ÐÅÏ¢Çå¾²Öܱ¨-2019ÄêµÚ35ÖÜ

Ðû²¼Ê±¼ä 2019-09-09

 > ±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö



2019Äê9ÔÂ02ÈÕÖÁ08ÈÕ¹²ÊÕ¼Çå¾²Îó²î46¸ö £¬£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇBD PyxisδÊÚȨ»á¼ûÎó²î£»£»£»£»Mozilla Firefox CVE-2019-11741ͨÓÿçÕ¾¾ç±¾¹¥»÷Îó²î£»£»£»£»CA Automic Workload Automation DIA CA Common Services´úÂëÖ´ÐÐÎó²î£»£»£»£»Aruba Mobility Controller WEB×é¼þÏÂÁî×¢ÈëÎó²î£»£»£»£»Samba CVE-2019-10197Ŀ¼±éÀúÎó²î ¡£¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇÈýÐÇ¡¢»ªÎªµÈÊÖ»úÒ×ÊÜOMA CP¶ÌÐÅÖ¸ÁîÓÕÆ­¹¥»÷£»£»£»£»FacebookÓû§µç»°ºÅÂëÊý¾Ý¿âй¶ £¬£¬£¬£¬£¬£¬£¬Éæ¼°4.19ÒÚÌõ¼Í¼£»£»£»£»FacebookÓû§µç»°ºÅÂëÊý¾Ý¿âй¶ £¬£¬£¬£¬£¬£¬£¬Éæ¼°4.19ÒÚÌõ¼Í¼£»£»£»£»Ó¢¹ú¹ú¾Û»áÔ±ÔÚ2019²ÆÄêÎüÊÕµ½½ü2100Íò·âÀ¬»øÓʼþ£»£»£»£»Windows 10 KB4512941¸üе¼ÖÂCortanaÕ¼ÓÃCPU¹ý¸ß ¡£¡£¡£¡£¡£


ƾ֤ÒÔÉÏ×ÛÊö £¬£¬£¬£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖÐ ¡£¡£¡£¡£¡£


> Ö÷ÒªÇå¾²Îó²îÁбí



1. BD PyxisδÊÚȨ»á¼ûÎó²î


BD PyxisÊÚȨ»úÖÆ±£´æÇå¾²Îó²î £¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó £¬£¬£¬£¬£¬£¬£¬Î´ÊÚȨ»á¼ûÓ¦Óà ¡£¡£¡£¡£¡£
https://www.us-cert.gov/ics/advisories/icsma-19-248-01

2. Mozilla Firefox CVE-2019-11741ͨÓÿçÕ¾¾ç±¾¹¥»÷Îó²î


Mozilla FirefoxʵÏÖ±£´æÍ¨ÓÿçÕ¾¾ç±¾Îó²î £¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄWEB £¬£¬£¬£¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö £¬£¬£¬£¬£¬£¬£¬²Ù¿Øaddons.mozilla.org¼°accounts.firefox.com¿ÉÐÞ¸ÄÓû§ÉèÖÃµÈ ¡£¡£¡£¡£¡£
https://www.mozilla.org/en-US/security/advisories/mfsa2019-25/

3. CA Automic Workload Automation DIA CA Common Services´úÂëÖ´ÐÐÎó²î


CA Automic Workload Automation DIA CA Common ServicesʵÏÖ±£´æÇå¾²Îó²î £¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó £¬£¬£¬£¬£¬£¬£¬¿ÉÖ´ÐдúÂë ¡£¡£¡£¡£¡£
https://www.auscert.org.au/bulletins/ESB-2019.3374/

4. Aruba Mobility Controller WEB×é¼þÏÂÁî×¢ÈëÎó²î


Aruba Mobility Controller WEB×é¼þ±£´æÏÂÁî×¢ÈëÎó²î £¬£¬£¬£¬£¬£¬£¬ÔÊÐíͨ¹ýÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó £¬£¬£¬£¬£¬£¬£¬¿ÉÖ´ÐÐí§ÒâÏÂÁî ¡£¡£¡£¡£¡£
https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2019-004.txt

