Libarchive´úÂëÖ´Ðзì϶ӰÏìLinux¼°BSD¿¯Ðа棻Ç÷Ïò¿Æ¼¼ÄÚ²¿Ô±¹¤ÇÔÈ¡³¬¹ý12ÍòÓû§ÐÅÏ¢²¢ÏúÊÛ
°ä²¼¹¦·ò 2019-11-07
¹È¸è°²È«×êÑÐÈËÔ±ÔÚLibarchiveÖз¢ÏÖÒ»¸ö´úÂëÖ´Ðзì϶£¨CVE-2019-18408£©£¬¹¥»÷Õß¿ÉÓÕʹÓû§´ò¿ª¶ñÒâ´æµµÎļþÔÚÆäϵͳÉÏÖ´ÐдúÂë¡£Debian¡¢Ubuntu¡¢Gentoo¡¢Arch LinuxÒÔ¼°FreeBSDºÍNetBSD¿¯Ðаæ¾ùÊÜÓ°Ï죬µ«WindowsºÍmacOS²»ÊÜÓ°Ïì¡£LibarchiveÍŶÓÔÚа汾3.4.0Öн¨¸´Á˸÷ì϶£¬Ä¿Ç°ÉÐδÔÚÒ°±í·¢Ïָ÷ì϶µÄPoC»òÀûÓôúÂë¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/libarchive-vulnerability-can-lead-to-code-execution-on-linux-freebsd-netbsd/2¡¢¹È¸è°ä²¼11ÔÂAndroid°²È«¸üУ¬½¨¸´40¸ö·ì϶
¹È¸è±¾Öܰ䲼11ÔÂAndroid°²È«¸üУ¬½¨¸´Á˽ü40¸ö·ì϶¡£¹È¸èÔÚ2019-11-01°²È«²¹¶¡·¨Ê½¼¶±ðÖн¨¸´ÁËFramework¡¢Library¡¢Ã½Ìå¿ò¼ÜºÍϵͳÖеÄ17¸ö·ì϶£¬ÆäÖÐ×îÑϳÁµÄ·ì϶ÊÇϵͳ×é¼þÖеÄÈý¸öRCE·ì϶£¨CVE-2019-2204~CVE-2019-2206£©£¬ÊÜÓ°ÏìµÄϵͳ°æ±¾Îª8.0¡¢8.1¡¢9ºÍ10¡£¹È¸è»¹ÔÚ2019-11-05°²È«²¹¶¡·¨Ê½¼¶±ðÖн¨¸´ÁË21¸ö·ì϶£¬ÆäÖÐ×îÑϳÁµÄÊǸßͨ×é¼þÖеÄ5¸ö·ì϶¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/google-patches-critical-flaws-androids-system-component3¡¢NVIDIA½¨¸´ÏÔ¿¨Çý¶¯¼°GeForce Experience 12¸ö·ì϶
NVIDIA°ä²¼°²È«¸üУ¬½¨¸´ÆäÏÔ¿¨Çý¶¯·¨Ê½ºÍGFEÈí¼þÖеÄ12¸ö·ì϶£¬·ì϶ÁìÓòº¸Ç´úÂëÖ´ÐÓעȨÏÞÌáÉý¡¢ÐÅϢй¶ºÍ»Ø¾ø·þÎñ¡£ËùÓеķì϶¶¼²»Äܱ»Ô¶³ÌÀûÓ㬱ØÐë±¾µØÓû§½Ó¼û£¬²¢ÇÒ¹¥»÷Õß±ØÐëÒÀÀµÓû§½»»¥À´ÀûÓÃËüÃÇ¡£ÕâЩ·ì϶µÄCVSS V3ÆÀ·ÖΪ5.1µ½7.8Ö®¼ä£¬ÆäÖÐ4¸ö¸ßΣ·ì϶ΪÏÔ¿¨Çý¶¯ÖеĻº³åÇøÒç³ö£¨CVE?2019?5690£©¡¢¿ÕÖ¸Õë½âÒýÓã¨CVE?2019?5691£©¡¢Êý×éË÷ÒýÔ½½ç£¨CVE?2019?5692£©ÒÔ¼°GFEÖеÄDLL½Ù³Ö£¨CVE?2019?5701£©¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/nvidia-fixes-security-flaws-in-gpu-driver-geforce-experience/4¡¢FacebookÔÙÆØÒþÖÔй¶£¬¿ª·¢ÈËԱΥ¹æ½Ó¼ûÓû§ÐÅÏ¢
