Å·Ã˳ÉÔ±¹ú°ä²¼ÓйØ5GÍøÂ簲ȫµÄ½áºÏ»ã±¨  £»Ó¡¶ÈËÑË÷ÒýÇæJustdial API·ì϶  £»NitroPDF¶à¸öRCE·ì϶

°ä²¼¹¦·ò 2019-10-11
1¡¢Å·Ã˳ÉÔ±¹ú°ä²¼ÓйØ5GÍøÂ簲ȫµÄ½áºÏ»ã±¨

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

Å·ÃË£¨EU£©³ÉÔ±¹ú°ä²¼ÁËÒ»·ÝÓйØ5GÍøÂ簲ȫµÄ·çÏÕÆÀ¹À½áºÏ»ã±¨£¬È·¶¨ÁË5GÍøÂçµÄÖØÒªÍþв¼°Íþв¹¥»÷Õß¡¢×îÃô¸ÐµÄ×ʲúÒÔ¼°Æä±³ºóµÄÖØÒª·ì϶¡£¸Ã»ã±¨Ç¿µ÷ÁËÒÀÀµÓÚµ¥Ò»É豸¹©¸øÉ̵ÄÒþ»¼ÒÔ¼°É豸ǷȱºÍ5G½â¾ö¹æ»®¶àÑùÐÔµÄÎÊÌâ¡£ÕâЩÎÊÌ⼫´óµØÀ©´óÁËEU¼°¹ú¶È²ãÃæµÄ5G»ù´¡ÉèÊ©µÄÕûÌå´àÈõÐÔ¡£¹ý¶ÈÒÀÀµµ¥Ò»É豸¹©¸øÉ̵ÄÅ·ÃËÔËÓªÉÌÃæ¶Ôןù©¸øÉÌ´øÀ´µÄ³ÖÐøÃ³Ò×ѹÁ¦£¬ÎÞÂÛÊÇóÒ×ʧ°Ü¡¢¹é²¢»¹ÊÇÊÕ¹º¡¢»òÊDZ»Ôì²Ã¡£Å·Ã˵Ļ㱨°µÊ¾£¬5GÍøÂç±³ºóµÄ°²È«ÌôÕ½»¹ÓëÍøÂçÓëµÚÈý·½ÏµÍ³Ö®¼äµÄÏνÓÒÔ¼°µÚÈý·½¹©¸øÉ̶ÔÅ·ÃË5GÍøÂçµÄ½Ó¼ûȨÏÞµÄÔö³¤ÓйØ¡£

   

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/eu-member-states-publish-joint-report-on-5g-networks-security/

2¡¢Ó¡¶ÈËÑË÷ÒýÇæJustdial API·ì϶µ¼ÖÂ1.56ÒÚÓû§ÕÊ»§Â¶³ö

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


Ó¡¶È±¾µØËÑË÷ÒýÇæJustdial´æÔÚ°²È«·ì϶£¬µ¼ÖºڿÍÄܹ»µÇ¼Æä1.56ÒÚÓû§ÕÊ»§ÖеÄÈκÎÒ»¸ö¡£³ýÁ˽ӼûÓû§ÐÅÏ¢£¨ÀýÈçÐÕÃû¡¢µç»°ºÅÂëºÍµç×ÓÓʼþµØÖ·£©±í£¬¹¥»÷Õß»¹Äܹ»Í¨¹ý¸Ã¹«Ë¾µÄÖ§¸¶·þÎñJustDial PayÀ´²é¿´Óû§µÄ²ÆÕþÐÅÏ¢£¬Ô̺¬ÕÊ»§µÄÓà¶îºÍÂòÂô¼Í¼¡£¸Ã·ì϶Óɰ²È«×êÑÐÔ±Ehraz Ahmed·¢ÏÖ£¬ËüÀûÓÃÁ˸ÃÍøÕ¾µÄ×¢²áAPI¡£¹¥»÷ÕßÉõÖÁÄܹ»ÀûÓø÷ì϶¸ü¸ÄÓû§µÄJustDial PayÕË»§ÐÅÏ¢£¬´Ó¶øµ¼Ö·¢ËÍÖÁ¸ÃÕË»§µÄËùÓÐ×ʽ𶼱»³Á¶¨Ïò£¬µ«¹¥»÷ÕßÎÞ·¨½øÐлã¿î²Ù×÷£¬ÓÉÓÚÕâ±ØÒª¶î±íµÄPINÂë¡£JustDialÔÚÒ»·ÝÉêÃ÷ÖаµÊ¾¸Ã·ì϶Òѱ»½¨¸´¡£

