ÐÅÏ¢Äþ¾²Öܱ¨-2018ÄêµÚ28ÖÜ

Ðû²¼Ê±¼ä 2018-07-16

Ò»¡¢±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


        2018Äê07ÔÂ09ÈÕÖÁ15ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´63¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇMicrosoft Edge Chakra½Å±¾ÒýÇæÔ¶³ÌÄÚ´æÆÆ»µÂ©¶´£»Microsoft Skype for Business CVE-2018-8311Ô¶³Ì´úÂëÖ´ÐЩ¶´£»Adobe Acrobat/Reader CVE-2018-4888ÊͷźóÀûÓôúÂëÖ´ÐЩ¶´£»TP-Link TL-WR841N CVE-2018-12577ÃüÁî×¢Èë©¶´£»Desdev DedeCMSÈÎÒâÎļþÉÏ´«Â©¶´¡£

 

        ±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇÃÀ¹ú¿¨Ë¹µØÓòµÄÒ½ÁÆÖÐÐÄÔ⵽δ֪ÀÕË÷Èí¼þµÄ¹¥»÷£»VSDC¹ÙÍø1¸öÔÂÄÚÈý´ÎÔâºÚ¿ÍÈëÇÖ£¬ÆäÈí¼þÏÂÔØÁ´½Ó±»½Ù³Ö£»Chrome²å¼þHola VPNÔ⺧£¬Ô­²å¼þ±»Ö²Èë¶ñÒâ´úÂ룻TimehopÔâºÚ¿ÍÈëÇÖ£¬Áè¼Ý2100ÍòÓû§µÄÊý¾Ýй¶£»Domain FactoryÈ·ÈÏÔÚ1Ô·ÝÔâºÚ¿ÍÈëÇÖ£¬²¿ÃÅÓû§µÄÊý¾Ýй¶¡£

 

        ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£

 

¶þ¡¢ÖØÒªÄþ¾²Â©¶´Áбí


1¡¢Microsoft Edge Chakra½Å±¾ÒýÇæÔ¶³ÌÄÚ´æÆÆ»µÂ©¶´

 

        Microsoft EdgeChakra½Å±¾ÒýÇæÃ»ÓÐÕýÈ·µÄ´¦ÖÃÄÚ´æÖеŤ¾ß£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓé¶´Ìá½»ÌØÊâµÄWEBÒ³ÇëÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£

 

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÄþ¾²²¹¶¡ÒÔÐÞ¸´¸Ã©¶´£º

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8294


2¡¢Microsoft Skype for Business CVE-2018-8311Ô¶³Ì´úÂëÖ´ÐЩ¶´

 

        Microsoft Skype for Business 2016ûÓÐÕýÈ·µÄ¹ýÂËÌØÖÆµÄÄÚÈÝ£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓé¶´Ìá½»ÌØÊâµÄÇëÇó£¬ÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£

 

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÄþ¾²²¹¶¡ÒÔÐÞ¸´¸Ã©¶´£º

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8311


3¡¢Adobe Acrobat/Reader CVE-2018-4888ÊͷźóÀûÓôúÂëÖ´ÐЩ¶´

 

        Adobe Acrobat/Reader XFAÒýÇæÊµÏÖ´æÔÚÊͷźóÀûÓé¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓé¶´Ìá½»ÌØÊâµÄÎļþÇëÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£

 

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÄþ¾²²¹¶¡ÒÔÐÞ¸´¸Ã©¶´£ºhttps://helpx.adobe.com/security/products/acrobat/apsb18-02.html


4¡¢TP-Link TL-WR841N CVE-2018-12577ÃüÁî×¢Èë©¶´

        TP-Link TL-WR841N Ping¼°Traceroute¹¦Ð§´æÔÚÊäÈëÑé֤©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓé¶´Ìá½»ÌØÊâµÄÇëÇó£¬ÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâÃüÁî¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÄþ¾²²¹¶¡ÒÔÐÞ¸´¸Ã©¶´£ºhttps://software-talk.org/blog/2018/06/tplink-wr841n-code-exec-cve-2018-12577/


