÈ¡£ ¡£¡£¡£¡£GoogleµÄFirebaseÊÇ×îÊܽӴýµÄÒÆ¶¯ºÍWebÓ¦Óõĺó¶Ë¿ª·¢Æ½Ì¨Ö®Ò»£¬£¬£¬ £¬£¬£¬£¬ËüΪ¿ª·¢Ö°Ô±ÌṩÁË»ùÓÚÔÆµÄÊý¾Ý¿â£¬£¬£¬ £¬£¬£¬£¬²¢ÒÔJSONÃûÌô洢Êý¾Ý¡£ ¡£¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷Ðí¶à¿ª·¢Ö°Ô±Î´Í×ÉÆ±£»£»£»£»£»£»¤ÆäFirebaseÊý¾Ý¿â£¬£¬£¬ £¬£¬£¬£¬Ê¹µÃ¹¥»÷ÕßÖ»ÐèÔÚÖ÷»úÃûĩβÌí¼Ó¿ÕÊý¾Ý¿âÃû+¡°/.json¡±¼´¿É»á¼ûÕâЩÊý¾Ý¡£ ¡£¡£¡£¡£

        Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/06/mobile-security-firebase-hosting.html