Libarchive´úÂëÖ´ÐÐÎó²îÓ°ÏìLinux¼°BSD¿¯Ðа棻£» £»£»Ç÷ÊÆ¿Æ¼¼ÄÚ²¿Ô±¹¤ÇÔÈ¡Áè¼Ý12ÍòÓû§ÐÅÏ¢²¢³öÊÛ

Ðû²¼Ê±¼ä 2019-11-07
1¡¢Libarchive´úÂëÖ´ÐÐÎó²îÓ°ÏìLinux¼°BSD¿¯Ðаæ

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

¹È¸èÇå¾²Ñо¿Ö°Ô±ÔÚLibarchiveÖз¢Ã÷Ò»¸ö´úÂëÖ´ÐÐÎó²î£¨CVE-2019-18408£©£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÓÕʹÓû§·­¿ª¶ñÒâ´æµµÎļþÔÚÆäϵͳÉÏÖ´ÐдúÂë¡£¡£¡£¡£¡£Debian¡¢Ubuntu¡¢Gentoo¡¢Arch LinuxÒÔ¼°FreeBSDºÍNetBSD¿¯Ðаæ¾ùÊÜÓ°Ï죬£¬£¬£¬£¬£¬£¬µ«WindowsºÍmacOS²»ÊÜÓ°Ïì¡£¡£¡£¡£¡£LibarchiveÍŶÓÔÚа汾3.4.0ÖÐÐÞ¸´Á˸ÃÎó²î£¬£¬£¬£¬£¬£¬£¬ÏÖÔÚÉÐδÔÚÒ°Íâ·¢Ã÷¸ÃÎó²îµÄPoC»òʹÓôúÂë¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/libarchive-vulnerability-can-lead-to-code-execution-on-linux-freebsd-netbsd/

2¡¢¹È¸èÐû²¼11ÔÂAndroidÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬ÐÞ¸´40¸öÎó²î


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


¹È¸è±¾ÖÜÐû²¼11ÔÂAndroidÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬ÐÞ¸´Á˽ü40¸öÎó²î¡£¡£¡£¡£¡£¹È¸èÔÚ2019-11-01Çå¾²²¹¶¡³ÌÐò¼¶±ðÖÐÐÞ¸´ÁËFramework¡¢Library¡¢Ã½Ìå¿ò¼ÜºÍϵͳÖеÄ17¸öÎó²î£¬£¬£¬£¬£¬£¬£¬ÆäÖÐ×îÑÏÖØµÄÎó²îÊÇϵͳ×é¼þÖеÄÈý¸öRCEÎó²î£¨CVE-2019-2204~CVE-2019-2206£©£¬£¬£¬£¬£¬£¬£¬ÊÜÓ°ÏìµÄϵͳ°æ±¾Îª8.0¡¢8.1¡¢9ºÍ10¡£¡£¡£¡£¡£¹È¸è»¹ÔÚ2019-11-05Çå¾²²¹¶¡³ÌÐò¼¶±ðÖÐÐÞ¸´ÁË21¸öÎó²î£¬£¬£¬£¬£¬£¬£¬ÆäÖÐ×îÑÏÖØµÄÊǸßͨ×é¼þÖеÄ5¸öÎó²î¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/google-patches-critical-flaws-androids-system-component

3¡¢NVIDIAÐÞ¸´ÏÔ¿¨Çý¶¯¼°GeForce Experience 12¸öÎó²î

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

NVIDIAÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬£¬£¬ÐÞ¸´ÆäÏÔ¿¨Çý¶¯³ÌÐòºÍGFEÈí¼þÖеÄ12¸öÎó²î£¬£¬£¬£¬£¬£¬£¬Îó²î¹æÄ£º­¸Ç´úÂëÖ´ÐС¢È¨ÏÞÌáÉý¡¢ÐÅϢй¶ºÍ¾Ü¾øÐ§ÀÍ¡£¡£¡£¡£¡£ËùÓеÄÎó²î¶¼²»¿É±»Ô¶³ÌʹÓ㬣¬£¬£¬£¬£¬£¬±ØÐèÍâµØÓû§»á¼û£¬£¬£¬£¬£¬£¬£¬²¢ÇÒ¹¥»÷Õß±ØÐèÒÀÀµÓû§½»»¥À´Ê¹ÓÃËüÃÇ¡£¡£¡£¡£¡£ÕâЩÎó²îµÄCVSS V3ÆÀ·ÖΪ5.1µ½7.8Ö®¼ä£¬£¬£¬£¬£¬£¬£¬ÆäÖÐ4¸ö¸ßΣÎó²îΪÏÔ¿¨Çý¶¯ÖеĻº³åÇøÒç³ö£¨CVE?2019?5690£©¡¢¿ÕÖ¸Õë½âÒýÓã¨CVE?2019?5691£©¡¢Êý×éË÷ÒýÔ½½ç£¨CVE?2019?5692£©ÒÔ¼°GFEÖеÄDLLÐ®ÖÆ£¨CVE?2019?5701£©¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/nvidia-fixes-security-flaws-in-gpu-driver-geforce-experience/