5¡¢Desdev DedeCMSÈÎÒâÎļþÉÏ´«Â©¶´

 

        DedeCMS dede/file_manage_control.phpÎļþ´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓé¶´Ìá½»ÌØÊâµÄupfile1¡¯²ÎÊýÇëÇó£¬ÉÏ´«ÈÎÒâÎļþ¡£

 

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÄþ¾²²¹¶¡ÒÔÐÞ¸´¸Ã©¶´£ºhttps://github.com/SukaraLin/php_code_audit_project/blob/master/dedecms/dedecms%20v5.7%20sp2%20%E4%BB%A3%E7%A0%81%E5%AE%A1%E8%AE%A1.md

 

Èý¡¢ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢ÃÀ¹ú¿¨Ë¹µØÓòµÄÒ½ÁÆÖÐÐÄÔ⵽δ֪ÀÕË÷Èí¼þµÄ¹¥»÷

 

×ðÁú¶¶È¦ - Ϊdu¶øÉú


        ÃÀ¹úÃÜËÕÀïÖÝ¿¨Ë¹µØÓòµÄÒ½ÁÆÖÐÐÄ³ÆÆäÔ⵽δ֪ÀÕË÷Èí¼þµÄ¹¥»÷£¬ÆäÄÚ²¿Í¨ÐÅϵͳºÍµç×Ó½¡¿µµµ°¸ÏµÍ³£¨EHR£©ÊÜÓ°Ïì¡£¸ÃÒ½ÁÆÖÐÐijÆÃ»ÓÐÖ¤¾Ý±íÃ÷»¼ÕßµÄÊý¾Ý±»·ÃÎÊ¡£Ä¿Ç°»¹²»Çå³þÆä¼ÆËã»ú/·þÎñÆ÷ÈçºÎ±»Ñ¬È¾£¬µ«Ïà¹ØÖ´·¨²¿ÃÅÒѾ­½éÈë½øÐÐÊӲ졣

 

        Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/cass-regional-medical-center-hit-with-unidentified-ransomware/

 

2¡¢VSDC¹ÙÍø1¸öÔÂÄÚÈý´ÎÔâºÚ¿ÍÈëÇÖ£¬ÆäÈí¼þÏÂÔØÁ´½Ó±»½Ù³Ö

 

×ðÁú¶¶È¦ - Ϊdu¶øÉú


        VSDCÊÇÒ»¼ÒÌṩÃâ·ÑÊÓÆµ±à¼­Èí¼þµÄ¹«Ë¾£¬Æä¹ÙÍøÔÚ1¸öÔÂÄÚÈý´ÎÔâµ½ºÚ¿ÍÈëÇÖ£¨6ÔÂ18ÈÕ¡¢7ÔÂ2ÈÕºÍ7ÔÂ6ÈÕ£©£¬¹¥»÷Õß½«ÆäVSDCÈí¼þµÄÏÂÔØÁ´½ÓÌæ»»Îª¶ñÒâÁ´½Ó£¬·Ö±ð½«Óû§Öض¨ÏòÖÁÈý¸ö¶ñÒâÈí¼þ£¨Ò»¸öÓÃÓÚÇÔÈ¡Óû§ÐÅÏ¢µÄ¶ñÒâÈí¼þ£¬Ò»¸ö¼üÅ̼ǼÆ÷ºÍÒ»¸öÔ¶¿ØÄ¾ÂíRAT£©¡£VSDCÈ·ÈÏÁËÕâЩʼþ£¬²¢³ÆÆäÒѾ­ÐÞ¸´ÁËÍøÕ¾¡£

 

        Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/popular-software-site-hacked-to-redirect-users-to-keylogger-infostealer-more/

 

3¡¢Chrome²å¼þHola VPNÔ⺧£¬Ô­²å¼þ±»Ö²Èë¶ñÒâ´úÂë

 