  

Ô­ÎÄÁ´½Ó£º

https://thenextweb.com/security/2019/10/10/a-bug-in-indian-local-search-app-exposed-over-156-million-accounts/

3¡¢Ó¡µÚ°²ÄÉÖÝijҽԺÔâµ½´¹µö¹¥»÷£¬»¼ÕßÐÅÏ¢¿ÉÄÜй¶

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

Ó¡µÚ°²ÄÉÖÝÎÀÀí¹«»áÒ½Ôº°µÊ¾ÆäÁ½ÃûÔ±¹¤Ôâ´¹µö¹¥»÷£¬6.8Íò»¼ÕßµÄÓ×ÎÒºÍÒ½ÁÆÐÅÏ¢¿ÉÄÜй¶¡£Æ¾¾Ýµ÷²é£¬µÚÒ»ÃûÔ±¹¤µÄÕË»§ÔÚ6ÔÂ12ÈÕ¼°7ÔÂ1ÈÕÖÁ7ÔÂ8ÈÕÔâµÚÈý·½Î´ÊÚȨ½Ó¼û£¬µÚ¶þÃûÔ±¹¤µÄÕË»§ÔòÓÚ3ÔÂ13ÈÕÖÁ6ÔÂ12ÈÕÖ®¼ä¶³ö¡£ÎÀÀí¹«»áÒ½Ôº°µÊ¾¹ÌȻûÓÐÖ¤¾ÝÅú×¢ÏÖʵ»òÊÔͼÀÄÓÃÔ±¹¤ÓÊÏäÕË»§ÖдæÔÚµÄÈκÎÐÅÏ¢£¬µ«µ÷²é²»ÄÜÅųý½Ó¼ûÕÊ»§ÖдæÔÚµÄÊý¾ÝµÄ¿ÉÄÜÐÔ¡£ÕâÁ½¸öÓÊÏäÕË»§ÖÐÔ̺¬»¼ÕßµÄÒÔÏÂÐÅÏ¢£ºÐÕÃû¡¢µØÖ·¡¢Éç»á±£Ïպš¢¼ÝÊ»ÅÆÕÕ/ÖݱêʶºÅ¡¢»¤Õպš¢½ðÈÚÕʺš¢ÒøÐп¨ÐÅÏ¢¡¢µç×ÓÊðÃû¡¢Óû§ÃûºÍÃÜÂë¡¢µ®ÉúÈÕÆÚ¡¢Ò½ÁƼ°Õï¶ÏÐÅÏ¢µÈ¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/phishing-incident-exposes-medical-personal-info-of-60k-patients/

