Libarchive´úÂëÖ´Ðзì϶ӰÏìLinux¼°BSD¿¯Ðаæ£»Ç÷Ïò¿Æ¼¼ÄÚ²¿Ô±¹¤ÇÔÈ¡³¬¹ý12ÍòÓû§ÐÅÏ¢²¢ÏúÊÛ

°ä²¼¹¦·ò 2019-11-07
1¡¢Libarchive´úÂëÖ´Ðзì϶ӰÏìLinux¼°BSD¿¯Ðаæ

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

¹È¸è°²È«×êÑÐÈËÔ±ÔÚLibarchiveÖз¢ÏÖÒ»¸ö´úÂëÖ´Ðзì϶£¨CVE-2019-18408£© £¬¹¥»÷Õß¿ÉÓÕʹÓû§´ò¿ª¶ñÒâ´æµµÎļþÔÚÆäϵͳÉÏÖ´ÐдúÂë¡£Debian¡¢Ubuntu¡¢Gentoo¡¢Arch LinuxÒÔ¼°FreeBSDºÍNetBSD¿¯Ðаæ¾ùÊÜÓ°Ïì £¬µ«WindowsºÍmacOS²»ÊÜÓ°Ïì¡£LibarchiveÍŶÓÔÚа汾3.4.0Öн¨¸´Á˸÷ì϶ £¬Ä¿Ç°ÉÐδÔÚÒ°±í·¢Ïָ÷ì϶µÄPoC»òÀûÓôúÂë¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/libarchive-vulnerability-can-lead-to-code-execution-on-linux-freebsd-netbsd/

2¡¢¹È¸è°ä²¼11ÔÂAndroid°²È«¸üР£¬½¨¸´40¸ö·ì϶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¹È¸è±¾Öܰ䲼11ÔÂAndroid°²È«¸üР£¬½¨¸´Á˽ü40¸ö·ì϶¡£¹È¸èÔÚ2019-11-01°²È«²¹¶¡·¨Ê½¼¶±ðÖн¨¸´ÁËFramework¡¢Library¡¢Ã½Ìå¿ò¼ÜºÍϵͳÖеÄ17¸ö·ì϶ £¬ÆäÖÐ×îÑϳÁµÄ·ì϶ÊÇϵͳ×é¼þÖеÄÈý¸öRCE·ì϶£¨CVE-2019-2204~CVE-2019-2206£© £¬ÊÜÓ°ÏìµÄϵͳ°æ±¾Îª8.0¡¢8.1¡¢9ºÍ10¡£¹È¸è»¹ÔÚ2019-11-05°²È«²¹¶¡·¨Ê½¼¶±ðÖн¨¸´ÁË21¸ö·ì϶ £¬ÆäÖÐ×îÑϳÁµÄÊǸßͨ×é¼þÖеÄ5¸ö·ì϶¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/google-patches-critical-flaws-androids-system-component

3¡¢NVIDIA½¨¸´ÏÔ¿¨Çý¶¯¼°GeForce Experience 12¸ö·ì϶

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

NVIDIA°ä²¼°²È«¸üР£¬½¨¸´ÆäÏÔ¿¨Çý¶¯·¨Ê½ºÍGFEÈí¼þÖеÄ12¸ö·ì϶ £¬·ì϶ÁìÓòº­¸Ç´úÂëÖ´ÐÓעȨÏÞÌáÉý¡¢ÐÅϢй¶ºÍ»Ø¾ø·þÎñ¡£ËùÓеķì϶¶¼²»Äܱ»Ô¶³ÌÀûÓà £¬±ØÐë±¾µØÓû§½Ó¼û £¬²¢ÇÒ¹¥»÷Õß±ØÐëÒÀÀµÓû§½»»¥À´ÀûÓÃËüÃÇ¡£ÕâЩ·ì϶µÄCVSS V3ÆÀ·ÖΪ5.1µ½7.8Ö®¼ä £¬ÆäÖÐ4¸ö¸ßΣ·ì϶ΪÏÔ¿¨Çý¶¯ÖеĻº³åÇøÒç³ö£¨CVE?2019?5690£©¡¢¿ÕÖ¸Õë½âÒýÓã¨CVE?2019?5691£©¡¢Êý×éË÷ÒýÔ½½ç£¨CVE?2019?5692£©ÒÔ¼°GFEÖеÄDLL½Ù³Ö£¨CVE?2019?5701£©¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/nvidia-fixes-security-flaws-in-gpu-driver-geforce-experience/