FacebookÔÙÆØÒþÖÔй¶ÊÂÎñ£¬Ô¼100Ãû¿ª·¢ÈËÔ±¿ÉÎ¥¹æ½Ó¼ûÓû§ÐÅÏ¢¡£±¾ÖܶþFacebookƽ̨ºÏ×÷×ܼàKonstantinos PapamiltiadisÔÚһƪ²©ÎÄÖÐй©£¬Ö»¹Ü2018Äê4ÔÂÔø¶ÔÆäȨÏÞ½øÐÐÏÞ¶È£¬µ«²¿ÃŸô·¢ÈËÔ±ÈÔÄܹ»½Ó¼ûÓû§µÄÐÕÃû¡¢Ó×ÎÒ×ÊÁÏͼƬÒÔ¼°ÏµÍ³APIµÈÐÅÏ¢¡£×ܹ²Ô¼ÓÐ100Ãû¿ª·¢ÈËÔ±Äܹ»½Ó¼û´ËÐÅÏ¢£¬FacebookÈ·ÈÏÖÁÉÙÓÐ11Ãû¿ª·¢ÈËÔ±ÔÚ´Óǰ60ÌìÄÚ½Ó¼ûÁËÕâЩÊý¾Ý¡£¸Ã¹«Ë¾°µÊ¾ÒѾȡµÞÁËÕâÒ»½Ó¼ûȨÏÞ£¬²¢°µÊ¾»á¶ÔÓйØÇé¿ö½øÐÐÉó²é¡£¸Ã¹«Ë¾Ã»ÓÐй©Óм¸¶àÓû§Êܵ½Ó°Ïì¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/facebook-reveals-another-data-breach-this-time-involving-developers/
5¡¢Ç÷Ïò¿Æ¼¼ÄÚ²¿Ô±¹¤ÇÔÈ¡³¬¹ý12ÍòÓû§ÐÅÏ¢²¢ÏúÊÛ
Ç÷Ïò¿Æ¼¼ÄÚ²¿Ô±¹¤ÇÔÈ¡¹«Ë¾¿Í»§ÐÅÏ¢²¢½«ÆäÏúÊÛ¸øµÚÈý·½Ú¿ÆÍŻÔÚ¿Í»§Ôâµ½¼¼ÊõÖ§³¶à¿Æºó£¬Ç÷Ïò¿Æ¼¼·¢Õ¹µ÷²é²¢·¢ÏÖ¸ÃÔ±¹¤·¸·¨½Ó¼ûÁ˿ͻ§Ö§³ÖÊý¾Ý¿â¡£¿ÉÄܱ»ÇÔµÄÐÅÏ¢Ô̺¬¿Í»§µÄÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢¼¼ÊõÖ§³Öµ¥ºÅÒÔ¼°µç»°ºÅÂ룬µ«¸Ã¹«Ë¾Ç¿µ÷ûÓм£ÏóÅú×¢²ÆÕþ»òÐÅÓþ¿¨ÐÅÏ¢±»ÇÔ£¬²¢ÇÒûÓÐÉæ¼°µ½ÆóÒµ»òµ±¾Ö¿Í»§¡£Æ¾¾ÝÆäÄÚ²¿µ÷²é£¬ÊÜÓ°ÏìµÄ¿Í»§Ö»Õ¼Ç÷Ïò¿Æ¼¼1200Íò¿Í»§ÈºµÄ²»µ½1%£¬¼´12Íò¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/trendmicro-employee-sold-customer-info-to-tech-support-scammers/
6¡¢AnonymousºÍLulzSecITAÈëÇÖÒâ´óÀûÔËÓªÉÌLyca Mobile
AnonymousºÍLulzSecITAÈëÇÖÒâ´óÀûͨѶÔËÓªÉÌLyca Mobile£¬´Ó¸Ã¹«Ë¾ÇÔÈ¡ÁË5.4GBµÄÎļþ¡£´Óй¶µÄÎļþÀ´¿´£¬ÎĵµÖÐÔ̺¬Lyca MobileÓû§µÄ¹«¹²ID¡¢»¤ÕÕ¡¢¼ÝÕÕ¡¢µç»°¼Í¼¼°ÐÅÓþ¿¨ÐÅÏ¢µÈ¡£ÆäÖÐÒ»¸öÎļþ¼ÐµÄÄÚÈÝËÆºõÊôÓڸù«Ë¾µÄ¹Ù·½ÓÊÏäÕË»§lycamobile[at]lycamobile[.]it¡£Ä¿Ç°ÉÐÎÞ·¨ÑéÖ¤ÕâЩÎĵµµÄÕæÊµÐÔ¡£ÐÒÔ˵ÄÊǺڿÍ×éÖ¯ÌáÒéÕâЩ¹¥»÷Ö»ÊÇΪÁËÑéÖ¤Æä°²È«ÐÔ£¬¶ø²»ÊǶÔÓû§½øÐÐڲơ£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/93474/hacktivism/lulzsecita-lyca-mobile.html


¾©¹«Íø°²±¸11010802024551ºÅ