ÐÅÏ¢°²È«Öܱ¨-2019ÄêµÚ35ÖÜ

°ä²¼¹¦·ò 2019-09-09

 > ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö



2019Äê9ÔÂ02ÈÕÖÁ08ÈÕ¹²ÊÕ¼°²È«·ì϶46¸ö £¬ÖµµÃ¹Ø×¢µÄÊÇBD PyxisδÊÚȨ½Ó¼û·ì϶ £»Mozilla Firefox CVE-2019-11741ͨÓÿçÕ¾¾ç±¾¹¥»÷·ì϶ £»CA Automic Workload Automation DIA CA Common Services´úÂëÖ´Ðзì϶ £»Aruba Mobility Controller WEB×é¼þºÅÁî×¢Èë·ì϶ £»Samba CVE-2019-10197Ŀ¼±éÀú·ì϶¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇÈýÐÇ¡¢»ªÎªµÈÊÖ»úÒ×ÊÜOMA CP¶ÌÐÅÖ¸ÁîºýŪ¹¥»÷ £»FacebookÓû§µç»°ºÅÂëÊý¾Ý¿âй¶ £¬Éæ¼°4.19Òڱʼͼ £»FacebookÓû§µç»°ºÅÂëÊý¾Ý¿âй¶ £¬Éæ¼°4.19Òڱʼͼ £»Ó¢¹ú¹ú»áÒéÔ±ÔÚ2019²ÆÄê½Ó¹Üµ½½ü2100Íò·âÀ¬»øÓʼþ £»Windows 10 KB4512941¸üе¼ÖÂCortanaÕ¼ÓÃCPU¹ý¸ß¡£


ƾ¾ÝÒÔÉÏ×ÛÊö £¬±¾Öܰ²È«ÍþвΪÖС£


> ³ÁÒª°²È«·ì϶Áбí



1. BD PyxisδÊÚȨ½Ó¼û·ì϶


BD PyxisÊÚȨ»úÔì´æÔÚ°²È«·ì϶ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó £¬Î´ÊÚȨ½Ó¼ûÀûÓá£
https://www.us-cert.gov/ics/advisories/icsma-19-248-01

2. Mozilla Firefox CVE-2019-11741ͨÓÿçÕ¾¾ç±¾¹¥»÷·ì϶


Mozilla FirefoxʵÏÖ´æÔÚͨÓÿçÕ¾¾ç±¾·ì϶ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄWEB £¬ÓÕʹÓû§½âÎö £¬²Ù¿Øaddons.mozilla.org¼°accounts.firefox.com¿ÉÅú¸ÄÓû§ÅäÖõÈ¡£
https://www.mozilla.org/en-US/security/advisories/mfsa2019-25/

3. CA Automic Workload Automation DIA CA Common Services´úÂëÖ´Ðзì϶


CA Automic Workload Automation DIA CA Common ServicesʵÏÖ´æÔÚ°²È«·ì϶ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó £¬¿ÉÖ´ÐдúÂë¡£
https://www.auscert.org.au/bulletins/ESB-2019.3374/

4. Aruba Mobility Controller WEB×é¼þºÅÁî×¢Èë·ì϶


Aruba Mobility Controller WEB×é¼þ´æÔÚºÅÁî×¢Èë·ì϶ £¬ÔÊÐíͨ¹ýÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó £¬¿ÉÖ´ÐÐËÁÒâºÅÁî¡£
https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2019-004.txt

5. Samba CVE-2019-10197Ŀ¼±éÀú·ì϶


SambaijЩ²ÎÊýÅäÖÃÏ´æÔÚ°²È«·ì϶ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó £¬¿ÉÈÆ¹ýĿ¼ÏÞ¶È £¬Î´ÊÚȨ½Ó¼û¡£
https://www.samba.org/samba/security/CVE-2019-10197.html


