ÐÅÏ¢Äþ¾²Öܱ¨-2018ÄêµÚ34ÖÜ

Ðû²¼Ê±¼ä 2018-08-27

Ò»¡¢±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


        2018Äê08ÔÂ20ÈÕÖÁ26ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´51¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇApache Struts 2 CVE-2018-11776´úÂëÖ´ÐЩ¶´£»Adobe Photoshop CC CVE-2018-12811ÄÚ´æÆÆ»µÂ©¶´£»Philips IntelliSpace CardiovascularÅäÖùÜÀíȨÏÞÌáÉý©¶´£»SambaĿ¼ÁÐ±í³¤Îļþ¼ì²é´úÂëÖ´ÐЩ¶´£»Emerson Electric DeltaV CVE-2018-14793»º³åÇøÒç³ö©¶´¡£


        ±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇÑо¿ÍŶӷ¢ÏÖ³¯ÏÊAPT×éÖ¯DarkhotelÀûÓÃVBScript½Å±¾ÒýÇæ0dayµÄ¹¥»÷»î¶¯£»Ñо¿±íÃ÷GDPRʵʩºóÅ·ÃËÐÂÎÅÍøÕ¾ÉϵĵÚÈý·½cookieÊýÁ¿Ï½µÁË22%£»ÃÀAugustaÒ½ÁÆÖÐÐÄÈ·ÈÏ2017Äê9ÔÂÔ¼41.7Íò»¼ÕßµÄÐÅϢй¶£»±£Ä··þÎñSitterÒòMongoDBÅäÖôíÎóµ¼ÖÂÁè¼Ý9.3ÍòÓû§µÄÐÅϢй¶£»Cheddar Scratch KitchenÔâºÚ¿ÍÈëÇÖ£¬Ô¼56ÍòÓû§µÄÒøÐп¨ÐÅϢй¶¡£


        ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£


 


¶þ¡¢ÖØÒªÄþ¾²Â©¶´Áбí


1¡¢Apache Struts 2 CVE-2018-11776´úÂëÖ´ÐЩ¶´


        Apache Struts½ç˵XMLÅäÖÃnamespaceֵΪͨÅä·û(¡°/*¡±)£¬»òÔÚÉϲãactionÖÐnamespaceֵȱʡʱ£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓé¶´Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£


        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÄþ¾²²¹¶¡ÒÔÐÞ¸´¸Ã©¶´£ºhttps://cwiki.apache.org/confluence/display/WW/S2-057
2¡¢Adobe Photoshop CC CVE-2018-12811ÄÚ´æÆÆ»µÂ©¶´


        Adobe Photoshop CC´¦ÖÃÎļþ´æÔÚÄÚ´æÆÆ»µÂ©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓé¶´Ìá½»ÌØÊâµÄÎļþÇëÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐÈÎÒâ´úÂë¡£


        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÄþ¾²²¹¶¡ÒÔÐÞ¸´¸Ã©¶´£ºhttps://helpx.adobe.com/security/products/photoshop/apsb18-28.html


3¡¢Philips IntelliSpace CardiovascularÅäÖùÜÀíȨÏÞÌáÉý©¶´


        Philips IntelliSpace CardiovascularûÓнøÐÐÕýÈ·µÄȨÏÞ¹ÜÀí£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓé¶´Ìá½»ÌØÊâµÄÇëÇó£¬ÌáÉýȨÏÞ¡£


        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÄþ¾²²¹¶¡ÒÔÐÞ¸´¸Ã©¶´£ºhttps://ics-cert.us-cert.gov/advisories/ICSMA-18-226-01
4¡¢SambaĿ¼ÁÐ±í³¤Îļþ¼ì²é´úÂëÖ´ÐЩ¶´


        samba¿Í»§¶ËûÓгäʵµÄ¼ì²âĿ¼ÁбíÖйý³¤µÄÎļþÃû£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓé¶´Ìá½»ÌØÊâµÄ¶ñÒâSAMBA·þÎñÆ÷ÇëÇó£¬Ö´ÐÐÈÎÒâ´úÂë¡£


        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÄþ¾²²¹¶¡ÒÔÐÞ¸´¸Ã©¶´£ºhttps://www.samba.org/samba/security/CVE-2018-10858.html


