ÐÅÏ¢Çå¾²Öܱ¨-2018ÄêµÚ47ÖÜ

Ðû²¼Ê±¼ä 2018-11-26

 ±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


2018Äê11ÔÂ19ÈÕÖÁ25ÈÕ¹²ÊÕ¼Çå¾²Îó²î48¸ö£¬ £¬£¬£¬ £¬£¬ÖµµÃ¹Ø×¢µÄÊÇApache Sparkµ¥»ú×ÊÔ´ÖÎÀíÆ÷í§Òâ´úÂëÖ´ÐÐÎó²î£»£»£»£»£»Dell EMC Avamar Server/EMC Integrated Data Protection Appliance CVE-2018-11077ÏÂÁî×¢ÈëÎó²î£»£»£»£»£»TP-Link TL-R600VPN HTTP Server CVE-2018-3950»º³åÇøÒç³öÎó²î£»£»£»£»£»Adobe Flash PlayerÀàÐÍ»ìÏýÔ¶³Ì´úÂëÖ´ÐÐÎó²î£»£»£»£»£»Google Chrome GPUÊͷźóʹÓÃÎó²î¡£¡£¡£¡£¡£



±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊǰµÍøÍйÜЧÀÍÉÌDaniel's HostingÔâºÚ¿ÍÈëÇÖ£¬ £¬£¬£¬ £¬£¬Áè¼Ý6500¸öÍøÕ¾±»É¾£»£»£»£»£»Ñо¿»ú¹¹Åû¶ͨ¹ýÀ¶ÑÀÈëÇÖÆû³µµÄCarsBlues¹¥»÷£¬ £¬£¬£¬ £¬£¬ÒÉÓ°ÏìÊýÍòÍòÆû³µ£»£»£»£»£»¿¨°Í˹»ùÐû²¼2019ÄêÍøÂçÍþвÇ÷ÊÆµÄÕ¹Íû±¨¸æ£»£»£»£»£»VMwareÐû²¼¸üУ¬ £¬£¬£¬ £¬£¬ÐÞ¸´ÐéÄâ»úÌÓÒÝÎó²îCVE-2018-6983£»£»£»£»£»¼ÓÃÜÓʼþЧÀÍÉÌProtonMailÔâµ½ÒÉËÆÀÕË÷Èí¼þڲƭ¹¥»÷¡£¡£¡£¡£¡£



ƾ֤ÒÔÉÏ×ÛÊö£¬ £¬£¬£¬ £¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£¡£




Ö÷ÒªÇå¾²Îó²îÁбí


1. Apache Sparkµ¥»ú×ÊÔ´ÖÎÀíÆ÷í§Òâ´úÂëÖ´ÐÐÎó²î


Apache Sparkµ¥»ú×ÊÔ´ÖÎÀíÆ÷±£´æÇå¾²Îó²î£¬ £¬£¬£¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó£¬ £¬£¬£¬ £¬£¬ÔÚ¡®master¡¯Ö÷»úÉÏÖ´ÐдúÂë¡£¡£¡£¡£¡£

https://lists.apache.org/thread.html/341c3187f15cdb0d353261d2bfecf2324d56cb7db1339bfc7b30f6e5@%3Cdev.spark.apache.org%3E



2. Dell EMC Avamar Server/EMC Integrated Data Protection Appliance CVE-2018-11077ÏÂÁî×¢ÈëÎó²î


Dell EMC Avamar Server/EMC Integrated Data Protection Appliance±£´æÊäÈëÑéÖ¤Îó²î£¬ £¬£¬£¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó£¬ £¬£¬£¬ £¬£¬ÒÔrootȨÏÞÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£

http://packetstormsecurity.com/files/150420/Dell-EMC-Avamar-IDPA-Command-Injection.html



3. TP-Link TL-R600VPN HTTP Server CVE-2018-3950»º³åÇøÒç³öÎó²î


TP-Link TL-R600VPN HTTP Server±£´æ»º³åÇøÒç³öÎó²î£¬ £¬£¬£¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó£¬ £¬£¬£¬ £¬£¬¿ÉʹϵͳÍ߽⻣»£»£»£»ò¿ÉÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£

https://www.tp-link.com/us/products/details/cat-4909_TL-R600VPN.html



4. Adobe Flash PlayerÀàÐÍ»ìÏýÔ¶³Ì´úÂëÖ´ÐÐÎó²î


Adobe Flash Player±£´æÀàÐÍ»ìÏýÎó²î£¬ £¬£¬£¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþÇëÇó£¬ £¬£¬£¬ £¬£¬ÓÕʹÓû§ÆÊÎö£¬ £¬£¬£¬ £¬£¬¿ÉÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£

https://helpx.adobe.com/security/products/flash-player/apsb18-44.html



5. Google Chrome GPUÊͷźóʹÓÃÎó²î


Google Chrome GPU±£´æÊͷźóʹÓÃÎó²î£¬ £¬£¬£¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄWEBÇëÇó£¬ £¬£¬£¬ £¬£¬¿ÉʹӦÓóÌÐòÍ߽⻣»£»£»£»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£

https://chromereleases.googleblog.com/2018/11/stable-channel-update-for-desktop_19.html





 Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢°µÍøÍйÜЧÀÍÉÌDaniel's HostingÔâºÚ¿ÍÈëÇÖ£¬ £¬£¬£¬ £¬£¬Áè¼Ý6500¸öÍøÕ¾±»É¾

Z6¡¤×ðÁú¿­Ê±¡¸ÖйúÇø¡¹¹Ù·½ÍøÕ¾


11ÔÂ15ÈÕ°µÍø×î´óµÄÍøÂçÍйÜЧÀÍÉÌDaniel's HostingÔâµ½ºÚ¿ÍÈëÇÖ£¬ £¬£¬£¬ £¬£¬¹¥»÷Õßɾ³ýÁË6500¶à¸öÍøÕ¾£¬ £¬£¬£¬ £¬£¬²¢ÇÒÕâÐ©ÍøÕ¾¶¼Ã»Óб¸·Ý¡£¡£¡£¡£¡£¸ÃÍйÜЧÀÍÉ̱³ºóµÄ¿ª·¢Ö°Ô±Daniel Winzen֤ʵ³Æ£¬ £¬£¬£¬ £¬£¬Ð§ÀÍÆ÷µÄrootÕË»§Ò²±»É¾³ýÁË£¬ £¬£¬£¬ £¬£¬²¢ÇÒÆ½Ì¨ÉÏÍйܵÄÁè¼Ý6500¸öÍøÕ¾µÄÊý¾Ý¶¼Òѳ¹µ×ɥʧ¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÄÜÊÇʹÓÃÁËphpÖеÄÁãÈÕÎó²î£¬ £¬£¬£¬ £¬£¬µ«Ò²ÓпÉÄÜÊÇʹÓÃÁËÆäËüµÄÎó²î¡£¡£¡£¡£¡£ÏÖÔÚ»¹Ã»Óй¥»÷ÕßÐû³Æ¶Ô´ËÊÂÈÏÕæ¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/78165/cyber-crime/daniels-hosting-hacked.html


2¡¢Ñо¿»ú¹¹Åû¶ͨ¹ýÀ¶ÑÀÈëÇÖÆû³µµÄCarsBlues¹¥»÷£¬ £¬£¬£¬ £¬£¬ÒÉÓ°ÏìÊýÍòÍòÆû³µ

Z6¡¤×ðÁú¿­Ê±¡¸ÖйúÇø¡¹¹Ù·½ÍøÕ¾


Privacy4Cars·¢Ã÷Ò»ÖÖͨ¹ýÀ¶ÑÀÈëÇÖÆû³µµÄCarsBlues¹¥»÷£¬ £¬£¬£¬ £¬£¬¸Ã¹¥»÷ÒªÁìÓëÏÖ´ú³µÁ¾ÖеijµÔØÓéÀÖϵͳÓйØ£¬ £¬£¬£¬ £¬£¬Í¨¹ýÀ¶ÑÀЭÒ飬 £¬£¬£¬ £¬£¬¹¥»÷Õ߿ɻñµÃÓû§µÄÁªÏµÈËÁÐ±í¡¢Í¨»°¼Í¼¡¢ÎĽñÈÕÖ¾ÉõÖÁÊǶÌÐÅÄÚÈݵÈСÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£¡£¡£Privacy4Cars³ÆÕâÖÖ¹¥»÷Ö»ÐèҪʹÓÃÁ®¼ÛÇÒÒ×ÓÚ»ñµÃµÄÓ²¼þ/Èí¼þÔÚ¼¸·ÖÖÓÄÚ¼´¿ÉÍê³É£¬ £¬£¬£¬ £¬£¬²¢ÇÒ²»ÐèÒª¸ßÉîµÄÊÖÒÕ֪ʶ¡£¡£¡£¡£¡£È«ÇòÊýÍòÍòÁ¾Æû³µÒÉÊܵ½Ó°Ï죬 £¬£¬£¬ £¬£¬²¿·Ö³§ÉÌÒѾ­Ðû²¼Á˸üС£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.privacy4cars.com/can-my-car-be-hacked/default.aspx