×ðÁú¶¶È¦ - Ϊdu¶øÉú


        Chrome²å¼þHola VPNµÄ¿ª·¢ÕßÕË»§ÔâºÚ¿ÍÈëÇÖ£¬Æä²å¼þ±»Ö²Èë¶ñÒâ´úÂ룬ÓÃÓÚ½«MyEtherWallet.comÍøÕ¾µÄÓû§Öض¨ÏòÖÁµöÓãÍøÕ¾¡£´Ë´Î¹¥»÷·¢ÉúÔÚ7ÔÂ9ÈÕ£¬¹²Á¬ÐøÁË5¸öСʱ£¬Ä¿Ç°¸Ã²å¼þÒѻָ´ÖÁ½à¾»µÄ°æ±¾¡£Hola VPNÍŶÓûÓÐ͸¶¹¥»÷ÕßÈçºÎ½øÈëÆäChrome¿ª·¢ÕßÕË»§¡£MEWÍŶÓÕýÔÚ¶½´ÙʹÓô˲å¼þµÄÓû§½«Æä¼ÓÃÜ»õ±Ò×ªÒÆÖÁеÄÕË»§£¬ÒÔÈ·±£Äþ¾²¡£

 

        Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/hacker-breaches-hola-vpn-chrome-extension-to-go-after-cryptocurrency-wallet-site/

 

4¡¢TimehopÔâºÚ¿ÍÈëÇÖ£¬Áè¼Ý2100ÍòÓû§µÄÊý¾Ýй¶

 

×ðÁú¶¶È¦ - Ϊdu¶øÉú


        Gentoo Linux¿ª·¢ÍŶÓÐû²¼¹ØÓÚGitHubÕË»§ÔâºÚ¿ÍÈëÇÖʼþµÄÊÓ²ì³ÂËß¡£¸ÃÍŶӳƹ¥»÷Õßͨ¹ýÃÜÂëÍÆ²â»ñµÃÆäGitHubÕË»§µÄÃÜÂë¼°¹ÜÀíȨÏÞ£¬ÊӲ췢ÏÖµÄÎÊÌ⻹°üÂÞδ½ÓÄÉË«ÒòËØÈÏÖ¤¡¢Î´Éú´æGitHub OrganizationÏêϸÐÅÏ¢µÄ±¸·ÝÒÔ¼°systemd repoÖ±½Ó´æ´¢ÔÚGitHubÉÏ¡£ÐÒÔ˵ÄÊÇ£¬GentooºÍGithub¶Ô¸ÃʼþµÄÏìÓ¦½Ï¼°Ê±£¬Ê¹µÃ¹¥»÷Ö»Á¬ÐøÁËÔ¼70·ÖÖÓ¡£

 

        Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/07/timehop-data-breach.html

 

5¡¢Domain FactoryÈ·ÈÏÔÚ1Ô·ÝÔâºÚ¿ÍÈëÇÖ£¬²¿ÃÅÓû§µÄÊý¾Ýй¶

 

×ðÁú¶¶È¦ - Ϊdu¶øÉú



        µÂ¹úÍйܷþÎñÌṩÉÌDomainFactoryÈ·ÈÏÔÚ1Ô·ݷ¢ÉúÊý¾Ýй¶Ê¼þ£¬²¿ÃÅÓû§µÄ¸öÈËÊý¾Ýй¶£¬µ«¸Ã¹«Ë¾Î´Åû¶¾ßÌåµÄÊý×Ö¡£Ð¹Â¶µÄÊý¾Ý°üÂÞÓû§µÄÐÕÃû¡¢¹«Ë¾Ãû¡¢ÕË»§ID¡¢µØÖ·¡¢µç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂë¡¢³öÉúÈÕÆÚ¡¢ÒøÐп¨Õ˺ŵÈÐÅÏ¢£¬ÍøÂç·¸×ï·Ö×Ó¿ÉÀûÓÃÕâЩÊý¾Ý½øÐÐÓÐÕë¶ÔÐÔµÄÉç»á¹¤³Ì¹¥»÷¡£DomainFactory½¨ÒéËùÓÐÓû§ÐÞ¸ÄÆäÃÜÂë¡£

 

        Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/07/web-hosting-server-hack.html