Oracle7ÔÂÐÞ¸´319¸öÎó²î£»£»£»±£¼ÓÀûÑǹú¼Ò˰Îñ¾ÖÔâºÚ¿ÍÈëÇÖ£»£»£»·Ç¹Ù·½°æTelegram°üÀ¨¶ñÒâ´úÂë

Ðû²¼Ê±¼ä 2019-07-17

1¡¢OracleÐû²¼7ÔÂÖ÷Òª²¹¶¡¸üУ¬£¬£¬ £¬£¬£¬ÐÞ¸´319¸öÎó²î


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


OracleµÄ7ÔÂÖ÷Òª²¹¶¡¸üаüÀ¨319¸öÎó²îµÄÐÞ¸´£¬£¬£¬ £¬£¬£¬ÆäÖÐOracleÊý¾Ý¿âÐÞ¸´ÁË9¸öÎó²î£¬£¬£¬ £¬£¬£¬Communications ApplicationsÐÞ¸´ÁË24¸öÎó²î£¬£¬£¬ £¬£¬£¬E-Business SuiteÐÞ¸´ÁË13¸öÎó²î£¬£¬£¬ £¬£¬£¬Financial Services ApplicationsÐÞ¸´ÁË60¸öÎó²î£¬£¬£¬ £¬£¬£¬Fusion MiddlewareÐÞ¸´ÁË33¸öÎó²î£¬£¬£¬ £¬£¬£¬Java SEÐÞ¸´ÁË10¸öÎó²î£¬£¬£¬ £¬£¬£¬MySQLÐÞ¸´ÁË45¸öÎó²îµÈ¡£¡£¡£¡£ ¡£¡£¡£±ðµÄ£¬£¬£¬ £¬£¬£¬OracleÔÙ´ÎÇ¿µ÷ÁËÕë¶ÔWebLogic ServerµÄÁ½¸öÇå¾²¾¯±¨£ºCVE-2019-2725£¨2019Äê4ÔÂ29ÈÕ£©ºÍCVE-2019-2729£¨2019Äê6ÔÂ18ÈÕ£©¡£¡£¡£¡£ ¡£¡£¡£ÏêϸÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html


2¡¢WordPress²å¼þAd Inserter RCEÎó²î£¬£¬£¬ £¬£¬£¬Ó°Ïì20¶àÍò¸öÍøÕ¾


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


WordPress²å¼þAd InserterÐÞ¸´Ò»¸ö¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐеÄÎó²î¡£¡£¡£¡£ ¡£¡£¡£¸ÃÎó²îÔ´ÓÚʹÓÃcheck_admin_referer£¨£©º¯Êý¾ÙÐÐÊÚȨ£¬£¬£¬ £¬£¬£¬¸Ãº¯ÊýÓÃÓÚ±£»£»£»¤WordPressÕ¾µãÃâÊÜʹÓÃnonceµÄCSRF¹¥»÷¡£¡£¡£¡£ ¡£¡£¡£¾­ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷ÕßÔÚ»ñÈ¡nonceºó£¬£¬£¬ £¬£¬£¬¿ÉÈÆ¹ýcheck_admin_referer£¨£©º¯ÊýµÄÊÚȨ¼ì²é£¬£¬£¬ £¬£¬£¬»á¼ûAd Inserter²å¼þÌṩµÄµ÷ÊÔģʽ£¬£¬£¬ £¬£¬£¬×îÖÕÖ´ÐÐí§ÒâPHP´úÂë¡£¡£¡£¡£ ¡£¡£¡£¸Ã²å¼þ±»×°ÖÃÔÚÖÁÉÙ20Íò¸öÍøÕ¾ÉÏ£¬£¬£¬ £¬£¬£¬½¨ÒéÍøÕ¾ÖÎÀíÔ±½«Æä¸üе½°æ±¾2.4.22¡£¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/critical-bug-in-wordpress-plugin-lets-hackers-execute-code/