3¡¢¿¨°Í˹»ùÐû²¼2019ÄêÍøÂçÍþвÇ÷ÊÆµÄÕ¹Íû±¨¸æ

Z6¡¤×ðÁú¿­Ê±¡¸ÖйúÇø¡¹¹Ù·½ÍøÕ¾


¿¨°Í˹»ùʵÑéÊÒÐû²¼¶Ô2019ÄêÍøÂçÍþвÇ÷ÊÆµÄÒ»¸öÕ¹ÍûÆÊÎö£¬ £¬£¬£¬ £¬£¬Ö÷ÒªÄÚÈݰüÀ¨£º»òÐí²»»áÔÙ·¢Ã÷¸ü¶àµÄ´óÐÍAPT×éÖ¯£»£»£»£»£»ÍøÂçÓ²¼þÓëÎïÁªÍøÍþв½«»áÒ»Ö±ÔöÇ¿£»£»£»£»£»ÓëÍâ½»ºÍÕþÖÎÓйصĹûÕæÅê»÷£»£»£»£»£»¶«ÄÏÑǺÍÖж«µØÇø»òÐí»á·ºÆð¸ü¶àµÄ¹¥»÷×éÖ¯£»£»£»£»£»£¨Ring -£©È¨ÏÞ£¬ £¬£¬£¬ £¬£¬±ÈRing 0¸ü¸ßµÄȨÏÞ£»£»£»£»£»×îÊܽӴýµÄѬȾǰÑÔ-´¹ÂÚ£»£»£»£»£»»ò½«·ºÆð¸ü¶àÀàËÆ¡°°ÂÔËÇýÖ𽢡±µÄ¹¥»÷£»£»£»£»£»¹©Ó¦Á´¹¥»÷½«¼ÌÐø£»£»£»£»£»Òƶ¯¶ñÒâÈí¼þ²»»á·ºÆð´ó±¬·¢£¬ £¬£¬£¬ £¬£¬µ«¸ß¼¶¹¥»÷Õß»á¼ÌÐøÑ°ÕÒÈëÇÖ×°±¸µÄÒªÁì¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º
https://securelist.com/kaspersky-security-bulletin-threat-predictions-for-2019/88878/


4¡¢VMwareÐû²¼¸üУ¬ £¬£¬£¬ £¬£¬ÐÞ¸´ÐéÄâ»úÌÓÒÝÎó²îCVE-2018-6983

Z6¡¤×ðÁú¿­Ê±¡¸ÖйúÇø¡¹¹Ù·½ÍøÕ¾


VMwareÐÞ¸´Ì츮±­ÉÏÅû¶µÄÐéÄâ»úÌÓÒÝÎó²î£¨CVE-2018-6983£©£¬ £¬£¬£¬ £¬£¬¸ÃÎó²îÊÇÒ»¸öÕûÊýÒç³öÎó²î£¬ £¬£¬£¬ £¬£¬ÀÖ³ÉʹÓøÃÎó²î¿Éµ¼ÖÂÐéÄâ»úÌÓÒݲ¢ÔÚËÞÖ÷»úÉÏÖ´ÐдúÂë¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄ²úÆ·°üÀ¨VMware Workstation¡¢VMware FusionµÈ£¬ £¬£¬£¬ £¬£¬VMwareÔÚWorkstation°æ±¾ 14.1.2/15.0.2¼°Fusion°æ±¾10.1.5/11.0.2ÖÐÐÞ¸´Á˸ÃÎó²î£¬ £¬£¬£¬ £¬£¬½¨ÒéÓû§¾¡¿ì¾ÙÐиüС£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º
https://www.vmware.com/security/advisories/VMSA-2018-0030.html


5¡¢¼ÓÃÜÓʼþЧÀÍÉÌProtonMailÔâµ½ÒÉËÆÀÕË÷Èí¼þڲƭ¹¥»÷

Z6¡¤×ðÁú¿­Ê±¡¸ÖйúÇø¡¹¹Ù·½ÍøÕ¾


Ê¢ÐеļÓÃܵç×ÓÓʼþЧÀÍProtonMailÔâµ½ÒÉËÆÀÕË÷Èí¼þڲƭµÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¹¥»÷ÕßAmFearLiathMorÉù³ÆÈëÇÖÁ˸ù«Ë¾²¢ÇÔÈ¡ÁË¡°´ó×Ú¡±µÄÓû§Êý¾Ý¡£¡£¡£¡£¡£¹¥»÷Õß½«ÆäÊê½ðÒªÇóÐû²¼ÔÚPastebinÉÏ£¬ £¬£¬£¬ £¬£¬²¢ÍþвҪÏòÈ«ÌìÏÂÐû²¼»òÏúÊÛÕâЩÊý¾Ý£¬ £¬£¬£¬ £¬£¬µ«²¢Î´Ìṩ±»µÁÊý¾ÝµÄÑù±¾¡£¡£¡£¡£¡£ProtonMailÔÚÊÓ²ìÖ®ºó·ñ¶¨ÁËÕâÆð¹¥»÷ÊÂÎñ£¬ £¬£¬£¬ £¬£¬Éù³ÆÕâÖ»ÊÇÒ»¸öÊÔͼڲƭµÄȦÌס£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/78133/hacking/protonmail-hacked-hoax.html


ÉùÃ÷£º±¾×ÊѶÓÉZ6×ðÁú¿­Ê±Î¬ËûÃüÇ徲С×é·­ÒëºÍÕûÀí