5¡¢Emerson Electric DeltaV CVE-2018-14793»º³åÇøÒç³ö©¶´


        Emerson Electric DeltaV´æÔÚ»ùÓÚÕ»µÄ»º³åÇøÒç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓé¶´Ìá½»ÌØÊâµÄÇëÇó£¬Ö´ÐÐÈÎÒâ´úÂë¡£


        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÄþ¾²²¹¶¡ÒÔÐÞ¸´¸Ã©¶´£ºhttps://ics-cert.us-cert.gov/advisories/ICSA-18-228-01


 


Èý¡¢ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢Ñо¿ÍŶӷ¢ÏÖ³¯ÏÊAPT×éÖ¯DarkhotelÀûÓÃVBScript½Å±¾ÒýÇæ0dayµÄ¹¥»÷»î¶¯ 



×ðÁú¶¶È¦ - Ϊdu¶øÉú


        Ç÷ÊÆ¿Æ¼¼µÄÄþ¾²Ñо¿ÍŶӷ¢ÏÖ³¯ÏÊAPT×éÖ¯DarkhotelÕýÔÚÀûÓÃ΢ÈíVBScript½Å±¾ÒýÇæÖеÄÁãÈÕ©¶´£¨CVE-2018-8373£©Ìᳫ¹¥»÷»î¶¯£¬¸Ã©¶´ÊÇÒ»¸öuse-after-free©¶´£¬¿ÉÔÊÐí¹¥»÷ÕßÔÚÄ¿±ê¼ÆËã»úÉÏÔËÐÐshellcode¡£ÔÚ×îа汾µÄWindowsÖУ¬Î¢ÈíÔÚä¯ÀÀÆ÷µÄĬÈÏÅäÖÃÖнûÓÃÁËVBScript£¬Ê¹Æä²»Ò×Êܵ½¹¥»÷¡£Î¢ÈíÒÑÔÚ8ÔÂÄþ¾²¸üÐÂÖÐÐÞ¸´ÁË´Ë©¶´¡£


        Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/zero-day-in-microsofts-vbscript-engine-used-by-darkhotel-apt/


2¡¢Ñо¿±íÃ÷GDPRʵʩºóÅ·ÃËÐÂÎÅÍøÕ¾ÉϵĵÚÈý·½cookieÊýÁ¿Ï½µÁË22%



×ðÁú¶¶È¦ - Ϊdu¶øÉú



        ƾ¾ÝÅ£½ò´óѧReuters InstituteµÄÒ»·Ý³ÂËߣ¬Å·ÃËÐÂÎÅÍøÕ¾ÉϵĵÚÈý·½cookieµÄÊýÁ¿ÔÚGDPRʵʩºóϽµÁË22%¡£¸Ã³ÂËß·Ö±ð·ÖÎöÁË2018Äê4ÔÂÒÔ¼°7ÔµÄÊý¾Ý£¬º­¸ÇÁË·ÒÀ¼¡¢·¨¹ú¡¢µÂ¹ú¡¢Òâ´óÀû¡¢²¨À¼¡¢Î÷°àÑÀºÍÓ¢¹úÆß¸ö¹ú¼ÒµÄ200¸öÐÂÎÅÍøÕ¾¡£Ï½µ·ù¶È×î´óµÄÊÇÓ¢¹ú£¬ÆäÐÂÎÅÍøÕ¾Ê¹Óõĸú×Ùcookie±ÈGDPRʵʩǰ¼õÉÙÁË45%¡£Ï½µ·ù¶È×îСµÄÊǵ¹ú£¬Îª6%¡£¶ø²¨À¼ÔòÊÇΨһһ¸öcookieÊýÁ¿Ôö³¤µÄ¹ú¼Ò£¬Ôö³¤·ù¶ÈΪ20%¡£


        Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/technology/number-of-third-party-cookies-on-eu-news-sites-dropped-by-22-percent-post-gdpr/