4¡¢FacebookÔÙÆØÒþÖÔй¶ £¬¿ª·¢ÈËԱΥ¹æ½Ó¼ûÓû§ÐÅÏ¢


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


FacebookÔÙÆØÒþÖÔй¶ÊÂÎñ £¬Ô¼100Ãû¿ª·¢ÈËÔ±¿ÉÎ¥¹æ½Ó¼ûÓû§ÐÅÏ¢¡£±¾ÖܶþFacebookƽ̨ºÏ×÷×ܼàKonstantinos PapamiltiadisÔÚһƪ²©ÎÄÖÐй© £¬Ö»¹Ü2018Äê4ÔÂÔø¶ÔÆäȨÏÞ½øÐÐÏÞ¶È £¬µ«²¿ÃŸô·¢ÈËÔ±ÈÔÄܹ»½Ó¼ûÓû§µÄÐÕÃû¡¢Ó×ÎÒ×ÊÁÏͼƬÒÔ¼°ÏµÍ³APIµÈÐÅÏ¢¡£×ܹ²Ô¼ÓÐ100Ãû¿ª·¢ÈËÔ±Äܹ»½Ó¼û´ËÐÅÏ¢ £¬FacebookÈ·ÈÏÖÁÉÙÓÐ11Ãû¿ª·¢ÈËÔ±ÔÚ´Óǰ60ÌìÄÚ½Ó¼ûÁËÕâЩÊý¾Ý¡£¸Ã¹«Ë¾°µÊ¾ÒѾ­È¡µÞÁËÕâÒ»½Ó¼ûȨÏÞ £¬²¢°µÊ¾»á¶ÔÓйØÇé¿ö½øÐÐÉó²é¡£¸Ã¹«Ë¾Ã»ÓÐй©Óм¸¶àÓû§Êܵ½Ó°Ïì¡£

Ô­ÎÄÁ´½Ó£º
https://www.zdnet.com/article/facebook-reveals-another-data-breach-this-time-involving-developers/

5¡¢Ç÷Ïò¿Æ¼¼ÄÚ²¿Ô±¹¤ÇÔÈ¡³¬¹ý12ÍòÓû§ÐÅÏ¢²¢ÏúÊÛ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ç÷Ïò¿Æ¼¼ÄÚ²¿Ô±¹¤ÇÔÈ¡¹«Ë¾¿Í»§ÐÅÏ¢²¢½«ÆäÏúÊÛ¸øµÚÈý·½Ú¿Æ­ÍŻÔÚ¿Í»§Ôâµ½¼¼ÊõÖ§³¶à¿Æ­ºó £¬Ç÷Ïò¿Æ¼¼·¢Õ¹µ÷²é²¢·¢ÏÖ¸ÃÔ±¹¤·¸·¨½Ó¼ûÁ˿ͻ§Ö§³ÖÊý¾Ý¿â¡£¿ÉÄܱ»ÇÔµÄÐÅÏ¢Ô̺¬¿Í»§µÄÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢¼¼ÊõÖ§³Öµ¥ºÅÒÔ¼°µç»°ºÅÂë £¬µ«¸Ã¹«Ë¾Ç¿µ÷ûÓм£ÏóÅú×¢²ÆÕþ»òÐÅÓþ¿¨ÐÅÏ¢±»ÇÔ £¬²¢ÇÒûÓÐÉæ¼°µ½ÆóÒµ»òµ±¾Ö¿Í»§¡£Æ¾¾ÝÆäÄÚ²¿µ÷²é £¬ÊÜÓ°ÏìµÄ¿Í»§Ö»Õ¼Ç÷Ïò¿Æ¼¼1200Íò¿Í»§ÈºµÄ²»µ½1% £¬¼´12Íò¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/trendmicro-employee-sold-customer-info-to-tech-support-scammers/

6¡¢AnonymousºÍLulzSecITAÈëÇÖÒâ´óÀûÔËÓªÉÌLyca Mobile


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


AnonymousºÍLulzSecITAÈëÇÖÒâ´óÀûͨѶÔËÓªÉÌLyca Mobile £¬´Ó¸Ã¹«Ë¾ÇÔÈ¡ÁË5.4GBµÄÎļþ¡£´Óй¶µÄÎļþÀ´¿´ £¬ÎĵµÖÐÔ̺¬Lyca MobileÓû§µÄ¹«¹²ID¡¢»¤ÕÕ¡¢¼ÝÕÕ¡¢µç»°¼Í¼¼°ÐÅÓþ¿¨ÐÅÏ¢µÈ¡£ÆäÖÐÒ»¸öÎļþ¼ÐµÄÄÚÈÝËÆºõÊôÓڸù«Ë¾µÄ¹Ù·½ÓÊÏäÕË»§lycamobile[at]lycamobile[.]it¡£Ä¿Ç°ÉÐÎÞ·¨ÑéÖ¤ÕâЩÎĵµµÄÕæÊµÐÔ¡£ÐÒÔ˵ÄÊǺڿÍ×éÖ¯ÌáÒéÕâЩ¹¥»÷Ö»ÊÇΪÁËÑéÖ¤Æä°²È«ÐÔ £¬¶ø²»ÊǶÔÓû§½øÐÐڲƭ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/93474/hacktivism/lulzsecita-lyca-mobile.html