3¡¢Zoom RCEÎó²î»¹Ó°ÏìÊÓÆµ¾Û»áÈí¼þRingCentralºÍZhumu


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Ñо¿Ö°Ô±·¢Ã÷macOS°æZoomÖеÄRCEÎó²îÒ²Ó°ÏìÁËÁíÍâÁ½¸öÊ¢ÐеÄÊÓÆµ¾Û»áÈí¼þRingCentralºÍZhumu¡£¡£¡£¡£ ¡£¡£¡£ÆäÖÐRingCentral±»Áè¼Ý35Íò¼ÒÆóҵʹÓ㬣¬£¬ £¬£¬£¬¿ª·¢ÍŶÓÒѾ­Ðû²¼ÁËа汾v7.0.151508.0712£¬£¬£¬ £¬£¬£¬Í¨¹ýɾ³ýÒ×Êܹ¥»÷µÄWebЧÀÍÆ÷À´ÐÞ²¹¸ÃÎó²î¡£¡£¡£¡£ ¡£¡£¡£ZhumuÉÐδÐû²¼ÐÞ¸´²¹¶¡£¬£¬£¬ £¬£¬£¬µ«Óû§ÈÔÈ»¿ÉÒÔͨ¹ýÏàͬµÄÏÂÁîÐ¶ÔØ¸ÃЧÀÍÆ÷¡£¡£¡£¡£ ¡£¡£¡£±ðµÄ£¬£¬£¬ £¬£¬£¬Çå¾²Ñо¿Ô±Karan»¹·¢Ã÷ÁíÍâ8¿îÈí¼þÒ²ÊÜÓ°Ï죬£¬£¬ £¬£¬£¬°üÀ¨Telus Meetings¡¢BT Cloud Phone Meetings¡¢Office Suite HD Meeting¡¢AT&T Video Meetings¡¢BizConf¡¢Huihui¡¢UMeetingºÍZoom CN¡£¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2019/07/zoom-ringcentral-vulnerabilities.html


4¡¢±£¼ÓÀûÑǹú¼Ò˰Îñ¾ÖÔâºÚ¿ÍÈëÇÖ£¬£¬£¬ £¬£¬£¬500¶àÍò¹«ÃñÐÅÏ¢±»µÁ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


¾Ýzdnet±¨µÀ£¬£¬£¬ £¬£¬£¬Ò»ºÚ¿Í×éÖ¯´Ó±£¼ÓÀûÑǹú¼Ò˰Îñ¾Ö£¨NRA£©ÖÐÇÔÈ¡ÁËÔ¼110¸öÊý¾Ý¿â£¬£¬£¬ £¬£¬£¬ÆäÖаüÀ¨½ü21GBµÄСÎÒ˽¼ÒÊý¾Ý£¬£¬£¬ £¬£¬£¬ÊÜÓ°ÏìÈËÊýÁè¼Ý500Íò¡£¡£¡£¡£ ¡£¡£¡£ºÚ¿Í½«²¿·Ö±»µÁÊý¾Ýͨ¹ýµç×ÓÓʼþ·¢Ë͸øÍâµØÃ½Ì壬£¬£¬ £¬£¬£¬µ¼ÖÂÊÂÎñÆØ¹â¡£¡£¡£¡£ ¡£¡£¡£¸Ã¹úÓйز¿·ÖÒѾ­ÈÏ¿ÉÕâÒ»ÊÂÎñ£¬£¬£¬ £¬£¬£¬²¢ÕýÓë±£¼ÓÀûÑǹú¼ÒÇå¾²¾ÖÏàÖúÊӲ졣¡£¡£¡£ ¡£¡£¡£Ð¹Â¶µÄÐÅÏ¢°üÀ¨±£¼ÓÀûÑǹ«ÃñµÄСÎÒ˽¼Òʶ±ðÂ루PIN£©¡¢ÐÕÃû¡¢¼ÒͥסַºÍ²ÆÎñÊÕÈ룬£¬£¬ £¬£¬£¬ÕâЩÊý¾Ý×îÔç¿É×·Ëݵ½2007Äê¡£¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/bulgarias-national-revenue-agency-hacked-to-steal-over-five-million-peoples-data-8e64c8d9