3¡¢ÃÀAugustaÒ½ÁÆÖÐÐÄÈ·ÈÏ2017Äê9ÔÂÔ¼41.7Íò»¼ÕßµÄÐÅϢй¶



×ðÁú¶¶È¦ - Ϊdu¶øÉú


        ÃÀ¹úAugustaÒ½ÁÆÖÐÐÄ7ÔÂ31ÈÕµÄÊÓ²ì½á¹ûÏÔʾ£¬2017Äê9ÔÂÕë¶ÔÆäÒ½ÁÆÊÂÇéÈËÔ±µÄÍøÂçµöÓã¹¥»÷µ¼ÖÂÔ¼41.7Íò»¼ÕßµÄÊý¾Ý±»ÇÔ¡£Ð¹Â¶µÄÊý¾Ý°üÂÞµØÖ·¡¢³öÉúÈÕÆÚ¡¢Ò½ÁƼǼ±àºÅ¡¢ÖÎÁƺÍÊÖÊõÐÅÏ¢¡¢Õï¶Ï½á¹û¡¢Ò©ÎïÒÔ¼°±£ÏÕÐÅÏ¢µÈ£¬ÉõÖÁ°üÂÞ²¿ÃÅ»¼ÕßµÄÉç±£ºÅÂëºÍ¼ÝÕÕºÅÂë¡£ÕâЩÐÅÏ¢¿ÉÄܻᱻºóÐøµÄÍøÂçµöÓã¹¥»÷¡¢Éí·ÝÆÛÕ©»î¶¯ÉõÖÁÀÕË÷»î¶¯ËùÀûÓá£


        Ô­ÎÄÁ´½Ó£ºhttps://www.infosecurity-magazine.com/news/augusta-health-center-reveals/


4¡¢±£Ä··þÎñSitterÒòMongoDBÅäÖôíÎóµ¼ÖÂÁè¼Ý9.3ÍòÓû§µÄÐÅϢй¶



×ðÁú¶¶È¦ - Ϊdu¶øÉú



        8ÔÂ14ÈÕÄþ¾²Ñо¿ÈËÔ±Bob Diachenko·¢ÏÖ±£Ä··þÎñSitterµÄÒ»¸öMongoDB¿Éͨ¹ý»¥ÁªÍø¹ûÈ»·ÃÎÊ£¨ÎÞÐèµÇ¼ƾ¾Ý£©£¬Áè¼Ý9.3ÍòÃûÓû§µÄÃô¸ÐÊý¾Ýй¶¡£Ð¹Â¶µÄÊý¾Ý°üÂÞÕË»§µÄÃÜÂë¹þÏ£¡¢Ã¿¸ö¼ÒÍ¥µÄº¢×ÓÊý¡¢¼ÒÍ¥µØÖ·¡¢µç»°ºÅÂë¡¢ÁªÏµÈËÁÐ±í¡¢Ö§¸¶¿¨ºÅÒÔ¼°appÄÚµÄÁÄÌìÐÅÏ¢µÈ¡£Êý¾Ý×ÜÁ¿Áè¼Ý2GB¡£


        Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/mongodb-server-exposes-babysitting-apps-database/


5¡¢Cheddar Scratch KitchenÔâºÚ¿ÍÈëÇÖ£¬Ô¼56ÍòÓû§µÄÒøÐп¨ÐÅϢй¶
×ðÁú¶¶È¦ - Ϊdu¶øÉú



        Cheddar Scratch KitchenÓÚ2018Äê8ÔÂ16ÈÕÊÕµ½Áª°îÕþ¸®µÄ¾¯¸æ£¬³ÆÆäPoSϵͳÔâµ½ºÚ¿ÍÈëÇÖ¡£Ä¿Ç°ÔÚ°µÍøÉÏÏúÊÛµÄÏà¹ØÒøÐп¨ÐÅϢԼΪ56.7ÍòÕÅ¡£ÊÓ²ì±íÃ÷£¬¹¥»÷ÕßÔøÓÚ2017Äê11ÔÂ3ÈÕÖÁ2018Äê1ÔÂ2ÈÕÆÚ¼äÈëÇÖÁ˸ù«Ë¾µÄÍøÂç¡£¸Ã¹«Ë¾³Æ2018Äê4ÔÂ10ÈÕÒÔÀ´ÆäÒÑʹÓÃÁËеÄPoSϵͳ£¬ÕâÒâζ×ŵ±Ç°µÄÖ§¸¶ÏµÍ³ºÍÍøÂç²»ÊÜÓ°Ïì¡£Cheddar Scratch KitchenÔÚ23¸öÖݶ¼Óзֵ꣬¸Ã¹«Ë¾ÕýÔÚÏòÊÜÓ°ÏìµÄÓû§ÌṩÃâ·ÑµÄÉí·Ý±£»¤·þÎñ¡£


        Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/cheddar-scratch-kitchen-exposes-card-data-of-over-500-000/