4¡¢¹¥»÷ÕßÀûÓÃWindows°æiTunesÖеķì϶·Ö·¢BitPaymer

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


ÀÕË÷Èí¼þBitPaymer±»·¢´Ë¿Ì¹¥»÷»î¶¯ÖÐÀûÓÃWindows°æiTunesÖеÄ0dayÀ´ÈƹýÊÜϰȾÖ÷»úÉϵķÀ²¡¶¾¼ì²â¡£°²È«³§ÉÌMorphisecÔÚ8Ô·ÝÕë¶ÔÒ»¼ÒÆû³µÆóÒµµÄBitPaymer¹¥»÷Öз¢ÏÖÁËÕâÖÖÐÐΪ¡£¸Ã·ì϶´æÔÚÓÚWindows°æiTunesºÍiCloudÖУ¬Æ»¹ûÓÚ±¾Öܽ¨¸´Á˸Ã0day¡£ÏÖʵµÄ·ì϶´æÔÚÓÚ²úÆ·Ëæ¸½µÄBonjour¸üÐÂ×é¼þÖУ¬¹¥»÷ÕßÄܹ»Æô¶¯Bonjour×é¼þ²¢½Ù³ÔìäÖ´ÐÐõè¾¶£¬½«ÆäÖ¸ÏòBitPaymerÀÕË÷Èí¼þ¡£¸Ã·ì϶²¢²»ÄÜʹBitPaymer»ñµÃÖÎÀíԱȨÏÞ£¬µ«ËüµÄÈ·Äܹ»ºýŪ±¾µØ×°ÖõķÀ²¡¶¾Èí¼þ¡£

Ô­ÎÄÁ´½Ó£º
https://www.zdnet.com/article/ransomware-gang-uses-itunes-zero-day/

5¡¢Ë¼¿ÆTalosÍŶӷ¢ÏÖNitroPDF´æÔÚ¶à¸öRCE·ì϶


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


˼¿ÆTalosÅû¶NitroPDFÖеĶà¸öÔ¶³Ì´úÂëÖ´Ðзì϶¡£Nitro PDFÔÊÐíÓû§ÔÚÆäÍÆËã»úÉϱ£Áô¡¢ÔĶÁºÍ±à×ëPDFÎļþ£¬¸Ã²úÆ··ÖΪÃâ·Ñ°æºÍÊշѰæ¡£Õâ´Î·¢Ïֵķì϶¶¼´æÔÚÓÚÊշѵÄPro°æÖС£·ì϶Ô̺¬jpeg2000 ssizDepthÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2019-5045£©¡¢Page KidsÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2019-5050£©¡¢ICCBasedÉ«²Ê¿Õ¼äÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2019-5048£©¡¢CharProcsÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2019-5047£©¡¢ jpeg2000 yTsizÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2019-5046£©¼°Á÷³¤¶È½âÎöÖ°ÄÜÄÚ´æ°Ü»µ·ì϶£¨CVE-2019-5053£©¡£ÊÜÓ°ÏìµÄ°æ±¾ÎªNitroPDF 12.12.1.522¡£NitroPDFÉÐδ°ä²¼Óйؽ¨¸´²¹¶¡¡£

Ô­ÎÄÁ´½Ó£º
https://blog.talosintelligence.com/2019/10/vuln-spotlight-Nitro-PDF-RCE-bugs-sept-19.html

6¡¢HP½¨¸´Touchpoint AnalyticsÈí¼þÖеÄLPE·ì϶


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


SafeBreach Labs°²È«×êÑÐÔ±Peleg Hadar·¢ÏÖHPµÄTouchPoint Analytics´æÔÚLPE·ì϶£¨CVE-2019-6333£¬CVSS 3ÆÀ·ÖΪ6.7·Ö£©¡£HP TouchPoint AnalyticsÒÔWindows·þÎñµÄ´ó¾ÖԤװÔÚ´óÎÞÊýHPÍÆËã»úÉÏ£¬Ö¼ÔÚÄäÃûÍøÂçÓ²¼þ»úÄÜÕï¶ÏÐÅÏ¢¡£¸ÃWindows·þÎñÓµÓеÚÒ»Á÷´ËÍâNT AUTHORITY\SYSTEMȨÏÞ¡£Hadar°µÊ¾¸Ã·ì϶ÊÇÓɲ»°²È«µÄDLL¼ÓÔØËùÒýÆðµÄ£¬Touchpoint Analytics Client°æ±¾4.1.4.2827ÒÔÏÂÊܵ½Ó°Ïì¡£HPÔÚTouchpoint Analytics Client 4.1.4.2827Öн¨¸´ÁË´Ë·ì϶¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/hp-touchpoint-analytics-lpe-vulnerability-affects-most-hp-pcs