ÐÅÏ¢°²È«Öܱ¨-2019ÄêµÚ35ÖÜ

°ä²¼¹¦·ò 2019-09-09

 > ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö



2019Äê9ÔÂ02ÈÕÖÁ08ÈÕ¹²ÊÕ¼°²È«·ì϶46¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇBD PyxisδÊÚȨ½Ó¼û·ì϶£»Mozilla Firefox CVE-2019-11741ͨÓÿçÕ¾¾ç±¾¹¥»÷·ì϶£»CA Automic Workload Automation DIA CA Common Services´úÂëÖ´Ðзì϶£»Aruba Mobility Controller WEB×é¼þºÅÁî×¢Èë·ì϶£»Samba CVE-2019-10197Ŀ¼±éÀú·ì϶ ¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇÈýÐÇ¡¢»ªÎªµÈÊÖ»úÒ×ÊÜOMA CP¶ÌÐÅÖ¸ÁîºýŪ¹¥»÷£»FacebookÓû§µç»°ºÅÂëÊý¾Ý¿âй¶£¬Éæ¼°4.19Òڱʼͼ£»FacebookÓû§µç»°ºÅÂëÊý¾Ý¿âй¶£¬Éæ¼°4.19Òڱʼͼ£»Ó¢¹ú¹ú»áÒéÔ±ÔÚ2019²ÆÄê½Ó¹Üµ½½ü2100Íò·âÀ¬»øÓʼþ£»Windows 10 KB4512941¸üе¼ÖÂCortanaÕ¼ÓÃCPU¹ý¸ß ¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖÐ ¡£


> ³ÁÒª°²È«·ì϶Áбí



1. BD PyxisδÊÚȨ½Ó¼û·ì϶


BD PyxisÊÚȨ»úÔì´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Î´ÊÚȨ½Ó¼ûÀûÓà ¡£
https://www.us-cert.gov/ics/advisories/icsma-19-248-01

2. Mozilla Firefox CVE-2019-11741ͨÓÿçÕ¾¾ç±¾¹¥»÷·ì϶


Mozilla FirefoxʵÏÖ´æÔÚͨÓÿçÕ¾¾ç±¾·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄWEB£¬ÓÕʹÓû§½âÎö£¬²Ù¿Øaddons.mozilla.org¼°accounts.firefox.com¿ÉÅú¸ÄÓû§ÅäÖõÈ ¡£
https://www.mozilla.org/en-US/security/advisories/mfsa2019-25/

3. CA Automic Workload Automation DIA CA Common Services´úÂëÖ´Ðзì϶


CA Automic Workload Automation DIA CA Common ServicesʵÏÖ´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉÖ´ÐдúÂë ¡£
https://www.auscert.org.au/bulletins/ESB-2019.3374/

4. Aruba Mobility Controller WEB×é¼þºÅÁî×¢Èë·ì϶


Aruba Mobility Controller WEB×é¼þ´æÔÚºÅÁî×¢Èë·ì϶£¬ÔÊÐíͨ¹ýÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉÖ´ÐÐËÁÒâºÅÁî ¡£
https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2019-004.txt

5. Samba CVE-2019-10197Ŀ¼±éÀú·ì϶


SambaijЩ²ÎÊýÅäÖÃÏ´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉÈÆ¹ýĿ¼ÏÞ¶È£¬Î´ÊÚȨ½Ó¼û ¡£
https://www.samba.org/samba/security/CVE-2019-10197.html