> ³ÁÒª°²È«ÊÂÎñ×ÛÊö



1¡¢ÈýÐÇ¡¢»ªÎªµÈÊÖ»úÒ×ÊÜOMA CP¶ÌÐÅÖ¸ÁîºýŪ¹¥»÷


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Check Point×êÑÐÈËÔ±·¢ÏÖËļÒÖÇÄÜÊÖ»úÔì×÷ÉÌ£¨Ô̺¬ÈýÐÇ¡¢»ªÎª¡¢LGºÍË÷ÄᣩδÔÚÆäÉ豸ÉÏÖ´Ðа²È«µÄOMA CPÖ¸Áî³ß¶È £¬Ê¹µÃ¹¥»÷ÕßÄܹ»Í¨¹ýαÔìOMA CP¶ÌÐÅÖ¸ÁîÓÕÆ­Óû§Åú¸ÄÉ豸ÅäÖà £¬´Ó¶øÀ¹½ØÆäµç×ÓÓʼþ»òÍøÂçÁ÷Á¿¡£OMA CP´ú±íÊ¢¿ªÒƶ¯Í¬Ã˿ͻ§¶ËÅäÖà £¬ËüÖ¸µÄÊÇÒÆ¶¯ÔËÓªÉÌ¿Éͨ¹ýÌØ¶¨¶ÌÐŽ«ÍøÂçÉèÖ÷¢Ë͵½Óû§É豸µÄÒ»Öֳ߶È¡£×êÑÐÈËÔ±³ÆÈýÐǵÄÊÖ»ú×î²»°²È« £¬ÓÉÓÚËüÄܹ»½ÓÊÜÈκÎÀàÐ͵ÄOMA CPÐÂÎŲ¢ÇÒûÓÐÈÏÖ¤»òÑéÖ¤»úÔì¡£ÈýÐǺÍLG±ðÀëÓÚ5Ô·ݺÍ7Ô·ݰ䲼Á˽¨¸´²¹¶¡ £¬»ªÎª°µÊ¾½«±ÉÈËÒ»´úMate»òPϵÁÐÊÖ»úÖвÎÓ뽨¸´²¹¶¡ £¬µ«Ë÷Äá»Ø¾øÈϿɸ÷ì϶¡£

Ô­ÎÄÁ´½Ó£º
https://www.zdnet.com/article/samsung-huawei-lg-and-sony-phones-vulnerable-to-rogue-provisioning-messages/

2¡¢FacebookÓû§µç»°ºÅÂëÊý¾Ý¿âй¶ £¬Éæ¼°4.19Òڱʼͼ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


×êÑÐÈËÔ±·¢ÏÖÒ»¸ö´æ´¢ÁËÊýÒÚFacebookÓû§µç»°ºÅÂë¼Í¼µÄÊý¾Ý¿âÔÚÍøÉ϶³ö¡£ÕâЩÊý¾Ý×ÜÊý³¬¹ý4.19Òڱʼͼ £¬º­¸Ç¶à¸öµØÓò £¬ÆäÖÐÔ̺¬1.33ÒÚÌõÃÀ¹úFacebookÓû§¼Í¼¡¢1800ÍòÓ¢¹úÓû§¼Í¼ÒÔ¼°5000¶àÍòÔ½ÄÏÓû§¼Í¼¡£¾ßÌå¶øÑÔ £¬Ã¿±Ê¼Í¼¶¼Ô̺¬Óû§µÄΨһFacebook IDºÍÕË»§¹ØÁªµÄµç»°ºÅÂë¡£ÓÉÓÚ´æ´¢ÕâЩÊý¾ÝµÄ·þÎñÆ÷ûÓÐÊÜÃÜÂë± £»¤ £¬µ¼ÖÂÈκÎÈ˶¼Äܹ»ÕÒµ½²¢½Ó¼û¸ÃÊý¾Ý¿â¡£Ã½ÌåÒѾ­¶ÔÆäÖÐһЩ¼Í¼½øÐÐÑéÖ¤ £¬»¹·¢ÏÖ²¿ÃżÍ¼Ô̺¬Óû§µÄÐÕÃû¡¢ÐÔ±ðºÍ¹ú¶È/µØÓòµØÎ»¡£

Ô­ÎÄÁ´½Ó£º
https://threatpost.com/leaky-server-exposes-419m-phone-numbers-of-facebook-users/148029/