4¡¢FacebookÔÙÆØÒþ˽й¶£¬£¬£¬£¬£¬£¬£¬¿ª·¢Ö°Ô±Î¥¹æ»á¼ûÓû§ÐÅÏ¢


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


FacebookÔÙÆØÒþ˽й¶ÊÂÎñ£¬£¬£¬£¬£¬£¬£¬Ô¼100Ãû¿ª·¢Ö°Ô±¿ÉÎ¥¹æ»á¼ûÓû§ÐÅÏ¢¡£¡£¡£¡£¡£±¾ÖܶþFacebookƽ̨ÏàÖú×ܼàKonstantinos PapamiltiadisÔÚһƪ²©ÎÄÖÐ͸¶£¬£¬£¬£¬£¬£¬£¬Ö»¹Ü2018Äê4ÔÂÔø¶ÔÆäȨÏÞ¾ÙÐÐÏÞÖÆ£¬£¬£¬£¬£¬£¬£¬µ«²¿·Ö¿ª·¢Ö°Ô±ÈÔ¿ÉÒÔ»á¼ûÓû§µÄÐÕÃû¡¢Ð¡ÎÒ˽¼Ò×ÊÁÏͼƬÒÔ¼°ÏµÍ³APIµÈÐÅÏ¢¡£¡£¡£¡£¡£×ܹ²Ô¼ÓÐ100Ãû¿ª·¢Ö°Ô±¿ÉÒÔ»á¼û´ËÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬FacebookÈ·ÈÏÖÁÉÙÓÐ11Ãû¿ª·¢Ö°Ô±ÔÚÒÑÍù60ÌìÄÚ»á¼ûÁËÕâЩÊý¾Ý¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÌåÏÖÒѾ­×÷·ÏÁËÕâÒ»»á¼ûȨÏÞ£¬£¬£¬£¬£¬£¬£¬²¢ÌåÏÖ»á¶ÔÏà¹ØÇéÐξÙÐÐÉó²é¡£¡£¡£¡£¡£¸Ã¹«Ë¾Ã»ÓÐ͸¶Óм¸¶àÓû§Êܵ½Ó°Ïì¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.zdnet.com/article/facebook-reveals-another-data-breach-this-time-involving-developers/

5¡¢Ç÷ÊÆ¿Æ¼¼ÄÚ²¿Ô±¹¤ÇÔÈ¡Áè¼Ý12ÍòÓû§ÐÅÏ¢²¢³öÊÛ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Ç÷ÊÆ¿Æ¼¼ÄÚ²¿Ô±¹¤ÇÔÈ¡¹«Ë¾¿Í»§ÐÅÏ¢²¢½«Æä³öÊÛ¸øµÚÈý·½Õ©Æ­ÍŻ¡£¡£¡£¡£ÔÚ¿Í»§Ôâµ½ÊÖÒÕÖ§³ÖÕ©Æ­ºó£¬£¬£¬£¬£¬£¬£¬Ç÷ÊÆ¿Æ¼¼Õö¿ªÊӲ첢·¢Ã÷¸ÃÔ±¹¤²»·¨»á¼ûÁ˿ͻ§Ö§³ÖÊý¾Ý¿â¡£¡£¡£¡£¡£¿£¿£¿£¿ÉÄܱ»ÇÔµÄÐÅÏ¢°üÀ¨¿Í»§µÄÐÕÃû¡¢µç×ÓÓʼþµØµã¡¢ÊÖÒÕÖ§³Öµ¥ºÅÒÔ¼°µç»°ºÅÂ룬£¬£¬£¬£¬£¬£¬µ«¸Ã¹«Ë¾Ç¿µ÷ûÓм£ÏóÅú×¢²ÆÎñ»òÐÅÓÿ¨ÐÅÏ¢±»ÇÔ£¬£¬£¬£¬£¬£¬£¬²¢ÇÒûÓÐÉæ¼°µ½ÆóÒµ»òÕþ¸®¿Í»§¡£¡£¡£¡£¡£Æ¾Ö¤ÆäÄÚ²¿ÊӲ죬£¬£¬£¬£¬£¬£¬ÊÜÓ°ÏìµÄ¿Í»§Ö»Õ¼Ç÷ÊÆ¿Æ¼¼1200Íò¿Í»§ÈºµÄ²»µ½1%£¬£¬£¬£¬£¬£¬£¬¼´12Íò¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/trendmicro-employee-sold-customer-info-to-tech-support-scammers/

6¡¢AnonymousºÍLulzSecITAÈëÇÖÒâ´óÀûÔËÓªÉÌLyca Mobile


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


AnonymousºÍLulzSecITAÈëÇÖÒâ´óÀûͨѶÔËÓªÉÌLyca Mobile£¬£¬£¬£¬£¬£¬£¬´Ó¸Ã¹«Ë¾ÇÔÈ¡ÁË5.4GBµÄÎļþ¡£¡£¡£¡£¡£´Óй¶µÄÎļþÀ´¿´£¬£¬£¬£¬£¬£¬£¬ÎĵµÖаüÀ¨Lyca MobileÓû§µÄ¹«¹²ID¡¢»¤ÕÕ¡¢¼ÝÕÕ¡¢µç»°¼Í¼¼°ÐÅÓÿ¨ÐÅÏ¢µÈ¡£¡£¡£¡£¡£ÆäÖÐÒ»¸öÎļþ¼ÐµÄÄÚÈÝËÆºõÊôÓڸù«Ë¾µÄ¹Ù·½ÓÊÏäÕË»§lycamobile[at]lycamobile[.]it¡£¡£¡£¡£¡£ÏÖÔÚÉÐÎÞ·¨ÑéÖ¤ÕâЩÎĵµµÄÕæÊµÐÔ¡£¡£¡£¡£¡£ÐÒÔ˵ÄÊǺڿÍ×éÖ¯ÌᳫÕâЩ¹¥»÷Ö»ÊÇΪÁËÑéÖ¤ÆäÇå¾²ÐÔ£¬£¬£¬£¬£¬£¬£¬¶ø²»ÊǶÔÓû§¾ÙÐÐڲƭ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/93474/hacktivism/lulzsecita-lyca-mobile.html