5¡¢·Ç¹Ù·½°æTelegram°üÀ¨¶ñÒâ´úÂ룬£¬£¬ £¬£¬£¬ÏÂÔØÁ¿³¬10Íò´Î


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Ñо¿Ö°Ô±ÔÚGoogle PlayÖз¢Ã÷¶ñÒâÓ¦ÓÃMobonoGram 2019£¬£¬£¬ £¬£¬£¬¸ÃAPPÊÇÒ»¸ö·Ç¹Ù·½°æTelegram£¬£¬£¬ £¬£¬£¬ËüʹÓùٷ½TelegramµÄ´úÂë²¢Ìí¼ÓÁ˶ñÒâ¾ç±¾ÒÔʵÏÖ³¤ÆÚÐÔ²¢¼ÓÔØ´ÓC&CÎüÊÕµÄURL¡£¡£¡£¡£ ¡£¡£¡£¸Ã¶ñÒâAPPµÄÏÂÔØÁ¿Áè¼Ý10Íò´Î£¬£¬£¬ £¬£¬£¬Ö÷ÒªÌṩӢÓïºÍ²¨Ë¹Óï°æ±¾¡£¡£¡£¡£ ¡£¡£¡£±ðµÄ£¬£¬£¬ £¬£¬£¬¸ÃAPPµÄ¿ª·¢Õß»¹Ðû²¼ÁËÁíÒ»¸öÃûΪWhatsgramµÄ¾ßÓÐÏàÙÉÐÐΪµÄ¶ñÒâAPP¡£¡£¡£¡£ ¡£¡£¡£Æ¾Ö¤ÈüÃÅÌú¿ËµÄÊý¾Ý£¬£¬£¬ £¬£¬£¬ÔÚ1ÔÂÖÁ5ÔÂʱ´ú¸Ã¶ñÒâAPPÓÐ1235¸ö¼ì²âЧ¹û£¬£¬£¬ £¬£¬£¬ÆäÖд󲿷ÖλÓÚÃÀ¹ú¡¢ÒÁÀÊ¡¢Ó¡¶ÈºÍ°¢ÁªÇõ¡£¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/unofficial-telegram-app-with-100k-installs-pushed-malicious-sites/


6¡¢Ñо¿Ö°Ô±ÑÝʾÔõÑùʹÓÃiOS URL SchemeʵÑéMITM¹¥»÷


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Ç÷ÊÆ¿Æ¼¼Ñо¿Ö°Ô±ÑÝʾÁËÒ»ÖÖеÄAPP-in-the-middle¹¥»÷£¬£¬£¬ £¬£¬£¬Ëü¿ÉÒÔÔÊÐí×°ÖÃÔÚiOSÉè±¹ØÁ¬Ä¶ñÒâAPPʹÓÃ×Ô½ç˵URL SchemeÇÔÈ¡ÆäËüAPPÖеÄÃô¸ÐÐÅÏ¢¡£¡£¡£¡£ ¡£¡£¡£Ä¬ÈÏÇéÐÎÏÂiOSµÄÿ¸öAPP¶¼ÔÚ×Ô¼ºµÄɳÏäÖÐÔËÐУ¬£¬£¬ £¬£¬£¬µ«URL SchemeÔÊÐíÓû§Í¨¹ýURLÆô¶¯ÆäËüAPP£¬£¬£¬ £¬£¬£¬ÓÉÓÚAppleûÓÐÃ÷È·½ç˵ÄĸöÓ¦ÓÿÉÒÔʹÓÃÄÄЩҪº¦×Ö×÷ΪÆä×Ô½ç˵URL Scheme£¬£¬£¬ £¬£¬£¬Òò´Ë¶à¸öAPP¿ÉÄÜʹÓÃÏàͬµÄURL Scheme£¬£¬£¬ £¬£¬£¬×îÖÕµ¼ÖÂÃô¸ÐÊý¾Ý±»×ª´ïµ½ÁíÒ»¸ö¶ñÒâAPPÖС£¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2019/07/ios-custom-url-scheme.html