> ³ÁÒª°²È«ÊÂÎñ×ÛÊö



1¡¢ÈýÐÇ¡¢»ªÎªµÈÊÖ»úÒ×ÊÜOMA CP¶ÌÐÅÖ¸ÁîºýŪ¹¥»÷


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


Check Point×êÑÐÈËÔ±·¢ÏÖËļÒÖÇÄÜÊÖ»úÔì×÷ÉÌ£¨Ô̺¬ÈýÐÇ¡¢»ªÎª¡¢LGºÍË÷ÄᣩδÔÚÆäÉ豸ÉÏÖ´Ðа²È«µÄOMA CPÖ¸Áî³ß¶È£¬Ê¹µÃ¹¥»÷ÕßÄܹ»Í¨¹ýαÔìOMA CP¶ÌÐÅÖ¸ÁîÓÕÆ­Óû§Åú¸ÄÉ豸ÅäÖ㬴ӶøÀ¹½ØÆäµç×ÓÓʼþ»òÍøÂçÁ÷Á¿ ¡£OMA CP´ú±íÊ¢¿ªÒƶ¯Í¬Ã˿ͻ§¶ËÅäÖã¬ËüÖ¸µÄÊÇÒÆ¶¯ÔËÓªÉÌ¿Éͨ¹ýÌØ¶¨¶ÌÐŽ«ÍøÂçÉèÖ÷¢Ë͵½Óû§É豸µÄÒ»Öֳ߶È ¡£×êÑÐÈËÔ±³ÆÈýÐǵÄÊÖ»ú×î²»°²È«£¬ÓÉÓÚËüÄܹ»½ÓÊÜÈκÎÀàÐ͵ÄOMA CPÐÂÎŲ¢ÇÒûÓÐÈÏÖ¤»òÑéÖ¤»úÔì ¡£ÈýÐǺÍLG±ðÀëÓÚ5Ô·ݺÍ7Ô·ݰ䲼Á˽¨¸´²¹¶¡£¬»ªÎª°µÊ¾½«±ÉÈËÒ»´úMate»òPϵÁÐÊÖ»úÖвÎÓ뽨¸´²¹¶¡£¬µ«Ë÷Äá»Ø¾øÈϿɸ÷ì϶ ¡£

Ô­ÎÄÁ´½Ó£º
https://www.zdnet.com/article/samsung-huawei-lg-and-sony-phones-vulnerable-to-rogue-provisioning-messages/

2¡¢FacebookÓû§µç»°ºÅÂëÊý¾Ý¿âй¶£¬Éæ¼°4.19Òڱʼͼ


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


×êÑÐÈËÔ±·¢ÏÖÒ»¸ö´æ´¢ÁËÊýÒÚFacebookÓû§µç»°ºÅÂë¼Í¼µÄÊý¾Ý¿âÔÚÍøÉ϶³ö ¡£ÕâЩÊý¾Ý×ÜÊý³¬¹ý4.19Òڱʼͼ£¬º­¸Ç¶à¸öµØÓò£¬ÆäÖÐÔ̺¬1.33ÒÚÌõÃÀ¹úFacebookÓû§¼Í¼¡¢1800ÍòÓ¢¹úÓû§¼Í¼ÒÔ¼°5000¶àÍòÔ½ÄÏÓû§¼Í¼ ¡£¾ßÌå¶øÑÔ£¬Ã¿±Ê¼Í¼¶¼Ô̺¬Óû§µÄΨһFacebook IDºÍÕË»§¹ØÁªµÄµç»°ºÅÂë ¡£ÓÉÓÚ´æ´¢ÕâЩÊý¾ÝµÄ·þÎñÆ÷ûÓÐÊÜÃÜÂë±£»¤£¬µ¼ÖÂÈκÎÈ˶¼Äܹ»ÕÒµ½²¢½Ó¼û¸ÃÊý¾Ý¿â ¡£Ã½ÌåÒѾ­¶ÔÆäÖÐһЩ¼Í¼½øÐÐÑéÖ¤£¬»¹·¢ÏÖ²¿ÃżÍ¼Ô̺¬Óû§µÄÐÕÃû¡¢ÐÔ±ðºÍ¹ú¶È/µØÓòµØÎ» ¡£

Ô­ÎÄÁ´½Ó£º
https://threatpost.com/leaky-server-exposes-419m-phone-numbers-of-facebook-users/148029/