3¡¢FacebookÓû§µç»°ºÅÂëÊý¾Ý¿âй¶ £¬Éæ¼°4.19Òڱʼͼ

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


×êÑÐÈËÔ±·¢ÏÖÒ»¸ö´æ´¢ÁËÊýÒÚFacebookÓû§µç»°ºÅÂë¼Í¼µÄÊý¾Ý¿âÔÚÍøÉ϶³ö¡£ÕâЩÊý¾Ý×ÜÊý³¬¹ý4.19Òڱʼͼ £¬º­¸Ç¶à¸öµØÓò £¬ÆäÖÐÔ̺¬1.33ÒÚÌõÃÀ¹úFacebookÓû§¼Í¼¡¢1800ÍòÓ¢¹úÓû§¼Í¼ÒÔ¼°5000¶àÍòÔ½ÄÏÓû§¼Í¼¡£¾ßÌå¶øÑÔ £¬Ã¿±Ê¼Í¼¶¼Ô̺¬Óû§µÄΨһFacebook IDºÍÕË»§¹ØÁªµÄµç»°ºÅÂë¡£ÓÉÓÚ´æ´¢ÕâЩÊý¾ÝµÄ·þÎñÆ÷ûÓÐÊÜÃÜÂë± £»¤ £¬µ¼ÖÂÈκÎÈ˶¼Äܹ»ÕÒµ½²¢½Ó¼û¸ÃÊý¾Ý¿â¡£Ã½ÌåÒѾ­¶ÔÆäÖÐһЩ¼Í¼½øÐÐÑéÖ¤ £¬»¹·¢ÏÖ²¿ÃżÍ¼Ô̺¬Óû§µÄÐÕÃû¡¢ÐÔ±ðºÍ¹ú¶È/µØÓòµØÎ»¡£

Ô­ÎÄÁ´½Ó£º
https://threatpost.com/leaky-server-exposes-419m-phone-numbers-of-facebook-users/148029/

4¡¢Ó¢¹ú¹ú»áÒéÔ±ÔÚ2019²ÆÄê½Ó¹Üµ½½ü2100Íò·âÀ¬»øÓʼþ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾ÝÒ»ÏîFOIÉêÇëÅû¶µÄÐÅÏ¢ £¬Ó¢¹ú¹ú»áÒéÔ±Äâ¶©ºÏͬ»á¹¤×÷ÈËÔ±ÔÚ2019²ÆÄê¶ÈÊÕµ½Á˽ü2100Íò·âÀ¬»øÓʼþ¡£ÕâЩÀ¬»øÓʼþÔ̺¬Á˶àÖÖDZÔڵĶñÒâÍþв £¬Ô̺¬ÍøÂç´¹µö¡¢¶ñÒâÁ´½Ó¡¢¶ñÒ⸽¼þÒÔ¼°ÆäËü¹¥»÷Õ½ÊõµÈ¡£2018²ÆÄêµÄ¼Í¼²¢²»ÆëÈ« £¬È»¶øÔÚÓмͼµÄ°ëÄêÄÚ¸ÃÊý×ÖΪ1430Íò·â¡£ÕâÅú×¢2019²ÆÄê¶ÈÕâЩÀ¬»øÓʼþµÄÊýÁ¿ÓÐËùÏ÷¼õ £¬Ò²¿ÉÄÜÊÇÓʼþ°²È«Íø¹ØµÄ»úÄܱÉÈ˽µ¡£


Ô­ÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/mps-bombarded-spam-brexit-no-deal/

5¡¢Windows 10 KB4512941¸üе¼ÖÂCortanaÕ¼ÓÃCPU¹ý¸ß


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÔÚ×°ÖÃÁËÉÏÖÜÕë¶ÔWindows 10 v1903µÄKB4512941ÀÛ»ý¸üкó £¬Ò»Ð©Óû§»ã±¨³ÆCortanaµÄSearchUI.exe¹ý³Ì²û·¢³ö¹ý¸ßµÄCPUÕ¼ÓÃÂÊ¡£ÕâÊÇÓÉÓڸð汾CortanaÖеÄÃýÎóµ¼Ö £¬µ±Óû§½ûÓÃÁËÏòBing·¢Ëͱ¾µØËÑË÷µÄÄÜÁ¦Ê±£¨ÎÞÂÛÊÇͨ¹ý×¢²á±í»¹ÊÇͨ¹ý×éÕ½Êõ£© £¬Cortana½«Õ¼ÓôóÁ¿CPU²¢ÇÒWindowsËÑË÷¿ÉÄÜ»áÏÔʾ¿ÕËÑË÷Á˾Ö¡£Òª½â¾ö´ËÎÊÌâ £¬Óû§Äܹ»Ñ¡Ôñ£ºÆôÓÃBingSearch £¬½«Cortana CacheÎļþ¼Ð´úÌæÎª¾É°æ±¾ £¬»òÐ¶ÔØ¸üС£µ±Ç°Î¢ÈíÉÐδÔÚKB4512941µÄÖ§³Ö²¼¸æÖÐÈ·ÈϸÃÎÊÌâ¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/microsoft/windows-10-kb4512941-update-causing-high-cpu-usage-in-cortana/