5. Samba CVE-2019-10197Ŀ¼±éÀúÎó²î


SambaijЩ²ÎÊýÉèÖÃϱ£´æÇå¾²Îó²î £¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó £¬£¬£¬£¬£¬£¬£¬¿ÉÈÆ¹ýĿ¼ÏÞÖÆ £¬£¬£¬£¬£¬£¬£¬Î´ÊÚȨ»á¼û ¡£¡£¡£¡£¡£
https://www.samba.org/samba/security/CVE-2019-10197.html


> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö



1¡¢ÈýÐÇ¡¢»ªÎªµÈÊÖ»úÒ×ÊÜOMA CP¶ÌÐÅÖ¸ÁîÓÕÆ­¹¥»÷


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Check PointÑо¿Ö°Ô±·¢Ã÷ËļÒÖÇÄÜÊÖ»úÖÆÔìÉÌ£¨°üÀ¨ÈýÐÇ¡¢»ªÎª¡¢LGºÍË÷ÄᣩδÔÚÆä×°±¸ÉÏʵÑéÇå¾²µÄOMA CPÖ¸Áî±ê×¼ £¬£¬£¬£¬£¬£¬£¬Ê¹µÃ¹¥»÷Õß¿ÉÒÔͨ¹ýαÔìOMA CP¶ÌÐÅÖ¸ÁîÓÕÆ­Óû§ÐÞ¸Ä×°±¸ÉèÖà £¬£¬£¬£¬£¬£¬£¬´Ó¶ø×èµ²Æäµç×ÓÓʼþ»òÍøÂçÁ÷Á¿ ¡£¡£¡£¡£¡£OMA CP´ú±í¿ª·ÅÒÆ¶¯Í¬Ã˿ͻ§¶ËÉèÖà £¬£¬£¬£¬£¬£¬£¬ËüÖ¸µÄÊÇÒÆ¶¯ÔËÓªÉÌ¿Éͨ¹ýÌØ¶¨¶ÌÐŽ«ÍøÂçÉèÖ÷¢Ë͵½Óû§×°±¸µÄÒ»ÖÖ±ê×¼ ¡£¡£¡£¡£¡£Ñо¿Ö°Ô±³ÆÈýÐǵÄÊÖ»ú×î²»Çå¾² £¬£¬£¬£¬£¬£¬£¬ÓÉÓÚËü¿ÉÒÔ½ÓÊÜÈκÎÀàÐ͵ÄOMA CPÐÂÎŲ¢ÇÒûÓÐÈÏÖ¤»òÑéÖ¤»úÖÆ ¡£¡£¡£¡£¡£ÈýÐǺÍLG»®·ÖÓÚ5Ô·ݺÍ7Ô·ÝÐû²¼ÁËÐÞ¸´²¹¶¡ £¬£¬£¬£¬£¬£¬£¬»ªÎªÌåÏÖ½«ÔÚÏÂÒ»´úMate»òPϵÁÐÊÖ»úÖмÓÈëÐÞ¸´²¹¶¡ £¬£¬£¬£¬£¬£¬£¬µ«Ë÷Äá¾Ü¾øÈϿɸÃÎó²î ¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.zdnet.com/article/samsung-huawei-lg-and-sony-phones-vulnerable-to-rogue-provisioning-messages/