3¡¢FacebookÓû§µç»°ºÅÂëÊý¾Ý¿âй¶£¬Éæ¼°4.19Òڱʼͼ

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


×êÑÐÈËÔ±·¢ÏÖÒ»¸ö´æ´¢ÁËÊýÒÚFacebookÓû§µç»°ºÅÂë¼Í¼µÄÊý¾Ý¿âÔÚÍøÉ϶³ö ¡£ÕâЩÊý¾Ý×ÜÊý³¬¹ý4.19Òڱʼͼ£¬º­¸Ç¶à¸öµØÓò£¬ÆäÖÐÔ̺¬1.33ÒÚÌõÃÀ¹úFacebookÓû§¼Í¼¡¢1800ÍòÓ¢¹úÓû§¼Í¼ÒÔ¼°5000¶àÍòÔ½ÄÏÓû§¼Í¼ ¡£¾ßÌå¶øÑÔ£¬Ã¿±Ê¼Í¼¶¼Ô̺¬Óû§µÄΨһFacebook IDºÍÕË»§¹ØÁªµÄµç»°ºÅÂë ¡£ÓÉÓÚ´æ´¢ÕâЩÊý¾ÝµÄ·þÎñÆ÷ûÓÐÊÜÃÜÂë±£»¤£¬µ¼ÖÂÈκÎÈ˶¼Äܹ»ÕÒµ½²¢½Ó¼û¸ÃÊý¾Ý¿â ¡£Ã½ÌåÒѾ­¶ÔÆäÖÐһЩ¼Í¼½øÐÐÑéÖ¤£¬»¹·¢ÏÖ²¿ÃżÍ¼Ô̺¬Óû§µÄÐÕÃû¡¢ÐÔ±ðºÍ¹ú¶È/µØÓòµØÎ» ¡£

Ô­ÎÄÁ´½Ó£º
https://threatpost.com/leaky-server-exposes-419m-phone-numbers-of-facebook-users/148029/

4¡¢Ó¢¹ú¹ú»áÒéÔ±ÔÚ2019²ÆÄê½Ó¹Üµ½½ü2100Íò·âÀ¬»øÓʼþ


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


ƾ¾ÝÒ»ÏîFOIÉêÇëÅû¶µÄÐÅÏ¢£¬Ó¢¹ú¹ú»áÒéÔ±Äâ¶©ºÏͬ»á¹¤×÷ÈËÔ±ÔÚ2019²ÆÄê¶ÈÊÕµ½Á˽ü2100Íò·âÀ¬»øÓʼþ ¡£ÕâЩÀ¬»øÓʼþÔ̺¬Á˶àÖÖDZÔڵĶñÒâÍþв£¬Ô̺¬ÍøÂç´¹µö¡¢¶ñÒâÁ´½Ó¡¢¶ñÒ⸽¼þÒÔ¼°ÆäËü¹¥»÷Õ½ÊõµÈ ¡£2018²ÆÄêµÄ¼Í¼²¢²»ÆëÈ«£¬È»¶øÔÚÓмͼµÄ°ëÄêÄÚ¸ÃÊý×ÖΪ1430Íò·â ¡£ÕâÅú×¢2019²ÆÄê¶ÈÕâЩÀ¬»øÓʼþµÄÊýÁ¿ÓÐËùÏ÷¼õ£¬Ò²¿ÉÄÜÊÇÓʼþ°²È«Íø¹ØµÄ»úÄܱÉÈ˽µ ¡£


Ô­ÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/mps-bombarded-spam-brexit-no-deal/

5¡¢Windows 10 KB4512941¸üе¼ÖÂCortanaÕ¼ÓÃCPU¹ý¸ß


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


ÔÚ×°ÖÃÁËÉÏÖÜÕë¶ÔWindows 10 v1903µÄKB4512941ÀÛ»ý¸üкó£¬Ò»Ð©Óû§»ã±¨³ÆCortanaµÄSearchUI.exe¹ý³Ì²û·¢³ö¹ý¸ßµÄCPUÕ¼ÓÃÂÊ ¡£ÕâÊÇÓÉÓڸð汾CortanaÖеÄÃýÎóµ¼Ö£¬µ±Óû§½ûÓÃÁËÏòBing·¢Ëͱ¾µØËÑË÷µÄÄÜÁ¦Ê±£¨ÎÞÂÛÊÇͨ¹ý×¢²á±í»¹ÊÇͨ¹ý×éÕ½Êõ£©£¬Cortana½«Õ¼ÓôóÁ¿CPU²¢ÇÒWindowsËÑË÷¿ÉÄÜ»áÏÔʾ¿ÕËÑË÷Á˾Ö ¡£Òª½â¾ö´ËÎÊÌ⣬Óû§Äܹ»Ñ¡Ôñ£ºÆôÓÃBingSearch£¬½«Cortana CacheÎļþ¼Ð´úÌæÎª¾É°æ±¾£¬»òÐ¶ÔØ¸üР¡£µ±Ç°Î¢ÈíÉÐδÔÚKB4512941µÄÖ§³Ö²¼¸æÖÐÈ·ÈϸÃÎÊÌâ ¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/microsoft/windows-10-kb4512941-update-causing-high-cpu-usage-in-cortana/