2¡¢FacebookÓû§µç»°ºÅÂëÊý¾Ý¿âй¶ £¬£¬£¬£¬£¬£¬£¬Éæ¼°4.19ÒÚÌõ¼Í¼


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Ñо¿Ö°Ô±·¢Ã÷Ò»¸ö´æ´¢ÁËÊýÒÚFacebookÓû§µç»°ºÅÂë¼Í¼µÄÊý¾Ý¿âÔÚÍøÉÏ̻¶ ¡£¡£¡£¡£¡£ÕâЩÊý¾Ý×ÜÊýÁè¼Ý4.19ÒÚÌõ¼Í¼ £¬£¬£¬£¬£¬£¬£¬º­¸Ç¶à¸öµØÇø £¬£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨1.33ÒÚÌõÃÀ¹úFacebookÓû§¼Í¼¡¢1800ÍòÓ¢¹úÓû§¼Í¼ÒÔ¼°5000¶àÍòÔ½ÄÏÓû§¼Í¼ ¡£¡£¡£¡£¡£Ïêϸ¶øÑÔ £¬£¬£¬£¬£¬£¬£¬Ã¿Ìõ¼Í¼¶¼°üÀ¨Óû§µÄΨһFacebook IDºÍÕË»§¹ØÁªµÄµç»°ºÅÂë ¡£¡£¡£¡£¡£ÓÉÓÚ´æ´¢ÕâЩÊý¾ÝµÄЧÀÍÆ÷ûÓÐÊÜÃÜÂë±£»£»£»£»¤ £¬£¬£¬£¬£¬£¬£¬µ¼ÖÂÈκÎÈ˶¼¿ÉÒÔÕÒµ½²¢»á¼û¸ÃÊý¾Ý¿â ¡£¡£¡£¡£¡£Ã½ÌåÒѾ­¶ÔÆäÖÐһЩ¼Í¼¾ÙÐÐÑéÖ¤ £¬£¬£¬£¬£¬£¬£¬»¹·¢Ã÷²¿·Ö¼Í¼°üÀ¨Óû§µÄÐÕÃû¡¢ÐÔ±ðºÍ¹ú¼Ò/µØÇøÎ»Öà ¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://threatpost.com/leaky-server-exposes-419m-phone-numbers-of-facebook-users/148029/

3¡¢FacebookÓû§µç»°ºÅÂëÊý¾Ý¿âй¶ £¬£¬£¬£¬£¬£¬£¬Éæ¼°4.19ÒÚÌõ¼Í¼

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Ñо¿Ö°Ô±·¢Ã÷Ò»¸ö´æ´¢ÁËÊýÒÚFacebookÓû§µç»°ºÅÂë¼Í¼µÄÊý¾Ý¿âÔÚÍøÉÏ̻¶ ¡£¡£¡£¡£¡£ÕâЩÊý¾Ý×ÜÊýÁè¼Ý4.19ÒÚÌõ¼Í¼ £¬£¬£¬£¬£¬£¬£¬º­¸Ç¶à¸öµØÇø £¬£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨1.33ÒÚÌõÃÀ¹úFacebookÓû§¼Í¼¡¢1800ÍòÓ¢¹úÓû§¼Í¼ÒÔ¼°5000¶àÍòÔ½ÄÏÓû§¼Í¼ ¡£¡£¡£¡£¡£Ïêϸ¶øÑÔ £¬£¬£¬£¬£¬£¬£¬Ã¿Ìõ¼Í¼¶¼°üÀ¨Óû§µÄΨһFacebook IDºÍÕË»§¹ØÁªµÄµç»°ºÅÂë ¡£¡£¡£¡£¡£ÓÉÓÚ´æ´¢ÕâЩÊý¾ÝµÄЧÀÍÆ÷ûÓÐÊÜÃÜÂë±£»£»£»£»¤ £¬£¬£¬£¬£¬£¬£¬µ¼ÖÂÈκÎÈ˶¼¿ÉÒÔÕÒµ½²¢»á¼û¸ÃÊý¾Ý¿â ¡£¡£¡£¡£¡£Ã½ÌåÒѾ­¶ÔÆäÖÐһЩ¼Í¼¾ÙÐÐÑéÖ¤ £¬£¬£¬£¬£¬£¬£¬»¹·¢Ã÷²¿·Ö¼Í¼°üÀ¨Óû§µÄÐÕÃû¡¢ÐÔ±ðºÍ¹ú¼Ò/µØÇøÎ»Öà ¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://threatpost.com/leaky-server-exposes-419m-phone-numbers-of-facebook-users/148029/

4¡¢Ó¢¹ú¹ú¾Û»áÔ±ÔÚ2019²ÆÄêÎüÊÕµ½½ü2100Íò·âÀ¬»øÓʼþ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ƾ֤һÏîFOIÉêÇëÅû¶µÄÐÅÏ¢ £¬£¬£¬£¬£¬£¬£¬Ó¢¹ú¹ú¾Û»áÔ±ºÍÒé»áÊÂÇéÖ°Ô±ÔÚ2019²ÆÄê¶ÈÊÕµ½Á˽ü2100Íò·âÀ¬»øÓʼþ ¡£¡£¡£¡£¡£ÕâЩÀ¬»øÓʼþ°üÀ¨Á˶àÖÖDZÔڵĶñÒâÍþв £¬£¬£¬£¬£¬£¬£¬°üÀ¨ÍøÂç´¹ÂÚ¡¢¶ñÒâÁ´½Ó¡¢¶ñÒ⸽¼þÒÔ¼°ÆäËü¹¥»÷Õ½ÂÔµÈ ¡£¡£¡£¡£¡£2018²ÆÄêµÄ¼Í¼²¢²»ÍêÕû £¬£¬£¬£¬£¬£¬£¬È»¶øÔÚÓмͼµÄ°ëÄêÄÚ¸ÃÊý×ÖΪ1430Íò·â ¡£¡£¡£¡£¡£ÕâÅú×¢2019²ÆÄê¶ÈÕâЩÀ¬»øÓʼþµÄÊýÄ¿ÓÐËùïÔÌ­ £¬£¬£¬£¬£¬£¬£¬Ò²¿ÉÄÜÊÇÓʼþÇå¾²Íø¹ØµÄÐÔÄÜÕýÔÚϽµ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/mps-bombarded-spam-brexit-no-deal/

5¡¢Windows 10 KB4512941¸üе¼ÖÂCortanaÕ¼ÓÃCPU¹ý¸ß


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ÔÚ×°ÖÃÁËÉÏÖÜÕë¶ÔWindows 10 v1903µÄKB4512941ÀÛ»ý¸üÐÂºó £¬£¬£¬£¬£¬£¬£¬Ò»Ð©Óû§±¨¸æ³ÆCortanaµÄSearchUI.exeÀú³ÌÌåÏÖ³ö¹ý¸ßµÄCPUÕ¼ÓÃÂÊ ¡£¡£¡£¡£¡£ÕâÊÇÓÉÓڸð汾CortanaÖеĹýʧµ¼Ö £¬£¬£¬£¬£¬£¬£¬µ±Óû§½ûÓÃÁËÏòBing·¢ËÍÍâµØËÑË÷µÄÄÜÁ¦Ê±£¨ÎÞÂÛÊÇͨ¹ý×¢²á±íÕÕ¾Éͨ¹ý×éÕ½ÂÔ£© £¬£¬£¬£¬£¬£¬£¬Cortana½«Õ¼Óôó×ÚCPU²¢ÇÒWindowsËÑË÷¿ÉÄÜ»áÏÔʾ¿ÕËÑË÷Ч¹û ¡£¡£¡£¡£¡£Òª½â¾ö´ËÎÊÌâ £¬£¬£¬£¬£¬£¬£¬Óû§¿ÉÒÔÑ¡Ôñ£ºÆôÓÃBingSearch £¬£¬£¬£¬£¬£¬£¬½«Cortana CacheÎļþ¼ÐÌæ»»Îª¾É°æ±¾ £¬£¬£¬£¬£¬£¬£¬»òÐ¶ÔØ¸üР¡£¡£¡£¡£¡£Ä¿½ñ΢ÈíÉÐδÔÚKB4512941µÄÖ§³Öͨ¸æÖÐÈ·ÈϸÃÎÊÌâ ¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/microsoft/windows-10-kb4512941-update-causing-high-cpu-usage-in-cortana/